{"id":48893,"date":"2022-11-01T00:15:05","date_gmt":"2023-09-02T14:51:32","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/"},"modified":"2024-04-28T22:22:40","modified_gmt":"2024-04-28T14:22:40","slug":"%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/","title":{"rendered":"\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684Terraform\u8fd0\u7ef4\u73af\u5883"},"content":{"rendered":"<h1>\u7b80\u8981\u6982\u8ff0<\/h1>\n<p>\u7531\u4e8e\u5728\u4e1a\u52a1\u4e2d\u6709\u673a\u4f1a\u4f7f\u7528AWS\u548cTerraform\uff0c<br \/>\n\u56e0\u6b64\u603b\u7ed3\u4e86\u5728\u4f7f\u7528\u8fc7\u7a0b\u4e2d\u83b7\u5f97\u7684\u8fd0\u7ef4\u7ecf\u9a8c\u3002<br \/>\n\u53e6\u5916\uff0c\u5728\u7b2c2\u7ae0\u53ca\u4ee5\u540e\u4ecb\u7ecd\u7684Terraform\u8fd0\u7ef4\u65b9\u6cd5\u662f\u4e2a\u4eba\u7684\u6700\u7ec8\u76ee\u6807\uff0c<br \/>\n\u5e76\u4e0d\u4ee3\u8868Terraform\u7684\u6700\u4f73\u5b9e\u8df5\uff0c\u53ea\u80fd\u4f5c\u4e3a\u53c2\u8003\u3002<br \/>\n\uff08\u4f8b\u5982\u6545\u610f\u6ca1\u6709\u4f7f\u7528terraform workspace\u7b49\uff09<\/p>\n<h1>\u672c\u6587\u6db5\u76d6\u7684\u73af\u5883\u5217\u8868<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u958b\u767a\u74b0\u5883\u3000(\u30ed\u30fc\u30ab\u30ebPC)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883\u3000(\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883\u7528AWS\u30a2\u30ab\u30a6\u30f3\u30c8)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u672c\u756a\u74b0\u5883\u3000(\u672c\u756a\u74b0\u5883\u7528AWS\u30a2\u30ab\u30a6\u30f3\u30c8)<\/ul>\n<h1>\u6267\u884c\u73af\u5883<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Linux<\/ul>\n<\/li>\n<\/ul>\n<p>Debian [v10.8]<\/p>\n<p>Windows<\/p>\n<p>WSL \u306e Ubuntu [v20.04]<br \/>\nWSL\u306e\u69cb\u7bc9\u306b\u3064\u3044\u3066\u306f\u4ee5\u4e0b\u3092\u53c2\u7167<\/p>\n<h1>0. \u521b\u5efaAWS\u8d26\u6237 AWS<\/h1>\n<p>\u8bf7\u53c2\u8003\u4ee5\u4e0b\u5185\u5bb9\uff0c\u5728AWS\u4e0a\u521b\u5efa\u7528\u4e8e\u4e34\u65f6\u73af\u5883\u548c\u751f\u4ea7\u73af\u5883\u7684\u8d26\u6237\uff0c\u5e76\u4e3aTerraform\u7ba1\u7406\u7684\u8d44\u6e90\u6388\u4e88\u76f8\u5e94\u6743\u9650\uff0c\u7136\u540e\u5206\u522b\u83b7\u53d6IAM\u7528\u6237\u7684\u51ed\u636e\u4fe1\u606f\u3002<\/p>\n<ul class=\"post-ul\">\u521d\u3081\u3066\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u4f5c\u308b\u5834\u5408<\/ul>\n<ul class=\"post-ul\">AWS\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u521d\u671f\u8a2d\u5b9a\u306b\u3064\u3044\u3066<\/ul>\n<ul class=\"post-ul\">IAM\u30e6\u30fc\u30b6\u4f5c\u6210\u306b\u3064\u3044\u3066<\/ul>\n<ul class=\"post-ul\">\u30de\u30eb\u30c1\u30a2\u30ab\u30a6\u30f3\u30c8\u7ba1\u7406\u306b\u3064\u3044\u3066<\/ul>\n<h1>1. \u8bbe\u7acb\u73af\u5883<\/h1>\n<h2>\u2170. \u5b89\u88c5AWS CLI<\/h2>\n<p>\u53c2\u7167 \u516c\u5f0f\u6307\u5357\uff0c\u987a\u5e8f\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u3002<\/p>\n<h3>\u2460. \u4e0b\u8f7dAWS CLI\u5b89\u88c5\u6587\u4ef6<\/h3>\n<pre class=\"post-pre\"><code>curl <span class=\"s2\">\"https:\/\/awscli.amazonaws.com\/awscli-exe-linux-x86_64.zip\"<\/span> <span class=\"nt\">-o<\/span> ~\/awscliv2.zip\r\n<\/code><\/pre>\n<h3>2. \u5b89\u88c5\u6587\u4ef6\u89e3\u538b\u7f29<\/h3>\n<pre class=\"post-pre\"><code>unzip ~\/awscliv2.zip\r\n<\/code><\/pre>\n<h3>\u2462. \u5b89\u88c5 AWS CLI\u3002<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo<\/span> ~\/aws\/install\r\n<\/code><\/pre>\n<h3>\u5c06\u4e3aAWS CLI\u4fdd\u5b58\u7684\u8bbe\u7f6e\u4fe1\u606f\u4fdd\u5b58\u5230\u5206\u6bb5\u73af\u5883<\/h3>\n<pre class=\"post-pre\"><code>aws configure <span class=\"nt\">--profile<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span><span class=\"nt\">-stage<\/span>\r\n<\/code><\/pre>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u4e0a\u8a18\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u5f8c\u3001\u4ee5\u4e0b\u306e\u8cea\u554f\u306b\u7b54\u3048\u308b\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>AWS Access Key ID [None]:<br \/>\n-&gt; \u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883\u7528IAM\u30e6\u30fc\u30b6\u306e\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u60c5\u5831(Access Key ID)\u3092\u5165\u529b<\/p>\n<p>AWS Secret Access Key [None]:<br \/>\n-&gt; \u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883\u7528IAM\u30e6\u30fc\u30b6\u306e\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u60c5\u5831(Secret Access Key)\u3092\u5165\u529b<\/p>\n<p>Default region name [None]:<br \/>\n-&gt; ap-northeast-1<\/p>\n<p>Default output format [None]:<br \/>\n-&gt; json<\/p>\n<h3>\u5c06\u751f\u4ea7\u73af\u5883\u7684\u914d\u7f6e\u4fe1\u606f\u4fdd\u5b58\u5230AWS CLI\u3002<\/h3>\n<pre class=\"post-pre\"><code>aws configure <span class=\"nt\">--profile<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span><span class=\"nt\">-prod<\/span>\r\n<\/code><\/pre>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u4e0a\u8a18\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u5f8c\u3001\u2463\u3068\u540c\u3058\u8cea\u554f\u306b<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u672c\u756a\u74b0\u5883\u7528IAM\u30e6\u30fc\u30b6\u306e\u30af\u30ec\u30c7\u30f3\u30b7\u30e3\u30eb\u60c5\u5831\u3067\u7b54\u3048\u308b\u3002<\/ul>\n<h2>\u2171. \u5b89\u88c5\u4f1a\u8bdd\u7ba1\u7406\u63d2\u4ef6<\/h2>\n<h3>\u2460. \u4e0b\u8f7d\u5305<\/h3>\n<pre class=\"post-pre\"><code>curl <span class=\"s2\">\"https:\/\/s3.amazonaws.com\/session-manager-downloads\/plugin\/latest\/ubuntu_64bit\/session-manager-plugin.deb\"<\/span> <span class=\"nt\">-o<\/span> <span class=\"s2\">\"session-manager-plugin.deb\"<\/span>\r\n<\/code><\/pre>\n<h3>\u2461. \u5b89\u88c5\u4f1a\u8bdd\u7ba1\u7406\u5668\u63d2\u4ef6<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo <\/span>dpkg <span class=\"nt\">-i<\/span> session-manager-plugin.deb\r\n<\/code><\/pre>\n<h3>\u786e\u8ba4\u4f1a\u8bdd\u7ba1\u7406\u63d2\u4ef6\u3002<\/h3>\n<pre class=\"post-pre\"><code>session-manager-plugin\r\n<\/code><\/pre>\n<h2>\u2172. \u5b89\u88c5 Terraform<\/h2>\n<h3>\u2460. \u4ed3\u5e93\u514b\u9686<\/h3>\n<pre class=\"post-pre\"><code>git clone https:\/\/github.com\/tfutils\/tfenv.git ~\/.tfenv\r\n<\/code><\/pre>\n<h3>\u5c06\u8def\u5f84\u6dfb\u52a0\u5230\u4ed3\u5e93<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nb\">cat<\/span> <span class=\"o\">&lt;&lt;<\/span> <span class=\"sh\">'<\/span><span class=\"no\">EOS<\/span><span class=\"sh\">' &gt;&gt; ~\/.bashrc\r\n\r\nexport PATH=\"<\/span><span class=\"nv\">$PATH<\/span><span class=\"sh\">:<\/span><span class=\"nv\">$HOME<\/span><span class=\"sh\">\/.tfenv\/bin\"\r\n<\/span><span class=\"no\">\r\nEOS\r\n<\/span><span class=\"nb\">source<\/span> ~\/.bashrc\r\n<\/code><\/pre>\n<h3>\u2462. \u5b89\u88c5tfenv<\/h3>\n<pre class=\"post-pre\"><code>tfenv <span class=\"nb\">install<\/span>\r\n<\/code><\/pre>\n<h3>\u2463. \u542f\u7528\u547d\u4ee4\u7684\u6807\u7b7e\u5b58\u50a8\u3002<\/h3>\n<pre class=\"post-pre\"><code>terraform <span class=\"nt\">-install-autocomplete<\/span>\r\n<\/code><\/pre>\n<h2>\u2173. \u5b89\u88c5 git-secrets<\/h2>\n<h3>\u2460. \u514b\u9686\u5b58\u50a8\u5e93<\/h3>\n<pre class=\"post-pre\"><code>git clone https:\/\/github.com\/awslabs\/git-secrets.git ~\/.git-secrets\r\n<\/code><\/pre>\n<h3>2. \u5b89\u88c5 