From 346f5629eb1073c4c0edc84e3c07a2ba82b74880 Mon Sep 17 00:00:00 2001 From: pat-s Date: Thu, 28 May 2026 15:52:28 +0200 Subject: [PATCH] refactor: collapse cdn.tf pullzones into for_each bunnynet_pullzone.devxy-r-binaries (cran.devxy.io) and bunnynet_pullzone.cran_rpkgs_com (cran.rpkgs.com) were byte-for-byte identical except for the zone name and hostname. Same for the two pullzone_hostname resources. Use a single local.pullzones map and for_each on both resources, so shared knobs (block_ips, limit_bandwidth, s3_auth_*, ...) only have to be edited once. State migration is handled by moved {} blocks so the existing pullzones get re-addressed under the new for_each keys instead of being destroyed+recreated. Run terraform plan to confirm a zero- change apply before applying. --- cdn.tf | 102 ++++++++++++++++++++++++--------------------------------- 1 file changed, 43 insertions(+), 59 deletions(-) diff --git a/cdn.tf b/cdn.tf index ea1ab2a..30ee1e2 100644 --- a/cdn.tf +++ b/cdn.tf @@ -1,7 +1,20 @@ # https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone -# terraform import bunnynet_pullzone.devxy-r-binaries cran -resource "bunnynet_pullzone" "devxy-r-binaries" { - name = "cran" + +locals { + pullzones = { + "cran" = { + hostname = "cran.devxy.io" + } + "cran-rpkgs" = { + hostname = "cran.rpkgs.com" + } + } +} + +resource "bunnynet_pullzone" "this" { + for_each = local.pullzones + + name = each.key origin { type = "OriginUrl" @@ -45,63 +58,11 @@ resource "bunnynet_pullzone" "devxy-r-binaries" { block_root_path = true } -resource "bunnynet_pullzone_hostname" "devxy-r-binaries" { - pullzone = bunnynet_pullzone.devxy-r-binaries.id - name = "cran.devxy.io" - force_ssl = true - tls_enabled = true -} +resource "bunnynet_pullzone_hostname" "this" { + for_each = local.pullzones -### cran.rpkgs.com - -resource "bunnynet_pullzone" "cran_rpkgs_com" { - name = "cran-rpkgs" - - origin { - type = "OriginUrl" - url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com" - } - - routing { - tier = "Standard" - } - - s3_auth_enabled = true - s3_auth_key = var.B2_S3_ACCESS_KEY - s3_auth_secret = var.B2_S3_SECRET_KEY - s3_auth_region = "eu-central-003" - - cache_enabled = true - cache_errors = true - request_coalescing_enabled = true - block_post_requests = true - - limit_requests = 60 - limit_connections = 10 - - safehop_enabled = true - - add_canonical_header = true - - cache_stale = ["offline", "updating"] - use_background_update = true - - block_ips = [ - "185.172.53.0" - ] - - # 50 TB - limit_bandwidth = 50000000000000 - - permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id - - # rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2 - block_root_path = true -} - -resource "bunnynet_pullzone_hostname" "cran_rpkgs_com" { - pullzone = bunnynet_pullzone.cran_rpkgs_com.id - name = "cran.rpkgs.com" + pullzone = bunnynet_pullzone.this[each.key].id + name = each.value.hostname force_ssl = true tls_enabled = true } @@ -113,3 +74,26 @@ resource "bunnynet_storage_zone" "devxy-r-binaries" { # Los Angeles and Singapore replication_regions = ["LA", "SG"] } + +# State-migration markers so the previously-singleton resources slide into +# the for_each map addresses without a destroy/create. Safe to delete after +# a successful apply on every workspace. +moved { + from = bunnynet_pullzone.devxy-r-binaries + to = bunnynet_pullzone.this["cran"] +} + +moved { + from = bunnynet_pullzone.cran_rpkgs_com + to = bunnynet_pullzone.this["cran-rpkgs"] +} + +moved { + from = bunnynet_pullzone_hostname.devxy-r-binaries + to = bunnynet_pullzone_hostname.this["cran"] +} + +moved { + from = bunnynet_pullzone_hostname.cran_rpkgs_com + to = bunnynet_pullzone_hostname.this["cran-rpkgs"] +} -- 2.54.0