chore(ceph): decommission dev sietch stack, repoint defaults to staging (#186)

This commit is contained in:
Andy Molenda
2026-06-25 14:40:06 -07:00
committed by GitHub
parent 3815637b50
commit a16ba1a570
16 changed files with 12 additions and 521 deletions
+5 -5
View File
@@ -71,20 +71,20 @@ run = [{ task = "*:fix" }, { task = "web:lingui" }]
# No literal secrets in the .env file — just op:// references.
[tasks."tf:init"]
description = "Terragrunt init for a given stack (default: deployment/dev/ceph)"
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} init"
description = "Terragrunt init for a given stack (default: deployment/staging/ceph)"
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/ceph} init"
[tasks."tf:plan"]
description = "Terragrunt plan for a given stack"
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} plan"
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/ceph} plan"
[tasks."tf:apply"]
description = "Terragrunt apply for a given stack"
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} apply"
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/ceph} apply"
[tasks."tf:destroy"]
description = "Terragrunt destroy for a given stack (use with care)"
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} destroy"
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/ceph} destroy"
[tasks."tf:fmt"]
description = "Format terraform + terragrunt files recursively"
+3 -3
View File
@@ -8,7 +8,7 @@ PATH = "{{config_root}}/.venv/bin:{{env.PATH}}"
# Note: CEPH_ENV is intentionally NOT declared here. mise's [env] block
# overrides shell-exported values, which silently sends operators to the
# wrong cluster. Operators must export CEPH_ENV once per shell session:
# export CEPH_ENV=inventories/sietch-ceph.dev.austin.int/inventory.ini
# export CEPH_ENV=inventories/sietch-ceph.staging.austin.int/inventory.ini
# export CEPH_ENV=inventories/painbox-ceph.dev.hel.htz/inventory.ini
# Inventory files are TF-generated — `mise run tf:apply` (from yucca root) if missing.
@@ -64,7 +64,7 @@ run = """
set -euo pipefail
# Syntax-check only parses YAML — any valid inventory works. Default to
# sietch when CEPH_ENV isn't inline-prefixed; the parse is identical.
CEPH_ENV="${CEPH_ENV:-inventories/sietch-ceph.dev.austin.int/inventory.ini}"
CEPH_ENV="${CEPH_ENV:-inventories/sietch-ceph.staging.austin.int/inventory.ini}"
for pb in *.yml; do
case "$pb" in
requirements.yml|ansible-navigator.yml) continue ;;
@@ -125,7 +125,7 @@ run = """
#!/usr/bin/env bash
set -euo pipefail
CEPH_ENV_DIR=$(dirname "$CEPH_ENV")
CLUSTER_ID=$(basename "$CEPH_ENV_DIR") # e.g., sietch-ceph.dev.austin.int
CLUSTER_ID=$(basename "$CEPH_ENV_DIR") # e.g., sietch-ceph.staging.austin.int
DOMAIN=${CLUSTER_ID#*-ceph.}.futo.cloud # e.g., dev.austin.int.futo.cloud
DESTROY_INV="$CEPH_ENV_DIR/inventory-destroy.ini"
echo "Usage: scripts/ansible-play.sh destroy-ceph.yml \\"
@@ -1,111 +0,0 @@
---
# === Naming ===
cluster_name: sietch
cluster_role: ceph
# === Network ===
cluster_domain: dev.austin.int.futo.cloud
public_network: 10.10.10.0/24
cluster_network: 10.10.10.0/24
gateway: 10.10.10.1
dns_server: 10.10.10.1
bond_mode: active-backup
bond_interfaces:
- eno1np0
- eno2np1
networkd_enabled: true
# === Ceph ===
ceph_release: tentacle
ceph_repo_url: "https://download.ceph.com/debian-{{ ceph_release }}/"
ceph_repo_key_url: "https://download.ceph.com/keys/release.asc"
# === OS Provisioning ===
admin_user: ansible-iac
timezone: UTC
# Deploy keypair path on the controller. Both {path} and {path}.pub must
# exist before running provision.yml (the preflight play in provision.yml
# enforces this). ansible-iac's authorized_keys on every node is populated
# by a file lookup at provision time — rotating the key on the controller
# automatically propagates on the next re-provision.
provision_iac_ssh_key_path: "~/.ssh/id_ed25519_sietch"
# 1P vault for cluster secret lookups (e.g., rotate-ssh-key.yml reads pubkey from here).
cluster_secrets_vault: yucca_tf_dev
# Secret aliases — vault_* vars populated by scripts/ansible-play.sh via op inject
#
# Note: the deploy public key is NOT a secret — it's public data and lives
# at {{ provision_iac_ssh_key_path }}.pub on the controller. Reading it via
# file lookup avoids drift between vault and disk.
ops_password: "{{ vault_ops_password }}"
ceph_dashboard_user: admin
ceph_dashboard_password: "{{ vault_ceph_dashboard_password }}"
# S3 svc-user (yucca-restic consumer) — TF+1P-predetermined keys passed to
# `radosgw-admin user create --access-key=... --secret-key=...` so the Yucca
# app can be pre-configured with matching credentials. Rotation path documented
# in docs/runbooks/rotate-secrets.md.
ceph_rgw_s3_user_access_key: "{{ vault_s3_restic_access_key }}"
ceph_rgw_s3_user_secret_key: "{{ vault_s3_restic_secret_key }}"
# === Storage ===
ssd_model_pattern: "Micron_5100"
os_partitions:
esp_size: "512M"
boot_size: "1G"
root_size: "80G"
swap_size: "8G"
ceph_db_size: "1440G"
ceph_db_lv_size: "240G"
ceph_db_lvs_per_ssd: 6
# === RGW (Object Gateway) ===
ceph_rgw_realm: sietch
ceph_rgw_zonegroup: us-east-1
ceph_rgw_zonegroup_api_name: us-east-1
ceph_rgw_zone: dev-z1
ceph_rgw_ec_profile: ec-k8m3-osd
ceph_rgw_ec_k: 8
ceph_rgw_ec_m: 3
ceph_rgw_ec_failure_domain: osd
ceph_rgw_ec_device_class: hdd
ceph_rgw_data_pool: "{{ ceph_rgw_zone }}.rgw.buckets.data"
ceph_rgw_index_pool: "{{ ceph_rgw_zone }}.rgw.buckets.index"
ceph_rgw_extra_pool: "{{ ceph_rgw_zone }}.rgw.buckets.non-ec"
ceph_rgw_replicated_size: 2
ceph_rgw_replicated_min_size: 1
ceph_rgw_port: 443
ceph_rgw_s3_user_uid: svc-yucca-restic
ceph_rgw_s3_user_display_name: "yucca/restic service account"
# --- RGW DNS + TLS ---
# Virtual-hosted S3 support: setting rgw_dns_name tells RGW to strip this
# suffix from the Host header and treat the remainder as the bucket name.
# Requires matching DNS: both s3.<domain> and *.s3.<domain> should resolve
# to the cluster nodes (round-robin A, or VIP/LB in prod).
ceph_rgw_dns_name: s3.dev.austin.int.futo.cloud
# Self-signed wildcard cert handed to cephadm via service spec.
# cephadm distributes to all RGW daemons. To rotate, delete
# /etc/ceph/rgw-ssl.{crt,key} on the bootstrap node and re-run the role.
ceph_rgw_ssl: true
ceph_rgw_ssl_cert_days: 3650 # 10 years
ceph_rgw_ssl_cert_subject_c: US
ceph_rgw_ssl_cert_subject_st: Texas
ceph_rgw_ssl_cert_subject_l: Austin
ceph_rgw_ssl_cert_subject_o: FUTO
ceph_rgw_ssl_cert_email: yucca@futo.org
# Computed: scheme used for endpoints, debug output, and zonegroup/zone URLs
ceph_rgw_scheme: "{{ 'https' if ceph_rgw_ssl else 'http' }}"
# === Monitoring Stack ===
ceph_prometheus_port: 9095
ceph_grafana_port: 3000
ceph_alertmanager_port: 9093
ceph_grafana_admin_user: admin
ceph_grafana_admin_password: "{{ vault_grafana_admin_password }}"
