mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
feat(net): add colt (#488)
This commit is contained in:
@@ -76,7 +76,8 @@ module "core" {
|
||||
# reachable on the spine via the Cilium iBGP /32). Counter samples every 5s =
|
||||
# the seconds-granularity bandwidth feed; every up physical port is listed
|
||||
# (sFlow attaches to members, not ae bundles): worker bonds (et-*/0/2:*), mgmt
|
||||
# hosts (et-*/0/3:0), transit (et-0/0/27), leaf uplink ae0 (et-*/0/30,31).
|
||||
# hosts (et-*/0/3:0), transits (et-0/0/27 Core-Backbone, et-1/0/27 Colt),
|
||||
# leaf uplink ae0 (et-*/0/30,31).
|
||||
sflow = {
|
||||
collector = cidrhost(module.addr_site.lb_internal_cidr, 14)
|
||||
agent_id = "69.48.224.254"
|
||||
@@ -86,7 +87,7 @@ module "core" {
|
||||
"xe-0/0/0:0", "xe-0/0/0:1", "xe-0/0/0:2",
|
||||
"xe-1/0/0:0", "xe-1/0/0:1", "xe-1/0/0:2",
|
||||
"et-0/0/3:0", "et-1/0/3:0",
|
||||
"et-0/0/27",
|
||||
"et-0/0/27", "et-1/0/27",
|
||||
"et-0/0/30", "et-0/0/31", "et-1/0/30", "et-1/0/31",
|
||||
]
|
||||
}
|
||||
@@ -100,10 +101,11 @@ module "core" {
|
||||
"10.40.10.13" = "69.48.224.243"
|
||||
}
|
||||
|
||||
# Upstream IP-transit. Today: one transit (Core-Backbone), primary/default
|
||||
# (prepend 0). Add a second entry with prepend>0 + a lower local_pref to
|
||||
# multi-home (the prepended one is the backup; see core-fabric/transit.tf —
|
||||
# prepend/local_pref need a provider regen to apply).
|
||||
# Upstream IP-transit, multi-homed active-active for egress: both received
|
||||
# defaults sit at the default local-pref and the groups run multipath
|
||||
# multiple-as (core-fabric/transit.tf), so the chassis-global ECMP export
|
||||
# (bgp-nodes.tf) hashes egress flows across both uplinks. Ingress still
|
||||
# favors Core-Backbone while colt exports with prepend 1.
|
||||
local_as = 402421
|
||||
transits = {
|
||||
core-backbone = {
|
||||
@@ -116,6 +118,17 @@ module "core" {
|
||||
advertise = "69.48.224.0/24"
|
||||
loopback = "69.48.224.254/32"
|
||||
}
|
||||
# v4-only handover (no v6 delivered). Colt's inbound route filter accepts
|
||||
# 69.48.224.0/22 le /24 from AS402421, so the /24 fits; widening past that
|
||||
# needs a Colt Online ticket.
|
||||
colt = {
|
||||
interface = "et-1/0/27"
|
||||
local_v4 = "62.67.19.110/30"
|
||||
peer_v4 = "62.67.19.109"
|
||||
peer_as = 8220
|
||||
advertise = "69.48.224.0/24"
|
||||
prepend = 1
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -43,12 +43,13 @@ module "netbox" {
|
||||
services = { prefix = "10.250.128.0/17", description = "father service CIDR (ClusterIPs; kube-dns at .128.10)", status = "container" }
|
||||
netbird = { prefix = "10.254.0.0/15", description = "NetBird mesh peer range (node plane CP<->worker, operators)", status = "container" }
|
||||
|
||||
public = { prefix = "69.48.224.0/24", description = "FUTO PI space announced from the spine (AS402421 via Core-Backbone)", status = "container" }
|
||||
lb_public_a = { prefix = "69.48.224.0/26", description = "Cilium LoadBalancer pool lb-public-a (father)" }
|
||||
lb_public_b = { prefix = "69.48.224.64/26", description = "Cilium LoadBalancer pool lb-public-b (father)" }
|
||||
worker_egress = { prefix = "69.48.224.240/29", description = "father worker fabric-egress SNAT IPs (.241 jeanne, .242 sheron, .243 dianna)" }
|
||||
spine_loopback = { prefix = "69.48.224.254/32", description = "spine lo0 (sFlow agent-id, LG source)" }
|
||||
transit_p2p = { prefix = "5.56.17.224/31", description = "Core-Backbone transit /31 (spine et-0/0/27)" }
|
||||
