Terraform 101

Reference: Terraform docs, blog.naver.com/alice_k106, [์ธํ”„๋Ÿฐ] DevOps : Infrastructure as Code with Terraform and AWS ๊ฐ•์ขŒ by ์†ก์ฃผ์˜๋‹˜

Before getting started

์ธํ”„๋Ÿฐ ๊ฐ•์ขŒ๋ฅผ ๋“ฃ๊ณ  ์ถ”๊ฐ€ํ•œ ๋‚ด์šฉ

IaC (Infrastructure as code)

  • ์ธํ”„๋ผ๋ฅผ ์ด๋ฃจ๋Š” ์„œ๋ฒ„, ๋ฏธ๋“ค์›จ์–ด, ์„œ๋น„์Šค ๋“ฑ ์ธํ”„๋ผ ๊ตฌ์„ฑ์š”์†Œ๋“ค์„ ์ฝ”๋“œ๋ฅผ ํ†ตํ•ด ๊ตฌ์ถ•ํ•˜๋Š” ๊ฒƒ

    • IaC๋Š” ์ฝ”๋“œ๋กœ์จ์˜ ์žฅ์ 

      • ์ž‘์„ฑ์šฉ์ด์„ฑ

        • ์ž‘์„ฑํ•˜๋Š” ๊ฒƒ์ด ๋นจ๋ผ์ง„๋‹ค!

      • ์žฌ์‚ฌ์šฉ์„ฑ

      • ์œ ์ง€๋ณด์ˆ˜ ๋“ฑ์˜ ์žฅ์ ์„ ๊ฐ€์ง„๋‹ค

Terraform by Hashicorp

Terraform is a tool for building, changing, and versioning infrastructure safely and efficiently

  • Terraform์€ ์ธํ”„๋ผ๋ฅผ ๋งŒ๋“ค๊ณ , ๋ณ€๊ฒฝํ•˜๊ณ  ๊ธฐ๋กํ•˜๋Š” IaC๋ฅผ ์œ„ํ•ด ๋งŒ๋“ค์–ด์ง„ ๋„๊ตฌ๋กœ์จ

    • ๋ฌธ๋ฒ•์ด ์‰ฌ์›Œ ๋น„๊ต์  ๋‹ค๋ฃจ๊ธฐ ์‰ฝ๊ณ , ์‚ฌ์šฉ์ž๊ฐ€ ๋งค์šฐ ๋งŽ์•„ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋Š” ์˜ˆ์ œ๊ฐ€ ๋งŽ๋‹ค

  • .tf ํ˜•์‹์˜ ํŒŒ์ผ ํ™•์žฅ์ž๋ฅผ ๊ฐ–๋Š”๋‹ค

  • AWS, Azure, GCP ๊ฐ™์€ Public Cloud ๋ฟ๋งŒ์ด ์•„๋‹Œ ๋‹ค์–‘ํ•œ Provider๋ฅผ ์ง€์›ํ•œ๋‹ค

Terraform ๊ธฐ๋ณธ ๊ตฌ์„ฑ ์š”์†Œ

  • provider

    • Terraform์œผ๋กœ ์ƒ์„ฑํ•  Infra์˜ ์ข…๋ฅ˜

      • Terraform ์€ ์ •๋ง ๋‹ค์–‘ํ•œ provider๋ฅผ ์ง€์›ํ•œ๋‹ค!

    • ๋ณดํ†ต provider.tf ๋กœ ํŒŒ์ผ์„ ์ƒ์„ฑํ•œ๋‹ค

    • ex)

      provider "aws" {
       region = "ap-northeast-2"
       version = "~> 3.0"
      }
      • Provider ์•ˆ์—์„œ ๋‹ค์–‘ํ•œ argument๋ฅผ ๊ฐ€์ง„๋‹ค

      • AWS resource๋ฅผ ๋‹ค๋ฃจ๊ธฐ ์œ„ํ•œ ํŒŒ์ผ๋“ค์„ ๋‹ค์šด๋กœ๋“œํ•˜๋Š” ์—ญํ• ์„ ํ•œ๋‹ค

  • resource

    • Terraform์œผ๋กœ ์‹ค์ œ๋กœ ์ƒ์„ฑํ•  ์ธํ”„๋ผ ์ž์›

    • ์›ํ•˜๋Š” ํ˜•ํƒœ๋กœ ํŒŒ์ผ ์ด๋ฆ„์„ ์‚ฌ์šฉํ•œ๋‹ค

    • ex)

      resource "aws_vpc" "example" {
       cidr_block = "10.0.0.0/16"  # cidr_block ์™ธ์—๋„ ์ˆ˜๋งŽ์€ ์ธ์ž๊ฐ€ ์กด์žฌํ•œ๋‹ค
      }
    • Terraform์œผ๋กœ VPC๋ฅผ ์ƒ์„ฑํ•˜๋Š” ์ฝ”๋“œ์ด๋‹ค

