mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
chore(ceph): decommission dev sietch stack, repoint defaults to staging (#186)
This commit is contained in:
+5
-5
@@ -71,20 +71,20 @@ run = [{ task = "*:fix" }, { task = "web:lingui" }]
|
||||
# No literal secrets in the .env file — just op:// references.
|
||||
|
||||
[tasks."tf:init"]
|
||||
description = "Terragrunt init for a given stack (default: deployment/dev/ceph)"
|
||||
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} init"
|
||||
description = "Terragrunt init for a given stack (default: deployment/staging/ceph)"
|
||||
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/ceph} init"
|
||||
|
||||
[tasks."tf:plan"]
|
||||
description = "Terragrunt plan for a given stack"
|
||||
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} plan"
|
||||
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/ceph} plan"
|
||||
|
||||
[tasks."tf:apply"]
|
||||
description = "Terragrunt apply for a given stack"
|
||||
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} apply"
|
||||
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/ceph} apply"
|
||||
|
||||
[tasks."tf:destroy"]
|
||||
description = "Terragrunt destroy for a given stack (use with care)"
|
||||
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} destroy"
|
||||
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/ceph} destroy"
|
||||
|
||||
[tasks."tf:fmt"]
|
||||
description = "Format terraform + terragrunt files recursively"
|
||||
|
||||
@@ -8,7 +8,7 @@ PATH = "{{config_root}}/.venv/bin:{{env.PATH}}"
|
||||
# Note: CEPH_ENV is intentionally NOT declared here. mise's [env] block
|
||||
# overrides shell-exported values, which silently sends operators to the
|
||||
# wrong cluster. Operators must export CEPH_ENV once per shell session:
|
||||
# export CEPH_ENV=inventories/sietch-ceph.dev.austin.int/inventory.ini
|
||||
# export CEPH_ENV=inventories/sietch-ceph.staging.austin.int/inventory.ini
|
||||
# export CEPH_ENV=inventories/painbox-ceph.dev.hel.htz/inventory.ini
|
||||
# Inventory files are TF-generated — `mise run tf:apply` (from yucca root) if missing.
|
||||
|
||||
@@ -64,7 +64,7 @@ run = """
|
||||
set -euo pipefail
|
||||
# Syntax-check only parses YAML — any valid inventory works. Default to
|
||||
# sietch when CEPH_ENV isn't inline-prefixed; the parse is identical.
|
||||
CEPH_ENV="${CEPH_ENV:-inventories/sietch-ceph.dev.austin.int/inventory.ini}"
|
||||
CEPH_ENV="${CEPH_ENV:-inventories/sietch-ceph.staging.austin.int/inventory.ini}"
|
||||
for pb in *.yml; do
|
||||
case "$pb" in
|
||||
requirements.yml|ansible-navigator.yml) continue ;;
|
||||
@@ -125,7 +125,7 @@ run = """
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
CEPH_ENV_DIR=$(dirname "$CEPH_ENV")
|
||||
CLUSTER_ID=$(basename "$CEPH_ENV_DIR") # e.g., sietch-ceph.dev.austin.int
|
||||
CLUSTER_ID=$(basename "$CEPH_ENV_DIR") # e.g., sietch-ceph.staging.austin.int
|
||||
DOMAIN=${CLUSTER_ID#*-ceph.}.futo.cloud # e.g., dev.austin.int.futo.cloud
|
||||
DESTROY_INV="$CEPH_ENV_DIR/inventory-destroy.ini"
|
||||
echo "Usage: scripts/ansible-play.sh destroy-ceph.yml \\"
|
||||
|
||||
@@ -1,111 +0,0 @@
|
||||
---
|
||||
# === Naming ===
|
||||
cluster_name: sietch
|
||||
cluster_role: ceph
|
||||
|
||||
# === Network ===
|
||||
cluster_domain: dev.austin.int.futo.cloud
|
||||
public_network: 10.10.10.0/24
|
||||
cluster_network: 10.10.10.0/24
|
||||
gateway: 10.10.10.1
|
||||
dns_server: 10.10.10.1
|
||||
bond_mode: active-backup
|
||||
bond_interfaces:
|
||||
- eno1np0
|
||||
- eno2np1
|
||||
networkd_enabled: true
|
||||
|
||||
# === Ceph ===
|
||||
ceph_release: tentacle
|
||||
ceph_repo_url: "https://download.ceph.com/debian-{{ ceph_release }}/"
|
||||
ceph_repo_key_url: "https://download.ceph.com/keys/release.asc"
