Files
ayurishchevandClaude Sonnet 5 b2d87c19d8 Add router_networks: fixed-IP router interfaces into external networks (mvm-s3)
mvm-s3 is a separate VK Cloud project whose admin pre-created two private
networks/subnets with a known IP per router. Unify project-managed
(private_network_cidrs, IPAM-assigned) and externally-owned (router_networks,
fixed-IP) private interfaces into one local.router_interfaces so both share
the existing port/dynamic-network mechanism instead of duplicating it.

Switch from implicit *.auto.tfvars loading to explicit -var-file per
environment (now two share this terraform/ directory) plus a dedicated
Terraform workspace for mvm-s3, so PROD's state and credentials are never
touched by mvm-s3 applies.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHfG9FgpMrGdrvC1QUewTw
2026-09-09 22:09:19 +03:00

118 lines
4.3 KiB
Terraform

variable "username" {
description = "VK Cloud username"
type = string
}
variable "password" {
description = "VK Cloud password"
type = string
sensitive = true
}
variable "project_id" {
description = "Project ID"
type = string
}
variable "region" {
description = "OpenStack region (VK Cloud typically has a single region, \"RegionOne\" - not to be confused with availability zones like \"ME1\"/\"MS1\")"
type = string
default = "RegionOne"
}
variable "auth_url" {
description = "VK Cloud Identity (Keystone) auth URL"
type = string
default = "https://infra.mail.ru:35357/v3/"
}
variable "user_domain_name" {
description = "Keystone domain the auth user resides in ('users' for regular accounts, 'service-users' for svc-* service accounts)"
type = string
default = "users"
}
variable "ssh_key_name" {
description = "Name of SSH key pair in VK Cloud"
type = string
}
variable "ssh_public_key" {
description = "OpenSSH public key content to register as the ssh_key_name keypair under the deploying account (Nova keypairs are per-user, not per-project - a key uploaded under a different account is invisible here). Leave null if a keypair with that name already exists under the deploying account."
type = string
default = null
}
variable "router_count" {
description = "Number of IaaS Router VMs to provision"
type = number
default = 2
validation {
condition = var.router_count >= 1
error_message = "router_count must be at least 1."
}
}
variable "router_availability_zones" {
description = "Availability zones to spread router VMs across (cycled via count.index)"
type = list(string)
default = ["ME1"]
}
variable "private_network_cidrs" {
description = "Explicit CIDR prefix for each project-managed private network that router VMs get an interface into (Terraform creates the network/subnet, Neutron IPAM assigns the address). One entry = one shared private network = one private interface per router. Optional - leave empty ([]) for a deployment that only uses var.router_networks (pre-existing externally-owned networks) for its private interfaces."
type = list(string)
default = []
validation {
condition = alltrue([for c in var.private_network_cidrs : can(cidrhost(c, 0))])
error_message = "Every entry in private_network_cidrs must be a valid IPv4 CIDR (e.g. \"10.90.0.0/29\")."
}
validation {
condition = length(var.private_network_cidrs) == length(distinct(var.private_network_cidrs))
error_message = "private_network_cidrs entries must be unique."
}
}
variable "router_networks" {
description = "Pre-existing private networks (typically owned by a different VK Cloud project, referenced by UUID only - not managed by this Terraform) that each router VM gets a fixed-IP interface into. Map key = role/interface name (e.g. \"primary\"/\"backup\"); ip_addresses[i] is the address for router(i+1). Optional - leave empty ({}) for a deployment that only uses var.private_network_cidrs for its private interfaces."
type = map(object({
network_id = string
subnet_id = string
cidr = string
ip_addresses = list(string)
}))
default = {}
validation {
condition = alltrue([for r in var.router_networks : can(cidrhost(r.cidr, 0))])
error_message = "Every router_networks[*].cidr must be a valid IPv4 CIDR (e.g. \"172.16.252.8/29\")."
}
validation {
condition = alltrue([
for r in var.router_networks : alltrue([
for ip in r.ip_addresses : can(cidrhost("${ip}/32", 0))
])
])
error_message = "Every router_networks[*].ip_addresses entry must be a valid IPv4 address."
}
validation {
condition = alltrue([
for r in var.router_networks : alltrue([
for ip in r.ip_addresses : cidrhost("${ip}/${split("/", r.cidr)[1]}", 0) == cidrhost(r.cidr, 0)
])
])
error_message = "Every router_networks[*].ip_addresses entry must fall inside that role's own cidr."
}
}
variable "default_security_group_id" {
description = "Explicit override for the project's 'default' security group UUID. Last resort only - by default it's resolved dynamically via data.vkcs_networking_secgroup (see main.tf), since this UUID is unique per project and must not be hardcoded."
type = string
default = null
}