build-cran-binaries/cdn.tf
pat-s 35dafab737 refactor: hoist CDN block_ips to a variable (#81)
## Summary

`block_ips = ["185.172.53.0"]` was duplicated in both `bunnynet_pullzone` resources in `cdn.tf`. Move it to a typed `cdn_block_ips` variable in `vars.tf` with the existing IP as the default.

- No plan diff on apply — same value, just sourced from `var.cdn_block_ips` instead of a literal.
- Adding/removing IPs is now a one-line var override (or a default change) instead of two edits in the resource bodies.

## Interaction with #80 (for_each refactor)

`#80` collapses the two pullzones to `bunnynet_pullzone.this[for_each]`. Either order works; whichever lands second is a trivial one-line rebase on the surviving `block_ips =` line.

Reviewed-on: #81
2026-06-08 08:29:06 +00:00

111 lines
2.7 KiB
HCL

# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone
# terraform import bunnynet_pullzone.devxy-r-binaries cran
resource "bunnynet_pullzone" "devxy-r-binaries" {
name = "cran"
origin {
type = "OriginUrl"
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
}
routing {
tier = "Standard"
}
s3_auth_enabled = true
s3_auth_key = var.B2_S3_ACCESS_KEY
s3_auth_secret = var.B2_S3_SECRET_KEY
s3_auth_region = "eu-central-003"
cache_enabled = true
cache_errors = true
request_coalescing_enabled = true
block_post_requests = true
limit_requests = 60
limit_connections = 10
safehop_enabled = true
add_canonical_header = true
cache_stale = ["offline", "updating"]
use_background_update = true
block_ips = var.cdn_block_ips
# 50 TB
limit_bandwidth = 50000000000000
permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
block_root_path = true
}
resource "bunnynet_pullzone_hostname" "devxy-r-binaries" {
pullzone = bunnynet_pullzone.devxy-r-binaries.id
name = "cran.devxy.io"
force_ssl = true
tls_enabled = true
}
### cran.rpkgs.com
resource "bunnynet_pullzone" "cran_rpkgs_com" {
name = "cran-rpkgs"
origin {
type = "OriginUrl"
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
}
routing {
tier = "Standard"
}
s3_auth_enabled = true
s3_auth_key = var.B2_S3_ACCESS_KEY
s3_auth_secret = var.B2_S3_SECRET_KEY
s3_auth_region = "eu-central-003"
cache_enabled = true
cache_errors = true
request_coalescing_enabled = true
block_post_requests = true
limit_requests = 60
limit_connections = 10
safehop_enabled = true
add_canonical_header = true
cache_stale = ["offline", "updating"]
use_background_update = true
block_ips = var.cdn_block_ips
# 50 TB
limit_bandwidth = 50000000000000
permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
block_root_path = true
}
resource "bunnynet_pullzone_hostname" "cran_rpkgs_com" {
pullzone = bunnynet_pullzone.cran_rpkgs_com.id
name = "cran.rpkgs.com"
force_ssl = true
tls_enabled = true
}
resource "bunnynet_storage_zone" "devxy-r-binaries" {
name = "devxy-r-binaries-storage"
region = "DE"
zone_tier = "Standard"
# Los Angeles and Singapore
replication_regions = ["LA", "SG"]
}