Jose Martinez and GitHub Enterprise
629614cba8
Merge pull request #28 from its-corp/feat/bcn01-lab-sw01-port15-servers
...
feat(bcn01-lab): set port 15 sw01 to SERVERS VLAN (110) access mode
2026-05-12 11:52:28 +02:00
Jose Martinez and Claude Sonnet 4.6
9b8c29d5dc
feat(bcn01-lab): set port 15 sw01 to SERVERS VLAN (110) access mode
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-12 11:47:20 +02:00
Jose Martinez and GitHub Enterprise
885365ff73
Merge pull request #27 from its-corp/feat/bcn01-lab-nat-port-5001
...
feat(bcn01-lab): add port 5001 to Synology 1:1 NAT rule
2026-05-07 15:02:11 +02:00
Jose Martinez
5e009ef49a
ci: retrigger plan for PR #27
2026-05-07 15:00:25 +02:00
Jose Martinez and Claude Sonnet 4.6
4d9b4c13bd
feat(bcn01-lab): add port 5001 to Synology 1:1 NAT rule
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-07 14:56:13 +02:00
Jose Martinez and GitHub Enterprise
9223699c79
Merge pull request #26 from its-corp/feat/bcn01-lab-sw01-ports-management-dhcp
...
feat(bcn01-lab): assign ports 11/12 on sw01 and enable DHCP on MANAGEMENT VLAN
2026-05-07 12:28:43 +02:00
Jose Martinez and Claude Sonnet 4.6
88895cbf8c
feat(bcn01-lab): assign ports 11/12 on sw01 and enable DHCP on MANAGEMENT VLAN
...
- Port 11 → VLAN 109 (MANAGEMENT), access, Open
- Port 12 → VLAN 110 (SERVERS), access, Open
- VLAN 109 DHCP enabled with static reserved range 10.2.55.1–10.2.55.49
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-07 12:26:50 +02:00
Jose Martinez and GitHub Enterprise
59427707e7
Merge pull request #25 from its-corp/feat/bcn01-lab-nat-ports
...
feat(bcn01-lab): restrict 1:1 NAT to specific service ports, allow any source
2026-05-07 10:33:53 +02:00
Jose Martinez and Claude Sonnet 4.6
85ef316745
feat(bcn01-lab): restrict 1:1 NAT to specific service ports, allow any source
...
Replace open any/any inbound rule on Synology NAT with explicit TCP ports:
443 (Synology), 9890 (Vaultwarden), 4769 (Zabbix), 8080 (Snipe-IT),
3000 (Metabase), 3333 (Gitea), 8081 (phpIPAM). Access allowed from any IP.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-07 10:30:29 +02:00
Jose Martinez and GitHub Enterprise
36f08cc7cb
Merge pull request #24 from its-corp/fix/radius-secret-default
...
feat(bcn01-lab): add 1:1 NAT support and import Synology rule
2026-05-07 09:54:03 +02:00
Jose Martinez and Claude Sonnet 4.6
6d0f186795
fix(meraki-site): correct 1:1 NAT resource type name
...
meraki_appliance_firewall_one_to_one_nat_rules does not exist in
provider v1.9.0; correct name is meraki_appliance_one_to_one_nat_rules.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-07 09:52:27 +02:00
Jose Martinez and Claude Sonnet 4.6
b8e517cb40
feat(bcn01-lab): add 1:1 NAT support and import Synology rule
...
Add meraki_appliance_firewall_one_to_one_nat_rules resource to the
meraki-site module and codify the existing Synology NAT rule found in
BCN01-LAB Dashboard (57.133.120.190 → 10.2.56.3 via internet2).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-07 09:42:59 +02:00
Jose Martinez and GitHub Enterprise
3268bae474
Merge pull request #23 from its-corp/fix/radius-secret-default
...
fix(bcn01-lab): use null default for radius_secret variable
2026-05-05 07:53:44 +02:00
Jose Martinez and Claude Sonnet 4.6
4a93967012
fix(bcn01-lab): use null default for radius_secret variable
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-05 07:51:24 +02:00
Jose Martinez and Claude Sonnet 4.6
de90079f32
ci: retrigger apply for BCN01-LAB port 1 sw01
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:34:00 +02:00
Jose Martinez and Claude Sonnet 4.6
d71ae52979
ci: retrigger apply for BCN01-LAB port 1 sw01
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:32:30 +02:00
Jose Martinez and GitHub Enterprise
1157b7cfc7
Merge pull request #22 from its-corp/bcn01-lab
...
feat(bcn01-lab): onboard BCN01-LAB site
2026-04-29 07:13:35 +02:00
Jose Martinez and Claude Sonnet 4.6
9227e3a1ab
fix(bcn01-lab): set DOT1X-CORPO host_mode to Multi-Host to match Dashboard
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:09:09 +02:00
Jose Martinez and Claude Sonnet 4.6
9184567152
fix(bcn01-lab): correct auth_mode value for EQT-CORPO SSID
...
Use '8021x-radius' instead of '8021x' — required by CiscoDevNet/meraki provider v1.9.0
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:04:35 +02:00
Jose Martinez and Claude Sonnet 4.6
29614e1dc4
feat(bcn01-lab): onboard BCN01-LAB site and extend module with WAN2 support
...
- Add sites/BCN01-LAB with full Meraki configuration: VLANs, SSIDs,
switch ports, 802.1X policy, firewall rules, WAN uplinks and warm spare
- Extend modules/meraki-site to support wan2_* fields in mx_wan_uplinks
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-04-29 07:02:06 +02:00
Javier Veral and GitHub Enterprise
097a3c5b6c
Merge pull request #21 from its-corp/feature/multi-site-scalability
...
feat: multi-site scalability, locals refactor, README
2026-04-21 10:33:53 +02:00
Xavier Lario
fde7a160ac
fake change: just to force checks
2026-04-21 10:29:53 +02:00
Xavier Lario
d1839fce7a
temp fix: remove BCN01-LAB to commit just code
2026-04-21 10:26:00 +02:00
Xavier Lario
824ba83f93
fix(ci): use MERAKI_API_KEY env var — correct name for CiscoDevNet/meraki provider
2026-04-21 09:03:57 +02:00
Xavier Lario
79ee5868ee
revert last changes
2026-04-21 08:58:41 +02:00
Xavier Lario
55a6a98044
fix: pass meraki api key explicitly via provider block and TF_VAR
2026-04-20 16:43:24 +02:00
Xavier Lario
6ffe6bfcc5
ix(BCN01-LAB): add required_providers to root module — not inherited from child modules
2026-04-20 16:27:20 +02:00
Xavier Lario
c6dfd9deef
fix(ci): add contents: read permission to plan job
2026-04-20 16:24:10 +02:00
Xavier Lario
01acb2e54d
fix(ci): reset git SSH override before checkout to prevent self-hosted runner state pollution
2026-04-20 16:20:39 +02:00
Xavier Lario
20c9b142fd
fix: problem with the sites discovery
2026-04-20 16:14:17 +02:00
Xavier Lario
a797a18909
fix: change ubuntu for selfhosted for tests
2026-04-20 15:00:24 +02:00
Xavier Lario
43d696a3c6
change: add vscode files to gitignore
2026-04-20 10:24:02 +02:00
Xavier Lario
8ff53503db
feat: multi-site scalability, locals refactor, README
2026-04-20 10:16:49 +02:00
Jose Martinez
881d0ac5b8
docs: add MANUAL_STEPS.md with Client VPN and OWE manual config
2026-04-07 06:28:43 +02:00
Jose Martinez
44f53fa5cb
changing rules
2026-03-27 12:38:37 +01:00
Jose Martinez
e0273cfdb1
feat: remove firewall rules - Acceso Javi, Bloqueo 8.8.8.8, Bloqueo Cloudflare
2026-03-27 12:31:44 +01:00
Jose Martinez
76a0ef9d93
fix: split SSID resource - ssids_open omits wpa_encryption_mode (API rejects it for auth_mode=open)
2026-03-27 12:24:21 +01:00
Jose Martinez
21bdb41e9d
fix: change wpa_encryption_mode default to null to avoid WPA3 incompatibility with open SSIDs
2026-03-27 12:19:53 +01:00
Jose Martinez
e8172f35d7
fix: set wpa_encryption_mode=null for EQT-CORPO-OWE-OK (open incompatible with WPA3)
2026-03-27 12:16:57 +01:00
Jose Martinez and GitHub Enterprise
57c1b9f2a2
Merge pull request #20 from its-corp/feature/bcn01-ssid-encryption-wan-ports
...
wip: add SSID slot 3 placeholder for drift detection via terraform plan
2026-03-27 12:02:16 +01:00
Jose Martinez
e6668edd37
feat: add visible field to SSID module + hide EQT-CORPO-OWE-OK
2026-03-27 11:53:02 +01:00
Jose Martinez
1919e1ffc9
feat: add EQT-CORPO-OWE-OK SSID (slot 2) synced from Dashboard
2026-03-27 11:35:06 +01:00
Jose Martinez
ab3f30469b
fix: sync wpa_encryption_mode WPA3 only for EQT-CORPO OWE + pass through from tfvars
2026-03-27 08:43:08 +01:00
Jose Martinez
27292fddb6
fix: set real name for SSID slot 2 (EQT-CORPO-OWE-OK)
2026-03-27 08:39:00 +01:00
Jose Martinez
02381faf91
fix: SSID slot 3 -> slot 2 (Meraki indexa desde 0)
2026-03-27 08:38:20 +01:00
Jose Martinez
af7f59f3c2
fix: only inject PSK and wpa_encryption_mode for auth_mode=psk SSIDs
2026-03-27 08:37:14 +01:00
Jose Martinez
4cf91c5c96
wip: add SSID slot 3 placeholder for drift detection via terraform plan
2026-03-27 08:32:54 +01:00
Jose Martinez and GitHub Enterprise
cb3fa39a6f
Merge pull request #19 from its-corp/feature/bcn01-ssid-encryption-wan-ports
...
fix: use auth_mode=open-enhanced to match OWE config in Dashboard
2026-03-27 08:28:04 +01:00
Jose Martinez
252695d911
fix: use auth_mode=open-enhanced to match OWE config in Dashboard
2026-03-27 08:26:01 +01:00
Jose Martinez and GitHub Enterprise
65452a8f05
Merge pull request #18 from its-corp/feature/bcn01-ssid-encryption-wan-ports
...
Feature/bcn01 ssid encryption wan ports
2026-03-27 07:26:47 +01:00