├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md ├── LICENSE ├── LambdaWordpress ├── bin │ ├── lambda_wordpress.d.ts │ ├── lambda_wordpress.js │ └── lambda_wordpress.ts ├── cdk.json ├── jest.config.js ├── lib │ ├── lambda_wordpress-stack.d.ts │ ├── lambda_wordpress-stack.js │ ├── lambda_wordpress-stack.ts │ └── phpLambdaFunc │ │ ├── Makefile │ │ ├── handler.php │ │ └── php.ini ├── package-lock.json ├── package.json ├── test │ ├── lambda_wordpress.test.d.ts │ ├── lambda_wordpress.test.js │ └── lambda_wordpress.test.ts └── tsconfig.json └── README.md /CODE_OF_CONDUCT.md: -------------------------------------------------------------------------------- 1 | ## Code of Conduct 2 | This project has adopted the [Amazon Open Source Code of Conduct](https://aws.github.io/code-of-conduct). 3 | For more information see the [Code of Conduct FAQ](https://aws.github.io/code-of-conduct-faq) or contact 4 | opensource-codeofconduct@amazon.com with any additional questions or comments. 5 | -------------------------------------------------------------------------------- /CONTRIBUTING.md: -------------------------------------------------------------------------------- 1 | # Contributing Guidelines 2 | 3 | Thank you for your interest in contributing to our project. Whether it's a bug report, new feature, correction, or additional 4 | documentation, we greatly value feedback and contributions from our community. 5 | 6 | Please read through this document before submitting any issues or pull requests to ensure we have all the necessary 7 | information to effectively respond to your bug report or contribution. 8 | 9 | 10 | ## Reporting Bugs/Feature Requests 11 | 12 | We welcome you to use the GitHub issue tracker to report bugs or suggest features. 13 | 14 | When filing an issue, please check existing open, or recently closed, issues to make sure somebody else hasn't already 15 | reported the issue. Please try to include as much information as you can. Details like these are incredibly useful: 16 | 17 | * A reproducible test case or series of steps 18 | * The version of our code being used 19 | * Any modifications you've made relevant to the bug 20 | * Anything unusual about your environment or deployment 21 | 22 | 23 | ## Contributing via Pull Requests 24 | Contributions via pull requests are much appreciated. Before sending us a pull request, please ensure that: 25 | 26 | 1. You are working against the latest source on the *master* branch. 27 | 2. You check existing open, and recently merged, pull requests to make sure someone else hasn't addressed the problem already. 28 | 3. You open an issue to discuss any significant work - we would hate for your time to be wasted. 29 | 30 | To send us a pull request, please: 31 | 32 | 1. Fork the repository. 33 | 2. Modify the source; please focus on the specific change you are contributing. If you also reformat all the code, it will be hard for us to focus on your change. 34 | 3. Ensure local tests pass. 35 | 4. Commit to your fork using clear commit messages. 36 | 5. Send us a pull request, answering any default questions in the pull request interface. 37 | 6. Pay attention to any automated CI failures reported in the pull request, and stay involved in the conversation. 38 | 39 | GitHub provides additional document on [forking a repository](https://help.github.com/articles/fork-a-repo/) and 40 | [creating a pull request](https://help.github.com/articles/creating-a-pull-request/). 41 | 42 | 43 | ## Finding contributions to work on 44 | Looking at the existing issues is a great way to find something to contribute on. As our projects, by default, use the default GitHub issue labels (enhancement/bug/duplicate/help wanted/invalid/question/wontfix), looking at any 'help wanted' issues is a great place to start. 45 | 46 | 47 | ## Code of Conduct 48 | This project has adopted the [Amazon Open Source Code of Conduct](https://aws.github.io/code-of-conduct). 49 | For more information see the [Code of Conduct FAQ](https://aws.github.io/code-of-conduct-faq) or contact 50 | opensource-codeofconduct@amazon.com with any additional questions or comments. 51 | 52 | 53 | ## Security issue notifications 54 | If you discover a potential security issue in this project we ask that you notify AWS/Amazon Security via our [vulnerability reporting page](http://aws.amazon.com/security/vulnerability-reporting/). Please do **not** create a public github issue. 55 | 56 | 57 | ## Licensing 58 | 59 | See the [LICENSE](LICENSE) file for our project's licensing. We will ask you to confirm the licensing of your contribution. 60 | -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- 1 | Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. 2 | 3 | Permission is hereby granted, free of charge, to any person obtaining a copy of 4 | this software and associated documentation files (the "Software"), to deal in 5 | the Software without restriction, including without limitation the rights to 6 | use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of 7 | the Software, and to permit persons to whom the Software is furnished to do so. 8 | 9 | THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR 10 | IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS 11 | FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR 12 | COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER 13 | IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN 14 | CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. 15 | 16 | -------------------------------------------------------------------------------- /LambdaWordpress/bin/lambda_wordpress.d.ts: -------------------------------------------------------------------------------- 1 | #!/usr/bin/env node 2 | import 'source-map-support/register'; 3 | -------------------------------------------------------------------------------- /LambdaWordpress/bin/lambda_wordpress.js: -------------------------------------------------------------------------------- 1 | #!/usr/bin/env node 2 | "use strict"; 3 | Object.defineProperty(exports, "__esModule", { value: true }); 4 | require("source-map-support/register"); 5 | const cdk = require("@aws-cdk/core"); 6 | const lambda_wordpress_stack_1 = require("../lib/lambda_wordpress-stack"); 7 | const app = new cdk.App(); 8 | new lambda_wordpress_stack_1.LambdaWordpressStack(app, 'LambdaWordpressStack'); 9 | //# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoibGFtYmRhX3dvcmRwcmVzcy5qcyIsInNvdXJjZVJvb3QiOiIiLCJzb3VyY2VzIjpbImxhbWJkYV93b3JkcHJlc3MudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6Ijs7O0FBQ0EsdUNBQXFDO0FBQ3JDLHFDQUFxQztBQUNyQywwRUFBcUU7QUFFckUsTUFBTSxHQUFHLEdBQUcsSUFBSSxHQUFHLENBQUMsR0FBRyxFQUFFLENBQUM7QUFDMUIsSUFBSSw2Q0FBb0IsQ0FBQyxHQUFHLEVBQUUsc0JBQXNCLENBQUMsQ0FBQyIsInNvdXJjZXNDb250ZW50IjpbIiMhL3Vzci9iaW4vZW52IG5vZGVcbmltcG9ydCAnc291cmNlLW1hcC1zdXBwb3J0L3JlZ2lzdGVyJztcbmltcG9ydCAqIGFzIGNkayBmcm9tICdAYXdzLWNkay9jb3JlJztcbmltcG9ydCB7IExhbWJkYVdvcmRwcmVzc1N0YWNrIH0gZnJvbSAnLi4vbGliL2xhbWJkYV93b3JkcHJlc3Mtc3RhY2snO1xuXG5jb25zdCBhcHAgPSBuZXcgY2RrLkFwcCgpO1xubmV3IExhbWJkYVdvcmRwcmVzc1N0YWNrKGFwcCwgJ0xhbWJkYVdvcmRwcmVzc1N0YWNrJyk7XG4iXX0= -------------------------------------------------------------------------------- /LambdaWordpress/bin/lambda_wordpress.ts: -------------------------------------------------------------------------------- 1 | #!/usr/bin/env node 2 | import 'source-map-support/register'; 3 | import * as cdk from '@aws-cdk/core'; 4 | import { LambdaWordpressStack } from '../lib/lambda_wordpress-stack'; 5 | 6 | const app = new cdk.App(); 7 | new LambdaWordpressStack(app, 'LambdaWordpressStack'); 8 | -------------------------------------------------------------------------------- /LambdaWordpress/cdk.json: -------------------------------------------------------------------------------- 1 | { 2 | "app": "npx ts-node bin/lambda_wordpress.ts", 3 | "context": { 4 | "@aws-cdk/core:enableStackNameDuplicates": "true", 5 | "aws-cdk:enableDiffNoFail": "true", 6 | "domainName": "forhead.online", 7 | "keyName": "virginia", 8 | "dbPassword":"dbPassword0!" 9 | } 10 | } 11 | -------------------------------------------------------------------------------- /LambdaWordpress/jest.config.js: -------------------------------------------------------------------------------- 1 | module.exports = { 2 | roots: ['/test'], 3 | testMatch: ['**/*.test.ts'], 4 | transform: { 5 | '^.+\\.tsx?$': 'ts-jest' 6 | } 7 | }; 8 | -------------------------------------------------------------------------------- /LambdaWordpress/lib/lambda_wordpress-stack.d.ts: -------------------------------------------------------------------------------- 1 | import * as cdk from '@aws-cdk/core'; 2 | export declare class LambdaWordpressStack extends cdk.Stack { 3 | constructor(scope: cdk.Construct, id: string, props?: cdk.StackProps); 4 | } 5 | -------------------------------------------------------------------------------- /LambdaWordpress/lib/lambda_wordpress-stack.js: -------------------------------------------------------------------------------- 1 | "use strict"; 2 | Object.defineProperty(exports, "__esModule", { value: true }); 3 | exports.LambdaWordpressStack = void 0; 4 | const cdk = require("@aws-cdk/core"); 5 | const ec2 = require("@aws-cdk/aws-ec2"); 6 | const efs = require("@aws-cdk/aws-efs"); 7 | const lambda = require("@aws-cdk/aws-lambda"); 8 | const rds = require("@aws-cdk/aws-rds"); 9 | const elbv2 = require("@aws-cdk/aws-elasticloadbalancingv2"); 10 | const targets = require("@aws-cdk/aws-elasticloadbalancingv2-targets"); 11 | const cm = require("@aws-cdk/aws-certificatemanager"); 12 | const aws_elasticloadbalancingv2_1 = require("@aws-cdk/aws-elasticloadbalancingv2"); 13 | const path = require("path"); 14 | class LambdaWordpressStack extends cdk.Stack { 15 | constructor(scope, id, props) { 16 | super(scope, id, props); 17 | var DB_HOST = null; 18 | var HTTP_HOST = null; 19 | const DB_NAME = 'wordpress'; 20 | const DB_USER = 'wordpressuser'; 21 | const BASE_PATH = '/mnt/efs'; 22 | const ACCESSPOINT_PATH = '/wordpress'; 23 | const WORDPRESS_PATH = '/mnt/efs'; 24 | const KEY_NAME = this.node.tryGetContext('keyName'); 25 | const DOMAIN_NAME = this.node.tryGetContext('domainName'); 26 | const DB_PASSWORD = this.node.tryGetContext('dbPassword'); 27 | //set the certificate 28 | const myCertificate = new cm.Certificate(this, 'myCertificate', { 29 | domainName: DOMAIN_NAME, 30 | validation: cm.CertificateValidation.fromDns(), 31 | }); 32 | //create VPC 33 | const serverlessVPC = new ec2.Vpc(this, 'serverlessWordpressVPC', { 34 | cidr: '10.0.0.0/16', 35 | subnetConfiguration: [ 36 | { 37 | subnetType: ec2.SubnetType.PUBLIC, 38 | name: 'public', 39 | cidrMask: 24, 40 | }, 41 | { 42 | cidrMask: 24, 43 | name: 'private', 44 | subnetType: ec2.SubnetType.PRIVATE, 45 | }, 46 | ], 47 | }); 48 | /** 49 | * create security group in VPC 50 | */ 51 | // NFS security group which used for ec2 to copy file 52 | const sgNFSSG = new ec2.SecurityGroup(this, 'NFSAllowAllSG', { 53 | vpc: serverlessVPC, 54 | description: 'allow 2049 inbound for ec2', 55 | allowAllOutbound: true, 56 | }); 57 | sgNFSSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(2049), 'allow 2049 inbound from ec2'); 58 | //ALB security group which allow 80 and 443 59 | const albSG = new ec2.SecurityGroup(this, 'albSG', { 60 | vpc: serverlessVPC, 61 | description: 'allow 80 and 443', 62 | allowAllOutbound: true, 63 | }); 64 | albSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(80), 'allow 80 inbound'); 65 | albSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(443), 'allow 443 inbound'); 66 | //EC2 security group which allow port 22 67 | const ec2SG = new ec2.SecurityGroup(this, 'ec2SG', { 68 | vpc: serverlessVPC, 69 | description: 'allow 22 inbound for ec2', 70 | allowAllOutbound: true, 71 | }); 72 | ec2SG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(22), 'allow 22 inbound from ec2'); 73 | // RDS security group which allow port 3306 74 | const rdsSG = new ec2.SecurityGroup(this, 'wordpressRdsSecurityGroup', { 75 | vpc: serverlessVPC, 76 | description: 'allow 3306 inbound', 77 | allowAllOutbound: true, 78 | }); 79 | rdsSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(3306), 'allow 3306 inbound from lambda'); 80 | /** 81 | * create EFS attached on Lambda 82 | */ 83 | const fileSystem = new efs.FileSystem(this, 'wordpressEFS', { 84 | vpc: serverlessVPC, 85 | encrypted: false, 86 | performanceMode: efs.PerformanceMode.GENERAL_PURPOSE, 87 | throughputMode: efs.ThroughputMode.BURSTING, 88 | securityGroup: sgNFSSG, 89 | removalPolicy: cdk.RemovalPolicy.DESTROY, 90 | }); 91 | //create access point on efs 92 | const accessPoint = fileSystem.addAccessPoint('LambdaAccessPoint', { 93 | path: ACCESSPOINT_PATH, 94 | createAcl: { 95 | ownerUid: '1000', 96 | ownerGid: '1000', 97 | permissions: '0777', 98 | }, 99 | posixUser: { 100 | uid: '1000', 101 | gid: '1000', 102 | }, 103 | }); 104 | /** 105 | * Create lambda function 106 | */ 107 | const lambdaFunc = new lambda.Function(this, 'wordpressLambdaFUnction', { 108 | code: lambda.Code.fromAsset(path.join(__dirname, 'phpLambdaFunc')), 109 | handler: 'handler.php', 110 | memorySize: 1024, 111 | timeout: cdk.Duration.minutes(15), 112 | tracing: lambda.Tracing.ACTIVE, 113 | runtime: lambda.Runtime.PROVIDED, 114 | layers: [lambda.LayerVersion.fromLayerVersionArn(this, 'customPhpLayer', 'arn:aws:lambda:us-east-1:887080169480:layer:php73:3')], 115 | vpc: serverlessVPC, 116 | filesystem: lambda.FileSystem.fromEfsAccessPoint(accessPoint, BASE_PATH), 117 | }); 118 | /* 119 | * create alb and integrate it with lambda 120 | */ 121 | const lb = new elbv2.ApplicationLoadBalancer(this, 'serverlessALB', { 122 | vpc: serverlessVPC, 123 | internetFacing: true, 124 | securityGroup: albSG, 125 | }); 126 | const lambdaTarget = new targets.LambdaTarget(lambdaFunc); 127 | const albTargetGroup = new elbv2.ApplicationTargetGroup(this, 'albTargetGroup', { 128 | targets: [lambdaTarget], 129 | }); 130 | albTargetGroup.setAttribute('lambda.multi_value_headers.enabled', 'true'); 131 | const listener80 = lb.addListener('Listener80', { 132 | port: 80, 133 | open: true, 134 | }); 135 | listener80.addAction('80action', { 136 | action: aws_elasticloadbalancingv2_1.ListenerAction.forward([albTargetGroup]) 137 | }); 138 | const listener443 = lb.addListener('Listener443', { 139 | port: 443, 140 | open: true, 141 | certificateArns: [myCertificate.certificateArn], 142 | }); 143 | listener443.addAction('443action', { 144 | action: aws_elasticloadbalancingv2_1.ListenerAction.forward([albTargetGroup]) 145 | }); 146 | /** 147 | * create RDS 148 | */ 149 | const secret = cdk.SecretValue.plainText(DB_PASSWORD); 150 | const auroraServerlessCluster = new rds.DatabaseCluster(this, 'ServerlessWordpressAuroraCluster', { 151 | engine: rds.DatabaseClusterEngine.AURORA_MYSQL, 152 | credentials: rds.Credentials.fromPassword(DB_USER, secret), 153 | removalPolicy: cdk.RemovalPolicy.DESTROY, 154 | instanceProps: { 155 | vpc: serverlessVPC, 156 | securityGroups: [rdsSG], 157 | }, 158 | defaultDatabaseName: DB_NAME, 159 | }); 160 | /*** 161 | * set the DB_HOST and HTTP_HOST which will used in the lambda environment 162 | */ 163 | DB_HOST = auroraServerlessCluster.clusterEndpoint.hostname; 164 | HTTP_HOST = lb.loadBalancerDnsName; 165 | //SET lambda enviromnent 166 | lambdaFunc.addEnvironment('DB_HOST', DB_HOST); 167 | lambdaFunc.addEnvironment('DB_NAME', DB_NAME); 168 | lambdaFunc.addEnvironment('DB_USER', DB_USER); 169 | lambdaFunc.addEnvironment('DB_PASSWORD', DB_PASSWORD); 170 | lambdaFunc.addEnvironment('WORDPRESS_PATH', WORDPRESS_PATH); 171 | lambdaFunc.addEnvironment('HTTP_HOST', HTTP_HOST); 172 | // create EC2 which used to install wordpress files to EFS 173 | const amznLinux = ec2.MachineImage.latestAmazonLinux({ 174 | generation: ec2.AmazonLinuxGeneration.AMAZON_LINUX, 175 | edition: ec2.AmazonLinuxEdition.STANDARD, 176 | virtualization: ec2.AmazonLinuxVirt.HVM, 177 | storage: ec2.AmazonLinuxStorage.GENERAL_PURPOSE, 178 | }); 179 | const ec2EFS = new ec2.Instance(this, 'efsInstance', { 180 | vpc: serverlessVPC, 181 | vpcSubnets: { subnetType: ec2.SubnetType.PUBLIC }, 182 | machineImage: amznLinux, 183 | instanceType: new ec2.InstanceType('t2.large'), 184 | securityGroup: ec2SG, 185 | keyName: KEY_NAME, 186 | }); 187 | ec2EFS.userData.addCommands( 188 | //install efs tool and create mount point 189 | 'sudo yum install -y amazon-efs-utils', 'sudo mkdir /mnt', 'sudo mkdir /mnt/efs'); 190 | new cdk.CfnOutput(this, 'outputEFS', { 191 | description: 'efs id', 192 | value: 'efs id: ' + fileSystem.fileSystemId, 193 | }); 194 | new cdk.CfnOutput(this, 'outputALBDNS', { 195 | description: 'alb dns name', 196 | value: 'alb dns name: ' + lb.loadBalancerDnsName, 197 | }); 198 | } 199 | } 200 | exports.LambdaWordpressStack = LambdaWordpressStack; 201 | //# sourceMappingURL=data:application/json;base64,{"version":3,"file":"lambda_wordpress-stack.js","sourceRoot":"","sources":["lambda_wordpress-stack.ts"],"names":[],"mappings":";;;AAAA,qCAAqC;AACrC,wCAAwC;AACxC,wCAAwC;AACxC,8CAA8C;AAC9C,wCAAwC;AACxC,6DAA6D;AAC7D,uEAAuE;AACvE,sDAAsD;AACtD,oFAA+G;AAC/G,6BAA6B;AAC7B,MAAa,oBAAqB,SAAQ,GAAG,CAAC,KAAK;IACjD,YAAY,KAAoB,EAAE,EAAU,EAAE,KAAsB;QAClE,KAAK,CAAC,KAAK,EAAE,EAAE,EAAE,KAAK,CAAC,CAAC;QAExB,IAAI,OAAO,GAAG,IAAI,CAAC;QACnB,IAAI,SAAS,GAAG,IAAI,CAAC;QACrB,MAAM,OAAO,GAAG,WAAW,CAAC;QAC5B,MAAM,OAAO,GAAG,eAAe,CAAC;QAChC,MAAM,SAAS,GAAG,UAAU,CAAC;QAC7B,MAAM,gBAAgB,GAAG,YAAY,CAAC;QACtC,MAAM,cAAc,GAAG,UAAU,CAAC;QAClC,MAAM,QAAQ,GAAG,IAAI,CAAC,IAAI,CAAC,aAAa,CAAC,SAAS,CAAC,CAAC;QACpD,MAAM,WAAW,GAAG,IAAI,CAAC,IAAI,CAAC,aAAa,CAAC,YAAY,CAAC,CAAC;QAC1D,MAAM,WAAW,GAAG,IAAI,CAAC,IAAI,CAAC,aAAa,CAAC,YAAY,CAAC,CAAC;QAE1D,qBAAqB;QACrB,MAAM,aAAa,GAAG,IAAI,EAAE,CAAC,WAAW,CAAC,IAAI,EAAE,eAAe,EAAC;YAC7D,UAAU,EAAE,WAAW;YACvB,UAAU,EAAE,EAAE,CAAC,qBAAqB,CAAC,OAAO,EAAE;SAC/C,CAAC,CAAC;QAEH,aAAa;QACb,MAAM,aAAa,GAAG,IAAI,GAAG,CAAC,GAAG,CAAC,IAAI,EAAE,wBAAwB,EAAE;YAChE,IAAI,EAAE,aAAa;YACnB,mBAAmB,EAAE;gBACnB;oBACE,UAAU,EAAE,GAAG,CAAC,UAAU,CAAC,MAAM;oBACjC,IAAI,EAAE,QAAQ;oBACd,QAAQ,EAAE,EAAE;iBACb;gBACD;oBACE,QAAQ,EAAE,EAAE;oBACZ,IAAI,EAAE,SAAS;oBACf,UAAU,EAAE,GAAG,CAAC,UAAU,CAAC,OAAO;iBACnC;aACF;SACF,CAAC,CAAC;QAEH;;WAEG;QACH,qDAAqD;QACrD,MAAM,OAAO,GAAG,IAAI,GAAG,CAAC,aAAa,CAAC,IAAI,EAAE,eAAe,EAAE;YAC3D,GAAG,EAAE,aAAa;YAClB,WAAW,EAAE,4BAA4B;YACzC,gBAAgB,EAAE,IAAI;SACvB,CAAC,CAAC;QACH,OAAO,CAAC,cAAc,CAAC,GAAG,CAAC,IAAI,CAAC,OAAO,EAAE,EAAE,GAAG,CAAC,IAAI,CAAC,GAAG,CAAC,IAAI,CAAC,EAAE,6BAA6B,CAAC,CAAA;QAE7F,2CAA2C;QAC3C,MAAM,KAAK,GAAG,IAAI,GAAG,CAAC,aAAa,CAAC,IAAI,EAAE,OAAO,EAAE;YACjD,GAAG,EAAE,aAAa;YAClB,WAAW,EAAE,kBAAkB;YAC/B,gBAAgB,EAAE,IAAI;SACvB,CAAC,CAAC;QACH,KAAK,CAAC,cAAc,CAAC,GAAG,CAAC,IAAI,CAAC,OAAO,EAAE,EAAE,GAAG,CAAC,IAAI,CAAC,GAAG,CAAC,EAAE,CAAC,EAAE,kBAAkB,CAAC,CAAC;QAC/E,KAAK,CAAC,cAAc,CAAC,GAAG,CAAC,IAAI,CAAC,OAAO,EAAE,EAAE,GAAG,CAAC,IAAI,CAAC,GAAG,CAAC,GAAG,CAAC,EAAE,mBAAmB,CAAC,CAAC;QAEjF,wCAAwC;QACxC,MAAM,KAAK,GAAG,IAAI,GAAG,CAAC,aAAa,CAAC,IAAI,EAAE,OAAO,EAAE;YACjD,GAAG,EAAE,aAAa;YAClB,WAAW,EAAE,0BAA0B;YACvC,gBAAgB,EAAE,IAAI;SACvB,CAAC,CAAC;QACH,KAAK,CAAC,cAAc,CAAC,GAAG,CAAC,IAAI,CAAC,OAAO,EAAE,EAAE,GAAG,CAAC,IAAI,CAAC,GAAG,CAAC,EAAE,CAAC,EAAE,2BAA2B,CAAC,CAAA;QAEvF,2CAA2C;QAC3C,MAAM,KAAK,GAAG,IAAI,GAAG,CAAC,aAAa,CAAC,IAAI,EAAE,2BAA2B,EAAE;YACrE,GAAG,EAAE,aAAa;YAClB,WAAW,EAAE,oBAAoB;YACjC,gBAAgB,EAAE,IAAI;SACvB,CAAC,CAAC;QACH,KAAK,CAAC,cAAc,CAAC,GAAG,CAAC,IAAI,CAAC,OAAO,EAAE,EAAE,GAAG,CAAC,IAAI,CAAC,GAAG,CAAC,IAAI,CAAC,EAAE,gCAAgC,CAAC,CAAC;QAE/F;;WAEG;QACH,MAAM,UAAU,GAAG,IAAI,GAAG,CAAC,UAAU,CAAC,IAAI,EAAE,cAAc,EAAE;YAC1D,GAAG,EAAE,aAAa;YAClB,SAAS,EAAE,KAAK;YAChB,eAAe,EAAE,GAAG,CAAC,eAAe,CAAC,eAAe;YACpD,cAAc,EAAE,GAAG,CAAC,cAAc,CAAC,QAAQ;YAC3C,aAAa,EAAE,OAAO;YACtB,aAAa,EAAE,GAAG,CAAC,aAAa,CAAC,OAAO;SACzC,CAAC,CAAC;QACH,4BAA4B;QAC5B,MAAM,WAAW,GAAG,UAAU,CAAC,cAAc,CAAC,mBAAmB,EAAE;YACjE,IAAI,EAAE,gBAAgB;YACtB,SAAS,EAAE;gBACT,QAAQ,EAAE,MAAM;gBAChB,QAAQ,EAAE,MAAM;gBAChB,WAAW,EAAE,MAAM;aACpB;YACD,SAAS,EAAE;gBACT,GAAG,EAAE,MAAM;gBACX,GAAG,EAAE,MAAM;aACZ;SACF,CAAC,CAAC;QAEH;;WAEG;QACH,MAAM,UAAU,GAAG,IAAI,MAAM,CAAC,QAAQ,CAAC,IAAI,EAAE,yBAAyB,EAAE;YACtE,IAAI,EAAE,MAAM,CAAC,IAAI,CAAC,SAAS,CAAC,IAAI,CAAC,IAAI,CAAC,SAAS,EAAE,eAAe,CAAC,CAAC;YAClE,OAAO,EAAE,aAAa;YACtB,UAAU,EAAE,IAAI;YAChB,OAAO,EAAE,GAAG,CAAC,QAAQ,CAAC,OAAO,CAAC,EAAE,CAAC;YACjC,OAAO,EAAE,MAAM,CAAC,OAAO,CAAC,MAAM;YAC9B,OAAO,EAAE,MAAM,CAAC,OAAO,CAAC,QAAQ;YAChC,MAAM,EAAE,CAAC,MAAM,CAAC,YAAY,CAAC,mBAAmB,CAAC,IAAI,EAAE,gBAAgB,EAAE,qDAAqD,CAAC,CAAC;YAChI,GAAG,EAAE,aAAa;YAClB,UAAU,EAAE,MAAM,CAAC,UAAU,CAAC,kBAAkB,CAAC,WAAW,EAAE,SAAS,CAAC;SACzE,CAAC,CAAC;QAEH;;WAEG;QACH,MAAM,EAAE,GAAG,IAAI,KAAK,CAAC,uBAAuB,CAAC,IAAI,EAAE,eAAe,EAAE;YAClE,GAAG,EAAE,aAAa;YAClB,cAAc,EAAE,IAAI;YACpB,aAAa,EAAE,KAAK;SACrB,CAAC,CAAC;QAEH,MAAM,YAAY,GAAG,IAAI,OAAO,CAAC,YAAY,CAAC,UAAU,CAAC,CAAC;QAC1D,MAAM,cAAc,GAAG,IAAI,KAAK,CAAC,sBAAsB,CAAC,IAAI,EAAC,gBAAgB,EAAC;YAC5E,OAAO,EAAE,CAAC,YAAY,CAAC;SACxB,CAAC,CAAC;QACH,cAAc,CAAC,YAAY,CAAC,oCAAoC,EAAE,MAAM,CAAC,CAAC;QAE1E,MAAM,UAAU,GAAG,EAAE,CAAC,WAAW,CAAC,YAAY,EAAE;YAC9C,IAAI,EAAE,EAAE;YACR,IAAI,EAAE,IAAI;SACX,CAAC,CAAC;QACH,UAAU,CAAC,SAAS,CAAC,UAAU,EAAC;YAC9B,MAAM,EAAE,2CAAc,CAAC,OAAO,CAAC,CAAC,cAAc,CAAC,CAAC;SACjD,CAAC,CAAC;QAEH,MAAM,WAAW,GAAG,EAAE,CAAC,WAAW,CAAC,aAAa,EAAE;YAChD,IAAI,EAAE,GAAG;YACT,IAAI,EAAE,IAAI;YACV,eAAe,EAAC,CAAC,aAAa,CAAC,cAAc,CAAC;SAC/C,CAAC,CAAC;QACH,WAAW,CAAC,SAAS,CAAC,WAAW,EAAC;YAChC,MAAM,EAAE,2CAAc,CAAC,OAAO,CAAC,CAAC,cAAc,CAAC,CAAC;SACjD,CAAC,CAAC;QAEH;;WAEG;QAEH,MAAM,MAAM,GAAG,GAAG,CAAC,WAAW,CAAC,SAAS,CAAC,WAAW,CAAC,CAAC;QACtD,MAAM,uBAAuB,GAAG,IAAI,GAAG,CAAC,eAAe,CAAC,IAAI,EAAE,kCAAkC,EAAE;YAChG,MAAM,EAAE,GAAG,CAAC,qBAAqB,CAAC,YAAY;YAC9C,WAAW,EAAE,GAAG,CAAC,WAAW,CAAC,YAAY,CAAC,OAAO,EAAC,MAAM,CAAC;YACzD,aAAa,EAAE,GAAG,CAAC,aAAa,CAAC,OAAO;YACxC,aAAa,EAAE;gBACb,GAAG,EAAE,aAAa;gBAClB,cAAc,EAAE,CAAC,KAAK,CAAC;aACxB;YACD,mBAAmB,EAAE,OAAO;SAC7B,CAAC,CAAC;QAEH;;WAEG;QACH,OAAO,GAAG,uBAAuB,CAAC,eAAe,CAAC,QAAQ,CAAC;QAC3D,SAAS,GAAG,EAAE,CAAC,mBAAmB,CAAC;QAEnC,wBAAwB;QACxB,UAAU,CAAC,cAAc,CAAC,SAAS,EAAE,OAAO,CAAC,CAAC;QAC9C,UAAU,CAAC,cAAc,CAAC,SAAS,EAAE,OAAO,CAAC,CAAC;QAC9C,UAAU,CAAC,cAAc,CAAC,SAAS,EAAE,OAAO,CAAC,CAAC;QAC9C,UAAU,CAAC,cAAc,CAAC,aAAa,EAAE,WAAW,CAAC,CAAC;QACtD,UAAU,CAAC,cAAc,CAAC,gBAAgB,EAAE,cAAc,CAAC,CAAC;QAC5D,UAAU,CAAC,cAAc,CAAC,WAAW,EAAE,SAAS,CAAC,CAAC;QAElD,0DAA0D;QAC1D,MAAM,SAAS,GAAG,GAAG,CAAC,YAAY,CAAC,iBAAiB,CAAC;YACnD,UAAU,EAAE,GAAG,CAAC,qBAAqB,CAAC,YAAY;YAClD,OAAO,EAAE,GAAG,CAAC,kBAAkB,CAAC,QAAQ;YACxC,cAAc,EAAE,GAAG,CAAC,eAAe,CAAC,GAAG;YACvC,OAAO,EAAE,GAAG,CAAC,kBAAkB,CAAC,eAAe;SAChD,CAAC,CAAC;QAEH,MAAM,MAAM,GAAG,IAAI,GAAG,CAAC,QAAQ,CAAC,IAAI,EAAC,aAAa,EAAC;YACjD,GAAG,EAAE,aAAa;YAClB,UAAU,EAAE,EAAC,UAAU,EAAC,GAAG,CAAC,UAAU,CAAC,MAAM,EAAC;YAC9C,YAAY,EAAG,SAAS;YACxB,YAAY,EAAE,IAAI,GAAG,CAAC,YAAY,CAAC,UAAU,CAAC;YAC9C,aAAa,EAAE,KAAK;YACpB,OAAO,EAAC,QAAQ;SACjB,CAAC,CAAC;QAEH,MAAM,CAAC,QAAQ,CAAC,WAAW;QACzB,yCAAyC;QACzC,sCAAsC,EACtC,iBAAiB,EACjB,qBAAqB,CACtB,CAAC;QAEF,IAAI,GAAG,CAAC,SAAS,CAAC,IAAI,EAAE,WAAW,EAAE;YACnC,WAAW,EAAE,QAAQ;YACrB,KAAK,EAAE,UAAU,GAAE,UAAU,CAAC,YAAY;SAC3C,CAAC,CAAC;QAEH,IAAI,GAAG,CAAC,SAAS,CAAC,IAAI,EAAE,cAAc,EAAE;YACtC,WAAW,EAAE,cAAc;YAC3B,KAAK,EAAE,gBAAgB,GAAE,EAAE,CAAC,mBAAmB;SAChD,CAAC,CAAC;IACL,CAAC;CACF;AAlND,oDAkNC","sourcesContent":["import * as cdk from '@aws-cdk/core';\nimport * as ec2 from '@aws-cdk/aws-ec2';\nimport * as efs from '@aws-cdk/aws-efs';\nimport * as lambda from '@aws-cdk/aws-lambda';\nimport * as rds from '@aws-cdk/aws-rds';\nimport * as elbv2 from '@aws-cdk/aws-elasticloadbalancingv2';\nimport * as targets from '@aws-cdk/aws-elasticloadbalancingv2-targets';\nimport * as cm from '@aws-cdk/aws-certificatemanager';\nimport {ApplicationTargetGroup, ApplicationProtocol, ListenerAction} from '@aws-cdk/aws-elasticloadbalancingv2'\nimport * as path from 'path';\nexport class LambdaWordpressStack extends cdk.Stack {\n  constructor(scope: cdk.Construct, id: string, props?: cdk.StackProps) {\n    super(scope, id, props);\n\n    var DB_HOST = null;\n    var HTTP_HOST = null;\n    const DB_NAME = 'wordpress';\n    const DB_USER = 'wordpressuser';\n    const BASE_PATH = '/mnt/efs';\n    const ACCESSPOINT_PATH = '/wordpress';\n    const WORDPRESS_PATH = '/mnt/efs';\n    const KEY_NAME = this.node.tryGetContext('keyName');\n    const DOMAIN_NAME = this.node.tryGetContext('domainName');\n    const DB_PASSWORD = this.node.tryGetContext('dbPassword');\n\n    //set the certificate\n    const myCertificate = new cm.Certificate(this, 'myCertificate',{\n      domainName: DOMAIN_NAME,\n      validation: cm.CertificateValidation.fromDns(),\n    });\n\n    //create VPC \n    const serverlessVPC = new ec2.Vpc(this, 'serverlessWordpressVPC', {\n      cidr: '10.0.0.0/16',\n      subnetConfiguration: [\n        {\n          subnetType: ec2.SubnetType.PUBLIC,\n          name: 'public',\n          cidrMask: 24,\n        },\n        {\n          cidrMask: 24,\n          name: 'private',\n          subnetType: ec2.SubnetType.PRIVATE,\n        },\n      ],\n    });\n\n    /**\n     * create security group in VPC\n     */\n    // NFS security group which used for ec2 to copy file\n    const sgNFSSG = new ec2.SecurityGroup(this, 'NFSAllowAllSG', {\n      vpc: serverlessVPC,\n      description: 'allow 2049 inbound for ec2',\n      allowAllOutbound: true,\n    });\n    sgNFSSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(2049), 'allow 2049 inbound from ec2')\n\n    //ALB security group which allow 80 and 443\n    const albSG = new ec2.SecurityGroup(this, 'albSG', {\n      vpc: serverlessVPC,\n      description: 'allow 80 and 443',\n      allowAllOutbound: true,\n    });\n    albSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(80), 'allow 80 inbound');\n    albSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(443), 'allow 443 inbound');\n\n    //EC2 security group which allow port 22\n    const ec2SG = new ec2.SecurityGroup(this, 'ec2SG', {\n      vpc: serverlessVPC,\n      description: 'allow 22 inbound for ec2',\n      allowAllOutbound: true,\n    });\n    ec2SG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(22), 'allow 22 inbound from ec2')\n\n    // RDS security group which allow port 3306\n    const rdsSG = new ec2.SecurityGroup(this, 'wordpressRdsSecurityGroup', {\n      vpc: serverlessVPC,\n      description: 'allow 3306 inbound',\n      allowAllOutbound: true,\n    });\n    rdsSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(3306), 'allow 3306 inbound from lambda');\n\n    /**\n     * create EFS attached on Lambda\n     */\n    const fileSystem = new efs.FileSystem(this, 'wordpressEFS', {\n      vpc: serverlessVPC,\n      encrypted: false,\n      performanceMode: efs.PerformanceMode.GENERAL_PURPOSE,\n      throughputMode: efs.ThroughputMode.BURSTING,\n      securityGroup: sgNFSSG,\n      removalPolicy: cdk.RemovalPolicy.DESTROY,\n    });\n    //create access point on efs\n    const accessPoint = fileSystem.addAccessPoint('LambdaAccessPoint', {\n      path: ACCESSPOINT_PATH,\n      createAcl: {\n        ownerUid: '1000',\n        ownerGid: '1000',\n        permissions: '0777',\n      },\n      posixUser: {\n        uid: '1000',\n        gid: '1000',\n      },\n    });\n\n    /**\n     * Create lambda function\n     */\n    const lambdaFunc = new lambda.Function(this, 'wordpressLambdaFUnction', {\n      code: lambda.Code.fromAsset(path.join(__dirname, 'phpLambdaFunc')),\n      handler: 'handler.php',\n      memorySize: 1024,\n      timeout: cdk.Duration.minutes(15),\n      tracing: lambda.Tracing.ACTIVE,\n      runtime: lambda.Runtime.PROVIDED,\n      layers: [lambda.LayerVersion.fromLayerVersionArn(this, 'customPhpLayer', 'arn:aws:lambda:us-east-1:887080169480:layer:php73:3')],\n      vpc: serverlessVPC,\n      filesystem: lambda.FileSystem.fromEfsAccessPoint(accessPoint, BASE_PATH),\n    });\n\n    /*\n     * create alb and integrate it with lambda\n     */\n    const lb = new elbv2.ApplicationLoadBalancer(this, 'serverlessALB', {\n      vpc: serverlessVPC,\n      internetFacing: true,\n      securityGroup: albSG,\n    });\n\n    const lambdaTarget = new targets.LambdaTarget(lambdaFunc);\n    const albTargetGroup = new elbv2.ApplicationTargetGroup(this,'albTargetGroup',{\n      targets: [lambdaTarget],\n    });\n    albTargetGroup.setAttribute('lambda.multi_value_headers.enabled', 'true');\n\n    const listener80 = lb.addListener('Listener80', {\n      port: 80,\n      open: true,\n    });\n    listener80.addAction('80action',{\n      action: ListenerAction.forward([albTargetGroup])\n    });\n\n    const listener443 = lb.addListener('Listener443', {\n      port: 443,\n      open: true,\n      certificateArns:[myCertificate.certificateArn],\n    });\n    listener443.addAction('443action',{\n      action: ListenerAction.forward([albTargetGroup])\n    });\n\n    /**\n     * create RDS\n     */\n\n    const secret = cdk.SecretValue.plainText(DB_PASSWORD);\n    const auroraServerlessCluster = new rds.DatabaseCluster(this, 'ServerlessWordpressAuroraCluster', {\n      engine: rds.DatabaseClusterEngine.AURORA_MYSQL,\n      credentials: rds.Credentials.fromPassword(DB_USER,secret),\n      removalPolicy: cdk.RemovalPolicy.DESTROY,\n      instanceProps: {\n        vpc: serverlessVPC,\n        securityGroups: [rdsSG],\n      },\n      defaultDatabaseName: DB_NAME,\n    });\n\n    /***\n     *  set the DB_HOST and HTTP_HOST which will used in the lambda environment\n     */\n    DB_HOST = auroraServerlessCluster.clusterEndpoint.hostname;\n    HTTP_HOST = lb.loadBalancerDnsName;\n\n    //SET lambda enviromnent\n    lambdaFunc.addEnvironment('DB_HOST', DB_HOST);\n    lambdaFunc.addEnvironment('DB_NAME', DB_NAME);\n    lambdaFunc.addEnvironment('DB_USER', DB_USER);\n    lambdaFunc.addEnvironment('DB_PASSWORD', DB_PASSWORD);\n    lambdaFunc.addEnvironment('WORDPRESS_PATH', WORDPRESS_PATH);\n    lambdaFunc.addEnvironment('HTTP_HOST', HTTP_HOST);\n\n    // create EC2 which used to install wordpress files to EFS\n    const amznLinux = ec2.MachineImage.latestAmazonLinux({\n      generation: ec2.AmazonLinuxGeneration.AMAZON_LINUX,\n      edition: ec2.AmazonLinuxEdition.STANDARD,\n      virtualization: ec2.AmazonLinuxVirt.HVM,\n      storage: ec2.AmazonLinuxStorage.GENERAL_PURPOSE,\n    });\n\n    const ec2EFS = new ec2.Instance(this,'efsInstance',{\n      vpc: serverlessVPC,\n      vpcSubnets: {subnetType:ec2.SubnetType.PUBLIC},\n      machineImage : amznLinux,\n      instanceType: new ec2.InstanceType('t2.large'),\n      securityGroup: ec2SG,\n      keyName:KEY_NAME,\n    });\n\n    ec2EFS.userData.addCommands(\n      //install efs tool and create mount point\n      'sudo yum install -y amazon-efs-utils',\n      'sudo mkdir /mnt',\n      'sudo mkdir /mnt/efs',\n    );\n\n    new cdk.CfnOutput(this, 'outputEFS', {\n      description: 'efs id',\n      value: 'efs id: ' +fileSystem.fileSystemId,\n    });\n\n    new cdk.CfnOutput(this, 'outputALBDNS', {\n      description: 'alb dns name',\n      value: 'alb dns name: ' +lb.loadBalancerDnsName,\n    });\n  }\n}\n"]} -------------------------------------------------------------------------------- /LambdaWordpress/lib/lambda_wordpress-stack.ts: -------------------------------------------------------------------------------- 1 | import * as cdk from '@aws-cdk/core'; 2 | import * as ec2 from '@aws-cdk/aws-ec2'; 3 | import * as efs from '@aws-cdk/aws-efs'; 4 | import * as lambda from '@aws-cdk/aws-lambda'; 5 | import * as rds from '@aws-cdk/aws-rds'; 6 | import * as elbv2 from '@aws-cdk/aws-elasticloadbalancingv2'; 7 | import * as targets from '@aws-cdk/aws-elasticloadbalancingv2-targets'; 8 | import * as cm from '@aws-cdk/aws-certificatemanager'; 9 | import {ApplicationTargetGroup, ApplicationProtocol, ListenerAction} from '@aws-cdk/aws-elasticloadbalancingv2' 10 | import * as path from 'path'; 11 | export class LambdaWordpressStack extends cdk.Stack { 12 | constructor(scope: cdk.Construct, id: string, props?: cdk.StackProps) { 13 | super(scope, id, props); 14 | 15 | var DB_HOST = null; 16 | var HTTP_HOST = null; 17 | const DB_NAME = 'wordpress'; 18 | const DB_USER = 'wordpressuser'; 19 | const BASE_PATH = '/mnt/efs'; 20 | const ACCESSPOINT_PATH = '/wordpress'; 21 | const WORDPRESS_PATH = '/mnt/efs'; 22 | const KEY_NAME = this.node.tryGetContext('keyName'); 23 | const DOMAIN_NAME = this.node.tryGetContext('domainName'); 24 | const DB_PASSWORD = this.node.tryGetContext('dbPassword'); 25 | 26 | //set the certificate 27 | const myCertificate = new cm.Certificate(this, 'myCertificate',{ 28 | domainName: DOMAIN_NAME, 29 | validation: cm.CertificateValidation.fromDns(), 30 | }); 31 | 32 | //create VPC 33 | const serverlessVPC = new ec2.Vpc(this, 'serverlessWordpressVPC', { 34 | cidr: '10.0.0.0/16', 35 | subnetConfiguration: [ 36 | { 37 | subnetType: ec2.SubnetType.PUBLIC, 38 | name: 'public', 39 | cidrMask: 24, 40 | }, 41 | { 42 | cidrMask: 24, 43 | name: 'private', 44 | subnetType: ec2.SubnetType.PRIVATE, 45 | }, 46 | ], 47 | }); 48 | 49 | /** 50 | * create security group in VPC 51 | */ 52 | // NFS security group which used for ec2 to copy file 53 | const sgNFSSG = new ec2.SecurityGroup(this, 'NFSAllowAllSG', { 54 | vpc: serverlessVPC, 55 | description: 'allow 2049 inbound for ec2', 56 | allowAllOutbound: true, 57 | }); 58 | sgNFSSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(2049), 'allow 2049 inbound from ec2') 59 | 60 | //ALB security group which allow 80 and 443 61 | const albSG = new ec2.SecurityGroup(this, 'albSG', { 62 | vpc: serverlessVPC, 63 | description: 'allow 80 and 443', 64 | allowAllOutbound: true, 65 | }); 66 | albSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(80), 'allow 80 inbound'); 67 | albSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(443), 'allow 443 inbound'); 68 | 69 | //EC2 security group which allow port 22 70 | const ec2SG = new ec2.SecurityGroup(this, 'ec2SG', { 71 | vpc: serverlessVPC, 72 | description: 'allow 22 inbound for ec2', 73 | allowAllOutbound: true, 74 | }); 75 | ec2SG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(22), 'allow 22 inbound from ec2') 76 | 77 | // RDS security group which allow port 3306 78 | const rdsSG = new ec2.SecurityGroup(this, 'wordpressRdsSecurityGroup', { 79 | vpc: serverlessVPC, 80 | description: 'allow 3306 inbound', 81 | allowAllOutbound: true, 82 | }); 83 | rdsSG.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(3306), 'allow 3306 inbound from lambda'); 84 | 85 | /** 86 | * create EFS attached on Lambda 87 | */ 88 | const fileSystem = new efs.FileSystem(this, 'wordpressEFS', { 89 | vpc: serverlessVPC, 90 | encrypted: false, 91 | performanceMode: efs.PerformanceMode.GENERAL_PURPOSE, 92 | throughputMode: efs.ThroughputMode.BURSTING, 93 | securityGroup: sgNFSSG, 94 | removalPolicy: cdk.RemovalPolicy.DESTROY, 95 | }); 96 | //create access point on efs 97 | const accessPoint = fileSystem.addAccessPoint('LambdaAccessPoint', { 98 | path: ACCESSPOINT_PATH, 99 | createAcl: { 100 | ownerUid: '1000', 101 | ownerGid: '1000', 102 | permissions: '0777', 103 | }, 104 | posixUser: { 105 | uid: '1000', 106 | gid: '1000', 107 | }, 108 | }); 109 | 110 | /** 111 | * Create lambda function 112 | */ 113 | const lambdaFunc = new lambda.Function(this, 'wordpressLambdaFUnction', { 114 | code: lambda.Code.fromAsset(path.join(__dirname, 'phpLambdaFunc')), 115 | handler: 'handler.php', 116 | memorySize: 1024, 117 | timeout: cdk.Duration.minutes(15), 118 | tracing: lambda.Tracing.ACTIVE, 119 | runtime: lambda.Runtime.PROVIDED, 120 | layers: [lambda.LayerVersion.fromLayerVersionArn(this, 'customPhpLayer', 'arn:aws:lambda:us-east-1:887080169480:layer:php73:3')], 121 | vpc: serverlessVPC, 122 | filesystem: lambda.FileSystem.fromEfsAccessPoint(accessPoint, BASE_PATH), 123 | }); 124 | 125 | /* 126 | * create alb and integrate it with lambda 127 | */ 128 | const lb = new elbv2.ApplicationLoadBalancer(this, 'serverlessALB', { 129 | vpc: serverlessVPC, 130 | internetFacing: true, 131 | securityGroup: albSG, 132 | }); 133 | 134 | const lambdaTarget = new targets.LambdaTarget(lambdaFunc); 135 | const albTargetGroup = new elbv2.ApplicationTargetGroup(this,'albTargetGroup',{ 136 | targets: [lambdaTarget], 137 | }); 138 | albTargetGroup.setAttribute('lambda.multi_value_headers.enabled', 'true'); 139 | 140 | const listener80 = lb.addListener('Listener80', { 141 | port: 80, 142 | open: true, 143 | }); 144 | listener80.addAction('80action',{ 145 | action: ListenerAction.forward([albTargetGroup]) 146 | }); 147 | 148 | const listener443 = lb.addListener('Listener443', { 149 | port: 443, 150 | open: true, 151 | certificateArns:[myCertificate.certificateArn], 152 | }); 153 | listener443.addAction('443action',{ 154 | action: ListenerAction.forward([albTargetGroup]) 155 | }); 156 | 157 | /** 158 | * create RDS 159 | */ 160 | 161 | const secret = cdk.SecretValue.plainText(DB_PASSWORD); 162 | const auroraServerlessCluster = new rds.DatabaseCluster(this, 'ServerlessWordpressAuroraCluster', { 163 | engine: rds.DatabaseClusterEngine.AURORA_MYSQL, 164 | credentials: rds.Credentials.fromPassword(DB_USER,secret), 165 | removalPolicy: cdk.RemovalPolicy.DESTROY, 166 | instanceProps: { 167 | vpc: serverlessVPC, 168 | securityGroups: [rdsSG], 169 | }, 170 | defaultDatabaseName: DB_NAME, 171 | }); 172 | 173 | /*** 174 | * set the DB_HOST and HTTP_HOST which will used in the lambda environment 175 | */ 176 | DB_HOST = auroraServerlessCluster.clusterEndpoint.hostname; 177 | HTTP_HOST = lb.loadBalancerDnsName; 178 | 179 | //SET lambda enviromnent 180 | lambdaFunc.addEnvironment('DB_HOST', DB_HOST); 181 | lambdaFunc.addEnvironment('DB_NAME', DB_NAME); 182 | lambdaFunc.addEnvironment('DB_USER', DB_USER); 183 | lambdaFunc.addEnvironment('DB_PASSWORD', DB_PASSWORD); 184 | lambdaFunc.addEnvironment('WORDPRESS_PATH', WORDPRESS_PATH); 185 | lambdaFunc.addEnvironment('HTTP_HOST', HTTP_HOST); 186 | 187 | // create EC2 which used to install wordpress files to EFS 188 | const amznLinux = ec2.MachineImage.latestAmazonLinux({ 189 | generation: ec2.AmazonLinuxGeneration.AMAZON_LINUX, 190 | edition: ec2.AmazonLinuxEdition.STANDARD, 191 | virtualization: ec2.AmazonLinuxVirt.HVM, 192 | storage: ec2.AmazonLinuxStorage.GENERAL_PURPOSE, 193 | }); 194 | 195 | const ec2EFS = new ec2.Instance(this,'efsInstance',{ 196 | vpc: serverlessVPC, 197 | vpcSubnets: {subnetType:ec2.SubnetType.PUBLIC}, 198 | machineImage : amznLinux, 199 | instanceType: new ec2.InstanceType('t2.large'), 200 | securityGroup: ec2SG, 201 | keyName:KEY_NAME, 202 | }); 203 | 204 | ec2EFS.userData.addCommands( 205 | //install efs tool and create mount point 206 | 'sudo yum install -y amazon-efs-utils', 207 | 'sudo mkdir /mnt', 208 | 'sudo mkdir /mnt/efs', 209 | ); 210 | 211 | new cdk.CfnOutput(this, 'outputEFS', { 212 | description: 'efs id', 213 | value: 'efs id: ' +fileSystem.fileSystemId, 214 | }); 215 | 216 | new cdk.CfnOutput(this, 'outputALBDNS', { 217 | description: 'alb dns name', 218 | value: 'alb dns name: ' +lb.loadBalancerDnsName, 219 | }); 220 | } 221 | } 222 | -------------------------------------------------------------------------------- /LambdaWordpress/lib/phpLambdaFunc/Makefile: -------------------------------------------------------------------------------- 1 | build-WordpressFunction: 2 | cp ./*.php ./*.ini $(ARTIFACTS_DIR) -------------------------------------------------------------------------------- /LambdaWordpress/lib/phpLambdaFunc/handler.php: -------------------------------------------------------------------------------- 1 | "text/css", 7 | "js" => "application/javascript", 8 | "png" => "image/png", 9 | "jpeg" => "image/jpeg", 10 | "jpg" => "image/jpeg", 11 | "svg" => "image/svg+xml" 12 | ); 13 | 14 | $request_uri = explode("?", $_SERVER['REQUEST_URI']); 15 | $local_file_path = getenv('WORDPRESS_PATH') . $request_uri[0]; 16 | 17 | $split = explode(".", $local_file_path); 18 | $extension = strtolower(array_pop($split)); 19 | $mapped_type = null; 20 | if (isset($extension_map[$extension])) { 21 | $mapped_type = $extension_map[$extension]; 22 | } 23 | 24 | if ( $mapped_type && file_exists( $local_file_path ) ) { 25 | header("Content-Type: {$mapped_type}"); 26 | readfile($local_file_path); 27 | 28 | } elseif ( $extension == "php" && file_exists( $local_file_path ) ) { 29 | require( $local_file_path ); 30 | 31 | } elseif ( substr($local_file_path, -1) == "/" && file_exists( $local_file_path . "index.php" ) ) { 32 | $exec_file_path = $local_file_path . "index.php"; 33 | require( $exec_file_path ); 34 | 35 | } else { 36 | $exec_file_path = getenv('WORDPRESS_PATH') . '/index.php'; 37 | require( $exec_file_path ); 38 | } 39 | -------------------------------------------------------------------------------- /LambdaWordpress/lib/phpLambdaFunc/php.ini: -------------------------------------------------------------------------------- 1 | extension=json 2 | extension=curl 3 | extension=mbstring 4 | extension=mysqlnd 5 | extension=mysqli 6 | extension=iconv 7 | extension=gettext 8 | extension=fileinfo 9 | extension=simplexml 10 | 11 | memory_limit = 1024M 12 | -------------------------------------------------------------------------------- /LambdaWordpress/package.json: -------------------------------------------------------------------------------- 1 | { 2 | "name": "lambda_wordpress", 3 | "version": "0.1.0", 4 | "bin": { 5 | "lambda_wordpress": "bin/lambda_wordpress.js" 6 | }, 7 | "scripts": { 8 | "build": "tsc", 9 | "watch": "tsc -w", 10 | "test": "jest", 11 | "cdk": "cdk" 12 | }, 13 | "dependencies": { 14 | "@aws-cdk/assert": "^1.180.0", 15 | "@aws-cdk/aws-certificatemanager": "^1.180.0", 16 | "@aws-cdk/aws-ec2": "^1.180.0", 17 | "@aws-cdk/aws-efs": "^1.180.0", 18 | "@aws-cdk/aws-elasticloadbalancingv2": "^1.180.0", 19 | "@aws-cdk/aws-elasticloadbalancingv2-targets": "^1.180.0", 20 | "@aws-cdk/aws-lambda": "^1.180.0", 21 | "@aws-cdk/aws-rds": "^1.180.0", 22 | "@aws-cdk/aws-secretsmanager": "^1.180.0", 23 | "@aws-cdk/core": "^1.180.0", 24 | "@types/jest": "^26.0.10", 25 | "jest": "^26.4.2", 26 | "path": "^0.12.7" 27 | } 28 | } 29 | -------------------------------------------------------------------------------- /LambdaWordpress/test/lambda_wordpress.test.d.ts: -------------------------------------------------------------------------------- 1 | export {}; 2 | -------------------------------------------------------------------------------- /LambdaWordpress/test/lambda_wordpress.test.js: -------------------------------------------------------------------------------- 1 | "use strict"; 2 | Object.defineProperty(exports, "__esModule", { value: true }); 3 | const assert_1 = require("@aws-cdk/assert"); 4 | const cdk = require("@aws-cdk/core"); 5 | const LambdaWordpress = require("../lib/lambda_wordpress-stack"); 6 | test('Empty Stack', () => { 7 | const app = new cdk.App(); 8 | // WHEN 9 | const stack = new LambdaWordpress.LambdaWordpressStack(app, 'MyTestStack'); 10 | // THEN 11 | assert_1.expect(stack).to(assert_1.matchTemplate({ 12 | "Resources": {} 13 | }, assert_1.MatchStyle.EXACT)); 14 | }); 15 | //# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoibGFtYmRhX3dvcmRwcmVzcy50ZXN0LmpzIiwic291cmNlUm9vdCI6IiIsInNvdXJjZXMiOlsibGFtYmRhX3dvcmRwcmVzcy50ZXN0LnRzIl0sIm5hbWVzIjpbXSwibWFwcGluZ3MiOiI7O0FBQUEsNENBQWlGO0FBQ2pGLHFDQUFxQztBQUNyQyxpRUFBaUU7QUFFakUsSUFBSSxDQUFDLGFBQWEsRUFBRSxHQUFHLEVBQUU7SUFDckIsTUFBTSxHQUFHLEdBQUcsSUFBSSxHQUFHLENBQUMsR0FBRyxFQUFFLENBQUM7SUFDMUIsT0FBTztJQUNQLE1BQU0sS0FBSyxHQUFHLElBQUksZUFBZSxDQUFDLG9CQUFvQixDQUFDLEdBQUcsRUFBRSxhQUFhLENBQUMsQ0FBQztJQUMzRSxPQUFPO0lBQ1AsZUFBUyxDQUFDLEtBQUssQ0FBQyxDQUFDLEVBQUUsQ0FBQyxzQkFBYSxDQUFDO1FBQ2hDLFdBQVcsRUFBRSxFQUFFO0tBQ2hCLEVBQUUsbUJBQVUsQ0FBQyxLQUFLLENBQUMsQ0FBQyxDQUFBO0FBQ3pCLENBQUMsQ0FBQyxDQUFDIiwic291cmNlc0NvbnRlbnQiOlsiaW1wb3J0IHsgZXhwZWN0IGFzIGV4cGVjdENESywgbWF0Y2hUZW1wbGF0ZSwgTWF0Y2hTdHlsZSB9IGZyb20gJ0Bhd3MtY2RrL2Fzc2VydCc7XG5pbXBvcnQgKiBhcyBjZGsgZnJvbSAnQGF3cy1jZGsvY29yZSc7XG5pbXBvcnQgKiBhcyBMYW1iZGFXb3JkcHJlc3MgZnJvbSAnLi4vbGliL2xhbWJkYV93b3JkcHJlc3Mtc3RhY2snO1xuXG50ZXN0KCdFbXB0eSBTdGFjaycsICgpID0+IHtcbiAgICBjb25zdCBhcHAgPSBuZXcgY2RrLkFwcCgpO1xuICAgIC8vIFdIRU5cbiAgICBjb25zdCBzdGFjayA9IG5ldyBMYW1iZGFXb3JkcHJlc3MuTGFtYmRhV29yZHByZXNzU3RhY2soYXBwLCAnTXlUZXN0U3RhY2snKTtcbiAgICAvLyBUSEVOXG4gICAgZXhwZWN0Q0RLKHN0YWNrKS50byhtYXRjaFRlbXBsYXRlKHtcbiAgICAgIFwiUmVzb3VyY2VzXCI6IHt9XG4gICAgfSwgTWF0Y2hTdHlsZS5FWEFDVCkpXG59KTtcbiJdfQ== -------------------------------------------------------------------------------- /LambdaWordpress/test/lambda_wordpress.test.ts: -------------------------------------------------------------------------------- 1 | import { expect as expectCDK, matchTemplate, MatchStyle } from '@aws-cdk/assert'; 2 | import * as cdk from '@aws-cdk/core'; 3 | import * as LambdaWordpress from '../lib/lambda_wordpress-stack'; 4 | 5 | test('Empty Stack', () => { 6 | const app = new cdk.App(); 7 | // WHEN 8 | const stack = new LambdaWordpress.LambdaWordpressStack(app, 'MyTestStack'); 9 | // THEN 10 | expectCDK(stack).to(matchTemplate({ 11 | "Resources": {} 12 | }, MatchStyle.EXACT)) 13 | }); 14 | -------------------------------------------------------------------------------- /LambdaWordpress/tsconfig.json: -------------------------------------------------------------------------------- 1 | { 2 | "compilerOptions": { 3 | "target": "ES2018", 4 | "module": "commonjs", 5 | "lib": ["es2018"], 6 | "declaration": true, 7 | "strict": true, 8 | "noImplicitAny": true, 9 | "strictNullChecks": true, 10 | "noImplicitThis": true, 11 | "alwaysStrict": true, 12 | "noUnusedLocals": false, 13 | "noUnusedParameters": false, 14 | "noImplicitReturns": true, 15 | "noFallthroughCasesInSwitch": false, 16 | "inlineSourceMap": true, 17 | "inlineSources": true, 18 | "experimentalDecorators": true, 19 | "strictPropertyInitialization": false, 20 | "typeRoots": ["./node_modules/@types"] 21 | }, 22 | "exclude": ["cdk.out"] 23 | } 24 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | this project is archived. please check another similar project 2 | 3 | https://github.com/aws-samples/serverless-woocommerce-workshop 4 | 5 | # cdk-serverless-wordpress 6 | 7 | ## what does this repo do 8 | 9 | this project help to run the serverless wordpress with AWS Lambda and AWS EFS 10 | 11 | ### init CDK project 12 | 13 | 1. run below commands to install cdk components 14 | 15 | ```ts 16 | npm install @aws-cdk/aws-ec2 @aws-cdk/aws-efs @aws-cdk/aws-lambda @aws-cdk/aws-rds @aws-cdk/aws-elasticloadbalancingv2 @aws-cdk/aws-elasticloadbalancingv2-targets @aws-cdk/aws-secretsmanager path 17 | ``` 18 | 2. find the cdk.json file, replace the domainName, keyName, dbPassword with your own value. 19 | 20 | | | | 21 | | ---------- | --- | 22 | | domainName | your domain name, which used to validate the certificate | 23 | | keyName | the key pairs which used to login to the EC2 | 24 | | dbPassword | the rds password | 25 | 26 | 27 | 3. compile and deploy 28 | 29 | ```ts 30 | npm run build 31 | cdk deploy 32 | ``` 33 | remeber use us-east-1 region, open aws console, find Certificate Manager service and validate the certificate with DNS name, you can refer this doc https://docs.aws.amazon.com/zh_cn/acm/latest/userguide/gs-acm-validate-dns.html 34 | 35 | you can find the EFS ID at the output 36 | 37 | 4. Launch EC2 and install wordpress on EFS 38 | 39 | ``` 40 | sudo mount -t efs YOUR_EFS_ID:/ /mnt/efs 41 | ``` 42 | 43 | you can download the wordpress package and unzip them into path /mnt/efs/wordpress 44 | then edit below items in the wp-config.php file 45 | 46 | ```php 47 | define( 'DB_NAME', getenv('DB_NAME') ); 48 | define( 'DB_USER', getenv('DB_USER') ); 49 | define( 'DB_PASSWORD', getenv('DB_PASSWORD') ); 50 | define( 'DB_HOST', getenv('DB_HOST') ); 51 | define('WP_SITEURL', 'https://' . getenv('HTTP_HOST') ); 52 | define('WP_HOME', 'https://' . getenv('HTTP_HOST') ); 53 | $_SERVER['HTTP_HOST'] = getenv('HTTP_HOST') ; 54 | ``` 55 | you can also download the source from below github 56 | https://github.com/forhead/wordpressForLambda.git 57 | 58 | 5. launch the serverless wordpress with alb DNS name, you can config the dns on your own domain 59 | 60 | 61 | ## Security 62 | 63 | See [CONTRIBUTING](CONTRIBUTING.md#security-issue-notifications) for more information. 64 | 65 | ## License 66 | 67 | This library is licensed under the MIT-0 License. See the LICENSE file. 68 | 69 | --------------------------------------------------------------------------------