Deploy Resource Aggregator
Application Scenario
Configuration Audit (Config) is a one-stop compliance management service provided by Huawei Cloud, helping users continuously monitor and evaluate the configuration compliance of cloud resources. Config service provides pre-built compliance rule packages and custom rules, supporting multiple compliance frameworks and standards, helping enterprises establish a comprehensive compliance management system.
Resource aggregator is an important function of Config service, used to aggregate cloud resource information across accounts or organizations, achieving unified compliance management. Through resource aggregators, enterprises can centrally manage resources across multiple accounts or organizations, uniformly execute compliance check policies, and improve the efficiency and consistency of compliance management. Resource aggregators support both account-level and organization-level types, providing enterprises with flexible resource configuration aggregation solutions. This best practice will introduce how to use Terraform to automatically deploy Config resource aggregators, including aggregator creation and account configuration.
Related Resources/Data Sources
This best practice involves the following main resources and data sources:
Resources
Resource/Data Source Dependencies
huaweicloud_rms_resource_aggregator.testOperation Steps
1. Script Preparation
Prepare the TF file (e.g., main.tf) in the specified workspace for writing the current best practice script, ensuring that it (or other TF files in the same directory) contains the provider version declaration and Huawei Cloud authentication information required for deploying resources. Refer to the "Preparation Before Deploying Huawei Cloud Resources" document for configuration introduction.
2. Create Resource Aggregator
Add the following script to the TF file (e.g., main.tf) to instruct Terraform to create a resource aggregator resource:
Parameter Description:
name: Resource aggregator name, assigned by referencing the input variable aggregator_name
type: Resource aggregator type, assigned by referencing the input variable aggregator_type, supports ACCOUNT or ORGANIZATION
account_ids: Source account ID list, assigned by referencing the input variable account_ids
3. Preset Input Parameters Required for Resource Deployment (Optional)
In this practice, some resources and data sources use input variables to assign values to configuration content. These input parameters need to be manually entered during subsequent deployments. At the same time, Terraform provides a method to preset these configurations through .tfvars files, which can avoid repeated input during each execution.
Create a terraform.tfvars file in the working directory with the following example content:
Usage:
Save the above content as
terraform.tfvarsfile in the working directory (this file name allows users to automatically import the content of thistfvarsfile when executing terraform commands; for other names,.autoneeds to be added before tfvars, such asvariables.auto.tfvars)Modify parameter values as needed
When executing
terraform planorterraform apply, Terraform will automatically read the variable values from this file
In addition to using terraform.tfvars file, variable values can also be set in the following ways:
Command line parameters:
terraform apply -var="aggregator_name=my-aggregator" -var="aggregator_type=ACCOUNT"Environment variables:
export TF_VAR_aggregator_name=my-aggregatorCustom named variable files:
terraform apply -var-file="custom.tfvars"
Note: If the same variable is set in multiple ways, Terraform will use the variable value according to the following priority: command line parameters > variable files > environment variables > default values.
4. Initialize and Apply Terraform Configuration
After completing the above script configuration, execute the following steps to create resources:
Run
terraform initto initialize the environmentRun
terraform planto view the resource creation planAfter confirming the resource plan is correct, run
terraform applyto start creating the resource aggregatorRun
terraform showto view the details of the created resource aggregator
Reference Information
Last updated