mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
fix(net): bgp (#507)
This commit is contained in:
@@ -120,12 +120,14 @@ module "core" {
|
||||
}
|
||||
# v4-only handover (no v6 delivered). Colt's inbound route filter accepts
|
||||
# 69.48.224.0/22 le /24 from AS402421, so the /24 fits; widening past that
|
||||
# needs a Colt Online ticket.
|
||||
# needs a Colt Online ticket. Client is 100GBE (Colt transport, LAN-WDM):
|
||||
# the port needs a QSFP28-100G-LR4 — a 40G-LR4 (CWDM) shows two dark lanes
|
||||
# and never links (2026-08 turn-up).
|
||||
colt = {
|
||||
interface = "et-1/0/27"
|
||||
local_v4 = "62.67.19.110/30"
|
||||
peer_v4 = "62.67.19.109"
|
||||
peer_as = 8220
|
||||
peer_as = 3356
|
||||
advertise = "69.48.224.0/24"
|
||||
prepend = 1
|
||||
}
|
||||
@@ -164,10 +166,13 @@ locals {
|
||||
netops_classes = {
|
||||
netops-ro = { permissions = ["view", "view-configuration", "network"] }
|
||||
}
|
||||
# uid must not collide with the identity registry's uids (3000+ are humans):
|
||||
# Junos merges same-uid logins into one user, which downgraded nutgood
|
||||
# (super-user, uid 3000) into this read-only class until netops moved to 3100.
|
||||
netops_users = {
|
||||
netops = {
|
||||
class = "netops-ro"
|
||||
uid = 3000
|
||||
uid = 3100
|
||||
full_name = "netops read-only (exporter/LG/backup)"
|
||||
ssh_ed25519_keys = ["ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJSaBWwn5kKONxc0bc1w39xYBeBFAuqRWzMQTBM0xCmb netops@father"]
|
||||
# For password-only tools (hyperglass/netmiko). Hash injected from 1P.
|
||||
|
||||
@@ -49,7 +49,7 @@ module "netbox" {
|
||||
worker_egress = { prefix = "69.48.224.240/29", description = "father worker fabric-egress SNAT IPs (.241 jeanne, .242 sheron, .243 dianna)" }
|
||||
spine_loopback = { prefix = "69.48.224.254/32", description = "spine lo0 (sFlow agent-id, LG source)" }
|
||||
transit_p2p = { prefix = "5.56.17.224/31", description = "Core-Backbone transit /31 (spine et-0/0/27)" }
|
||||
transit_p2p_colt = { prefix = "62.67.19.108/30", description = "Colt transit /30 (spine et-1/0/27, v4-only; .109 Colt, .110 us)" }
|
||||
transit_p2p_colt = { prefix = "62.67.19.108/30", description = "Colt transit /30 (spine et-1/0/27, 100GBASE-LR4, v4-only; .109 Colt, .110 us)" }
|
||||
}
|
||||
|
||||
devices = {
|
||||
|
||||
@@ -15,6 +15,15 @@ variable "users" {
|
||||
# glass). Source it from 1Password via a TF var — never commit even the hash.
|
||||
encrypted_password = optional(string)
|
||||
}))
|
||||
|
||||
# Junos aliases same-uid logins into ONE user: whoever authenticates gets the
|
||||
# merged user's class, so a collision silently reassigns rights (a super-user
|
||||
# key landing in a read-only class, as happened with nutgood/netops both at
|
||||
# uid 3000).
|
||||
validation {
|
||||
condition = length(distinct([for u in var.users : u.uid if u.uid != null])) == length([for u in var.users : u.uid if u.uid != null])
|
||||
error_message = "Duplicate uid across login users: Junos treats same-uid logins as one user and silently merges their classes/keys. Give every user a unique uid."
|
||||
}
|
||||
}
|
||||
|
||||
variable "classes" {
|
||||
|
||||
Reference in New Issue
Block a user