3.3 KiB
Assignment
The Nautilus DevOps team needs to set up CloudWatch logging for their application. They need to create a CloudWatch log group and log stream with the following specifications:
-
The log group name should be xfusion-log-group.
-
The log stream name should be xfusion-log-stream.
Use Terraform to create the CloudWatch log group and log stream. The Terraform working directory is /home/bob/terraform. Create the main.tf file (do not create a different .tf file) to accomplish this task.
Note: Right-click under the EXPLORER section in VS Code and select Open in Integrated Terminal to launch the terminal.
Solution
CloudWatch Logs — xfusion-log-group + xfusion-log-stream
Terraform solution to create a CloudWatch log group and a log stream nested inside it.
main.tf
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 6.0"
}
}
}
provider "aws" {
region = "us-east-1"
}
resource "aws_cloudwatch_log_group" "xfusion" {
name = "xfusion-log-group"
}
resource "aws_cloudwatch_log_stream" "xfusion" {
name = "xfusion-log-stream"
log_group_name = aws_cloudwatch_log_group.xfusion.name
}
How to run
cd /home/bob/terraform
terraform init
terraform apply -auto-approve
How it works
CloudWatch Logs has a two-level hierarchy: a log group is the container (where you set retention, encryption, and access policy), and a log stream is an ordered sequence of log events inside a group, typically one per source (an instance, container, or function). This task creates one of each.
aws_cloudwatch_log_group
name = "xfusion-log-group"— the group name, exactly as required.- No
retention_in_daysis set, so logs are retained indefinitely (the AWS default). The task doesn't specify retention, so the default is fine; you'd addretention_in_days = Nif a policy required expiring logs.
aws_cloudwatch_log_stream
-
name = "xfusion-log-stream"— the stream name, exactly as required. -
log_group_name = aws_cloudwatch_log_group.xfusion.name— a stream can't exist on its own; it must live inside a group. Referencing the group resource'snameattribute (rather than hardcoding the string) does two things:- It wires the value correctly, and
- it creates an implicit dependency so Terraform provisions the group before the stream. Without that ordering, the stream create would fail because its parent group wouldn't exist yet.
This is why no explicit
depends_onis needed — the attribute reference expresses the dependency for you.
Ordering matters
The dependency direction is one-way: group first, then stream. On destroy,
Terraform reverses it automatically — stream removed before group — so teardown is
clean too.
Verify
# Confirm the group exists
aws logs describe-log-groups \
--log-group-name-prefix xfusion-log-group \
--query 'logGroups[0].{Name:logGroupName,Retention:retentionInDays}'
# Confirm the stream exists inside it
aws logs describe-log-streams \
--log-group-name xfusion-log-group \
--query 'logStreams[?logStreamName==`xfusion-log-stream`].logStreamName'
Expected — the group xfusion-log-group (retention null = never expire), and the
stream query returning ["xfusion-log-stream"].