# Configure infrastructure

Prepare an existing application for the new deployment pipeline by making some small infrastructure changes.

## Before you begin

- You have familiarized yourself with [the key points from the risk assessment analysis (ROS)](https://github.com/oslokommune/golden-path-docs-internal/blob/main/oppsummering-ros-nytt-cicd-oppsett.md)
- You have migrated to new CI/CD for infrastructure:
  - [Prepare infrastructure repository](../../terraform-automation/migrate-to-latest-workflows/prepare-infrastructure-repository.md)
  - [Add plan workflow](../../terraform-automation/migrate-to-latest-workflows/add-plan-workflow.md)
  - [Add apply workflow](../../terraform-automation/migrate-to-latest-workflows/add-apply-workflow.md)
- Your application uses the `app` or `cloudfront-static-website` Boilerplate template

## Step 1: Configure the `cicd-common` stack in `dev`

Add your application repository to `config_override.tf`. The configuration differs depending on your repository type.

- **Application repository**—the repository contains code for a single application, while the associated infrastructure lives in a separate IaC repository (for example, `pirates-iac`).
- **Application monorepo**—the repository contains code for many applications, while the associated infrastructure lives in a separate IaC repository (for example, `pirates-iac`).
- **Application repository with infrastructure**—the repository contains both application code and the associated infrastructure for a single application.

Select the tab that matches your repository type:

=== "Application repository"

    Make the following changes:

    ```terraform title="repo-iac/environments/dev/cicd-common/config_override.tf"
    locals {
      trusted_repositories = [
        # ...
        {
          name = "<repo-name>"
          type = "app"
        }
      ]
    }
    ```

    Update these values:

    | Field           | Description                           | Example           |
    |-----------------|---------------------------------------|-------------------|
    | `<repo-name>` | The name of your application repository | `pirates-app-zebra` |

=== "Application monorepo"

    Make the following changes:

    ```terraform title="repo-iac/environments/dev/cicd-common/config_override.tf"
    locals {
      trusted_repositories = [
        # ...
        {
          name = "<repo-name>"
          type = "app"
          apps = [
            # Add more as needed
            "<app-name>"
          ]
        }
      ]
    }
    ```

    Update these values:

    | Field           | Description                           | Example           |
    |-----------------|---------------------------------------|-------------------|
    | `<repo-name>` | The name of your application monorepo | `pirates-apps` |
    | `<app-name>` | The name of your application | `too-tikki` |

=== "Application repository with infrastructure"

    Make the following changes:

    ```terraform title="repo-iac/environments/dev/cicd-common/config_override.tf"
    locals {
      trusted_repositories = [
        # ...
        {
          name = "<repo-name>"
          type = "hybrid"
        }
      ]
    }
    ```

    Update these values:

    | Field           | Description                           | Example           |
    |-----------------|---------------------------------------|-------------------|
    | `<repo-name>` | The name of your application repository with infrastructure | `pirates-app-swordsmith` |

## Step 2: Configure the application stack

In a stack using an `app` or `cloudfront-static-website` template, enable the new deployment mechanism:

```yaml title="repo-iac/environments/dev/app-example/package-config.yml"
DeploymentPipelineV2:
  Enable: true
```

Install the package:

```bash title="repo-iac/environments/dev/app-example/"
ok pkg install
```

<!-- prettier-ignore-start -->
!!! warning "For existing ECS container applications: Avoid downtime"

    `DeploymentPipelineV2` sets the ECS container's image URI (`local.image_uri`) automatically based on an image tag that's read from SSM Parameter Store (`local.artifact_tag`). During initial setup, the tag will contain a placeholder value (`"null"`) because the new CI/CD pipeline hasn't run yet.

    **In critical environments, add a fallback value in `config_override.tf` to prevent downtime that can occur from trying to deploy a non-existent image:**

    ```terraform
    locals {
      image_uri = (
        local.artifact_tag != "null" ?
        "${local.account_id}.dkr.ecr.${local.region}.amazonaws.com/${local.environment}-artifact:${local.artifact_tag}" :
        "<fallback-image-uri>"
      )
    }
    ```

    Update these values (you can find your current image URI in the ECS console in AWS):

    | Field           | Description                           | Example           |
    |-----------------|---------------------------------------|-------------------|
    | `<fallback-image-uri>` | The URI of an image to use on the first deploy | `123456789012.dkr.ecr.eu-west-1.amazonaws.com/my-repo:my-tag` |
<!-- prettier-ignore-end -->

## Step 3: Create a pull request

Create a pull request with your changes. GitHub Actions runs automatically and shows the planned changes in the pull request.

The plan contents depends on your set up, but based on a standard setup of a container application using Golden Path, the plan includes:

- A new SSM parameter for storing artifact references
- ECS service configured to have Terraform wait for container health checks to succeed through `wait_for_steady_state`
- IAM resources from the old CI/CD setup to be removed
- IAM resources for the new CI/CD setup to be added
- Changes to environment variables, Terraform outputs, and variables

Be sure to check that the `image_uri` in the task definition is either the image you provided in the workaround (see warning above), or otherwise an expected image (not an image tagged with `"null"`).

If you are unsure whether changes are safe to apply, don't hesitate to [contact Utviklerflyt](../../help/contact-us.md).

## Step 4: Merge the pull request

Merge the pull request and let the Terraform apply workflow in GitHub Actions apply the changes.

## Step 5: Repeat for production

Repeat steps above for your production environment.

## Next steps

[Prepare app repository](prepare-app-repository.md) with secrets, branch rulesets, and deployment approval.