public = { prefix = "69.48.224.0/24", description = "FUTO PI space announced from the spine (AS402421 via Core-Backbone + Colt)", status = "container" }
|
||||
lb_public_a = { prefix = "69.48.224.0/26", description = "Cilium LoadBalancer pool lb-public-a (father)" }
|
||||
lb_public_b = { prefix = "69.48.224.64/26", description = "Cilium LoadBalancer pool lb-public-b (father)" }
|
||||
worker_egress = { prefix = "69.48.224.240/29", description = "father worker fabric-egress SNAT IPs (.241 jeanne, .242 sheron, .243 dianna)" }
|
||||
spine_loopback = { prefix = "69.48.224.254/32", description = "spine lo0 (sFlow agent-id, LG source)" }
|
||||
transit_p2p = { prefix = "5.56.17.224/31", description = "Core-Backbone transit /31 (spine et-0/0/27)" }
|
||||
transit_p2p_colt = { prefix = "62.67.19.108/30", description = "Colt transit /30 (spine et-1/0/27, v4-only; .109 Colt, .110 us)" }
|
||||
}
|
||||
|
||||
devices = {
|
||||
|
||||
@@ -153,9 +153,12 @@ resource "junos_interface_logical" "transit" {
|
||||
cidr_ip = each.value.local_v4
|
||||
}
|
||||
}
|
||||
family_inet6 {
|
||||
address {
|
||||
cidr_ip = each.value.local_v6
|
||||
dynamic "family_inet6" {
|
||||
for_each = each.value.local_v6 == null ? [] : [each.value.local_v6]
|
||||
content {
|
||||
address {
|
||||
cidr_ip = family_inet6.value
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -15,7 +15,7 @@ locals {
|
||||
[for t in var.transits : "${t.peer_v4}/32"],
|
||||
var.node_bgp == null ? [] : [var.node_bgp.peer_range],
|
||||
)
|
||||
bgp_trusted_v6 = [for t in var.transits : "${t.peer_v6}/128"]
|
||||
bgp_trusted_v6 = [for t in var.transits : "${t.peer_v6}/128" if t.peer_v6 != null]
|
||||
}
|
||||
|
||||
resource "junos_firewall_filter" "protect_re" {
|
||||
|
||||
@@ -34,11 +34,17 @@ resource "junos_static_route" "advertise" {
|
||||
discard = true
|
||||
}
|
||||
|
||||
# multiple-as: the transits' defaults come from different peer ASes, which plain
|
||||
# multipath refuses to combine. With equal local-pref they ECMP per-flow via the
|
||||
# chassis-global forwarding-table export (bgp-nodes.tf ECMP-LOAD-BALANCE).
|
||||
resource "junos_bgp_group" "transit" {
|
||||
for_each = var.transits
|
||||
name = each.key
|
||||
type = "external"
|
||||
peer_as = tostring(each.value.peer_as)
|
||||
bgp_multipath {
|
||||
multiple_as = true
|
||||
}
|
||||
}
|
||||
|
||||
# import/export live on the neighbor (matches the device), not the group.
|
||||
@@ -54,7 +60,7 @@ resource "junos_bgp_neighbor" "v4" {
|
||||
}
|
||||
|
||||
resource "junos_bgp_neighbor" "v6" {
|
||||
for_each = var.transits
|
||||
for_each = { for name, t in var.transits : name => t if t.peer_v6 != null }
|
||||
group = junos_bgp_group.transit[each.key].name
|
||||
ip = each.value.peer_v6
|
||||
import = ["${upper(each.key)}-IN"]
|
||||
|
||||
@@ -176,9 +176,9 @@ variable "transits" {
|
||||
type = map(object({
|
||||
interface = string # uplink port (e.g. et-0/0/27)
|
||||
local_v4 = string # our /31 (e.g. 5.56.17.225/31)
|
||||
local_v6 = string # our /64 (e.g. 2a01:4a0:1338:226::2/64)
|
||||
local_v6 = optional(string) # our /64; null = v4-only handover (no v6 unit address)
|
||||
peer_v4 = string # provider v4 (e.g. 5.56.17.224)
|
||||
peer_v6 = string # provider v6 (e.g. 2a01:4a0:1338:226::1)
|
||||
peer_v6 = optional(string) # provider v6; null = v4-only handover (no v6 neighbor)
|
||||
peer_as = number # provider ASN (e.g. 33891)
|
||||
advertise = string # prefix to originate + advertise
|
||||
loopback = optional(string) # lo0 host in the advertised space (e.g. 69.48.224.254/32)
|
||||
|
||||
Reference in New Issue
Block a user