## Motivation `cran.rpkgs.com` and `cran.allianceswisspass.devxy.io` serve the same B2 repository through separate Bunny pull zones, but only the first zone was managed and purged after weekly reindexing. This allowed the Alliance endpoint to retain stale repository metadata and left locked `renv` restores unable to retrieve versions whose binary archive object was absent. ## Changes - Adopt the Alliance SwissPass pull zone `3265648` into OpenTofu and configure it with the shared B2 origin and middleware script. - Purge both Bunny pull zones after the weekly rebuild reindex. - Preserve the requested public hostname in middleware redirects. - Redirect missing archived binaries to the corresponding CRAN source package, checking whether the version is archived or still current. - Cover the existing archived-binary passthrough behavior in the edge routing matrix. ## Verification - `prek run -a` - `just edge-test` - `crow lint .crow/` - `tofu validate` - `bash -n scripts/purge_cdn_zone.sh` ## Deployment Run `tofu apply` to adopt pull zone `3265648`, publish the middleware release, and align both pull zones. After the apply, rerun the Alliance SwissPass CI restore that requested `cli 3.6.5` and `AzureStor 3.7.1`. Reviewed-on: #165
208 lines
6 KiB
HCL
208 lines
6 KiB
HCL
# https://registry.terraform.io/providers/BunnyWay/bunnynet/latest/docs/resources/pullzone
|
|
# terraform import bunnynet_pullzone.devxy-r-binaries cran
|
|
# resource "bunnynet_pullzone" "devxy-r-binaries" {
|
|
# name = "cran"
|
|
|
|
# origin {
|
|
# type = "OriginUrl"
|
|
# url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
|
|
# }
|
|
|
|
# routing {
|
|
# tier = "Standard"
|
|
# }
|
|
|
|
# s3_auth_enabled = true
|
|
# s3_auth_key = var.B2_S3_ACCESS_KEY
|
|
# s3_auth_secret = var.B2_S3_SECRET_KEY
|
|
# s3_auth_region = "eu-central-003"
|
|
|
|
# cache_enabled = true
|
|
# cache_errors = true
|
|
# request_coalescing_enabled = true
|
|
# block_post_requests = true
|
|
|
|
# limit_requests = 500
|
|
# limit_connections = 50
|
|
|
|
# safehop_enabled = true
|
|
|
|
# add_canonical_header = true
|
|
|
|
# cache_stale = ["offline", "updating"]
|
|
# use_background_update = true
|
|
|
|
# block_ips = var.cdn_block_ips
|
|
|
|
# # 50 TB
|
|
# limit_bandwidth = 50000000000000
|
|
|
|
# permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
|
|
|
|
# # rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
|
|
# block_root_path = true
|
|
# }
|
|
|
|
# resource "bunnynet_pullzone_hostname" "devxy-r-binaries" {
|
|
# pullzone = bunnynet_pullzone.devxy-r-binaries.id
|
|
# name = "cran.devxy.io"
|
|
# force_ssl = true
|
|
# tls_enabled = true
|
|
# }
|
|
|
|
### cran.rpkgs.com
|
|
|
|
# The edge middleware that resolves the bare cran.rpkgs.com form to an
|
|
# <arch>/<os> slot and routes PACKAGES* to the per-R-minor slot. The source of
|
|
# truth is edge/rpkgs-router.ts; `tofu apply` publishes a new release.
|
|
#
|
|
# The script pre-dates this configuration, so it is adopted rather than created:
|
|
# tofu import bunnynet_compute_script.rpkgs_router 29277
|
|
resource "bunnynet_compute_script" "rpkgs_router" {
|
|
type = "middleware"
|
|
name = "rpkgs-router"
|
|
content = file("${path.module}/edge/rpkgs-router.ts")
