Resolve the default security group UUID dynamically instead of hardcoding it
The "default" security group VK Cloud auto-creates in every project has a UUID unique to that project, but main.tf hardcoded one project's UUID across all 4 instance resources (router, priv_srv_01/02/03) - not portable to another project. Replaced with data.vkcs_networking_secgroup (matched by name = "default", verified against the real provider schema via terraform providers schema -json on the local provider mirror) behind local.default_security_group_id. The new default_security_group_id variable is a last-resort manual override via coalesce() for projects where the lookup doesn't fit (non-standard name/SDN) - not the normal path. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
This commit is contained in:
1 parent
1ef4b12143
commit
b5d6367fd8
7 files changed
+174
-6
No files matched your search
@@ -35,6 +35,10 @@ Each entry in `private_network_cidrs` is one network shared by *all* routers - e
|
||||
|
||||
New Terraform variables: `router_count`, `private_network_cidrs`, `router_availability_zones` (see `terraform/variables.tf`). The post-install script is a Terraform template (`terraform/scripts/network-init.sh.tpl`) rendered per-router via `templatefile()`, matching each private interface to its expected subnet deterministically instead of guessing - it already handles any interface count, no hardcoded assumption of 2. `terraform/versions.tf` now pins the provider source (`vk-cs/vkcs`, `~> 0.17`), which was previously undeclared.
|
||||
|
||||
**Default security group**
|
||||
|
||||
Every VK Cloud project auto-creates a `default` security group with a UUID unique to that project. Rather than hardcoding one project's UUID, it's resolved dynamically via `data.vkcs_networking_secgroup` (matched by `name = "default"`) and attached to every VM through `local.default_security_group_id`. `default_security_group_id` is a Terraform variable for the rare case that lookup doesn't fit a given project (non-standard name/SDN) - treat setting it explicitly (via `terraform.tfvars` or `TF_VAR_default_security_group_id`) as a last resort, not the normal path.
|
||||
|
||||
**Horizontal scaling via environment variables**
|
||||
|
||||
`router_count` has a default and isn't set in `terraform.tfvars`, so it scales purely through `TF_VAR_router_count` using Terraform's standard `TF_VAR_<name>` convention. `private_network_cidrs` has no default and must be set somewhere - either in `terraform.tfvars` (as shipped) or overridden via `TF_VAR_private_network_cidrs` as a JSON-encoded list:
|
||||
|
||||
Reference in new issue
Block a user