|
||||
|
||||
# === OS Provisioning ===
|
||||
admin_user: ansible-iac
|
||||
timezone: UTC
|
||||
|
||||
# Deploy keypair path on the controller. Both {path} and {path}.pub must
|
||||
# exist before running provision.yml (the preflight play in provision.yml
|
||||
# enforces this). ansible-iac's authorized_keys on every node is populated
|
||||
# by a file lookup at provision time — rotating the key on the controller
|
||||
# automatically propagates on the next re-provision.
|
||||
provision_iac_ssh_key_path: "~/.ssh/id_ed25519_sietch"
|
||||
|
||||
# 1P vault for cluster secret lookups (e.g., rotate-ssh-key.yml reads pubkey from here).
|
||||
cluster_secrets_vault: yucca_tf_dev
|
||||
|
||||
# Secret aliases — vault_* vars populated by scripts/ansible-play.sh via op inject
|
||||
#
|
||||
# Note: the deploy public key is NOT a secret — it's public data and lives
|
||||
# at {{ provision_iac_ssh_key_path }}.pub on the controller. Reading it via
|
||||
# file lookup avoids drift between vault and disk.
|
||||
ops_password: "{{ vault_ops_password }}"
|
||||
ceph_dashboard_user: admin
|
||||
ceph_dashboard_password: "{{ vault_ceph_dashboard_password }}"
|
||||
|
||||
# S3 svc-user (yucca-restic consumer) — TF+1P-predetermined keys passed to
|
||||
# `radosgw-admin user create --access-key=... --secret-key=...` so the Yucca
|
||||
# app can be pre-configured with matching credentials. Rotation path documented
|
||||
# in docs/runbooks/rotate-secrets.md.
|
||||
ceph_rgw_s3_user_access_key: "{{ vault_s3_restic_access_key }}"
|
||||
ceph_rgw_s3_user_secret_key: "{{ vault_s3_restic_secret_key }}"
|
||||
|
||||
# === Storage ===
|
||||
ssd_model_pattern: "Micron_5100"
|
||||
|
||||
os_partitions:
|
||||
esp_size: "512M"
|
||||
boot_size: "1G"
|
||||
root_size: "80G"
|
||||
swap_size: "8G"
|
||||
ceph_db_size: "1440G"
|
||||
|
||||
ceph_db_lv_size: "240G"
|
||||
ceph_db_lvs_per_ssd: 6
|
||||
|
||||
# === RGW (Object Gateway) ===
|
||||
ceph_rgw_realm: sietch
|
||||
ceph_rgw_zonegroup: us-east-1
|
||||
ceph_rgw_zonegroup_api_name: us-east-1
|
||||
ceph_rgw_zone: dev-z1
|
||||
ceph_rgw_ec_profile: ec-k8m3-osd
|
||||
ceph_rgw_ec_k: 8
|
||||
ceph_rgw_ec_m: 3
|
||||
ceph_rgw_ec_failure_domain: osd
|
||||
ceph_rgw_ec_device_class: hdd
|
||||
ceph_rgw_data_pool: "{{ ceph_rgw_zone }}.rgw.buckets.data"
|
||||
ceph_rgw_index_pool: "{{ ceph_rgw_zone }}.rgw.buckets.index"
|
||||
ceph_rgw_extra_pool: "{{ ceph_rgw_zone }}.rgw.buckets.non-ec"
|
||||
ceph_rgw_replicated_size: 2
|
||||
ceph_rgw_replicated_min_size: 1
|
||||
ceph_rgw_port: 443
|
||||
ceph_rgw_s3_user_uid: svc-yucca-restic
|
||||
ceph_rgw_s3_user_display_name: "yucca/restic service account"
