以 IaC 管理 Incus 接入与 Ayatori 双环境基础容器
This commit is contained in:
+22
@@ -0,0 +1,22 @@
|
||||
# This file is maintained automatically by "terraform init".
|
||||
# Manual edits may be lost in future updates.
|
||||
|
||||
provider "registry.terraform.io/lxc/incus" {
|
||||
version = "1.2.0"
|
||||
constraints = "1.2.0"
|
||||
hashes = [
|
||||
"h1:9G5MaYQY9mKIpO341aG6f0Bt46DFD/bssrtNB+r861U=",
|
||||
"zh:3be797962ed009eedcd6badb2cce1f707345032d48814f050f2103f00eba0177",
|
||||
"zh:53fd1bf8685ef140372ab3282267fba38219dd2351efa723888a80aa41aa9367",
|
||||
"zh:59a9f9bd027380346b8ebc09da7c98c7ef5aed0783d33aa3d3c4f51ca2fafd0f",
|
||||
"zh:65ca786dd942c068b5953e7bd92c6813b1aeeb8a381da7cc96c45a846f3a5965",
|
||||
"zh:6dd3262124c41f8a416cbd1c289dbf1ab9bf9116fc3f3be4714971272811926a",
|
||||
"zh:8cce2da3db95f1088e02bf7ee68d9cacd55bf7b12dd0dd1e61165d5e5432e38b",
|
||||
"zh:a637c5299aeed3984a0b39b45f4bac026d701a6cc203dff05a82a4f43027f37c",
|
||||
"zh:a9017e39f3e8d2dbbfbbc1c6d663d22465b783d1c0e9a6e3ab324b497d0b14ed",
|
||||
"zh:c3954bf1f4796a529dd76f5617f63f570dee76e9b7c17b12416e3afb059314ba",
|
||||
"zh:dd5a081a9778794d89fa54ccddf4287550e9522d6e69b5e777859857809c9d20",
|
||||
"zh:fa95ea158d045386be416cf9146c74a5e4b3fe5fd85850e1b8f6d2977c45bc9b",
|
||||
"zh:fbe8006406da07ba0c40282050cd34343a584d028890c8601592414044abab7e",
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,102 @@
|
||||
terraform {
|
||||
required_version = ">= 1.10.0"
|
||||
required_providers {
|
||||
incus = {
|
||||
source = "lxc/incus"
|
||||
version = "1.2.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
provider "incus" {
|
||||
default_remote = "local"
|
||||
remote {
|
||||
name = "local"
|
||||
address = "unix://"
|
||||
}
|
||||
remote {
|
||||
name = "images"
|
||||
address = "https://images.linuxcontainers.org"
|
||||
protocol = "simplestreams"
|
||||
public = true
|
||||
}
|
||||
}
|
||||
|
||||
# 专用子 dataset,不接管整个宿主 data 池。
|
||||
resource "incus_storage_pool" "ayatori" {
|
||||
name = "ayatori"
|
||||
driver = "zfs"
|
||||
config = {
|
||||
source = "data/incus-ayatori"
|
||||
}
|
||||
lifecycle {
|
||||
prevent_destroy = true
|
||||
}
|
||||
}
|
||||
|
||||
resource "incus_instance" "ayatori" {
|
||||
for_each = toset(["dev", "prod"])
|
||||
name = "ayatori-${each.key}"
|
||||
description = "Ayatori ${each.key} 基础容器;应用由独立部署流程管理"
|
||||
# Ubuntu 24.04 cloud amd64,20260924_07:42;固定指纹避免重建时静默更换镜像。
|
||||
image = "images:b39d3d56c30738ad74c507066cc5d410e1c0f1647bdcdff398be1ee51d63862a"
|
||||
type = "container"
|
||||
profiles = []
|
||||
running = true
|
||||
config = {
|
||||
"boot.autostart" = "true"
|
||||
"security.privileged" = "false"
|
||||
"security.nesting" = "false"
|
||||
"limits.cpu" = "2"
|
||||
"limits.memory" = "2GiB"
|
||||
"limits.memory.swap" = "false"
|
||||
"cloud-init.user-data" = "#cloud-config\n${yamlencode({
|
||||
hostname = "ayatori-${each.key}"
|
||||
manage_etc_hosts = true
|
||||
ssh_pwauth = false
|
||||
disable_root = true
|
||||
users = [{
|
||||
name = "panxiao81"
|
||||
groups = ["sudo"]
|
||||
shell = "/bin/bash"
|
||||
sudo = ["ALL=(ALL) NOPASSWD:ALL"]
|
||||
lock_passwd = true
|
||||
ssh_authorized_keys = [trimspace(file("${path.module}/../ansible/files/panxiao81.pub"))]
|
||||
}]
|
||||
})}"
|
||||
}
|
||||
device {
|
||||
name = "root"
|
||||
type = "disk"
|
||||
properties = {
|
||||
path = "/"
|
||||
pool = incus_storage_pool.ayatori.name
|
||||
size = "20GiB"
|
||||
}
|
||||
}
|
||||
device {
|
||||
name = "eth0"
|
||||
type = "nic"
|
||||
properties = {
|
||||
name = "eth0"
|
||||
nictype = "bridged"
|
||||
parent = "br0"
|
||||
hwaddr = each.key == "dev" ? "02:16:3e:aa:00:01" : "02:16:3e:aa:00:02"
|
||||
}
|
||||
}
|
||||
wait_for {
|
||||
type = "ipv4"
|
||||
nic = "eth0"
|
||||
}
|
||||
lifecycle {
|
||||
prevent_destroy = true
|
||||
}
|
||||
}
|
||||
|
||||
output "containers" {
|
||||
value = { for env, instance in incus_instance.ayatori : env => {
|
||||
name = instance.name
|
||||
ipv4 = instance.ipv4_address
|
||||
mac = instance.mac_address
|
||||
} }
|
||||
}
|
||||
Reference in New Issue
Block a user