feat(terraform): add proxmox-bootstrap state for user and role creation
This commit is contained in:
parent
17de32268d
commit
12b1faf029
1 changed files with 71 additions and 0 deletions
71
terraform/proxmox-bootstrap/main.tf
Normal file
71
terraform/proxmox-bootstrap/main.tf
Normal file
|
|
@ -0,0 +1,71 @@
|
|||
terraform {
|
||||
required_providers {
|
||||
proxmox = {
|
||||
source = "bpg/proxmox"
|
||||
version = "~> 0.61.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# This bootstrap state must be run manually ONCE with the root@pam credentials
|
||||
# to establish the restricted terraform@pve user for the rest of the CI pipeline.
|
||||
provider "proxmox" {
|
||||
# Configuration can be passed via environment variables:
|
||||
# PROXMOX_VE_ENDPOINT=https://your-proxmox-ip:8006/
|
||||
# PROXMOX_VE_USERNAME=root@pam
|
||||
# PROXMOX_VE_PASSWORD=your-root-password
|
||||
# PROXMOX_VE_INSECURE=true # If using self-signed certs
|
||||
}
|
||||
|
||||
resource "proxmox_virtual_environment_role" "terraform_prov" {
|
||||
role_id = "TerraformProv"
|
||||
|
||||
privileges = [
|
||||
"VM.Allocate",
|
||||
"VM.Audit",
|
||||
"VM.Clone",
|
||||
"VM.Config.CDROM",
|
||||
"VM.Config.CPU",
|
||||
"VM.Config.Disk",
|
||||
"VM.Config.HWType",
|
||||
"VM.Config.Memory",
|
||||
"VM.Config.Network",
|
||||
"VM.Config.Options",
|
||||
"VM.Monitor",
|
||||
"VM.PowerMgmt",
|
||||
"Datastore.AllocateSpace",
|
||||
"Datastore.Audit",
|
||||
"SDN.Use"
|
||||
]
|
||||
}
|
||||
|
||||
resource "proxmox_virtual_environment_user" "terraform_user" {
|
||||
user_id = "terraform@pve"
|
||||
comment = "Managed by Terraform (proxmox-bootstrap) for GitOps CI/CD"
|
||||
}
|
||||
|
||||
resource "proxmox_virtual_environment_acl" "terraform_vms" {
|
||||
user_id = proxmox_virtual_environment_user.terraform_user.user_id
|
||||
role_id = proxmox_virtual_environment_role.terraform_prov.role_id
|
||||
path = "/vms"
|
||||
}
|
||||
|
||||
resource "proxmox_virtual_environment_acl" "terraform_storage" {
|
||||
user_id = proxmox_virtual_environment_user.terraform_user.user_id
|
||||
role_id = proxmox_virtual_environment_role.terraform_prov.role_id
|
||||
# Update this path to match your actual local-zfs or TrueNAS mounted storage
|
||||
path = "/storage/local-zfs"
|
||||
}
|
||||
|
||||
resource "proxmox_virtual_environment_user_token" "terraform_token" {
|
||||
user_id = proxmox_virtual_environment_user.terraform_user.user_id
|
||||
token_id = "tf-automation"
|
||||
privsep = false
|
||||
comment = "Token for Forgejo CI/CD to provision VMs"
|
||||
}
|
||||
|
||||
output "terraform_api_token" {
|
||||
value = proxmox_virtual_environment_user_token.terraform_token.value
|
||||
sensitive = true
|
||||
description = "The secret API token for terraform@pve. Save this to Forgejo Secrets as PROXMOX_VE_API_TOKEN."
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue