3 ms·
Terraform is definitely an option, but we found (the story might be different since 0.12) that creating large full meshes with many VPCs across many accounts wi
by bmcalary_atl 7y ago
Terraform is definitely an option, but we found (the story might be different since 0.12) that creating large full meshes with many VPCs across many accounts with many route tables resulted in Terraform modules and files that were quite complex, long and hard to overlap with other meshes.
This tool can be used alongside terraform, ansible or whatever infra-as-code orchestration tool you like. I encourage you to do so! :)
- eropple 7y agoFWIW, this problem is significantly alleviated with Pulumi. I've knocked together something internal that's a lot like this, in Pulumi, in something like thirty lines. That's emphatically not to take anything away from this, as if you're not using Pulumi this is a relatively hard problem to deal with, but it does feel as though a lot of the more annoying aspects of our jobs as infra professionals are made a lot easier with it.
- Terretta 7y agoYes, that’s the right approach. I recall we shared with Atlassian about extracting this from Ansible and keeping it outside the then brand new Terraform back when we met at a certain forum as well as when we had an NDA sync at our HQ. It really is remarkable how identical this is to that implementation, someone using that tool would be instantly at home in this. I guess it’s one of those ‘obvious’ problems once you decide to tackle it! Well done. I regret that back then our firm was uninterested to open source more than our enterprisification (abstraction from one CSP allowing it to work for others) of Security Monkey.
- saber6 7y agoYup your point is true about having to manage N(N-1) number of vpc peering related components. I don’t ever deal with more than 10 VPCs at a time. Maybe you have world-conquering aspirations and need insane scale ;D