home.social

#terragrunt — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #terragrunt, aggregated by home.social.

fetched live
  1. #DevOps challenge for today. Explain to my kids (#JuniorEngineers), that there is little difference between #Terraform vs #OpenTofu , and that #Terragrunt keeps shit #DRY , because some of them just dont quite "understand" why terragrunt is necessary.

    Gladly I will take input from others who would provide opinions that I can easily communicate later.

  2. #DevOps challenge for today. Explain to my kids (#JuniorEngineers), that there is little difference between #Terraform vs #OpenTofu , and that #Terragrunt keeps shit #DRY , because some of them just dont quite "understand" why terragrunt is necessary.

    Gladly I will take input from others who would provide opinions that I can easily communicate later.

  3. #DevOps challenge for today. Explain to my kids (#JuniorEngineers), that there is little difference between #Terraform vs #OpenTofu , and that #Terragrunt keeps shit #DRY , because some of them just dont quite "understand" why terragrunt is necessary.

    Gladly I will take input from others who would provide opinions that I can easily communicate later.

  4. #DevOps challenge for today. Explain to my kids (#JuniorEngineers), that there is little difference between #Terraform vs #OpenTofu , and that #Terragrunt keeps shit #DRY , because some of them just dont quite "understand" why terragrunt is necessary.

    Gladly I will take input from others who would provide opinions that I can easily communicate later.

  5. Atlantis: что пошло не так, а потом — так

    Всё началось с желания организовать и автоматизировать работу с Terraform, впоследствии с Terragrunt, выстроить управляемый процесс, централизовать, настроить понятный RBAC, в общем, сделать так, «чтобы было красиво». Было сделано несколько подходов, и были рассмотрены разные варианты. Отправной точкой стало структурирование кода, его декомпозиция и рефакторинг, и постепенно дошло до автоматизации самого процесса применения (или просто plan/apply). К этому моменту основная часть кода сконцентрировалась в монорепозитории в self-hosted GitLab, общая и повторяемая логика отделилась во внутренние приватные модули, а сам код вырос в объёмах: более 4 000 .tf файлов, не учитывая внешних и внутренних модулей, более 900 проектов (каталогов), более 30 000 ресурсов, более 30 уникальных провайдеров Terraform. Конечно, все эти условия в той или иной степени повлияли на конечный выбор. В этой статье расскажу, как мы перешли от ручного управления Terraform и Terragrunt к автоматизированному процессу на базе Atlantis, какие альтернативы рассматривали, почему выбрали именно Atlantis и с какими неочевидными особенностями столкнулись при его эксплуатации.

    habr.com/ru/articles/1073152/

    #terraform #terragrunt #atlantis #aws #devops

  6. Atlantis: что пошло не так, а потом — так

    Всё началось с желания организовать и автоматизировать работу с Terraform, впоследствии с Terragrunt, выстроить управляемый процесс, централизовать, настроить понятный RBAC, в общем, сделать так, «чтобы было красиво». Было сделано несколько подходов, и были рассмотрены разные варианты. Отправной точкой стало структурирование кода, его декомпозиция и рефакторинг, и постепенно дошло до автоматизации самого процесса применения (или просто plan/apply). К этому моменту основная часть кода сконцентрировалась в монорепозитории в self-hosted GitLab, общая и повторяемая логика отделилась во внутренние приватные модули, а сам код вырос в объёмах: более 4 000 .tf файлов, не учитывая внешних и внутренних модулей, более 900 проектов (каталогов), более 30 000 ресурсов, более 30 уникальных провайдеров Terraform. Конечно, все эти условия в той или иной степени повлияли на конечный выбор. В этой статье расскажу, как мы перешли от ручного управления Terraform и Terragrunt к автоматизированному процессу на базе Atlantis, какие альтернативы рассматривали, почему выбрали именно Atlantis и с какими неочевидными особенностями столкнулись при его эксплуатации.

    habr.com/ru/articles/1073152/

    #terraform #terragrunt #atlantis #aws #devops

  7. Today's Challenge: try to pull apart a #Cloudformation template (because #CFT sucks as an #IaC solution) and build #Terraform from it. Ive been working on this one all day. I mean, I even built #terragrunt hcls around it to deploy it DRY.

    But does anyone deal with Cloudformation in AWS accounts and actually have a good opinion about it?

    Because I can find NOTHING good about it.

  8. Today's Challenge: try to pull apart a #Cloudformation template (because #CFT sucks as an #IaC solution) and build #Terraform from it. Ive been working on this one all day. I mean, I even built #terragrunt hcls around it to deploy it DRY.

    But does anyone deal with Cloudformation in AWS accounts and actually have a good opinion about it?

    Because I can find NOTHING good about it.

  9. Today's Challenge: try to pull apart a #Cloudformation template (because #CFT sucks as an #IaC solution) and build #Terraform from it. Ive been working on this one all day. I mean, I even built #terragrunt hcls around it to deploy it DRY.

