Add Cloud-Init automation with Tailscale
The commit rephrases the README to focus on Cloud-Init setup and removes unused Ansible code, making Tailscale configuration automatic. Subject line: Replace Ansible with automated Cloud-Init configuration Body: Refactors infrastructure bootstrapping to leverage Cloud-Init instead of Ansible for initial VM setup, particularly with respect to Tailscale installation and authentication. This simplifies the architecture by: - Removing manual post-provisioning Ansible steps - Automating Tailscale setup via Cloud-Init - Updating documentation to reflect new workflow
This commit is contained in:
196
terraform/prod/03-lxc-containers.tf
Normal file
196
terraform/prod/03-lxc-containers.tf
Normal file
@@ -0,0 +1,196 @@
|
||||
# Fichier: terraform/prod/lxc-containers.tf
|
||||
# Description: Déploiement des conteneurs LXC sur Proxmox
|
||||
# Status: Préparatoire - À développer selon les besoins
|
||||
|
||||
# NOTE: Ce fichier est préparé pour le futur déploiement de conteneurs LXC
|
||||
# Il n'est pas encore fonctionnel et servira de base pour le développement
|
||||
|
||||
# 1. Récupération des templates LXC disponibles
|
||||
# data "proxmox_virtual_environment_container_templates" "lxc_templates" {
|
||||
# node_name = var.target_node
|
||||
# }
|
||||
|
||||
# 2. Mapping des templates LXC par distribution
|
||||
# locals {
|
||||
# # Distributions LXC supportées
|
||||
# supported_lxc_distros = toset(["ubuntu", "debian", "alpine", "centos"])
|
||||
#
|
||||
# # Map des templates LXC par distribution (à implémenter)
|
||||
# lxc_template_map = {
|
||||
# # Structure exemple :
|
||||
# # "ubuntu" = "ubuntu-20.04-standard_20.04-1_amd64.tar.gz"
|
||||
# # "debian" = "debian-11-standard_11.0-1_amd64.tar.gz"
|
||||
# # "alpine" = "alpine-3.14-default_20210623_amd64.tar.xz"
|
||||
# }
|
||||
# }
|
||||
|
||||
# 3. Création des conteneurs LXC
|
||||
# resource "proxmox_virtual_environment_container" "lxc_containers" {
|
||||
# for_each = var.lxc_containers
|
||||
#
|
||||
# # Configuration de base
|
||||
# node_name = var.target_node
|
||||
# vm_id = each.value.vm_id
|
||||
#
|
||||
# # Configuration du conteneur
|
||||
# description = "LXC Container: ${each.key}"
|
||||
# tags = concat(["terraform-managed", "lxc"], each.value.tags)
|
||||
#
|
||||
# # Configuration système
|
||||
# unprivileged = lookup(each.value, "unprivileged", true)
|
||||
# on_boot = lookup(each.value, "on_boot", true)
|
||||
# started = lookup(each.value, "started", true)
|
||||
#
|
||||
# # Configuration OS
|
||||
# operating_system {
|
||||
# template_file_id = each.value.template
|
||||
# type = lookup(each.value, "os_type", "ubuntu")
|
||||
# }
|
||||
#
|
||||
# # Configuration CPU et mémoire
|
||||
# cpu {
|
||||
# cores = each.value.cores
|
||||
# }
|
||||
#
|
||||
# memory {
|
||||
# dedicated = each.value.memory
|
||||
# swap = lookup(each.value, "swap", 512)
|
||||
# }
|
||||
#
|
||||
# # Configuration réseau
|
||||
# network_interface {
|
||||
# name = "eth0"
|
||||
# bridge = lookup(each.value, "network_bridge", "vmbr0")
|
||||
# enabled = true
|
||||
# firewall = lookup(each.value, "firewall", false)
|
||||
# }
|
||||
#
|
||||
# # Configuration stockage
|
||||
# disk {
|
||||
# datastore_id = lookup(each.value, "datastore", "local-lvm")
|
||||
# size = each.value.disk_gb
|
||||
# }
|
||||
#
|
||||
# # Configuration d'initialisation
|
||||
# initialization {
|
||||
# hostname = "${each.key}.${var.domain_suffix}"
|
||||
#
|
||||
# ip_config {
|
||||
# ipv4 {
|
||||
# address = "${each.value.ip}/${lookup(each.value, "netmask", "24")}"
|
||||
# gateway = each.value.gateway
|
||||
# }
|
||||
# }
|
||||
#
|
||||
# dns {
|
||||
