Terraform now provisions router_count IaaS Router VMs (default 2, no longer hardcoded to router1/router2), each with 1 public + private_interface_count isolated private interfaces (no shared LAN or VRRP between routers). Both counts scale via Terraform variables and TF_VAR_* environment variables. The post-install script became a Terraform template that matches interfaces to their expected subnet by CIDR instead of a fragile "first private IP" heuristic. Added an offline pytest suite (terraform/tests/) that checks the delivery's internal consistency and runs real terraform init/validate against the actual vkcs provider schema via a project-local filesystem mirror (provider binary fetched from its GitHub releases, bypassing the region-blocked HashiCorp registry) - no cloud credentials or API calls involved. terraform/versions.tf now declares the previously-missing required_providers block. Ansible (inventory.ini, base/frr_router/keepalived roles) still assumes the old 2-router/2-NIC/VRRP topology and is not yet adapted - documented as a follow-up, not addressed here. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
72 lines
1.8 KiB
Terraform
72 lines
1.8 KiB
Terraform
variable "username" {
|
|
description = "VK Cloud username"
|
|
type = string
|
|
}
|
|
|
|
variable "password" {
|
|
description = "VK Cloud password"
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "project_id" {
|
|
description = "Project ID"
|
|
type = string
|
|
}
|
|
|
|
variable "region" {
|
|
description = "Region"
|
|
type = string
|
|
default = "ME1"
|
|
}
|
|
|
|
variable "ssh_key_name" {
|
|
description = "Name of SSH key pair in VK Cloud"
|
|
type = string
|
|
}
|
|
|
|
variable "router_count" {
|
|
description = "Number of IaaS Router VMs to provision"
|
|
type = number
|
|
default = 2
|
|
|
|
validation {
|
|
condition = var.router_count >= 1
|
|
error_message = "router_count must be at least 1."
|
|
}
|
|
}
|
|
|
|
variable "private_supernet" {
|
|
description = "Address pool from which each router's private per-interface subnets are carved (must not overlap router-lan-subnet 10.200.10.0/24)"
|
|
type = string
|
|
default = "10.90.0.0/16"
|
|
}
|
|
|
|
variable "private_subnet_prefix_length" {
|
|
description = "Prefix length of each router's private interface subnet (/29 or /28)"
|
|
type = number
|
|
default = 29
|
|
|
|
validation {
|
|
condition = contains([28, 29], var.private_subnet_prefix_length)
|
|
error_message = "private_subnet_prefix_length must be 28 or 29."
|
|
}
|
|
}
|
|
|
|
variable "router_availability_zones" {
|
|
description = "Availability zones to spread router VMs across (cycled via count.index)"
|
|
type = list(string)
|
|
default = ["ME1"]
|
|
}
|
|
|
|
variable "private_interface_count" {
|
|
description = "Number of isolated private interfaces per router VM (in addition to the single public/WAN interface)"
|
|
type = number
|
|
default = 2
|
|
|
|
validation {
|
|
condition = var.private_interface_count >= 1
|
|
error_message = "private_interface_count must be at least 1."
|
|
}
|
|
}
|