Skip to content

Latest commit

Β 

History

100 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

devops-terraform-buildkite-scripts

Buildkite Terraform OpenTofu Semgrep License Maintained

Security Scan State Backend Secrets Compliance

Modern Terraform infrastructure deployment pipeline using Buildkite, Clivern Lynx state backend, and comprehensive security scanning.


πŸ“‹ Table of Contents


🎯 Overview

This repository contains Terraform infrastructure-as-code that deploys and manages cloud resources using a modern CI/CD pipeline with:

  • πŸ—οΈ Infrastructure as Code: OpenTofu/Terraform for declarative infrastructure
  • πŸ”„ CI/CD Automation: Buildkite for pipeline orchestration
  • πŸ’Ύ State Management: Clivern Lynx HTTP backend with distributed locking
  • πŸ” Security: Comprehensive scanning with TFSec, Checkov, Terrascan, KICS
  • πŸ›‘οΈ Compliance: Mondoo security posture management
  • πŸ”‘ Secrets: HashiCorp Vault for secure credential management
  • πŸ€– AI Analysis: Fabric AI and Overmind for plan analysis

✨ Features

πŸš€ Deployment

  • βœ… Multi-environment support (dev, staging, production)
  • βœ… Progressive deployment with approval gates
  • βœ… Automated state backups before changes
  • βœ… Rollback capabilities
  • βœ… Environment-specific configurations

πŸ”’ Security

  • βœ… TFSec - Terraform static analysis
  • βœ… Checkov - Policy-as-code scanning
  • βœ… Terrascan - Infrastructure security scanner
  • βœ… KICS - Comprehensive IaC scanner
  • βœ… GitGuardian - Secret detection
  • βœ… Mondoo - Security posture management
  • βœ… Compliance score enforcement (minimum 85%)

πŸ€– Intelligent Analysis

  • βœ… Fabric AI - Natural language plan analysis
  • βœ… Overmind - Blast radius calculation
  • βœ… Change impact assessment
  • βœ… Risk scoring and recommendations

πŸ—οΈ Infrastructure

  • βœ… Module-based architecture
  • βœ… Reusable Terraform modules
  • βœ… Version-pinned dependencies
  • βœ… Automated documentation generation
  • βœ… Drift detection

πŸ›οΈ Architecture

πŸ›οΈ Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                        Buildkite CI/CD                          β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”        β”‚
β”‚  β”‚ Validation   β”‚β†’ β”‚  Security    β”‚β†’ β”‚  Deployment  β”‚        β”‚
β”‚  β”‚ & Formatting β”‚  β”‚  Scanning    β”‚  β”‚  Pipeline    β”‚        β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜        β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                             β”‚
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β–Ό                       β–Ό
        β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
        β”‚  HashiCorp      β”‚     β”‚  Clivern Lynx   β”‚
        β”‚  Vault          β”‚     β”‚  State Backend  β”‚
        β”‚  (Secrets)      β”‚     β”‚  (HTTP + Lock)  β”‚
        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                 β”‚                       β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                             β–Ό
                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚   Cloud         β”‚
                    β”‚   Infrastructureβ”‚
                    β”‚   (AWS/Azure)   β”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ“¦ Prerequisites

Required Tools

Tool Minimum Version Purpose
OpenTofu 1.6.0+ Infrastructure provisioning
PowerShell 7.0+ Script execution
Buildkite Agent 3.x+ CI/CD pipeline execution
Vault CLI 1.15.0+ Secret management

Optional Tools

Tool Purpose
Fabric AI AI-powered plan analysis
Overmind CLI Blast radius analysis
terraform-docs Documentation generation

Access Requirements

  • βœ… HashiCorp Vault access with JWT authentication
  • βœ… Clivern Lynx HTTP backend endpoint
  • βœ… Buildkite organization and pipeline
  • βœ… Cloud provider credentials (AWS/Azure/GCP)
  • βœ… Mondoo service account token

πŸš€ Quick Start

1. Clone Repository

git clone https://github.com/yourorg/terraform-infrastructure.git
cd terraform-infrastructure

2. Configure Pipeline

Edit .buildkite/pipeline.yml:

env:
  PROJECT_NAME: "my-infrastructure"
  SERVICE_NAME: "my-service"
  TARGET_ENVIRONMENTS: "dev,stg,prd"
  VAULT_NAMESPACE: "DevOps/prd/my-project"
  LYNX_BASE_URL: "https://lynx.company.com"

3. Set Up Vault Secrets

# Lynx backend credentials
vault kv put secret/lynx/terraform \
  username="terraform-user" \
  password="secure-password"

# Mondoo token
vault kv put secret/mondoo \
  token="your-mondoo-token"

4. Create Environment Directories

mkdir -p dev stg prd
cd dev

cat > main.tf <<EOF
terraform {
  required_version = ">= 1.6.0"
  
  backend "http" {
    # Configured by Initialize-TofuBackend
  }
}

module "vpc" {
  source  = "terraform-aws-modules/vpc/aws"
  version = "~> 5.0"
  
  name = "my-vpc"
  cidr = "10.0.0.0/16"
}
EOF

5. Commit and Push

git add .
git commit -m "feat: initial infrastructure setup"
git push origin main

6. Watch Pipeline Execute

Visit your Buildkite dashboard to see the pipeline run! πŸŽ‰


πŸ“ Project Structure

About

Terraform release scripts

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages