diff --git a/backend.tf b/backend.tf index b3b286f..e7754fb 100644 --- a/backend.tf +++ b/backend.tf @@ -3,8 +3,6 @@ terraform { bucket = "devxy-tf-state-build-binaries" key = "terraform.tfstate" region = "fsn1" - access_key = var.HETZNER_S3_ACCESS_KEY_K3S - secret_key = var.HETZNER_S3_SECRET_KEY_K3S endpoint = "https://fsn1.your-objectstorage.com" skip_credentials_validation = true skip_metadata_api_check = true diff --git a/cdn.tf b/cdn.tf index 7a08015..cdd5f90 100644 --- a/cdn.tf +++ b/cdn.tf @@ -1,3 +1,119 @@ +# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone +# terraform import bunnynet_pullzone.devxy-r-binaries cran +resource "bunnynet_pullzone" "devxy-r-binaries" { + name = "cran" + + origin { + type = "OriginUrl" + url = "https://devxy-r-package-binaries-hel1.hel1.your-objectstorage.com" + } + + routing { + tier = "Standard" + } + + s3_auth_enabled = true + s3_auth_key = var.HETZNER_S3_ACCESS_KEY_K3S + s3_auth_secret = var.HETZNER_S3_SECRET_KEY_K3S + s3_auth_region = "hel1" + + cache_enabled = true + cache_errors = true + request_coalescing_enabled = true + block_post_requests = true + + limit_requests = 60 + limit_connections = 10 + + safehop_enabled = true + + add_canonical_header = true + + cache_stale = ["offline", "updating"] + use_background_update = true + + block_ips = [ + "185.172.53.0" + ] + + # 50 TB + limit_bandwidth = 50000000000000 + + permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id + + # rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2 + block_root_path = true +} + +resource "bunnynet_pullzone_hostname" "devxy-r-binaries" { + pullzone = bunnynet_pullzone.devxy-r-binaries.id + name = "cran.devxy.io" + force_ssl = true + tls_enabled = true +} + +### cran.rpkgs.com + +resource "bunnynet_pullzone" "cran_rpkgs_com" { + name = "cran-rpkgs" + + origin { + type = "OriginUrl" + url = "https://devxy-r-package-binaries-hel1.hel1.your-objectstorage.com" + } + + routing { + tier = "Standard" + } + + s3_auth_enabled = true + s3_auth_key = var.HETZNER_S3_ACCESS_KEY_K3S + s3_auth_secret = var.HETZNER_S3_SECRET_KEY_K3S + s3_auth_region = "hel1" + + cache_enabled = true + cache_errors = true + request_coalescing_enabled = true + block_post_requests = true + + limit_requests = 60 + limit_connections = 10 + + safehop_enabled = true + + add_canonical_header = true + + cache_stale = ["offline", "updating"] + use_background_update = true + + block_ips = [ + "185.172.53.0" + ] + + # 50 TB + limit_bandwidth = 50000000000000 + + permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id + + # rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2 + block_root_path = true +} + +resource "bunnynet_pullzone_hostname" "cran_rpkgs_com" { + pullzone = bunnynet_pullzone.cran_rpkgs_com.id + name = "cran.rpkgs.com" + force_ssl = true + tls_enabled = true +} + +resource "bunnynet_storage_zone" "devxy-r-binaries" { + name = "devxy-r-binaries-storage" + region = "DE" + zone_tier = "Standard" + # Los Angeles and Singapore + replication_regions = ["LA", "SG"] +} + resource "bunnynet_pullzone" "r-package-binaries-docs" { name = "r-package-binaries-docs" @@ -34,9 +150,6 @@ resource "bunnynet_pullzone" "r-package-binaries-docs" { add_canonical_header = false block_root_path = false - - # FIXME: https://github.com/BunnyWay/terraform-provider-bunnynet/issues/19 - log_forward_server = "127.0.0.1" } resource "bunnynet_pullzone_hostname" "r-package-binaries-docs" {