    • VPC ์—ญ์‹œ ๋‹ค์–‘ํ•œ argument์™€ ๋‹ค๋ฅธ ๊ตฌ์„ฑ์š”์†Œ๊ฐ€ ์กด์žฌํ•œ๋‹ค

  • state

    • Terrafrom์„ ํ†ตํ•ด ์ƒ์„ฑํ•œ ์ž์›์˜ ์ƒํƒœ

      • ์‹ค์ œ๋กœ Terraform ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•œ ๊ฒฐ๊ณผ๋ฌผ

      • terraform.tfstate ๋ผ๋Š” ํŒŒ์ผ๋ช…์„ ๊ฐ€์ง

        • ์‹ค์ œ๋กœ๋Š” ์ฝ”๋“œ๊ฐ€ ๊ต‰์žฅํžˆ ๊ธธ์–ด์งˆ ์ˆ˜ ์žˆ์Œ

    • ex)

      {
       "version": 4,
       "terraform_version": "0.12.24",
       "serial": 3,
       "lineage": "3c77xxxx-2de4-7736-1447-038974a3c187",
       "outputs": {},
       "resources": [
        {...},
        {...}
       ]
      }
      • Terraform์˜ state์ด๋‹ค

        • ํ˜„์žฌ ์ธํ”„๋ผ์˜ ์ƒํƒœ๋ฅผ ์˜๋ฏธํ•˜๋Š” ๊ฒƒ์€ ์•„๋‹˜!!

          • Terraform ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ด์„œ ์ƒ์„ฑํ•œ resource๋“ค์˜ ๊ฒฐ๊ณผ๋ฌผ์ด๊ณ , ์ธํ”„๋ผ์˜ ์‹ค์ œ ์ƒํƒœ๋Š” ์•„๋‹˜!!

            • ๊ทธ๋ž˜์„œ state ํŒŒ์ผ๊ณผ ํ˜„์žฌ ์ธํ”„๋ผ์˜ ์ƒํƒœ๋ฅผ ๋™์ผํ•˜๊ฒŒ ์œ ์ง€ํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•˜๋‹ค!

      • state๋Š” ์›๊ฒฉ ์ €์žฅ์†Œ์˜ backend์— ์ €์žฅ ๋  ์ˆ˜ ์žˆ๋‹ค

        • ํ˜„์žฌ ํ˜„์—…์—์„œ๋Š” ๋Œ€๋ถ€๋ถ„ backend๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค

  • output

    • Terraform์œผ๋กœ ๋งŒ๋“  ์ž์›์„ ๋ณ€์ˆ˜ ํ˜•ํƒœ๋กœ state ํŒŒ์ผ์— ์ €์žฅํ•˜๋Š” ๊ฒƒ

    • ex)

      resource "aws_vpc" "default" {
       cidr_block = "10.0.0.0/16"  # cidr_block ์™ธ์—๋„ ์ˆ˜๋งŽ์€ ์ธ์ž๊ฐ€ ์กด์žฌํ•œ๋‹ค
      }
      
      output "vpc_id" {
       value = aws_vpc.default.id
      }
      
      output "cidr_block" {
       value = aws_vpc.default.cidr_block
      }
      • vpc id ๋‚˜ cidr๊ฐ’์„ ์ฐธ์กฐํ•ด์„œ vpc_id ๋ผ๋Š” ๋ณ€์ˆ˜๋ฅผ state ํŒŒ์ผ๋กœ ์ €์žฅํ•˜๋Š” ๊ฒƒ

      • output์œผ๋กœ ์ถ”์ถœ๋œ ๋ถ€๋ถ„์€ ์ดํ›„์— remote state ๋ฅผ ํ™œ์šฉํ•ด์„œ ์žฌ์‚ฌ์šฉ ํ•  ์ˆ˜ ์žˆ๋‹ค

  • backend

    • terraform ์ƒํƒœ๋ฅผ ์ €์žฅํ•  ๊ณต๊ฐ„์„ ์ง€์ •ํ•˜๋Š” ๋ถ€๋ถ„

      • ์ƒ์„ฑ๋œ output, ์ฆ‰ variable๋กœ ์ƒ์„ฑ๋œ state file์„ ์ €์žฅํ•˜๋Š” ๊ณต๊ฐ„

    • backend๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ํ˜„์žฌ ๋ฐฐํฌ๋œ ์ตœ์‹  ์ƒํƒœ๋ฅผ ์™ธ๋ถ€์— ์ €์žฅํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๋‹ค๋ฅธ ์‚ฌ๋žŒ๊ณผ์˜ ํ˜‘์—…์ด ๊ฐ€๋Šฅํ•˜๋‹ค!