|
||||
|
||||
# --- RGW DNS + TLS ---
|
||||
# Virtual-hosted S3 support: setting rgw_dns_name tells RGW to strip this
|
||||
# suffix from the Host header and treat the remainder as the bucket name.
|
||||
# Requires matching DNS: both s3.<domain> and *.s3.<domain> should resolve
|
||||
# to the cluster nodes (round-robin A, or VIP/LB in prod).
|
||||
ceph_rgw_dns_name: s3.dev.austin.int.futo.cloud
|
||||
|
||||
# Self-signed wildcard cert handed to cephadm via service spec.
|
||||
# cephadm distributes to all RGW daemons. To rotate, delete
|
||||
# /etc/ceph/rgw-ssl.{crt,key} on the bootstrap node and re-run the role.
|
||||
ceph_rgw_ssl: true
|
||||
ceph_rgw_ssl_cert_days: 3650 # 10 years
|
||||
ceph_rgw_ssl_cert_subject_c: US
|
||||
ceph_rgw_ssl_cert_subject_st: Texas
|
||||
ceph_rgw_ssl_cert_subject_l: Austin
|
||||
ceph_rgw_ssl_cert_subject_o: FUTO
|
||||
ceph_rgw_ssl_cert_email: yucca@futo.org
|
||||
|
||||
# Computed: scheme used for endpoints, debug output, and zonegroup/zone URLs
|
||||
ceph_rgw_scheme: "{{ 'https' if ceph_rgw_ssl else 'http' }}"
|
||||
|
||||
# === Monitoring Stack ===
|
||||
ceph_prometheus_port: 9095
|
||||
ceph_grafana_port: 3000
|
||||
ceph_alertmanager_port: 9093
|
||||
ceph_grafana_admin_user: admin
|
||||
ceph_grafana_admin_password: "{{ vault_grafana_admin_password }}"
|
||||
@@ -1,36 +0,0 @@
|
||||
---
|
||||
# Copy to host_vars/sietch-ceph-<name>.yml (full inventory_hostname).
|
||||
# The <name> segment is either operator-declared in clusters.auto.tfvars
|
||||
# or TF-auto-picked from wordlist.txt — see docs/naming.md.
|
||||
# Filename MUST match inventory_hostname for Ansible auto-load.
|
||||
# Values are node-specific — hardware paths differ per chassis.
|
||||
hostname_short: sietch-ceph-EXAMPLE
|
||||
bond_ip: 10.0.0.1
|
||||
|
||||
# SAS expander base path (unique per chassis)
|
||||
# Find with: ls /dev/disk/by-path/ | grep sas
|
||||
sas_path_prefix: "pci-0000:02:00.0-sas-exp0x500056b3XXXXXXXX"
|
||||
|
||||
# SSD PHY positions in the SAS topology
|
||||
ssd1_phy: 12
|
||||
ssd2_phy: 13
|
||||
|
||||
# LVM volume group names for block.db (on SSD partition 5)
|
||||
ceph_db_vg1: ceph-db-ssd1
|
||||
ceph_db_vg2: ceph-db-ssd2
|
||||
|
||||
# HDD OSD mappings: SAS PHY slot -> block.db LV
|
||||
# 6 HDDs per SSD, each gets a dedicated 240G block.db LV
|
||||
ceph_hdd_osds:
|
||||
- path_phy: phy0
|
||||
db: ceph-db-ssd1/db-slot0
|
||||
- path_phy: phy1
|
||||
db: ceph-db-ssd1/db-slot1
|
||||
# ... one entry per HDD
|
||||
|
||||
# SSD OSD partitions (partition 6 on each SSD, no separate block.db)
|
||||
ceph_ssd_osds:
|
||||
- path_phy: phy12
|
||||
partition: 6
|
||||
- path_phy: phy13
|
||||
partition: 6
|
||||
@@ -1,52 +0,0 @@
|
||||
---
|
||||
hostname_short: sietch-ceph-laurel
|
||||
bond_ip: 10.10.10.90
|
||||
|
||||
# SAS expander base path (unique per chassis — different backplane address per node)
|
||||
