feat: multi-site scalability, locals refactor, README
This commit is contained in:
@@ -1,209 +1,15 @@
|
||||
# Definición de la Organización
|
||||
variable "organization_name" {
|
||||
type = string
|
||||
description = "Nombre exacto de tu organización en el Dashboard de Meraki"
|
||||
}
|
||||
# Sensitive variables — injected via TF_VAR_* environment variables (GitHub Secrets).
|
||||
# Never put values for these in any .tf file.
|
||||
|
||||
# Definición de la Red
|
||||
variable "network_name" {
|
||||
type = string
|
||||
description = "Nombre de la red (Network) donde reside el switch"
|
||||
}
|
||||
|
||||
|
||||
# Reglas de firewall L3
|
||||
variable "firewall_rules" {
|
||||
type = list(object({
|
||||
comment = string
|
||||
policy = string
|
||||
protocol = string
|
||||
src_cidr = string
|
||||
src_port = string
|
||||
dest_cidr = string
|
||||
dest_port = string
|
||||
syslog_enabled = optional(bool, false)
|
||||
}))
|
||||
default = []
|
||||
description = "Lista de reglas de firewall L3 para el site"
|
||||
}
|
||||
|
||||
# SSIDs wireless
|
||||
variable "wireless_ssids" {
|
||||
type = list(object({
|
||||
number = number
|
||||
name = string
|
||||
enabled = optional(bool, true)
|
||||
auth_mode = string
|
||||
psk = optional(string, null)
|
||||
encryption_mode = optional(string, null) # "wpa" para PSK; null para open/OWE
|
||||
splash_page = optional(string, "None")
|
||||
wpa_encryption_mode = optional(string, "WPA3 only")
|
||||
ip_assignment_mode = optional(string, "Bridge mode")
|
||||
use_vlan_tagging = optional(bool, false)
|
||||
default_vlan_id = optional(number, null)
|
||||
redirect_url = optional(string, "")
|
||||
radius_servers = optional(list(object({
|
||||
host = string
|
||||
port = number
|
||||
})), [])
|
||||
}))
|
||||
default = []
|
||||
description = "Lista de SSIDs wireless a configurar en el site"
|
||||
}
|
||||
|
||||
variable "wifi_password_psk" {
|
||||
type = string
|
||||
description = "Password para la SSID WPA2 desde GitHub Secrets"
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
# Shared secret para servidores RADIUS (sensible, no incluir en tfvars)
|
||||
variable "radius_secret" {
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
description = "Shared secret para autenticación RADIUS. Pasar via TF_VAR_radius_secret"
|
||||
description = "RADIUS shared secret. Pass via TF_VAR_radius_secret (GitHub Secret: RADIUS_SECRET)."
|
||||
}
|
||||
|
||||
# Definición de VLANs
|
||||
variable "switch_vlans" {
|
||||
type = map(object({
|
||||
name = string
|
||||
subnet = optional(string, null)
|
||||
appliance_ip = optional(string, null)
|
||||
dhcp_handling = optional(string, "Run a DHCP server")
|
||||
reserved_ip_ranges = optional(list(object({
|
||||
comment = string
|
||||
id = string
|
||||
start = string
|
||||
end = string
|
||||
})), [])
|
||||
}))
|
||||
description = "Mapa de configuraciones de VLAN. La clave del mapa será el ID de la VLAN"
|
||||
}
|
||||
|
||||
|
||||
# Políticas de acceso 802.1X para switches
|
||||
variable "switch_access_policies" {
|
||||
type = list(object({
|
||||
name = string
|
||||
access_policy_type = optional(string, "802.1x")
|
||||
host_mode = optional(string, "Multi-Auth")
|
||||
radius_accounting_enabled = optional(bool, false)
|
||||
radius_testing_enabled = optional(bool, false)
|
||||
radius_coa_support_enabled = optional(bool, false)
|
||||
radius_failed_auth_vlan_id = optional(number, null)
|
||||
radius_re_authentication_interval = optional(number, 0)
|
||||
url_redirect_walled_garden_enabled = optional(bool, false)
|
||||
radius_servers = list(object({
|
||||
host = string
|
||||
port = number
|
||||
}))
|
||||
}))
|
||||
default = []
|
||||
description = "Políticas de acceso 802.1X para switches MS"
|
||||
}
|
||||
|
||||
# Configuración de puertos de switch
|
||||
variable "switch_port_configs" {
|
||||
type = list(object({
|
||||
serial = string
|
||||
port_range = string
|
||||
name = optional(string, "")
|
||||
type = optional(string, "access")
|
||||
vlan = optional(number, null)
|
||||
allowed_vlans = optional(string, "all")
|
||||
access_policy_type = optional(string, "Open")
|
||||
access_policy_number = optional(number, null)
|
||||
}))
|
||||
default = []
|
||||
description = "Puertos de switch a configurar con 802.1X. Requiere serial del switch."