git-secrets<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nb\">cd<\/span> ~\/.git-secrets\/ <span class=\"o\">&amp;&amp;<\/span> <span class=\"nb\">sudo <\/span>make <span class=\"nb\">install<\/span>\r\n<\/code><\/pre>\n<h3>\u2462. \u5c06 git-secrets \u914d\u7f6e\u4e3a\u9002\u7528\u4e8eAWS\u3002<\/h3>\n<pre class=\"post-pre\"><code>git secrets <span class=\"nt\">--register-aws<\/span> <span class=\"nt\">--global<\/span>\r\n<\/code><\/pre>\n<h3>\u2463. Git\u7684\u81ea\u5b9a\u4e49<\/h3>\n<pre class=\"post-pre\"><code>git secrets <span class=\"nt\">--install<\/span> ~\/.git-templates\/git-secrets\r\ngit config <span class=\"nt\">--global<\/span> init.templatedir <span class=\"s1\">'~\/.git-templates\/git-secrets'<\/span>\r\n<\/code><\/pre>\n<h1>2. \u521b\u5efaTerraform\u4ed3\u5e93 (CJIAAN)<\/h1>\n<p>\u5728master\u5206\u652f\u4e0a\uff0c\u521b\u5efaTerraform\u4ed3\u5e93\u3002<br \/>\n\u521b\u5efa\u5b8c\u6210\u540e\uff0c\u8981\u521b\u5efa\u7528\u4e8e\u8d44\u6e90\u6784\u5efa\u7ba1\u7406\u7684\u5206\u652f\uff0c\u4f8b\u5982v1.0.0\/stage\u548cv1.0.0\/prod\u3002<br \/>\n\u4ee5\u540e\uff0c\u4e3b\u5206\u652f\u5c06\u7528\u4e8e\u7ba1\u7406\u4e0e\u6574\u4f53\u76f8\u5173\u7684\u66f4\u6539\u3002<br \/>\n\u4e0b\u9762\u662f\u6211\u521b\u5efa\u7684Terraform\u4ed3\u5e93\u7684\u76ee\u5f55\u7ed3\u6784\u793a\u4f8b\uff0c\u7528\u4e8e\u5c06Laravel\u5e94\u7528\u90e8\u7f72\u5230AWS Fargate\u3002<\/p>\n<pre class=\"post-pre\"><code>.\r\n\u251c\u2500\u2500 README.md\r\n\u251c\u2500\u2500 .terraform-version                      --&gt; Terraform\u5b9f\u884c\u6642\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u6307\u5b9a\r\n\u251c\u2500\u2500 set_aws_profile.sh                      --&gt; terraform\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u7528\u3059\u308b\u4e8b\u524d\u6e96\u5099\r\n\u251c\u2500\u2500 modules                                 --&gt; Terraform\u3067\u7e70\u308a\u8fd4\u3057\u4f7f\u3046\u30e2\u30b8\u30e5\u30fc\u30eb\r\n\u2502   \u251c\u2500\u2500 alb_target_group\r\n\u2502   \u2502   \u251c\u2500\u2500 main.tf\r\n\u2502   \u2502   \u251c\u2500\u2500 outputs.tf\r\n\u2502   \u2502   \u2514\u2500\u2500 variables.tf\r\n\u2502   \u251c\u2500\u2500 ecs_service\r\n\u2502   \u2502   \u251c\u2500\u2500 main.tf\r\n\u2502   \u2502   \u251c\u2500\u2500 outputs.tf\r\n\u2502   \u2502   \u2514\u2500\u2500 variables.tf\r\n\u2502   \u251c\u2500\u2500 host_client_security_group\r\n\u2502   \u2502   \u251c\u2500\u2500 main.tf\r\n\u2502   \u2502   \u251c\u2500\u2500 outputs.tf\r\n\u2502   \u2502   \u2514\u2500\u2500 variables.tf\r\n\u2502   \u251c\u2500\u2500 iam_role\r\n\u2502   \u2502   \u251c\u2500\u2500 main.tf\r\n\u2502   \u2502   \u251c\u2500\u2500 outputs.tf\r\n\u2502   \u2502   \u2514\u2500\u2500 variables.tf\r\n\u2502   \u251c\u2500\u2500 route53_domain\r\n\u2502   \u2502   \u251c\u2500\u2500 main.tf\r\n\u2502   \u2502   \u251c\u2500\u2500 outputs.tf\r\n\u2502   \u2502   \u2514\u2500\u2500 variables.tf\r\n\u2502   \u251c\u2500\u2500 s3_log_bucket\r\n\u2502   \u2502   \u251c\u2500\u2500 main.tf\r\n\u2502   \u2502   \u251c\u2500\u2500 outputs.tf\r\n\u2502   \u2502   \u2514\u2500\u2500 variables.tf\r\n\u2502   \u2514\u2500\u2500 security_group\r\n\u2502       \u251c\u2500\u2500 main.tf\r\n\u2502       \u251c\u2500\u2500 outputs.tf\r\n\u2502       \u2514\u2500\u2500 variables.tf\r\n\u251c\u2500\u2500 operation                               --&gt; \u30a2\u30d7\u30ea\u30e1\u30f3\u30c6\u7528\u30ea\u30bd\u30fc\u30b9\u7fa4\r\n\u2502   \u251c\u2500\u2500 .gitignore\r\n\u2502   \u251c\u2500\u2500 main.tf\r\n\u2502   \u251c\u2500\u2500 operation_setup.sh\r\n\u2502   \u251c\u2500\u2500 outputs.tf\r\n\u2502   \u251c\u2500\u2500 prod.tfbackend\r\n\u2502   \u251c\u2500\u2500 prod.tfvars\r\n\u2502   \u2514\u2500\u2500 variables.tf\r\n\u251c\u2500\u2500 step0.sh                                --&gt; \u521d\u671f\u69cb\u7bc9\u30ea\u30bd\u30fc\u30b9\u7fa4\r\n\u251c\u2500\u2500 step1                                   --&gt; \u7b2c\u4e00\u6bb5\u968e\u69cb\u7bc9\u30ea\u30bd\u30fc\u30b9\u7fa4\r\n\u2502   \u251c\u2500\u2500 .gitignore\r\n\u2502   \u251c\u2500\u2500 ecr_repository.tf\r\n\u2502   \u251c\u2500\u2500 lambda_iam_role.tf\r\n\u2502   \u251c\u2500\u2500 main.tf\r\n\u2502   \u251c\u2500\u2500 outputs.tf\r\n\u2502   \u251c\u2500\u2500 prod.tfbackend\r\n\u2502   \u251c\u2500\u2500 prod.tfvars\r\n\u2502   \u251c\u2500\u2500 rds_db.tf\r\n\u2502   \u251c\u2500\u2500 s3_buckets.tf\r\n\u2502   \u251c\u2500\u2500 ssm_parameters.tf\r\n\u2502   \u251c\u2500\u2500 ssm_parameters_setup.sh            --&gt; \u30bb\u30f3\u30b7\u30c6\u30a3\u30d6\u306a\u5024\u3092\u624b\u52d5\u66f4\u65b0\r\n\u2502   \u251c\u2500\u2500 variables.tf\r\n\u2502   \u2514\u2500\u2500 vpc_endpoint.tf\r\n\u251c\u2500\u2500 step2                                   --&gt; \u7b2c\u4e8c\u6bb5\u968e\u69cb\u7bc9\u30ea\u30bd\u30fc\u30b9\u7fa4\r\n\u2502   \u251c\u2500\u2500 .gitignore\r\n\u2502   \u251c\u2500\u2500 ******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)_container.json\r\n\u2502   \u251c\u2500\u2500 ******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)_container_admin.json\r\n\u2502   \u251c\u2500\u2500 ******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)_container_camera.json\r\n\u2502   \u251c\u2500\u2500 main.tf\r\n\u2502   \u251c\u2500\u2500 outputs.tf\r\n\u2502   \u251c\u2500\u2500 prod.tfbackend\r\n\u2502   \u251c\u2500\u2500 prod.tfvars\r\n\u2502   \u2514\u2500\u2500 variables.tf\r\n\u251c\u2500\u2500 git_cherry-pick_from_master.sh          --&gt; master\u30d6\u30e9\u30f3\u30c1\u304b\u3089\u5404\u30d6\u30e9\u30f3\u30c1\u3078\u306echerry-pick\r\n\u251c\u2500\u2500 terraform_apply.sh                      --&gt; [terraform apply] \u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u7528\r\n\u2514\u2500\u2500 terraform_destroy.sh                    --&gt; [terraform destroy] \u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u7528\r\n<\/code><\/pre>\n<p>\u5728\u4e0a\u8ff0\u7684\u76ee\u5f55\u7ed3\u6784\u4e2d\u4ecb\u7ecd\u4e0e\u8fd0\u8425\u76f8\u5173\u7684\u5185\u5bb9\u3002<\/p>\n<h2>\u2170. .terraform\u7248\u672c<\/h2>\n<pre class=\"post-pre\"><code>1.0.0\r\n<\/code><\/pre>\n<p>\u8bf4\u660e\uff1a\u7528\u4e8e\u5728\u6b64\u5b58\u50a8\u5e93\u4e2d\u6267\u884cterraform\u547d\u4ee4\u7684Terraform\u7248\u672c\u6307\u5b9a\u6587\u4ef6\u3002<\/p>\n<h2>\u2171. \u8bbe\u7f6e_aws_\u914d\u7f6e\u6587\u4ef6.sh<\/h2>\n<pre class=\"post-pre\"><code><span class=\"nb\">set<\/span> <span class=\"nt\">-eu<\/span>\r\n\r\n<span class=\"nb\">echo<\/span> <span class=\"s1\">'\u30c7\u30d7\u30ed\u30a4\u5148\uff1a\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883 or \u672c\u756a\u74b0\u5883\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n<span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'ex) stage\/prod:'<\/span> ENV\r\n\r\n<span class=\"c\"># \u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883 or \u672c\u756a\u74b0\u5883\u306e\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u3092\u8a2d\u5b9a<\/span>\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'stage'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span><span class=\"nb\">export <\/span><span class=\"nv\">PS1<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"se\">\\[\\e<\/span><span