      • ๋Œ€ํ‘œ์ ์œผ๋กœ AWS S3๊ฐ€ ์žˆ๋‹ค

  • module

    • ๊ณตํ†ต์ ์œผ๋กœ ํ™œ์šฉํ•  ์ˆ˜ ์žˆ๋Š” code๋ฅผ ๋ง๊ทธ๋Œ€๋กœ module ํ˜•ํƒœ๋กœ ์ •์˜ํ•˜๋Š” ๊ฒƒ

      • ์žฌ์‚ฌ์šฉ ํ•˜๋Š”๋ฐ ๊ฐ•์ ์ด ์žˆ๋‹ค

    • ์ผ์ข…์˜ ํ•จ์ˆ˜๋ผ๊ณ  ์ƒ๊ฐํ•˜๋ฉด ํŽธํ•˜๋‹ค

      • ์—ฌ๋Ÿฌ terraform code๋ฅผ ๋ณ€์ˆ˜๋งŒ ๋ฐ”๊พธ์–ด์„œ ํ•˜๋‚˜์˜ module๋กœ ์ƒ์„ฑํ•˜๋Š” ๊ฒƒ์„ ์˜๋ฏธ

    • ex)

      module "vpc" {
       source = ":./_modulesvpc"
      
       cidr_block = "1.0.0.0/16"
      }
      • ํ•œ ๋ฒˆ ๋งŒ๋“ค์–ด์ง„ Terraform ์ฝ”๋“œ๋กœ ๊ฐ™์€ ํ˜•ํƒœ๋ฅผ ๋ฐ˜๋ณต์ ์œผ๋กœ ๋งŒ๋“ค์–ด๋‚ผ ๋•Œ ์ฃผ๋กœ ์‚ฌ์šฉ

  • remote state

    • ๋‹ค๋ฅธ ๊ฒฝ๋กœ์˜ state๋ฅผ ์ฐธ์กฐํ•˜๋Š” ๊ฒƒ

      • ์›๊ฒฉ ์ฐธ์กฐ ๊ฐœ๋…

      • output ๋ณ€์ˆ˜๋ฅผ ๋ถˆ๋Ÿฌ์˜ฌ ๋•Œ ์ฃผ๋กœ ์‚ฌ์šฉ

    • remote state๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด VPC, IAM ๋“ฑ๊ณผ ๊ฐ™์€ ๊ณต์šฉ service๋ฅผ ๋‹ค๋ฅธ service ์—์„œ ์ฐธ์กฐํ•  ์ˆ˜ ์žˆ๋‹ค

      • tfstate ํŒŒ์ผ (์ตœ์‹  terraform ์ƒํƒœ ์ •๋ณด) ์ด ์ €์žฅ๋˜์–ด ์žˆ๋Š” backend ์ •๋ณด๋ฅผ ๋ช…์‹œํ•˜๋ฉด,

        • ํ•ด๋‹น backend์—์„œ output ์ •๋ณด๋“ค์„ ๊ฐ€์ ธ์˜จ๋‹ค

    • ex)

      data "terraform_remote_state" "vpc"{
       backend = "remote"
       
       config = {
        bucket  = "terraform-s3-bucket"
      region  = "ap-northeast-2"
        key    = "terraform/vpc/terraform.tfstate"
       }
      }
      • remote state ๋Š” key ๊ฐ’์— ๋ช…์‹œํ•œ state ์—์„œ output์„ ํ†ตํ•ด ์ƒ์„ฑ๋œ ๋ณ€์ˆ˜๋ฅผ ๊ฐ€์ ธ์˜จ๋‹ค

Terraform ์ž‘๋™ ์›๋ฆฌ

  • Terraform์—๋Š” 3๊ฐ€์ง€ ํ˜•์ƒ์ด ์กด์žฌํ•œ๋‹ค

    1. Local code

      • ํ˜„์žฌ ๊ฐœ๋ฐœ์ž๊ฐ€ ์ž‘์„ฑ/์ˆ˜์ •ํ•˜๊ณ  ์žˆ๋Š” code

    2. AWS ์‹ค์ œ ์ธํ”„๋ผ

      • ์‹ค์ œ๋กœ AWS์— ๋ฐฐํฌ๋˜์–ด ์žˆ๋Š” ์ธํ”„๋ผ

    3. Backend์— ์ €์žฅ๋œ ์ƒํƒœ

      • ๊ฐ€์žฅ ์ตœ๊ทผ์— ๋ฐฐํฌํ•œ terraform code ํ˜•์ƒ

        • tfstate ํŒŒ์ผ

  • ์—ฌ๊ธฐ์„œ ๊ฐ€์žฅ ์ค‘์š”ํ•œ ๊ฒƒ์€ AWS ์‹ค์ œ ์ธํ”„๋ผ ์™€ Backend์— ์ €์žฅ๋œ ์ƒํƒœ ๊ฐ€ 100% ์ผ์น˜ํ•˜๋„๋ก ๋งŒ๋“œ๋Š” ๊ฒƒ ์ด๋‹ค!!!

