From 35dafab737da8d9d27b8caa62d92f7470818eb3f Mon Sep 17 00:00:00 2001 From: pat-s Date: Mon, 8 Jun 2026 08:29:06 +0000 Subject: [PATCH] refactor: hoist CDN block_ips to a variable (#81) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Summary `block_ips = ["185.172.53.0"]` was duplicated in both `bunnynet_pullzone` resources in `cdn.tf`. Move it to a typed `cdn_block_ips` variable in `vars.tf` with the existing IP as the default. - No plan diff on apply — same value, just sourced from `var.cdn_block_ips` instead of a literal. - Adding/removing IPs is now a one-line var override (or a default change) instead of two edits in the resource bodies. ## Interaction with #80 (for_each refactor) `#80` collapses the two pullzones to `bunnynet_pullzone.this[for_each]`. Either order works; whichever lands second is a trivial one-line rebase on the surviving `block_ips =` line. Reviewed-on: https://git.devxy.io/devxy/build-cran-binaries/pulls/81 --- cdn.tf | 8 ++------ vars.tf | 8 ++++++++ 2 files changed, 10 insertions(+), 6 deletions(-) diff --git a/cdn.tf b/cdn.tf index ea1ab2a..c41fdb4 100644 --- a/cdn.tf +++ b/cdn.tf @@ -32,9 +32,7 @@ resource "bunnynet_pullzone" "devxy-r-binaries" { cache_stale = ["offline", "updating"] use_background_update = true - block_ips = [ - "185.172.53.0" - ] + block_ips = var.cdn_block_ips # 50 TB limit_bandwidth = 50000000000000 @@ -86,9 +84,7 @@ resource "bunnynet_pullzone" "cran_rpkgs_com" { cache_stale = ["offline", "updating"] use_background_update = true - block_ips = [ - "185.172.53.0" - ] + block_ips = var.cdn_block_ips # 50 TB limit_bandwidth = 50000000000000 diff --git a/vars.tf b/vars.tf index aad56ff..b831269 100644 --- a/vars.tf +++ b/vars.tf @@ -17,3 +17,11 @@ variable "B2_S3_SECRET_KEY" { type = string sensitive = true } + +variable "cdn_block_ips" { + description = "IP addresses to block at the BunnyCDN pullzones (cran.devxy.io, cran.rpkgs.com)." + type = list(string) + default = [ + "185.172.53.0", + ] +}