@@ -1,36 +0,0 @@
---
# Copy to host_vars/sietch-ceph-<name>.yml (full inventory_hostname).
# The <name> segment is either operator-declared in clusters.auto.tfvars
# or TF-auto-picked from wordlist.txt — see docs/naming.md.
# Filename MUST match inventory_hostname for Ansible auto-load.
# Values are node-specific — hardware paths differ per chassis.
hostname_short: sietch-ceph-EXAMPLE
bond_ip: 10.0.0.1
# SAS expander base path (unique per chassis)
# Find with: ls /dev/disk/by-path/ | grep sas
sas_path_prefix: "pci-0000:02:00.0-sas-exp0x500056b3XXXXXXXX"
# SSD PHY positions in the SAS topology
ssd1_phy: 12
ssd2_phy: 13
# LVM volume group names for block.db (on SSD partition 5)
ceph_db_vg1: ceph-db-ssd1
ceph_db_vg2: ceph-db-ssd2
# HDD OSD mappings: SAS PHY slot -> block.db LV
# 6 HDDs per SSD, each gets a dedicated 240G block.db LV
ceph_hdd_osds:
- path_phy: phy0
db: ceph-db-ssd1/db-slot0
- path_phy: phy1
db: ceph-db-ssd1/db-slot1
# ... one entry per HDD
# SSD OSD partitions (partition 6 on each SSD, no separate block.db)
ceph_ssd_osds:
- path_phy: phy12
partition: 6
- path_phy: phy13
partition: 6
@@ -1,52 +0,0 @@
---
hostname_short: sietch-ceph-laurel
bond_ip: 10.10.10.90
# SAS expander base path (unique per chassis — different backplane address per node)
sas_path_prefix: "pci-0000:02:00.0-sas-exp0x500056b3fcf498ff"
# SSD PHY positions (rear bays)
ssd1_phy: 12 # serial 17321A07BA4A
ssd2_phy: 13 # serial 17321A07CFEE
# LVM VGs on SSD partition 5
ceph_db_vg1: ceph-db-rear12 # VG on SSD1 (phy12) partition 5
ceph_db_vg2: ceph-db-rear13 # VG on SSD2 (phy13) partition 5
# HDD OSD mappings: PHY slot -> block.db LV
# PHY 0-5 -> SSD1 (ceph-db-rear12/db-slot0..5)
# PHY 6-11 -> SSD2 (ceph-db-rear13/db-slot6..11)
# by-path is slot-stable: replacing a drive in the same bay keeps the same path
# 12 HDDs — all front bays populated
ceph_hdd_osds:
- path_phy: phy0
db: ceph-db-rear12/db-slot0
- path_phy: phy1
db: ceph-db-rear12/db-slot1
- path_phy: phy2
db: ceph-db-rear12/db-slot2
- path_phy: phy3
db: ceph-db-rear12/db-slot3 # serial Z4D09B99 (ST6000NKCLAR6000, added 2026-04-10)
- path_phy: phy4
db: ceph-db-rear12/db-slot4
- path_phy: phy5
db: ceph-db-rear12/db-slot5 # serial Z4D0G7VC (ST6000NKCLAR6000, added 2026-04-10)
- path_phy: phy6
db: ceph-db-rear13/db-slot6
- path_phy: phy7
db: ceph-db-rear13/db-slot7 # serial Z4D0G7SC (ST6000NKCLAR6000, added 2026-04-10)
- path_phy: phy8
db: ceph-db-rear13/db-slot8
- path_phy: phy9
db: ceph-db-rear13/db-slot9
- path_phy: phy10
db: ceph-db-rear13/db-slot10 # serial Z4D0G7XK (ST6000NKCLAR6000, added 2026-04-10)
- path_phy: phy11
db: ceph-db-rear13/db-slot11
# SSD OSD partitions (partition 6 on each rear SSD, no separate block.db)
ceph_ssd_osds:
- path_phy: phy12
partition: 6
- path_phy: phy13
partition: 6
@@ -1,52 +0,0 @@
---
hostname_short: sietch-ceph-lawson
bond_ip: 10.10.10.91
