{Terraform} RDS/OCI

 

https://qiita.com/yama6/items/c3c39fcf905861d1055e

https://registry.terraform.io/providers/oracle/oci/latest/docs/resources/database_autonomous_database

 

cat <<-'EOF' > variables.tf

locals {
  tenancy_ocid = "ocid1.tenancy.oc1..000000000000000000000000000000000000000000000000000000000000"

}

variable "compartment_name" {
  description = "compartment_name"
  type = string
  default = "cmp01"
}

EOF

 

cat <<-'EOF' > main.tf

terraform {
  required_version = ">= 1.0.0, < 2.0.0"
  required_providers {
    oci = {
       source  = "hashicorp/oci"
       version = "= 5.23.0"
    }
  }
}

provider "oci" {
  tenancy_ocid = local.tenancy_ocid
  user_ocid = "ocid1.user.oc1..000000000000000000000000000000000000000000000000000000000000" 
  private_key_path = "~/.oci/oci_api_key.pem"
  fingerprint = "45:ed:22:e6:cc:fd:63:97:12:9d:62:7a:90:12:65:7a"
  region = "us-ashburn-1"
}


resource "oci_identity_compartment" "cmp01" {
    # Required
    compartment_id = local.tenancy_ocid
    description = var.compartment_name
    name = var.compartment_name
    
    enable_delete = true
}

resource "oci_core_vcn" "vcn01" {
    #Required
    compartment_id = oci_identity_compartment.cmp01.id

    #Optional
    cidr_block = "10.0.0.0/16"
    display_name = "vcn01"
    dns_label = "vcn01"

}


resource "oci_core_internet_gateway" "igw01" {
    #Required
    compartment_id = oci_identity_compartment.cmp01.id
    vcn_id = oci_core_vcn.vcn01.id

    #Optional
    enabled = true
    display_name = "igw01"
}

resource "oci_core_route_table" "rt01" {
    #Required
    compartment_id = oci_identity_compartment.cmp01.id
    vcn_id = oci_core_vcn.vcn01.id

    #Optional
    display_name = "rt01"
    route_rules {
        #Required
        network_entity_id = oci_core_internet_gateway.igw01.id
        #Optional
        destination = "0.0.0.0/0"
    }
    
}


resource "oci_core_security_list" "sl01" {
    #Required
    compartment_id = oci_identity_compartment.cmp01.id
    vcn_id = oci_core_vcn.vcn01.id

    #Optional
    display_name = "sl01"
    
    egress_security_rules {
        destination = "0.0.0.0/0"
        protocol = "all"
        stateless = false
    }
    
    ingress_security_rules {
        protocol = "6"
        source = "0.0.0.0/0"
        stateless = false
        tcp_options {
            max = 22
            min = 22
        }
    }
    ingress_security_rules {
        protocol = "6"
        source = "0.0.0.0/0"
        stateless = false
        tcp_options {
            max = 1522
            min = 1522
        }
    }
}

 

resource "oci_core_subnet" "subnet01" {
    #Required
    cidr_block = "10.0.1.0/24"
    compartment_id = oci_identity_compartment.cmp01.id
    vcn_id = oci_core_vcn.vcn01.id

    #Optional

    display_name = "subnet01"
    dns_label = "subnet01"
    route_table_id = oci_core_route_table.rt01.id
    security_list_ids = [oci_core_security_list.sl01.id]
}


resource "oci_database_autonomous_database" "adb01" {
    #Required
    compartment_id = oci_identity_compartment.cmp01.id
    db_name = "adb01"

    #Optional
    admin_password = "passwordpassword"
    backup_retention_period_in_days = "1"
    character_set = "AL32UTF8"
    compute_count = "2"
    compute_model = "ECPU"
    data_storage_size_in_gb = "20"
    db_version = "19c"
    db_workload = "OLTP"
    display_name = "adb01"
    is_auto_scaling_enabled = false
    is_auto_scaling_for_storage_enabled = false
    is_local_data_guard_enabled = false
    is_mtls_connection_required = false
    license_model = "LICENSE_INCLUDED"
    ncharacter_set = "AL16UTF16"
    whitelisted_ips = ["192.0.2.1"]
}

resource "oci_database_autonomous_database" "adb02" {
    #Required
    compartment_id = oci_identity_compartment.cmp01.id
    db_name = "adb02"