    But does anyone deal with Cloudformation in AWS accounts and actually have a good opinion about it?

    Because I can find NOTHING good about it.

  10. Today's Challenge: try to pull apart a #Cloudformation template (because #CFT sucks as an #IaC solution) and build #Terraform from it. Ive been working on this one all day. I mean, I even built #terragrunt hcls around it to deploy it DRY.

    But does anyone deal with Cloudformation in AWS accounts and actually have a good opinion about it?

    Because I can find NOTHING good about it.

  11. So my engineer (who is my problem child), admitted today that he can only work in #azure environments, and refuses to work in #aws and #gcp environments. Because he doesnt understand them, how they work, or how to build stuff in them. Despite his constant use of #claude to build #IaC #terragrunt. So console and env awareness shouldnt matter right?

    #Devops #Cloudops #Revops #FinOps #WhatTheFuckEverOps

    As everyone can guess (I am the at the bottom of the list in the pic).

  12. So my engineer (who is my problem child), admitted today that he can only work in #azure environments, and refuses to work in #aws and #gcp environments. Because he doesnt understand them, how they work, or how to build stuff in them. Despite his constant use of #claude to build #IaC #terragrunt. So console and env awareness shouldnt matter right?

    #Devops #Cloudops #Revops #FinOps #WhatTheFuckEverOps

    As everyone can guess (I am the at the bottom of the list in the pic).

  13. So my engineer (who is my problem child), admitted today that he can only work in #azure environments, and refuses to work in #aws and #gcp environments. Because he doesnt understand them, how they work, or how to build stuff in them. Despite his constant use of #claude to build #IaC #terragrunt. So console and env awareness shouldnt matter right?

    #Devops #Cloudops #Revops #FinOps #WhatTheFuckEverOps

    As everyone can guess (I am the at the bottom of the list in the pic).

  14. So my engineer (who is my problem child), admitted today that he can only work in #azure environments, and refuses to work in #aws and #gcp environments. Because he doesnt understand them, how they work, or how to build stuff in them. Despite his constant use of #claude to build #IaC #terragrunt. So console and env awareness shouldnt matter right?

    #Devops #Cloudops #Revops #FinOps #WhatTheFuckEverOps

    As everyone can guess (I am the at the bottom of the list in the pic).

  15. > Mildly complex logic constraint
    > Attempt to encode in variable constraints
    > Compiler too dumb to realize what I'm doing
    > Figure out a check resource and assertion provider
    > Terragrunt swallows the error

    Terraform, not even once

    #Terraform #Terragrunt

  16. > Mildly complex logic constraint
    > Attempt to encode in variable constraints
    > Compiler too dumb to realize what I'm doing
    > Figure out a check resource and assertion provider
    > Terragrunt swallows the error

    Terraform, not even once

    #Terraform #Terragrunt

  17. > Mildly complex logic constraint
    > Attempt to encode in variable constraints
    > Compiler too dumb to realize what I'm doing
    > Figure out a check resource and assertion provider
    > Terragrunt swallows the error

    Terraform, not even once

    #Terraform #Terragrunt

  18. > Mildly complex logic constraint
    > Attempt to encode in variable constraints
    > Compiler too dumb to realize what I'm doing
    > Figure out a check resource and assertion provider
    > Terragrunt swallows the error

    Terraform, not even once

    #Terraform #Terragrunt

  19. Ok, one more but it goes with 2. : DO NOT configure your providers in the #terraform / #opentofu code. You're shooting yourself in the foot here, let #terragrunt handle this dynamically.

  20. Ok, one more but it goes with 2. : DO NOT configure your providers in the #terraform / #opentofu code. You're shooting yourself in the foot here, let #terragrunt handle this dynamically.

  21. Ok, one more but it goes with 2. : DO NOT configure your providers in the #terraform / #opentofu code. You're shooting yourself in the foot here, let #terragrunt handle this dynamically.

  22. Ok, one more but it goes with 2. : DO NOT configure your providers in the #terraform / #opentofu code. You're shooting yourself in the foot here, let #terragrunt handle this dynamically.

  23. The more I work as a Dev Ops / Platform Eng, the more I fight a single anti-pattern.

    For your future self :
    1. Use #terragrunt and not only #terraform / #opentofu ,
    2. Centralize you #tf code in different modules in a single repository and have #tg use them ,
    3. That one goes without saying but here it is : DRY your code using locals !

    I'm tired of removing hundred lines of #IaC code just for the sake of maintainability.

  24. The more I work as a Dev Ops / Platform Eng, the more I fight a single anti-pattern.

    For your future self :
    1. Use #terragrunt and not only #terraform / #opentofu ,
    2. Centralize you #tf code in different modules in a single repository and have #tg use them ,
    3. That one goes without saying but here it is : DRY your code using locals !

    I'm tired of removing hundred lines of #IaC code just for the sake of maintainability.