|
|
}
|
|
|
|
# Slots ("<arch>/<os>", comma separated) whose per-minor index bincraft has
|
|
# already republished as a union of the per-minor and flat slots. Routing to a
|
|
# slot that is not listed here would hide every package the per-minor index does
|
|
# not carry, so this stays empty until a slot has been backfilled.
|
|
resource "bunnynet_compute_script_variable" "rpkgs_router_union_slots" {
|
|
script = bunnynet_compute_script.rpkgs_router.id
|
|
name = "UNION_SLOTS"
|
|
default_value = ""
|
|
required = false
|
|
}
|
|
|
|
resource "bunnynet_pullzone" "cran_rpkgs_com" {
|
|
name = "cran-rpkgs"
|
|
|
|
cache_errors = false
|
|
|
|
cache_expiration_time = 31919000
|
|
websockets_enabled = false
|
|
errorpage_whitelabel = true
|
|
|
|
origin {
|
|
type = "OriginUrl"
|
|
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
|
|
middleware_script = bunnynet_compute_script.rpkgs_router.id
|
|
}
|
|
|
|
routing {
|
|
filters = [
|
|
"scripting",
|
|
]
|
|
}
|
|
|
|
s3_auth_enabled = true
|
|
s3_auth_key = var.B2_S3_ACCESS_KEY
|
|
s3_auth_secret = var.B2_S3_SECRET_KEY
|
|
s3_auth_region = "eu-central-003"
|
|
|
|
cache_enabled = true
|
|
request_coalescing_enabled = true
|
|
block_post_requests = true
|
|
|
|
# Set on the zone since before this configuration existed; declared here so
|
|
# `tofu apply` stops silently removing it.
|
|
#
|
|
# The router makes it redundant on paper: the only UA-dependent responses it
|
|
# produces are redirects, and those carry `Cache-Control: no-store`, while
|
|
# their targets are concrete per-slot, per-minor URLs whose content depends
|
|
# only on the path. Dropping it would also be a real win, because otherwise
|
|
# every distinct R version string keys its own copy of every tarball.
|
|
#
|
|
# It stays for now anyway: it is the second line of defence against the one
|
|
# failure that would be quiet and confusing (an R 4.6 client served the 4.5
|
|
# index), and removing it is worth doing on its own once per-minor routing is
|
|
# confirmed live, not as a side effect of enabling that routing.
|
|
cache_vary_headers = ["User-Agent"]
|
|
|
|
limit_requests = 5000
|
|
limit_connections = 1000
|
|
|
|
safehop_enabled = true
|
|
|
|
add_canonical_header = true
|
|
|
|
cache_stale = ["offline", "updating"]
|
|
|
|
block_ips = var.cdn_block_ips
|
|
|
|
# 50 TB
|
|
limit_bandwidth = 50000000000000
|
|
|
|
# permacache_storagezone = bunnynet_storage_zone.devxy-r-binaries.id
|
|
|
|
# rec from docs: https://www.backblaze.com/docs/cloud-storage-integrate-bunnynet-with-backblaze-b2
|
|
block_root_path = true
|
|
}
|
|
|
|
resource "bunnynet_pullzone_hostname" "cran_rpkgs_com" {
|
|
pullzone = bunnynet_pullzone.cran_rpkgs_com.id
|
|
name = "cran.rpkgs.com"
|
|
force_ssl = true
|
|
tls_enabled = true
|
|
}
|
|
|
|
# Alliance SwissPass historically used a separate, manually configured pull
|
|
# zone. Adopt it so both public repositories use the same B2 origin, middleware
|
|
# release and cache behavior.
|
|
import {
|
|
to = bunnynet_pullzone.cran_allianceswisspass
|
|
id = "3265648"
|
|
}
|
|
|
|
resource "bunnynet_pullzone" "cran_allianceswisspass" {
|
|
name = "cran-allianceswisspass"
|
|
|
|
cache_errors = false
|
|
cache_expiration_time = 31919000
|
|
websockets_enabled = false
|
|
errorpage_whitelabel = true
|
|
|
|
origin {
|
|
type = "OriginUrl"
|
|
url = "https://devxy-rpkgs-binaries.s3.eu-central-003.backblazeb2.com"
|
|
middleware_script = bunnynet_compute_script.rpkgs_router.id
|
|
}
|
|
|
|
routing {
|
|
filters = [
|
|
"scripting",
|
|
]
|
|
}
|
|
|
|
s3_auth_enabled = true
|
|
s3_auth_key = var.B2_S3_ACCESS_KEY
|
|
s3_auth_secret = var.B2_S3_SECRET_KEY
|
|
s3_auth_region = "eu-central-003"
|
|
|
|
cache_enabled = true
|
|
request_coalescing_enabled = true
|
|
block_post_requests = true
|
|
cache_vary_headers = ["User-Agent"]
|
|
|
|
limit_requests = 5000
|
|
limit_connections = 1000
|
|
|
|
safehop_enabled = true
|
|
add_canonical_header = true
|
|
cache_stale = ["offline", "updating"]
|
|
block_ips = var.cdn_block_ips
|
|
|
|
# 50 TB
|
|
limit_bandwidth = 50000000000000
|
|
|
|
block_root_path = true
|
|
}
|
|
|
|
# resource "bunnynet_storage_zone" "devxy-r-binaries" {
|
|
# name = "devxy-r-binaries-storage"
|
|
# region = "DE"
|
|
# zone_tier = "Standard"
|
|
# # Los Angeles and Singapore
|
|
# replication_regions = ["LA", "SG"]
|
|
# }
|