通過Terraform建立GCP Pubsub

2023-01-13 18:00:52

1 簡介

Terraform是管理許多平臺的基礎設施的工具,如AWS、GCP和Azure。這篇文章將講解如何通過Terraform來管理GCP Pub/Sub。

建立GCP專案請參考:初始化一個GCP專案並用gcloud存取操作

2 Terraform建立Pub/Sub

2.1 下載Terraform外掛

我們需要安裝GCP的Terraform外掛來管理GCP資源:

# 設定外掛目錄
$ export TERRAFORM_PLUGIN=/Users/larry/Software/terraform/plugins
# 建立目錄
$ mkdir -p ${TERRAFORM_PLUGIN}/registry.terraform.io/hashicorp/google/4.0.0/darwin_amd64
$ cd ${TERRAFORM_PLUGIN}/registry.terraform.io/hashicorp/google/4.0.0/darwin_amd64
# 下載
$ wget https://releases.hashicorp.com/terraform-provider-google/4.0.0/terraform-provider-google_4.0.0_darwin_amd64.zip
# 解壓
$ unzip terraform-provider-google_4.0.0_darwin_amd64.zip

2.2 準備Terraform程式碼

需要提供Terraform程式碼理管理Pub/Sub,更多細節請參考: Terrafrom GCP.

版本檔案version.tf:

terraform {
  required_version = "= 1.0.11"
  required_providers {

    google = {
      source  = "hashicorp/google"
      version = "= 4.0.0"
    }
  }
}

主檔案main.tf:

provider "google" {
  project     = "pkslow"
}

resource "google_pubsub_topic" "pkslow-poc" {
  name = "pkslow-poc"
}

resource "google_pubsub_subscription" "pkslow-poc" {
  name  = "pkslow-poc"
  topic = google_pubsub_topic.pkslow-poc.name

  labels = {
    foo = "bar"
  }

  # 20 minutes
  message_retention_duration = "1200s"
  retain_acked_messages      = true

  ack_deadline_seconds = 20

  expiration_policy {
    ttl = "300000.5s"
  }
  retry_policy {
    minimum_backoff = "10s"
  }

  enable_message_ordering    = true
}

2.3 初始化和變更

指定外掛目錄初始化:

$ terraform init -plugin-dir=${TERRAFORM_PLUGIN}

使變更生效,就會在GCP上建立對應的資源:

$ terraform apply -auto-approve

如果沒有發生錯誤,則意味著建立成功,我們檢查一下:

$ gcloud pubsub topics list
---
name: projects/pkslow/topics/pkslow-poc

$ gcloud pubsub subscriptions list
---
ackDeadlineSeconds: 20
enableMessageOrdering: true
expirationPolicy:
  ttl: 300000.500s
labels:
  foo: bar
messageRetentionDuration: 1200s
name: projects/pkslow/subscriptions/pkslow-poc
pushConfig: {}
retainAckedMessages: true
retryPolicy:
  maximumBackoff: 600s
  minimumBackoff: 10s
topic: projects/pkslow/topics/pkslow-poc

注意:我們並沒有提供任何密碼或金鑰,那Terraform怎麼可以直接操作我的GCP資源呢?因為它會根據環境變數GOOGLE_APPLICATION_CREDENTIALS來獲取。

3 傳送和接收訊息

我們通過gcloud來傳送訊息到Pub/Sub上:

$ gcloud pubsub topics publish pkslow-poc --message="www.pkslow.com"
messageIds:
- '3491736520339885'

$ gcloud pubsub topics publish pkslow-poc --message="Larry Deng"
messageIds:
- '3491738650256958'

$ gcloud pubsub topics publish pkslow-poc --message="Hi, pkslower"
messageIds:
- '3491739306095970'

從Pub/Sub拉取訊息:

$ gcloud pubsub subscriptions pull pkslow-poc --auto-ack

我們還能在GCP介面上監控對應的佇列,十分方便:

4 程式碼

程式碼在 GitHub上: https://github.com/LarryDpk/pkslow-samples