Provisioning the infrastructure¶
This OpenTofu configuration manages the QueFaireDeMesObjets infrastructure on Scaleway.
Scaleway¶
All resources on Scaleway are provisioned in the organization Incubateur ADEME (Pathtech) and the project longuevieauxobjets.
All resources are named following the pattern lvao-{env}-{explicit-name} (for example: lvao-prod-webapp-db).
OpenTofu & Terragrunt¶
We use OpenTofu, the open-source version of Terraform, to automate infrastructure provisioning. Follow the documentation to install OpenTofu.
Terragrunt is used alongside OpenTofu to keep the configuration DRY. Follow the documentation to install Terragrunt.
The configuration is defined in the infrastructure directory.
Prerequisites¶
Install and configure the Scaleway CLI by following Scaleway’s instructions.
Make sure you have administration rights on the project targeted by this infrastructure plan.
IaC: Infrastructure as Code¶
Structure¶
infrastructure/
├── environments/
│ ├── prod/
│ │ ├── terragrunt.hcl
│ │ ├── terraform.tfvars.example
│ │ └── terraform.tfvars -> not versioned
│ ├── preprod/
│ └── preview/
└── modules/
├── database/
│ ├── main.tf
│ ├── variables.tf
│ └── outputs.tf
└── provider/
Configuration¶
Copy
environments/<ENV>/terraform.tfvars.exampletoterraform.tfvars.Edit the values in
terraform.tfvarswith your information:project_id: Scaleway project IDorganization_id: Scaleway organization IDdb_password: secure password for the database…
Execution¶
tfstate¶
⚠️ The Terraform state is stored in a Scaleway S3 bucket: s3://lvao-terraform-state.
Per environment¶
The preview environment is used to test our IaC project. We intentionally destroy the infrastructure created in this environment once the Terraform configuration has been tested.
For each environment:
Preprod:
infrastructure/environments/preprodat the repository rootProd:
infrastructure/environments/prodat the repository root
Change directory to infrastructure/environments/<ENV> and run:
terragrunt init -reconfigure --all
terragrunt plan --all
terragrunt apply --all
For each command, the environment must be specified.
Composants déployés¶
Voir aussi : Architecture applicative, Bases de données, Airflow, Sauvegardes, PCA, PRA.
Scalingo (région osc-fr1)¶
Composant |
Détail |
|---|---|
Webapp Django |
Application web principale exposée aux utilisateurs (front public, back-office Django Admin, CMS Wagtail). Servie par Gunicorn sur socket Unix, fichiers statiques via WhiteNoise ( |
Buildpacks |
|
Procfile |
|
Worker django-tasks |
Container Scalingo |
nginx Scalingo |
Couche de cache devant Gunicorn ( |
Base de données |
La webapp cible la DB Scaleway |
Cache applicatif |
|
Médias |
Délégués à Scaleway Object Storage ( |
Scaleway (région fr-par, projet longuevieauxobjets)¶
Toutes les ressources suivent la nomenclature lvao-{env}-{nom} où env ∈ {prod, preprod, preview}.
Container as a Service (CaaS)¶
Trois Serverless Containers distincts pour Airflow 3 (apache/airflow:slim-3.1.7-python3.12), construits via Dockerfiles dédiés :
Container |
Image |
Rôle |
|---|---|---|
|
|
Interface UI/API Airflow ( |
|
|
Orchestrateur ( |
|
|
Parsing isolé des DAGs avec nginx en façade pour le healthcheck. |
Voir data-platform/airflow.md pour le détail de la configuration runtime (auth manager, JWT, métadonnées).
Container Registry¶
Namespace privé ns-qfdmo — héberge les images Docker des 3 containers Airflow (push par la CI, pull par les Serverless Containers).
Bases de données (RDB PostgreSQL 16 HA)¶
Base de données |
Nom Scaleway |
Usage |
|---|---|---|
DB Webapp |
Instance |
Données applicatives (acteurs, propositions de service, configurations carte, utilisateurs Wagtail/Django, cache, médias Wagtail). Extension PostGIS activée. |
DB Warehouse |
Instance |
Tables analytiques produites par dbt. Schéma |
DB Airflow |
Instance |
Métadonnées Airflow (état des DAGs, XComs, logs courts). Nettoyée quotidiennement par le DAG |
DB Metabase |
Instance |
Base applicative Metabase (optionnelle, provisionnée si |
Connexions clientes en sslmode=require. Voir db/db_organisation.md pour la liaison postgres_fdw et security/backups.md pour la stratégie de sauvegarde.
Pour faire tourner les mots de passe (webapp_db_password, warehouse_db_password, airflow_db_password), suivre Rotating database passwords.
Object Storage (S3 fr-par)¶
Bucket |
Connexion Airflow |
Usage |
|---|---|---|
|
— |
Fichiers (images) uploadés depuis l’interface Django Admin de la webapp : |
|
|
Export CSV opendata des acteurs ( |
|
|
Fichiers Excel ad-hoc consommés par le DAG |
|
|
Remote logs Airflow ( |
|
— |
Backend OpenTofu/Terragrunt (versionné, chiffré). |