Commit Graph
61 Commits
Author SHA1 Message Date
Jose MartinezandGitHub Enterprise d0566dbaf3 Merge pull request #10 from its-corp/feature/bcn01-sync-dashboard-changes
Feature/bcn01 sync dashboard changes
2026-03-26 07:16:46 +01:00
Jose MartinezandClaude Sonnet 4.6 6dc629ea18 feat: soporte port_range con listas y combinaciones ("2,3", "1-3,5")
- _expand_range ahora procesa segmentos separados por coma, cada uno
  puede ser un puerto único o un rango numérico (1-48).
  Ejemplos: "2,3" -> ["2","3"] | "1-3,5,47" -> ["1","2","3","5","47"]
- switch.auto.tfvars: puertos 2 y 3 de eqt-lab-st01-sw01 consolidados
  en una sola entrada con port_range = "2,3"

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-26 07:09:12 +01:00
Jose MartinezandClaude Sonnet 4.6 a1068c831d feat(BCN01-LAB): puerto 2 eqt-lab-st01-sw01 como AP trunk
- Añadido puerto 2 de eqt-lab-st01-sw01 como trunk AP con VLAN nativa
  108 (APs) y tageadas 100 (ACCESS) y 101 (GUEST), igual que puerto 3

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-26 07:07:38 +01:00
Jose MartinezandGitHub Enterprise 3d5d5f0481 Merge pull request #9 from its-corp/feature/bcn01-sync-dashboard-changes
Feature/bcn01 sync dashboard changes
2026-03-26 07:02:21 +01:00
Jose Martinez 76af4e256a ci: re-trigger plan with fixes 2026-03-26 06:48:14 +01:00
Jose Martinez 380c8adea8 ci: re-trigger apply with fix 2026-03-26 06:46:43 +01:00
Jose Martinez fb56dc23c4 ci: re-trigger apply with fix 2026-03-26 06:44:47 +01:00
Jose MartinezandClaude Sonnet 4.6 7cb7c22b5b fix(bcn01-lab): corregir errores de apply en VLAN 111 y SSID EQT-CORPO
- meraki_appliance_vlan: filtrar VLANs sin subnet (if v.subnet != null)
  para que VLAN 111 WAN (L2-only) no se pase a la API del MX, que exige
  CIDR en el campo subnet.
- meraki_wireless_ssid: pasar wpa_encryption_mode = null cuando
  auth_mode = "open", ya que la API Meraki rechaza modos WPA con auth
  abierta. OWE/Enhanced Open se negocia a nivel beacon y no se expone
  como atributo API.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-26 06:32:39 +01:00
Jose MartinezandGitHub Enterprise 551b755b2b Merge pull request #8 from its-corp/feature/bcn01-sync-dashboard-changes
feat(BCN01-LAB): sync manual Dashboard changes to Terraform
2026-03-26 06:28:41 +01:00
Jose Martinez 7378e9977c feat(BCN01-LAB): puerto AP trunk y VLAN 111 WAN sin L3
- Puerto 3 eqt-lab-st01-sw01: trunk, native 108 (APs), tagged 100+101
- VLAN 111 WAN sin subnet ni appliance_ip (switching puro)
- subnet/appliance_ip pasan a ser opcionales en el módulo
2026-03-25 23:07:09 +01:00
Jose Martinez f55a54064d fix: usar meraki_network_devices y nombres correctos de recursos
- data meraki_devices → data meraki_network_devices
- meraki_networks_switch_settings → meraki_switch_settings
- meraki_networks_switch_stacks_routing_interfaces → meraki_switch_stack_routing_interface
- switch_named_port_configs vuelve a usar switch_name (lookup dinámico)
2026-03-25 18:33:50 +01:00
Jose Martinez c86569436b feat(BCN01-LAB): sync manual Dashboard changes to Terraform
- Management VLAN switches → 109
- Puerto 47 stack: trunk, native VLAN 109
- SVI stack bcn01-lab-stack01: VLAN 109, 10.2.55.2/24, GW 10.2.55.1
- MX puerto 7: trunk, native VLAN 109
- Firewall: allow MANAGEMENT → internet (primera regla)
- Puerto 1 eqt-lab-st01-sw01: VLAN 110 (SERVERS)
2026-03-25 18:24:47 +01:00
Jose MartinezandClaude Sonnet 4.6 88ae4a7574 chore: ignorar carpeta docs/ en git
La documentacion (HLD, LLD) se almacena en docs/ localmente
pero no se versiona en el repositorio.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 12:55:22 +01:00
Jose MartinezandClaude Sonnet 4.6 67268df12d fix: correct stack name to bcn01-lab-stack01 (matches Meraki Dashboard)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 09:05:17 +01:00
Jose MartinezandClaude Sonnet 4.6 73497c1b49 fix: correct stack name typo bcn01 -> bnc01
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 08:59:16 +01:00
Jose MartinezandClaude Sonnet 4.6 418b0e94f4 feat: configure port 5 of bcn01-lab-stack01 to VLAN 101 (GUEST)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 08:55:13 +01:00
Jose MartinezandClaude Sonnet 4.6 c6343d977e feat: add switch stack port config with dynamic serial resolution
- Add data source meraki_switch_stacks to resolve member serials by stack name
- Add switch_stack_port_configs variable: specify stack_name + port_range
  instead of individual switch serials
- Terraform applies port_range to ALL members of the stack automatically
- Merge switch_port_configs and switch_stack_port_configs into all_ports local
- Add example for bcn01-lab-stack01 (2x48p) in switch.auto.tfvars

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 08:42:48 +01:00
Jose MartinezandClaude Sonnet 4.6 16c09f8cc5 docs: fix comments - Group Policies en switches no asignan VLAN, es estatica en el puerto
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-19 09:50:26 +01:00
Jose MartinezandClaude Sonnet 4.6 711dfa79bf docs: add APs port example in switch.auto.tfvars
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 12:13:14 +01:00
Jose MartinezandClaude Sonnet 4.6 dcc7398355 docs: add port config examples (802.1X, impresoras, uplink) in switch.auto.tfvars
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 12:11:02 +01:00
Jose MartinezandClaude Sonnet 4.6 775dbce9a8 feat: support port ranges in switch_port_configs (e.g. port_range = "1-24")
Replace port_id with port_range in variable; add local to expand ranges
into individual port entries before creating meraki_switch_port resources.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 11:37:11 +01:00
Jose MartinezandClaude Sonnet 4.6 67420fc099 feat: change access_policy_type to Hybrid authentication (802.1X + MAB fallback)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 11:27:25 +01:00
Jose Martinez 0536a2f1b0 trigger: re-run apply with DOT1X-CORPO name 2026-03-18 11:24:36 +01:00
Jose Martinez 4500466248 Merge branch 'feature/switch-dot1x' 2026-03-18 11:19:21 +01:00
Jose MartinezandClaude Sonnet 4.6 cc5c3615b0 fix: rename access policy 802.1X-CORPO to DOT1X-CORPO (Meraki naming rules)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 11:16:02 +01:00
Jose MartinezandGitHub Enterprise 9cccd25e85 Merge pull request #7 from its-corp/feature/switch-dot1x
Feature/switch dot1x
2026-03-18 11:14:50 +01:00
Jose MartinezandClaude Sonnet 4.6 51622ab923 fix: remove unsupported voice_vlan_id from meraki_switch_port resource
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 11:12:02 +01:00
Jose MartinezandClaude Sonnet 4.6 cecf38efd7 fix: add required radius_testing_enabled and radius_coa_support_enabled to switch_access_policy
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 11:10:42 +01:00
Jose MartinezandClaude Sonnet 4.6 0aa21b56f9 fix: set critical VLAN to 101 (GUEST) for 802.1X policy
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 11:04:35 +01:00
Jose MartinezandClaude Sonnet 4.6 9b86ba97af feat: add 802.1X switch access policy support
- Add meraki_switch_access_policy resource to module (multi-auth, critical VLAN)
- Add meraki_switch_port resource for per-port policy assignment
- Add switch_access_policies and switch_port_configs variables to module and site
- Create switch.auto.tfvars for BCN01-LAB with 802.1X-CORPO policy
  (RADIUS: 15.15.15.15:1912, critical VLAN: 100, host_mode: Multi-Auth)
- switch_port_configs starts empty; add serial + port_id to assign policy to ports

