fix(tofu): protect volumes, align defaults, tighten ci checks #457
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!457
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/tofu-hygiene"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
OpenTofu hygiene from the 2026-09-09 infrastructure audit. No production apply is needed: every change is a plan no-op at today's values.
prevent_destroyon all five Cinder volumes.ignore_changes = [image_id]on the two root volumes, since the image lookup ismost_recentand a republished Debian image would otherwise plan a rebuild of both VMs.terraform.tfvars, the old defaults would have planned a shrink, which Cinder turns into a replace.required_versionbounded below 2.0. Validation onmonitoring_count(0 or 1) andmonitoring_fixed_ip.scripts/teardown.shskips the named data volumes even under--yesunless--include-data-volumesis passed.tofu validateaftertofu fmt;pnpm tofu:checknow matches CI with-recursive.opentofu/README.mdfile table, a stale runner boot-volume comment.Checks
tofu fmt -check -recursive,tofu init -backend=false+tofu validate, shellcheck onteardown.sh,pnpm tofu:check.