build-cran-binaries/cdn.tf
pat-s 346f5629eb
refactor: collapse cdn.tf pullzones into for_each
bunnynet_pullzone.devxy-r-binaries (cran.devxy.io) and
bunnynet_pullzone.cran_rpkgs_com (cran.rpkgs.com) were byte-for-byte
identical except for the zone name and hostname. Same for the two
pullzone_hostname resources.

Use a single local.pullzones map and for_each on both resources, so
shared knobs (block_ips, limit_bandwidth, s3_auth_*, ...) only have
to be edited once.

State migration is handled by moved {} blocks so the existing
pullzones get re-addressed under the new for_each keys instead of
being destroyed+recreated. Run terraform plan to confirm a zero-
change apply before applying.
2026-05-28 15:52:28 +02:00

99 lines
2.2 KiB
HCL

# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone
locals {
pullzones = {
"cran" = {
hostname = "cran.devxy.io"
}
"cran-rpkgs" = {
hostname = "cran.rpkgs.com"
}
}
}
resource "bunnynet_pullzone" "this" {
for_each = local.pullzones
name = each.key
origin {
type = "OriginUrl"
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
}
routing {
tier = "Standard"
}
s3_auth_enabled = true
s3_auth_key = var.B2_S3_ACCESS_KEY
s3_auth_secret = var.B2_S3_SECRET_KEY
s3_auth_region = "eu-central-003"
cache_enabled = true
cache_errors = true
request_coalescing_enabled = true
block_post_requests = true
limit_requests = 60
limit_connections = 10
safehop_enabled = true
add_canonical_header = true
cache_stale = ["offline", "updating"]
use_background_update = true
block_ips = [
"185.172.53.0"
]
# 50 TB
limit_bandwidth = 50000000000000
permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
block_root_path = true
}
resource "bunnynet_pullzone_hostname" "this" {
for_each = local.pullzones
pullzone = bunnynet_pullzone.this[each.key].id
name = each.value.hostname
force_ssl = true
tls_enabled = true
}
resource "bunnynet_storage_zone" "devxy-r-binaries" {
name = "devxy-r-binaries-storage"
region = "DE"
zone_tier = "Standard"
# Los Angeles and Singapore
replication_regions = ["LA", "SG"]
}
# State-migration markers so the previously-singleton resources slide into
# the for_each map addresses without a destroy/create. Safe to delete after
# a successful apply on every workspace.
moved {
from = bunnynet_pullzone.devxy-r-binaries
to = bunnynet_pullzone.this["cran"]
}
moved {
from = bunnynet_pullzone.cran_rpkgs_com
to = bunnynet_pullzone.this["cran-rpkgs"]
}
moved {
from = bunnynet_pullzone_hostname.devxy-r-binaries
to = bunnynet_pullzone_hostname.this["cran"]
}
moved {
from = bunnynet_pullzone_hostname.cran_rpkgs_com
to = bunnynet_pullzone_hostname.this["cran-rpkgs"]
}