The "default" security group VK Cloud auto-creates in every project has a UUID unique to that project, but main.tf hardcoded one project's UUID across all 4 instance resources (router, priv_srv_01/02/03) - not portable to another project. Replaced with data.vkcs_networking_secgroup (matched by name = "default", verified against the real provider schema via terraform providers schema -json on the local provider mirror) behind local.default_security_group_id. The new default_security_group_id variable is a last-resort manual override via coalesce() for projects where the lookup doesn't fit (non-standard name/SDN) - not the normal path. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011hXR2ftXZZhJ4Y3XuSoR8r
70 lines
2.1 KiB
Terraform
70 lines
2.1 KiB
Terraform
variable "username" {
|
|
description = "VK Cloud username"
|
|
type = string
|
|
}
|
|
|
|
variable "password" {
|
|
description = "VK Cloud password"
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "project_id" {
|
|
description = "Project ID"
|
|
type = string
|
|
}
|
|
|
|
variable "region" {
|
|
description = "Region"
|
|
type = string
|
|
default = "ME1"
|
|
}
|
|
|
|
variable "ssh_key_name" {
|
|
description = "Name of SSH key pair in VK Cloud"
|
|
type = string
|
|
}
|
|
|
|
variable "router_count" {
|
|
description = "Number of IaaS Router VMs to provision"
|
|
type = number
|
|
default = 2
|
|
|
|
validation {
|
|
condition = var.router_count >= 1
|
|
error_message = "router_count must be at least 1."
|
|
}
|
|
}
|
|
|
|
variable "router_availability_zones" {
|
|
description = "Availability zones to spread router VMs across (cycled via count.index)"
|
|
type = list(string)
|
|
default = ["ME1"]
|
|
}
|
|
|
|
variable "private_network_cidrs" {
|
|
description = "Explicit CIDR prefix for each private network that router VMs get an interface into. One entry = one shared private network = one private interface per router (list order determines eth1..ethN). Must be supplied explicitly - no auto-carving from a supernet."
|
|
type = list(string)
|
|
|
|
validation {
|
|
condition = length(var.private_network_cidrs) >= 1
|
|
error_message = "private_network_cidrs must contain at least one CIDR."
|
|
}
|
|
|
|
validation {
|
|
condition = alltrue([for c in var.private_network_cidrs : can(cidrhost(c, 0))])
|
|
error_message = "Every entry in private_network_cidrs must be a valid IPv4 CIDR (e.g. \"10.90.0.0/29\")."
|
|
}
|
|
|
|
validation {
|
|
condition = length(var.private_network_cidrs) == length(distinct(var.private_network_cidrs))
|
|
error_message = "private_network_cidrs entries must be unique."
|
|
}
|
|
}
|
|
|
|
variable "default_security_group_id" {
|
|
description = "Explicit override for the project's 'default' security group UUID. Last resort only - by default it's resolved dynamically via data.vkcs_networking_secgroup (see main.tf), since this UUID is unique per project and must not be hardcoded."
|
|
type = string
|
|
default = null
|
|
}
|