Merge pull request #10 from 1Password/andrey/aws-example

package update instructions and code
This commit is contained in:
Tim Sattarov
2018-07-11 17:14:38 -04:00
committed by GitHub
3 changed files with 48 additions and 28 deletions

View File

@@ -23,7 +23,27 @@ Init mode will guide the administrator through an interactive process which gene
## OP-SCIM Bridge
The 1Password SCIM Bridge is distributed as the Debian package and can be installed during the deployment process using the following repo configuration: `deb https://apt.agilebits.com/op-scim/ stable op-scim`. [Repo GPG key](apt.agilebits.com_repo_key.asc).
The 1Password SCIM Bridge is distributed as a Debian package and can be installed automatically during the deployment process. You can add repository manually using the following commands:
Add [Repository GPG key](https://apt.agilebits.com/gpg.key) first:
```
curl -sS https://apt.agilebits.com/gpg.key | sudo apt-key add -
```
Add Repository:
```
echo "deb https://apt.agilebits.com/op-scim/ stable op-scim" > /etc/apt/sources.list.d/op-scim.list
```
Package upgrade script is included in the instance [User Data](https://github.com/1Password/scim-examples/blob/81f66e808941a9215af3fb27b3f4351c9c8b17ff/aws-terraform/terraform/module_scim_app/data/user_data/02-environment.yml#L13) and instance cron job runs that script hourly to automatically install newer version when it is available. Automatic updates can be disabled by removing the cron job:
```
sudo rm /etc/cron.d/50_op-scim
```
You can update to the later version of 1Password SCIM Bridge manually by running the following commands:
```
sudo apt-get update
sudo apt-get install op-scim
```
The bridge exposes a service listening on TCP port 3002. The bridge must be deployed and protected by an API gateway, proxy, or load balancer supporting TLS. The bridge service runs using unprivileged user/group credentials, and administrators should use a separate user/group for the bridge service. The bridge writes logs to STDOUT allowing collection with a syslog facility. A systemd unit is included in the package and used to manage service operation, service default environment variables can be altered in `/etc/default/op-scim`. The scimsession file and a running instance of Redis are required to start the service. By default, 'localhost' Redis server is configured. 1Password SCIM Bridge service start command example:
```
op-scim --redis-host={cache address} --redis-port={redis port} --session={/path/to/scimsession}
@@ -31,8 +51,6 @@ op-scim --redis-host={cache address} --redis-port={redis port} --session={/path/
__Note:__ If the `--redis-host` and/or `--redis-port` command flags are not passed, the bridge will default to the hostname `redis`, and the port number `6379`, respectively.
A [sample](op-scim.service) is provided.
## Logs
Endpoint writes to STDOUT, thus logs can be processed in a preferred way, for example, send to a remote log collector using rsyslog. A systemd unit file configuration can be used to set a specific _SyslogIdentifier_ in order to filter service logs.
@@ -58,6 +76,7 @@ TLS is not implemented on the bridge application, it is __highly__ recommended t
- Optional, AWS S3 bucket for the terraform remote state.
- Optional, AWS S3 bucket for Load Balancer logs.
### Steps
1. OP-SCIM session file and application binary/package are created outside of the infrastructure deployment and have to be available at the time of the deployment.
2. S3 buckets (Optional) are deployed separately prior to the rest of the infrastructure. These buckets can be used to store terraform state file, Load balancer logs and etc.
@@ -90,7 +109,7 @@ _NOTE_: Application can be redeployed at any time with minimal or no downtime. F
- _providers.tf_ - aws and terraform provider configuration.
- _main.tf_ - invokes required modules and sets module specific variables.
- _output.tf_ - prints out some of the resources and values.
- _`module_scim_app/data/user_data/03-default-users.yml`_ - user configuration, ssh username and key.
- _module\_scim\_app/data/user\_data/03-default-users.yml_ - user configuration, ssh username and key.
- _new environment_ - can be created by copying an existing one to a new directory and adjusting `variables.tf`, `main.tf`, `providers.tf` as required.
- _module\_scim\_app_ - deploys the following AWS resources and their dependencies: ASG, ALB, app instances (ASG), instance IAM, instance and LB security groups, public DNS record. ASG monitors instances and automatically adjusts capacity to maintain steady, predictable performance. Capacity is configured in _main.tf_ and instance specific configuration is in _variables.tf_.

View File

@@ -1,22 +0,0 @@
[Unit]
Description=scim endpoint
After=network.target
Wants=cloud-final.service
ConditionPathExists=/path/to/scimsession
[Service]
Type=simple
StandardOutput=syslog
StandardError=syslog
SyslogIdentifier=scim_endpoint
TimeoutStopSec=3
RestartSec=5
WorkingDirectory=/path/to/op-scim
EnvironmentFile=/etc/default/op-scim
ExecStart=/path/to/op-scim/op-scim --redis-host=${REDIS} --redis-port=${REDISPORT} --session=/path/to/scimsession
Restart=always
User=scim_user
Group=scim_group
[Install]
WantedBy=multi-user.target

View File

@@ -10,11 +10,34 @@ write_files:
SCIM_SESSION_PATH="${SCIM_SESSION_PATH}"
path: /etc/default/op-scim
permissions: '644'
# op-scim package upgrade script:
- content: |
#!/bin/bash
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
export DEBIAN_FRONTEND="noninteractive"
# Check if session file exists before installing package
if [ -e "${SCIM_SESSION_PATH}" ] ; then
# Wait for lock on /var/lock/.op-scim-upgrade (fd 200) for 10 seconds
( flock -x -w 10 200 || exit 1
apt-get -qq update -o Dir::Etc::sourcelist="sources.list.d/op-scimrepo.list" -o Dir::Etc::sourceparts="-" -o APT::Get::List-Cleanup="0"
apt-get -qq -y install op-scim
) 200>/var/lock/.op-scim-upgrade
fi
path: /usr/local/bin/op-scim-upgrade.sh
permissions: '0755'
owner: root:root
# op-scim package upgrade cron job, runs hourly
- content: '0 * * * * root /usr/local/bin/op-scim-upgrade.sh 2>&1 | logger -t op-scim-upgrade
'
path: /etc/cron.d/50_op-scim
permissions: '0644'
owner: root:root
apt:
preserve_sources_list: true
sources:
scimrepo:
op-scimrepo:
source: '${SCIM_REPO}'
key: |
-----BEGIN PGP PUBLIC KEY BLOCK-----
@@ -86,4 +109,4 @@ runcmd:
- aws secretsmanager get-secret-value --secret-id ${SCIM_SESSION_SECRET} --region ${REGION} --output text --query SecretBinary | base64 --decode > ${SCIM_SESSION_PATH}
- chmod -v 600 ${SCIM_SESSION_PATH}
# install op-scim
- apt-get update && apt-get -y install op-scim
- bash -vc "( flock -x -w 10 200 || exit 1 apt-get update && apt-get -y install op-scim ) 200>/var/lock/.op-scim-upgrade"