# Definición de la Organización variable "organization_name" { type = string description = "Nombre exacto de tu organización en el Dashboard de Meraki" } # Definición de la Red variable "network_name" { type = string description = "Nombre de la red (Network)" } # Reglas de firewall L3 variable "firewall_rules" { type = list(object({ comment = string policy = string protocol = string src_cidr = string src_port = string dest_cidr = string dest_port = string syslog_enabled = optional(bool, false) })) default = [] description = "Reglas de firewall L3 para el site. Se aplican en orden, antes de la regla allow-all implícita de Meraki" } # SSIDs wireless variable "wireless_ssids" { type = list(object({ number = number name = string enabled = optional(bool, true) auth_mode = string splash_page = optional(string, "None") wpa_encryption_mode = optional(string, "WPA3 only") ip_assignment_mode = optional(string, "Bridge mode") use_vlan_tagging = optional(bool, false) default_vlan_id = optional(number, null) redirect_url = optional(string, "") radius_servers = optional(list(object({ host = string port = number })), []) })) default = [] description = "Lista de SSIDs wireless a configurar en el site" } # Shared secret para servidores RADIUS (sensible, no incluir en tfvars) variable "radius_secret" { type = string sensitive = true default = "" description = "Shared secret para autenticación RADIUS. Pasar via TF_VAR_radius_secret" } # Definición del mapa de VLANs variable "switch_vlans" { type = map(object({ name = string subnet = string appliance_ip = string dhcp_handling = optional(string, "Run a DHCP server") reserved_ip_ranges = optional(list(object({ comment = string id = string start = string end = string })), []) })) description = "VLANs para el site" validation { condition = alltrue([ for v in values(var.switch_vlans) : contains(["Run a DHCP server", "Relay DHCP to another server", "Do not respond to DHCP requests"], v.dhcp_handling) ]) error_message = "dhcp_handling debe ser uno de: 'Run a DHCP server', 'Relay DHCP to another server', 'Do not respond to DHCP requests'." } }