使用 Terraform 配置 IBM Cloud Logs 实例
IBM Cloud® 上的 Terraform 可实现 IBM Cloud 服务的可预测和一致调配,因此您可以快速构建复杂的多层云环境,并遵循基础设施即代码 ( IaC ) 原则。 与使用 IBM Cloud CLI 或 API 和 SDK 类似,您可以通过 HashiCorp 配置语言 (HCL) 自动配置、更新和删除 IBM Cloud Logs 实例。
对于生产部署,可考虑使用 Terraform IBM Modules(TIM)。IBM Cloud Logs 提供预构建、开源和企业就绪的配置,遵循 IBM Cloud 最佳实践。
TIM 模块可简化复杂的部署,确保跨环境的一致性,并减少配置错误。 探索 Terraform IBM Modules(TIM)注册表,查找可用模块。
正在寻找 IBM Cloud 上的 Terraform 托管解决方案? 试用 IBM Cloud® Schematics. 通过 Schematics,您可以使用熟悉的 Terraform 脚本语言,但无需担心设置和维护 Terraform 命令行和 IBM Cloud Provider 插件。Schematics 还提供预定义的 Terraform 模板,您可以从 IBM Cloud 目录中安装。
先决条件
- 在开始之前,请确保您拥有创建和使用 IBM Cloud Logs 资源 所需的权限。
- 安装 Terraform CLI。
安装 Terraform CLI
完成以下步骤安装 Terraform CLI:
-
在本地机器上创建 Terraform 文件夹,然后浏览到 terraform 文件夹。
mkdir terraform && cd terraform -
下载所需的 Terraform 版本。 例如,您可以为 MacOS 下载
terraform_1.12.2_darwin_amd64.zip。 请参阅 安装 Terraform。 -
解压缩 Terraform zip 文件并将这些文件复制到 terraform 目录。 请运行以下命令:
chmod +x terraformsudo mv terraform /usr/local/bin/ -
使用 terraform 命令确认版本,以验证安装是否成功。
terraform --version
设置 Terraform 工作目录
创建文件夹并导航进入文件夹。 该文件夹用于存储创建 IBM Cloud Logs 实例所需的所有配置文件和变量定义。
例如,在 Terraform 工作目录 <terraform-working-directory>/terraform 中,创建目录 myproject。
mkdir myproject && cd myproject
设置 IBM Cloud Provider 插件
Terraform CLI 安装完成后,必须为 Terraform 设置 IBM Cloud Provider 插件,以便开始在 IBM Cloud 中处理资源和服务。
有关支持版本的列表,请参阅 IBM Cloud Provider 插件版本。
确保使用最新发布的 IBM Cloud Provider 插件。
创建 versions.tf 文件,并使用 version 参数指定要使用的 IBM Cloud Provider 插件版本。
terraform {
required_providers {
ibm = {
source = "IBM-Cloud/ibm"
version = "<provider version>"
}
}
}
例如:
terraform {
required_providers {
ibm = {
source = "IBM-Cloud/ibm"
version = ">=1.80.0"
}
}
}
配置 IBM Cloud 提供者插件
完成设置后,必须 配置 IBM Cloud 提供程序插件。
在 IBM Cloud上开始使用 Terraform 之前,必须检索 Terraform 资源或数据源所需的凭证和参数,并在 provider 配置中指定这些凭证和参数。 此配置由 IBM Cloud 提供者插件用于向 IBM Cloud 平台进行认证,以及用于查看,创建,更新或删除 IBM Cloud 资源和服务。
下表列出了可以在 IBM Cloud 配置文件的 Terraform 的 provider 块中设置的输入参数:
| 输入参数 | 必需/可选 | 描述 |