sas_path_prefix: "pci-0000:02:00.0-sas-exp0x500056b3fcf498ff"
|
||||
|
||||
# SSD PHY positions (rear bays)
|
||||
ssd1_phy: 12 # serial 17321A07BA4A
|
||||
ssd2_phy: 13 # serial 17321A07CFEE
|
||||
|
||||
# LVM VGs on SSD partition 5
|
||||
ceph_db_vg1: ceph-db-rear12 # VG on SSD1 (phy12) partition 5
|
||||
ceph_db_vg2: ceph-db-rear13 # VG on SSD2 (phy13) partition 5
|
||||
|
||||
# HDD OSD mappings: PHY slot -> block.db LV
|
||||
# PHY 0-5 -> SSD1 (ceph-db-rear12/db-slot0..5)
|
||||
# PHY 6-11 -> SSD2 (ceph-db-rear13/db-slot6..11)
|
||||
# by-path is slot-stable: replacing a drive in the same bay keeps the same path
|
||||
# 12 HDDs — all front bays populated
|
||||
ceph_hdd_osds:
|
||||
- path_phy: phy0
|
||||
db: ceph-db-rear12/db-slot0
|
||||
- path_phy: phy1
|
||||
db: ceph-db-rear12/db-slot1
|
||||
- path_phy: phy2
|
||||
db: ceph-db-rear12/db-slot2
|
||||
- path_phy: phy3
|
||||
db: ceph-db-rear12/db-slot3 # serial Z4D09B99 (ST6000NKCLAR6000, added 2026-04-10)
|
||||
- path_phy: phy4
|
||||
db: ceph-db-rear12/db-slot4
|
||||
- path_phy: phy5
|
||||
db: ceph-db-rear12/db-slot5 # serial Z4D0G7VC (ST6000NKCLAR6000, added 2026-04-10)
|
||||
- path_phy: phy6
|
||||
db: ceph-db-rear13/db-slot6
|
||||
- path_phy: phy7
|
||||
db: ceph-db-rear13/db-slot7 # serial Z4D0G7SC (ST6000NKCLAR6000, added 2026-04-10)
|
||||
- path_phy: phy8
|
||||
db: ceph-db-rear13/db-slot8
|
||||
- path_phy: phy9
|
||||
db: ceph-db-rear13/db-slot9
|
||||
- path_phy: phy10
|
||||
db: ceph-db-rear13/db-slot10 # serial Z4D0G7XK (ST6000NKCLAR6000, added 2026-04-10)
|
||||
- path_phy: phy11
|
||||
db: ceph-db-rear13/db-slot11
|
||||
|
||||
# SSD OSD partitions (partition 6 on each rear SSD, no separate block.db)
|
||||
ceph_ssd_osds:
|
||||
- path_phy: phy12
|
||||
partition: 6
|
||||
- path_phy: phy13
|
||||
partition: 6
|
||||
@@ -1,52 +0,0 @@
|
||||
---
|
||||
hostname_short: sietch-ceph-lawson
|
||||
bond_ip: 10.10.10.91
|
||||
|
||||
# SAS expander base path (unique per chassis — different backplane address per node)
|
||||
sas_path_prefix: "pci-0000:02:00.0-sas-exp0x500056b35be6b4ff"
|
||||
|
||||
# SSD PHY positions (rear bays)
|
||||
ssd1_phy: 12 # serial 17321A07CF91
|
||||
ssd2_phy: 13 # serial 17251B44C4D8
|
||||
|
||||
# LVM VGs on SSD partition 5
|
||||
ceph_db_vg1: ceph-db-rear12 # VG on SSD1 (phy12) partition 5
|
||||
ceph_db_vg2: ceph-db-rear13 # VG on SSD2 (phy13) partition 5
|
||||
|
||||
# HDD OSD mappings: PHY slot -> block.db LV
|
||||
# PHY 0-5 -> SSD1 (ceph-db-rear12/db-slot0..5)
|
||||
# PHY 6-11 -> SSD2 (ceph-db-rear13/db-slot6..11)
|
||||
# by-path is slot-stable: replacing a drive in the same bay keeps the same path
|
||||
# 12 HDDs — all front bays populated
|
||||
ceph_hdd_osds:
|
||||
- path_phy: phy0
|
||||
db: ceph-db-rear12/db-slot0
|
||||
- path_phy: phy1
|
||||
db: ceph-db-rear12/db-slot1
|
||||
- path_phy: phy2
|
||||
db: ceph-db-rear12/db-slot2
|
||||
- path_phy: phy3
|
||||
db: ceph-db-rear12/db-slot3
|
||||
