Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions IaC/ami/ami-builder-userdata.sh
Original file line number Diff line number Diff line change
Expand Up @@ -58,9 +58,9 @@ EOF
docker compose build
aws ecr get-login-password --region ${REGION} | docker login --username AWS --password-stdin ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com

docker tag platform-sql-judge:latest ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/platform-sql-judge:latest
docker tag platform-ctfd:latest ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/platform-ctfd:latest
docker push ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/platform-sql-judge:latest
docker push ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/platform-ctfd:latest
docker tag platform-sql-judge:latest ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/${SQL_JUDGE_ECR_REPOSITORY_NAME}:latest
docker tag platform-ctfd:latest ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/${CTFD_ECR_REPOSITORY_NAME}:latest
docker push ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/${SQL_JUDGE_ECR_REPOSITORY_NAME}:latest
docker push ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/${CTFD_ECR_REPOSITORY_NAME}:latest

docker rmi -f $(docker images -aq)
docker rmi -f $(docker images -aq)
8 changes: 5 additions & 3 deletions IaC/ami/ami.tf
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
resource "aws_ecr_repository" "platform-sql-judge-ecr-repository" {
name = "platform-sql-judge"
name = var.sql_judge_ecr_repository_name
image_tag_mutability = "MUTABLE"
force_delete = true # Allow deletion even with images

Expand All @@ -9,7 +9,7 @@ resource "aws_ecr_repository" "platform-sql-judge-ecr-repository" {
}

resource "aws_ecr_repository" "platform-sql-judge-ecr-ctfd" {
name = "platform-ctfd"
name = var.ctfd_ecr_repository_name
image_tag_mutability = "MUTABLE"
force_delete = true # Allow deletion even with images

Expand Down Expand Up @@ -128,6 +128,8 @@ resource "aws_instance" "ami_builder_arm" {
GOOGLE_CLIENT_SECRET = var.google_client_secret
REGION = var.region
AWS_ACCOUNT_ID = var.aws_account_id
CTFD_ECR_REPOSITORY_NAME = var.ctfd_ecr_repository_name
SQL_JUDGE_ECR_REPOSITORY_NAME = var.sql_judge_ecr_repository_name
}))

tags = {
Expand Down Expand Up @@ -171,4 +173,4 @@ resource "null_resource" "terminate_builder_arm" {
provisioner "local-exec" {
command = "aws ec2 terminate-instances --instance-ids ${aws_instance.ami_builder_arm[0].id} --region ${var.region} --profile ${var.aws_profile}"
}
}
}
4 changes: 3 additions & 1 deletion IaC/ami/var.tf
Original file line number Diff line number Diff line change
Expand Up @@ -10,4 +10,6 @@ variable "ctfd_secret_key" { type = string }
variable "google_client_id" { type = string }
variable "google_client_secret" { type = string }
variable "aws_account_id" { type = string }
variable "elasticache_serverless_endpoint" { type = string }
variable "ctfd_ecr_repository_name" { type = string }
variable "sql_judge_ecr_repository_name" { type = string }
variable "elasticache_serverless_endpoint" { type = string }
5 changes: 5 additions & 0 deletions IaC/backend.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
terraform {
required_version = "~> 1.16.0"

backend "s3" {}
}
11 changes: 8 additions & 3 deletions IaC/ec2/ec2.tf
Original file line number Diff line number Diff line change
Expand Up @@ -211,8 +211,13 @@ resource "aws_launch_template" "arm_launch_template" {
}

user_data = base64encode(templatefile("${path.module}/userdata.sh", {
REGION = var.region
AWS_ACCOUNT_ID = var.aws_account_id
REGION = var.region
AWS_ACCOUNT_ID = var.aws_account_id
CTFD_ECR_REPOSITORY_NAME = var.ctfd_ecr_repository_name
SQL_JUDGE_ECR_REPOSITORY_NAME = var.sql_judge_ecr_repository_name
APPLICATION_LOG_GROUP_NAME = var.application_log_group_name
BEHAVIOR_LOG_GROUP_NAME = var.behavior_log_group_name
BEHAVIOR_LOG_STREAM_NAME = var.behavior_log_stream_name
}))

