Files
CloudRouterAdvanced/terraform/variables.tf
T
ayurishchevandClaude Sonnet 5 b5d6367fd8 Resolve the default security group UUID dynamically instead of hardcoding it
The "default" security group VK Cloud auto-creates in every project has
a UUID unique to that project, but main.tf hardcoded one project's UUID
across all 4 instance resources (router, priv_srv_01/02/03) - not
portable to another project. Replaced with data.vkcs_networking_secgroup
(matched by name = "default", verified against the real provider schema
via terraform providers schema -json on the local provider mirror) behind
local.default_security_group_id. The new default_security_group_id
variable is a last-resort manual override via coalesce() for projects
where the lookup doesn't fit (non-standard name/SDN) - not the normal path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
2026-09-06 20:32:05 +03:00

70 lines
2.1 KiB
Terraform

variable "username" {
description = "VK Cloud username"
type = string
}
variable "password" {
description = "VK Cloud password"
type = string
sensitive = true
}
variable "project_id" {
description = "Project ID"
type = string
}
variable "region" {
description = "Region"
type = string
default = "ME1"
}
variable "ssh_key_name" {
description = "Name of SSH key pair in VK Cloud"
type = string
}
variable "router_count" {
description = "Number of IaaS Router VMs to provision"
type = number
default = 2
validation {
condition = var.router_count >= 1
error_message = "router_count must be at least 1."
}
}
variable "router_availability_zones" {
description = "Availability zones to spread router VMs across (cycled via count.index)"
type = list(string)
default = ["ME1"]
}
variable "private_network_cidrs" {
description = "Explicit CIDR prefix for each private network that router VMs get an interface into. One entry = one shared private network = one private interface per router (list order determines eth1..ethN). Must be supplied explicitly - no auto-carving from a supernet."
type = list(string)
validation {
condition = length(var.private_network_cidrs) >= 1
error_message = "private_network_cidrs must contain at least one CIDR."
}
validation {
condition = alltrue([for c in var.private_network_cidrs : can(cidrhost(c, 0))])
error_message = "Every entry in private_network_cidrs must be a valid IPv4 CIDR (e.g. \"10.90.0.0/29\")."
}
validation {
condition = length(var.private_network_cidrs) == length(distinct(var.private_network_cidrs))
error_message = "private_network_cidrs entries must be unique."
}
}
variable "default_security_group_id" {
description = "Explicit override for the project's 'default' security group UUID. Last resort only - by default it's resolved dynamically via data.vkcs_networking_secgroup (see main.tf), since this UUID is unique per project and must not be hardcoded."
type = string
default = null
}