build-cran-binaries/cdn.tf
pat-s bd43869515
Some checks failed
ci/crow/cron/update-package-index-alpine-320-amd64 Pipeline failed
ci/crow/cron/update-package-index-ubuntu-2204-amd64 Pipeline failed
ci/crow/cron/update-package-index-alpine-321-arm64 Pipeline failed
ci/crow/cron/update-package-index-redhat-8-arm64 Pipeline failed
ci/crow/cron/update-package-index-alpine-320-arm64 Pipeline failed
ci/crow/cron/update-package-index-alpine-321-amd64 Pipeline failed
ci/crow/cron/update-package-index-redhat-8-amd64 Pipeline failed
ci/crow/cron/update-package-index-redhat-9-amd64 Pipeline failed
ci/crow/cron/update-package-index-ubuntu-2404-amd64 Pipeline failed
ci/crow/cron/update-package-index-ubuntu-2404-arm64 Pipeline failed
ci/crow/cron/update-package-index-redhat-9-arm64 Pipeline failed
ci/crow/cron/update-package-index-ubuntu-2204-arm64 Pipeline failed
ci/crow/cron/process-updates-alpine-321-arm64 Pipeline failed
ci/crow/cron/process-updates-alpine-320-arm64 Pipeline failed
ci/crow/cron/process-updates-redhat-8-arm64 Pipeline failed
ci/crow/cron/process-updates-redhat-8-amd64 Pipeline failed
ci/crow/cron/process-updates-alpine-320-amd64 Pipeline failed
ci/crow/cron/process-updates-ubuntu-2404-amd64 Pipeline failed
ci/crow/cron/process-updates-redhat-9-arm64 Pipeline failed
ci/crow/cron/process-updates-alpine-321-amd64 Pipeline failed
ci/crow/cron/process-updates-ubuntu-2204-amd64 Pipeline failed
feat: import bunny pullzone, add cran.rpkgs.com pullzone config
2025-05-25 10:45:13 +02:00

161 lines
3.9 KiB
HCL

# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone
# terraform import bunnynet_pullzone.devxy-r-binaries cran
resource "bunnynet_pullzone" "devxy-r-binaries" {
name = "cran"
origin {
type = "OriginUrl"
url = "https://devxy-r-package-binaries-hel1.hel1.your-objectstorage.com"
}
routing {
tier = "Standard"
}
s3_auth_enabled = true
s3_auth_key = var.HETZNER_S3_ACCESS_KEY_K3S
s3_auth_secret = var.HETZNER_S3_SECRET_KEY_K3S
s3_auth_region = "hel1"
cache_enabled = true
cache_errors = true
request_coalescing_enabled = true
block_post_requests = true
limit_requests = 60
limit_connections = 10
safehop_enabled = true
add_canonical_header = true
cache_stale = ["offline", "updating"]
use_background_update = true
block_ips = [
"185.172.53.0"
]
# 50 TB
limit_bandwidth = 50000000000000
permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
block_root_path = true
}
resource "bunnynet_pullzone_hostname" "devxy-r-binaries" {
pullzone = bunnynet_pullzone.devxy-r-binaries.id
name = "cran.devxy.io"
force_ssl = true
tls_enabled = true
}
### cran.rpkgs.com
resource "bunnynet_pullzone" "cran_rpkgs_com" {
name = "cran-rpkgs"
origin {
type = "OriginUrl"
url = "https://devxy-r-package-binaries-hel1.hel1.your-objectstorage.com"
}
routing {
tier = "Standard"
}
s3_auth_enabled = true
s3_auth_key = var.HETZNER_S3_ACCESS_KEY_K3S
s3_auth_secret = var.HETZNER_S3_SECRET_KEY_K3S
s3_auth_region = "hel1"
cache_enabled = true
cache_errors = true
request_coalescing_enabled = true
block_post_requests = true
limit_requests = 60
limit_connections = 10
safehop_enabled = true
add_canonical_header = true
cache_stale = ["offline", "updating"]
use_background_update = true
block_ips = [
"185.172.53.0"
]
# 50 TB
limit_bandwidth = 50000000000000
permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
block_root_path = true
}
resource "bunnynet_pullzone_hostname" "cran_rpkgs_com" {
pullzone = bunnynet_pullzone.cran_rpkgs_com.id
name = "cran.rpkgs.com"
force_ssl = true
tls_enabled = true
}
resource "bunnynet_storage_zone" "devxy-r-binaries" {
name = "devxy-r-binaries-storage"
region = "DE"
zone_tier = "Standard"
# Los Angeles and Singapore
replication_regions = ["LA", "SG"]
}
resource "bunnynet_pullzone" "r-package-binaries-docs" {
name = "r-package-binaries-docs"
origin {
type = "OriginUrl"
url = "https://devxy-r-package-binaries-docs.fsn1.your-objectstorage.com"
}
routing {
tier = "Standard"
}
s3_auth_enabled = true
s3_auth_key = var.HETZNER_S3_ACCESS_KEY_K3S
s3_auth_secret = var.HETZNER_S3_SECRET_KEY_K3S
s3_auth_region = "fsn1"
cache_enabled = true
cache_errors = true
# 3 months (override origin cache policy which is 30d)
cache_expiration_time = 7776000
# not so great in case data from users is being sent (at some point)
request_coalescing_enabled = false
block_post_requests = true
originshield_enabled = true
originshield_concurrency_limit = true
originshield_zone = "FR"
safehop_enabled = true
# otherwise this will expose the S3 origin URL as a secondary canonical URL
add_canonical_header = false
block_root_path = false
}
resource "bunnynet_pullzone_hostname" "r-package-binaries-docs" {
pullzone = bunnynet_pullzone.r-package-binaries-docs.id
name = "docs.r-package-binaries.devxy.io"
force_ssl = true
tls_enabled = true
}