tag_specifications {
Expand Down Expand Up @@ -315,4 +320,4 @@ resource "aws_autoscaling_policy" "request_count_tracking" {
# 어떤게 좋을지 알아봐야 할듯함.
target_value = 300.0 # 인스턴스당 300 요청 유지
}
}
}
24 changes: 12 additions & 12 deletions IaC/ec2/userdata.sh
Original file line number Diff line number Diff line change
Expand Up @@ -14,38 +14,38 @@ cat << 'CWCONFIG' | tee /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-a
"collect_list": [
{
"file_path": "/home/ubuntu/sql-playzone/platform/.data/CTFd/logs/logins.log",
"log_group_name": "/aws/ec2/sql-playzone",
"log_group_name": "${APPLICATION_LOG_GROUP_NAME}",
"log_stream_name": "logins",
"timezone": "Local"
},
{
"file_path": "/home/ubuntu/sql-playzone/platform/.data/CTFd/logs/registrations.log",
"log_group_name": "/aws/ec2/sql-playzone",
"log_group_name": "${APPLICATION_LOG_GROUP_NAME}",
"log_stream_name": "registrations",
"timezone": "Local"
},
{
"file_path": "/home/ubuntu/sql-playzone/platform/.data/CTFd/logs/submissions.log",
"log_group_name": "/aws/ec2/sql-playzone",
"log_group_name": "${APPLICATION_LOG_GROUP_NAME}",
"log_stream_name": "submissions",
"timezone": "Local"
},
{
"file_path": "/home/ubuntu/sql-playzone/platform/.data/CTFd/logs/error.log",
"log_group_name": "/aws/ec2/sql-playzone",
"log_group_name": "${APPLICATION_LOG_GROUP_NAME}",
"log_stream_name": "error",
"timezone": "Local"
},
{
"file_path": "/home/ubuntu/sql-playzone/platform/.data/CTFd/logs/sql-judge.log",
"log_group_name": "/aws/ec2/sql-playzone",
"log_group_name": "${APPLICATION_LOG_GROUP_NAME}",
"log_stream_name": "sql-judge",
"timezone": "Local"
},
{
"file_path": "/home/ubuntu/sql-playzone/platform/.data/CTFd/logs/sql_challenge_behavior.log",
"log_group_name": "/aws/ec2/sql-playzone-behavior",
"log_stream_name": "sql-challenge",
"log_group_name": "${BEHAVIOR_LOG_GROUP_NAME}",
"log_stream_name": "${BEHAVIOR_LOG_STREAM_NAME}",
"timezone": "Local"
}
]
Expand All @@ -70,12 +70,12 @@ git pull origin main
aws ecr get-login-password --region ${REGION} | docker login --username AWS --password-stdin ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com

# Pull images from ECR
docker pull ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/platform-sql-judge:latest
docker pull ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/platform-ctfd:latest
docker pull ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/${SQL_JUDGE_ECR_REPOSITORY_NAME}:latest
docker pull ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/${CTFD_ECR_REPOSITORY_NAME}:latest

# Tag the pulled images with local names that docker-compose expects
docker tag ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/platform-sql-judge:latest platform-sql-judge:latest
docker tag ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/platform-ctfd:latest platform-ctfd:latest
docker tag ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/${SQL_JUDGE_ECR_REPOSITORY_NAME}:latest platform-sql-judge:latest
docker tag ${AWS_ACCOUNT_ID}.dkr.ecr.${REGION}.amazonaws.com/${CTFD_ECR_REPOSITORY_NAME}:latest platform-ctfd:latest

# Run docker-compose
docker compose up -d
docker compose up -d
7 changes: 6 additions & 1 deletion IaC/ec2/var.tf
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,9 @@ variable "asg_desired_capacity" { type = number }
variable "key_name" { type = string }
variable "ondemand_instance_type" { type = string }
variable "region" { type = string }
variable "aws_account_id" { type = string }
variable "aws_account_id" { type = string }
variable "ctfd_ecr_repository_name" { type = string }
variable "sql_judge_ecr_repository_name" { type = string }
variable "application_log_group_name" { type = string }
variable "behavior_log_group_name" { type = string }
variable "behavior_log_stream_name" { type = string }
5 changes: 2 additions & 3 deletions IaC/lambda/lambda.tf
Original file line number Diff line number Diff line change
Expand Up @@ -39,8 +39,7 @@ resource "aws_iam_role_policy" "lambda_policy" {
{
Effect = "Allow"
Action = [
"s3:PutObject",
"s3:PutObjectAcl"
"s3:PutObject"
]
Resource = "arn:aws:s3:::${var.bucket_name}/*"
}
Expand Down Expand Up @@ -99,4 +98,4 @@ resource "aws_lambda_permission" "allow_eventbridge" {
function_name = aws_lambda_function.log_processor.function_name
principal = "events.amazonaws.com"
source_arn = aws_cloudwatch_event_rule.daily_trigger.arn
}
}
9 changes: 9 additions & 0 deletions IaC/locals.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
locals {
ctfd_ecr_repository_name = "${var.prefix}-ctfd"
sql_judge_ecr_repository_name = "${var.prefix}-sql-judge"