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 11:01:55 +01:00
Jose MartinezandClaude Sonnet 4.6 cb77482368 refactor: rename site bcn01 to BCN01-LAB
- Rename sites/bcn01/ -> sites/BCN01-LAB/
- Update S3 backend key: bcn01/terraform.tfstate -> BCN01-LAB/terraform.tfstate
- Rename Terraform module: bcn01 -> bcn01_lab
- Update working-directory in apply.yml and plan.yml
- Update job/step names to BCN01-LAB

NOTA: mover manualmente en S3 el objeto
  bcn01/terraform.tfstate  ->  BCN01-LAB/terraform.tfstate
antes de hacer terraform init en el nuevo directorio.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-18 10:29:58 +01:00
Jose Martinez ed9ee66972 Merge branch 'main' of github.mpi-internal.com:its-corp/eqt-network-meraki 2026-03-16 18:52:14 +01:00
Jose MartinezandClaude Sonnet 4.6 f0cc9781a6 fix: set auth_mode=open for RADIUS splash page on EQT-CORPO SSID
open-with-radius es para MAC-based RADIUS (sin splash), incompatible
con splash pages. auth_mode=open con custom RADIUS splash es la
combinacion correcta para captive portal + autenticacion RADIUS.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-16 18:49:50 +01:00
Jose Martinez fea7b85099 fix: remove wpa_encryption_mode to fix MAC-based AC incompatibility 2026-03-16 18:44:57 +01:00
Jose MartinezandGitHub Enterprise 8a72f5aa6c Merge pull request #6 from its-corp/feature/add-ssid-eqt-corpo
fix: use radius_servers as list attribute in wireless SSID
2026-03-16 18:42:13 +01:00
Jose Martinez bbe4921bc9 fix: use radius_servers as list attribute in wireless SSID 2026-03-16 17:18:07 +01:00
Jose MartinezandGitHub Enterprise e60ea38939 Merge pull request #5 from its-corp/feature/add-ssid-eqt-corpo
feat: add EQT-CORPO SSID with OWE and Okta RADIUS
2026-03-16 17:16:10 +01:00
Jose Martinez c1595cd9d5 feat: add EQT-CORPO SSID with OWE and Okta RADIUS 2026-03-16 17:13:40 +01:00
Jose MartinezandGitHub Enterprise 9857fde037 Merge pull request #4 from its-corp/feature/borrar-vlan-test
borrando vlan test
2026-03-16 14:15:08 +01:00
Jose Martinez 6b995dfc4b borrando vlan test 2026-03-16 14:11:54 +01:00
Jose MartinezandGitHub Enterprise 24d7ba41ba Merge pull request #3 from its-corp/feature/crear-vlan-test
testeando la creacion de una nueva VLAN
2026-03-16 13:45:01 +01:00
Jose Martinez 7079c7cfaf testeando la creacion de una nueva VLAN 2026-03-16 13:42:46 +01:00
Jose Martinez 13261ce136 fix: disable syslog on firewall rules (no syslog server configured) 2026-03-16 13:36:19 +01:00
Jose Martinez 7c56b8a6c4 fix: revert to dynamodb_table for state locking 2026-03-16 13:33:54 +01:00
Jose Martinez 1ca684c20f fix: replace deprecated dynamodb_table with use_lockfile 2026-03-16 13:28:18 +01:00
Jose Martinez 4de8fa62dd fixing the problem with meraki key 2026-03-16 12:05:28 +01:00
Jose Martinez 303e816754 fix: remove vlan_profile_name output from module 2026-03-16 11:36:20 +01:00
Jose MartinezandGitHub Enterprise fffc900cc6 Merge pull request #2 from its-corp/feature/remove-vlan-999-test
test: remove VLAN 999 TEST
2026-03-16 11:33:58 +01:00
Jose Martinez d112d6298d Merge branch 'main' into feature/remove-vlan-999-test 2026-03-16 11:31:20 +01:00
Jose Martinez 0bcf568759 fix: add required_providers to meraki-site module 2026-03-16 11:28:13 +01:00