chore: cleanup and adjust cdn definitions
All checks were successful
ci/crow/cron/process-updates-ubuntu-2404-amd64 Pipeline was successful
ci/crow/cron/process-updates-ubuntu-2404-arm64 Pipeline was successful
ci/crow/cron/process-updates-redhat-10-amd64 Pipeline was successful
ci/crow/cron/process-updates-redhat-10-arm64 Pipeline was successful

This commit is contained in:
Patrick Schratz 2026-06-11 11:16:55 +02:00
commit 44482b18f9
Signed by: pat-s
GPG key ID: 3C6318841EF78925

111
cdn.tf
View file

@ -1,67 +1,76 @@
# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone
# terraform import bunnynet_pullzone.devxy-r-binaries cran
resource "bunnynet_pullzone" "devxy-r-binaries" {
name = "cran"
# resource "bunnynet_pullzone" "devxy-r-binaries" {
# name = "cran"
origin {
type = "OriginUrl"
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
}
# origin {
# type = "OriginUrl"
# url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
# }
routing {
tier = "Standard"
}
# routing {
# tier = "Standard"
# }
s3_auth_enabled = true
s3_auth_key = var.B2_S3_ACCESS_KEY
s3_auth_secret = var.B2_S3_SECRET_KEY
s3_auth_region = "eu-central-003"
# s3_auth_enabled = true
# s3_auth_key = var.B2_S3_ACCESS_KEY
# s3_auth_secret = var.B2_S3_SECRET_KEY
# s3_auth_region = "eu-central-003"
cache_enabled = true
cache_errors = true
request_coalescing_enabled = true
block_post_requests = true
# cache_enabled = true
# cache_errors = true
# request_coalescing_enabled = true
# block_post_requests = true
limit_requests = 60
limit_connections = 10
# limit_requests = 500
# limit_connections = 50
safehop_enabled = true
# safehop_enabled = true
add_canonical_header = true
# add_canonical_header = true
cache_stale = ["offline", "updating"]
use_background_update = true
# cache_stale = ["offline", "updating"]
# use_background_update = true
block_ips = var.cdn_block_ips
# block_ips = var.cdn_block_ips
# 50 TB
limit_bandwidth = 50000000000000
# # 50 TB
# limit_bandwidth = 50000000000000
permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
block_root_path = true
}
# # rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
# block_root_path = true
# }
resource "bunnynet_pullzone_hostname" "devxy-r-binaries" {
pullzone = bunnynet_pullzone.devxy-r-binaries.id
name = "cran.devxy.io"
force_ssl = true
tls_enabled = true
}
# resource "bunnynet_pullzone_hostname" "devxy-r-binaries" {
# pullzone = bunnynet_pullzone.devxy-r-binaries.id
# name = "cran.devxy.io"
# force_ssl = true
# tls_enabled = true
# }
### cran.rpkgs.com
resource "bunnynet_pullzone" "cran_rpkgs_com" {
name = "cran-rpkgs"
cache_errors = false
cache_expiration_time = 31919000
websockets_enabled = false
errorpage_whitelabel = true
origin {
type = "OriginUrl"
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
type = "OriginUrl"
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
middleware_script = 29277
}
routing {
tier = "Standard"
filters = [
"scripting",
]
}
s3_auth_enabled = true
@ -70,26 +79,24 @@ resource "bunnynet_pullzone" "cran_rpkgs_com" {
s3_auth_region = "eu-central-003"
cache_enabled = true
cache_errors = true
request_coalescing_enabled = true
block_post_requests = true
limit_requests = 60
limit_connections = 10
limit_requests = 500
limit_connections = 50
safehop_enabled = true
add_canonical_header = true
cache_stale = ["offline", "updating"]
use_background_update = true
cache_stale = ["offline", "updating"]
block_ips = var.cdn_block_ips
# 50 TB
limit_bandwidth = 50000000000000
permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
block_root_path = true
@ -102,10 +109,10 @@ resource "bunnynet_pullzone_hostname" "cran_rpkgs_com" {
tls_enabled = true
}
resource "bunnynet_storage_zone" "devxy-r-binaries" {
name = "devxy-r-binaries-storage"
region = "DE"
zone_tier = "Standard"
# Los Angeles and Singapore
replication_regions = ["LA", "SG"]
}
# resource "bunnynet_storage_zone" "devxy-r-binaries" {
# name = "devxy-r-binaries-storage"
# region = "DE"
# zone_tier = "Standard"
# # Los Angeles and Singapore
# replication_regions = ["LA", "SG"]
# }