-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsetup.sh
More file actions
executable file
·112 lines (94 loc) · 3.91 KB
/
Copy pathsetup.sh
File metadata and controls
executable file
·112 lines (94 loc) · 3.91 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
#!/usr/bin/env bash
#
# One-time, idempotent project-level setup for the rqlite perf rig:
# APIs, VPC + firewall, rig service account, results bucket.
# Everything here is persistent and free (or near-free) when idle;
# per-run ephemeral resources are up.sh's job.
ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
source "${ROOT_DIR}/lib/common.sh"
require_project
log "Setting up project-level resources in ${PROJECT} (region ${REGION})"
# --- APIs ---------------------------------------------------------------------
log "Enabling APIs (no-op if already enabled)..."
gcloud services enable \
compute.googleapis.com \
monitoring.googleapis.com \
logging.googleapis.com \
iap.googleapis.com \
iam.googleapis.com \
storage.googleapis.com \
telemetry.googleapis.com \
--project "${PROJECT}"
# --- Network -------------------------------------------------------------------
if ! gcloud compute networks describe "${NETWORK}" --project "${PROJECT}" &>/dev/null; then
log "Creating VPC ${NETWORK}..."
gcloud compute networks create "${NETWORK}" \
--project "${PROJECT}" --subnet-mode=custom
else
log "VPC ${NETWORK} exists."
fi
if ! gcloud compute networks subnets describe "${SUBNET}" \
--project "${PROJECT}" --region "${REGION}" &>/dev/null; then
log "Creating subnet ${SUBNET} (${SUBNET_RANGE}) in ${REGION}..."
gcloud compute networks subnets create "${SUBNET}" \
--project "${PROJECT}" --network "${NETWORK}" \
--region "${REGION}" --range "${SUBNET_RANGE}"
else
log "Subnet ${SUBNET} exists."
fi
# --- Firewall -------------------------------------------------------------------
# Rig VMs get ephemeral external IPs for image pulls (Docker Hub, ghcr), but
# nothing inbound is reachable from the internet: SSH only via IAP's range,
# rqlite and OTLP ports only from other rig VMs (tag-sourced).
create_fw_rule() {
local name="$1"
shift
if gcloud compute firewall-rules describe "${name}" --project "${PROJECT}" &>/dev/null; then
log "Firewall rule ${name} exists."
else
log "Creating firewall rule ${name}..."
gcloud compute firewall-rules create "${name}" \
--project "${PROJECT}" --network "${NETWORK}" \
--direction INGRESS --action allow "$@"
fi
}
create_fw_rule rqlite-perf-allow-iap-ssh \
--rules "tcp:22" \
--source-ranges "35.235.240.0/20" \
--target-tags "${TAG_ALL}"
create_fw_rule rqlite-perf-allow-rqlite \
--rules "tcp:${RQLITE_HTTP_PORT},tcp:${RQLITE_RAFT_PORT}" \
--source-tags "${TAG_ALL}" \
--target-tags "${TAG_NODE}"
create_fw_rule rqlite-perf-allow-otlp \
--rules "tcp:${OTLP_GRPC_PORT},tcp:4318,tcp:${GBOC_HEALTH_PORT}" \
--source-tags "${TAG_ALL}" \
--target-tags "${TAG_COLLECTOR}"
# --- Service account -------------------------------------------------------------
# Dedicated least-privilege SA for rig VMs: writes metrics (the collector's
# export path) and logs. Nothing else.
SA_EMAIL="$(sa_email)"
if ! gcloud iam service-accounts describe "${SA_EMAIL}" --project "${PROJECT}" &>/dev/null; then
log "Creating service account ${SA_EMAIL}..."
gcloud iam service-accounts create "${SA_NAME}" \
--project "${PROJECT}" --display-name "rqlite perf rig"
else
log "Service account ${SA_EMAIL} exists."
fi
for role in roles/monitoring.metricWriter roles/logging.logWriter; do
log "Granting ${role} to ${SA_EMAIL}..."
gcloud projects add-iam-policy-binding "${PROJECT}" \
--member "serviceAccount:${SA_EMAIL}" \
--role "${role}" --condition=None --quiet >/dev/null
done
# --- Results bucket ---------------------------------------------------------------
BUCKET="$(bucket_url)"
if ! gcloud storage buckets describe "${BUCKET}" --project "${PROJECT}" &>/dev/null; then
log "Creating results bucket ${BUCKET}..."
gcloud storage buckets create "${BUCKET}" \
--project "${PROJECT}" --location "${REGION}" \
--uniform-bucket-level-access
else
log "Bucket ${BUCKET} exists."
fi
log "Done. Bring up a rig with: ./up.sh --nodes 1"