- path_phy: phy4
|
||||
db: ceph-db-rear12/db-slot4
|
||||
- path_phy: phy5
|
||||
db: ceph-db-rear12/db-slot5
|
||||
- path_phy: phy6
|
||||
db: ceph-db-rear13/db-slot6
|
||||
- path_phy: phy7
|
||||
db: ceph-db-rear13/db-slot7 # serial Z4D0GKJX (ST6000NKCLAR6000, added 2026-04-10)
|
||||
- path_phy: phy8
|
||||
db: ceph-db-rear13/db-slot8
|
||||
- path_phy: phy9
|
||||
db: ceph-db-rear13/db-slot9
|
||||
- path_phy: phy10
|
||||
db: ceph-db-rear13/db-slot10
|
||||
- path_phy: phy11
|
||||
db: ceph-db-rear13/db-slot11
|
||||
|
||||
# SSD OSD partitions (partition 6 on each rear SSD, no separate block.db)
|
||||
ceph_ssd_osds:
|
||||
- path_phy: phy12
|
||||
partition: 6
|
||||
- path_phy: phy13
|
||||
partition: 6
|
||||
@@ -1,52 +0,0 @@
|
||||
---
|
||||
hostname_short: sietch-ceph-samara
|
||||
bond_ip: 10.10.10.92
|
||||
|
||||
# SAS expander base path (unique per chassis — different backplane address per node)
|
||||
sas_path_prefix: "pci-0000:02:00.0-sas-exp0x500056b3393ba1ff"
|
||||
|
||||
# SSD PHY positions (rear bays)
|
||||
ssd1_phy: 12 # serial 17321A07D1D3
|
||||
ssd2_phy: 13 # serial 17251B44DF51
|
||||
|
||||
# LVM VGs on SSD partition 5
|
||||
ceph_db_vg1: ceph-db-rear12 # VG on SSD1 (phy12) partition 5
|
||||
ceph_db_vg2: ceph-db-rear13 # VG on SSD2 (phy13) partition 5
|
||||
|
||||
# HDD OSD mappings: PHY slot -> block.db LV
|
||||
# PHY 0-5 -> SSD1 (ceph-db-rear12/db-slot0..5)
|
||||
# PHY 6-11 -> SSD2 (ceph-db-rear13/db-slot6..11)
|
||||
# by-path is slot-stable: replacing a drive in the same bay keeps the same path
|
||||
# 12 HDDs — all front bays populated
|
||||
ceph_hdd_osds:
|
||||
- path_phy: phy0
|
||||
db: ceph-db-rear12/db-slot0
|
||||
- path_phy: phy1
|
||||
db: ceph-db-rear12/db-slot1
|
||||
- path_phy: phy2
|
||||
db: ceph-db-rear12/db-slot2
|
||||
- path_phy: phy3
|
||||
db: ceph-db-rear12/db-slot3
|
||||
- path_phy: phy4
|
||||
db: ceph-db-rear12/db-slot4 # serial Z4D0GKB2 (replacement, added 2026-04-11)
|
||||
- path_phy: phy5
|
||||
db: ceph-db-rear12/db-slot5
|
||||
- path_phy: phy6
|
||||
db: ceph-db-rear13/db-slot6
|
||||
- path_phy: phy7
|
||||
db: ceph-db-rear13/db-slot7
|
||||
- path_phy: phy8
|
||||
db: ceph-db-rear13/db-slot8
|
||||
- path_phy: phy9
|
||||
db: ceph-db-rear13/db-slot9
|
||||
- path_phy: phy10
|
||||
db: ceph-db-rear13/db-slot10
|
||||
- path_phy: phy11
|
||||
db: ceph-db-rear13/db-slot11
|
||||
|
||||
# SSD OSD partitions (partition 6 on each rear SSD, no separate block.db)
|
||||
ceph_ssd_osds:
|
||||
- path_phy: phy12
|
||||
partition: 6
|
||||
- path_phy: phy13
|
||||
partition: 6
|
||||
@@ -26,7 +26,7 @@ declare -A KEYS=(
|
||||
# different env vaults (e.g. sietch moves to yucca_tf_staging on promotion).
|
||||
# Override any lookup with OP_VAULT=<vault>.
|
||||
declare -A VAULTS=(
|
||||
[sietch]="yucca_tf_dev"
|
||||
[sietch]="yucca_tf_staging"
|
||||
[painbox]="yucca_tf_dev"
|
||||
)
|
||||
DEFAULT_VAULT="yucca_tf_dev"