class=\"s2\">[1;36m<\/span><span class=\"se\">\\]<\/span><span class=\"s2\">[fw-<\/span><span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span><span class=\"s2\">]<\/span><span class=\"se\">\\[\\e<\/span><span class=\"s2\">[0;39m<\/span><span class=\"se\">\\]<\/span><span class=\"k\">${<\/span><span class=\"nv\">PS1<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span>\r\n    <span class=\"nb\">export <\/span><span class=\"nv\">AWS_PROFILE<\/span><span class=\"o\">=<\/span><span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span>\r\n<span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'prod'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span><span class=\"nb\">export <\/span><span class=\"nv\">PS1<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"se\">\\[\\e<\/span><span class=\"s2\">[1;31m<\/span><span class=\"se\">\\]<\/span><span class=\"s2\">[%%% fw-<\/span><span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span><span class=\"s2\"> %%%]<\/span><span class=\"se\">\\[\\e<\/span><span class=\"s2\">[0;39m<\/span><span class=\"se\">\\]<\/span><span class=\"k\">${<\/span><span class=\"nv\">PS1<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span>\r\n    <span class=\"nb\">export <\/span><span class=\"nv\">AWS_PROFILE<\/span><span class=\"o\">=<\/span><span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span>\r\n<span class=\"k\">else\r\n    <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[stage] or [prod] \u306e\u3069\u3061\u3089\u304b\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n<span class=\"k\">fi\r\n\r\n<\/span><span class=\"nb\">set<\/span> +eu\r\n<\/code><\/pre>\n<p>\u8bf4\u660e\uff1a\u7528\u4e8e\u5728\u6267\u884cterraform\u547d\u4ee4\u65f6\u8bbe\u7f6eAWS\u51ed\u8bc1\u4fe1\u606f\u7684sh\u6587\u4ef6\u3002<\/p>\n<h2>\u2172. \u6b65\u9aa40.sh<\/h2>\n<pre class=\"post-pre\"><code><span class=\"nb\">set<\/span> <span class=\"nt\">-eu<\/span>\r\n\r\ncreate_bucket <span class=\"o\">()<\/span> <span class=\"o\">{<\/span>\r\n    <span class=\"c\"># step1\u306eTerraform\u72b6\u614b\u7ba1\u7406S3\u30d0\u30b1\u30c3\u30c8\u4f5c\u6210<\/span>\r\n    <span class=\"nb\">echo<\/span> <span class=\"s1\">'step1\u306eTerraform\u72b6\u614b\u7ba1\u7406S3\u30d0\u30b1\u30c3\u30c8\u4f5c\u6210\u4e2d...'<\/span>\r\n    aws s3api create-bucket <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-step1<\/span> <span class=\"nt\">--create-bucket-configuration<\/span> <span class=\"nv\">LocationConstraint<\/span><span class=\"o\">=<\/span>ap-northeast-1\r\n    aws s3api put-bucket-versioning <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-step1<\/span> <span class=\"nt\">--versioning-configuration<\/span> <span class=\"nv\">Status<\/span><span class=\"o\">=<\/span>Enabled\r\n    aws s3api put-bucket-encryption <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-step1<\/span> <span class=\"nt\">--server-side-encryption-configuration<\/span> <span class=\"s1\">'{\"Rules\": [{\"ApplyServerSideEncryptionByDefault\": {\"SSEAlgorithm\": \"AES256\"}}]}'<\/span>\r\n    aws s3api put-public-access-block <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-step1<\/span> <span class=\"nt\">--public-access-block-configuration<\/span> <span class=\"s1\">'{\"BlockPublicAcls\": true, \"IgnorePublicAcls\": true, \"BlockPublicPolicy\": true, \"RestrictPublicBuckets\": true}'<\/span>\r\n\r\n    <span class=\"c\"># operation\u306eTerraform\u72b6\u614b\u7ba1\u7406S3\u30d0\u30b1\u30c3\u30c8\u4f5c\u6210<\/span>\r\n    <span class=\"nb\">echo<\/span> <span class=\"s1\">'operation\u306eTerraform\u72b6\u614b\u7ba1\u7406S3\u30d0\u30b1\u30c3\u30c8\u4f5c\u6210\u4e2d...'<\/span>\r\n    aws s3api create-bucket <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-operation<\/span> <span class=\"nt\">--create-bucket-configuration<\/span> <span class=\"nv\">LocationConstraint<\/span><span class=\"o\">=<\/span>ap-northeast-1\r\n    aws s3api put-bucket-versioning <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-operation<\/span> <span class=\"nt\">--versioning-configuration<\/span> <span class=\"nv\">Status<\/span><span class=\"o\">=<\/span>Enabled\r\n    aws s3api put-bucket-encryption <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-operation<\/span> <span class=\"nt\">--server-side-encryption-configuration<\/span> <span class=\"s1\">'{\"Rules\": [{\"ApplyServerSideEncryptionByDefault\": {\"SSEAlgorithm\": \"AES256\"}}]}'<\/span>\r\n    aws s3api put-public-access-block <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-operation<\/span> <span class=\"nt\">--public-access-block-configuration<\/span> <span class=\"s1\">'{\"BlockPublicAcls\": true, \"IgnorePublicAcls\": true, \"BlockPublicPolicy\": true, \"RestrictPublicBuckets\": true}'<\/span>\r\n\r\n    <span class=\"c\"># step2\u306eTerraform\u72b6\u614b\u7ba1\u7406S3\u30d0\u30b1\u30c3\u30c8\u4f5c\u6210<\/span>\r\n    <span class=\"nb\">echo<\/span> <span class=\"s1\">'step2\u306eTerraform\u72b6\u614b\u7ba1\u7406S3\u30d0\u30b1\u30c3\u30c8\u4f5c\u6210\u4e2d...'<\/span>\r\n    aws s3api create-bucket <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-step2<\/span> <span class=\"nt\">--create-bucket-configuration<\/span> <span class=\"nv\">LocationConstraint<\/span><span class=\"o\">=<\/span>ap-northeast-1\r\n    aws s3api put-bucket-versioning <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-step2<\/span> <span class=\"nt\">--versioning-configuration<\/span> <span class=\"nv\">Status<\/span><span class=\"o\">=<\/span>Enabled\r\n    aws s3api put-bucket-encryption <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-step2<\/span> <span class=\"nt\">--server-side-encryption-configuration<\/span> <span class=\"s1\">'{\"Rules\": [{\"ApplyServerSideEncryptionByDefault\": {\"SSEAlgorithm\": \"AES256\"}}]}'<\/span>\r\n    aws s3api put-public-access-block <span class=\"nt\">--bucket<\/span> <span class=\"k\">******<\/span><span class=\"o\">(<\/span>\u30a2\u30d7\u30ea\u540d\u306a\u3069<span class=\"o\">)<\/span>-<span class=\"k\">${<\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"k\">}<\/span><span class=\"nt\">-tfstate-step2<\/span> <span class=\"nt\">--public-access-block-configuration<\/span> <span class=\"s1\">'{\"BlockPublicAcls\": true, \"IgnorePublicAcls\": true, \"BlockPublicPolicy\": true, \"RestrictPublicBuckets\": true}'<\/span>\r\n<span class=\"o\">}<\/span>\r\n\r\n<span class=\"c\"># \u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883 or \u672c\u756a\u74b0\u5883\u3067S3\u30d0\u30b1\u30c3\u30c8\u306e\u540d\u524d\u3092\u5207\u308a\u66ff\u3048\u308b<\/span>\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">AWS_PROFILE<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-stage'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span><span class=\"nb\">export <\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"o\">=<\/span>stage\r\n    create_bucket\r\n    <span class=\"nb\">echo<\/span> <span class=\"s1\">'----- \u5168S3\u30d0\u30b1\u30c3\u30c8\u4f5c\u6210\u5b8c\u4e86 -----'<\/span>\r\n<span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">AWS_PROFILE<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-prod'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span><span