Fix real-deployment blockers and scope down to router-only VMs
Confirmed working against a real VK Cloud PROD deployment (3 routers, 19 resources, apply succeeded end to end). Fixes found along the way: - provider "vkcs" was never configured (versions.tf) - username/password/ project_id/region were declared but wired to nothing; added auth_url and user_domain_name to complete it. - Nova keypairs are per-user, not per-project - added an optional vkcs_compute_keypair resource (var.ssh_public_key) so Terraform can register a keypair under the deploying service account itself. - router_priv_port used a hand-computed fixed_ip offset that collided with VKCS's own auto-created service ports on each network (observed: a "network:dns" port) - now left unset so Neutron's IPAM auto-assigns, which is collision-free by construction. - vkcs_compute_instance set image_id at the top level while also booting from a volume via block_device - the provider docs say not to do this; Nova echoes back a sentinel string for image_id on a volume-booted server, which Terraform read as drift on a ForceNew attribute and wanted to destroy+recreate every already-created instance on every subsequent plan. - private_network_cidrs bumped from /29 to /28 - too tight once the platform's own reserved ports are accounted for. Also removed the priv_srv_01/02/03 demo instances and the LAN network/ security group only they used - this deployment provisions router VMs only, confirmed with the user. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
This commit is contained in:
1 parent
b5d6367fd8
commit
8886c1baad
13 files changed
+506
-171
No files matched your search
@@ -11,9 +11,17 @@ __pycache__/
|
||||
.terraform.lock.hcl
|
||||
*.tfstate
|
||||
*.tfstate.*
|
||||
*.tfplan
|
||||
crash.log
|
||||
crash.*.log
|
||||
|
||||
# Real credentials layered on top of terraform.tfvars (see terraform/prod.auto.tfvars.example) -
|
||||
# terraform.tfvars itself stays a committed, anonymized template; auto-loaded
|
||||
# overrides with real secrets must never be committed.
|
||||
*.auto.tfvars
|
||||
*.auto.tfvars.json
|
||||
terraform.tfvars.local
|
||||
|
||||
# Claude Code session-local runtime state (not project content)
|
||||
.claude/scheduled_tasks.lock
|
||||
.claude/*.lock
|
||||
Reference in new issue
Block a user