# servers = lookup(each.value, "dns_servers", ["8.8.8.8", "8.8.4.4"])
|
||||
# }
|
||||
#
|
||||
# user_account {
|
||||
# keys = [file(var.admin_ssh_public_key_path)]
|
||||
# }
|
||||
# }
|
||||
# }
|
||||
|
||||
# 4. Outputs pour les conteneurs LXC
|
||||
# output "lxc_info" {
|
||||
# description = "Informations des conteneurs LXC créés"
|
||||
# value = {
|
||||
# for k, v in proxmox_virtual_environment_container.lxc_containers : k => {
|
||||
# id = v.id
|
||||
# name = v.hostname
|
||||
# node = v.node_name
|
||||
# ip = var.lxc_containers[k].ip
|
||||
# status = v.status
|
||||
# }
|
||||
# }
|
||||
# }
|
||||
|
||||
# ===== SECTION COMMENTÉE - EXEMPLES DE CONFIGURATION =====
|
||||
|
||||
# Exemple de configuration pour les variables LXC (à ajouter dans variables.tf) :
|
||||
# variable "lxc_containers" {
|
||||
# description = "Configuration des conteneurs LXC à déployer"
|
||||
# type = map(object({
|
||||
# # Configuration de base
|
||||
# vm_id = number
|
||||
# template = string
|
||||
# cores = number
|
||||
# memory = number
|
||||
# disk_gb = number
|
||||
# ip = string
|
||||
# gateway = string
|
||||
#
|
||||
# # Configuration optionnelle
|
||||
# os_type = optional(string, "ubuntu")
|
||||
# netmask = optional(string, "24")
|
||||
# datastore = optional(string, "local-lvm")
|
||||
# network_bridge = optional(string, "vmbr0")
|
||||
# unprivileged = optional(bool, true)
|
||||
# on_boot = optional(bool, true)
|
||||
# started = optional(bool, true)
|
||||
# firewall = optional(bool, false)
|
||||
# swap = optional(number, 512)
|
||||
# dns_servers = optional(list(string), ["8.8.8.8", "8.8.4.4"])
|
||||
# tags = optional(list(string), [])
|
||||
# }))
|
||||
# default = {}
|
||||
# }
|
||||
|
||||
# Exemple de configuration dans terraform.tfvars :
|
||||
# lxc_containers = {
|
||||
# "web-proxy" = {
|
||||
# vm_id = 200
|
||||
# template = "ubuntu-20.04-standard_20.04-1_amd64.tar.gz"
|
||||
# cores = 1
|
||||
# memory = 1024
|
||||
# disk_gb = 8
|
||||
# ip = "192.168.1.200"
|
||||
# gateway = "192.168.1.254"
|
||||
# tags = ["proxy", "nginx"]
|
||||
# }
|
||||
#
|
||||
# "monitoring-light" = {
|
||||
# vm_id = 201
|
||||
# template = "alpine-3.14-default_20210623_amd64.tar.xz"
|
||||
# cores = 1
|
||||
# memory = 512
|
||||
# disk_gb = 4
|
||||
# ip = "192.168.1.201"
|
||||
# gateway = "192.168.1.254"
|
||||
# tags = ["monitoring", "lightweight"]
|
||||
# }
|
||||
# }
|
||||
|
||||
# ===== AVANTAGES DES LXC =====
|
||||
#
|
||||
# 1. Consommation réduite de ressources par rapport aux VMs
|
||||
# 2. Démarrage plus rapide
|
||||
# 3. Idéal pour les services légers (reverse proxy, monitoring, etc.)
|
||||
# 4. Partage du kernel avec l'hôte = meilleure efficacité
|
||||
# 5. Isolation suffisante pour la plupart des cas d'usage homelab
|
||||
#
|
||||
# ===== QUAND UTILISER LXC VS VM =====
|
||||
#
|
||||
# Utiliser LXC pour :
|
||||
# - Services web légers (nginx, apache)
|
||||
# - Outils de monitoring légers
|
||||
# - Reverse proxy
|
||||
# - Services de fichiers simples
|
||||
# - Environnements de développement
|
||||
#
|
||||
# Utiliser VM pour :
|
||||
# - Services nécessitant un kernel spécifique
|
||||
# - Applications nécessitant une isolation forte
|
||||
# - Kubernetes nodes
|
||||
# - Bases de données critiques
|
||||
# - Services Windows
|
||||
|
||||
# ===== TODO POUR ACTIVATION =====
|
||||
#
|
||||
# Pour activer ce fichier :
|
||||
# 1. Décommenter le code ci-dessus
|
||||
# 2. Ajouter la variable lxc_containers dans variables.tf
|
||||
# 3. Configurer les templates LXC disponibles
|
||||
# 4. Tester avec un conteneur simple
|
||||
# 5. Documenter les templates disponibles
|
||||
Reference in New Issue
Block a user