Add router_networks: fixed-IP router interfaces into external networks (mvm-s3)
mvm-s3 is a separate VK Cloud project whose admin pre-created two private networks/subnets with a known IP per router. Unify project-managed (private_network_cidrs, IPAM-assigned) and externally-owned (router_networks, fixed-IP) private interfaces into one local.router_interfaces so both share the existing port/dynamic-network mechanism instead of duplicating it. Switch from implicit *.auto.tfvars loading to explicit -var-file per environment (now two share this terraform/ directory) plus a dedicated Terraform workspace for mvm-s3, so PROD's state and credentials are never touched by mvm-s3 applies. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GHfG9FgpMrGdrvC1QUewTw
This commit is contained in:
1 parent
e7235d96c9
commit
b2d87c19d8
13 files changed
+740
-132
No files matched your search
+36
-6
@@ -61,13 +61,9 @@ variable "router_availability_zones" {
|
||||
}
|
||||
|
||||
variable "private_network_cidrs" {
|
||||
description = "Explicit CIDR prefix for each private network that router VMs get an interface into. One entry = one shared private network = one private interface per router (list order determines eth1..ethN). Must be supplied explicitly - no auto-carving from a supernet."
|
||||
description = "Explicit CIDR prefix for each project-managed private network that router VMs get an interface into (Terraform creates the network/subnet, Neutron IPAM assigns the address). One entry = one shared private network = one private interface per router. Optional - leave empty ([]) for a deployment that only uses var.router_networks (pre-existing externally-owned networks) for its private interfaces."
|
||||
type = list(string)
|
||||
|
||||
validation {
|
||||
condition = length(var.private_network_cidrs) >= 1
|
||||
error_message = "private_network_cidrs must contain at least one CIDR."
|
||||
}
|
||||
default = []
|
||||
|
||||
validation {
|
||||
condition = alltrue([for c in var.private_network_cidrs : can(cidrhost(c, 0))])
|
||||
@@ -80,6 +76,40 @@ variable "private_network_cidrs" {
|
||||
}
|
||||
}
|
||||
|
||||
variable "router_networks" {
|
||||
description = "Pre-existing private networks (typically owned by a different VK Cloud project, referenced by UUID only - not managed by this Terraform) that each router VM gets a fixed-IP interface into. Map key = role/interface name (e.g. \"primary\"/\"backup\"); ip_addresses[i] is the address for router(i+1). Optional - leave empty ({}) for a deployment that only uses var.private_network_cidrs for its private interfaces."
|
||||
type = map(object({
|
||||
network_id = string
|
||||
subnet_id = string
|
||||
cidr = string
|
||||
ip_addresses = list(string)
|
||||
}))
|
||||
default = {}
|
||||
|
||||
validation {
|
||||
condition = alltrue([for r in var.router_networks : can(cidrhost(r.cidr, 0))])
|
||||
error_message = "Every router_networks[*].cidr must be a valid IPv4 CIDR (e.g. \"172.16.252.8/29\")."
|
||||
}
|
||||
|
||||
validation {
|
||||
condition = alltrue([
|
||||
for r in var.router_networks : alltrue([
|
||||
for ip in r.ip_addresses : can(cidrhost("${ip}/32", 0))
|
||||
])
|
||||
])
|
||||
error_message = "Every router_networks[*].ip_addresses entry must be a valid IPv4 address."
|
||||
}
|
||||
|
||||
validation {
|
||||
condition = alltrue([
|
||||
for r in var.router_networks : alltrue([
|
||||
for ip in r.ip_addresses : cidrhost("${ip}/${split("/", r.cidr)[1]}", 0) == cidrhost(r.cidr, 0)
|
||||
])
|
||||
])
|
||||
error_message = "Every router_networks[*].ip_addresses entry must fall inside that role's own cidr."
|
||||
}
|
||||
}
|
||||
|
||||
variable "default_security_group_id" {
|
||||
description = "Explicit override for the project's 'default' security group UUID. Last resort only - by default it's resolved dynamically via data.vkcs_networking_secgroup (see main.tf), since this UUID is unique per project and must not be hardcoded."
|
||||
type = string
|
||||
|
||||
Reference in new issue
Block a user