    • Terraform์„ ์šด์˜ํ•˜๋ฉด์„œ ์ตœ๋Œ€ํ•œ ์ด ๋‘๊ฐ€์ง€๊ฐ€ 100% ๋™์ผํ•˜๋„๋ก ์œ ์ง€ํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•œ๋ฐ,

      • Terraform์—์„œ๋Š” ์ด๋ฅผ ์œ„ํ•ด import, state ๋“ฑ ์—ฌ๋Ÿฌ ๋ช…๋ น์–ด๋ฅผ ์ œ๊ณตํ•œ๋‹ค

  • ์ธํ”„๋ผ ์ •์˜๋Š” ๋จผ์ € Local code ์—์„œ ์‹œ์ž‘ํ•œ๋‹ค

    • ๊ฐœ๋ฐœ์ž๋Š” local์—์„œ terraform code๋ฅผ ์ •์˜ํ•œ ํ›„์—

    • ํ•ด๋‹น ์ฝ”๋“œ๋ฅผ ์‹ค์ œ ์ธํ”„๋ผ๋กœ ํ”„๋กœ๋น„์ „ํ•œ๋‹ค

      • ์ด ๋•Œ, backend๋ฅผ ๊ตฌ์„ฑํ•˜์—ฌ ์ตœ์‹  ์ฝ”๋“œ๋ฅผ ์ €์žฅํ•œ๋‹ค

Terraform ๊ธฐ๋ณธ ๋ช…๋ น์–ด

init

  • Terraform ๋ช…๋ น์–ด ์‚ฌ์šฉ์„ ์œ„ํ•œ ๊ฐ์ข… ์„ค์ •์„ ์ง„ํ–‰

    • ์ง€์ •ํ•œ backend์— ์ƒํƒœ ์ €์žฅ์„ ์œ„ํ•œ .tfstate ํŒŒ์ผ์„ ์ƒ์„ฑํ•œ๋‹ค

      • ์—ฌ๊ธฐ์—๋Š” ๊ฐ€์žฅ ๋งˆ์ง€๋ง‰์— ์ ์šฉํ•œ terraform ๋‚ด์—ญ์ด ์ €์žฅ๋œ๋‹ค

    • init ์ž‘์—…์„ ์™„๋ฃŒํ•˜๋ฉด, local์—๋Š” .tfstate ์— ์ •์˜๋œ ๋‚ด์šฉ์„ ๋‹ด์€ .terraform ํŒŒ์ผ์ด ์ƒ์„ฑ๋œ๋‹ค

    • ๊ธฐ์กด์— ๋‹ค๋ฅธ ๊ฐœ๋ฐœ์ž๊ฐ€ ์ด๋ฏธ .tfstate ์— ์ธํ”„๋ผ๋ฅผ ์ •์˜ํ•ด ๋†“์€ ๊ฒƒ์ด ์žˆ๋‹ค๋ฉด, ๋‹ค๋ฅธ ๊ฐœ๋ฐœ์ž๋Š” init ์ž‘์—…์„ ํ†ตํ•ด์„œ local์— sync๋ฅผ ๋งž์ถœ ์ˆ˜ ์žˆ๋‹ค

plan

  • Terraform์œผ๋กœ ์ž‘์„ฑํ•œ ์ฝ”๋“œ๊ฐ€ ์‹ค์ œ๋กœ ์–ด๋–ป๊ฒŒ ๋งŒ๋“ค์–ด์งˆ์ง€์— ๋Œ€ํ•œ ์˜ˆ์ธก ๊ฒฐ๊ณผ๋ฅผ ๋ณด์—ฌ์คŒ

    • ๋‹จ, plan์„ ํ•œ ๋‚ด์šฉ์— error๊ฐ€ ์—†์–ด๋„, ์‹ค์ œ ์ ์šฉ๋˜์—ˆ์„ ๋•Œ๋Š” error๊ฐ€ ๋ฐœ์ƒ ํ•  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ์œ ์˜ํ•ด์•ผ ํ•œ๋‹ค!

    • Plan ๋ช…๋ น์–ด๋Š” ์–ด๋– ํ•œ ํ˜•์ƒ์—๋„ ๋ณ€ํ™”๋ฅผ ์ฃผ์ง€ ์•Š๋Š”๋‹ค

apply

  • Terraform ์ฝ”๋“œ๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ ์‹ค์ œ๋กœ ์ธํ”„๋ผ๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๋ช…๋ น์–ด

    • apply๋ฅผ ์™„๋ฃŒํ•˜๋ฉด AWS ์ƒ์— ์‹ค์ œ๋กœ ํ•ด๋‹น ์ธํ”„๋ผ๊ฐ€ ์ƒ์„ฑ๋˜๊ณ ,

      • ์ž‘์—… ๊ฒฐ๊ณผ๊ฐ€ backend์˜ .tfstate ํŒŒ์ผ์— ์ €์žฅ๋œ๋‹ค

        • ํ•ด๋‹น ๊ฒฐ๊ณผ๋Š” local์˜ .terraform ํŒŒ์ผ์—๋„ ์ €์žฅ๋œ๋‹ค

    • ์‹ค์ œ ์ธํ”„๋ผ์— ์˜ํ–ฅ์„ ๋ผ์น˜๋Š” ๋ช…๋ น์–ด์ด๊ธฐ๋•Œ๋ฌธ์— ์ฃผ์˜๊นŠ๊ฒŒ ์‹คํ–‰ํ•ด์•ผํ•จ!

