Files
CloudRouterAdvanced/.gitignore
T
ayurishchevandClaude Sonnet 5 8886c1baad Fix real-deployment blockers and scope down to router-only VMs
Confirmed working against a real VK Cloud PROD deployment (3 routers,
19 resources, apply succeeded end to end). Fixes found along the way:

- provider "vkcs" was never configured (versions.tf) - username/password/
  project_id/region were declared but wired to nothing; added auth_url and
  user_domain_name to complete it.
- Nova keypairs are per-user, not per-project - added an optional
  vkcs_compute_keypair resource (var.ssh_public_key) so Terraform can
  register a keypair under the deploying service account itself.
- router_priv_port used a hand-computed fixed_ip offset that collided with
  VKCS's own auto-created service ports on each network (observed: a
  "network:dns" port) - now left unset so Neutron's IPAM auto-assigns,
  which is collision-free by construction.
- vkcs_compute_instance set image_id at the top level while also booting
  from a volume via block_device - the provider docs say not to do this;
  Nova echoes back a sentinel string for image_id on a volume-booted
  server, which Terraform read as drift on a ForceNew attribute and
  wanted to destroy+recreate every already-created instance on every
  subsequent plan.
- private_network_cidrs bumped from /29 to /28 - too tight once the
  platform's own reserved ports are accounted for.

Also removed the priv_srv_01/02/03 demo instances and the LAN network/
security group only they used - this deployment provisions router VMs
only, confirmed with the user.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
2026-09-07 08:55:15 +03:00

28 lines
663 B
Plaintext

# Local Python venv used for running terraform/tests (see terraform/tests/)
venv/
# Python
__pycache__/
*.pyc
.pytest_cache/
# Terraform local state/plugin cache (never committed)
.terraform/
.terraform.lock.hcl
*.tfstate
*.tfstate.*
*.tfplan
crash.log
crash.*.log
# Real credentials layered on top of terraform.tfvars (see terraform/prod.auto.tfvars.example) -
# terraform.tfvars itself stays a committed, anonymized template; auto-loaded
# overrides with real secrets must never be committed.
*.auto.tfvars
*.auto.tfvars.json
terraform.tfvars.local
# Claude Code session-local runtime state (not project content)
.claude/scheduled_tasks.lock
.claude/*.lock