class=\"nb\">export <\/span><span class=\"nv\">S3_BUCKET_ENV<\/span><span class=\"o\">=<\/span>prod\r\n    create_bucket\r\n    <span class=\"nb\">echo<\/span> <span class=\"s1\">'----- \u5168S3\u30d0\u30b1\u30c3\u30c8\u4f5c\u6210\u5b8c\u4e86 -----'<\/span>\r\n<span class=\"k\">else\r\n    <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[source set_aws_profile.sh] \u3092\u5b9f\u884c\u3057\u3001\u30c7\u30d7\u30ed\u30a4\u5148\u3092\u6307\u5b9a\u3057\u3066\u4e0b\u3055\u3044\u3002'<\/span>\r\n<span class=\"k\">fi\r\n\r\n<\/span><span class=\"nb\">set<\/span> +eu\r\n<\/code><\/pre>\n<p>\u8bf4\u660e\uff1a\u521b\u5efa\u7528\u4e8e\u5b58\u50a8Terraform\u72b6\u6001\u7ba1\u7406\u6587\u4ef6\u7684S3\u5b58\u50a8\u6876\u7684sh\u811a\u672c\u3002<\/p>\n<h2>\u2173. \u4ece\u4e3b\u5206\u652f\u4e2d\u6311\u9009\u8fdb\u884cgit cherry-pick\u7684\u811a\u672c<\/h2>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/bash<\/span>\r\n<span class=\"nb\">set<\/span> <span class=\"nt\">-eu<\/span>\r\n\r\n<span class=\"nb\">echo<\/span> <span class=\"s1\">'master\u30d6\u30e9\u30f3\u30c1\u3067\u30b3\u30df\u30c3\u30c8\u3092\u3057\u3066\u3044\u307e\u3059\u304b\uff1f'<\/span>\r\n<span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'ex) y\/n:'<\/span> YN\r\n\r\n<span class=\"c\"># master\u30d6\u30e9\u30f3\u30c1\u3067\u30b3\u30df\u30c3\u30c8\u3092\u3057\u3066\u3044\u308b\u304b\u3092\u78ba\u8a8d<\/span>\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">YN<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'y'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then<\/span>\r\n    :\r\n<span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">YN<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'n'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'master\u30d6\u30e9\u30f3\u30c1\u3067\u30b3\u30df\u30c3\u30c8\u3092\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"nb\">exit <\/span>1\r\n<span class=\"k\">else\r\n    <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[y] or [n] \u306e\u3069\u3061\u3089\u304b\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"nb\">exit <\/span>1\r\n<span class=\"k\">fi<\/span>\r\n\r\n\r\n\r\n<span class=\"c\"># master\u304b\u3089\u3001[v1.0.0\/stage, v1.0.0\/prod]\u305d\u308c\u305e\u308c\u3078\u3001HEAD_commit\u3092cherry-pick<\/span>\r\ngit checkout master\r\n<span class=\"nv\">GIT_MASTER_HEAD_COMMIT_HASH<\/span><span class=\"o\">=<\/span><span class=\"sb\">`<\/span>git rev-parse HEAD<span class=\"sb\">`<\/span>\r\n\r\ngit checkout v1.0.0\/stage\r\ngit cherry-pick <span class=\"k\">${<\/span><span class=\"nv\">GIT_MASTER_HEAD_COMMIT_HASH<\/span><span class=\"k\">}<\/span>\r\n\r\ngit checkout v1.0.0\/prod\r\ngit cherry-pick <span class=\"k\">${<\/span><span class=\"nv\">GIT_MASTER_HEAD_COMMIT_HASH<\/span><span class=\"k\">}<\/span>\r\n\r\ngit checkout master\r\n<\/code><\/pre>\n<p>\u8bf4\u660e\uff1a\u7528shell\u5c06master\u5206\u652f\u7684HEAD_commit\u9009\u62e9\u6027\u5730\u590d\u5236\u5230stage\u548cprod\u5206\u652f\u4e0a\u3002<\/p>\n<h2>\u2174. \u7530\u91ce\u5851\u9020\u5e94\u7528.sh<\/h2>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/bash<\/span>\r\n<span class=\"nb\">set<\/span> <span class=\"nt\">-eu<\/span>\r\n\r\n<span class=\"c\"># \u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883 and \u672c\u756a\u74b0\u5883\u3067Terraform apply\u30b3\u30de\u30f3\u30c9\u306e\u5b9a\u7fa9<\/span>\r\nterraform_apply_stage <span class=\"o\">()<\/span> <span class=\"o\">{<\/span>\r\n    <span class=\"nb\">cd<\/span> .\/<span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span>\r\n    terraform <span class=\"nb\">fmt\r\n    <\/span>terraform init <span class=\"nt\">-reconfigure<\/span>\r\n    terraform apply\r\n    <span class=\"nb\">cd<\/span> -\r\n<span class=\"o\">}<\/span>\r\n\r\nterraform_apply_prod <span class=\"o\">()<\/span> <span class=\"o\">{<\/span>\r\n    <span class=\"nb\">cd<\/span> .\/<span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span>\r\n    terraform <span class=\"nb\">fmt\r\n    <\/span>terraform init <span class=\"nt\">-reconfigure<\/span> <span class=\"nt\">-backend-config<\/span><span class=\"o\">=<\/span>prod.tfbackend\r\n    terraform apply <span class=\"nt\">-var-file<\/span><span class=\"o\">=<\/span>prod.tfvars\r\n    <span class=\"nb\">cd<\/span> -\r\n<span class=\"o\">}<\/span>\r\n\r\n\r\n\r\n<span class=\"c\"># [source set_aws_profile.sh] \u3092\u5b9f\u884c\u3057\u3001\u30c7\u30d7\u30ed\u30a4\u5148\u3092\u6307\u5b9a\u3057\u3066\u3044\u308b\u304b\u78ba\u8a8d<\/span>\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">AWS_PROFILE<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-stage'<\/span> <span class=\"nt\">-o<\/span> <span class=\"k\">${<\/span><span class=\"nv\">AWS_PROFILE<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-prod'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then<\/span>\r\n    :\r\n<span class=\"k\">else\r\n    <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[source set_aws_profile.sh] \u3092\u5b9f\u884c\u3057\u3001\u30c7\u30d7\u30ed\u30a4\u5148\u3092\u6307\u5b9a\u3057\u3066\u4e0b\u3055\u3044\u3002'<\/span>\r\n    <span class=\"nb\">exit <\/span>1\r\n<span class=\"k\">fi\r\n\r\n\r\n\r\n<\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'\u30c7\u30d7\u30ed\u30a4\u5148\uff1a\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883 or \u672c\u756a\u74b0\u5883\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n<span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'ex) stage\/prod:'<\/span> ENV\r\n\r\n<span class=\"c\"># \u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883 or \u672c\u756a\u74b0\u5883\u3067Terraform apply\u30b3\u30de\u30f3\u30c9\u3092\u5207\u308a\u66ff\u3048\u308b<\/span>\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'stage'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span>git checkout v1.0.0\/<span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span>\r\n    <span class=\"nb\">echo<\/span> <span class=\"s1\">'AWS\u30ea\u30bd\u30fc\u30b9\u69cb\u7bc9\uff1astep1 or operation or step2\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'ex) step1\/operation\/step2:'<\/span> DEPLOY\r\n\r\n    <span class=\"c\"># step1 \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'step1'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_apply_stage\r\n\r\n    <span class=\"c\"># operation \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'operation'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_apply_stage\r\n\r\n    <span class=\"c\"># step2 \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'step2'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_apply_stage\r\n\r\n    <span class=\"k\">else\r\n        <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[step1] or [operation] or [step2] \u306e\u3044\u305a\u308c\u304b\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"k\">fi\r\n\r\n\r\nelif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'prod'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span>git checkout v1.0.0\/<span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span>\r\n    <span class=\"nb\">echo<\/span> <span class=\"s1\">'AWS\u30ea\u30bd\u30fc\u30b9\u69cb\u7bc9\uff1astep1 