|
||||
|
||||
-42
@@ -1,42 +0,0 @@
|
||||
# This file is maintained automatically by "tofu init".
|
||||
# Manual edits may be lost in future updates.
|
||||
|
||||
provider "registry.opentofu.org/hashicorp/local" {
|
||||
version = "2.8.0"
|
||||
constraints = "~> 2.5"
|
||||
hashes = [
|
||||
"h1:3c528BCbO8BFB7199qOBFpJ20Xoals6eSDcLX/GRzxA=",
|
||||
"zh:0aaa04a29638eb2f84145aeec030ed4b469980c51f60f7f72ddbd705e0c9ceea",
|
||||
"zh:1d2f29cdfdc607f6b6b641e8bc7b00c73ac29f572ae8aa9b18fd068c107a7315",
|
||||
"zh:3cba45610ee2abbbe73694f5604d6628b036cee35d5e77f2353043088e950ff2",
|
||||
"zh:435fca586d45fcf200974d90962fa4cffaf761bad4c774bd34d1b92463a9887f",
|
||||
"zh:662748c6ad1e3d64500b70d3e2ccd5d2b04471dfd687c524f15bf3dbe68954a2",
|
||||
"zh:68f3a6dd1a6ddb7f4935ce894861740dd39f2202c5ba4aebc217c742e426a80c",
|
||||
"zh:75267c8b3d693125e7c6814058fef6189e0dae6c44c47cd63109d919b35e665e",
|
||||
"zh:88a1e4c13876774fae1ae20129a328cb6031e3aca00435bc7899e4038c2f43f7",
|
||||
"zh:8b8bffe1adeedf13a5c4af7b208b47ca5d4cac09ff51028962a3465e26830fef",
|
||||
"zh:b99ddf3c8fb730e4a9e4ded4c5706bcca3b7b8d2f2ea458f01a4dda26c78fdd3",
|
||||
"zh:d08174d23b2fe4a53b7f81f32ff0089e6ca76162a9de3c411deff7eb45d3d677",
|
||||
"zh:d220cd9f2ea3426ab5e2c528700c15d8fbcd4254496a84945b38885c6e4b18d3",
|
||||
"zh:de1e7f2ec372aaf717a26017e25f24bc22cbfc0e1691711484df26d828c6f8a0",
|
||||
"zh:e1b7c0ccaea53904b999a0d3993e86b97766eaa3698040c0bbe14b453cefd91a",
|
||||
"zh:e7eacd0e7a223fee0ac1fee5f032199219fde3cf0db43ad9d31b75a122f440ae",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.opentofu.org/hashicorp/random" {
|
||||
version = "3.8.1"
|
||||
constraints = "~> 3.6"
|
||||
hashes = [
|
||||
"h1:EHn3jsqOKhWjbg0X+psk0Ww96yz3N7ASqEKKuFvDFwo=",
|
||||
"zh:25c458c7c676f15705e872202dad7dcd0982e4a48e7ea1800afa5fc64e77f4c8",
|
||||
"zh:2edeaf6f1b20435b2f81855ad98a2e70956d473be9e52a5fdf57ccd0098ba476",
|
||||
"zh:44becb9d5f75d55e36dfed0c5beabaf4c92e0a2bc61a3814d698271c646d48e7",
|
||||
"zh:7699032612c3b16cc69928add8973de47b10ce81b1141f30644a0e8a895b5cd3",
|
||||
"zh:86d07aa98d17703de9fbf402c89590dc1e01dbe5671dd6bc5e487eb8fe87eee0",
|
||||
"zh:8c411c77b8390a49a8a1bc9f176529e6b32369dd33a723606c8533e5ca4d68c1",
|
||||
"zh:a5ecc8255a612652a56b28149994985e2c4dc046e5d34d416d47fa7767f5c28f",
|
||||
"zh:aea3fe1a5669b932eda9c5c72e5f327db8da707fe514aaca0d0ef60cb24892f9",
|
||||
"zh:f56e26e6977f755d7ae56fa6320af96ecf4bb09580d47cb481efbf27f1c5afff",
|
||||
]