# SAS expander base path (unique per chassis — different backplane address per node)
sas_path_prefix: "pci-0000:02:00.0-sas-exp0x500056b35be6b4ff"
# SSD PHY positions (rear bays)
ssd1_phy: 12 # serial 17321A07CF91
ssd2_phy: 13 # serial 17251B44C4D8
# LVM VGs on SSD partition 5
ceph_db_vg1: ceph-db-rear12 # VG on SSD1 (phy12) partition 5
ceph_db_vg2: ceph-db-rear13 # VG on SSD2 (phy13) partition 5
# HDD OSD mappings: PHY slot -> block.db LV
# PHY 0-5 -> SSD1 (ceph-db-rear12/db-slot0..5)
# PHY 6-11 -> SSD2 (ceph-db-rear13/db-slot6..11)
# by-path is slot-stable: replacing a drive in the same bay keeps the same path
# 12 HDDs — all front bays populated
ceph_hdd_osds:
- path_phy: phy0
db: ceph-db-rear12/db-slot0
- path_phy: phy1
db: ceph-db-rear12/db-slot1
- path_phy: phy2
db: ceph-db-rear12/db-slot2
- path_phy: phy3
db: ceph-db-rear12/db-slot3
- path_phy: phy4
db: ceph-db-rear12/db-slot4
- path_phy: phy5
db: ceph-db-rear12/db-slot5
- path_phy: phy6
db: ceph-db-rear13/db-slot6
- path_phy: phy7
db: ceph-db-rear13/db-slot7 # serial Z4D0GKJX (ST6000NKCLAR6000, added 2026-04-10)
- path_phy: phy8
db: ceph-db-rear13/db-slot8
- path_phy: phy9
db: ceph-db-rear13/db-slot9
- path_phy: phy10
db: ceph-db-rear13/db-slot10
- path_phy: phy11
db: ceph-db-rear13/db-slot11
# SSD OSD partitions (partition 6 on each rear SSD, no separate block.db)
ceph_ssd_osds:
- path_phy: phy12
partition: 6
- path_phy: phy13
partition: 6
@@ -1,52 +0,0 @@
---
hostname_short: sietch-ceph-samara
bond_ip: 10.10.10.92
# SAS expander base path (unique per chassis — different backplane address per node)
sas_path_prefix: "pci-0000:02:00.0-sas-exp0x500056b3393ba1ff"
# SSD PHY positions (rear bays)
ssd1_phy: 12 # serial 17321A07D1D3
ssd2_phy: 13 # serial 17251B44DF51
# LVM VGs on SSD partition 5
ceph_db_vg1: ceph-db-rear12 # VG on SSD1 (phy12) partition 5
ceph_db_vg2: ceph-db-rear13 # VG on SSD2 (phy13) partition 5
# HDD OSD mappings: PHY slot -> block.db LV
# PHY 0-5 -> SSD1 (ceph-db-rear12/db-slot0..5)
# PHY 6-11 -> SSD2 (ceph-db-rear13/db-slot6..11)
# by-path is slot-stable: replacing a drive in the same bay keeps the same path
# 12 HDDs — all front bays populated
ceph_hdd_osds:
- path_phy: phy0
db: ceph-db-rear12/db-slot0
- path_phy: phy1
db: ceph-db-rear12/db-slot1
- path_phy: phy2
db: ceph-db-rear12/db-slot2
- path_phy: phy3
db: ceph-db-rear12/db-slot3
- path_phy: phy4
db: ceph-db-rear12/db-slot4 # serial Z4D0GKB2 (replacement, added 2026-04-11)
- path_phy: phy5
db: ceph-db-rear12/db-slot5
- path_phy: phy6
db: ceph-db-rear13/db-slot6
- path_phy: phy7
db: ceph-db-rear13/db-slot7
- path_phy: phy8
db: ceph-db-rear13/db-slot8
- path_phy: phy9
db: ceph-db-rear13/db-slot9
- path_phy: phy10
db: ceph-db-rear13/db-slot10
- path_phy: phy11
db: ceph-db-rear13/db-slot11
# SSD OSD partitions (partition 6 on each rear SSD, no separate block.db)
ceph_ssd_osds:
