mvm-s3 is a separate VK Cloud project whose admin pre-created two private networks/subnets with a known IP per router. Unify project-managed (private_network_cidrs, IPAM-assigned) and externally-owned (router_networks, fixed-IP) private interfaces into one local.router_interfaces so both share the existing port/dynamic-network mechanism instead of duplicating it. Switch from implicit *.auto.tfvars loading to explicit -var-file per environment (now two share this terraform/ directory) plus a dedicated Terraform workspace for mvm-s3, so PROD's state and credentials are never touched by mvm-s3 applies. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GHfG9FgpMrGdrvC1QUewTw
37 lines
1.6 KiB
HCL
37 lines
1.6 KiB
HCL
# Non-secret shape config for the "mvm-s3" environment (a separate VK Cloud
|
|
# project from PROD - see docs/changes/2026-09-09-mvm-s3-external-networks-*.md).
|
|
# Use with -var-file explicitly (auto-load is intentionally not relied upon
|
|
# once more than one environment exists - see mvm-s3.secrets.tfvars.example).
|
|
#
|
|
# Apply against the "mvm-s3" Terraform workspace (terraform workspace new/select
|
|
# mvm-s3), never against the "default" workspace that holds PROD's state:
|
|
# terraform workspace select mvm-s3
|
|
# terraform apply -var-file=terraform.tfvars -var-file=mvm-s3.tfvars -var-file=mvm-s3.secrets.tfvars
|
|
|
|
router_count = 4
|
|
|
|
# TODO: fill in the real SSH key pair name for this project (Nova keypairs
|
|
# are per-user, not per-project - a key uploaded under a different account
|
|
# won't be visible here even if it has the same name as PROD's "mcs_ru").
|
|
ssh_key_name = "<fill in - SSH key pair name for the mvm-s3 project>"
|
|
|
|
# No project-managed private networks in this environment - both private
|
|
# interfaces come from var.router_networks below (pre-existing networks in
|
|
# another project, fixed IP per router).
|
|
private_network_cidrs = []
|
|
|
|
router_networks = {
|
|
primary = {
|
|
network_id = "25532efe-2931-4666-a090-0da3a6f18224"
|
|
subnet_id = "1fa5357c-1f11-4d20-89f4-b27a4fb56e6e"
|
|
cidr = "172.16.252.8/29"
|
|
ip_addresses = ["172.16.252.11", "172.16.252.12", "172.16.252.13", "172.16.252.14"]
|
|
}
|
|
backup = {
|
|
network_id = "2b4cc25f-55a1-4d36-a3a2-5b16414af31a"
|
|
subnet_id = "5eacbc86-e15d-4c49-8704-547a719acc23"
|
|
cidr = "172.16.252.0/29"
|
|
ip_addresses = ["172.16.252.3", "172.16.252.4", "172.16.252.5", "172.16.252.6"]
|
|
}
|
|
}
|