bunnynet_pullzone.devxy-r-binaries (cran.devxy.io) and
bunnynet_pullzone.cran_rpkgs_com (cran.rpkgs.com) were byte-for-byte
identical except for the zone name and hostname. Same for the two
pullzone_hostname resources.
Use a single local.pullzones map and for_each on both resources, so
shared knobs (block_ips, limit_bandwidth, s3_auth_*, ...) only have
to be edited once.
State migration is handled by moved {} blocks so the existing
pullzones get re-addressed under the new for_each keys instead of
being destroyed+recreated. Run terraform plan to confirm a zero-
change apply before applying.
99 lines
2.2 KiB
HCL
99 lines
2.2 KiB
HCL
# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone
|
|
|
|
locals {
|
|
pullzones = {
|
|
"cran" = {
|
|
hostname = "cran.devxy.io"
|
|
}
|
|
"cran-rpkgs" = {
|
|
hostname = "cran.rpkgs.com"
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "bunnynet_pullzone" "this" {
|
|
for_each = local.pullzones
|
|
|
|
name = each.key
|
|
|
|
origin {
|
|
type = "OriginUrl"
|
|
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
|
|
}
|
|
|
|
routing {
|
|
tier = "Standard"
|
|
}
|
|
|
|
s3_auth_enabled = true
|
|
s3_auth_key = var.B2_S3_ACCESS_KEY
|
|
s3_auth_secret = var.B2_S3_SECRET_KEY
|
|
s3_auth_region = "eu-central-003"
|
|
|
|
cache_enabled = true
|
|
cache_errors = true
|
|
request_coalescing_enabled = true
|
|
block_post_requests = true
|
|
|
|
limit_requests = 60
|
|
limit_connections = 10
|
|
|
|
safehop_enabled = true
|
|
|
|
add_canonical_header = true
|
|
|
|
cache_stale = ["offline", "updating"]
|
|
use_background_update = true
|
|
|
|
block_ips = [
|
|
"185.172.53.0"
|
|
]
|
|
|
|
# 50 TB
|
|
limit_bandwidth = 50000000000000
|
|
|
|
permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
|
|
|
|
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
|
|
block_root_path = true
|
|
}
|
|
|
|
resource "bunnynet_pullzone_hostname" "this" {
|
|
for_each = local.pullzones
|
|
|
|
pullzone = bunnynet_pullzone.this[each.key].id
|
|
name = each.value.hostname
|
|
force_ssl = true
|
|
tls_enabled = true
|
|
}
|
|
|
|
resource "bunnynet_storage_zone" "devxy-r-binaries" {
|
|
name = "devxy-r-binaries-storage"
|
|
region = "DE"
|
|
zone_tier = "Standard"
|
|
# Los Angeles and Singapore
|
|
replication_regions = ["LA", "SG"]
|
|
}
|
|
|
|
# State-migration markers so the previously-singleton resources slide into
|
|
# the for_each map addresses without a destroy/create. Safe to delete after
|
|
# a successful apply on every workspace.
|
|
moved {
|
|
from = bunnynet_pullzone.devxy-r-binaries
|
|
to = bunnynet_pullzone.this["cran"]
|
|
}
|
|
|
|
moved {
|
|
from = bunnynet_pullzone.cran_rpkgs_com
|
|
to = bunnynet_pullzone.this["cran-rpkgs"]
|
|
}
|
|
|
|
moved {
|
|
from = bunnynet_pullzone_hostname.devxy-r-binaries
|
|
to = bunnynet_pullzone_hostname.this["cran"]
|
|
}
|
|
|
|
moved {
|
|
from = bunnynet_pullzone_hostname.cran_rpkgs_com
|
|
to = bunnynet_pullzone_hostname.this["cran-rpkgs"]
|
|
}
|