fix(tofu): protect volumes, align defaults, tighten ci checks #457

Sammanfogat
supernaut sammanfogade 3 incheckningar från fix/tofu-hygiene in i main 2026-09-08 23:03:43 +00:00
Ägare

What

OpenTofu hygiene from the 2026-09-09 infrastructure audit. No production apply is needed: every change is a plan no-op at today's values.

  • prevent_destroy on all five Cinder volumes. ignore_changes = [image_id] on the two root volumes, since the image lookup is most_recent and a republished Debian image would otherwise plan a rebuild of both VMs.
  • Variable defaults aligned with production: backup volume 150 GB (was 40), LFS volume 60 GB (was 20), also in the tfvars example. On a machine without the local terraform.tfvars, the old defaults would have planned a shrink, which Cinder turns into a replace.
  • Three dead runner variables removed; the runner controller role is the only source.
  • required_version bounded below 2.0. Validation on monitoring_count (0 or 1) and monitoring_fixed_ip.
  • scripts/teardown.sh skips the named data volumes even under --yes unless --include-data-volumes is passed.
  • CI and lefthook run tofu validate after tofu fmt; pnpm tofu:check now matches CI with -recursive.
  • Docs: backup volume size in the runbook (150 GB), opentofu/README.md file table, a stale runner boot-volume comment.

Checks

tofu fmt -check -recursive, tofu init -backend=false + tofu validate, shellcheck on teardown.sh, pnpm tofu:check.

## What OpenTofu hygiene from the 2026-09-09 infrastructure audit. No production apply is needed: every change is a plan no-op at today's values. - `prevent_destroy` on all five Cinder volumes. `ignore_changes = [image_id]` on the two root volumes, since the image lookup is `most_recent` and a republished Debian image would otherwise plan a rebuild of both VMs. - Variable defaults aligned with production: backup volume 150 GB (was 40), LFS volume 60 GB (was 20), also in the tfvars example. On a machine without the local `terraform.tfvars`, the old defaults would have planned a shrink, which Cinder turns into a replace. - Three dead runner variables removed; the runner controller role is the only source. - `required_version` bounded below 2.0. Validation on `monitoring_count` (0 or 1) and `monitoring_fixed_ip`. - `scripts/teardown.sh` skips the named data volumes even under `--yes` unless `--include-data-volumes` is passed. - CI and lefthook run `tofu validate` after `tofu fmt`; `pnpm tofu:check` now matches CI with `-recursive`. - Docs: backup volume size in the runbook (150 GB), `opentofu/README.md` file table, a stale runner boot-volume comment. ## Checks `tofu fmt -check -recursive`, `tofu init -backend=false` + `tofu validate`, shellcheck on `teardown.sh`, `pnpm tofu:check`.
supernaut lade till 3 incheckningar 2026-09-08 23:00:49 +00:00
supernaut sammanfogade incheckning 7cdaf5f205 till main 2026-09-08 23:03:43 +00:00
supernaut tog bort grenen fix/tofu-hygiene 2026-09-08 23:03:43 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!457
Ingen beskrivning angiven.