- path_phy: phy12
partition: 6
- path_phy: phy13
partition: 6
+1 -1
View File
@@ -26,7 +26,7 @@ declare -A KEYS=(
# different env vaults (e.g. sietch moves to yucca_tf_staging on promotion).
# Override any lookup with OP_VAULT=<vault>.
declare -A VAULTS=(
[sietch]="yucca_tf_dev"
[sietch]="yucca_tf_staging"
[painbox]="yucca_tf_dev"
)
DEFAULT_VAULT="yucca_tf_dev"
-42
View File
@@ -1,42 +0,0 @@
# This file is maintained automatically by "tofu init".
# Manual edits may be lost in future updates.
provider "registry.opentofu.org/hashicorp/local" {
version = "2.8.0"
constraints = "~> 2.5"
hashes = [
"h1:3c528BCbO8BFB7199qOBFpJ20Xoals6eSDcLX/GRzxA=",
"zh:0aaa04a29638eb2f84145aeec030ed4b469980c51f60f7f72ddbd705e0c9ceea",
"zh:1d2f29cdfdc607f6b6b641e8bc7b00c73ac29f572ae8aa9b18fd068c107a7315",
"zh:3cba45610ee2abbbe73694f5604d6628b036cee35d5e77f2353043088e950ff2",
"zh:435fca586d45fcf200974d90962fa4cffaf761bad4c774bd34d1b92463a9887f",
"zh:662748c6ad1e3d64500b70d3e2ccd5d2b04471dfd687c524f15bf3dbe68954a2",
"zh:68f3a6dd1a6ddb7f4935ce894861740dd39f2202c5ba4aebc217c742e426a80c",
"zh:75267c8b3d693125e7c6814058fef6189e0dae6c44c47cd63109d919b35e665e",
"zh:88a1e4c13876774fae1ae20129a328cb6031e3aca00435bc7899e4038c2f43f7",
"zh:8b8bffe1adeedf13a5c4af7b208b47ca5d4cac09ff51028962a3465e26830fef",
"zh:b99ddf3c8fb730e4a9e4ded4c5706bcca3b7b8d2f2ea458f01a4dda26c78fdd3",
"zh:d08174d23b2fe4a53b7f81f32ff0089e6ca76162a9de3c411deff7eb45d3d677",
"zh:d220cd9f2ea3426ab5e2c528700c15d8fbcd4254496a84945b38885c6e4b18d3",
"zh:de1e7f2ec372aaf717a26017e25f24bc22cbfc0e1691711484df26d828c6f8a0",
"zh:e1b7c0ccaea53904b999a0d3993e86b97766eaa3698040c0bbe14b453cefd91a",
"zh:e7eacd0e7a223fee0ac1fee5f032199219fde3cf0db43ad9d31b75a122f440ae",
]
}
provider "registry.opentofu.org/hashicorp/random" {
version = "3.8.1"
constraints = "~> 3.6"
hashes = [
"h1:EHn3jsqOKhWjbg0X+psk0Ww96yz3N7ASqEKKuFvDFwo=",
"zh:25c458c7c676f15705e872202dad7dcd0982e4a48e7ea1800afa5fc64e77f4c8",
"zh:2edeaf6f1b20435b2f81855ad98a2e70956d473be9e52a5fdf57ccd0098ba476",
"zh:44becb9d5f75d55e36dfed0c5beabaf4c92e0a2bc61a3814d698271c646d48e7",
"zh:7699032612c3b16cc69928add8973de47b10ce81b1141f30644a0e8a895b5cd3",
"zh:86d07aa98d17703de9fbf402c89590dc1e01dbe5671dd6bc5e487eb8fe87eee0",
"zh:8c411c77b8390a49a8a1bc9f176529e6b32369dd33a723606c8533e5ca4d68c1",
"zh:a5ecc8255a612652a56b28149994985e2c4dc046e5d34d416d47fa7767f5c28f",
"zh:aea3fe1a5669b932eda9c5c72e5f327db8da707fe514aaca0d0ef60cb24892f9",
"zh:f56e26e6977f755d7ae56fa6320af96ecf4bb09580d47cb481efbf27f1c5afff",
]
