From 2f3ee7088402d81ff809e304c1023c25f7cbf694 Mon Sep 17 00:00:00 2001 From: Andrey Chertkov Date: Fri, 6 Jul 2018 21:48:08 -0400 Subject: [PATCH 1/2] added package update instructions and code --- aws-terraform/README.md | 18 ++++++++++--- aws-terraform/op-scim.service | 22 --------------- .../data/user_data/02-environment.yml | 27 +++++++++++++++++-- 3 files changed, 39 insertions(+), 28 deletions(-) delete mode 100644 aws-terraform/op-scim.service diff --git a/aws-terraform/README.md b/aws-terraform/README.md index 0841c2a..4efda12 100644 --- a/aws-terraform/README.md +++ b/aws-terraform/README.md @@ -23,7 +23,18 @@ Init mode will guide the administrator through an interactive process which gene ## OP-SCIM Bridge -The 1Password SCIM Bridge is distributed as the Debian package and can be installed during the deployment process using the following repo configuration: `deb https://apt.agilebits.com/op-scim/ stable op-scim`. [Repo GPG key](apt.agilebits.com_repo_key.asc). +The 1Password SCIM Bridge is distributed as the Debian package and can be installed during the deployment process using the following repo configuration: `deb https://apt.agilebits.com/op-scim/ stable op-scim`. [Repo GPG key](https://apt.agilebits.com/gpg.key) can be downloaded from the same repo. +Package upgrade script is included in the instance [User Data](https://github.com/1Password/scim-examples/blob/81f66e808941a9215af3fb27b3f4351c9c8b17ff/aws-terraform/terraform/module_scim_app/data/user_data/02-environment.yml#L13) and instance cron job runs that script hourly to automatically install newer version when it is available. Automatic updates can be disabled by removing the cron job: +``` +sudo rm /etc/cron.d/50_op-scim +``` + +You can update to the later version of 1Password SCIM Bridge manually by running the following commands: +``` +sudo apt-get update +sudo apt-get install op-scim +``` + The bridge exposes a service listening on TCP port 3002. The bridge must be deployed and protected by an API gateway, proxy, or load balancer supporting TLS. The bridge service runs using unprivileged user/group credentials, and administrators should use a separate user/group for the bridge service. The bridge writes logs to STDOUT allowing collection with a syslog facility. A systemd unit is included in the package and used to manage service operation, service default environment variables can be altered in `/etc/default/op-scim`. The scimsession file and a running instance of Redis are required to start the service. By default, 'localhost' Redis server is configured. 1Password SCIM Bridge service start command example: ``` op-scim --redis-host={cache address} --redis-port={redis port} --session={/path/to/scimsession} @@ -31,8 +42,6 @@ op-scim --redis-host={cache address} --redis-port={redis port} --session={/path/ __Note:__ If the `--redis-host` and/or `--redis-port` command flags are not passed, the bridge will default to the hostname `redis`, and the port number `6379`, respectively. -A [sample](op-scim.service) is provided. - ## Logs Endpoint writes to STDOUT, thus logs can be processed in a preferred way, for example, send to a remote log collector using rsyslog. A systemd unit file configuration can be used to set a specific _SyslogIdentifier_ in order to filter service logs. @@ -58,6 +67,7 @@ TLS is not implemented on the bridge application, it is __highly__ recommended t - Optional, AWS S3 bucket for the terraform remote state. - Optional, AWS S3 bucket for Load Balancer logs. +### Steps 1. OP-SCIM session file and application binary/package are created outside of the infrastructure deployment and have to be available at the time of the deployment. 2. S3 buckets (Optional) are deployed separately prior to the rest of the infrastructure. These buckets can be used to store terraform state file, Load balancer logs and etc. @@ -90,7 +100,7 @@ _NOTE_: Application can be redeployed at any time with minimal or no downtime. F - _providers.tf_ - aws and terraform provider configuration. - _main.tf_ - invokes required modules and sets module specific variables. - _output.tf_ - prints out some of the resources and values. - - _`module_scim_app/data/user_data/03-default-users.yml`_ - user configuration, ssh username and key. + - _module\_scim\_app/data/user\_data/03-default-users.yml_ - user configuration, ssh username and key. - _new environment_ - can be created by copying an existing one to a new directory and adjusting `variables.tf`, `main.tf`, `providers.tf` as required. - _module\_scim\_app_ - deploys the following AWS resources and their dependencies: ASG, ALB, app instances (ASG), instance IAM, instance