or operation or step2\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'ex) step1\/operation\/step2:'<\/span> DEPLOY\r\n\r\n    <span class=\"c\"># step1 \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'step1'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_apply_prod\r\n\r\n    <span class=\"c\"># operation \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'operation'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_apply_prod\r\n\r\n    <span class=\"c\"># step2 \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'step2'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_apply_prod\r\n\r\n    <span class=\"k\">else\r\n        <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[step1] or [operation] or [step2] \u306e\u3044\u305a\u308c\u304b\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"k\">fi\r\n\r\nelse\r\n    <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[stage] or [prod] \u306e\u3069\u3061\u3089\u304b\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n<span class=\"k\">fi<\/span>\r\n<\/code><\/pre>\n<p>\u8bf4\u660e\uff1a[terraform apply] \u547d\u4ee4\u662f\u7528\u4e8e\u5728\u4e0d\u540c\u7684\u5206\u671f\u73af\u5883\u548c\u751f\u4ea7\u73af\u5883\u4e2d\u8fdb\u884c\u533a\u5206\u4f7f\u7528\u7684sh\u3002<\/p>\n<h2>\u2175. \u6709\u5f62\u5730\u6bc1\u706d\u811a\u672c<\/h2>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/bash<\/span>\r\n<span class=\"nb\">set<\/span> <span class=\"nt\">-eu<\/span>\r\n\r\n<span class=\"c\"># \u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883 and \u672c\u756a\u74b0\u5883\u3067Terraform destroy\u30b3\u30de\u30f3\u30c9\u306e\u5b9a\u7fa9<\/span>\r\nterraform_destroy_stage <span class=\"o\">()<\/span> <span class=\"o\">{<\/span>\r\n    <span class=\"nb\">cd<\/span> .\/<span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span>\r\n    terraform <span class=\"nb\">fmt\r\n    <\/span>terraform init <span class=\"nt\">-reconfigure<\/span>\r\n    terraform destroy\r\n    <span class=\"nb\">cd<\/span> -\r\n<span class=\"o\">}<\/span>\r\n\r\nterraform_destroy_prod <span class=\"o\">()<\/span> <span class=\"o\">{<\/span>\r\n    <span class=\"nb\">cd<\/span> .\/<span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span>\r\n    terraform <span class=\"nb\">fmt\r\n    <\/span>terraform init <span class=\"nt\">-reconfigure<\/span> <span class=\"nt\">-backend-config<\/span><span class=\"o\">=<\/span>prod.tfbackend\r\n    terraform destroy <span class=\"nt\">-var-file<\/span><span class=\"o\">=<\/span>prod.tfvars\r\n    <span class=\"nb\">cd<\/span> -\r\n<span class=\"o\">}<\/span>\r\n\r\n\r\n\r\n<span class=\"c\"># [source set_aws_profile.sh] \u3092\u5b9f\u884c\u3057\u3001\u30c7\u30d7\u30ed\u30a4\u5148\u3092\u6307\u5b9a\u3057\u3066\u3044\u308b\u304b\u78ba\u8a8d<\/span>\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">AWS_PROFILE<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-stage'<\/span> <span class=\"nt\">-o<\/span> <span class=\"k\">${<\/span><span class=\"nv\">AWS_PROFILE<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-prod'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then<\/span>\r\n    :\r\n<span class=\"k\">else\r\n    <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[source set_aws_profile.sh] \u3092\u5b9f\u884c\u3057\u3001\u30c7\u30d7\u30ed\u30a4\u5148\u3092\u6307\u5b9a\u3057\u3066\u4e0b\u3055\u3044\u3002'<\/span>\r\n    <span class=\"nb\">exit <\/span>1\r\n<span class=\"k\">fi\r\n\r\n\r\n\r\n<\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'\u30c7\u30d7\u30ed\u30a4\u5148\uff1a\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883 or \u672c\u756a\u74b0\u5883\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n<span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'ex) stage\/prod:'<\/span> ENV\r\n\r\n<span class=\"c\"># \u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u74b0\u5883 or \u672c\u756a\u74b0\u5883\u3067Terraform destroy\u30b3\u30de\u30f3\u30c9\u3092\u5207\u308a\u66ff\u3048\u308b<\/span>\r\n<span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'stage'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span>git checkout v1.0.0\/<span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span>\r\n    <span class=\"nb\">echo<\/span> <span class=\"s1\">'AWS\u30ea\u30bd\u30fc\u30b9\u69cb\u7bc9\uff1astep1 or operation or step2\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'ex) step1\/operation\/step2:'<\/span> DEPLOY\r\n\r\n    <span class=\"c\"># step1 \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'step1'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_destroy_stage\r\n\r\n    <span class=\"c\"># operation \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'operation'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_destroy_stage\r\n\r\n    <span class=\"c\"># step2 \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'step2'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_destroy_stage\r\n\r\n    <span class=\"k\">else\r\n        <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[step1] or [operation] or [step2] \u306e\u3044\u305a\u308c\u304b\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"k\">fi\r\n\r\n\r\nelif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'prod'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n    <\/span>git checkout v1.0.0\/<span class=\"k\">${<\/span><span class=\"nv\">ENV<\/span><span class=\"k\">}<\/span>\r\n    <span class=\"nb\">echo<\/span> <span class=\"s1\">'AWS\u30ea\u30bd\u30fc\u30b9\u69cb\u7bc9\uff1astep1 or operation or step2\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'ex) step1\/operation\/step2:'<\/span> DEPLOY\r\n\r\n    <span class=\"c\"># step1 \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">if<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'step1'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_destroy_prod\r\n\r\n    <span class=\"c\"># operation \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'operation'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_destroy_prod\r\n\r\n    <span class=\"c\"># step2 \u3092\u30c7\u30d7\u30ed\u30a4<\/span>\r\n    <span class=\"k\">elif<\/span> <span class=\"o\">[<\/span> <span class=\"k\">${<\/span><span class=\"nv\">DEPLOY<\/span><span class=\"k\">}<\/span> <span class=\"o\">=<\/span> <span class=\"s1\">'step2'<\/span> <span class=\"o\">]<\/span><span class=\"p\">;<\/span> <span class=\"k\">then\r\n        <\/span>terraform_destroy_prod\r\n\r\n    <span class=\"k\">else\r\n        <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[step1] or [operation] or [step2] \u306e\u3044\u305a\u308c\u304b\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n    <span class=\"k\">fi\r\n\r\nelse\r\n    <\/span><span class=\"nb\">echo<\/span> <span class=\"s1\">'[stage] or [prod] \u306e\u3069\u3061\u3089\u304b\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n<span class=\"k\">fi<\/span>\r\n<\/code><\/pre>\n<p>\u8bf4\u660e\uff1a\u5728\u5206\u522b\u4f7f\u7528staging\u73af\u5883\u548cproduction\u73af\u5883\u4e2d\u6267\u884c[terraform destroy]\u547d\u4ee4\u7684\u7528\u9014\u7684shell\u811a\u672c\u3002<\/p>\n<h2>\u2176. ssm_parameters_setup.sh:<br \/>\nSSM\u53c2\u6570\u8bbe\u7f6e\u811a\u672c\u3002<\/h2>\n<pre class=\"post-pre\"><code><span class=\"c\">#!\/bin\/bash<\/span>\r\n<span class=\"nb\">set<\/span> <span class=\"nt\">-eu<\/span>\r\n\r\n<span class=\"nb\">echo<\/span> <span class=\"s1\">'Laravel\u306eAPP_KEY\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n<span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'APP_KEY:'<\/span> APP_KEY\r\n<span class=\"nb\">echo<\/span> <span class=\"s1\">'RDS\u306eDB\u30de\u30b9\u30bf\u30fc\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002'<\/span>\r\n<span class=\"nb\">read<\/span> <span class=\"nt\">-p<\/span> <span class=\"s1\">'DB_PASSWORD:'<\/span> DB_PASSWORD\r\n\r\n<span class=\"c\"># AWS\u30ea\u30bd\u30fc\u30b9\u306b\u9069\u7528<\/span>\r\naws ssm put-parameter <span class=\"nt\">--name<\/span> <span class=\"s1\">'\/******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)\/app\/key'<\/span> <span class=\"nt\">--type<\/span> SecureString <span class=\"nt\">--value<\/span> <span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"nv\">APP_KEY<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"nt\">--overwrite<\/span>\r\naws ssm put-parameter <span class=\"nt\">--name<\/span> <span class=\"s1\">'\/******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)\/db\/password'<\/span> <span class=\"nt\">--type<\/span> SecureString <span class=\"nt\">--value<\/span> <span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"nv\">DB_PASSWORD<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span> <span class=\"nt\">--overwrite<\/span>\r\naws rds modify-db-instance <span class=\"nt\">--db-instance-identifier<\/span> <span class=\"s1\">'******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)'<\/span> <span class=\"nt\">--master-user-password<\/span> <span class=\"s2\">\"<\/span><span class=\"k\">${<\/span><span class=\"nv\">DB_PASSWORD<\/span><span class=\"k\">}<\/span><span class=\"s2\">\"<\/span>\r\n<\/code><\/pre>\n<p>\u8bf4\u660e\uff1a\u7528\u4e8e\u624b\u52a8\u66f4\u65b0\u8d44\u6e90\u4e0a\u7684\u654f\u611f\u503c\u7684sh\u811a\u672c\u3002<\/p>\n<h2>\u6784\u5efa\u8d44\u6e90\u7ec4\u7684prod.tfbackend\u3002<\/h2>\n<pre class=\"post-pre\"><code>bucket = \"******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-prod-tfstate-step1\"\r\n<\/code><\/pre>\n<p>\u8bf4\u660e\uff1a\u7528\u4e8e\u5f15\u7528\u751f\u4ea7\u73af\u5883Terraform\u72b6\u6001\u7ba1\u7406S3\u5b58\u50a8\u6876\u7684\u6587\u4ef6\u3002<\/p>\n<h2>\u2178. \u5efa\u7acbprod.tfvars\u7684\u8d44\u6e90\u7ec4<\/h2>\n<pre class=\"post-pre\"><code>s3_bucket_env                  = \"prod\"\r\ns3_force_destroy               = false\r\nalb_enable_deletion_protection = true\r\ndb_name                        = \"******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)Prod\"\r\ndb_multi_az                    = true\r\ndb_deletion_protection         = true\r\ndb_skip_final_snapshot         = false\r\ndomain_name                    = \"&lt;test_domain_prod&gt;\"\r\ndomain_name_camera             = \"&lt;test_domain_prod_camera&gt;\"\r\ndomain_name_admin              = \"&lt;test_domain_prod_admin&gt;\"\r\necr_mutability                 = \"IMMUTABLE\"\r\n<\/code><\/pre>\n<p>\u8bf4\u660e\uff1a\u7528\u4e8e\u642d\u5efa\u751f\u4ea7\u73af\u5883\u8d44\u6e90\u7684\u53c2\u6570\u6587\u4ef6\u3002<\/p>\n<h2>\u2179.\u3000\u6784\u5efa\u8d44\u6e90\u7ec4\u7684.gitignore<\/h2>\n<pre class=\"post-pre\"><code># \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\r\n\/.terraform\/\r\n\r\n# \u30d5\u30a1\u30a4\u30eb\r\n.terraform.lock.hcl\r\n.terraform.tfstate.lock.info\r\nterraform.tfstate\r\nterraform.tfstate.backup\r\n<\/code><\/pre>\n<p>\u89e3\u91ca\uff1a\u4e3a\u4e86\u9632\u6b62terraform\u6267\u884c\u547d\u4ee4\u65f6\u81ea\u52a8\u521b\u5efa\u7684\u6587\u4ef6\u88ab\u5305\u542b\u5728\u8fdc\u7a0b\u5b58\u50a8\u5e93\u4e2d\uff0c\u8bf7\u4f7f\u7528\u4ee5\u4e0b\u6587\u4ef6\u3002<\/p>\n<h1>3. \u5173\u4e8e\u8fd0\u8425\u64cd\u4f5c\u7684\u5e94\u7528<\/h1>\n<p>\u4ee5\u4e0b\u662f\u6211\u4e3a\u4e86\u5c06Laravel\u5e94\u7528\u7a0b\u5e8f\u90e8\u7f72\u5230AWS Fargate\u800c\u521b\u5efa\u7684Terraform\u8fd0\u7ef4\u64cd\u4f5c\u7684\u4ecb\u7ecd\u3002\u4e3a\u4e86\u7b80\u5316\u64cd\u4f5c\u6b65\u9aa4\u5e76\u6700\u5927\u7a0b\u5ea6\u5730\u9632\u6b62\u4eba\u4e3a\u9519\u8bef\uff0c\u8fd9\u4e2a\u914d\u7f6e\u53d8\u5f97\u6709\u4e9b\u7b28\u62d9\u7684\u8d1f\u8d23\u4eba\u662f\u811a\u672c\u3002 \uff08\u603b\u6709\u4e00\u5929\u6211\u60f3\u81ea\u5df1\u521b\u5efa\u4e00\u4e2a\u547d\u4ee4\u884c\u5de5\u5177\uff09<\/p>\n<h2>\u5f00\u59cb\u6784\u5efaAWS\u8d44\u6e90\u4e4b\u524d<\/h2>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u672c\u30ea\u30dd\u30b8\u30c8\u30ea\u76f4\u4e0b\u3067 source set_aws_profile.sh \u3092\u5b9f\u884c\u3057<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u3053\u308c\u304b\u3089\u30c7\u30d7\u30ed\u30a4\u3059\u308b\u74b0\u5883\u3092\u6307\u5b9a\u3059\u308b\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>AWS\u30ea\u30bd\u30fc\u30b9\u306e\u69cb\u7bc9\u72b6\u614b\u3092\u7ba1\u7406\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306aS3\u30d0\u30b1\u30c3\u30c8\u3092\u4f5c\u6210\u3057\u3066\u304a\u304f\u3002<br \/>\n(\u4e0a\u8a18S3\u30d0\u30b1\u30c3\u30c8\u306e\u69cb\u7bc9\u306f\u3001\u672c\u30ea\u30dd\u30b8\u30c8\u30ea\u76f4\u4e0b\u3078\u79fb\u52d5\u3057\u3001source step0.sh )<br \/>\n\u30c6\u30b9\u30c8\u30c9\u30e1\u30a4\u30f3\u3068\u3057\u3066\u7121\u6599\u72ec\u81ea\u30c9\u30e1\u30a4\u30f3\u3092\u53d6\u5f97\u3057\u3066\u304a\u304f\u3002(https:\/\/my.freenom.com\/clientarea.php)<br \/>\n\u4ee5\u4e0b\u30b3\u30fc\u30c9\u5185\u306e\u30d1\u30e9\u30e1\u30fc\u30bf\u3092\u78ba\u8a8d\u3059\u308b\u3002<\/p>\n<p>\/step1\/variables.tf \u306e\u30c6\u30b9\u30c8\u30c9\u30e1\u30a4\u30f33\u7a2e<br \/>\n(\u540c\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u5185\u306e prod.tfvars \u3082\u8981\u5909\u66f4)<\/p>\n<p>\/step2\/prod.tfvars \u306e ecs_docker_image_tag<\/p>\n<h2>\u2171. AWS\u8d44\u6e90\u6784\u5efa\u6b65\u9aa4<\/h2>\n<p>\u8bf7\u6ce8\u610f\uff0c\u5728\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u4e4b\u540e\uff0c\u4e0d\u8981\u4f7f\u7528 [Ctrl + c] \u5f3a\u5236\u7ec8\u6b62\u3002<\/p>\n<h3>Paraphrase: \u672c\u4ed3\u5e93\u4e0b<\/h3>\n<pre class=\"post-pre\"><code>bash terraform_apply.sh\r\n<\/code><\/pre>\n<h3>\u2461. AWS\u8d44\u6e90\u6784\u5efa\uff1a\u6b65\u9aa41<\/h3>\n<h3>\u786e\u8ba4\u6784\u5efa\u8d44\u6e90\u5217\u8868\uff0c\u662f\u7684\u3002<\/h3>\n<h3>\u2463. \u6d4b\u8bd5\u57df\u540d\u7684\u540d\u79f0\u670d\u52a1\u5668\u8bbe\u7f6e<\/h3>\n<p>\u5f53\u4ee5\u4e0b\u7684\u8f93\u51fa\u88ab\u91cd\u590d\u65f6\uff0c\u8bf7\u8fdb\u884c\u8bbe\u7f6e\u3002<\/p>\n<pre class=\"post-pre\"><code>module.route53_domain.aws_acm_certificate_validation.default: Still creating... [2m30s elapsed]\r\n<\/code><\/pre>\n<p>\u987a\u4fbf\u63d0\u4e00\u4e0b\uff0c\u8981\u786e\u8ba4\u6d4b\u8bd5\u57df\u540d\u7684NameServer\u8bbe\u7f6e\u662f\u5426\u6b63\u786e\uff0c\u53ef\u4ee5\u4f7f\u7528\u4ee5\u4e0bdig\u547d\u4ee4\u8fdb\u884c\u9a8c\u8bc1\uff1a<br \/>\ndig +trace \u6216\u8005<br \/>\ndig @8.8.8.8 NS\u3002<br \/>\n\uff08\u9a8c\u8bc1SSL\u8bc1\u4e66\u53ef\u80fd\u9700\u89815\u81f3100\u5206\u949f\u7684\u65f6\u95f4\u3002\uff09<\/p>\n<h3>\u2464. \u901a\u8fc7\u4ee5\u4e0b\u547d\u4ee4\uff0c\u66f4\u6539Laravel\u7684APP_KEY\u503c\u548cRDS\u7684DB\u4e3b\u5bc6\u7801\u3002<\/h3>\n<pre class=\"post-pre\"><code>bash .