      • ๊ทธ๋ž˜์„œ apply ์ „์— ๊ผญ plan ์„ ํ•ด์•ผํ•จ!

import

  • ์ด๋ฏธ ๋งŒ๋“ค์–ด์ง„ ์ž์›์„ terraform state ํŒŒ์ผ๋กœ ์˜ฎ๊ฒจ์ฃผ๋Š” ๋ช…๋ น์–ด

    • ์ด๋ฏธ ๋งŒ๋“ค์–ด์ง„ ์ž์›์„ code๋กœ ์˜ฎ๊ธฐ๊ณ  ์‹ถ์„ ๋•Œ ์‚ฌ์šฉ

    • local์˜ .terraform ์— ํ•ด๋‹น resource์˜ ์ƒํƒœ ์ •๋ณด๋ฅผ ์ €์žฅํ•ด์ฃผ๋Š” ์—ญํ• ์„ ํ•œ๋‹ค

      • ๋‹จ, code๋ฅผ ์ƒ์„ฑํ•ด์ฃผ์ง€ ์•Š๋Š”๋‹ค!!

        • apply ์ „๊นŒ์ง€๋Š” backend์— ์ €์žฅ๋˜์ง€ ์•Š๋Š”๋‹ค

        • import ์ดํ›„์— plan ์„ ํ•˜๋ฉด local์— ํ•ด๋‹น ์ฝ”๋“œ๊ฐ€ ์—†๊ธฐ ๋•Œ๋ฌธ์— resource๊ฐ€ ์‚ญ์ œ ๋˜๋Š” ๋ณ€๊ฒฝ๋œ๋‹ค๋Š” ๊ฒฐ๊ณผ๋ฅผ ๋ณด์—ฌ์ค€๋‹ค

          • ์ด ๊ฒฐ๊ณผ๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ code๋ฅผ ์ž‘์„ฑํ•  ์ˆ˜ ์žˆ๋‹ค

    • ex)

      terraform import [options] ADDRESS ID

state

  • Terraform state๋ฅผ ๋‹ค๋ฃจ๋Š” ๋ช…๋ น์–ด

    • ์‹ค์ œ๋กœ ์ƒ์„ฑ๋œ ์ธํ”„๋ผ๋ฅผ ๋ณผ ์ˆ˜ ์žˆ๋‹ค

      • ex)

        terraform state list
    • ํ•˜์œ„ ๋ช…๋ น์–ด๋กœ mv, push ๊ฐ™์€ ๋ช…๋ น์–ด๊ฐ€ ์žˆ์Œ

destroy

  • ์ƒ์„ฑ๋œ ์ž์›๋“ค์„ state ํŒŒ์ผ ๊ธฐ์ค€์œผ๋กœ ๋ชจ๋‘ ์‚ญ์ œํ•˜๋Š” ๋ฐฉ๋ฒ•

workspace

  • workspace๋ฅผ ๊ด€๋ฆฌํ•  ๋•Œ ์“ฐ์ด๋Š” ๋ช…๋ น์–ด

    • ex1)

      $ terraform workspace list
        default
      * product
      • workspace ๋ชฉ๋ก์„ ๋ณด์—ฌ์ค€๋‹ค

      • ํ˜„์žฌ ์‚ฌ์šฉ์ค‘์ธ workspace๋Š” asterisk(*)๋กœ ํ‘œ์‹œ๋œ๋‹ค

    • ex2)

      terraform workspace select [NAME]
      • ๋‹ค๋ฅธ workspace๋กœ ์ด๋™ ํ•  ๋•Œ ์‚ฌ์šฉํ•œ๋‹ค

    • ex3)

      terraform workspace new [NAME]
      • ์ƒˆ๋กœ์šด workspace๋ฅผ ์ƒ์„ฑํ•  ๋•Œ ์‚ฌ์šฉํ•œ๋‹ค

What is Terraform?