|
||||
}
|
||||
|
||||
variable "switch_stack_port_configs" {
|
||||
type = list(object({
|
||||
stack_name = string
|
||||
port_range = string
|
||||
name = optional(string, "")
|
||||
type = optional(string, "access")
|
||||
vlan = optional(number, null)
|
||||
allowed_vlans = optional(string, "all")
|
||||
access_policy_type = optional(string, "Open")
|
||||
access_policy_number = optional(number, null)
|
||||
}))
|
||||
default = []
|
||||
description = "Puertos de stack a configurar por nombre. Terraform resuelve los seriales automáticamente."
|
||||
}
|
||||
|
||||
variable "switch_named_port_configs" {
|
||||
type = list(object({
|
||||
switch_name = string
|
||||
port_range = string
|
||||
name = optional(string, "")
|
||||
type = optional(string, "access")
|
||||
vlan = optional(number, null)
|
||||
allowed_vlans = optional(string, "all")
|
||||
access_policy_type = optional(string, "Open")
|
||||
access_policy_number = optional(number, null)
|
||||
}))
|
||||
default = []
|
||||
description = "Puertos de switch a configurar por nombre de dispositivo. Terraform resuelve el serial automáticamente."
|
||||
}
|
||||
|
||||
variable "switch_management_vlan" {
|
||||
type = number
|
||||
default = null
|
||||
description = "VLAN ID de gestión para los switches del site."
|
||||
}
|
||||
|
||||
variable "stack_routing_interfaces" {
|
||||
type = list(object({
|
||||
stack_name = string
|
||||
name = string
|
||||
vlan_id = number
|
||||
ip_address = string
|
||||
subnet = string
|
||||
default_gateway = optional(string, null)
|
||||
dns1 = optional(string, null)
|
||||
dns2 = optional(string, null)
|
||||
}))
|
||||
default = []
|
||||
description = "Interfaces L3 (SVIs) en stacks de switches para acceso de gestión al Dashboard."
|
||||
}
|
||||
|
||||
variable "appliance_ports" {
|
||||
type = list(object({
|
||||
port_id = string
|
||||
enabled = optional(bool, true)
|
||||
type = optional(string, "access")
|
||||
vlan = optional(number, null)
|
||||
allowed_vlans = optional(string, "all")
|
||||
drop_untagged_traffic = optional(bool, false)
|
||||
}))
|
||||
default = []
|
||||
description = "Configuración de puertos LAN del firewall MX."
|
||||
}
|
||||
|
||||
variable "mx_warm_spare" {
|
||||
type = object({
|
||||
enabled = optional(bool, true)
|
||||
spare_name = string
|
||||
uplink_mode = optional(string, "virtual")
|
||||
virtual_ip1 = optional(string, null)
|
||||
virtual_ip2 = optional(string, null)
|
||||
})
|
||||
default = null
|
||||
description = "Configuración Warm Spare (HA) del MX."
|
||||
}
|
||||
|
||||
variable "mx_wan_uplinks" {
|
||||
type = list(object({
|
||||
name = string # Nombre del dispositivo en el Dashboard
|
||||
wan1_static_ip = optional(string, null)
|
||||
wan1_static_subnet_mask = optional(string, null)
|
||||
wan1_static_gateway_ip = optional(string, null)
|
||||
wan1_static_dns = optional(list(string), null)
|
||||
}))
|
||||
default = []
|
||||
description = "Configuración WAN1 estática de los MX. El serial se resuelve automáticamente por nombre de dispositivo."
|
||||
variable "wifi_password_psk" {
|
||||
type = string
|
||||
sensitive = true
|
||||
description = "PSK Wi-Fi password. Pass via TF_VAR_wifi_password_psk (GitHub Secret: WIFI_PASSWORD_PSK)."
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user