Skip to content

Step 3 - Nais: terraforming the tenant

Here we describe the steps required to run through the terraform as this is not necessarily a straight forward process.

Nais-terraform-modules repository

  1. Copy an existing tenant folder to get have naas.tf and main.tf as templates.
  2. A (non-exhaustive) list of things needed:
    1. Their "nais folder ID"
    2. GitHub org name
    3. GCP org ID
    4. CIDR routing ranges per env
    5. If they want "cost viewing" (BQ) experience, a tenant_cost_viewer_group must be created by tenant
  3. Update the naas.tf and main.tf files to represent desired reality.
    • Comment out the part about internal and external load balancers, as they need to be running in the cluster first (they create the NEG in GCP).
    • To maximize profit, wait with adding domains that require manual certificates.
  4. Add the new tenant to atlantis.yaml
  5. naisd must be manually deployed with helm to each new tenant cluster before fasit will work
    • Remember to set the --version flag for the fasit helm chart

Info

This process will most likely not run on the first try, maybe not even the second try.

console.cloud.google.com -> nais-io project

While you work on applying the changes in the Terraform, when the nais-tf-<tenant> user is made, you can do the following step:

  1. Go to https://search.google.com/search-console?resource_id=sc-domain%3Adoc.<tenant>.cloud.nais.io.
  2. Log in with your Nav user (@nav.no).
  3. Add nais-tf-<tenant>@nais-io.iam.gserviceaccount.com to the new domain