## Problem
`tofu plan` after importing the middleware script shows:
```
~ resource "bunnynet_pullzone" "cran_rpkgs_com" {
~ cache_vary_headers = [
- "User-Agent",
]
```
The zone carries `cache_vary_headers = ["User-Agent"]`, set before this configuration existed. `cdn.tf` never declared it, so the first apply of the managed middleware would remove it — as a side effect of an unrelated change, with no decision recorded anywhere.
## What this changes
Declares the attribute with its current value, so the pull zone is a no-op in that plan.
## Why keep it rather than let it go
On paper the router makes it redundant. The only UA-dependent responses it produces are redirects, and those carry `Cache-Control: no-store`; their targets are concrete per-slot, per-minor URLs whose content depends only on the path. Dropping the vary would also be a genuine win, since otherwise every distinct R version string (`R (4.5.3 x86_64-pc-linux-musl …)`) keys its own copy of every tarball.
It stays anyway, for now:
- it is the second line of defence against the one failure mode that would be quiet and confusing — an R 4.6 client served the 4.5 index
- Bunny honouring `no-store` on an edge-script response has been confirmed for today's redirects (`cdn-cache: BYPASS` on `max-age=0`), but not for the new script in production
- keeping it is the status quo, so it cannot regress anything
Removing it is worth doing on its own, once per-minor routing is confirmed live and the redirects can be observed bypassing cache — not as a side effect of enabling that routing.
## Verification
`tofu validate` passes. Re-planning after this merges should leave `bunnynet_pullzone.cran_rpkgs_com` unchanged, reducing the plan to the script `content` update and the new `UNION_SLOTS` variable.
Reviewed-on: #156
156 lines
4.7 KiB
HCL
156 lines
4.7 KiB
HCL
# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone
|
|
# terraform import bunnynet_pullzone.devxy-r-binaries cran
|
|
# resource "bunnynet_pullzone" "devxy-r-binaries" {
|
|
# name = "cran"
|
|
|
|
# origin {
|
|
# type = "OriginUrl"
|
|
# url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
|
|
# }
|
|
|
|
# routing {
|
|
# tier = "Standard"
|
|
# }
|
|
|
|
# s3_auth_enabled = true
|
|
# s3_auth_key = var.B2_S3_ACCESS_KEY
|
|
# s3_auth_secret = var.B2_S3_SECRET_KEY
|
|
# s3_auth_region = "eu-central-003"
|
|
|
|
# cache_enabled = true
|
|
# cache_errors = true
|
|
# request_coalescing_enabled = true
|
|
# block_post_requests = true
|
|
|
|
# limit_requests = 500
|
|
# limit_connections = 50
|
|
|
|
# safehop_enabled = true
|
|
|
|
# add_canonical_header = true
|
|
|
|
# cache_stale = ["offline", "updating"]
|
|
# use_background_update = true
|
|
|
|
# block_ips = var.cdn_block_ips
|
|
|
|
# # 50 TB
|
|
# limit_bandwidth = 50000000000000
|
|
|
|
# permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
|
|
|
|
# # rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
|
|
# block_root_path = true
|
|
# }
|
|
|
|
# resource "bunnynet_pullzone_hostname" "devxy-r-binaries" {
|
|
# pullzone = bunnynet_pullzone.devxy-r-binaries.id
|
|
# name = "cran.devxy.io"
|
|
# force_ssl = true
|
|
# tls_enabled = true
|
|
# }
|
|
|
|
### cran.rpkgs.com
|
|
|
|
# The edge middleware that resolves the bare cran.rpkgs.com form to an
|
|
# <arch>/<os> slot and routes PACKAGES* to the per-R-minor slot. The source of
|
|
# truth is edge/rpkgs-router.ts; `tofu apply` publishes a new release.
|
|
#
|
|
# The script pre-dates this configuration, so it is adopted rather than created:
|
|
# tofu import bunnynet_compute_script.rpkgs_router 29277
|
|
resource "bunnynet_compute_script" "rpkgs_router" {
|
|
type = "middleware"
|
|
name = "rpkgs-router"
|
|
content = file("${path.module}/edge/rpkgs-router.ts")
|
|
}
|
|
|
|
# Slots ("<arch>/<os>", comma separated) whose per-minor index bincraft has
|
|
# already republished as a union of the per-minor and flat slots. Routing to a
|
|
# slot that is not listed here would hide every package the per-minor index does
|
|
# not carry, so this stays empty until a slot has been backfilled.
|
|
resource "bunnynet_compute_script_variable" "rpkgs_router_union_slots" {
|
|
script = bunnynet_compute_script.rpkgs_router.id
|
|
name = "UNION_SLOTS"
|
|
default_value = ""
|
|
required = false
|
|
}
|
|
|
|
resource "bunnynet_pullzone" "cran_rpkgs_com" {
|
|
name = "cran-rpkgs"
|
|
|
|
cache_errors = false
|
|
|
|
cache_expiration_time = 31919000
|
|
websockets_enabled = false
|
|
errorpage_whitelabel = true
|
|
|
|
origin {
|
|
type = "OriginUrl"
|
|
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
|
|
middleware_script = bunnynet_compute_script.rpkgs_router.id
|
|
}
|
|
|
|
routing {
|
|
filters = [
|
|
"scripting",
|
|
]
|
|
}
|
|
|
|
s3_auth_enabled = true
|
|
s3_auth_key = var.B2_S3_ACCESS_KEY
|
|
s3_auth_secret = var.B2_S3_SECRET_KEY
|
|
s3_auth_region = "eu-central-003"
|
|
|
|
cache_enabled = true
|
|
request_coalescing_enabled = true
|
|
block_post_requests = true
|
|
|
|
# Set on the zone since before this configuration existed; declared here so
|
|
# `tofu apply` stops silently removing it.
|
|
#
|
|
# The router makes it redundant on paper: the only UA-dependent responses it
|
|
# produces are redirects, and those carry `Cache-Control: no-store`, while
|
|
# their targets are concrete per-slot, per-minor URLs whose content depends
|
|
# only on the path. Dropping it would also be a real win, because otherwise
|
|
# every distinct R version string keys its own copy of every tarball.
|
|
#
|
|
# It stays for now anyway: it is the second line of defence against the one
|
|
# failure that would be quiet and confusing (an R 4.6 client served the 4.5
|
|
# index), and removing it is worth doing on its own once per-minor routing is
|
|
# confirmed live, not as a side effect of enabling that routing.
|
|
cache_vary_headers = ["User-Agent"]
|
|
|
|
limit_requests = 5000
|
|
limit_connections = 1000
|
|
|
|
safehop_enabled = true
|
|
|
|
add_canonical_header = true
|
|
|
|
cache_stale = ["offline", "updating"]
|
|
|
|
block_ips = var.cdn_block_ips
|
|
|
|
# 50 TB
|
|
limit_bandwidth = 50000000000000
|
|
|
|
# permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
|
|
|
|
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
|
|
block_root_path = true
|
|
}
|
|
|
|
resource "bunnynet_pullzone_hostname" "cran_rpkgs_com" {
|
|
pullzone = bunnynet_pullzone.cran_rpkgs_com.id
|
|
name = "cran.rpkgs.com"
|
|
force_ssl = true
|
|
tls_enabled = true
|
|
}
|
|
|
|
# resource "bunnynet_storage_zone" "devxy-r-binaries" {
|
|
# name = "devxy-r-binaries-storage"
|
|
# region = "DE"
|
|
# zone_tier = "Standard"
|
|
# # Los Angeles and Singapore
|
|
# replication_regions = ["LA", "SG"]
|
|
# }
|