Terraform docs์™€ ๋ธ”๋กœ๊ทธ๋ฅผ ์ฐธ๊ณ ํ•˜์—ฌ ์ •๋ฆฌํ•œ ๋‚ด์šฉ

  • Infrastructure๋ฅผ ์•ˆ์ „ํ•˜๊ณ  ํšจ์œจ์ ์œผ๋กœ ๋นŒ๋“œ, ์ˆ˜์ •ํ•˜๊ณ  versioning ํ•  ์ˆ˜ ์žˆ๋Š” tool

  • Terraform์ด Ansible ์ด๋‚˜ Chef ์™€ ๋น„์Šทํ•˜๋‹ค๊ณ  ์ƒ๊ฐํ•  ์ˆ˜ ์žˆ์œผ๋‚˜, Terraform์€ ํŠน์ • Cloud ํ™˜๊ฒฝ ์— ์ดˆ์ ์ด ๋งž์ถฐ์ ธ ์žˆ๋‹ค๋Š” ๊ฒƒ์ด ๋‹ค๋ฅด๋‹ค

    • Ansible ์€ ์ผ๋ฐ˜ ์„œ๋ฒ„, ๊ฐ€์ƒ ๋จธ์‹ , ์‹ฌ์ง€์–ด ๋ผ์ฆˆ๋ฒ ๋ฆฌํŒŒ์ด์—์„œ๋„ SSH๋ฅผ ํ†ตํ•ด ๋™์ผํ•œ ํ™˜๊ฒฝ ์„ ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐ˜๋ฉด,

    • Terraform ์€ AWS, GCP ๋“ฑ์˜ Cloud platform ์œ„์—์„œ ํ™˜๊ฒฝ์„ ๋ฐฐํฌํ•  ๋•Œ ์ฃผ๋กœ ์‚ฌ์šฉํ•œ๋‹ค

      • Code ๋กœ์„œ Infra๋ฅผ ์ •์˜ํ•œ๋‹ค๋Š” ๊ฐœ๋… ์ž์ฒด๋Š” Ansible ๊ณผ ๊ฐ™์€ ํ™˜๊ฒฝ ๋ฐฐํฌ tool๊ณผ ๋™์ผํ•˜๋ฉฐ,

      • ์ผ๋ฐ˜ Bare Metal Server ๊ฐ€ ์•„๋‹Œ ํŠน์ • Cloud Platform ์— ๋งž๋Š” ํ™˜๊ฒฝ์„ code๋กœ์„œ ๋ฐฐํฌํ•œ๋‹ค๋Š” ์ ์ด ๋‹ค๋ฅด๋‹ค

Code๋กœ์„œ Infra๋ฅผ ์ •์˜ํ•˜๊ธฐ & ์žฌํ˜„ ๊ฐ€๋Šฅํ•œ Infra

  • ํ…Œ๋ผํผ์˜ ์›นํŽ˜์ด์ง€์—์„œ ๊ฐ•์กฐํ•˜๋Š” ๊ฒƒ์ด

    • Infrastructure as a Code (์ฝ”๋“œ๋กœ์„œ ์ธํ”„๋ผ๋ฅผ ์ •์˜ํ•˜๊ธฐ)

    • Reproducible Infrastructure (์žฌํ˜„ ๊ฐ€๋Šฅํ•œ ์ธํ”„๋ผ) ์ด๋‹ค

  • AWS๋“ , GCP๋“ , Azure๋“  Cloud Infra ํ™˜๊ฒฝ์„ ์ฝ”๋“œ๋กœ์„œ ์ •์˜ํ•ด ์‚ฌ์šฉํ•จ์œผ๋กœ์จ ๋™์ผํ•œ ์ธํ”„๋ผ๋ฅผ ์žฌํ˜„ํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๋œป์ด๋‹ค

    • ๋™์ผ ํด๋ผ์šฐ๋“œ ๋‚ด์—์„œ!

  • ํด๋ผ์šฐ๋“œ ์ธํ”„๋ผ๋ฅผ ์ฝ”๋“œ๋กœ ๋ช…์‹œ์ ์œผ๋กœ ์ •์˜ํ•˜๋‹ˆ ์ˆ˜์‹ญ๋ฒˆ์„ ์‹คํ–‰ํ•ด๋„ ๋™์ผํ•œ ํ™˜๊ฒฝ์ด ์ƒ์„ฑ๋ ๊ฒƒ์ด๋‹ค.

Terraform ๋„์ž… ์‹œ workflow

  • ๋ฏธ๋ฆฌ ์ค€๋น„ํ•œ Terraform template๋“ค์„ ์‚ฌ์šฉํ•˜๋ฉด ์›ํ•˜๋Š” ํ™˜๊ฒฝ์„ cloud์— ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ๋‹ค

    • ์˜ˆ๋ฅผ๋“ค์–ด VPC๋Š” vpc.tf ๋ผ๋Š” ํŒŒ์ผ์—, EC2 instance๋Š” instance.tf ํŒŒ์ผ์—, subnet์€ subnet.tf ํŒŒ์ผ์— ์ €์žฅํ•œ ๋’ค Terraform ์„ ์‹คํ–‰์‹œํ‚ค๊ธฐ๋งŒ ํ•˜๋ฉด ๋™์ผํ•œ ํ™˜๊ฒฝ์„ cloud์—์„œ ์™„๋ฒฝํ•˜๊ฒŒ ์žฌํ˜„ํ•  ์ˆ˜ ์žˆ๋‹ค

    • ์ด๋Ÿฌํ•œ cloud ํ™˜๊ฒฝ ์„ค์ •์€ ์‚ฌ๋žŒ์ด ์ง์ ‘ ์ผ์ผ์ด ์ž‘์—…ํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ, HCL (Hashicorp Configuration Language) ๋ผ๋Š” ์–ธ์–ด๋กœ ์ž‘์„ฑ๋œ ์ฝ”๋“œ๋ฅผ Terraform์— ์ž…๋ ฅํ•จ์œผ๋กœ์จ ๊ตฌ์„ฑ๋œ๋‹ค

  • ๋ชจ๋“  cloud ์„ค์ •์€ code์— ์˜ํ•ด ๋ช…์‹œ์ ์œผ๋กœ ์ž‘์„ฑ๋˜๊ธฐ ๋•Œ๋ฌธ์— cloud infra๋ฅผ ๋™์ผํ•˜๊ฒŒ ๋ฐฐํฌํ•˜๋Š” ๊ฒƒ์ด ๊ฐ€๋Šฅํ•ด์ง„๋‹ค

  • ๋‹ค์–‘ํ•œ ์š”๊ตฌ์‚ฌํ•ญ์— ๋งž๋„๋ก ์—ฌ๋Ÿฌ version์˜ code๋ฅผ ์ž‘์„ฑํ•ด cloud infra์˜ revision ์„ ๊ด€๋ฆฌํ•  ์ˆ˜๋„ ์žˆ๋‹ค

    • ๋ฏธ๋ฆฌ ์ค€๋น„ํ•ด๋‘” Terrafrom ์„ค์ • ํŒŒ์ผ์„ Terraform์—์„œ ์‚ฌ์šฉํ•˜๊ธฐ๋งŒ ํ•˜๋ฉด ๋ณต์žกํ•œ AWS cloud ํ™˜๊ฒฝ์„ ํ•œ๊บผ๋ฒˆ์— ์ƒ์„œ์•Ÿ๊ณ  ํ•œ๊บผ๋ฒˆ์— ์‚ญ์ œํ•  ์ˆ˜๋„ ์žˆ๋‹ค

Terraform Quickstart

0. Terraform ํŒŒ์ผ์˜ ๊ตฌ์„ฑ

  • Terraform ํŒŒ์ผ์ธ .tf ํŒŒ์ผ์€ ์ผ๋ฐ˜์ ์œผ๋กœ ์•„๋ž˜์™€ ๊ฐ™์ด ๊ตฌ์„ฑ๋œ๋‹ค

  • resource

    • Terraform ํŒŒ์ผ์—์„œ ์‚ฌ์šฉ๋˜๋Š” object ์ข…๋ฅ˜

      • ๋ณ€์ˆ˜๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” resource

      • Data๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” data ๋“ฑ์ด ์žˆ๋‹ค

  • aws_key_par

    • AWS์˜ SSH key pair๋ฅผ ์œ„ํ•œ resource ์ด๋ฆ„

      • AWS์—์„œ ์‚ฌ์šฉ๋˜๋Š” object๋ฅผ terraform์—์„œ ๋ถ€๋ฅด๋Š” ์ด๋ฆ„

      • ์ด๋Ÿฌํ•œ ์ด๋ฆ„๋“ค์€ Terraform ๊ณต์‹ docs ์— ์ •๋ฆฌ๋˜์–ด ์žˆ๋‹ค

  • terraform-key

    • Terraform ํŒŒ์ผ์—์„œ ์ด object๋ฅผ ๊ณ ์œ ํ•˜๊ฒŒ ์‹๋ณ„ํ•˜๊ฒŒ ๋  ์ด๋ฆ„

      • ๊ฐ€๋Šฅํ•˜๋ฉด ๋ชจ๋“  ํŒŒ์ผ ๋‚ด์—์„œ ๊ณ ์œ ํ•œ ์ด๋ฆ„์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹๋‹ค

1. tf init

  • terraform project์˜ root์—์„œ ์‹คํ–‰ํ•œ๋‹ค

  • Terraform์„ ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” Terraform ์ดˆ๊ธฐํ™” ์ž‘์—…์ด ํ•„์š”ํ•˜๋‹ค

    • terraform init ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ด terraform directory๋ฅผ ์ดˆ๊ธฐํ™”ํ•œ๋‹ค

  • ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ

    1. ์ฒ˜์Œ ํ”„๋กœ์ ํŠธ๋ฅผ ์‹œ์ž‘ํ•œ ๊ฒฝ์šฐ

    2. module ์ด ๋ณ€๊ฒฝ๋œ ๊ฒฝ์šฐ

  • ex)

    ~/workspace/monocoque/dev-musinsa-main master* โ‡ฃ 17s
    โฏ tf init        
    Initializing modules...
    
