Repository navigation
chore: DB EC2 의 private IP 를 현재 주소로 고정 - #86
Conversation
인스턴스를 교체하면 private IP 가 바뀌어 Parameter Store 의 spring.datasource.url 갱신과 API 서버 재배포가 함께 필요했다. DB EC2 는 private subnet 에 있어 EIP 로 주소를 유지할 수도 없다. 복구 워크플로우(#68)에서 인스턴스를 교체해도 datasource 설정을 그대로 쓸 수 있도록 현재 주소를 명시적으로 고정한다. - prod 의 db_ec2_private_ip 는 default 없이 secrets tfvars 에서 읽는다 - 모듈 변수는 DB EC2 를 쓰지 않는 stage 를 위해 null 기본값을 둔다 - 현재 주소와 같은 값이면 plan 이 No changes 임을 확인했다 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (5)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughprod 환경에서 DB EC2의 고정 사설 IP를 입력하고 app_stack 모듈을 통해 인스턴스에 전달하도록 변경했습니다. 또한 config/secrets의 서브모듈 커밋 참조를 갱신했습니다. ChangesDB EC2 사설 IP 설정
secrets 서브모듈 참조 갱신
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to No confirmed issue prevents merging. Confirm the production secrets value and CI Terraform plan before applying the change to production. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The visible changes are narrowly scoped and retain existing network and storage protections. However, the updated secret values and address continuity during database replacement have not been verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Terraform Plan:
|
Terraform Plan:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c8426f9180
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| variable "db_ec2_private_ip" { | ||
| description = "DB EC2에 고정할 Private IP (db_ec2_subnet_id 의 CIDR 안에 있어야 합니다)" | ||
| type = string | ||
| } |
There was a problem hiding this comment.
Update the secrets submodule for the required IP input
The prod plan/apply workflows check out config/secrets recursively and load prod_db.tfvars, but this commit leaves the submodule pinned at the previous cbceeaaba7de5fa1c944732d2223759fe4a44d2a revision. Because this new variable has no default, Terraform requires the pinned file to define it (HashiCorp variable reference); otherwise the prod CI run triggered by these changes cannot generate a plan or apply. Update the submodule pointer to the revision containing db_ec2_private_ip in the same change.
Useful? React with 👍 / 👎.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Terraform Plan:
|
Terraform Plan:
|
관련 이슈
작업 내용
aws_instance.db_server)의 private IP를 현재 주소로 명시적으로 고정했습니다.db_ec2_private_ip변수로 받으며, default 없이 secrets의prod_db.tfvars에서 읽습니다.app_stack모듈 변수db_private_ip는 DB EC2를 쓰지 않는 stage를 위해null기본값을 둡니다.배경
복구 워크플로우(#68)는 인스턴스를 교체하는 방식으로 진행합니다. 지금은 교체할 때마다 private IP가 바뀌어 다음 작업이 함께 필요합니다.
/solid-connection/prod/spring.datasource.url갱신 (현재 private IP를 직접 가리킴)DB EC2는 private subnet에 있어 EIP로 주소를 유지할 수 없습니다. 그래서 private IP를 고정해 두 단계를 복구 절차에서 없앱니다.
특이 사항
prod_db.tfvars에db_ec2_private_ip를 추가하고 이 PR의 submodule 포인터를 올리기 전까지는 CI plan이 변수 누락으로 실패합니다.-target으로 지정해 plan을 확인했습니다.No changes.117):private_ip ... # forces replacement,Plan: 2 to add, 0 to change, 2 to destroyterraform validate를 통과했습니다.리뷰 요구사항 (선택)
module.prod_stack.aws_instance.db_server에 변경이 없는지 확인 부탁드립니다.-replace는 destroy 후 create 순서로 진행됩니다. 기존 인스턴스가 종료되면서 반환된 IP를 새 인스턴스가 바로 받는지는 복구 리허설에서 확인할 예정입니다.🤖 Generated with Claude Code
Summary by CodeRabbit