Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Terraform: set witnesses per environment #118

Merged
merged 3 commits into from
Feb 28, 2024

Conversation

mhutchinson
Copy link
Contributor

With this I've removed the final use of the baked-in witnesses config. Witnesses must now be configured explicitly, either via flags or a config file.

The single witnesses.yaml file has been sharded into 3 files: one per environment. These files are the canonical description of witnesses allowed for each environment. The terraform script reads the environment-specific file and configures the flags appropriately.

This seems like a good place to leave the witness list until such time that we can resource the design and rollout of defining them in a log (or logs).

With this I've removed the final use of the baked-in witnesses config. Witnesses must now be configured explicitly, either via flags or a config file.

The single witnesses.yaml file has been sharded into 3 files: one per environment. These files are the canonical description of witnesses allowed for each environment. The terraform script reads the environment-specific file and configures the flags appropriately.

This seems like a good place to leave the witness list until such time that we can resource the design and rollout of defining them in a log (or logs).
Refactoring that moves the logic of parsing the witness file and transforming it into flags into the common file. Doing this meant I solved the problem of accessing local environment variables in the root include, which meant we could remove a second parsing of that file, and a duplicate definition of the environment. The env name now comes only from the directory name containing the leaf terragrunt file. Super nice.
@mhutchinson mhutchinson merged commit 99019c5 into transparency-dev:main Feb 28, 2024
3 checks passed
@mhutchinson mhutchinson deleted the configWitnessPerEnv branch February 28, 2024 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants