mvm-s3 is a separate VK Cloud project whose admin pre-created two private networks/subnets with a known IP per router. Unify project-managed (private_network_cidrs, IPAM-assigned) and externally-owned (router_networks, fixed-IP) private interfaces into one local.router_interfaces so both share the existing port/dynamic-network mechanism instead of duplicating it. Switch from implicit *.auto.tfvars loading to explicit -var-file per environment (now two share this terraform/ directory) plus a dedicated Terraform workspace for mvm-s3, so PROD's state and credentials are never touched by mvm-s3 applies. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GHfG9FgpMrGdrvC1QUewTw
43 lines
2.0 KiB
Plaintext
43 lines
2.0 KiB
Plaintext
# Example of the per-environment secrets tfvars for PROD.
|
|
#
|
|
# terraform.tfvars stays a committed, anonymized template of non-secret
|
|
# values (router_count, ssh_key_name, ...). Real credentials go here.
|
|
#
|
|
# Historical note: this file used to be named prod.auto.tfvars and relied on
|
|
# Terraform's automatic *.auto.tfvars loading. Since a second environment
|
|
# ("mvm-s3", see docs/changes/2026-09-09-mvm-s3-external-networks-*.md) now
|
|
# shares this same terraform/ directory, auto-loading is no longer safe -
|
|
# two *.auto.tfvars files present at once would both load and silently merge,
|
|
# risking one environment's credentials leaking into another's apply. Copy
|
|
# this file to prod.secrets.tfvars (gitignored - see .gitignore, pattern
|
|
# *.secrets.tfvars) and pass it explicitly:
|
|
#
|
|
# terraform workspace select default
|
|
# terraform apply -var-file=terraform.tfvars -var-file=prod.secrets.tfvars
|
|
#
|
|
# If you still have the old prod.auto.tfvars from before this change, rename
|
|
# it to prod.secrets.tfvars yourself (its values don't need to change) -
|
|
# Claude does not read or move files containing real credentials.
|
|
#
|
|
# Mapping from an OpenStack-style openrc.sh:
|
|
# OS_AUTH_URL -> auth_url
|
|
# OS_USERNAME -> username
|
|
# OS_PASSWORD -> password
|
|
# OS_PROJECT_ID -> project_id
|
|
# OS_REGION_NAME -> region
|
|
# OS_USER_DOMAIN_NAME -> user_domain_name
|
|
|
|
auth_url = "https://infra.mail.ru:35357/v3/"
|
|
username = "svc-<project_id>-svc-deployer"
|
|
password = "<real password - never commit this>"
|
|
project_id = "<project_id>"
|
|
region = "RegionOne"
|
|
user_domain_name = "service-users"
|
|
|
|
# Optional: Nova keypairs are per-user, not per-project - a keypair uploaded
|
|
# under a different account (e.g. your personal VK Cloud login) is invisible
|
|
# to a service account. Set this to have Terraform register var.ssh_key_name
|
|
# under the deploying account from this public key. Leave unset if a keypair
|
|
# with that name already exists under the deploying account.
|
|
ssh_public_key = "ssh-ed25519 AAAA... or ssh-rsa AAAA... your-public-key-content"
|