Terraform now provisions router_count IaaS Router VMs (default 2, no longer hardcoded to router1/router2), each with 1 public + private_interface_count isolated private interfaces (no shared LAN or VRRP between routers). Both counts scale via Terraform variables and TF_VAR_* environment variables. The post-install script became a Terraform template that matches interfaces to their expected subnet by CIDR instead of a fragile "first private IP" heuristic. Added an offline pytest suite (terraform/tests/) that checks the delivery's internal consistency and runs real terraform init/validate against the actual vkcs provider schema via a project-local filesystem mirror (provider binary fetched from its GitHub releases, bypassing the region-blocked HashiCorp registry) - no cloud credentials or API calls involved. terraform/versions.tf now declares the previously-missing required_providers block. Ansible (inventory.ini, base/frr_router/keepalived roles) still assumes the old 2-router/2-NIC/VRRP topology and is not yet adapted - documented as a follow-up, not addressed here. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
86 lines
3.6 KiB
Bash
Executable File
86 lines
3.6 KiB
Bash
Executable File
#!/bin/bash
|
|
# Sets up a fully local, offline-capable Terraform toolchain for this repo:
|
|
# - a Python venv at <repo>/venv (also used for the pytest suite)
|
|
# - the terraform CLI, downloaded (with checksum verification) from a
|
|
# region-unrestricted HashiCorp releases mirror
|
|
# - the vkcs provider binary, downloaded (with checksum verification)
|
|
# directly from its GitHub releases (bypasses the HashiCorp provider
|
|
# registry, which is region-blocked in some environments), installed as
|
|
# a local filesystem-mirror provider
|
|
# - a project-local CLI config (venv/terraform.d/cli-config.tfrc) that
|
|
# points `terraform init` at that filesystem mirror instead of the
|
|
# network registry
|
|
#
|
|
# Nothing here talks to any cloud API or touches real infrastructure -
|
|
# `terraform init`/`validate` only need the provider's static schema.
|
|
#
|
|
# Usage: terraform/tests/setup-local-terraform.sh
|
|
set -euo pipefail
|
|
|
|
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
|
|
VENV_DIR="$REPO_ROOT/venv"
|
|
TF_VERSION="1.16.1"
|
|
TF_RELEASES_MIRROR="https://hashicorp-releases.mcs.mail.ru"
|
|
VKCS_PROVIDER_VERSION="0.17.2"
|
|
VKCS_PROVIDER_NAMESPACE="vk-cs"
|
|
MIRROR_BASE="$VENV_DIR/terraform.d/plugins"
|
|
CLI_CONFIG="$VENV_DIR/terraform.d/cli-config.tfrc"
|
|
|
|
echo "==> Python venv at $VENV_DIR"
|
|
if [ ! -d "$VENV_DIR" ]; then
|
|
python3 -m venv "$VENV_DIR"
|
|
fi
|
|
"$VENV_DIR/bin/pip" install -q --upgrade pip
|
|
"$VENV_DIR/bin/pip" install -q -r "$REPO_ROOT/terraform/tests/requirements.txt"
|
|
|
|
echo "==> terraform $TF_VERSION CLI at $VENV_DIR/bin/terraform"
|
|
if [ ! -x "$VENV_DIR/bin/terraform" ]; then
|
|
tmp="$(mktemp -d)"
|
|
trap 'rm -rf "$tmp"' EXIT
|
|
zip_name="terraform_${TF_VERSION}_linux_amd64.zip"
|
|
curl -sL -o "$tmp/$zip_name" "$TF_RELEASES_MIRROR/terraform/$TF_VERSION/$zip_name"
|
|
curl -sL -o "$tmp/SHA256SUMS" "$TF_RELEASES_MIRROR/terraform/$TF_VERSION/terraform_${TF_VERSION}_SHA256SUMS"
|
|
(cd "$tmp" && grep "$zip_name\$" SHA256SUMS | sha256sum -c -)
|
|
unzip -o -q "$tmp/$zip_name" -d "$VENV_DIR/bin" terraform
|
|
chmod +x "$VENV_DIR/bin/terraform"
|
|
rm -rf "$tmp"
|
|
trap - EXIT
|
|
fi
|
|
|
|
echo "==> vkcs provider $VKCS_PROVIDER_VERSION from GitHub releases (bypasses the region-blocked HashiCorp registry)"
|
|
PROVIDER_DIR="$MIRROR_BASE/registry.terraform.io/$VKCS_PROVIDER_NAMESPACE/vkcs/$VKCS_PROVIDER_VERSION/linux_amd64"
|
|
if [ ! -d "$PROVIDER_DIR" ]; then
|
|
tmp="$(mktemp -d)"
|
|
trap 'rm -rf "$tmp"' EXIT
|
|
zip_name="terraform-provider-vkcs_${VKCS_PROVIDER_VERSION}_linux_amd64.zip"
|
|
base_url="https://github.com/$VKCS_PROVIDER_NAMESPACE/terraform-provider-vkcs/releases/download/v${VKCS_PROVIDER_VERSION}"
|
|
curl -sL -o "$tmp/$zip_name" "$base_url/$zip_name"
|
|
curl -sL -o "$tmp/SHA256SUMS" "$base_url/terraform-provider-vkcs_${VKCS_PROVIDER_VERSION}_SHA256SUMS"
|
|
(cd "$tmp" && grep "$zip_name\$" SHA256SUMS | sha256sum -c -)
|
|
mkdir -p "$PROVIDER_DIR"
|
|
unzip -o -q "$tmp/$zip_name" -d "$PROVIDER_DIR"
|
|
chmod +x "$PROVIDER_DIR"/terraform-provider-vkcs*
|
|
rm -rf "$tmp"
|
|
trap - EXIT
|
|
fi
|
|
|
|
echo "==> CLI config at $CLI_CONFIG"
|
|
mkdir -p "$(dirname "$CLI_CONFIG")"
|
|
cat > "$CLI_CONFIG" <<EOF
|
|
provider_installation {
|
|
filesystem_mirror {
|
|
path = "$MIRROR_BASE"
|
|
include = ["registry.terraform.io/$VKCS_PROVIDER_NAMESPACE/vkcs"]
|
|
}
|
|
direct {
|
|
exclude = ["registry.terraform.io/$VKCS_PROVIDER_NAMESPACE/vkcs"]
|
|
}
|
|
}
|
|
EOF
|
|
|
|
echo "==> Done. To use:"
|
|
echo " export TF_CLI_CONFIG_FILE=$CLI_CONFIG"
|
|
echo " $VENV_DIR/bin/terraform -chdir=$REPO_ROOT/terraform init -backend=false"
|
|
echo " $VENV_DIR/bin/terraform -chdir=$REPO_ROOT/terraform validate"
|
|
echo " or simply: $VENV_DIR/bin/pytest $REPO_ROOT/terraform/tests -v"
|