refactor: collapse cdn.tf pullzones into for_each

bunnynet_pullzone.devxy-r-binaries (cran.devxy.io) and
bunnynet_pullzone.cran_rpkgs_com (cran.rpkgs.com) were byte-for-byte
identical except for the zone name and hostname. Same for the two
pullzone_hostname resources.

Use a single local.pullzones map and for_each on both resources, so
shared knobs (block_ips, limit_bandwidth, s3_auth_*, ...) only have
to be edited once.

State migration is handled by moved {} blocks so the existing
pullzones get re-addressed under the new for_each keys instead of
being destroyed+recreated. Run terraform plan to confirm a zero-
change apply before applying.
This commit is contained in:
Patrick Schratz 2026-05-28 15:52:28 +02:00
commit 346f5629eb
Signed by: pat-s
GPG key ID: 3C6318841EF78925

102
cdn.tf
View file

@ -1,7 +1,20 @@
# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone
# terraform import bunnynet_pullzone.devxy-r-binaries cran
resource "bunnynet_pullzone" "devxy-r-binaries" {
name = "cran"
locals {
pullzones = {
"cran" = {
hostname = "cran.devxy.io"
}
"cran-rpkgs" = {
hostname = "cran.rpkgs.com"
}
}
}
resource "bunnynet_pullzone" "this" {
for_each = local.pullzones
name = each.key
origin {
type = "OriginUrl"
@ -45,63 +58,11 @@ resource "bunnynet_pullzone" "devxy-r-binaries" {
block_root_path = true
}
resource "bunnynet_pullzone_hostname" "devxy-r-binaries" {
pullzone = bunnynet_pullzone.devxy-r-binaries.id
name = "cran.devxy.io"
force_ssl = true
tls_enabled = true
}
resource "bunnynet_pullzone_hostname" "this" {
for_each = local.pullzones
### cran.rpkgs.com
resource "bunnynet_pullzone" "cran_rpkgs_com" {
name = "cran-rpkgs"
origin {
type = "OriginUrl"
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
}
routing {
tier = "Standard"
}
s3_auth_enabled = true
s3_auth_key = var.B2_S3_ACCESS_KEY
s3_auth_secret = var.B2_S3_SECRET_KEY
s3_auth_region = "eu-central-003"
cache_enabled = true
cache_errors = true
request_coalescing_enabled = true
block_post_requests = true
limit_requests = 60
limit_connections = 10
safehop_enabled = true
add_canonical_header = true
cache_stale = ["offline", "updating"]
use_background_update = true
block_ips = [
"185.172.53.0"
]
# 50 TB
limit_bandwidth = 50000000000000
permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
block_root_path = true
}
resource "bunnynet_pullzone_hostname" "cran_rpkgs_com" {
pullzone = bunnynet_pullzone.cran_rpkgs_com.id
name = "cran.rpkgs.com"
pullzone = bunnynet_pullzone.this[each.key].id
name = each.value.hostname
force_ssl = true
tls_enabled = true
}
@ -113,3 +74,26 @@ resource "bunnynet_storage_zone" "devxy-r-binaries" {
# Los Angeles and Singapore
replication_regions = ["LA", "SG"]
}
# State-migration markers so the previously-singleton resources slide into
# the for_each map addresses without a destroy/create. Safe to delete after
# a successful apply on every workspace.
moved {
from = bunnynet_pullzone.devxy-r-binaries
to = bunnynet_pullzone.this["cran"]
}
moved {
from = bunnynet_pullzone.cran_rpkgs_com
to = bunnynet_pullzone.this["cran-rpkgs"]
}
moved {
from = bunnynet_pullzone_hostname.devxy-r-binaries
to = bunnynet_pullzone_hostname.this["cran"]
}
moved {
from = bunnynet_pullzone_hostname.cran_rpkgs_com
to = bunnynet_pullzone_hostname.this["cran-rpkgs"]
}