Files
terraform-infra/Makefile
unkinben 585d32b15c
ci/woodpecker/pr/plan Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/backfill-test Pipeline was successful
Backfill NetBox reality from pdbmux
Automate the PuppetDB reality import (issue #1) by querying pdbmux — the
PuppetDB multiplexer whose HTTPS gateway is reachable from CI/workstations,
unlike raw PuppetDB — instead of PuppetDB directly, and shaping the result to
the NetBox reality side the devices module reconciles.

- Add tools/backfill (Go): query pdbmux /pdb/query/v4/facts for the 13 existing
  physicals and emit per-host reality YAML — serial/model/UUID, every recordable
  interface (real NICs plus overlay/loopback/kube-lb) with MAC and CIDR IPs, and
  CPU/RAM/disk inventory. Filter ephemeral Calico veths and Ceph RBD volumes;
  take interface names from Facter, never assume them.
- Emit deterministic, idempotent, yamllint-clean output into
  config/au/syd1/reality/<host>.yaml, generated for prodnxsr0001-0013.
- Extend modules/infra with a reality variable and reality.tf creating
  netbox_device_interface/netbox_mac_address/netbox_ip_address/
  netbox_inventory_item and device serial; wire reality only for hosts that also
  have an intent device.
- Load reality/*.yaml in the terragrunt env; add `make backfill`; add a
  go vet/test woodpecker job; drop the in-cluster-only Python script.

Closes #1

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-06 23:15:21 +10:00

52 lines
2.0 KiB
Makefile

.PHONY: init plan apply format pre-commit backfill
# Hosts whose hardware reality is backfilled from pdbmux into NetBox. Override to
# add/limit hosts, e.g. `make backfill BACKFILL_HOSTS="prodnxsr0001 prodnxsr0002"`.
BACKFILL_HOSTS ?= prodnxsr0001 prodnxsr0002 prodnxsr0003 prodnxsr0004 prodnxsr0005 \
prodnxsr0006 prodnxsr0007 prodnxsr0008 prodnxsr0009 prodnxsr0010 prodnxsr0011 \
prodnxsr0012 prodnxsr0013
PDBMUX_URL ?= https://pdbmux.k8s.syd1.au.unkin.net/pdb/query/v4/facts
BACKFILL_OUT ?= config/au/syd1/reality
VAULT_AUTH_METHOD ?= approle
VAULT_K8S_ROLE ?= woodpecker_terraform_infra
VAULT_K8S_MOUNT ?= auth/k8s/au/syd1
VAULT_K8S_JWT_PATH ?= /var/run/secrets/kubernetes.io/serviceaccount/token
define vault_env
@export VAULT_ADDR="https://vault.service.consul:8200" && \
if [ "$(VAULT_AUTH_METHOD)" = "kubernetes" ]; then \
export VAULT_TOKEN=$$(vault write -field=token $(VAULT_K8S_MOUNT)/login role=$(VAULT_K8S_ROLE) jwt=$$(cat $(VAULT_K8S_JWT_PATH))); \
else \
export VAULT_TOKEN=$$(vault write -field=token auth/approle/login role_id=$$VAULT_ROLEID); \
fi && \
export CONSUL_HTTP_TOKEN=$$(vault read -field=token consul_root/au/syd1/creds/terraform-infra)
endef
init:
@$(call vault_env) && \
terragrunt run --all --non-interactive init -- -upgrade
plan: init
@$(call vault_env) && \
terragrunt run --all --parallelism 4 --non-interactive plan
apply: init
@$(call vault_env) && \
terragrunt run --all --parallelism 2 --non-interactive apply
format:
@echo "Formatting OpenTofu files..."
@tofu fmt -recursive .
@echo "Formatting Terragrunt files..."
@terragrunt hcl fmt
pre-commit:
@uvx pre-commit run --all-files
# Regenerate NetBox reality YAML from pdbmux. Idempotent with stable ordering,
# so re-running against unchanged facts leaves a clean git diff. Needs network
# reachability to pdbmux (its HTTPS gateway is reachable from CI/workstations).
backfill:
@go -C tools/backfill run . --url "$(PDBMUX_URL)" --out "$(CURDIR)/$(BACKFILL_OUT)" $(BACKFILL_HOSTS)