feat(BCN01-LAB): sync manual Dashboard changes to Terraform

- Management VLAN switches → 109
- Puerto 47 stack: trunk, native VLAN 109
- SVI stack bcn01-lab-stack01: VLAN 109, 10.2.55.2/24, GW 10.2.55.1
- MX puerto 7: trunk, native VLAN 109
- Firewall: allow MANAGEMENT → internet (primera regla)
- Puerto 1 eqt-lab-st01-sw01: VLAN 110 (SERVERS)
This commit is contained in:
Jose Martinez
2026-03-25 18:24:47 +01:00
parent 88ae4a7574
commit c86569436b
7 changed files with 267 additions and 12 deletions
+55
View File
@@ -112,6 +112,7 @@ variable "switch_port_configs" {
name = optional(string, "")
type = optional(string, "access")
vlan = optional(number, null)
allowed_vlans = optional(string, "all")
access_policy_type = optional(string, "Open")
access_policy_number = optional(number, null)
}))
@@ -127,6 +128,7 @@ variable "switch_stack_port_configs" {
name = optional(string, "")
type = optional(string, "access")
vlan = optional(number, null)
allowed_vlans = optional(string, "all")
access_policy_type = optional(string, "Open")
access_policy_number = optional(number, null)
}))
@@ -134,3 +136,56 @@ variable "switch_stack_port_configs" {
description = "Puertos de stack a configurar por nombre. Terraform resuelve los seriales de todos los miembros automáticamente."
}
# Configuración de puertos por nombre de switch (resolución dinámica de serial por nombre)
variable "switch_named_port_configs" {
type = list(object({
switch_name = string # nombre exacto del switch en Meraki Dashboard
port_range = string # puerto único "1" o rango "1-24"
name = optional(string, "")
type = optional(string, "access")
vlan = optional(number, null)
allowed_vlans = optional(string, "all")
access_policy_type = optional(string, "Open")
access_policy_number = optional(number, null)
}))
default = []
description = "Puertos de switch a configurar por nombre de dispositivo. Terraform resuelve el serial automáticamente."
}
# VLAN de gestión de los switches del site
variable "switch_management_vlan" {
type = number
default = null
description = "VLAN ID de gestión para los switches del site (Dashboard > Switch > Switch settings > Management VLAN)"
}
# Interfaces de enrutamiento L3 en stacks de switches
variable "stack_routing_interfaces" {
type = list(object({
stack_name = string # nombre exacto del stack en Meraki Dashboard
name = string # nombre descriptivo de la interfaz
vlan_id = number
ip_address = string # IP estática del stack en esta VLAN
subnet = string # subred en formato CIDR, ej: "10.2.55.0/24"
default_gateway = optional(string, null) # gateway para acceso a internet
dns1 = optional(string, null) # DNS primario
dns2 = optional(string, null) # DNS secundario
}))
default = []
description = "Interfaces L3 (SVIs) en stacks de switches para acceso de gestión al Dashboard de Meraki."
}
# Puertos del firewall MX
variable "appliance_ports" {
type = list(object({
port_id = string
enabled = optional(bool, true)
type = optional(string, "access") # "access" o "trunk"
vlan = optional(number, null) # VLAN nativa en trunk, o VLAN de acceso
allowed_vlans = optional(string, "all") # solo para trunk
drop_untagged_traffic = optional(bool, false)
}))
default = []
description = "Configuración de puertos del firewall MX (LAN ports)."
}