Files
CloudRouterAdvanced/terraform/mvm-s3.secrets.tfvars.example
ayurishchevandClaude Sonnet 5 b2d87c19d8 Add router_networks: fixed-IP router interfaces into external networks (mvm-s3)
mvm-s3 is a separate VK Cloud project whose admin pre-created two private
networks/subnets with a known IP per router. Unify project-managed
(private_network_cidrs, IPAM-assigned) and externally-owned (router_networks,
fixed-IP) private interfaces into one local.router_interfaces so both share
the existing port/dynamic-network mechanism instead of duplicating it.

Switch from implicit *.auto.tfvars loading to explicit -var-file per
environment (now two share this terraform/ directory) plus a dedicated
Terraform workspace for mvm-s3, so PROD's state and credentials are never
touched by mvm-s3 applies.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHfG9FgpMrGdrvC1QUewTw
2026-09-09 22:09:19 +03:00

33 lines
1.5 KiB
Plaintext

# Example of the per-environment secrets tfvars for "mvm-s3".
#
# Copy this file to mvm-s3.secrets.tfvars (gitignored - see .gitignore,
# pattern *.secrets.tfvars) and fill in real values. Unlike the old
# *.auto.tfvars convention, this file is NOT auto-loaded by Terraform - pass
# it explicitly with -var-file so it can never accidentally merge with
# another environment's creds:
#
# terraform workspace select mvm-s3
# terraform apply -var-file=terraform.tfvars -var-file=mvm-s3.tfvars -var-file=mvm-s3.secrets.tfvars
#
# Mapping from an OpenStack-style openrc.sh:
# OS_AUTH_URL -> auth_url
# OS_USERNAME -> username
# OS_PASSWORD -> password
# OS_PROJECT_ID -> project_id
# OS_REGION_NAME -> region
# OS_USER_DOMAIN_NAME -> user_domain_name
auth_url = "https://infra.mail.ru:35357/v3/"
username = "<real username for the mvm-s3 project>"
password = "<real password - never commit this>"
project_id = "<mvm-s3 project_id>"
region = "RegionOne"
user_domain_name = "users"
# Optional: Nova keypairs are per-user, not per-project - a keypair uploaded
# under a different account is invisible to whichever account deploys here.
# Set this to have Terraform register var.ssh_key_name (see mvm-s3.tfvars)
# under the deploying account from this public key. Leave unset if a keypair
# with that name already exists under the deploying account.
# ssh_public_key = "ssh-ed25519 AAAA... or ssh-rsa AAAA... your-public-key-content"