\/step1\/ssm_parameters_setup.sh\r\n<\/code><\/pre>\n<h3>\u5c06Docker\u955c\u50cf\u63a8\u9001\u5230ECR\u7684\u79c1\u6709\u5b58\u50a8\u5e93\u3002<\/h3>\n<h3>\u6839\u636e\u4e0a\u8ff0\u76841\u81f33\u4e2a\u6b65\u9aa4\uff0c\u8fdb\u884cAWS\u8d44\u6e90\u7684\u6784\u5efa\u64cd\u4f5c\u3002<\/h3>\n<h3>8. \u901a\u8fc7\u4ee5\u4e0b\u547d\u4ee4\u8bbf\u95ee\u64cd\u4f5c\u670d\u52a1\u5668\u7684shell<\/h3>\n<pre class=\"post-pre\"><code>aws ssm start-session <span class=\"nt\">--target<\/span> &lt;operation_instance_id&gt;\r\n<\/code><\/pre>\n<p>\u5728\u8bbf\u95eeShell\u540e\uff0c\u6267\u884c\u4ee5\u4e0b\u6b65\u9aa4\u3002<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>sudo su &#8211;<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\u6267\u884cdocker_run.sh<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\u6267\u884cphp artisan migrate<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\u6267\u884cphp artisan db:seed &#8211;class=&lt;\u4f7f\u7528\u7684\u6570\u636e\u586b\u5145\u5668&gt;<\/ol>\n<\/li>\n<\/ol>\n<p>\u6309Ctrl + D\u952e\u4e24\u6b21\uff0c\u9000\u51fa\u767b\u5f55\u3002<\/p>\n<h3>\u5728\u4e0a\u8ff0\u76841\u81f33\u6b65\u9aa4\u4e2d\uff0cAWS\u8d44\u6e90\u5efa\u7acb\uff1a\u7b2c\u4e8c\u6b65\u3002<\/h3>\n<h2>\u2172. \u6d4b\u8bd5\u57df\u540d\u53d8\u66f4\u6b65\u9aa4<\/h2>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\u5c06CNAME\u8bb0\u5f55\u6dfb\u52a0\u5230\u76ee\u6807DNS\u670d\u52a1\u4e2d\uff0c\u6dfb\u52a0\u7684\u6570\u91cf\u53d6\u51b3\u4e8e\u8981\u8fc1\u79fb\u7684\u6d4b\u8bd5\u57df\u540d\u6570\u91cf\u3002\uff08\u4f8b\u5982\uff1adomain CNAME ALBhost\uff09<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\u4f7f\u7528dig\u547d\u4ee4\u786e\u8ba4\u8bbe\u7f6e\u662f\u5426\u751f\u6548\u3002<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\u5206\u522b\u66f4\u6539ALB\u7684HTTPS\u76d1\u542c\u89c4\u5219\u7684\u4e3b\u673a\u6761\u4ef6\u3002<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\u5728\u4e1c\u4eac\u5730\u533a\uff08ap-northeast-1\uff09\u53d1\u884cSSL\u901a\u914d\u7b26\u8bc1\u4e66\u3002<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\u5c06\u751f\u6210\u7684CNAME\u8bb0\u5f55\u6dfb\u52a0\u5230\u76ee\u6807DNS\u670d\u52a1\u4e2d\uff0c\u8fd9\u662f\u5728\u53d1\u884cSSL\u8bc1\u4e66\u65f6\u751f\u6210\u7684\u3002<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\u5728SSL\u8bc1\u4e66\u9a8c\u8bc1\u5b8c\u6210\u540e\uff0c\u66f4\u6539ALB\u7684HTTPS\u76d1\u542c\u89c4\u5219\u7684\u9ed8\u8ba4SSL\u8bc1\u4e66\u3002<\/ol>\n<p>\u6d4b\u8bd5\u57df\u540d\u66f4\u6539\u540e\uff0c\u9700\u8981\u5c06\u6807\u6ce8\u4e3a\u201c\u203b\u30b3\u30e1\u30f3\u30c8\u30a2\u30a6\u30c8\u5bfe\u8c61\u201d\u7684\u4ee3\u7801\u6ce8\u91ca\u6389\uff0c\u7136\u540e\u6267\u884c bash terraform_apply.sh\uff08step1\uff09\u3002<\/p>\n<h2>\u2173. AWS\u8d44\u6e90\u9500\u6bc1\u6b65\u9aa4<\/h2>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\u5728\u8fd0\u884cterraform_destroy.sh\u4e4b\u524d\uff0c\u5148\u9500\u6bc1\u4e0eLambda\u76f8\u5173\u7684\u8d44\u6e90\u3002<\/ol>\n<\/li>\n<\/ol>\n<p>\u8fd0\u884cterraform_destroy.sh -&gt; \u6b65\u9aa42<\/p>\n<p>\u8fd0\u884cterraform_destroy.sh -&gt; \u64cd\u4f5c<\/p>\n<p>\u8fd0\u884cterraform_destroy.sh -&gt; \u6b65\u9aa41<\/p>\n<h2>\u2174. \u5173\u4e8e\u751f\u4ea7\u73af\u5883<\/h2>\n<p>\u4ee5\u4e0b\u662f\u4e0e Staging \u73af\u5883\u4e0d\u540c\u7684\u51e0\u70b9\uff1a<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">S3\u30d0\u30b1\u30c3\u30c8\u306e\u540d\u524d<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">S3\u30d0\u30b1\u30c3\u30c8\u306e\u5f37\u5236\u524a\u9664\u7121\u52b9\u5316<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ALB\u306e\u524a\u9664\u4fdd\u8b77\u6709\u52b9\u5316<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u672c\u756a\u74b0\u5883\u7528\u306eDB\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306eDB\u540d\u3092\u4f7f\u7528<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">DB\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u30de\u30eb\u30c1AZ\u6709\u52b9\u5316<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">DB\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u524a\u9664\u4fdd\u8b77\u6709\u52b9\u5316<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">DB\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u30b9\u30ca\u30c3\u30d7\u30b7\u30e7\u30c3\u30c8\u30b9\u30ad\u30c3\u30d7\u7121\u52b9\u5316<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u672c\u756a\u74b0\u5883\u7528\u306e\u30c6\u30b9\u30c8\u30c9\u30e1\u30a4\u30f3\u3092\u4f7f\u7528<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ECR\u30ea\u30dd\u30b8\u30c8\u30ea\u306e\u30bf\u30b0\u306e\u30a4\u30df\u30e5\u30fc\u30bf\u30d3\u30ea\u30c6\u30a3\u6709\u52b9\u5316<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u672c\u756a\u74b0\u5883\u7528\u306eECS\u30bf\u30b9\u30af\u5b9a\u7fa9\u3067\u4f7f\u7528\u3059\u308bDocker\u30a4\u30e1\u30fc\u30b8\u30bf\u30b0<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ECS\u30bf\u30b9\u30af\u3067\u78ba\u4fdd\u3059\u308bvCPU\u3001\u30e1\u30e2\u30ea\u5bb9\u91cfUP<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ECS\u30bf\u30b9\u30af\u306e\u5b9f\u884c\u7dad\u6301\u6570\u304c1\u21922<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">ECS\u30bf\u30b9\u30af\u306e\u5b9f\u884c\u7dad\u6301\u6570\u306e\u5909\u5316\u306b\u4f34\u3046\u3001ECS\u30b5\u30fc\u30d3\u30b9\u306e\u6700\u5c0f\/\u6700\u5927\u30d8\u30eb\u30b9\u7387\u306e\u8abf\u6574<\/ul>\n<h2>\u2175. \u5173\u4e8e\u90e8\u7f72\u5355\u4f4d<\/h2>\n<p>\u4f5c\u4e3a\u89c4\u8303\uff0c\u5c06AWS\u8d44\u6e90\u7684\u90e8\u7f72\u5355\u4f4d\u5206\u4e3a\u4ee5\u4e0b\u51e0\u4e2a\u90e8\u5206\u3002<\/p>\n<p>step1 &#8211;&gt; \u5404App\u30b5\u30fc\u30d0\u306e\u7a3c\u50cd\u306b\u5fc5\u8981\u306a\u30d9\u30fc\u30b9\u3068\u306a\u308b\u30ea\u30bd\u30fc\u30b9\u3092\u62c5\u5f53<\/p>\n<p>VPC<br \/>\nALB<br \/>\nRoute 53 (\u30c6\u30b9\u30c8\u30c9\u30e1\u30a4\u30f3\u7528)<br \/>\nRDS<br \/>\nS3<br \/>\n\u30d1\u30e9\u30e1\u30fc\u30bf\u30b9\u30c8\u30a2<br \/>\nVPC Endpoint<\/p>\n<p>operation &#8211;&gt; App\u30b5\u30fc\u30d0\u3084DB\u306e\u30e1\u30f3\u30c6\u30ca\u30f3\u30b9\u3092\u3059\u308b\u305f\u3081\u306e\u30ea\u30bd\u30fc\u30b9\u3092\u62c5\u5f53<\/p>\n<p>\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u30b5\u30fc\u30d0 (EC2)<br \/>\n\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u30ed\u30b0<br \/>\n\u30bb\u30c3\u30b7\u30e7\u30f3\u30de\u30cd\u30fc\u30b8\u30e3<br \/>\n(\u4e0a\u8a18\u30ea\u30bd\u30fc\u30b9\u306b\u5fc5\u8981\u306a) VPC Endpoint<\/p>\n<p>step2 &#8211;&gt; \u5404App\u30b5\u30fc\u30d0\u306e\u30ea\u30bd\u30fc\u30b9\u3092\u62c5\u5f53<\/p>\n<p>App\u30b5\u30fc\u30d0 (Fargate)<br \/>\nCamera\u30b5\u30fc\u30d0 (Fargate)<br \/>\nAdmin\u30b5\u30fc\u30d0 (Fargate)<\/p>\n<h2>\u2176. \u6ce8\u610f\u4e8b\u9879<\/h2>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">DB\u306e\u30e1\u30f3\u30c6\u30ca\u30f3\u30b9\u306a\u3069\u304c\u7d42\u4e86\u3057\u3001\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3\u30b5\u30fc\u30d0\u304c\u5fc5\u8981\u7121\u304f\u306a\u3063\u305f\u3089<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">bash terraform_destroy.sh -&gt; operation<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">(\u672c\u756a\u74b0\u5883\u306e\u5834\u5408\u3001\u30ed\u30b0\u7528S3\u30d0\u30b1\u30c3\u30c8\u304c\u524a\u9664\u3067\u304d\u306a\u3044\u30a8\u30e9\u30fc\u304c\u51fa\u529b\u3055\u308c\u308b\u304c\u3001\u7121\u8996\u3067OK)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u73fe\u5728\u306eAWS\u30ea\u30bd\u30fc\u30b9\u69cb\u7bc9\u72b6\u6cc1\u3092\u78ba\u8a8d\u3057\u305f\u3044\u5834\u5408\u306f<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u78ba\u8a8d\u3057\u305f\u3044\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u76f4\u4e0b\u3067 terraform show<\/ul>\n<\/li>\n<\/ul>\n<p>\u30b3\u30fc\u30c9\u7de8\u96c6\u5f8c\u306f\u3001(\u7de8\u96c6\u3057\u305f\u30d5\u30a1\u30a4\u30eb\u306e\u30ab\u30ec\u30f3\u30c8\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3067)<br \/>\nterraform fmt \u3067\u30b3\u30fc\u30c9\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3002<br \/>\n(\u30a8\u30c7\u30a3\u30bf\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u3067\u3001\u30d5\u30a1\u30a4\u30eb\u4fdd\u5b58\u6642\u306b\u81ea\u52d5\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3059\u308b\u8a2d\u5b9a\u3092\u5c0e\u5165\u3059\u308b\u306e\u304c\u30d9\u30b9\u30c8)<br \/>\nAWS\u306e\u5404\u7a2e\u30ea\u30bd\u30fc\u30b9\u306f\u3001\u4ee5\u4e0b\u306eS3\u30d0\u30b1\u30c3\u30c8\u306e terraform.tfstate \u3067<br \/>\n\u305d\u308c\u305e\u308c\u72b6\u614b\u7ba1\u7406\u3055\u308c\u3066\u3044\u308b\u3002<br \/>\n\u3053\u308c\u3089\u306e\u30d0\u30b1\u30c3\u30c8\u306f\u30d0\u30fc\u30b8\u30e7\u30cb\u30f3\u30b0\u3001\u6697\u53f7\u5316\u3001\u30d6\u30ed\u30c3\u30af\u30d1\u30d6\u30ea\u30c3\u30af\u30a2\u30af\u30bb\u30b9\u304c\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u308b\u3002<\/p>\n<p>******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-${S3_BUCKET_ENV}-tfstate-step1<br \/>\n******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-${S3_BUCKET_ENV}-tfstate-operation<br \/>\n******(\u30a2\u30d7\u30ea\u540d\u306a\u3069)-${S3_BUCKET_ENV}-tfstate-step2<\/p>\n<p>Fargate\u306e\u5404\u30b3\u30f3\u30c6\u30ca\u3078\u4ee5\u4e0b\u30b3\u30de\u30f3\u30c9\u3067\u30a2\u30af\u30bb\u30b9\u304c\u53ef\u80fd\u3002<\/p>\n<pre class=\"post-pre\"><code>aws ecs execute-command --cluster ******(\u30a2\u30d7\u30ea\u540d\u306a\u3069) --task &lt;\u30bf\u30b9\u30afNo&gt; --container &lt;\u30b3\u30f3\u30c6\u30ca\u540d&gt; --interactive --command \"\/bin\/bash\"\r\n<\/code><\/pre>\n<h1>\u53c2\u8003\u8005<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Terraform by HashiCorp<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u5b9f\u8df5Terraform\u3000AWS\u306b\u304a\u3051\u308b\u30b7\u30b9\u30c6\u30e0\u8a2d\u8a08\u3068\u30d9\u30b9\u30c8\u30d7\u30e9\u30af\u30c6\u30a3\u30b9<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Terraform\u8077\u4eba\u5165\u9580: \u65e5\u3005\u306e\u904b\u7528\u3067\u5b66\u3093\u3060\u77e5\u898b\u3092\u6de1\u3005\u3068\u307e\u3068\u3081\u308b<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">git-secrets\u306f\u3058\u3081\u307e\u3057\u305f<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u7b80\u8981\u6982\u8ff0 \u7531\u4e8e\u5728\u4e1a\u52a1\u4e2d\u6709\u673a\u4f1a\u4f7f\u7528AWS\u548cTerraform\uff0c \u56e0\u6b64\u603b\u7ed3\u4e86\u5728\u4f7f\u7528\u8fc7\u7a0b\u4e2d\u83b7\u5f97\u7684\u8fd0\u7ef4\u7ecf\u9a8c\u3002 \u53e6\u5916\uff0c\u5728 [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-48893","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684Terraform\u8fd0\u7ef4\u73af\u5883 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684terraform\u8fd0\u7ef4\u73af\u5883\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684Terraform\u8fd0\u7ef4\u73af\u5883\" \/>\n<meta property=\"og:description\" content=\"\u7b80\u8981\u6982\u8ff0 \u7531\u4e8e\u5728\u4e1a\u52a1\u4e2d\u6709\u673a\u4f1a\u4f7f\u7528AWS\u548cTerraform\uff0c \u56e0\u6b64\u603b\u7ed3\u4e86\u5728\u4f7f\u7528\u8fc7\u7a0b\u4e2d\u83b7\u5f97\u7684\u8fd0\u7ef4\u7ecf\u9a8c\u3002 \u53e6\u5916\uff0c\u5728 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684terraform\u8fd0\u7ef4\u73af\u5883\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-09-02T14:51:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-28T14:22:40+00:00\" \/>\n<meta name=\"author\" content=\"\u65b0, \u97f5\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u65b0, \u97f5\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/\",\"name\":\"\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684Terraform\u8fd0\u7ef4\u73af\u5883 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-09-02T14:51:32+00:00\",\"dateModified\":\"2024-04-28T14:22:40+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684Terraform\u8fd0\u7ef4\u73af\u5883\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9\",\"name\":\"\u65b0, \u97f5\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g\",\"caption\":\"\u65b0, \u97f5\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunxin\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684Terraform\u8fd0\u7ef4\u73af\u5883 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684terraform\u8fd0\u7ef4\u73af\u5883\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684Terraform\u8fd0\u7ef4\u73af\u5883","og_description":"\u7b80\u8981\u6982\u8ff0 \u7531\u4e8e\u5728\u4e1a\u52a1\u4e2d\u6709\u673a\u4f1a\u4f7f\u7528AWS\u548cTerraform\uff0c \u56e0\u6b64\u603b\u7ed3\u4e86\u5728\u4f7f\u7528\u8fc7\u7a0b\u4e2d\u83b7\u5f97\u7684\u8fd0\u7ef4\u7ecf\u9a8c\u3002 \u53e6\u5916\uff0c\u5728 [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684terraform\u8fd0\u7ef4\u73af\u5883\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-09-02T14:51:32+00:00","article_modified_time":"2024-04-28T14:22:40+00:00","author":"\u65b0, \u97f5","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u65b0, \u97f5","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"8 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/","name":"\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684Terraform\u8fd0\u7ef4\u73af\u5883 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-09-02T14:51:32+00:00","dateModified":"2024-04-28T14:22:40+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u642d\u5efa\u9002\u7528\u4e8e\u751f\u4ea7\u73af\u5883\u7684Terraform\u8fd0\u7ef4\u73af\u5883"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9","name":"\u65b0, \u97f5","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g","caption":"\u65b0, \u97f5"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunxin\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%90%ad%e5%bb%ba%e9%80%82%e7%94%a8%e4%ba%8e%e7%94%9f%e4%ba%a7%e7%8e%af%e5%a2%83%e7%9a%84terraform%e8%bf%90%e7%bb%b4%e7%8e%af%e5%a2%83%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/48893","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=48893"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/48893\/revisions"}],"predecessor-version":[{"id":61386,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/48893\/revisions\/61386"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=48893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=48893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=48893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}