Archived
initial commit of infrastructure
This commit is contained in:
@@ -0,0 +1,132 @@
|
||||
terraform {
|
||||
required_providers {
|
||||
proxmox = {
|
||||
source = "bpg/proxmox"
|
||||
version = "0.111.0"
|
||||
}
|
||||
}
|
||||
# backend "http" {
|
||||
# address = "https://gitea.oyacoi.ru/api/packages/pyrschtjag/terraform/state/proxmox"
|
||||
# lock_address = "https://gitea.oyacoi.ru/api/packages/pyrschtjag/terraform/state/proxmox/lock"
|
||||
# unlock_address = "https://gitea.oyacoi.ru/api/packages/pyrschtjag/terraform/state/proxmox/lock"
|
||||
# lock_method = "POST"
|
||||
# unlock_method = "DELETE"
|
||||
# }
|
||||
}
|
||||
|
||||
provider "proxmox" {
|
||||
endpoint = "https://firebat.lan:8006/"
|
||||
api_token = var.proxmox_api_token
|
||||
insecure = true
|
||||
}
|
||||
|
||||
locals {
|
||||
processed_containers = {
|
||||
for k, v in var.containers : k => {
|
||||
vmid = v.vmid
|
||||
tags = (floor(v.vmid / 100) == 10) ? "general" : (floor(v.vmid / 100) == 11) ? "services" : "games"
|
||||
vlan = floor(v.vmid / 100) % 100
|
||||
ip = "10.${floor(v.vmid / 100) % 100}.0.${v.vmid % 100}"
|
||||
gw = "10.${floor(v.vmid / 100) % 100}.0.1"
|
||||
nameserver = "10.${floor(v.vmid / 100) % 100}.0.1"
|
||||
memory = v.memory
|
||||
swap = v.swap
|
||||
cores = v.cores
|
||||
size = v.size
|
||||
started = v.started
|
||||
start_on_boot = v.start_on_boot
|
||||
unprivileged = v.unprivileged
|
||||
features = v.features
|
||||
mount_point = v.mount_point
|
||||
device_passthrough = v.device_passthrough
|
||||
operating_system = v.operating_system
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "proxmox_virtual_environment_container" "all_containers" {
|
||||
for_each = local.processed_containers
|
||||
|
||||
node_name = "firebat"
|
||||
vm_id = each.value.vmid
|
||||
|
||||
initialization {
|
||||
hostname = each.key
|
||||
ip_config {
|
||||
ipv4 {
|
||||
address = "${each.value.ip}/24"
|
||||
gateway = each.value.gw
|
||||
}
|
||||
}
|
||||
dns {
|
||||
servers = [each.value.nameserver]
|
||||
domain = "lan"
|
||||
}
|
||||
}
|
||||
|
||||
cpu {
|
||||
#architecture = "amd64"
|
||||
cores = each.value.cores
|
||||
#limit = 0
|
||||
}
|
||||
|
||||
memory {
|
||||
dedicated = each.value.memory
|
||||
swap = each.value.swap
|
||||
}
|
||||
|
||||
network_interface {
|
||||
name = "eth0"
|
||||
bridge = "vmbr0"
|
||||
vlan_id = each.value.vlan
|
||||
firewall = true
|
||||
}
|
||||
|
||||
disk {
|
||||
datastore_id = "local-zfs"
|
||||
size = each.value.size
|
||||
}
|
||||
|
||||
features {
|
||||
fuse = each.value.features.fuse
|
||||
keyctl = each.value.features.keyctl
|
||||
mknod = each.value.features.mknod
|
||||
nesting = each.value.features.nesting
|
||||
mount = each.value.features.mount
|
||||
}
|
||||
|
||||
console {
|
||||
enabled = null
|
||||
tty_count = null
|
||||
type = null
|
||||
}
|
||||
|
||||
dynamic "mount_point" {
|
||||
for_each = each.value.mount_point
|
||||
content {
|
||||
volume = mount_point.value.volume
|
||||
path = mount_point.value.path
|
||||
}
|
||||
}
|
||||
|
||||
dynamic "device_passthrough" {
|
||||
for_each = each.value.device_passthrough
|
||||
content {
|
||||
path = device_passthrough.value.path
|
||||
gid = device_passthrough.value.gid
|
||||
uid = device_passthrough.value.uid
|
||||
mode = device_passthrough.value.mode
|
||||
deny_write = device_passthrough.value.deny_write
|
||||
}
|
||||
}
|
||||
|
||||
operating_system {
|
||||
type = each.value.operating_system.type
|
||||
template_file_id = each.value.operating_system.template_file_id
|
||||
}
|
||||
|
||||
unprivileged = each.value.unprivileged
|
||||
started = each.value.started
|
||||
start_on_boot = each.value.start_on_boot
|
||||
tags = [each.value.tags]
|
||||
}
|
||||
Reference in New Issue
Block a user