Confirmed working against a real VK Cloud PROD deployment (3 routers, 19 resources, apply succeeded end to end). Fixes found along the way: - provider "vkcs" was never configured (versions.tf) - username/password/ project_id/region were declared but wired to nothing; added auth_url and user_domain_name to complete it. - Nova keypairs are per-user, not per-project - added an optional vkcs_compute_keypair resource (var.ssh_public_key) so Terraform can register a keypair under the deploying service account itself. - router_priv_port used a hand-computed fixed_ip offset that collided with VKCS's own auto-created service ports on each network (observed: a "network:dns" port) - now left unset so Neutron's IPAM auto-assigns, which is collision-free by construction. - vkcs_compute_instance set image_id at the top level while also booting from a volume via block_device - the provider docs say not to do this; Nova echoes back a sentinel string for image_id on a volume-booted server, which Terraform read as drift on a ForceNew attribute and wanted to destroy+recreate every already-created instance on every subsequent plan. - private_network_cidrs bumped from /29 to /28 - too tight once the platform's own reserved ports are accounted for. Also removed the priv_srv_01/02/03 demo instances and the LAN network/ security group only they used - this deployment provisions router VMs only, confirmed with the user. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
18 lines
699 B
HCL
18 lines
699 B
HCL
username = "user@domain.local"
|
|
password = "DemoUserPassw"
|
|
project_id = "XXXXXd424998422XXXXXf13ac9XXXXX"
|
|
ssh_key_name = "mcs_ru"
|
|
|
|
# Adaptive router VM count (has a default - see variables.tf - uncomment to override).
|
|
router_count = 3
|
|
# router_availability_zones = ["ME1"]
|
|
|
|
# One CIDR per private network that router VMs get an interface into.
|
|
# No default - must be supplied explicitly. List order determines eth1..ethN.
|
|
# /28 (not /29): VKCS auto-creates its own service ports on each network
|
|
# (observed: a "network:dns" port) that consume addresses from the pool
|
|
# too, and a /29 (5 usable) proved too tight in practice.
|
|
private_network_cidrs = [
|
|
"10.90.0.0/28",
|
|
"10.90.0.16/28",
|
|
] |