    #Optional
    admin_password = "passwordpassword"
    db_version = "19c"
    db_workload = "OLTP"
    display_name = "adb02"
    is_auto_scaling_enabled = false
    is_auto_scaling_for_storage_enabled = false
    is_local_data_guard_enabled = false
    is_mtls_connection_required = false
    whitelisted_ips = ["192.0.2.1"]
    is_free_tier = true
}


resource "oci_database_db_system" "dbs01" {
    availability_domain = "OEIw:US-ASHBURN-AD-3"
    compartment_id = oci_identity_compartment.cmp01.id

    db_home {
        database {
            admin_password = "passwordpassword"
            character_set = "AL32UTF8"
            db_backup_config {
                auto_backup_enabled = false
            }
            db_name = "db01"
            
            db_workload = "OLTP"
            ncharacter_set = "AL16UTF16"
            pdb_name = "db01pdb01"
        }
        db_version = "19.21.0.0"
        display_name = "dbh01"
    }

    hostname = "orcl"
    shape = "VM.Standard2.1"
    ssh_public_keys = [file("~/.ssh/id_rsa.pub")]
    subnet_id = oci_core_subnet.subnet01.id

    cluster_name = "cluster01"
    cpu_core_count = "1"
    data_collection_options {
        is_diagnostics_events_enabled = false
        is_health_monitoring_enabled = false
        is_incident_logs_enabled = false
    }
    
    data_storage_size_in_gb = "256"
    database_edition = "STANDARD_EDITION"
    db_system_options {
        storage_management = "ASM"
    }
    disk_redundancy = "NORMAL"
    display_name = "dbs01"
    domain = "subnet01.vcn01.oraclevcn.com"
    license_model = "LICENSE_INCLUDED"
    

    node_count = "1"
    private_ip = "10.0.1.10"
    source = "NONE"
        storage_volume_performance_mode = "BALANCED"
    time_zone = "Asia/Tokyo" 
    fault_domains = ["FAULT-DOMAIN-3"]

    timeouts {
       create = "4h"
    }

}

 

EOF

 

cat <<-'EOF' > outputs.tf

output "cmp01_id" {
  value = oci_identity_compartment.cmp01.id
  description = "cmp01.id"
}

output "vcn01_id" {
  value = oci_core_vcn.vcn01.id
  description = "vcn01.id"
}

output "igw01_id" {
  value = oci_core_internet_gateway.igw01.id
  description = "igw01.id"
}
output "rt01_id" {
  value = oci_core_route_table.rt01.id
  description = "rt01.id"
}

output "sl01_id" {
  value = oci_core_security_list.sl01.id
  description = "sl01.id"
}

output "subnet01_id" {
  value = oci_core_subnet.subnet01.id
  description = "subnet01.id"
}


output "adb01_id" {
  value = oci_database_autonomous_database.adb01.id
  description = "adb01.id"
}
output "adb02_id" {
  value = oci_database_autonomous_database.adb02.id
  description = "adb02.id"
}

 

output "dbs01_id" {
  value = oci_database_db_system.dbs01.id
  description = "dbs01.id"
}

EOF

 


terraform init
terraform fmt
terraform -version


export TF_VAR_compartment_name=cmp01

terraform plan

 

terraform apply -auto-approve

 

★BaseDB作成時、2時間後にポーリングタイムアウト
→ Operation Timeout4時間の設定追加

 


terraform destroy -auto-approve

 


oci db autonomous-database list \
--compartment-id ocid1.compartment.oc1..000000000000000000000000000000000000000000000000000000000000 \
--query 'data.{"db-name":"db-name","id":"id","lifecycle-state":"lifecycle-state"}' \
--output table

 

oci db system list \
--compartment-id ocid1.compartment.oc1..000000000000000000000000000000000000000000000000000000000000 \
--query 'data.{"display-name":"display-name","id":"id","lifecycle-state":"lifecycle-state"}' \
--output table