terraform { required_providers { proxmox = { source = "bpg/proxmox" version = "0.111.1" } } backend "http" { address = "http://10.1.0.104:3000/api/packages/pyrschtjag/terraform/state/runner" lock_address = "http://10.1.0.104:3000/api/packages/pyrschtjag/terraform/state/runner/lock" unlock_address = "http://10.1.0.104:3000/api/packages/pyrschtjag/terraform/state/runner/lock" lock_method = "POST" unlock_method = "DELETE" } } provider "proxmox" { endpoint = "https://10.1.0.4:8006/" username = "root@pam" password = var.proxmox_root_password insecure = true } locals { processed_containers = { for k, v in var.containers : k => { vmid = v.vmid tags = v.tags networks = length(v.networks) > 0 ? [ for net in v.networks : { name = lookup(net, "name", "eth0") bridge = lookup(net, "bridge", "vmbr0") vlan_id = net.vlan_id == null ? (floor(v.vmid / 100) % 100) : net.vlan_id hwaddr = lookup(net, "hwaddr", null) firewall = lookup(net, "firewall", true) } ] : [] ip = v.ip == "" ? null : "10.${floor(v.vmid / 100) % 100}.0.${v.vmid % 100}/24" gw = v.ip == "" ? null : "10.${floor(v.vmid / 100) % 100}.0.1" nameserver = v.ip == "" ? null : "10.${floor(v.vmid / 100) % 100}.0.1" memory = v.memory swap = v.swap cores = v.cores size = v.size started = v.started start_on_boot = v.start_on_boot unprivileged = v.unprivileged features = v.features mount_point = v.mount_point device_passthrough = v.device_passthrough operating_system = v.operating_system } } } resource "proxmox_virtual_environment_container" "all_containers" { for_each = local.processed_containers node_name = "firebat" vm_id = each.value.vmid initialization { hostname = each.key dynamic "ip_config" { for_each = each.value.ip != null ? [1] : [] content { ipv4 { address = each.value.ip gateway = each.value.gw } } } dynamic "dns" { for_each = each.value.nameserver != null ? [1] : [] content { servers = [each.value.nameserver] domain = "lan" } } } cpu { #architecture = "amd64" cores = each.value.cores #limit = 0 } memory { dedicated = each.value.memory swap = each.value.swap } dynamic "network_interface" { for_each = each.value.networks content { name = network_interface.value.name bridge = network_interface.value.bridge vlan_id = network_interface.value.vlan_id mac_address = network_interface.value.hwaddr firewall = network_interface.value.firewall } } disk { datastore_id = "local-zfs" size = each.value.size } features { fuse = each.value.features.fuse keyctl = each.value.features.keyctl mknod = each.value.features.mknod nesting = each.value.features.nesting mount = each.value.features.mount } #console { # enabled = null # tty_count = null # type = null #} dynamic "mount_point" { for_each = each.value.mount_point content { volume = mount_point.value.volume size = mount_point.value.size != null ? "${mount_point.value.size}G" : null path = mount_point.value.path } } dynamic "device_passthrough" { for_each = each.value.device_passthrough content { path = device_passthrough.value.path gid = device_passthrough.value.gid uid = device_passthrough.value.uid mode = device_passthrough.value.mode deny_write = device_passthrough.value.deny_write } } operating_system { type = each.value.operating_system.type template_file_id = each.value.operating_system.template_file_id } unprivileged = each.value.unprivileged started = each.value.started start_on_boot = each.value.start_on_boot tags = each.value.tags } #output "containers_info" { # value = local.processed_containers #}