Github repo:
At Alibaba Cloud, we use Terraform to provide fast demos to our customers. I truly believe that the infrasture-as-code is the quick way to leverage a public cloud provider services. Instead of clicking on the Web Console UI, the logic of the infrasture-as-code allows us to define more accuratly each used services, automate the entire infrastructure and version it with a versionning control (git).
We provide the Alicloud credentials with envrionments variables. In this tutorial, we are going to use the Singapore Region (ap-southeast-1).
root@alicloud:~$ export ALICLOUD_ACCESS_KEY="anaccesskey"
root@alicloud:~$ export ALICLOUD_SECRET_KEY="asecretkey"
root@alicloud:~$ export ALICLOUD_REGION="ap-southeast-1"
If you don't have an access key for your Alicloud account yet, just follow this tutorial.
To install Terraform, download the appropriate package for your OS. The download contains an executable file that you can add in your global PATH.
Verify your PATH configuration by typing the terraform
root@alicloud:~$ terraform
Usage: terraform [--version] [--help] <command> [args]
The official repository for Alicloud terraform provider is
- Download a compiled binary from
- Create a custom plugin directory named terraform.d/plugins/darwin_amd64.
- Move the binary inside this custom plugin directory.
- Create file for the plan and provide inside:
# Configure the Alicloud Provider
provider "alicloud" {}
- Initialize the working directory but Terraform will not download the alicloud provider plugin from internet, because we provide a newest version locally.
terraform init
terraform init solutions/base_vpc
terraform plan|apply|destroy \
-var-file=parameters/base_vpc.tfvars \
-state=states/base_vpc.tfstate \
Please follow the prerequisites to get your trial access of Docker EE :
terraform init solutions/docker_ha
terraform plan|apply|destroy \
-var 'ssh_password=<SSH_PASSWORD>' \
-var 'docker_ee_url=<DOCKER_EE_URL>' \
-var-file=parameters/docker_ha.tfvars \
-state=states/docker_ha.tfstate \
Default login: admin / admindocker To finalise the setup of the cluster by adding the worker nodes, you need to login into the UCP web ui and follow:
openssl s_client -connect $DOMAIN_NAME:443 -showcerts </dev/null 2>/dev/null | openssl x509 -outform PEM | sudo tee /usr/local/share/ca-certificates/$DOMAIN_NAME.crt
sudo update-ca-certificates
### Setup Docker Trusted Registry (DTR) on a worker node
Choose one node worker already added to the cluster and then follow:
You can set the option "“Disabled TLS verification For UCP" on installing DTR to avoid issue with the UDP certificate.
## Issues