    Initializing the backend...
    
    Initializing provider plugins...
    
    Terraform has been successfully initialized!
    
    You may now begin working with Terraform. Try running "terraform plan" to see
    any changes that are required for your infrastructure. All Terraform commands
    should now work.
    
    If you ever set or change modules or backend configuration for Terraform,
    rerun this command to reinitialize your working directory. If you forget, other
    commands will detect it and remind you to do so if necessary.

2. tf workspace

  • ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ํ•ด๋‹น ํ”„๋กœ์ ํŠธ์˜ root ๊ฒฝ๋กœ์—์„œ ์‹คํ–‰ํ•œ๋‹ค

  • Commands

    • tf workspace list

      • workspace ๋ชฉ๋ก ๋ณด๊ธฐ

        ex)

        ~/workspace/monocoque/dev-musinsa-main master* โ‡ฃ
        โฏ tf workspace list
        * default
          main
    • tf workspace select main

      • workspace ์„ ํƒํ•˜๊ธฐ

        ex)

        ~/workspace/monocoque/dev-musinsa-main master* โ‡ฃ
        โฏ tf workspace select main
        Switched to workspace "main".

3. tf plan

  • ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ํ•ด๋‹น ํ”„๋กœ์ ํŠธ์˜ root ๊ฒฝ๋กœ์—์„œ ์‹คํ–‰ํ•œ๋‹ค

  • Terraform project directory ๋‚ด์˜ ๋ชจ๋“  .tf ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ์‹ค์ œ๋กœ ์ ์šฉ ๊ฐ€๋Šฅํ•œ์ง€ ํ™•์ธํ•˜๋Š” ์ž‘์—…์„ ๊ณ„ํš ์ด๋ผ๊ณ  ํ•œ๋‹ค

  • terraform plan ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๋ฉด

    • ์–ด๋–ค resource๊ฐ€ ์ƒ์„ฑ๋˜๊ณ 

    • ์ˆ˜์ •๋˜๊ณ 

    • ์‚ญ์ œ๋ ์ง€ ๊ณ„ํš์„ ๋ณด์—ฌ์ค€๋‹ค

  • ex)

        ~/workspace/monocoque/dev-musinsa-main master*
        โฏ tf plan
        Refreshing Terraform state in-memory prior to plan...
        The refreshed state will be used to calculate this plan, but will not be
        persisted to local or remote state storage.
    
      ...
        
        Plan: 6 to add, 0 to change, 0 to destroy.
    
        ------------------------------------------------------------------------
    
        Note: You didn't specify an "-out" parameter to save this plan, so Terraform
        can't guarantee that exactly these actions will be performed if
        "terraform apply" is subsequently run.
  • ์‹คํ–‰ ๊ฒฐ๊ณผ๋ฅผ ๋ณด๊ณ , ๊ณ„ํšํ•œ ๋Œ€๋กœ ์ƒ์„ฑ๋˜๋Š” ์ง€ ํ™•์ธํ•œ๋‹ค

4. tf apply

  • ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ํ”„๋กœ์ ํŠธ root ๊ฒฝ๋กœ์—์„œ ์‹คํ–‰ํ•œ๋‹ค

  • Terraform project directory ๋‚ด์˜ ๋ชจ๋“  .tf ํŒŒ์ผ์˜ ๋‚ด์šฉ๋Œ€๋กœ resource๋ฅผ ์ƒ์„ฑ, ์ˆ˜์ •, ์‚ญ์ œ ํ•˜๋Š”์ผ์„ ์ ์šฉ์ด๋ผ๊ณ  ํ•œ๋‹ค

  • ์ด ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๊ธฐ ์ „์— ๋ณ€๊ฒฝ ์˜ˆ์ • ์‚ฌํ•ญ์€ ์œ„์˜ plan ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ด ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค

5. tf force-unlock [ID]

  • terraform state lock ๊ฑธ๋ ธ์„ ๋•Œ ์‚ฌ์šฉ

  • ์•„๋ž˜์˜ error message ์ถœ๋ ฅ ์‹œ ID ๊ฐ’์„ tf force-unlock ๋’ค์— ์ž…๋ ฅํ•œ๋‹ค

Error: Error locking state: Error acquiring the state lock: ConditionalCheckFailedException: The conditional request failed
Lock Info:
  ID:        ID ๊ฐ’
  Path:      PATH
  Operation: OperationTypePlan
  Who:       chloe@Chloes-MacBookPro.local
  Version:   0.12.26
  Created:   2021-02-05 03:26:02.065859 +0000 UTC
  Info:      


Terraform acquires a state lock to protect the state from being written
by multiple users at the same time. Please resolve the issue above and try
again. For most commands, you can disable locking with the "-lock=false"
flag, but this is not recommended.

Last updated

Was this helpful?