FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Gaucho-Racing/infrastructure: Gaucho Racing's infrastructure as code repository. · GitHub

Latest commit

 

History

275 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

infrastructure

Gaucho Racing's AWS infrastructure and Kubernetes deployment configuration.

Layout

infra/         Terraform — AWS accounts, S3, EC2 data services, Cloudflare
  environments/dev    → Gaucho Racing Development account (104050870528)
  environments/prod   → Gaucho Racing Production account (174765207334)
  modules/            shared module definitions
kubernetes/    GitOps — ArgoCD apps + kustomize manifests
  gr-foundry/         on-prem k3s cluster (sentinel, vault, jiffy, atlantis, …)

The two trees are decoupled. Terraform changes go through Atlantis on pull requests; Kubernetes manifests are reconciled continuously by ArgoCD.

AWS accounts

Account ID Purpose
gauchoracing 211125506628 Org management + legacy infra (not terraform-managed)
Gaucho Racing Development 104050870528 Member sandbox + dev services (environments/dev)
Gaucho Racing Production 174765207334 Production services (environments/prod)

The legacy infra in the management account (EC2 data services, Cloudflare DNS/tunnel) is deprecated: it's administered manually until each piece is removed or migrated into the production account's terraform. Its final terraform state is archived at s3://gaucho-racing-tfstate/archive/legacy-mgmt-prod.tfstate.

Terraform workflow — Atlantis only

All Terraform planning and applying happens through Atlantis on pull requests. Never run terraform plan or terraform apply locally — local applies race Atlantis's locks and bypass review.

  1. Open a PR touching infra/ — Atlantis autoplans affected projects and comments the diff (prod plans additionally wait for PR approval).
  2. Get the PR approved.
  3. Comment atlantis apply — Atlantis applies pre-merge and reports back.
  4. Squash and merge.

If a PR is abandoned with an unapplied plan, comment atlantis unlock on it to release the project lock.

Branch rules

main is fully protected — no one can bypass, including admins:

  • Squash-and-merge is the only merge method; linear history is required.
  • Every PR needs an approving review. PRs touching infra/ additionally need a Code Owner approval (see .github/CODEOWNERS).
  • Atlantis refuses to apply until the PR is approved and mergeable, so the review gate covers infrastructure changes, not just merges.

Kubernetes workflow

ArgoCD on the foundry cluster watches kubernetes/gr-foundry/apps/ (see bootstrap/root.yaml). Each app is an ArgoCD Application pointing at a kustomize dir in manifests/. Secrets are never committed — they live in Vault and sync into namespaces via VaultSecretSync resources, gated by per-namespace access rules configured in the Vault UI.

Region

us-west-2.

State backend

S3 (gaucho-racing-tfstate, management account) with native locking (use_lockfile = true, Terraform ≥ 1.10). One key per environment root. Only management-account credentials (Atlantis) can reach the backend — member credentials live in the dev account and cannot init it locally.

About

Gaucho Racing's infrastructure as code repository.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages


Back | FazBrowse Home | New Git URL