-
Notifications
You must be signed in to change notification settings - Fork 0
/
server.tf
75 lines (68 loc) · 1.91 KB
/
server.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
resource "digitalocean_droplet" "challenge-server" {
image = "ubuntu-20-04-x64"
name = "montrehack-h0h0h0day-2020-challenges"
region = "tor1"
ipv6 = true
vpc_uuid = digitalocean_vpc.server.id
# initial size (smallest cpu-optimized)
size = "c-2"
# production size
#size = "c-32"
resize_disk = false
ssh_keys = [data.digitalocean_ssh_key.server.fingerprint]
connection {
host = self.ipv4_address
user = "root"
type = "ssh"
agent = true
#private_key = file(var.SSH_KEY_FILE)
timeout = "2m"
}
# Wait until instance responds to SSH before triggering next actions
provisioner "remote-exec" {
inline = [
"until [ -f /var/lib/cloud/instance/boot-finished ]; do sleep 1; done",
"apt -y update"
]
}
}
resource "null_resource" "run-ansible-challenge-server" {
depends_on = [
digitalocean_droplet.challenge-server
]
provisioner "local-exec" {
command = "ANSIBLE_HOST_KEY_CHECKING=False ansible-playbook -i ansible/terraform.py ansible/server.yml"
}
triggers = {
always = timestamp()
revision = "1"
}
}
# Ansible provider for terrraform
resource "ansible_host" "challenge-server" {
count = 1
inventory_hostname = "challenge-server"
vars = {
ansible_user = "root"
ansible_host = digitalocean_droplet.challenge-server.ipv4_address
ansible_ssh_private_key_file = var.SSH_KEY_FILE
ansible_python_interpreter = "/usr/bin/python3"
}
}
# SSH keyname passed as an environment variable
variable "DO_SSH_KEY_NAME" {
type = string
}
data "digitalocean_ssh_key" "server" {
name = var.DO_SSH_KEY_NAME
}
# SSH keyfile passed as an environment variable
variable "SSH_KEY_FILE" {
type = string
}
# Section below handle creating a random vpc per droplet instance
resource "random_pet" "vpc_name" {}
resource "digitalocean_vpc" "server" {
name = "honeynet-vpc-${random_pet.vpc_name.id}"
region = "tor1"
}