|
||||
}
|
||||
@@ -1,26 +0,0 @@
|
||||
# Declarative cluster inventory. Adding a cluster = add an entry here, run
|
||||
# `terragrunt apply`, then `ansible/ceph/scripts/render-inventories.sh dev`.
|
||||
#
|
||||
# painbox is intentionally NOT managed here right now: it is in active use by
|
||||
# Zack for other purposes, so this stack must not render or reconcile it. Its
|
||||
# spec is kept as a reference in clusters.example.tfvars (not auto-loaded). Its
|
||||
# 1Password items are left untouched.
|
||||
|
||||
clusters = {
|
||||
sietch = {
|
||||
domain = "dev.austin.int.futo.cloud"
|
||||
environment = "dev"
|
||||
datacenter = "austin"
|
||||
provider_code = "int"
|
||||
role_in_hostname = "ceph"
|
||||
ansible_ssh_user = "ansible-iac"
|
||||
ansible_ssh_key = "~/.ssh/id_ed25519_sietch"
|
||||
vault = "yucca_tf_dev"
|
||||
provision_profile = "debian-live"
|
||||
hosts = [
|
||||
{ name = "laurel", bond_ip = "10.10.10.90", bootstrap = true },
|
||||
{ name = "lawson", bond_ip = "10.10.10.91" },
|
||||
{ name = "samara", bond_ip = "10.10.10.92" },
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -1,27 +0,0 @@
|
||||
# Example cluster spec, NOT auto-loaded (only *.auto.tfvars is). Kept as a
|
||||
# reference for clusters that exist but are not currently managed by this stack.
|
||||
#
|
||||
# painbox: a single-node Ceph Tentacle cluster on Bookworm (1x SX295) in
|
||||
# Hetzner Helsinki, reprovisioned end to end via Hetzner installimage (hence no
|
||||
# provision_profile; installimage handles partitioning + base OS). It is in
|
||||
# active use by Zack, so it is excluded from clusters.auto.tfvars. To bring it
|
||||
# back under management, move this entry into the clusters map there, run
|
||||
# `terragrunt apply`, then render. Its 1Password items already exist in
|
||||
# yucca_tf_dev and are left untouched either way.
|
||||
#
|
||||
# clusters = {
|
||||
# painbox = {
|
||||
# domain = "dev.hel.htz.futo.cloud"
|
||||
# environment = "dev"
|
||||
# datacenter = "hel"
|
||||
# provider_code = "htz"
|
||||
# role_in_hostname = "ceph"
|
||||
# ansible_ssh_user = "root"
|
||||
# ansible_ssh_key = "~/.ssh/id_ed25519_painbox"
|
||||
# vault = "yucca_tf_dev"
|
||||
# # Auto-picked wordlist name: "evelyn" -> painbox-ceph-evelyn.
|
||||
# hosts = [
|
||||
# { bond_ip = "157.180.105.198", bootstrap = true },
|
||||
# ]
|
||||
# }
|
||||
# }
|
||||
@@ -1,50 +0,0 @@
|
||||
module "cluster" {
|
||||
for_each = var.clusters
|
||||
source = "../../../shared/modules/ceph-cluster"
|
||||
|
||||
cluster_name = each.key
|
||||
domain = each.value.domain
|
||||
environment = each.value.environment
|
||||
datacenter = each.value.datacenter
|
||||
provider_code = each.value.provider_code
|
||||
role_in_hostname = coalesce(each.value.role_in_hostname, "ceph")
|
||||
ansible_ssh_user = each.value.ansible_ssh_user
|
||||
ansible_ssh_key = each.value.ansible_ssh_key
|
||||
vault = coalesce(each.value.vault, "Yucca")
|
||||
hosts = each.value.hosts
|
||||
|
||||
provision_profile = each.value.provision_profile
|
||||
|
||||
# NOTE: onepassword_item provisioning is dormant per ADR-009. Re-enable
|
||||
# once a dedicated ceph-scoped 1P service account replaces the org-wide
|
||||
# superuser SA (current blocker). See secrets.tf.disabled for the dormant
|
||||
# resource declarations. Items referenced by secrets.yml.tpl already exist
|
||||
# in var.vault (yucca_tf_dev) — created via the superuser SA + op CLI.
|
||||
}
|
||||
|
||||
output "cluster_summaries" {
|
||||
value = {
|
||||
for k, m in module.cluster : k => {
|
||||
fqdn = m.fqdn_cluster
|
||||
bootstrap_host = m.bootstrap_host.hostname_short
|
||||
host_count = length(m.hosts)
|
||||
inventory_dir = m.inventory_dirname
|
||||
secrets = m.secrets
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# Consumed by ansible/ceph/scripts/render-inventories.sh: it reads this output
|
||||
# and writes each cluster's files under ansible/ceph/inventories/<dirname>/.
|
||||
# Rendered content lives in a TF OUTPUT (not in local_file resources), so the
|
||||
# shared remote state never records a checkout-specific filesystem path. See
|
||||
# the module's rendering.tf for the full rationale.
|
||||
output "render" {
|
||||
description = "Per-cluster { dirname, files } for the local render wrapper."