application_log_group_name = "/aws/ec2/${var.prefix}"
behavior_log_group_name = "/aws/ec2/${var.prefix}-behavior"
behavior_log_stream_name = "${var.prefix}-sql-challenge"
log_bucket_name = "${var.prefix}-logs-${var.aws_account_id}-${var.region}"
}
39 changes: 39 additions & 0 deletions IaC/logging.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
resource "aws_cloudwatch_log_group" "application" {
name = local.application_log_group_name
}

resource "aws_cloudwatch_log_group" "behavior" {
name = local.behavior_log_group_name
retention_in_days = 3
}

resource "aws_s3_bucket" "log_archive" {
bucket = local.log_bucket_name
}

resource "aws_s3_bucket_ownership_controls" "log_archive" {
bucket = aws_s3_bucket.log_archive.id

rule {
object_ownership = "BucketOwnerEnforced"
}
}

resource "aws_s3_bucket_public_access_block" "log_archive" {
bucket = aws_s3_bucket.log_archive.id

block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
}

resource "aws_s3_bucket_server_side_encryption_configuration" "log_archive" {
bucket = aws_s3_bucket.log_archive.id

rule {
apply_server_side_encryption_by_default {
sse_algorithm = "AES256"
}
}
}
21 changes: 18 additions & 3 deletions IaC/main.tf
Original file line number Diff line number Diff line change
@@ -1,6 +1,14 @@
provider "aws" {
region = var.region
profile = var.aws_profile

default_tags {
tags = {
Project = "sql-playzone"
Deployment = var.prefix
ManagedBy = "terraform"
}
}
}

# VPC Module
Expand Down Expand Up @@ -59,6 +67,8 @@ module "ami" {
google_client_id = var.google_client_id
google_client_secret = var.google_client_secret
aws_account_id = var.aws_account_id
ctfd_ecr_repository_name = local.ctfd_ecr_repository_name
sql_judge_ecr_repository_name = local.sql_judge_ecr_repository_name
elasticache_serverless_endpoint = module.elasticache.elasticache_serverless_endpoint[0].address

depends_on = [module.vpc, module.rds, module.elasticache]
Expand All @@ -84,6 +94,11 @@ module "ec2" {
ondemand_instance_type = var.ondemand_server_instance_class
region = var.region
aws_account_id = var.aws_account_id
ctfd_ecr_repository_name = local.ctfd_ecr_repository_name
sql_judge_ecr_repository_name = local.sql_judge_ecr_repository_name
application_log_group_name = aws_cloudwatch_log_group.application.name
behavior_log_group_name = aws_cloudwatch_log_group.behavior.name
behavior_log_stream_name = local.behavior_log_stream_name

depends_on = [module.vpc, module.rds] # We do not append ami module but you have to create ami before apply this module
# depends_on = [module.vpc, module.rds, module.ami] # When you want to use only `terraform apply` without designating targets, use this.
Expand All @@ -96,9 +111,9 @@ module "lambda" {
prefix = var.prefix
region = var.region
aws_account_id = var.aws_account_id
bucket_name = var.log_bucket_name
log_group_name = var.behavior_log_group_name
log_stream_name = var.behavior_log_stream_name
bucket_name = aws_s3_bucket.log_archive.bucket
log_group_name = aws_cloudwatch_log_group.behavior.name
log_stream_name = local.behavior_log_stream_name

depends_on = [module.vpc]
}
29 changes: 8 additions & 21 deletions IaC/var.tf
Original file line number Diff line number Diff line change
@@ -1,7 +1,12 @@
variable "prefix" {
description = "The prefix to use for all resources"
description = "Deployment identifier used to name all deployment-scoped resources"
type = string
default = "playzone"
default = "sql-2026-s2"

validation {
condition = length(var.prefix) <= 28 && can(regex("^[a-z0-9][a-z0-9-]*[a-z0-9]$", var.prefix))
error_message = "prefix must be at most 28 characters and contain only lowercase letters, numbers, and internal hyphens."
}
}

variable "region" {
Expand Down Expand Up @@ -89,7 +94,7 @@ variable "ondemand_server_instance_class" {
variable "domain_name" {
description = "Domain name for the application"
type = string
default = "playzone.ddps.cloud"
default = "sql.ddps.cloud"
}

variable "on_demand_base_capacity" {
Expand Down Expand Up @@ -121,21 +126,3 @@ variable "asg_desired_capacity" {
type = number
default = 1
}

variable "log_bucket_name" {
description = "S3 Bucket name for storing logs"
type = string
default = "sql-playzone-log"
}

variable "behavior_log_group_name" {
description = "CloudWatch Log Group name for behavior logs"
type = string
default = "/aws/ec2/sql-playzone-behavior"
}

variable "behavior_log_stream_name" {
description = "CloudWatch Log Stream name for behavior logs"
type = string
default = "sql-challenge"
}