|---|---|---|
ibmcloud_api_key |
必需 | 用于向 IBM Cloud 平台认证的 IBM Cloud API 密钥。 有关如何创建 API 密钥的更多信息,请参阅 创建 API 密钥。 您可以在 provider 块中指定 API 密钥,也可以从 IC_API_KEY 或 IBMCLOUD_API_KEY 环境变量中检索值。 如果定义了两个环境变量,那么 IC_API_KEY 优先。 |
ibmcloud_timeout |
可选 | 要等待到 IBM Cloud API 被视为不可用的秒数。 默认值为 60。 您可以在 provider 块中指定超时,也可以从 IC_TIMEOUT 或 IBMCLOUD_TIMEOUT 环境变量中检索值。 如果同时指定了这两个变量,那么 IC_TIMEOUT 优先。 |
region |
可选 | 要在其中创建资源的 IBM Cloud 区域。 如果未指定此值,那么缺省情况下将使用 us-south。 您可以在 provider 块中指定区域,也可以从 IBMCLOUD_REGION 或 IC_REGION 环境变量中检索值。 如果同时指定了两个环境变量,那么 IC_REGION 优先。 |
resource_group |
可选 | 要用于 IBM Cloud 资源的资源组的标识。 要检索 ID,请运行 ibmcloud resource groups。 您可以在 provider 块中指定资源组,也可以从 IC_RESOURCE_GROUP 或 IBMCLOUD_RESOURCE_GROUP 环境变量中检索值。 如果定义了两个环境变量,那么 IC_RESOURCE_GROUP 优先。 |
有关如何使用环境变量的更多信息,请参阅 使用环境变量。
在 terraform.tfvars 文件中配置输入变量
您可以在本地 terraform.tfvars 文件中存储信息,并在 provider 块中引用这些数据。
请勿将 terraform.tfvars 落实到公共源存储库中。 该文件只能存储在本地计算机上。
在项目目录 <terraform-directory>/terraform/myproject 中,在本地计算机上创建一个 terraform.tfvars 文件,并添加资源或数据源所需的输入参数。
ibmcloud_api_key = "<ibmcloud_api_key>"
region = "region"
account_id = "<Account ID>"
rg_id = "d7c0e937c529461f90a19e1421f9746d"
plan = "standard"
cos_instance_crn = "crn:v1:bluemix:public:cloud-object-storage:global:a/<Account ID>:<COS instance ID>::"
cos_storage_class = "standard"
cos_bucket_data_name = "cloud-logs-tf-data"
cos_bucket_metrics_name = "cloud-logs-tf-metrics"
event_notifications_crn = "crn:v1:bluemix:public:event-notifications:eu-gb:a/<Account ID>:<Event Notifications instance ID>::"
event_notifications_instance_id = "<Event Notifications instance ID>"
event_notifications_region = "eu-gb"
在 variables.tf 文件中声明变量
在项目目录 <terraform-directory>/terraform/myproject 中,创建一个名为 variables.tf 的变量文件,以包含默认值。
下面的示例列出了在配置 IBM Cloud Logs 实例时可以使用的变量:
variable "ibm_region" {
description = "Region to create resources. To see the list of valid regions, see https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-regions."
