mvm-s3 is a separate VK Cloud project whose admin pre-created two private networks/subnets with a known IP per router. Unify project-managed (private_network_cidrs, IPAM-assigned) and externally-owned (router_networks, fixed-IP) private interfaces into one local.router_interfaces so both share the existing port/dynamic-network mechanism instead of duplicating it. Switch from implicit *.auto.tfvars loading to explicit -var-file per environment (now two share this terraform/ directory) plus a dedicated Terraform workspace for mvm-s3, so PROD's state and credentials are never touched by mvm-s3 applies. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GHfG9FgpMrGdrvC1QUewTw
34 lines
874 B
Plaintext
34 lines
874 B
Plaintext
# Local Python venv used for running terraform/tests (see terraform/tests/)
|
|
venv/
|
|
|
|
# Python
|
|
__pycache__/
|
|
*.pyc
|
|
.pytest_cache/
|
|
|
|
# Terraform local state/plugin cache (never committed)
|
|
.terraform/
|
|
.terraform.lock.hcl
|
|
*.tfstate
|
|
*.tfstate.*
|
|
*.tfplan
|
|
crash.log
|
|
crash.*.log
|
|
|
|
# Real credentials, one file per environment, passed explicitly via
|
|
# -var-file (see terraform/*.secrets.tfvars.example) - terraform.tfvars and
|
|
# terraform/<env>.tfvars stay committed, anonymized/non-secret templates.
|
|
*.secrets.tfvars
|
|
*.secrets.tfvars.json
|
|
|
|
# Legacy *.auto.tfvars pattern (pre-dates the explicit -var-file convention
|
|
# above, kept ignored in case a stray file from before the mvm-s3 environment
|
|
# is still present locally).
|
|
*.auto.tfvars
|
|
*.auto.tfvars.json
|
|
terraform.tfvars.local
|
|
|
|
# Claude Code session-local runtime state (not project content)
|
|
.claude/scheduled_tasks.lock
|
|
.claude/*.lock
|