Step 3 - Nais: terraforming the tenant¶
Here we describe the steps required to run through the terraform as this is not necessarily a straight forward process.
Nais-terraform-modules repository¶
- Copy an existing tenant folder to get have
naas.tfandmain.tfas templates. - A (non-exhaustive) list of things needed:
- Their "nais folder ID"
- GitHub org name
- GCP org ID
- CIDR routing ranges per env
- If they want "cost viewing" (BQ) experience, a
tenant_cost_viewer_groupmust be created by tenant
- Update the
naas.tfandmain.tffiles to represent desired reality.- Comment out the part about internal and external load balancers, as they need to be running in the cluster first (they create the NEG in GCP).
- To maximize profit, wait with adding domains that require manual certificates.
- Add the new tenant to
atlantis.yaml naisdmust be manually deployed with helm to each new tenant cluster before fasit will work- Remember to set the
--versionflag for the fasit helm chart
- Remember to set the
Info
This process will most likely not run on the first try, maybe not even the second try.
console.cloud.google.com -> nais-io project¶
While you work on applying the changes in the Terraform, when the nais-tf-<tenant> user is made, you can do the following step:
- Go to
https://search.google.com/search-console?resource_id=sc-domain%3Adoc.<tenant>.cloud.nais.io. - Log in with your Nav user (@nav.no).
- Add
nais-tf-<tenant>@nais-io.iam.gserviceaccount.comto the new domain