neulabs-cdk-constructs
Project description
Neulabs CDK Constructs
The neulabs-cdk-constructs library contains CDK-based constructs and stacks to allow the creation of cloud infrastructure on AWS.
The purpose of the library is to expose modules that can facilitate the creation and maintenance of the infrastructure as code.
Inside you will find generic stacks that allow the creation of services by simply instantiating a class, or constructs that implement logic to facilitate the developer and many other aspects.
We decided to develop it in Typescript, using projen for repository management, and the JSII library to be able to compile the neulabs-cdk-constructs package into multiple languages.
Usage
Package Installation (npm):
yarn add neulabs-cdk-constructs
# or
npm install neulabs-cdk-constructs
Package Installation (python):
pip install neulabs-cdk-constructs
Create Github OIDC
The creation of Github OIDC allows a role within workflows to be used to log in to aws. In this stack, the:
- github-oidc-workflow-role user used for authentication
- cdk-oidc-deploy-role role used for deploying
- cdk-oidc-bootsrap-role role used for bootstrap
environment = process.env.ENVIRONMENT! || 'staging';
new GithubOIDCStack(app, 'OidcStack', {
env: {
account: process.env.CDK_DEFAULT_ACCOUNT,
region: process.env.CDK_DEFAULT_REGION,
},
stage: environment,
githubUser: 'username',
githubRepository: 'repositoryName', # You can also use '*'
tokenAction: TokenActions.ALL,
cdkDeployRoleManagedPolicies: ['AdministratorAccess'],
});
Github workflow
...
# permission can be added at job level or workflow level
permissions:
id-token: write
contents: read # This is required for actions/checkout
jobs:
...
oidc:
name: Auth
runs-on: ubuntu-20.04
steps:
- name: Configure aws credentials
uses: aws-actions/configure-aws-credentials@v1
with:
role-to-assume: arn:aws:iam::{ACCOUNT ID}:role/github-oidc-workflow-role
aws-region: {REGION}
mask-aws-account-id: no
...
Create NewRelic Connection
The NewRelicStack implements the infrastructure to send metrics and logs to Newrelic through Kinesis and Cloudwatch Stream. Once deployed you can copy the ARN of the 'NewRelicInfrastructure-Integrations' role and use it to configure Newrelic.
new NewRelicStack(app, 'NewrelicStack', {
env: constants.env,
stage: constants.environment,
newRelicBucketName: `newrelic-${constants.awsAccountId}-${constants.environment}`,
newRelicAccountId: newRelicAccountId,
newRelicLicenseKey: newRelicLicenseKey,
newRelicApiUrlMetrics: EndpointUrlMetrics.EU_METRICS,
newRelicApiUrlLogs: EndpointUrlLogs.EU_LOGS,
});
Dev mode
Run in shell
npx projen default
Contributors
License
See the LICENSE
file for more information.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Hashes for neulabs-cdk-constructs-0.4.2.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | fc4dc8c855fa47f327b2f9403a678c256cdbe2fe55d94f0ac1e4a970cb9262ef |
|
MD5 | b368b83938fde9b999d77ff0a164b9d6 |
|
BLAKE2b-256 | b12cfecb734ec57c936699cb59aa0948b824ebb9a7a4add7284a69fc3222513a |
Hashes for neulabs_cdk_constructs-0.4.2-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 655e7021b06c7d85aa74d0a261c4806592400769f2ed78272b1b5a58e560dcdd |
|
MD5 | 1cc5a2503e03769002e16836a6bbb32f |
|
BLAKE2b-256 | e025a5990205d0523faaeeb2dfbe388579664cd2af623c1fc460614124f8e43f |