build-cran-binaries/cdn.tf
pat-s a1c1f5e78f fix(cdn): align repository routing across pull zones (#165)
## Motivation

`cran.rpkgs.com` and `cran.allianceswisspass.devxy.io` serve the same B2 repository through separate Bunny pull zones, but only the first zone was managed and purged after weekly reindexing.
This allowed the Alliance endpoint to retain stale repository metadata and left locked `renv` restores unable to retrieve versions whose binary archive object was absent.

## Changes

- Adopt the Alliance SwissPass pull zone `3265648` into OpenTofu and configure it with the shared B2 origin and middleware script.
- Purge both Bunny pull zones after the weekly rebuild reindex.
- Preserve the requested public hostname in middleware redirects.
- Redirect missing archived binaries to the corresponding CRAN source package, checking whether the version is archived or still current.
- Cover the existing archived-binary passthrough behavior in the edge routing matrix.

## Verification

- `prek run -a`
- `just edge-test`
- `crow lint .crow/`
- `tofu validate`
- `bash -n scripts/purge_cdn_zone.sh`

## Deployment

Run `tofu apply` to adopt pull zone `3265648`, publish the middleware release, and align both pull zones.
After the apply, rerun the Alliance SwissPass CI restore that requested `cli 3.6.5` and `AzureStor 3.7.1`.

Reviewed-on: #165
2026-08-13 14:08:10 +00:00

208 lines
6 KiB
HCL

# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone
# terraform import bunnynet_pullzone.devxy-r-binaries cran
# resource "bunnynet_pullzone" "devxy-r-binaries" {
# name = "cran"
# origin {
# type = "OriginUrl"
# url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
# }
# routing {
# tier = "Standard"
# }
# s3_auth_enabled = true
# s3_auth_key = var.B2_S3_ACCESS_KEY
# s3_auth_secret = var.B2_S3_SECRET_KEY
# s3_auth_region = "eu-central-003"
# cache_enabled = true
# cache_errors = true
# request_coalescing_enabled = true
# block_post_requests = true
# limit_requests = 500
# limit_connections = 50
# safehop_enabled = true
# add_canonical_header = true
# cache_stale = ["offline", "updating"]
# use_background_update = true
# block_ips = var.cdn_block_ips
# # 50 TB
# limit_bandwidth = 50000000000000
# permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# # rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
# block_root_path = true
# }
# resource "bunnynet_pullzone_hostname" "devxy-r-binaries" {
# pullzone = bunnynet_pullzone.devxy-r-binaries.id
# name = "cran.devxy.io"
# force_ssl = true
# tls_enabled = true
# }
### cran.rpkgs.com
# The edge middleware that resolves the bare cran.rpkgs.com form to an
# <arch>/<os> slot and routes PACKAGES* to the per-R-minor slot. The source of
# truth is edge/rpkgs-router.ts; `tofu apply` publishes a new release.
#
# The script pre-dates this configuration, so it is adopted rather than created:
# tofu import bunnynet_compute_script.rpkgs_router 29277
resource "bunnynet_compute_script" "rpkgs_router" {
type = "middleware"
name = "rpkgs-router"
content = file("${path.module}/edge/rpkgs-router.ts")
}
# Slots ("<arch>/<os>", comma separated) whose per-minor index bincraft has
# already republished as a union of the per-minor and flat slots. Routing to a
# slot that is not listed here would hide every package the per-minor index does
# not carry, so this stays empty until a slot has been backfilled.
resource "bunnynet_compute_script_variable" "rpkgs_router_union_slots" {
script = bunnynet_compute_script.rpkgs_router.id
name = "UNION_SLOTS"
default_value = ""
required = false
}
resource "bunnynet_pullzone" "cran_rpkgs_com" {
name = "cran-rpkgs"
cache_errors = false
cache_expiration_time = 31919000
websockets_enabled = false
errorpage_whitelabel = true
origin {
type = "OriginUrl"
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
middleware_script = bunnynet_compute_script.rpkgs_router.id
}
routing {
filters = [
"scripting",
]
}
s3_auth_enabled = true
s3_auth_key = var.B2_S3_ACCESS_KEY
s3_auth_secret = var.B2_S3_SECRET_KEY
s3_auth_region = "eu-central-003"
cache_enabled = true
request_coalescing_enabled = true
block_post_requests = true
# Set on the zone since before this configuration existed; declared here so
# `tofu apply` stops silently removing it.
#
# The router makes it redundant on paper: the only UA-dependent responses it
# produces are redirects, and those carry `Cache-Control: no-store`, while
# their targets are concrete per-slot, per-minor URLs whose content depends
# only on the path. Dropping it would also be a real win, because otherwise
# every distinct R version string keys its own copy of every tarball.
#
# It stays for now anyway: it is the second line of defence against the one
# failure that would be quiet and confusing (an R 4.6 client served the 4.5
# index), and removing it is worth doing on its own once per-minor routing is
# confirmed live, not as a side effect of enabling that routing.
cache_vary_headers = ["User-Agent"]
limit_requests = 5000
limit_connections = 1000
safehop_enabled = true
add_canonical_header = true
cache_stale = ["offline", "updating"]
block_ips = var.cdn_block_ips
# 50 TB
limit_bandwidth = 50000000000000
# permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
block_root_path = true
}
resource "bunnynet_pullzone_hostname" "cran_rpkgs_com" {
pullzone = bunnynet_pullzone.cran_rpkgs_com.id
name = "cran.rpkgs.com"
force_ssl = true
tls_enabled = true
}
# Alliance SwissPass historically used a separate, manually configured pull
# zone. Adopt it so both public repositories use the same B2 origin, middleware
# release and cache behavior.
import {
to = bunnynet_pullzone.cran_allianceswisspass
id = "3265648"
}
resource "bunnynet_pullzone" "cran_allianceswisspass" {
name = "cran-allianceswisspass"
cache_errors = false
cache_expiration_time = 31919000
websockets_enabled = false
errorpage_whitelabel = true
origin {
type = "OriginUrl"
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
middleware_script = bunnynet_compute_script.rpkgs_router.id
}
routing {
filters = [
"scripting",
]
}
s3_auth_enabled = true
s3_auth_key = var.B2_S3_ACCESS_KEY
s3_auth_secret = var.B2_S3_SECRET_KEY
s3_auth_region = "eu-central-003"
cache_enabled = true
request_coalescing_enabled = true
block_post_requests = true
cache_vary_headers = ["User-Agent"]
limit_requests = 5000
limit_connections = 1000
safehop_enabled = true
add_canonical_header = true
cache_stale = ["offline", "updating"]
block_ips = var.cdn_block_ips
# 50 TB
limit_bandwidth = 50000000000000
block_root_path = true
}
# resource "bunnynet_storage_zone" "devxy-r-binaries" {
# name = "devxy-r-binaries-storage"
# region = "DE"
# zone_tier = "Standard"
# # Los Angeles and Singapore
# replication_regions = ["LA", "SG"]
# }