feat: multi-site scalability, locals refactor, README

This commit is contained in:
Xavier Lario
2026-04-20 10:16:49 +02:00
parent 881d0ac5b8
commit 8ff53503db
23 changed files with 1155 additions and 740 deletions
+121
View File
@@ -0,0 +1,121 @@
locals {
# 802.1X access policies
# The RADIUS shared secret is injected from var.radius_secret — never put it here.
switch_access_policies = [
{
name = "DOT1X-CORPO"
access_policy_type = "Hybrid authentication"
host_mode = "Multi-Auth"
radius_accounting_enabled = false
radius_re_authentication_interval = 0
url_redirect_walled_garden_enabled = false
radius_failed_auth_vlan_id = 101 # Fallback to GUEST if RADIUS unreachable
radius_servers = [
{ host = "15.15.15.15", port = 1912 }
]
},
]
# Ports by explicit serial — use when targeting a switch directly by serial number
# Example:
# switch_port_configs = [
# {
# serial = "XXXX-XXXX-XXXX"
# port_range = "1-20"
# type = "access"
# vlan = 100 # ACCESS — fallback if RADIUS doesn't assign a VLAN
# access_policy_type = "Custom access policy"
# access_policy_number = 1 # references DOT1X-CORPO above
# },
# ]
switch_port_configs = []
# Ports by stack name — Terraform resolves serials for all stack members automatically.
# The same port_range is applied to EVERY switch in the stack.
switch_stack_port_configs = [
{
stack_name = "bcn01-lab-stack01"
port_range = "6"
type = "access"
vlan = 101 # GUEST
access_policy_type = "Open"
},
{
stack_name = "bcn01-lab-stack01"
port_range = "44"
name = "ISP router 1"
type = "access"
vlan = 111 # WAN
access_policy_type = "Open"
},
{
stack_name = "bcn01-lab-stack01"
port_range = "45"
name = "WAN 1 BCN01-F04-MX01"
type = "access"
vlan = 111 # WAN
access_policy_type = "Open"
},
{
stack_name = "bcn01-lab-stack01"
port_range = "46"
name = "WAN 1 BCN01-F04-MX02"
type = "access"
vlan = 111 # WAN
access_policy_type = "Open"
},
{
stack_name = "bcn01-lab-stack01"
port_range = "47"
name = "UPLINK LAN BCN01-F04-MX01"
type = "trunk"
vlan = 109 # MANAGEMENT — native (untagged) VLAN
allowed_vlans = "all"
access_policy_type = "Open"
},
{
stack_name = "bcn01-lab-stack01"
port_range = "48"
name = "UPLINK LAN BCN01-F04-MX02"
type = "trunk"
vlan = 109 # MANAGEMENT — native (untagged) VLAN
allowed_vlans = "all"
access_policy_type = "Open"
},
]
# Ports by switch display name — targets a specific stack member without knowing its serial
switch_named_port_configs = [
{
switch_name = "eqt-lab-st01-sw01"
port_range = "1"
name = "Servers"
type = "access"
vlan = 101 # SERVERS
access_policy_type = "Open"
},
{
switch_name = "eqt-lab-st01-sw01"
port_range = "2,3"
name = "AP"
type = "trunk"
vlan = 108 # APs — native (untagged) VLAN
allowed_vlans = "100,101,108" # ACCESS + GUEST + APs
access_policy_type = "Open"
},
]
switch_management_vlan = 109
# L3 routing interfaces on the stack (SVIs for management access to Meraki Dashboard)
stack_routing_interfaces = [
{
stack_name = "bcn01-lab-stack01"
name = "MANAGEMENT"
vlan_id = 109
ip_address = "10.2.55.2"
subnet = "10.2.55.0/24"
default_gateway = "10.2.55.1"
},
]
}