Repository navigation
docs: Provide worked examples for the AWS tag schema #207
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
2 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,60 @@ | ||
| # AWS Tags | ||
|
|
||
| > [!NOTE] | ||
| > Resources provisioned using [GuCDK](https://github.com/guardian/cdk) automatically fulfil these requirements. | ||
| > When using a YAML/JSON CloudFormation template, resources that are not explicitly tagged will inherit tags from the parent CloudFormation stack. | ||
|
|
||
| Most resources in AWS can be [tagged](https://docs.aws.amazon.com/whitepapers/latest/tagging-best-practices/what-are-tags.html). | ||
| This document outlines tags used at the Guardian. In short, resources should have the following tags: | ||
| - `App` | ||
| - `Stack` | ||
| - `Stage` | ||
| - `gu:repo` | ||
|
akash1810 marked this conversation as resolved.
|
||
|
|
||
| You can apply your own tags as well. | ||
|
|
||
| ## Core tags | ||
| The following tags should be applied to all taggable resources. | ||
|
|
||
| ### `App` | ||
| This tag identifies an individual application. | ||
|
|
||
| For example, `user-api` could be a web service for managing a user's preferences, or `user-cleanup` could be a lambda that runs periodically to remove inactive users. | ||
|
|
||
| ### `Stack` | ||
|
akash1810 marked this conversation as resolved.
|
||
| This tag identifies a group of related applications. | ||
|
|
||
| For example, the aforementioned `user-api` and `user-cleanup` would be part of a `user-management` stack. | ||
|
|
||
| Tools that operate across accounts use `Stack` in the following ways: | ||
| - [Riff-Raff](https://github.com/guardian/riff-raff) uses `Stack` to derive an individual AWS account. Therefore, we can consider `Stack` as being unique to a single AWS account | ||
| - [Anghammarad](https://github.com/guardian/anghammarad) can use `Stack` to route messages to a team for the entire group of applications, which can be easier than adding a mapping for every application individually. | ||
|
|
||
| Tools which operate across account, for example Riff-Raff, use the stack to derive an individual AWS account. | ||
| Therefore, we could consider a stack as being unique to a single AWS account. | ||
|
|
||
| > [!NOTE] | ||
| > "Stack" is an overloaded term. For example, in some contexts it can mean a CloudFormation stack. | ||
| > Indeed, a CloudFormation stack should have a `Stack` tag! | ||
|
|
||
| ### `Stage` | ||
| This tag identifies the environment. Typical values are: | ||
| - `PROD` for production | ||
| - `CODE` for pre-production | ||
| - `INFRA` for account-wide infrastructure or singleton resources e.g. [elasticsearch-node-rotation](https://github.com/guardian/elasticsearch-node-rotation) | ||
|
|
||
| > [!IMPORTANT] | ||
| > The combination of `App`, `Stack`, `Stage` should **uniquely identify** a service. | ||
| > For example, there will be one lambda tagged `App=user-cleanup`, `Stack=user-management`, `Stage=PROD` in the entire estate. | ||
|
|
||
| ### `gu:repo` | ||
| *This tag is automatically set by tooling such as [GuCDK](https://github.com/guardian/cdk) or [Riff-Raff](https://github.com/guardian/riff-raff).* | ||
|
|
||
| This tag identifies the GitHub repository where the resource's infrastructure as code definition can be found. It takes the form `guardian/<REPO NAME>`. | ||
|
|
||
| ## Other common tags | ||
| There are some additional tags to consider based on the circumstance. | ||
|
|
||
| ### `Owner` | ||
| When provisioning a resource in another team's account, the `Owner` tags helps that team know who to contact if needed. | ||
| It should be the team name, for example `DevX`. | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.