fix(net): bgp (#507)

This commit is contained in:
Antoine Lecompte
2026-08-20 13:07:35 +00:00
committed by GitHub
parent 09f10fcbf5
commit 4eaaaa6e6f
3 changed files with 18 additions and 4 deletions
+8 -3
View File
@@ -120,12 +120,14 @@ module "core" {
}
# v4-only handover (no v6 delivered). Colt's inbound route filter accepts
# 69.48.224.0/22 le /24 from AS402421, so the /24 fits; widening past that
# needs a Colt Online ticket.
# needs a Colt Online ticket. Client is 100GBE (Colt transport, LAN-WDM):
# the port needs a QSFP28-100G-LR4 — a 40G-LR4 (CWDM) shows two dark lanes
# and never links (2026-08 turn-up).
colt = {
interface = "et-1/0/27"
local_v4 = "62.67.19.110/30"
peer_v4 = "62.67.19.109"
peer_as = 8220
peer_as = 3356
advertise = "69.48.224.0/24"
prepend = 1
}
@@ -164,10 +166,13 @@ locals {
netops_classes = {
netops-ro = { permissions = ["view", "view-configuration", "network"] }
}
# uid must not collide with the identity registry's uids (3000+ are humans):
# Junos merges same-uid logins into one user, which downgraded nutgood
# (super-user, uid 3000) into this read-only class until netops moved to 3100.
netops_users = {
netops = {
class = "netops-ro"
uid = 3000
uid = 3100
full_name = "netops read-only (exporter/LG/backup)"
ssh_ed25519_keys = ["ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJSaBWwn5kKONxc0bc1w39xYBeBFAuqRWzMQTBM0xCmb netops@father"]
# For password-only tools (hyperglass/netmiko). Hash injected from 1P.
+1 -1
View File
@@ -49,7 +49,7 @@ module "netbox" {
worker_egress = { prefix = "69.48.224.240/29", description = "father worker fabric-egress SNAT IPs (.241 jeanne, .242 sheron, .243 dianna)" }
spine_loopback = { prefix = "69.48.224.254/32", description = "spine lo0 (sFlow agent-id, LG source)" }
transit_p2p = { prefix = "5.56.17.224/31", description = "Core-Backbone transit /31 (spine et-0/0/27)" }
transit_p2p_colt = { prefix = "62.67.19.108/30", description = "Colt transit /30 (spine et-1/0/27, v4-only; .109 Colt, .110 us)" }
transit_p2p_colt = { prefix = "62.67.19.108/30", description = "Colt transit /30 (spine et-1/0/27, 100GBASE-LR4, v4-only; .109 Colt, .110 us)" }
}
devices = {
@@ -15,6 +15,15 @@ variable "users" {
# glass). Source it from 1Password via a TF var — never commit even the hash.
encrypted_password = optional(string)
}))
# Junos aliases same-uid logins into ONE user: whoever authenticates gets the
# merged user's class, so a collision silently reassigns rights (a super-user
# key landing in a read-only class, as happened with nutgood/netops both at
# uid 3000).
validation {
condition = length(distinct([for u in var.users : u.uid if u.uid != null])) == length([for u in var.users : u.uid if u.uid != null])
error_message = "Duplicate uid across login users: Junos treats same-uid logins as one user and silently merges their classes/keys. Give every user a unique uid."
}
}
variable "classes" {