From 9402af23bbb27dab7c8a3f39e85686a5f1785249 Mon Sep 17 00:00:00 2001 From: pyrschtjag Date: Mon, 7 Sep 2026 19:53:00 +0000 Subject: [PATCH] add new parameters and hosts --- .gitignore | 1 + main.tf | 256 +++++++++++++++++++++++++-------------------------- variables.tf | 36 ++++++-- 3 files changed, 159 insertions(+), 134 deletions(-) diff --git a/.gitignore b/.gitignore index d00f35c..8aa8a20 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,4 @@ .terraform .terraform.lock.hcl terraform.tfvars +*.tfstate diff --git a/main.tf b/main.tf index 4d44e0d..9f9bfb0 100644 --- a/main.tf +++ b/main.tf @@ -1,161 +1,161 @@ terraform { - required_providers { - proxmox = { - source = "bpg/proxmox" - version = "0.111.0" + required_providers { + proxmox = { + source = "bpg/proxmox" + version = "0.111.1" + } + } + backend "http" { + address = "http://10.1.0.104:3000/api/packages/pyrschtjag/terraform/state/runner" + lock_address = "http://10.1.0.104:3000/api/packages/pyrschtjag/terraform/state/runner/lock" + unlock_address = "http://10.1.0.104:3000/api/packages/pyrschtjag/terraform/state/runner/lock" + lock_method = "POST" + unlock_method = "DELETE" } - } - backend "http" { - address = "https://gitea.oyacoi.ru/api/packages/pyrschtjag/terraform/state/runner" - lock_address = "https://gitea.oyacoi.ru/api/packages/pyrschtjag/terraform/state/runner/lock" - unlock_address = "https://gitea.oyacoi.ru/api/packages/pyrschtjag/terraform/state/runner/lock" - lock_method = "POST" - unlock_method = "DELETE" - } } provider "proxmox" { - endpoint = "https://firebat.lan:8006/" - username = "root@pam" - password = var.proxmox_root_password - insecure = true + endpoint = "https://10.1.0.4:8006/" + username = "root@pam" + password = var.proxmox_root_password + insecure = true } locals { - processed_containers = { - for k, v in var.containers : k => { - vmid = v.vmid - tags = v.tags + processed_containers = { + for k, v in var.containers : k => { + vmid = v.vmid + tags = v.tags - networks = length(v.networks) > 0 ? [ - for net in v.networks : { - name = lookup(net, "name", "eth0") - bridge = lookup(net, "bridge", "vmbr0") - vlan_id = net.vlan_id == null ? (floor(v.vmid / 100) % 100) : net.vlan_id - hwaddr = lookup(net, "hwaddr", null) - firewall = lookup(net, "firewall", true) + networks = length(v.networks) > 0 ? [ + for net in v.networks : { + name = lookup(net, "name", "eth0") + bridge = lookup(net, "bridge", "vmbr0") + vlan_id = net.vlan_id == null ? (floor(v.vmid / 100) % 100) : net.vlan_id + hwaddr = lookup(net, "hwaddr", null) + firewall = lookup(net, "firewall", true) + } + ] : [] + + ip = v.ip == "" ? null : "10.${floor(v.vmid / 100) % 100}.0.${v.vmid % 100}/24" + gw = v.ip == "" ? null : "10.${floor(v.vmid / 100) % 100}.0.1" + nameserver = v.ip == "" ? null : "10.${floor(v.vmid / 100) % 100}.0.1" + + memory = v.memory + swap = v.swap + cores = v.cores + size = v.size + started = v.started + start_on_boot = v.start_on_boot + unprivileged = v.unprivileged + features = v.features + mount_point = v.mount_point + device_passthrough = v.device_passthrough + operating_system = v.operating_system } - ] : [] - - ip = v.ip == "" ? null : "10.${floor(v.vmid / 100) % 100}.0.${v.vmid % 100}" - gw = v.ip == "" ? null : "10.${floor(v.vmid / 100) % 100}.0.1" - nameserver = v.ip == "" ? null : "10.${floor(v.vmid / 100) % 100}.0.1" - - memory = v.memory - swap = v.swap - cores = v.cores - size = v.size - started = v.started - start_on_boot = v.start_on_boot - unprivileged = v.unprivileged - features = v.features - mount_point = v.mount_point - device_passthrough = v.device_passthrough - operating_system = v.operating_system } - } } resource "proxmox_virtual_environment_container" "all_containers" { - for_each = local.processed_containers + for_each = local.processed_containers - node_name = "firebat" - vm_id = each.value.vmid + node_name = "firebat" + vm_id = each.value.vmid - initialization { - hostname = each.key + initialization { + hostname = each.key - dynamic "ip_config" { - for_each = each.value.ip != null ? [1] : [] - content { - ipv4 { - address = each.value.ip - gateway = each.value.gw + dynamic "ip_config" { + for_each = each.value.ip != null ? [1] : [] + content { + ipv4 { + address = each.value.ip + gateway = each.value.gw + } + } + } + + dynamic "dns" { + for_each = each.value.nameserver != null ? [1] : [] + content { + servers = [each.value.nameserver] + domain = "lan" + } } - } } - dynamic "dns" { - for_each = each.value.nameserver != null ? [1] : [] - content { - servers = [each.value.nameserver] - domain = "lan" - } + cpu { + #architecture = "amd64" + cores = each.value.cores + #limit = 0 } - } - cpu { - #architecture = "amd64" - cores = each.value.cores - #limit = 0 - } - - memory { - dedicated = each.value.memory - swap = each.value.swap - } - - dynamic "network_interface" { - for_each = each.value.networks - content { - name = network_interface.value.name - bridge = network_interface.value.bridge - vlan_id = network_interface.value.vlan_id - mac_address = network_interface.value.hwaddr - firewall = network_interface.value.firewall + memory { + dedicated = each.value.memory + swap = each.value.swap } - } - disk { - datastore_id = "local-zfs" - size = each.value.size - } - - features { - fuse = each.value.features.fuse - keyctl = each.value.features.keyctl - mknod = each.value.features.mknod - nesting = each.value.features.nesting - mount = each.value.features.mount - } - - #console { - # enabled = null - # tty_count = null - # type = null - #} - - dynamic "mount_point" { - for_each = each.value.mount_point - content { - volume = mount_point.value.volume - size = mount_point.value.size != null ? "${mount_point.value.size}G" : null - path = mount_point.value.path + dynamic "network_interface" { + for_each = each.value.networks + content { + name = network_interface.value.name + bridge = network_interface.value.bridge + vlan_id = network_interface.value.vlan_id + mac_address = network_interface.value.hwaddr + firewall = network_interface.value.firewall + } } - } - dynamic "device_passthrough" { - for_each = each.value.device_passthrough - content { - path = device_passthrough.value.path - gid = device_passthrough.value.gid - uid = device_passthrough.value.uid - mode = device_passthrough.value.mode - deny_write = device_passthrough.value.deny_write + disk { + datastore_id = "local-zfs" + size = each.value.size } - } - operating_system { - type = each.value.operating_system.type - template_file_id = each.value.operating_system.template_file_id - } + features { + fuse = each.value.features.fuse + keyctl = each.value.features.keyctl + mknod = each.value.features.mknod + nesting = each.value.features.nesting + mount = each.value.features.mount + } - unprivileged = each.value.unprivileged - started = each.value.started - start_on_boot = each.value.start_on_boot - tags = each.value.tags + #console { + # enabled = null + # tty_count = null + # type = null + #} + + dynamic "mount_point" { + for_each = each.value.mount_point + content { + volume = mount_point.value.volume + size = mount_point.value.size != null ? "${mount_point.value.size}G" : null + path = mount_point.value.path + } + } + + dynamic "device_passthrough" { + for_each = each.value.device_passthrough + content { + path = device_passthrough.value.path + gid = device_passthrough.value.gid + uid = device_passthrough.value.uid + mode = device_passthrough.value.mode + deny_write = device_passthrough.value.deny_write + } + } + + operating_system { + type = each.value.operating_system.type + template_file_id = each.value.operating_system.template_file_id + } + + unprivileged = each.value.unprivileged + started = each.value.started + start_on_boot = each.value.start_on_boot + tags = each.value.tags } #output "containers_info" { -# value = local.processed_containers +# value = local.processed_containers #} diff --git a/variables.tf b/variables.tf index be1181e..da1117e 100644 --- a/variables.tf +++ b/variables.tf @@ -16,7 +16,7 @@ variable "containers" { started = optional(bool, true) start_on_boot = optional(bool, true) unprivileged = optional(bool, true) - ip = optional(string) + ip = optional(string, null) gw = optional(string) nameserver = optional(string) tags = optional(list(string), []) @@ -61,15 +61,15 @@ variable "containers" { }) })) default = { - "router-test" = { - vmid = 100 + "router" = { + vmid = 101 memory = 1024 swap = 128 cores = 1 - size = 1 + size = 2 tags = ["main"] - started = false - start_on_boot = false + started = true + start_on_boot = true ip = "" networks = [ { @@ -77,12 +77,14 @@ variable "containers" { bridge = "vmbr0" firewall = false vlan_id = 0 + hwaddr = "bc:24:11:2f:fa:f6" }, { name = "eth1" bridge = "vmbr1" firewall = false vlan_id = 0 + hwaddr = "bc:24:11:dd:b3:08" } ] operating_system = { @@ -90,6 +92,28 @@ variable "containers" { template_file_id = "local:vztmpl/debian-13-standard_13.6-1_amd64.tar.zst" } } + "steamcmd" = { + vmid = 1203 + memory = 6144 + swap = 128 + cores = 8 + size = 2 + tags = ["games"] + started = true + start_on_boot = true + networks = [ + { + vlan_id = 12 + } + ] + operating_system = { + type = "debian", + template_file_id = "local:vztmpl/debian-13-standard_13.6-1_amd64.tar.zst" + } + mount_point = [ + { volume= "/rpool/data/steamcmd/", path = "/mnt/steamcmd/" } + ] + } #"GITEA-TEST" = { # vmid = 1012 # memory = 2048