Confirmed working against a real VK Cloud PROD deployment (3 routers, 19 resources, apply succeeded end to end). Fixes found along the way: - provider "vkcs" was never configured (versions.tf) - username/password/ project_id/region were declared but wired to nothing; added auth_url and user_domain_name to complete it. - Nova keypairs are per-user, not per-project - added an optional vkcs_compute_keypair resource (var.ssh_public_key) so Terraform can register a keypair under the deploying service account itself. - router_priv_port used a hand-computed fixed_ip offset that collided with VKCS's own auto-created service ports on each network (observed: a "network:dns" port) - now left unset so Neutron's IPAM auto-assigns, which is collision-free by construction. - vkcs_compute_instance set image_id at the top level while also booting from a volume via block_device - the provider docs say not to do this; Nova echoes back a sentinel string for image_id on a volume-booted server, which Terraform read as drift on a ForceNew attribute and wanted to destroy+recreate every already-created instance on every subsequent plan. - private_network_cidrs bumped from /29 to /28 - too tight once the platform's own reserved ports are accounted for. Also removed the priv_srv_01/02/03 demo instances and the LAN network/ security group only they used - this deployment provisions router VMs only, confirmed with the user. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
30 lines
1.4 KiB
Plaintext
30 lines
1.4 KiB
Plaintext
# Example of the *.auto.tfvars overlay pattern for real credentials.
|
|
#
|
|
# terraform.tfvars stays a committed, anonymized template. To deploy with
|
|
# real credentials (e.g. from an openrc.sh for a service account), copy this
|
|
# file to prod.auto.tfvars (gitignored - see .gitignore) and fill in real
|
|
# values. Terraform auto-loads *.auto.tfvars in addition to terraform.tfvars,
|
|
# so this layers on top of the template without ever modifying/committing it.
|
|
#
|
|
# Mapping from an OpenStack-style openrc.sh:
|
|
# OS_AUTH_URL -> auth_url
|
|
# OS_USERNAME -> username
|
|
# OS_PASSWORD -> password
|
|
# OS_PROJECT_ID -> project_id
|
|
# OS_REGION_NAME -> region
|
|
# OS_USER_DOMAIN_NAME -> user_domain_name
|
|
|
|
auth_url = "https://infra.mail.ru:35357/v3/"
|
|
username = "svc-<project_id>-svc-deployer"
|
|
password = "<real password - never commit this>"
|
|
project_id = "<project_id>"
|
|
region = "RegionOne"
|
|
user_domain_name = "service-users"
|
|
|
|
# Optional: Nova keypairs are per-user, not per-project - a keypair uploaded
|
|
# under a different account (e.g. your personal VK Cloud login) is invisible
|
|
# to a service account. Set this to have Terraform register var.ssh_key_name
|
|
# under the deploying account from this public key. Leave unset if a keypair
|
|
# with that name already exists under the deploying account.
|
|
ssh_public_key = "ssh-ed25519 AAAA... or ssh-rsa AAAA... your-public-key-content"
|