Imported from richh-brreto/scripts-grupo4 (
AGENTS.md). Install upstream withnpx skills add richh-brreto/scripts-grupo4. Copyright stays with the author.
AGENTS.md
Repository Overview
Infrastructure scripts for university group project (Grupo 4). Three parallel approaches to the same architecture, plus Docker/LB configs.
Structure
AWS/ CLI-only infra provisioning + monitoring + teardown
Terraform/ Modular Terraform (infra + medallion S3 buckets)
LocalStack/ Local development via LocalStack + awslocal
Docker/ HAProxy, Nginx configs, install docs
Architecture (shared across all approaches)
- Region:
us-east-1(hardcoded everywhere) - Key pair:
key-server(must exist in AWS before running scripts) - VPC: 10.0.0.0/16, 5 subnets (2 public, 3 private)
- Compute: Bastion (public) + 4 app servers (private, 2 per AZ) + 1 DB instance
- Load Balancer: ALB forwarding to app instances A2 and B2 only
- Storage: EFS mounted on private subnets, S3 medallion (bronze/silver/gold) via Terraform
- Cleanup order matters: EC2 → ALB → Target Groups → EFS (mount targets first) → NAT → EIP → SG → Route Tables → IGW → Subnets → VPC
Terraform
Two independent root configs:
Terraform/infra/— full infrastructure (VPC, EC2, ALB, EFS, IAM, etc.)Terraform/Bucket/— S3 medallion buckets (bronze/silver/gold with versioning + KMS encryption)
Both require terraform.tfvars with aws_access_key, aws_secret_key, and optionally aws_session_token. The file is gitignored — use terraform.tfvars.txt as a template.
Commands (from the root config directory):
terraform init
terraform validate
terraform plan
terraform apply
Watch out: Terraform/Bucket/main.tf references module source ../modules/medallion, but the directory is modules/Buckets. Verify this path is correct before applying.
AWS CLI Scripts
All scripts use set -e (fail fast) and hardcode REGION=us-east-1.
| Script | Purpose |
|---|---|
AWS/infra.sh |
Provision full VPC + EC2 + ALB + EFS |
AWS/cloudwach.sh |
Create CloudWatch monitoring dashboard |
AWS/limpaAWS.sh |
Tear down all resources (safe, respects dependencies) |
Prerequisites: AWS CLI configured with credentials, key-server key pair imported.
LocalStack
Requires localstack start (via docker-compose) and awslocal (pip install awscli-local).
cd LocalStack
docker compose up -d # starts LocalStack, auto-runs infra.sh via init hook
Services enabled: s3, lambda, ec2, efs, elbv2, cloudcontrol. Data persists to ./localstack-data/.
Security
.gitignoreblocks:*.tfvars,*.tfstate*,*.pem,*.ppk,credentialsTerraform/infra/terraform.tfvarsexists in git (contains secrets — should not be committed)- All Terraform variables with
sensitive = trueare handled correctly - Do not commit AWS credentials, key files, or tfstate
Gotchas
- EFS mount targets require a
sleep 15before creation; the scripts handle this - ALB only registers instances A2 and B2 (not A1/B1) — this is intentional
dashboard.jsonin AWS/ is auto-generated bycloudwach.sh, don't edit manually- Terraform provider is AWS
~> 5.0