Resolve the default security group UUID dynamically instead of hardcoding it

The "default" security group VK Cloud auto-creates in every project has
a UUID unique to that project, but main.tf hardcoded one project's UUID
across all 4 instance resources (router, priv_srv_01/02/03) - not
portable to another project. Replaced with data.vkcs_networking_secgroup
(matched by name = "default", verified against the real provider schema
via terraform providers schema -json on the local provider mirror) behind
local.default_security_group_id. The new default_security_group_id
variable is a last-resort manual override via coalesce() for projects
where the lookup doesn't fit (non-standard name/SDN) - not the normal path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
This commit is contained in:
ayurishchevandClaude Sonnet 5 committed 2026-09-06 20:32:05 +03:00
1 parent 1ef4b12143
commit b5d6367fd8
7 files changed
+174 -6

No files matched your search

+4
View File
@@ -35,6 +35,10 @@ Each entry in `private_network_cidrs` is one network shared by *all* routers - e
New Terraform variables: `router_count`, `private_network_cidrs`, `router_availability_zones` (see `terraform/variables.tf`). The post-install script is a Terraform template (`terraform/scripts/network-init.sh.tpl`) rendered per-router via `templatefile()`, matching each private interface to its expected subnet deterministically instead of guessing - it already handles any interface count, no hardcoded assumption of 2. `terraform/versions.tf` now pins the provider source (`vk-cs/vkcs`, `~> 0.17`), which was previously undeclared.
**Default security group**
Every VK Cloud project auto-creates a `default` security group with a UUID unique to that project. Rather than hardcoding one project's UUID, it's resolved dynamically via `data.vkcs_networking_secgroup` (matched by `name = "default"`) and attached to every VM through `local.default_security_group_id`. `default_security_group_id` is a Terraform variable for the rare case that lookup doesn't fit a given project (non-standard name/SDN) - treat setting it explicitly (via `terraform.tfvars` or `TF_VAR_default_security_group_id`) as a last resort, not the normal path.
**Horizontal scaling via environment variables**
`router_count` has a default and isn't set in `terraform.tfvars`, so it scales purely through `TF_VAR_router_count` using Terraform's standard `TF_VAR_<name>` convention. `private_network_cidrs` has no default and must be set somewhere - either in `terraform.tfvars` (as shipped) or overridden via `TF_VAR_private_network_cidrs` as a JSON-encoded list: