User Tools

Site Tools


guide:cloud:advanced

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
guide:cloud:advanced [2025/10/20 22:24]
sfebruary [Base project]
guide:cloud:advanced [2025/10/22 10:21] (current)
sfebruary [Single, generic, VM project]
Line 135: Line 135:
   * Now we can proceed to initialising Terraform for this project. To do this, on GitLab navigate to "Operate", then "Terraform states" on the left menu.   * Now we can proceed to initialising Terraform for this project. To do this, on GitLab navigate to "Operate", then "Terraform states" on the left menu.
   {{:guide:cloud:terraform-states.png?350|}}   {{:guide:cloud:terraform-state-files.png?550|}}   {{:guide:cloud:terraform-states.png?350|}}   {{:guide:cloud:terraform-state-files.png?550|}}
-  * Then click on "Copy Terraform init command" -- you will see that you require your GitLab access token for this. Copy the relevant commands and run them them in your terminal session.+  * Then click on "Copy Terraform init command" -- you will see that you require your GitLab access token for this. Copy the relevant commands and run them in your terminal session.
   * After successfully initialising, you will then execute "**terraform plan -var-file=settings.tfvars**".   * After successfully initialising, you will then execute "**terraform plan -var-file=settings.tfvars**".
   * Assuming everything looks good with the above (NB! you have the freedom to modify **settings.tfvars** to customise your specific environment), proceed to running "**terraform apply -var-file=settings.tfvars**", and type "yes" at the prompt to proceed.   * Assuming everything looks good with the above (NB! you have the freedom to modify **settings.tfvars** to customise your specific environment), proceed to running "**terraform apply -var-file=settings.tfvars**", and type "yes" at the prompt to proceed.
  
 Once all of your base resources are in place, you may now proceed to creating virtual machines that make use of them. Once all of your base resources are in place, you may now proceed to creating virtual machines that make use of them.
 +
 +NB! Depending on one's workflow, additional resources such as SSH key-pairs and Security Group definitions might be good to define in this base setup too. Alternatively, they can be defined in other Terraform/GitLab projects, or setup more manually via the Horizon dashboard. 
 ==== Single, generic, VM project ==== ==== Single, generic, VM project ====
  
 +Now that we have some base resources defined, we can proceed to creating an OpenStack instance via the IAC approach. To illustrate the concept, we can again draw on a [[https://github.com/sfebruary/terraform-module-openstack-instance|pre-defined module for an instance]]. NB! This particular example assumes that an SSH key-pair already exists as a resource within your OpenStack project space, as well as a Security Group that allows SSH access to your instances, so be sure to create those first as they will be referenced below.
 +
 +Begin by [[https://docs.gitlab.com/user/project/#create-a-blank-project|creating a new, blank project in GitLab]]. 
 +
 +Next, we want to create a few files:
 +
 +**main.tf**:
 +
 +  terraform {
 +    backend "http" {
 +    }
 +    required_providers {
 +      openstack = {
 +        source  = "terraform-provider-openstack/openstack"
 +        version = "3.0.0"
 +      }
 +    }
 +  }
 +  provider "openstack" {
 +    # Configuration options
 +  }
 +  module "instance-project" {
 +    source = "git::git@github.com:sfebruary/terraform-module-openstack-instance.git?ref=main"
 +    image_name               = var.image_name
 +    flavor_name              = var.flavor_name
 +    shortname                = var.shortname
 +    key_pair_name            = var.key_pair_name
 +    volume_name              = var.volume_name
 +    volume_size              = var.volume_size
 +    volume_type              = var.volume_type
 +    volume_device_path       = var.volume_device_path
 +    enable_online_resize     = var.enable_online_resize
 +    public_network_name      = var.public_network_name
 +    private_network_name     = var.private_network_name
 +    private_subnet_name      = var.private_subnet_name
 +    server_private_port_name = var.server_private_port_name
 +    server_private_ip        = var.server_private_ip
 +    ssh_security_group_name  = var.ssh_security_group_name
 +    admin_username           = var.admin_username
 +  }
 +  
 +**settings.tfvars**:
 +
 +  # general instance settings
 +  image_name           = "Rocky 9"
 +  flavor_name          = "C4.small"
 +  shortname            = "instance-project"
 +  volume_name          = "SSD-volume-128"
 +  volume_size          = "128"
 +  volume_type          = "SSD"
 +  volume_device_path   = "/dev/vdc"
 +  enable_online_resize = "true"
 +  admin_username       = "rocky"
 +  # network settings
 +  public_network_name      = "Public Internet"
 +  private_network_name     = "Private Research Network"
 +  private_subnet_name      = "Private Subnet"
 +  server_private_port_name = "instance-private-port"
 +  server_private_ip        = "10.0.0.11"
 +  ssh_security_group_name  = "ssh-secgroup"
 +  key_pair_name            = "instance-keypair"
 +  
 +**variables.tf**:
 +
 +  variable "public_network_name" {
 +    type        = string
 +    description = "The name of the public network"
 +    default     = null
 +  }
 +  variable "private_network_name" {
 +    type        = string
 +    description = "The name of the private network"
 +    default     = null
 +  }
 +  variable "private_subnet_name" {
 +    type        = string
 +    description = "The name of the private subnet"
 +    default     = null
 +  }
 +  variable "server_private_port_name" {
 +    type        = string
 +    description = "The name of the private network port for the instance"
 +    default     = null
 +  }
 +  variable "server_private_ip" {
 +    type        = string
 +    description = "The fixed IP address of the instance on the private network"
 +    default     = null 
 +  }
 +  variable "image_name" {
 +    type        = string
 +    description = "The image to be used for the instance"
 +    default     = null
 +  }
 +  variable "admin_username" {
 +    type        = string
 +    description = "The admin username to be used for the instance"
 +    default     = null
 +  }
 +  variable "shortname" {
 +    type        = string
 +    description = "The shortname to assign to the instance"
 +    default     = null
 +  }
 +  variable "flavor_name" {
 +    type        = string
 +    description = "The flavor for the instance"
 +    default     = null
 +  }
 +  variable "volume_name" {
 +    type        = string
 +    description = "The volume name to assign to the device"
 +    default     = null
 +  }
 +  variable "volume_size" {
 +    type        = string
 +    description = "The volume size to assign to the device"
 +    default     = null
 +  }
 +  variable "volume_type" {
 +    type        = string
 +    description = "The volume type to assign to the device"
 +    default     = null
 +  }
 +  variable "volume_device_path" {
 +    type        = string
 +    description = "The path to the device associated with the volume"
 +    default     = null
 +  }
 +  variable "enable_online_resize" {
 +    type        = bool
 +    description = "Enable volume to be resized on the fly or not"
 +    default     = null
 +  }
 +  variable "key_pair_name" {
 +    type        = string
 +    description = "The name of the pre-defined key-pair to use for logging in to the nodes"
 +    default     = null
 +  }
 +  variable "ssh_security_group_name" {
 +    type        = string
 +    description = "The name of the security group to allow ssh access"
 +    default     = null
 +  }
 +  
 +Finally, proceed to initialise Terraform, plan and apply as we did above in the case of the base project.
 +
 +NB! In order to assign a publicly reachable IP address (i.e. a floating IP) to the above instance, you may either modify the above to include this to be done via code, or this may be done/managed via the Horizon dashboard too.
/app/dokuwiki/data/attic/guide/cloud/advanced.1760991866.txt.gz · Last modified: 2025/10/20 22:24 by sfebruary