}
@@ -1,26 +0,0 @@
# Declarative cluster inventory. Adding a cluster = add an entry here, run
# `terragrunt apply`, then `ansible/ceph/scripts/render-inventories.sh dev`.
#
# painbox is intentionally NOT managed here right now: it is in active use by
# Zack for other purposes, so this stack must not render or reconcile it. Its
# spec is kept as a reference in clusters.example.tfvars (not auto-loaded). Its
# 1Password items are left untouched.
clusters = {
sietch = {
domain = "dev.austin.int.futo.cloud"
environment = "dev"
datacenter = "austin"
provider_code = "int"
role_in_hostname = "ceph"
ansible_ssh_user = "ansible-iac"
ansible_ssh_key = "~/.ssh/id_ed25519_sietch"
vault = "yucca_tf_dev"
provision_profile = "debian-live"
hosts = [
{ name = "laurel", bond_ip = "10.10.10.90", bootstrap = true },
{ name = "lawson", bond_ip = "10.10.10.91" },
{ name = "samara", bond_ip = "10.10.10.92" },
]
}
}
@@ -1,27 +0,0 @@
# Example cluster spec, NOT auto-loaded (only *.auto.tfvars is). Kept as a
# reference for clusters that exist but are not currently managed by this stack.
#
# painbox: a single-node Ceph Tentacle cluster on Bookworm (1x SX295) in
# Hetzner Helsinki, reprovisioned end to end via Hetzner installimage (hence no
# provision_profile; installimage handles partitioning + base OS). It is in
# active use by Zack, so it is excluded from clusters.auto.tfvars. To bring it
# back under management, move this entry into the clusters map there, run
# `terragrunt apply`, then render. Its 1Password items already exist in
# yucca_tf_dev and are left untouched either way.
#
# clusters = {
# painbox = {
# domain = "dev.hel.htz.futo.cloud"
# environment = "dev"
# datacenter = "hel"
# provider_code = "htz"
# role_in_hostname = "ceph"
# ansible_ssh_user = "root"
# ansible_ssh_key = "~/.ssh/id_ed25519_painbox"
# vault = "yucca_tf_dev"
# # Auto-picked wordlist name: "evelyn" -> painbox-ceph-evelyn.
# hosts = [
# { bond_ip = "157.180.105.198", bootstrap = true },
# ]
# }
# }
-50
View File
@@ -1,50 +0,0 @@
module "cluster" {
for_each = var.clusters
source = "../../../shared/modules/ceph-cluster"
cluster_name = each.key
domain = each.value.domain
environment = each.value.environment
datacenter = each.value.datacenter
provider_code = each.value.provider_code
role_in_hostname = coalesce(each.value.role_in_hostname, "ceph")
ansible_ssh_user = each.value.ansible_ssh_user
ansible_ssh_key = each.value.ansible_ssh_key
vault = coalesce(each.value.vault, "Yucca")
