Files
CloudRouterAdvanced/terraform/variables.tf
T
ayurishchevandClaude Sonnet 5 8886c1baad Fix real-deployment blockers and scope down to router-only VMs
Confirmed working against a real VK Cloud PROD deployment (3 routers,
19 resources, apply succeeded end to end). Fixes found along the way:

- provider "vkcs" was never configured (versions.tf) - username/password/
  project_id/region were declared but wired to nothing; added auth_url and
  user_domain_name to complete it.
- Nova keypairs are per-user, not per-project - added an optional
  vkcs_compute_keypair resource (var.ssh_public_key) so Terraform can
  register a keypair under the deploying service account itself.
- router_priv_port used a hand-computed fixed_ip offset that collided with
  VKCS's own auto-created service ports on each network (observed: a
  "network:dns" port) - now left unset so Neutron's IPAM auto-assigns,
  which is collision-free by construction.
- vkcs_compute_instance set image_id at the top level while also booting
  from a volume via block_device - the provider docs say not to do this;
  Nova echoes back a sentinel string for image_id on a volume-booted
  server, which Terraform read as drift on a ForceNew attribute and
  wanted to destroy+recreate every already-created instance on every
  subsequent plan.
- private_network_cidrs bumped from /29 to /28 - too tight once the
  platform's own reserved ports are accounted for.

Also removed the priv_srv_01/02/03 demo instances and the LAN network/
security group only they used - this deployment provisions router VMs
only, confirmed with the user.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
2026-09-07 08:55:15 +03:00

88 lines
3.0 KiB
Terraform

variable "username" {
description = "VK Cloud username"
type = string
}
variable "password" {
description = "VK Cloud password"
type = string
sensitive = true
}
variable "project_id" {
description = "Project ID"
type = string
}
variable "region" {
description = "OpenStack region (VK Cloud typically has a single region, \"RegionOne\" - not to be confused with availability zones like \"ME1\"/\"MS1\")"
type = string
default = "RegionOne"
}
variable "auth_url" {
description = "VK Cloud Identity (Keystone) auth URL"
type = string
default = "https://infra.mail.ru:35357/v3/"
}
variable "user_domain_name" {
description = "Keystone domain the auth user resides in ('users' for regular accounts, 'service-users' for svc-* service accounts)"
type = string
default = "users"
}
variable "ssh_key_name" {
description = "Name of SSH key pair in VK Cloud"
type = string
}
variable "ssh_public_key" {
description = "OpenSSH public key content to register as the ssh_key_name keypair under the deploying account (Nova keypairs are per-user, not per-project - a key uploaded under a different account is invisible here). Leave null if a keypair with that name already exists under the deploying account."
type = string
default = null
}
variable "router_count" {
description = "Number of IaaS Router VMs to provision"
type = number
default = 2
validation {
condition = var.router_count >= 1
error_message = "router_count must be at least 1."
}
}
variable "router_availability_zones" {
description = "Availability zones to spread router VMs across (cycled via count.index)"
type = list(string)
default = ["ME1"]
}
variable "private_network_cidrs" {
description = "Explicit CIDR prefix for each private network that router VMs get an interface into. One entry = one shared private network = one private interface per router (list order determines eth1..ethN). Must be supplied explicitly - no auto-carving from a supernet."
type = list(string)
validation {
condition = length(var.private_network_cidrs) >= 1
error_message = "private_network_cidrs must contain at least one CIDR."
}
validation {
condition = alltrue([for c in var.private_network_cidrs : can(cidrhost(c, 0))])
error_message = "Every entry in private_network_cidrs must be a valid IPv4 CIDR (e.g. \"10.90.0.0/29\")."
}
validation {
condition = length(var.private_network_cidrs) == length(distinct(var.private_network_cidrs))
error_message = "private_network_cidrs entries must be unique."
}
}
variable "default_security_group_id" {
description = "Explicit override for the project's 'default' security group UUID. Last resort only - by default it's resolved dynamically via data.vkcs_networking_secgroup (see main.tf), since this UUID is unique per project and must not be hardcoded."
type = string
default = null
}