|
||||
value = {
|
||||
for k, m in module.cluster : k => {
|
||||
dirname = m.inventory_dirname
|
||||
files = m.rendered_files
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,9 +0,0 @@
|
||||
include "root" {
|
||||
path = find_in_parent_folders("terragrunt.hcl")
|
||||
}
|
||||
|
||||
# clusters.auto.tfvars is automatically loaded by OpenTofu in this directory.
|
||||
# No inputs are injected here: rendered inventories are no longer written by
|
||||
# tofu (which previously needed get_repo_root() to locate ansible/ceph and so
|
||||
# coupled shared state to the applying worktree). Content is emitted via the
|
||||
# `render` output and written locally by ansible/ceph/scripts/render-inventories.sh.
|
||||
@@ -1,20 +0,0 @@
|
||||
variable "clusters" {
|
||||
description = "Map of cluster spec keyed by short cluster name (sietch, painbox, ...)."
|
||||
type = map(object({
|
||||
domain = string
|
||||
environment = string
|
||||
datacenter = string
|
||||
provider_code = string
|
||||
role_in_hostname = optional(string, "ceph")
|
||||
ansible_ssh_user = string
|
||||
ansible_ssh_key = string
|
||||
vault = optional(string, "Yucca")
|
||||
provision_profile = optional(string)
|
||||
hosts = list(object({
|
||||
name = optional(string)
|
||||
bond_ip = string
|
||||
bootstrap = optional(bool, false)
|
||||
roles = optional(list(string), ["mon", "mgr", "osd", "rgw"])
|
||||
}))
|
||||
}))
|
||||
}
|
||||
@@ -1,16 +0,0 @@
|
||||
terraform {
|
||||
required_version = ">= 1.6"
|
||||
required_providers {
|
||||
local = {
|
||||
source = "hashicorp/local"
|
||||
version = "~> 2.5"
|
||||
}
|
||||
random = {
|
||||
source = "hashicorp/random"
|
||||
version = "~> 3.6"
|
||||
}
|
||||
# onepassword provider re-enabled once a dedicated ceph-scoped 1P service
|
||||
# account replaces the org-wide superuser SA (per ADR-009).
|
||||
# Credentials via OP_SERVICE_ACCOUNT_TOKEN env var (injected by op run --env-file).
|
||||
}
|
||||
}
|
||||
@@ -1,26 +1,10 @@
|
||||
# futo.cloud zone (FUTO Account).
|
||||
zone_id = "474fbfd96bf49879054a493f126c4071"
|
||||
|
||||
# Sietch RGW S3 endpoint: round-robin A records across the 3 ceph nodes'
|
||||
# bond IPs. The addresses are RFC1918 (10.10.10.0/24 management VLAN) —
|
||||
# resolvable from anywhere, routable only from networks that reach the
|
||||
# mgmt VLAN. proxied stays false everywhere here: Cloudflare cannot proxy
|
||||
# private addresses, and these names are internal infrastructure.
|
||||
#
|
||||
# The wildcard serves S3 virtual-hosted bucket addressing
|
||||
# (<bucket>.s3.dev.austin.int.futo.cloud); the cluster's rgw_dns_name and
|
||||
# TLS SANs already expect it. See ansible/ceph/docs/s3-integration.md.
|
||||
# The Sietch RGW S3 endpoint records (s3.dev + *.s3.dev) were removed when the
|
||||
# Austin cluster was promoted dev -> staging; the live records now live in
|
||||
# tf/deployment/staging/dns. Only the stray homelab record remains here.
|
||||
records = {
|
||||
"s3.dev.austin.int.futo.cloud" = {
|
||||
type = "A"
|
||||
values = ["10.10.10.90", "10.10.10.91", "10.10.10.92"]
|
||||
comment = "Sietch RGW S3 endpoint (tf/deployment/dev/dns)"
|
||||
}
|
||||
"*.s3.dev.austin.int.futo.cloud" = {
|
||||
type = "A"
|
||||
values = ["10.10.10.90", "10.10.10.91", "10.10.10.92"]
|
||||
comment = "Sietch RGW S3 virtual-hosted buckets (tf/deployment/dev/dns)"
|
||||
}
|
||||
# move me to somewhere sensible!
|
||||
"futo.cloud" = {
|
||||
type = "A"
|
||||
|
||||
Reference in New Issue
Block a user