and LB security groups, public DNS record. ASG monitors instances and automatically adjusts capacity to maintain steady, predictable performance. Capacity is configured in _main.tf_ and instance specific configuration is in _variables.tf_. diff --git a/aws-terraform/op-scim.service b/aws-terraform/op-scim.service deleted file mode 100644 index 4176c2e..0000000 --- a/aws-terraform/op-scim.service +++ /dev/null @@ -1,22 +0,0 @@ -[Unit] -Description=scim endpoint -After=network.target -Wants=cloud-final.service -ConditionPathExists=/path/to/scimsession - -[Service] -Type=simple -StandardOutput=syslog -StandardError=syslog -SyslogIdentifier=scim_endpoint -TimeoutStopSec=3 -RestartSec=5 -WorkingDirectory=/path/to/op-scim -EnvironmentFile=/etc/default/op-scim -ExecStart=/path/to/op-scim/op-scim --redis-host=${REDIS} --redis-port=${REDISPORT} --session=/path/to/scimsession -Restart=always -User=scim_user -Group=scim_group - -[Install] -WantedBy=multi-user.target \ No newline at end of file diff --git a/aws-terraform/terraform/module_scim_app/data/user_data/02-environment.yml b/aws-terraform/terraform/module_scim_app/data/user_data/02-environment.yml index a262616..f863cc5 100644 --- a/aws-terraform/terraform/module_scim_app/data/user_data/02-environment.yml +++ b/aws-terraform/terraform/module_scim_app/data/user_data/02-environment.yml @@ -10,11 +10,34 @@ write_files: SCIM_SESSION_PATH="${SCIM_SESSION_PATH}" path: /etc/default/op-scim permissions: '644' + # op-scim package upgrade script: + - content: | + #!/bin/bash + export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin + export DEBIAN_FRONTEND="noninteractive" + # Check if session file exists before installing package + if [ -e "${SCIM_SESSION_PATH}" ] ; then + # Wait for lock on /var/lock/.op-scim-upgrade (fd 200) for 10 seconds + ( flock -x -w 10 200 || exit 1 + apt-get -qq update -o Dir::Etc::sourcelist="sources.list.d/op-scimrepo.list" -o Dir::Etc::sourceparts="-" -o APT::Get::List-Cleanup="0" + apt-get -qq -y install op-scim + ) 200>/var/lock/.op-scim-upgrade + fi + path: /usr/local/bin/op-scim-upgrade.sh + permissions: '0755' + owner: root:root + # op-scim package upgrade cron job, runs hourly + - content: '0 * * * * root /usr/local/bin/op-scim-upgrade.sh 2>&1 | logger -t op-scim-upgrade + + ' + path: /etc/cron.d/50_op-scim + permissions: '0644' + owner: root:root apt: preserve_sources_list: true sources: - scimrepo: + op-scimrepo: source: '${SCIM_REPO}' key: | -----BEGIN PGP PUBLIC KEY BLOCK----- @@ -86,4 +109,4 @@ runcmd: - aws secretsmanager get-secret-value --secret-id ${SCIM_SESSION_SECRET} --region ${REGION} --output text --query SecretBinary | base64 --decode > ${SCIM_SESSION_PATH} - chmod -v 600 ${SCIM_SESSION_PATH} # install op-scim - - apt-get update && apt-get -y install op-scim + - bash -vc "( flock -x -w 10 200 || exit 1 apt-get update && apt-get -y install op-scim ) 200>/var/lock/.op-scim-upgrade" From adafe84ebc44bcfe363b40f683f6d9882a2d1c91 Mon Sep 17 00:00:00 2001 From: Andrey Chertkov Date: Sat, 7 Jul 2018 19:06:40 -0400 Subject: [PATCH 2/2] added repository handling instructions --- aws-terraform/README.md | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/aws-terraform/README.md b/aws-terraform/README.md index 4efda12..8d0d3a4 100644 --- a/aws-terraform/README.md +++ b/aws-terraform/README.md @@ -23,7 +23,16 @@ Init mode will guide the administrator through an interactive process which gene ## OP-SCIM Bridge -The 1Password SCIM Bridge is distributed as the Debian package and can be installed during the deployment process using the following repo configuration: `deb https://apt.agilebits.com/op-scim/ stable op-scim`. [Repo GPG key](https://apt.agilebits.com/gpg.key) can be downloaded from the same repo. +The 1Password SCIM Bridge is distributed as a Debian package and can be installed automatically during the deployment process. You can add repository manually using the following commands: +Add [Repository GPG key](https://apt.agilebits.com/gpg.key) first: +``` +curl -sS https://apt.agilebits.com/gpg.key | sudo apt-key add - +``` +Add Repository: +``` +echo "deb https://apt.agilebits.com/op-scim/ stable op-scim" > /etc/apt/sources.list.d/op-scim.list +``` + Package upgrade script is included in the instance [User Data](https://github.com/1Password/scim-examples/blob/81f66e808941a9215af3fb27b3f4351c9c8b17ff/aws-terraform/terraform/module_scim_app/data/user_data/02-environment.yml#L13) and instance cron job runs that script hourly to automatically install newer version when it is available. Automatic updates can be disabled by removing the cron job: ``` sudo rm /etc/cron.d/50_op-scim