2025-11-17 14:19:38 +03:00
variable "username" {
description = "VK Cloud username"
type = string
}
variable "password" {
description = "VK Cloud password"
type = string
sensitive = true
}
variable "project_id" {
description = "Project ID"
type = string
}
variable "region" {
description = "Region"
type = string
default = "ME1"
}
variable "ssh_key_name" {
description = "Name of SSH key pair in VK Cloud"
type = string
}
2026-09-03 16:03:12 +03:00
variable "router_count" {
description = "Number of IaaS Router VMs to provision"
type = number
default = 2
validation {
condition = var . router_count >= 1
error_message = "router_count must be at least 1."
}
}
variable "router_availability_zones" {
description = "Availability zones to spread router VMs across (cycled via count.index)"
type = list ( string )
default = [ "ME1" ]
}
2026-09-04 10:49:24 +03:00
variable "private_network_cidrs" {
description = "Explicit CIDR prefix for each private network that router VMs get an interface into. One entry = one shared private network = one private interface per router (list order determines eth1..ethN). Must be supplied explicitly - no auto-carving from a supernet."
type = list ( string )
2026-09-03 16:03:12 +03:00
validation {
2026-09-04 10:49:24 +03:00
condition = length ( var . private_network_cidrs ) >= 1
error_message = "private_network_cidrs must contain at least one CIDR."
}
validation {
condition = alltrue ([ for c in var . private_network_cidrs : can ( cidrhost ( c , 0 ))])
error_message = "Every entry in private_network_cidrs must be a valid IPv4 CIDR (e.g. \ " 10 . 90 . 0 . 0 / 29 \ ")."
}
validation {
condition = length ( var . private_network_cidrs ) == length ( distinct ( var . private_network_cidrs ))
error_message = "private_network_cidrs entries must be unique."
2026-09-03 16:03:12 +03:00
}
}
2026-09-06 20:32:05 +03:00
variable "default_security_group_id" {
description = "Explicit override for the project's 'default' security group UUID. Last resort only - by default it's resolved dynamically via data.vkcs_networking_secgroup (see main.tf), since this UUID is unique per project and must not be hardcoded."
type = string
default = null
}