  25. The more I work as a Dev Ops / Platform Eng, the more I fight a single anti-pattern.

    For your future self :
    1. Use #terragrunt and not only #terraform / #opentofu ,
    2. Centralize you #tf code in different modules in a single repository and have #tg use them ,
    3. That one goes without saying but here it is : DRY your code using locals !

    I'm tired of removing hundred lines of #IaC code just for the sake of maintainability.

  26. The more I work as a Dev Ops / Platform Eng, the more I fight a single anti-pattern.

    For your future self :
    1. Use #terragrunt and not only #terraform / #opentofu ,
    2. Centralize you #tf code in different modules in a single repository and have #tg use them ,
    3. That one goes without saying but here it is : DRY your code using locals !

    I'm tired of removing hundred lines of #IaC code just for the sake of maintainability.

  27. Any #terragrunt persons out there?

    I need a modular way to build a framework for building AWS accounts (with required services), that is DRY and repeatable.

    best I can come up with:

    ├── _example-account
    │   ├── account.hcl
    │   ├── us-east-1
    │   ├── us-east-2
    │   ├── us-west-1
    │   └── us-west-2
    ├── _templates
    │   ├── account.hcl
    │   ├── env.hcl
    │   ├── region.hcl
    │   └── service
    ├── modules
    └── terragrunt.hcl

  28. Any #terragrunt persons out there?

    I need a modular way to build a framework for building AWS accounts (with required services), that is DRY and repeatable.

    best I can come up with:

    ├── _example-account
    │   ├── account.hcl
    │   ├── us-east-1
    │   ├── us-east-2
    │   ├── us-west-1
    │   └── us-west-2
    ├── _templates
    │   ├── account.hcl
    │   ├── env.hcl
    │   ├── region.hcl
    │   └── service
    ├── modules
    └── terragrunt.hcl

  29. #devops #terraform

    When you build a #terragrunt compliant stack of modules that can be used in any case for any capacity, and your engineers still use #clickops.

    Why? oh why do they do this?

  30. #devops #terraform

    When you build a #terragrunt compliant stack of modules that can be used in any case for any capacity, and your engineers still use #clickops.

    Why? oh why do they do this?

  31. Another day another set of #terraform and #terragrunt and a little more burnout on #infosec , another day in the life

  32. Another day another set of #terraform and #terragrunt and a little more burnout on #infosec , another day in the life

  33. Here I am working today, on stupid #devops shit, when , and I am shocked to have to say this, but a Senior Architect tells me and I literally quote "Wendy, I dont understand #DNS nearly as good as you do, so can you help me understand the cadence of what goes first or second", and all I can think is, this guy is a developer and he stupidly asks me this question? how in the fuck?

    #aws #terragrunt #terraform #opentofu #git #gitproblems #gitops #wtf

  34. Here I am working today, on stupid #devops shit, when , and I am shocked to have to say this, but a Senior Architect tells me and I literally quote "Wendy, I dont understand #DNS nearly as good as you do, so can you help me understand the cadence of what goes first or second", and all I can think is, this guy is a developer and he stupidly asks me this question? how in the fuck?

    #aws #terragrunt #terraform #opentofu #git #gitproblems #gitops #wtf

  35. Am I the only person who sees no advantage in using Terragrunt over pure Terraform/OpenTofu? If anything i think it adds unnecessary complexity that you're locked in to.

    #IaC #Terragrunt #Terraform #OpenTofu #CNCF

  36. Am I the only person who sees no advantage in using Terragrunt over pure Terraform/OpenTofu? If anything i think it adds unnecessary complexity that you're locked in to.

    #IaC #Terragrunt #Terraform #OpenTofu #CNCF

  37. Am I the only person who sees no advantage in using Terragrunt over pure Terraform/OpenTofu? If anything i think it adds unnecessary complexity that you're locked in to.

    #IaC #Terragrunt #Terraform #OpenTofu #CNCF

  38. Just when I thought I was almost out of yaks (and finally installing #Airflow!), #terragrunt got confused and started demanding to create resources that already exist, which broke #openEBS, which broke... sigh ...

    Another 2 days of work later, #argocd is installed in my neurons and my cluster, and most of my config is refactored "enough". I swear we'll actually get to do some #datascience someday folks...

    Big data on a tiny budget is hard!

    #dataengineering #sre

  39. However, it looks like the catalog only works with local modules and for upstream modules you should use scaffold. #terragrunt

    terragrunt.gruntwork.io/docs/f

  40. However, it looks like the catalog only works with local modules and for upstream modules you should use scaffold. #terragrunt

    terragrunt.gruntwork.io/docs/f

  41. @arichtman *cluster api instead of #terraform and #terragrunt - tg makes it a lot nicer to work with tf, we still have to make use of the tf helm provider for a handful of things like #karpenter but outside of that the TF has been painless after the initial dev on all the modules.