hosts = each.value.hosts
provision_profile = each.value.provision_profile
# NOTE: onepassword_item provisioning is dormant per ADR-009. Re-enable
# once a dedicated ceph-scoped 1P service account replaces the org-wide
# superuser SA (current blocker). See secrets.tf.disabled for the dormant
# resource declarations. Items referenced by secrets.yml.tpl already exist
# in var.vault (yucca_tf_dev) — created via the superuser SA + op CLI.
}
output "cluster_summaries" {
value = {
for k, m in module.cluster : k => {
fqdn = m.fqdn_cluster
bootstrap_host = m.bootstrap_host.hostname_short
host_count = length(m.hosts)
inventory_dir = m.inventory_dirname
secrets = m.secrets
}
}
}
# Consumed by ansible/ceph/scripts/render-inventories.sh: it reads this output
# and writes each cluster's files under ansible/ceph/inventories/<dirname>/.
# Rendered content lives in a TF OUTPUT (not in local_file resources), so the
# shared remote state never records a checkout-specific filesystem path. See
# the module's rendering.tf for the full rationale.
output "render" {
description = "Per-cluster { dirname, files } for the local render wrapper."
value = {
for k, m in module.cluster : k => {
dirname = m.inventory_dirname
files = m.rendered_files
}
}
}
-9
View File
@@ -1,9 +0,0 @@
include "root" {
path = find_in_parent_folders("terragrunt.hcl")
}
# clusters.auto.tfvars is automatically loaded by OpenTofu in this directory.
# No inputs are injected here: rendered inventories are no longer written by
# tofu (which previously needed get_repo_root() to locate ansible/ceph and so
# coupled shared state to the applying worktree). Content is emitted via the
# `render` output and written locally by ansible/ceph/scripts/render-inventories.sh.
-20
View File
@@ -1,20 +0,0 @@
variable "clusters" {
description = "Map of cluster spec keyed by short cluster name (sietch, painbox, ...)."
type = map(object({
domain = string
environment = string
datacenter = string
provider_code = string
role_in_hostname = optional(string, "ceph")
ansible_ssh_user = string
ansible_ssh_key = string
vault = optional(string, "Yucca")
provision_profile = optional(string)
hosts = list(object({
name = optional(string)
bond_ip = string
bootstrap = optional(bool, false)
roles = optional(list(string), ["mon", "mgr", "osd", "rgw"])
}))
}))
}
-16
View File
@@ -1,16 +0,0 @@
terraform {
required_version = ">= 1.6"
required_providers {
local = {
source = "hashicorp/local"
version = "~> 2.5"
}
random = {
source = "hashicorp/random"
version = "~> 3.6"
}
# onepassword provider re-enabled once a dedicated ceph-scoped 1P service
# account replaces the org-wide superuser SA (per ADR-009).
# Credentials via OP_SERVICE_ACCOUNT_TOKEN env var (injected by op run --env-file).
}
}
+3 -19
View File
@@ -1,26 +1,10 @@
# futo.cloud zone (FUTO Account).
zone_id = "474fbfd96bf49879054a493f126c4071"
# Sietch RGW S3 endpoint: round-robin A records across the 3 ceph nodes'
# bond IPs. The addresses are RFC1918 (10.10.10.0/24 management VLAN) —
# resolvable from anywhere, routable only from networks that reach the
# mgmt VLAN. proxied stays false everywhere here: Cloudflare cannot proxy
# private addresses, and these names are internal infrastructure.
#
# The wildcard serves S3 virtual-hosted bucket addressing
# (<bucket>.s3.dev.austin.int.futo.cloud); the cluster's rgw_dns_name and
# TLS SANs already expect it. See ansible/ceph/docs/s3-integration.md.
# The Sietch RGW S3 endpoint records (s3.dev + *.s3.dev) were removed when the
# Austin cluster was promoted dev -> staging; the live records now live in
# tf/deployment/staging/dns. Only the stray homelab record remains here.
records = {
"s3.dev.austin.int.futo.cloud" = {
type = "A"
values = ["10.10.10.90", "10.10.10.91", "10.10.10.92"]
comment = "Sietch RGW S3 endpoint (tf/deployment/dev/dns)"
}
"*.s3.dev.austin.int.futo.cloud" = {
type = "A"
values = ["10.10.10.90", "10.10.10.91", "10.10.10.92"]
comment = "Sietch RGW S3 virtual-hosted buckets (tf/deployment/dev/dns)"
}
# move me to somewhere sensible!
"futo.cloud" = {
type = "A"