feat(terraform): add proxmox-bootstrap state for user and role creation

This commit is contained in:
Tibo De Peuter 2026-07-17 22:06:44 +02:00
parent 17de32268d
commit 12b1faf029
Signed by: tdpeuter
SSH key fingerprint: SHA256:u/h/LVoqKF1Iz02uOyxe6hcjmoZASCGV2HM0TG9ZMoU

View file

@ -0,0 +1,71 @@
terraform {
required_providers {
proxmox = {
source = "bpg/proxmox"
version = "~> 0.61.0"
}
}
}
# This bootstrap state must be run manually ONCE with the root@pam credentials
# to establish the restricted terraform@pve user for the rest of the CI pipeline.
provider "proxmox" {
# Configuration can be passed via environment variables:
# PROXMOX_VE_ENDPOINT=https://your-proxmox-ip:8006/
# PROXMOX_VE_USERNAME=root@pam
# PROXMOX_VE_PASSWORD=your-root-password
# PROXMOX_VE_INSECURE=true # If using self-signed certs
}
resource "proxmox_virtual_environment_role" "terraform_prov" {
role_id = "TerraformProv"
privileges = [
"VM.Allocate",
"VM.Audit",
"VM.Clone",
"VM.Config.CDROM",
"VM.Config.CPU",
"VM.Config.Disk",
"VM.Config.HWType",
"VM.Config.Memory",
"VM.Config.Network",
"VM.Config.Options",
"VM.Monitor",
"VM.PowerMgmt",
"Datastore.AllocateSpace",
"Datastore.Audit",
"SDN.Use"
]
}
resource "proxmox_virtual_environment_user" "terraform_user" {
user_id = "terraform@pve"
comment = "Managed by Terraform (proxmox-bootstrap) for GitOps CI/CD"
}
resource "proxmox_virtual_environment_acl" "terraform_vms" {
user_id = proxmox_virtual_environment_user.terraform_user.user_id
role_id = proxmox_virtual_environment_role.terraform_prov.role_id
path = "/vms"
}
resource "proxmox_virtual_environment_acl" "terraform_storage" {
user_id = proxmox_virtual_environment_user.terraform_user.user_id
role_id = proxmox_virtual_environment_role.terraform_prov.role_id
# Update this path to match your actual local-zfs or TrueNAS mounted storage
path = "/storage/local-zfs"
}
resource "proxmox_virtual_environment_user_token" "terraform_token" {
user_id = proxmox_virtual_environment_user.terraform_user.user_id
token_id = "tf-automation"
privsep = false
comment = "Token for Forgejo CI/CD to provision VMs"
}
output "terraform_api_token" {
value = proxmox_virtual_environment_user_token.terraform_token.value
sensitive = true
description = "The secret API token for terraform@pve. Save this to Forgejo Secrets as PROXMOX_VE_API_TOKEN."
}