Merge pull request #20 from its-corp/feature/bcn01-ssid-encryption-wan-ports

wip: add SSID slot 3 placeholder for drift detection via terraform plan
This commit is contained in:
Jose Martinez
2026-03-27 12:02:16 +01:00
committed by GitHub Enterprise
3 changed files with 25 additions and 7 deletions
+5 -6
View File
@@ -159,13 +159,12 @@ resource "meraki_wireless_ssid" "ssids" {
number = each.value.number
name = each.value.name
enabled = each.value.enabled
visible = each.value.visible
auth_mode = each.value.auth_mode
# Si el SSID no tiene psk en el tfvars, usa var.wifi_password_psk (TF_VAR_wifi_password_psk)
psk = each.value.psk != null ? each.value.psk : var.wifi_password_psk
# wpa_encryption_mode solo es compatible con auth_mode != "open"
# Para OWE (open + WPA3) la API rechaza el campo; la encriptación Enhanced Open
# se negocia a nivel de beacon y no se expone como atributo de la API Meraki.
wpa_encryption_mode = each.value.auth_mode != "open" ? each.value.wpa_encryption_mode : null
# PSK solo se envía para SSIDs con auth_mode "psk"; para open/open-enhanced se deja null
psk = each.value.auth_mode == "psk" ? (each.value.psk != null ? each.value.psk : var.wifi_password_psk) : null
# wpa_encryption_mode se pasa directamente desde el tfvars (null si no aplica)
wpa_encryption_mode = each.value.wpa_encryption_mode
encryption_mode = each.value.encryption_mode
splash_page = each.value.splash_page
ip_assignment_mode = each.value.ip_assignment_mode
+1
View File
@@ -33,6 +33,7 @@ variable "wireless_ssids" {
number = number
name = string
enabled = optional(bool, true)
visible = optional(bool, true) # false = SSID oculto (no broadcast)
auth_mode = string
psk = optional(string, null) # Contraseña WPA2/WPA3-PSK (sensible, usar TF_VAR o secret)
encryption_mode = optional(string, null) # "wpa" para PSK; null para open/OWE
+19 -1
View File
@@ -10,7 +10,25 @@ wireless_ssids = [
auth_mode = "open-enhanced" # OWE (Opportunistic Wireless Encryption)
# Meraki API utiliza "open-enhanced" para indicar Enhanced Open / OWE.
# Este valor refleja exactamente lo que está configurado en el Dashboard.
wpa_encryption_mode = null
wpa_encryption_mode = "WPA3 only"
splash_page = "Password-protected with custom RADIUS"
ip_assignment_mode = "Bridge mode"
use_vlan_tagging = true
default_vlan_id = 100
redirect_url = "https://www.adevinta.com"
radius_servers = [
{
host = "15.15.15.15"
port = 1912
}
]
},
{
number = 2
name = "EQT-CORPO-OWE-OK"
enabled = true
visible = false # SSID oculto — no hace broadcast del nombre
auth_mode = "open"
splash_page = "Password-protected with custom RADIUS"
ip_assignment_mode = "Bridge mode"
use_vlan_tagging = true