# Example of the per-environment secrets tfvars for PROD. # # terraform.tfvars stays a committed, anonymized template of non-secret # values (router_count, ssh_key_name, ...). Real credentials go here. # # Historical note: this file used to be named prod.auto.tfvars and relied on # Terraform's automatic *.auto.tfvars loading. Since a second environment # ("mvm-s3", see docs/changes/2026-09-09-mvm-s3-external-networks-*.md) now # shares this same terraform/ directory, auto-loading is no longer safe - # two *.auto.tfvars files present at once would both load and silently merge, # risking one environment's credentials leaking into another's apply. Copy # this file to prod.secrets.tfvars (gitignored - see .gitignore, pattern # *.secrets.tfvars) and pass it explicitly: # # terraform workspace select default # terraform apply -var-file=terraform.tfvars -var-file=prod.secrets.tfvars # # If you still have the old prod.auto.tfvars from before this change, rename # it to prod.secrets.tfvars yourself (its values don't need to change) - # Claude does not read or move files containing real credentials. # # Mapping from an OpenStack-style openrc.sh: # OS_AUTH_URL -> auth_url # OS_USERNAME -> username # OS_PASSWORD -> password # OS_PROJECT_ID -> project_id # OS_REGION_NAME -> region # OS_USER_DOMAIN_NAME -> user_domain_name auth_url = "https://infra.mail.ru:35357/v3/" username = "svc--svc-deployer" password = "" project_id = "" region = "RegionOne" user_domain_name = "service-users" # Optional: Nova keypairs are per-user, not per-project - a keypair uploaded # under a different account (e.g. your personal VK Cloud login) is invisible # to a service account. Set this to have Terraform register var.ssh_key_name # under the deploying account from this public key. Leave unset if a keypair # with that name already exists under the deploying account. ssh_public_key = "ssh-ed25519 AAAA... or ssh-rsa AAAA... your-public-key-content"