Skip to content

Commit

Permalink
first commit
Browse files Browse the repository at this point in the history
  • Loading branch information
Gitigi committed Oct 16, 2022
0 parents commit 70c7ea4
Show file tree
Hide file tree
Showing 10 changed files with 1,311 additions and 0 deletions.
135 changes: 135 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,135 @@
# Byte-compiled / optimized / DLL files
__pycache__/
*.py[cod]
*$py.class

# C extensions
*.so

# Distribution / packaging
.Python
build/
develop-eggs/
dist/
downloads/
eggs/
.eggs/
lib/
lib64/
parts/
sdist/
var/
wheels/
pip-wheel-metadata/
share/python-wheels/
*.egg-info/
.installed.cfg
*.egg
MANIFEST

# PyInstaller
# Usually these files are written by a python script from a template
# before PyInstaller builds the exe, so as to inject date/other infos into it.
*.manifest
*.spec

# Installer logs
pip-log.txt
pip-delete-this-directory.txt

# Unit test / coverage reports
htmlcov/
.tox/
.nox/
.coverage
.coverage.*
.cache
nosetests.xml
coverage.xml
*.cover
*.py,cover
.hypothesis/
.pytest_cache/

# Translations
*.mo
*.pot

# Django stuff:
*.log
local_settings.py
db.sqlite3
db.sqlite3-journal

# Flask stuff:
instance/
.webassets-cache

# Scrapy stuff:
.scrapy

# Sphinx documentation
docs/_build/

# PyBuilder
target/

# Jupyter Notebook
.ipynb_checkpoints

# IPython
profile_default/
ipython_config.py

# pyenv
.python-version

# pipenv
# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control.
# However, in case of collaboration, if having platform-specific dependencies or dependencies
# having no cross-platform support, pipenv may install dependencies that don't work, or not
# install all needed dependencies.
#Pipfile.lock

# PEP 582; used by e.g. github.com/David-OConnor/pyflow
__pypackages__/

# Celery stuff
celerybeat-schedule
celerybeat.pid

# SageMath parsed files
*.sage.py

# Environments
.env
.venv
env/
venv/
ENV/
env.bak/
venv.bak/

# Spyder project settings
.spyderproject
.spyproject

# Rope project settings
.ropeproject

# mkdocs documentation
/site

# mypy
.mypy_cache/
.dmypy.json
dmypy.json

# Pyre type checker
.pyre/

main.zip
requirements.zip
requirements/
devops/terraform.exe
devops/.terraform/
8 changes: 8 additions & 0 deletions README.me
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
uvicorn main:app --reload


# Deploy
terraform init
terraform apply

NB: set aws access_key and secret_key in devops/variables.tf
59 changes: 59 additions & 0 deletions devops/.terraform.lock.hcl

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

50 changes: 50 additions & 0 deletions devops/iam.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
#
# lambda assume role policy
#

# trust relationships
data "aws_iam_policy_document" "fastapi_assume_role_policy" {
statement {
actions = ["sts:AssumeRole"]
principals {
type = "Service"
identifiers = ["lambda.amazonaws.com"]
}
}
}

resource "aws_iam_role" "fastapi_role" {
name = "${var.project_name}-lambda-role"
assume_role_policy = data.aws_iam_policy_document.fastapi_assume_role_policy.json
}


resource "aws_cloudwatch_log_group" "fastapi_logging_group" {
name = "/aws/lambda/${var.project_name}"
retention_in_days = 14
}

data "aws_iam_policy_document" "fastapi_logging_role_policy" {
statement {
actions = [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:PutLogEvents"
]
resources = ["arn:aws:logs:*:*:*"]
effect = "Allow"
}
}

resource "aws_iam_policy" "fastapi_logging" {
name = "fastapi_logging"
path = "/"
description = "IAM policy for logging from a lambda"

policy = data.aws_iam_policy_document.fastapi_logging_role_policy.json
}

resource "aws_iam_role_policy_attachment" "fastapi_logs" {
role = aws_iam_role.fastapi_role.name
policy_arn = aws_iam_policy.fastapi_logging.arn
}
Loading

0 comments on commit 70c7ea4

Please sign in to comment.