1
0
Fork 0
distrust-stack/Makefile

111 lines
2.7 KiB
Makefile
Raw Normal View History

2023-03-10 04:43:38 +00:00
include $(PWD)/src/toolchain/Makefile
2023-02-17 06:09:13 +00:00
BACKEND_TF := $(wildcard infra/backend/*.tf)
2023-04-14 03:22:35 +00:00
MAIN_TF := $(wildcard infra/main/*.tf)
2023-02-17 06:09:13 +00:00
ENVIRONMENT := production
2023-03-10 04:43:38 +00:00
REGION := sfo3
ROOT_DIR := $(shell pwd)
TERRAFORM := $(ROOT_DIR)/out/terraform
KEYS := \
6B61ECD76088748C70590D55E90A401336C8AAA9 \
88823A75ECAA786B0FF38B148E401478A3FBEF72 \
2023-03-17 03:37:07 +00:00
3D7C8D39E8C4DF771583D3F0A8A091FD346001CA
2023-02-17 06:09:13 +00:00
2023-04-14 03:47:41 +00:00
SKIP_SECRETS=
ifeq ("$(wildcard $(CACHE_DIR)/secrets/$(ENVIRONMENT).env)$(SKIP_SECRETS)","")
noop=$(shell \
$(MAKE) SKIP_SECRETS=1 $(CACHE_DIR)/secrets/$(ENVIRONMENT).env \
)
2023-04-14 03:22:35 +00:00
endif
include $(CACHE_DIR)/secrets/$(ENVIRONMENT).env
2023-04-14 03:47:41 +00:00
export $(shell sed 's/=.*//' $(CACHE_DIR)/secrets/$(ENVIRONMENT).env 2>/dev/null)
2023-04-14 03:22:35 +00:00
2023-03-10 07:43:21 +00:00
.DEFAULT_GOAL :=
.PHONY: default
default: \
toolchain \
2023-03-17 03:37:07 +00:00
$(patsubst %,$(KEY_DIR)/%.asc,$(KEYS)) \
2023-03-17 04:14:39 +00:00
$(OUT_DIR)/website/.well-known/openpgpkey \
2023-03-10 07:43:21 +00:00
apply
2023-02-17 06:09:13 +00:00
.PHONY:
clean:
rm -rf $(CACHE_DIR)
.PHONY:
credentials: \
$(CACHE_DIR)/secrets/credentials.tfvars
$(KEY_DIR)/%.asc:
$(call fetch_pgp_key,$(basename $(notdir $@)))
2023-03-17 04:14:39 +00:00
$(OUT_DIR)/website/.well-known/openpgpkey:
2023-03-17 03:37:07 +00:00
$(call toolchain," \
sq wkd \
2023-03-17 04:14:39 +00:00
generate $(OUT_DIR)/website distrust.co \
2023-03-17 03:37:07 +00:00
<(cat $(patsubst %,$(KEY_DIR)/%.asc,$(KEYS))) \
")
2023-03-10 04:43:38 +00:00
infra/backend/.terraform: \
$(OUT_DIR)/terraform \
$(BACKEND_TF)
env -C infra/backend $(TERRAFORM) init
2023-02-17 06:09:13 +00:00
2023-03-10 07:43:21 +00:00
infra/main/.terraform: \
$(OUT_DIR)/terraform \
2023-04-14 03:22:35 +00:00
config/$(ENVIRONMENT).tfbackend \
$(MAIN_TF)
2023-03-10 07:43:21 +00:00
env -C infra/main $(TERRAFORM) init \
-backend-config="../../config/$(ENVIRONMENT).tfbackend"
2023-03-10 04:43:38 +00:00
infra/backend/$(ENVIRONMENT).tfstate: \
$(OUT_DIR)/terraform \
infra/backend/.terraform
env -C infra/backend $(TERRAFORM) apply \
-var environment=$(ENVIRONMENT) \
-var namespace=$(ENVIRONMENT) \
-var region=$(REGION) \
2023-04-14 03:22:35 +00:00
-state ../../$@
2023-02-17 06:09:13 +00:00
2023-04-14 03:47:41 +00:00
config/$(ENVIRONMENT).tfbackend: \
2023-03-10 04:43:38 +00:00
$(OUT_DIR)/terraform
2023-04-14 03:47:41 +00:00
# File is not committed and this has no shared state
$(MAKE) infra/backend/$(ENVIRONMENT).tfstate
2023-03-10 07:43:21 +00:00
env -C infra/backend $(TERRAFORM) \
output -state ../../$< \
> $@
2023-02-17 06:09:13 +00:00
.PHONY:
2023-03-10 07:43:21 +00:00
apply: \
$(OUT_DIR)/terraform \
infra/main/.terraform
env -C infra/main $(TERRAFORM) apply \
2023-03-17 04:14:39 +00:00
-var environment=$(ENVIRONMENT) \
-var namespace=$(ENVIRONMENT) \
2023-04-14 03:22:35 +00:00
-var region=$(REGION)
2023-02-17 06:09:13 +00:00
$(CACHE_DIR)/secrets:
mkdir -p $@
2023-04-14 03:22:35 +00:00
$(CACHE_DIR)/secrets/%.env: secrets/%.env.gpg $(CACHE_DIR)/secrets
2023-04-14 03:47:41 +00:00
@echo "Decrypting $@"
gpg --decrypt $< 2>/dev/null > $@
2023-02-17 06:09:13 +00:00
$(FETCH_DIR)/terraform:
$(call git_clone,$@,$(TERRAFORM_REPO),$(TERRAFORM_REF))
$(OUT_DIR)/terraform: $(FETCH_DIR)/terraform
2023-03-10 05:06:33 +00:00
$(call toolchain," \
2023-02-17 06:09:13 +00:00
cd $(FETCH_DIR)/terraform && \
export SSL_CERT_DIR=/etc/ssl/certs && \
2023-03-10 03:49:01 +00:00
export CGO_ENABLED=0 && \
2023-03-10 05:06:33 +00:00
export GOCACHE=/home/build/$(CACHE_DIR) && \
export GOPATH=/home/build/$(CACHE_DIR) && \
2023-03-10 03:49:01 +00:00
go build \
-v \
-trimpath \
-ldflags='-w -extldflags=-static' \
-o /home/build/$@ \
2023-02-17 06:09:13 +00:00
")