type = string
default = "eu-gb"
}
variable "resource_group_name" {
type = string
description = "Resource group where resources are created"
default = "Default"
}
variable "rg_id" {
type = string
description = "Resource group ID where resources are created"
default = "b302120431c4456097f8970d80b93dfb"
}
variable "plan" {
type = string
description = "Service plan for Cloud Logs instances"
default = "standard"
}
variable "cos_instance_crn" {
type = string
description = "COS instance CRN where buckets are created"
default = "crn:v1:bluemix:public:cloud-object-storage:global:a/<Account ID>:<COS instance ID>::"
}
variable "cos_storage_class" {
type = string
description = "COS instance storage class"
default = "standard"
}
variable "account_id" {
type = string
description = "Account where resources are created"
default = "<Account ID>"
}
variable "cos_bucket_data_name" {
type = string
description = "Cloud Object Storage bucket data name"
default = "cloud-logs-tf-data"
}
variable "cos_bucket_metrics_name" {
type = string
description = "Cloud Object Storage bucket data name"
default = "cloud-logs-tf-metrics"
}
variable "event_notifications_crn" {
type = string
description = "Event Notifications CRN"
default = "crn:v1:bluemix:public:event-notifications:eu-gb:a/<Account ID>:<Event Notifications Instance ID>::"
}
variable "event_notifications_instance_id" {
type = string
description = "Event Notifications instance ID"
default = "<Event Notifications Instance ID>"
}
variable "event_notifications_region" {
type = string
description = "Event notifications region"
default = "eu-gb"
}
provider.tf 文件中的引用变量
在项目目录 <terraform-directory>/terraform/myproject 中,创建 provider.tf 文件,并使用 Terraform 插值语法引用 terraform.tfvars 中的变量。
variable "ibmcloud_api_key" {}
variable "region" {}
provider "ibm" {
ibmcloud_api_key = var.ibmcloud_api_key
region = var.region
}
创建 Terraform 配置文件以配置 IBM Cloud Logs
接下来,创建以下文件:
-
data-bucket.tf:包含用于创建日志数据存储桶的 Terraform 资源定义。resource "ibm_cos_bucket" "data_bucket" { bucket_name = var.cos_bucket_data_name resource_instance_id = var.cos_instance_crn region_location = var.region storage_class = var.cos_storage_class } -
metrics-bucket.tf:包含 Terraform 资源定义,用于创建一个存储从日志数据中收集的指标的桶。resource "ibm_cos_bucket" "metrics_bucket" { bucket_name = var.cos_bucket_metrics_name resource_instance_id = var.cos_instance_crn region_location = var.region storage_class = var.cos_storage_class } -
main.tf:包含 Terraform 资源定义,用于创建 IBM Cloud Logs 实例并附加数据桶和指标桶。data "ibm_resource_group" "group" { name = "marisa" } resource "ibm_resource_instance" "cloud_logs_instance" { name = "cloud-logs-via-tf" service = "logs" plan = var.plan location = var.region resource_group_id = data.ibm_resource_group.group.id parameters = { retention_period = "7" } } resource "null_resource" "update_instance_parameters" { triggers = { instance_id = ibm_resource_instance.cloud_logs_instance.id } provisioner "local-exec" { command = <<EOT ibmcloud login --apikey=$IC_API_KEY ibmcloud resource service-instance-update ${ibm_resource_instance.cloud_logs_instance.guid} -p '{"logs_bucket_crn": "${ibm_cos_bucket.data_bucket.crn}", "logs_bucket_endpoint": "${ibm_cos_bucket.data_bucket.s3_endpoint_direct}", "metrics_bucket_crn": "${ibm_cos_bucket.metrics_bucket.crn}","metrics_bucket_endpoint": "${ibm_cos_bucket.metrics_bucket.s3_endpoint_direct}"}' EOT } depends_on = [ibm_iam_authorization_policy.policy-cl-data-bucket,ibm_iam_authorization_policy.policy-cl-metrics-bucket] } -
en_s2s.tf:包含 Terraform 资源定义,用于在 IBM Cloud Logs 实例和存储桶之间创建服务对服务授权。locals { cos_instance_id = split(":", ibm_cos_bucket.data_bucket.resource_instance_id)[7] } resource "ibm_iam_authorization_policy" "policy-cl-data-bucket" { source_service_name = "logs" source_resource_instance_id = ibm_resource_instance.cloud_logs_instance.guid roles = ["Writer"] resource_attributes { name = "serviceName" value = "cloud-object-storage" } resource_attributes { name = "serviceInstance" value = local.cos_instance_id operator = "stringEquals" } resource_attributes { name = "resourceType" value = "bucket" operator = "stringEquals" } resource_attributes { name = "resource" value = ibm_cos_bucket.data_bucket.bucket_name operator = "stringEquals" } resource_attributes { name = "accountId" value = var.account_id } } resource "ibm_iam_authorization_policy" "policy-cl-metrics-bucket" { source_service_name = "logs" source_resource_instance_id = ibm_resource_instance.cloud_logs_instance.guid roles = ["Writer"] resource_attributes { name = "serviceName" value = "cloud-object-storage" } resource_attributes { name = "serviceInstance" value = local.cos_instance_id operator = "stringEquals" } resource_attributes { name = "resourceType" value = "bucket" operator = "stringEquals" } resource_attributes { name = "resource" value = ibm_cos_bucket.metrics_bucket.bucket_name operator = "stringEquals" } resource_attributes { name = "accountId" value = var.account_id } } -
event-notification-extension.tf:包含 Terraform 资源定义,用于在 IBM Cloud Logs 实例和 IBM Cloud Event Notifications 实例之间创建向外集成,通过该集成向 Slack 或电子邮件等目的地发送通知。resource "ibm_logs_outgoing_webhook" "logs_outgoing_webhook_instance" { instance_id = ibm_resource_instance.cloud_logs_instance.guid region = ibm_resource_instance.cloud_logs_instance.location name = "Event-notification-cloud-logs-instance" type = "ibm_event_notifications" ibm_event_notifications { event_notifications_instance_id = var.event_notifications_instance_id region_id = var.event_notifications_region } depends_on = [ibm_iam_authorization_policy.policy-event-notifications] } -
s2s.tf:包含 Terraform 资源定义,用于在 IBM Cloud Logs 实例和 IBM Cloud Event Notifications 实例之间创建授权。resource "ibm_iam_authorization_policy" "policy-event-notifications" { source_service_name = "logs" source_resource_instance_id = ibm_resource_instance.cloud_logs_instance.guid roles = ["Reader","Event Source Manager","Viewer"] description = "" target_service_name = "event-notifications" }
有关如何将 Terraform 用于 IBM Cloud 资源的更多信息,请参见 ibm_resource_instance
使用 Terraform IBM 模块调配 IBM Cloud Logs 实例
作为步骤 4 的替代方法,可以使用 Terraform IBM 模块 (TIM) 配置 IBM Cloud Logs。 如果选择这种基于模块的方法,请跳过步骤 4,直接进入“提供资源”。
-
创建
main.tf文件:module "cloud_logs" { source = "terraform-ibm-modules/cloud-logs/ibm" version = "latest" # Replace "latest" with a release version to lock into a specific release resource_group_id = var.resource_group_id region = var.region instance_name = "my-cloud-logs-instance" plan = "standard" resource_tags = ["env:production", "team:devops"] } output "cloud_logs_instance_guid" { value = module.cloud_logs.guid } -
可选项:如果要对配置进行参数化,请定义输入变量。 例如,创建
variables.tf文件:variable "resource_group_id" { description = "Resource group ID for the Cloud Logs instance" type = string } variable "region" { description = "Region where the Cloud Logs instance will be created" type = string default = "us-south" }
有关完整的模块文档和高级配置选项,请参阅 IBM Cloud Logs 模块。
还可参考此 文档,了解如何使用 Terraform CLI 部署 Terraform IBM 模块。
供应资源
完成以下步骤:
-
初始化 Terraform CLI。
../terraform init您应该会看到以下消息:
Terraform has been successfully initialized!。 -
创建 Terraform 执行计划。 Terraform 执行计划汇总了需要运行的所有操作,以在您的帐户中创建 IBM Cloud Logs 实例,资源密钥和 IAM 访问策略。
../terraform plan -
创建资源。
../terraform apply要删除资源,请运行
./terraform destroy。
后续步骤?
验证资源是否已创建。 启动 Observability UI 并检查实例是否已创建。
您可以探索所有模块的生产就绪配置: