{"id":43244540,"url":"https://github.com/huzefaaa2/terraform-apigee-enterprise-stack","last_synced_at":"2026-02-01T12:04:15.041Z","repository":{"id":334785693,"uuid":"1142743988","full_name":"Huzefaaa2/terraform-apigee-enterprise-stack","owner":"Huzefaaa2","description":"Production-grade Terraform Stack for Apigee X on GCP (Enterprise-ready, opinionated, secure-by-default)","archived":false,"fork":false,"pushed_at":"2026-01-27T03:20:53.000Z","size":3037,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-01-27T07:46:35.245Z","etag":null,"topics":["apigee","cicd","enterprise-solutions","gcp","secure-by-default","secure-by-design","terraform","terraform-module","terraform-stack","terraform-stacks"],"latest_commit_sha":null,"homepage":"https://github.com/Huzefaaa2/terraform-apigee-enterprise-stack/wiki","language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Huzefaaa2.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-01-26T19:58:32.000Z","updated_at":"2026-01-27T06:14:01.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/Huzefaaa2/terraform-apigee-enterprise-stack","commit_stats":null,"previous_names":["huzefaaa2/terraform-apigee-enterprise-stack"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/Huzefaaa2/terraform-apigee-enterprise-stack","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Huzefaaa2%2Fterraform-apigee-enterprise-stack","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Huzefaaa2%2Fterraform-apigee-enterprise-stack/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Huzefaaa2%2Fterraform-apigee-enterprise-stack/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Huzefaaa2%2Fterraform-apigee-enterprise-stack/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Huzefaaa2","download_url":"https://codeload.github.com/Huzefaaa2/terraform-apigee-enterprise-stack/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Huzefaaa2%2Fterraform-apigee-enterprise-stack/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28977671,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-01T11:31:13.034Z","status":"ssl_error","status_checked_at":"2026-02-01T11:30:25.558Z","response_time":56,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["apigee","cicd","enterprise-solutions","gcp","secure-by-default","secure-by-design","terraform","terraform-module","terraform-stack","terraform-stacks"],"created_at":"2026-02-01T12:03:41.070Z","updated_at":"2026-02-01T12:04:15.026Z","avatar_url":"https://github.com/Huzefaaa2.png","language":"HCL","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Terraform Apigee Enterprise Stack (GCP) - Production-Grade Terraform Stacks Reference Architecture\n\n**terraform-apigee-enterprise-stack** is an opinionated, **enterprise-ready** reference implementation for deploying **Apigee X on Google Cloud (GCP)** using **Terraform Stacks**.  \nIt gives platform teams a repeatable way to provision **Apigee Org, Instances, Environments, EnvGroups, networking, DNS, IAM, and KMS (CMEK)** with secure-by-default patterns.\n\n\u003e Keywords: Terraform Apigee X, Apigee Terraform, Apigee X Terraform Stack, GCP API Management Terraform, Apigee enterprise architecture, Apigee landing zone, Apigee private ingress, Apigee CMEK, Apigee multi-region HA.\n\n---\n\n## Why this repository exists\n\nMany Apigee Terraform examples are either low-level or incomplete for enterprise rollouts. This stack provides:\n\n- **Terraform Stacks-first** structure for platform engineering and multi-environment workflows\n- **Secure-by-default** networking patterns (private ingress, controlled egress, IAM least privilege)\n- **Enterprise readiness**: CMEK, logging/monitoring hooks, clear separation of duties, production checklists\n- **Battle-tested repo hygiene**: examples, docs, diagrams, changelog, CI scaffolding\n\n---\n\n## What you can deploy\n\n### Apigee control plane (platform)\n- Apigee Org (existing Google Cloud Org / project model)\n- Apigee X Instances (single region or multi-region)\n- Apigee Environments and EnvGroups\n- Hostnames + DNS record structure (authoritative DNS external to this repo is supported)\n\n### Enterprise foundations\n- Networking patterns for Apigee runtime access (**private ingress** supported)\n- **Cloud KMS (CMEK)** for supported resources (where applicable)\n- IAM roles and service accounts for platform vs application teams\n\n---\n\n## Architecture diagrams\n\nMermaid renders (colorful by default):\n\n```mermaid\n%%{init: {\"theme\":\"base\",\"themeVariables\":{\"primaryColor\":\"#D9F0FF\",\"primaryTextColor\":\"#0F172A\",\"secondaryColor\":\"#FFE1D6\",\"tertiaryColor\":\"#E6FFFA\",\"lineColor\":\"#334155\",\"fontFamily\":\"Inter, ui-sans-serif, system-ui\"}}}%%\nflowchart LR\n  User((Client)) --\u003e|HTTPS| Edge[\"Public DNS and TLS certs\"]\n  Edge --\u003e|Private access| LB[\"Ingress ILB or Gateway\"]\n  LB --\u003e Apigee[\"Apigee X Runtime\"]\n  Apigee --\u003e|mTLS private| PSC[\"Private Service Connect\"]\n  PSC --\u003e Backends[\"GCP services or private backends\"]\n  Apigee --\u003e Logs[\"Cloud Logging\"]\n  Apigee --\u003e Mon[\"Cloud Monitoring\"]\n```\n\n```mermaid\n%%{init: {\"theme\":\"base\",\"themeVariables\":{\"primaryColor\":\"#E0F2FE\",\"primaryTextColor\":\"#0F172A\",\"secondaryColor\":\"#FCE7F3\",\"tertiaryColor\":\"#ECFCCB\",\"lineColor\":\"#334155\",\"fontFamily\":\"Inter, ui-sans-serif, system-ui\"}}}%%\nflowchart LR\n  User((Client)) --\u003e DNS[\"Global DNS and traffic policy\"]\n  DNS --\u003e R1[\"Region A ingress\"]\n  DNS --\u003e R2[\"Region B ingress\"]\n  R1 --\u003e A[\"Apigee X Instance A\"]\n  R2 --\u003e B[\"Apigee X Instance B\"]\n  A --\u003e Backends[\"Private backends\"]\n  B --\u003e Backends\n  A --\u003e Obs[\"Central observability\"]\n  B --\u003e Obs\n```\n\n```mermaid\n%%{init: {\"theme\":\"base\",\"themeVariables\":{\"primaryColor\":\"#DCFCE7\",\"primaryTextColor\":\"#0F172A\",\"secondaryColor\":\"#FEF3C7\",\"tertiaryColor\":\"#EDE9FE\",\"lineColor\":\"#334155\",\"fontFamily\":\"Inter, ui-sans-serif, system-ui\"}}}%%\nflowchart LR\n  Dev[\"Developer\"] --\u003e PR[\"Pull request\"]\n  PR --\u003e CI[\"CI: fmt, validate, security\"]\n  CI --\u003e|pass| Plan[\"Terraform plan\"]\n  Plan --\u003e Review[\"Approval gate\"]\n  Review --\u003e Apply[\"Terraform apply\"]\n  Apply --\u003e Drift[\"Scheduled drift detection\"]\n  CI --\u003e Policy[\"OPA or Conftest policy set\"]\n  Policy --\u003e CI\n```\n\nMermaid sources:\n- `diagrams/mermaid/apigee-single-region.mmd`\n- `diagrams/mermaid/apigee-multi-region-ha.mmd`\n- `diagrams/mermaid/apigee-cicd-policy.mmd`\n\n## Docs (MkDocs)\n\nThe docs live in `docs/` and can be published with MkDocs.\n\nLocal preview:\n\n```\nmkdocs serve\n```\n\nDeploy to GitHub Pages:\n\n```\nmkdocs gh-deploy --force\n```\n\nSuggested reading order:\n\n- `docs/index.md`\n- `docs/13-implementation.md`\n\n---\n\n## Repository layout\n\n```text\nterraform-apigee-enterprise-stack/\n├── stacks/\n│   ├── apigee-platform/             # Apigee control plane + foundation components\n│   │   ├── stack.hcl                 # Terraform Stacks entrypoint\n│   │   ├── variables.tf\n│   │   ├── outputs.tf\n│   │   └── components/\n│   │       ├── iam/\n│   │       ├── kms/\n│   │       ├── networking/\n│   │       ├── org/\n│   │       ├── instances/\n│   │       ├── environments/\n│   │       └── envgroups/\n│   └── runtime/                      # Optional runtime ingress/DNS patterns\n│       ├── stack.hcl\n│       ├── components/\n│       │   ├── ingress/\n│       │   ├── dns/\n│       │   └── observability/\n├── policies/                         # Policy-as-code examples (OPA/Conftest-ready)\n├── examples/                         # End-to-end example deployments\n├── docs/                             # Enterprise documentation\n├── diagrams/                         # Mermaid + PNG diagrams\n└── .github/workflows/                # CI scaffolding (fmt, validate, docs)\n```\n\n---\n\n## Quickstart (10-15 minutes)\n\n\u003e This repo is designed for **platform engineering teams**. If you are new to Apigee X, start with the docs: `docs/01-overview.md`.\n\n### Prerequisites\n- Terraform \u003e= 1.6\n- Google Cloud project(s) + permissions\n- Apigee API enabled\n- A VPC strategy decided (shared VPC recommended for enterprises)\n\n### Steps\n1. Clone and enter the repo\n2. Copy an example:\n   - `examples/single-region/` (recommended first)\n3. Populate `terraform.tfvars`\n4. Run:\n   - `terraform init`\n   - `terraform plan`\n   - `terraform apply`\n\n\u003e Terraform Stacks workflow depends on your Terraform Stacks runtime (Terraform Cloud/Enterprise, or local stacks toolchain if available in your environment).  \n\u003e This repo includes both **Stacks structure** and **plain Terraform module execution** paths.\n\n---\n\n## Production checklist\n\nSee: `docs/06-production-checklist.md`\n\nHighlights:\n- Enable CMEK where supported\n- Separate projects for platform vs app teams\n- Centralized logging/monitoring and alerting\n- Define hostname strategy and certificate lifecycle\n- Adopt policy-as-code and drift detection\n\n---\n\n## Security \u0026 compliance\n\n- Least-privilege IAM patterns in `stacks/apigee-platform/components/iam`\n- CMEK/KMS scaffolding in `stacks/apigee-platform/components/kms`\n- Policy examples in `policies/`\n\nSee: `docs/05-security.md`\n\n---\n\n## Examples\n\n- `examples/single-region/` - single region baseline (prod-ready starter)\n- `examples/multi-region-ha/` - multi-region HA pattern (active/active-ish routing patterns)\n\n---\n\n## Roadmap\n\n- v1.0: Single-region platform stack + private ingress patterns + docs\n- v1.1: Multi-region HA reference + runbooks\n- v1.2: GitHub/GitLab CI templates + policy gate examples\n- v2.0: Apigee Edge -\u003e X migration helper docs and scripts\n\n---\n\n## Contributing\n\nPRs welcome. Please read `CONTRIBUTING.md` and open an issue for architectural changes.\n\n---\n\n## License\n\nMIT. See `LICENSE`.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhuzefaaa2%2Fterraform-apigee-enterprise-stack","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fhuzefaaa2%2Fterraform-apigee-enterprise-stack","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhuzefaaa2%2Fterraform-apigee-enterprise-stack/lists"}