|
| 1 | +resource "confluent_kafka_cluster" "kafka_cluster" { |
| 2 | + display_name = var.cc_default_kafka_cluster_name |
| 3 | + availability = "SINGLE_ZONE" |
| 4 | + cloud = var.cloud_provider |
| 5 | + region = var.cloud_region |
| 6 | + standard {} |
| 7 | + environment { |
| 8 | + id = confluent_environment.cc_env.id |
| 9 | + } |
| 10 | + |
| 11 | + depends_on = [confluent_environment.cc_env] |
| 12 | +} |
| 13 | + |
| 14 | +# --------------------------------------------------------------------------- |
| 15 | +# API KEY and Role for Administration of Kafka |
| 16 | +# --------------------------------------------------------------------------- |
| 17 | +resource "confluent_service_account" "kafka_manager" { |
| 18 | + display_name = "${var.cc_env_name}-kafka_manager" |
| 19 | + description = "Service account to manage Kafka cluster" |
| 20 | +} |
| 21 | + |
| 22 | +resource "confluent_role_binding" "kafka_manager_kafka_cluster_admin" { |
| 23 | + principal = "User:${confluent_service_account.kafka_manager.id}" |
| 24 | + role_name = "CloudClusterAdmin" |
| 25 | + crn_pattern = confluent_kafka_cluster.kafka_cluster.rbac_crn |
| 26 | +} |
| 27 | + |
| 28 | +resource "confluent_api_key" "kafka_manager_kafka_api_key" { |
| 29 | + display_name = "kafka_manager_kafka_api_key" |
| 30 | + description = "Kafka API Key that is owned by 'kafka_manager' service account" |
| 31 | + owner { |
| 32 | + id = confluent_service_account.kafka_manager.id |
| 33 | + api_version = confluent_service_account.kafka_manager.api_version |
| 34 | + kind = confluent_service_account.kafka_manager.kind |
| 35 | + } |
| 36 | + |
| 37 | + managed_resource { |
| 38 | + id = confluent_kafka_cluster.kafka_cluster.id |
| 39 | + api_version = confluent_kafka_cluster.kafka_cluster.api_version |
| 40 | + kind = confluent_kafka_cluster.kafka_cluster.kind |
| 41 | + |
| 42 | + environment { |
| 43 | + id = confluent_environment.cc_env.id |
| 44 | + } |
| 45 | + } |
| 46 | + |
| 47 | + depends_on = [ |
| 48 | + confluent_environment.cc_env, |
| 49 | + confluent_role_binding.kafka_manager_kafka_cluster_admin |
| 50 | + ] |
| 51 | +} |
| 52 | + |
| 53 | +# --------------------------------------------------------------------------- |
| 54 | +# API KEY and Role for Developers on Kafka |
| 55 | +# --------------------------------------------------------------------------- |
| 56 | + |
| 57 | +resource "confluent_service_account" "kafka_developer" { |
| 58 | + display_name = "${var.cc_env_name}-kafka_developer" |
| 59 | + description = "Service account for developer using Kafka cluster" |
| 60 | +} |
| 61 | + |
| 62 | +resource "confluent_role_binding" "kafka_developer_read_all_topics" { |
| 63 | + principal = "User:${confluent_service_account.kafka_manager.id}" |
| 64 | + role_name = "DeveloperRead" |
| 65 | + crn_pattern = "${confluent_kafka_cluster.kafka_cluster.rbac_crn}/kafka=${confluent_kafka_cluster.kafka_cluster.id}/topic=*" |
| 66 | +} |
| 67 | + |
| 68 | +resource "confluent_role_binding" "kafka_developer_write_all_topics" { |
| 69 | + principal = "User:${confluent_service_account.kafka_manager.id}" |
| 70 | + role_name = "DeveloperWrite" |
| 71 | + crn_pattern = "${confluent_kafka_cluster.kafka_cluster.rbac_crn}/kafka=${confluent_kafka_cluster.kafka_cluster.id}/topic=*" |
| 72 | +} |
| 73 | + |
| 74 | +resource "confluent_api_key" "kafka_developer_kafka_api_key" { |
| 75 | + display_name = "kafka_developer_kafka_api_key" |
| 76 | + description = "Kafka API Key that is owned by 'kafka_developer' service account" |
| 77 | + owner { |
| 78 | + id = confluent_service_account.kafka_developer.id |
| 79 | + api_version = confluent_service_account.kafka_developer.api_version |
| 80 | + kind = confluent_service_account.kafka_developer.kind |
| 81 | + } |
| 82 | + |
| 83 | + managed_resource { |
| 84 | + id = confluent_kafka_cluster.kafka_cluster.id |
| 85 | + api_version = confluent_kafka_cluster.kafka_cluster.api_version |
| 86 | + kind = confluent_kafka_cluster.kafka_cluster.kind |
| 87 | + |
| 88 | + environment { |
| 89 | + id = confluent_environment.cc_env.id |
| 90 | + } |
| 91 | + } |
| 92 | + |
| 93 | + depends_on = [ |
| 94 | + confluent_role_binding.kafka_developer_read_all_topics, |
| 95 | + confluent_role_binding.kafka_developer_write_all_topics |
| 96 | + ] |
| 97 | +} |
0 commit comments