Files
ayurishchevandClaude Sonnet 5 5979a9a58b Add adaptive router VM/interface scaling and local delivery integrity tests
Terraform now provisions router_count IaaS Router VMs (default 2, no
longer hardcoded to router1/router2), each with 1 public +
private_interface_count isolated private interfaces (no shared LAN or
VRRP between routers). Both counts scale via Terraform variables and
TF_VAR_* environment variables. The post-install script became a
Terraform template that matches interfaces to their expected subnet by
CIDR instead of a fragile "first private IP" heuristic.

Added an offline pytest suite (terraform/tests/) that checks the
delivery's internal consistency and runs real terraform init/validate
against the actual vkcs provider schema via a project-local filesystem
mirror (provider binary fetched from its GitHub releases, bypassing the
region-blocked HashiCorp registry) - no cloud credentials or API calls
involved. terraform/versions.tf now declares the previously-missing
required_providers block.

Ansible (inventory.ini, base/frr_router/keepalived roles) still assumes
the old 2-router/2-NIC/VRRP topology and is not yet adapted - documented
as a follow-up, not addressed here.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
2026-09-03 16:03:12 +03:00

86 lines
3.6 KiB
Bash
Executable File

#!/bin/bash
# Sets up a fully local, offline-capable Terraform toolchain for this repo:
# - a Python venv at <repo>/venv (also used for the pytest suite)
# - the terraform CLI, downloaded (with checksum verification) from a
# region-unrestricted HashiCorp releases mirror
# - the vkcs provider binary, downloaded (with checksum verification)
# directly from its GitHub releases (bypasses the HashiCorp provider
# registry, which is region-blocked in some environments), installed as
# a local filesystem-mirror provider
# - a project-local CLI config (venv/terraform.d/cli-config.tfrc) that
# points `terraform init` at that filesystem mirror instead of the
# network registry
#
# Nothing here talks to any cloud API or touches real infrastructure -
# `terraform init`/`validate` only need the provider's static schema.
#
# Usage: terraform/tests/setup-local-terraform.sh
set -euo pipefail
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
VENV_DIR="$REPO_ROOT/venv"
TF_VERSION="1.16.1"
TF_RELEASES_MIRROR="https://hashicorp-releases.mcs.mail.ru"
VKCS_PROVIDER_VERSION="0.17.2"
VKCS_PROVIDER_NAMESPACE="vk-cs"
MIRROR_BASE="$VENV_DIR/terraform.d/plugins"
CLI_CONFIG="$VENV_DIR/terraform.d/cli-config.tfrc"
echo "==> Python venv at $VENV_DIR"
if [ ! -d "$VENV_DIR" ]; then
python3 -m venv "$VENV_DIR"
fi
"$VENV_DIR/bin/pip" install -q --upgrade pip
"$VENV_DIR/bin/pip" install -q -r "$REPO_ROOT/terraform/tests/requirements.txt"
echo "==> terraform $TF_VERSION CLI at $VENV_DIR/bin/terraform"
if [ ! -x "$VENV_DIR/bin/terraform" ]; then
tmp="$(mktemp -d)"
trap 'rm -rf "$tmp"' EXIT
zip_name="terraform_${TF_VERSION}_linux_amd64.zip"
curl -sL -o "$tmp/$zip_name" "$TF_RELEASES_MIRROR/terraform/$TF_VERSION/$zip_name"
curl -sL -o "$tmp/SHA256SUMS" "$TF_RELEASES_MIRROR/terraform/$TF_VERSION/terraform_${TF_VERSION}_SHA256SUMS"
(cd "$tmp" && grep "$zip_name\$" SHA256SUMS | sha256sum -c -)
unzip -o -q "$tmp/$zip_name" -d "$VENV_DIR/bin" terraform
chmod +x "$VENV_DIR/bin/terraform"
rm -rf "$tmp"
trap - EXIT
fi
echo "==> vkcs provider $VKCS_PROVIDER_VERSION from GitHub releases (bypasses the region-blocked HashiCorp registry)"
PROVIDER_DIR="$MIRROR_BASE/registry.terraform.io/$VKCS_PROVIDER_NAMESPACE/vkcs/$VKCS_PROVIDER_VERSION/linux_amd64"
if [ ! -d "$PROVIDER_DIR" ]; then
tmp="$(mktemp -d)"
trap 'rm -rf "$tmp"' EXIT
zip_name="terraform-provider-vkcs_${VKCS_PROVIDER_VERSION}_linux_amd64.zip"
base_url="https://github.com/$VKCS_PROVIDER_NAMESPACE/terraform-provider-vkcs/releases/download/v${VKCS_PROVIDER_VERSION}"
curl -sL -o "$tmp/$zip_name" "$base_url/$zip_name"
curl -sL -o "$tmp/SHA256SUMS" "$base_url/terraform-provider-vkcs_${VKCS_PROVIDER_VERSION}_SHA256SUMS"
(cd "$tmp" && grep "$zip_name\$" SHA256SUMS | sha256sum -c -)
mkdir -p "$PROVIDER_DIR"
unzip -o -q "$tmp/$zip_name" -d "$PROVIDER_DIR"
chmod +x "$PROVIDER_DIR"/terraform-provider-vkcs*
rm -rf "$tmp"
trap - EXIT
fi
echo "==> CLI config at $CLI_CONFIG"
mkdir -p "$(dirname "$CLI_CONFIG")"
cat > "$CLI_CONFIG" <<EOF
provider_installation {
filesystem_mirror {
path = "$MIRROR_BASE"
include = ["registry.terraform.io/$VKCS_PROVIDER_NAMESPACE/vkcs"]
}
direct {
exclude = ["registry.terraform.io/$VKCS_PROVIDER_NAMESPACE/vkcs"]
}
}
EOF
echo "==> Done. To use:"
echo " export TF_CLI_CONFIG_FILE=$CLI_CONFIG"
echo " $VENV_DIR/bin/terraform -chdir=$REPO_ROOT/terraform init -backend=false"
echo " $VENV_DIR/bin/terraform -chdir=$REPO_ROOT/terraform validate"
echo " or simply: $VENV_DIR/bin/pytest $REPO_ROOT/terraform/tests -v"