refactor: hoist CDN block_ips to a variable
block_ips was hardcoded in both pullzones as a single IP
("185.172.53.0"). Move it to a variable so updates don't require
editing the resource bodies (and so a future for_each refactor
doesn't bake the list into the map).
Default keeps the existing entry; no plan diff on apply.
This commit is contained in:
parent
b1bed68898
commit
233dbfbdfd
2 changed files with 10 additions and 6 deletions
8
cdn.tf
8
cdn.tf
|
|
@ -32,9 +32,7 @@ resource "bunnynet_pullzone" "devxy-r-binaries" {
|
||||||
cache_stale = ["offline", "updating"]
|
cache_stale = ["offline", "updating"]
|
||||||
use_background_update = true
|
use_background_update = true
|
||||||
|
|
||||||
block_ips = [
|
block_ips = var.cdn_block_ips
|
||||||
"185.172.53.0"
|
|
||||||
]
|
|
||||||
|
|
||||||
# 50 TB
|
# 50 TB
|
||||||
limit_bandwidth = 50000000000000
|
limit_bandwidth = 50000000000000
|
||||||
|
|
@ -86,9 +84,7 @@ resource "bunnynet_pullzone" "cran_rpkgs_com" {
|
||||||
cache_stale = ["offline", "updating"]
|
cache_stale = ["offline", "updating"]
|
||||||
use_background_update = true
|
use_background_update = true
|
||||||
|
|
||||||
block_ips = [
|
block_ips = var.cdn_block_ips
|
||||||
"185.172.53.0"
|
|
||||||
]
|
|
||||||
|
|
||||||
# 50 TB
|
# 50 TB
|
||||||
limit_bandwidth = 50000000000000
|
limit_bandwidth = 50000000000000
|
||||||
|
|
|
||||||
8
vars.tf
8
vars.tf
|
|
@ -17,3 +17,11 @@ variable "B2_S3_SECRET_KEY" {
|
||||||
type = string
|
type = string
|
||||||
sensitive = true
|
sensitive = true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
variable "cdn_block_ips" {
|
||||||
|
description = "IP addresses to block at the BunnyCDN pullzones (cran.devxy.io, cran.rpkgs.com)."
|
||||||
|
type = list(string)
|
||||||
|
default = [
|
||||||
|
"185.172.53.0",
|
||||||
|
]
|
||||||
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue