From 4082c8f57353b4e09ff2aa67f2b9d7d6cb166f7a Mon Sep 17 00:00:00 2001 From: Andrea Dell'Amico Date: Tue, 29 Sep 2026 16:29:22 +0200 Subject: [PATCH] Resources for the dmarc reports service. --- modules/dmarc_reports/dmarc-reports.tf | 133 ++++++++++++++++++ modules/dmarc_reports/outputs.tf | 35 +++++ modules/dmarc_reports/terraform-provider.tf | 10 ++ .../dmarc_reports/variables-dmarc-reports.tf | 96 +++++++++++++ s2i2s/dmarc-reports/README.md | 57 ++++++++ s2i2s/dmarc-reports/main.tf | 80 +++++++++++ s2i2s/dmarc-reports/outputs.tf | 39 +++++ s2i2s/dmarc-reports/provider.tf | 14 ++ s2i2s/dmarc-reports/terraform.tfstate | 1 + 9 files changed, 465 insertions(+) create mode 100644 modules/dmarc_reports/dmarc-reports.tf create mode 100644 modules/dmarc_reports/outputs.tf create mode 100644 modules/dmarc_reports/terraform-provider.tf create mode 100644 modules/dmarc_reports/variables-dmarc-reports.tf create mode 100644 s2i2s/dmarc-reports/README.md create mode 100644 s2i2s/dmarc-reports/main.tf create mode 100644 s2i2s/dmarc-reports/outputs.tf create mode 100644 s2i2s/dmarc-reports/provider.tf create mode 100644 s2i2s/dmarc-reports/terraform.tfstate diff --git a/modules/dmarc_reports/dmarc-reports.tf b/modules/dmarc_reports/dmarc-reports.tf new file mode 100644 index 0000000..848dbb1 --- /dev/null +++ b/modules/dmarc_reports/dmarc-reports.tf @@ -0,0 +1,133 @@ +# +# DMARC reports service: parsedmarc reads the aggregate and forensic reports +# from the IMAP mailbox, OpenSearch stores them, OpenSearch Dashboards shows +# them. All three on one VM. +# +# One interface, on the main private network: the L7 load balancers reach +# Dashboards there, and the VM reaches the IMAP server through the router of +# the project. No floating IP. +# + +locals { + # One rule per (load balancer, service port) pair + dmarc_reports_service_rules = { + for pair in setproduct(var.haproxy_l7_ip, var.dmarc_reports_data.service_ports) : + "${pair[0]}-${pair[1]}" => { address = pair[0], port = pair[1] } + } +} + +# +# Traffic from the main L7 load balancers +# +resource "openstack_networking_secgroup_v2" "traffic_to_dmarc_reports" { + name = "traffic_to_dmarc_reports_from_the_main_load_balancers" + delete_default_rules = "true" + description = "Traffic from the main L7 HAPROXY load balancers to OpenSearch Dashboards" +} + +resource "openstack_networking_secgroup_rule_v2" "haproxy_to_dmarc_reports" { + for_each = local.dmarc_reports_service_rules + security_group_id = openstack_networking_secgroup_v2.traffic_to_dmarc_reports.id + description = "Traffic from the HAPROXY L7 ${each.value.address} to the port ${each.value.port}" + direction = "ingress" + ethertype = "IPv4" + protocol = "tcp" + port_range_min = each.value.port + port_range_max = each.value.port + remote_ip_prefix = "${each.value.address}/32" +} + +# +# Data volume: the OpenSearch indexes. Online resize enabled, like every other +# additional volume of the project +# +resource "openstack_blockstorage_volume_v3" "dmarc_reports_data_vol" { + name = var.dmarc_reports_data.vol_data_name + description = "OpenSearch data directory of the DMARC reports service" + size = var.dmarc_reports_data.vol_data_size + volume_type = var.dmarc_reports_data.volume_type + enable_online_resize = true +} + +# +# Port, declared outside the instance +# +resource "openstack_networking_port_v2" "dmarc_reports_main_port" { + name = "${var.dmarc_reports_data.name}-main-port" + description = "Port of the DMARC reports service on the main private network" + admin_state_up = true + network_id = var.main_private_network_id + security_group_ids = [ + var.default_security_group_id, + openstack_networking_secgroup_v2.traffic_to_dmarc_reports.id, + ] + fixed_ip { + subnet_id = var.main_private_subnet_id + ip_address = var.dmarc_reports_main_ip + } +} + +# +# Instance +# +resource "openstack_compute_instance_v2" "dmarc_reports" { + name = var.dmarc_reports_data.name + availability_zone_hints = var.availability_zone + flavor_name = var.dmarc_reports_data.flavor + key_pair = var.ssh_key_name + + block_device { + uuid = var.image.uuid + source_type = "image" + volume_size = var.dmarc_reports_data.boot_vol_size + boot_index = 0 + destination_type = "volume" + delete_on_termination = false + } + + network { + port = openstack_networking_port_v2.dmarc_reports_main_port.id + } + + user_data = file(var.image.user_data_file) + + # Do not replace the instance when the ssh key or the user data change + lifecycle { + ignore_changes = [ + key_pair, user_data, network + ] + } +} + +resource "openstack_compute_volume_attach_v2" "dmarc_reports_data_attach" { + instance_id = openstack_compute_instance_v2.dmarc_reports.id + volume_id = openstack_blockstorage_volume_v3.dmarc_reports_data_vol.id + device = var.dmarc_reports_data.vol_data_device +} + +# +# A record on the main network address, so that the name can be used by the +# playbooks and by the load balancer configuration +# +resource "openstack_dns_recordset_v2" "dmarc_reports_recordset" { + zone_id = var.dns_zone_id + name = "${var.dmarc_reports_data.name}.${var.dns_zone_name}" + description = "Address of the DMARC reports service on the main private network" + ttl = 8600 + type = "A" + records = [var.dmarc_reports_main_ip] +} + +# +# Public name of the service, a CNAME of the main load balancer that publishes +# it +# +resource "openstack_dns_recordset_v2" "dmarc_reports_public_recordset" { + count = length(var.dmarc_reports_public_name) > 0 ? 1 : 0 + zone_id = var.dns_zone_id + name = "${var.dmarc_reports_public_name}.${var.dns_zone_name}" + description = "DMARC reports, published by the main load balancer" + ttl = 8600 + type = "CNAME" + records = [var.dmarc_reports_cname_target] +} diff --git a/modules/dmarc_reports/outputs.tf b/modules/dmarc_reports/outputs.tf new file mode 100644 index 0000000..c33d0d3 --- /dev/null +++ b/modules/dmarc_reports/outputs.tf @@ -0,0 +1,35 @@ +output "dmarc_reports_data" { + description = "The input data, re-exported for the dependent workspaces" + value = var.dmarc_reports_data +} + +output "dmarc_reports_instance_id" { + value = openstack_compute_instance_v2.dmarc_reports.id +} + +output "dmarc_reports_server_name" { + value = openstack_compute_instance_v2.dmarc_reports.name +} + +output "dmarc_reports_main_ip" { + description = "Address on the main private network, used by the ansible inventory" + value = var.dmarc_reports_main_ip +} + +output "dmarc_reports_data_volume_id" { + value = openstack_blockstorage_volume_v3.dmarc_reports_data_vol.id +} + +output "traffic_to_dmarc_reports_security_group_id" { + value = openstack_networking_secgroup_v2.traffic_to_dmarc_reports.id +} + +output "dmarc_reports_hostname" { + description = "Internal name, on the main private network address" + value = openstack_dns_recordset_v2.dmarc_reports_recordset.name +} + +output "dmarc_reports_public_hostname" { + description = "Public name, a CNAME of the main load balancer" + value = length(var.dmarc_reports_public_name) > 0 ? openstack_dns_recordset_v2.dmarc_reports_public_recordset[0].name : "" +} diff --git a/modules/dmarc_reports/terraform-provider.tf b/modules/dmarc_reports/terraform-provider.tf new file mode 100644 index 0000000..31f07e2 --- /dev/null +++ b/modules/dmarc_reports/terraform-provider.tf @@ -0,0 +1,10 @@ +# Define required providers +terraform { + required_version = ">= 0.14.0" + required_providers { + openstack = { + source = "terraform-provider-openstack/openstack" + version = ">= 2.0.0" + } + } +} diff --git a/modules/dmarc_reports/variables-dmarc-reports.tf b/modules/dmarc_reports/variables-dmarc-reports.tf new file mode 100644 index 0000000..b58fb5d --- /dev/null +++ b/modules/dmarc_reports/variables-dmarc-reports.tf @@ -0,0 +1,96 @@ +# +# DMARC reports service: parsedmarc, OpenSearch and OpenSearch Dashboards on +# one VM. +# +# Sizing and service ports belong to the service, so they have defaults here. +# The address on the main private network does not: it is part of the address +# plan of the project, and it is passed in by the caller. +# + +variable "dmarc_reports_data" { + description = "Instance, volume and ports of the DMARC reports service. m1.large is RAM 8 - VCPUs 4" + type = object({ + name = optional(string, "opensearch-dmarc") + description = optional(string, "DMARC reports: parsedmarc, OpenSearch and OpenSearch Dashboards") + flavor = optional(string, "m1.large") + boot_vol_size = optional(number, 20) + # OpenSearch data directory. SSD, as every volume that holds an index + vol_data_name = optional(string, "opensearch-dmarc-data") + vol_data_size = optional(number, 50) + vol_data_device = optional(string, "/dev/vdb") + volume_type = optional(string, "CephSSD") + # OpenSearch Dashboards, the only port the load balancers reach. It + # terminates TLS itself with the certificate of the internal CA + service_ports = optional(list(number), [5601]) + }) + default = {} +} + +# Part of the address plan of the project: no default on purpose +variable "dmarc_reports_main_ip" { + type = string + description = "Address of the instance on the main private network" +} + +# Data that comes from the network/DNS and project setup workspaces +variable "main_private_network_id" { + type = string + description = "ID of the main private network of the project" +} + +variable "main_private_subnet_id" { + type = string + description = "ID of the main private subnet of the project" +} + +variable "default_security_group_id" { + type = string + description = "ID of the 'default_for_all' security group of the project" +} + +variable "haproxy_l7_ip" { + type = list(string) + description = "Addresses of the L7 HAPROXY load balancers, the only ones allowed to reach the service" +} + +variable "availability_zone" { + type = string + description = "Availability zone hint of the instance" +} + +variable "image" { + description = "Image of the instance: uuid and cloud-init user data file" + type = object({ + uuid = string + user_data_file = string + }) +} + +variable "ssh_key_name" { + type = string + description = "Name of the SSH key pair injected by cloud-init" +} + +# DNS. The A record on the main network address is always created; the public +# name is a CNAME of the load balancer that publishes the service +variable "dns_zone_id" { + type = string + description = "ID of the DNS zone of the project" +} + +variable "dns_zone_name" { + type = string + description = "Name of the DNS zone of the project, with the trailing dot" +} + +variable "dmarc_reports_public_name" { + type = string + default = "dmarc" + description = "Left part of the public name, a CNAME of the load balancer. Empty means no record" +} + +variable "dmarc_reports_cname_target" { + type = string + default = "" + description = "Target of the CNAME, usually the name of the main load balancer, with the trailing dot" +} diff --git a/s2i2s/dmarc-reports/README.md b/s2i2s/dmarc-reports/README.md new file mode 100644 index 0000000..73f6107 --- /dev/null +++ b/s2i2s/dmarc-reports/README.md @@ -0,0 +1,57 @@ +# DMARC reports service of the S2I2S project + +One VM, `m1.large` (RAM 8 - VCPUs 4), Ubuntu 24.04, 20 GB of root disk, on the +main private network only (`10.10.0.166`), and **one 50 GB SSD volume** +(`CephSSD`, `enable_online_resize`) on `/dev/vdb`, for the OpenSearch indexes. + +It runs parsedmarc, OpenSearch and OpenSearch Dashboards. parsedmarc reads the +aggregate and failure reports sent to `dmarc-reports@isti.cnr.it` (the `rua` +and `ruf` of `_dmarc.isti.cnr.it`) over IMAP, through the router of the +project: no floating IP. + +The resources live in [`../../modules/dmarc_reports`](../../modules/dmarc_reports), +which carries the sizing and the service port as defaults. Only the address on +the main private network, from the address plan in [`../variables`](../variables) +(`basic_services_ip.dmarc_reports`), and the IDs read from the other +workspaces are set in `main.tf`. + +Security groups on the port: + +* `default_for_all`; +* `traffic_to_dmarc_reports_from_the_main_load_balancers`: **5601** + (OpenSearch Dashboards, TLS with the certificate of the internal CA) from + each L7 load balancer. + +OpenSearch itself (9200) is not reachable from outside the VM. The Grafana +server that will read the indexes (`public_grafana_server_cidr` in +`../variables`) is a separate activity: it will need either a rule here or a +service on the load balancers. + +## Names + +| Name | Type | +|---|---| +| `opensearch-dmarc.s2i2s.cloud.isti.cnr.it` | A → `10.10.0.166`, used by the playbooks and by the load balancer | +| `dmarc.s2i2s.cloud.isti.cnr.it` | CNAME → `main-lb.s2i2s.cloud.isti.cnr.it.` | + +The public name is served by the L7 load balancers: the `dmarc_reports` entry +of `haproxy_l7_services` in `group_vars/main_haproxy_l7/main_haproxy_l7.yml` of +`infrastructure-playbooks`. + +## Order of the applies + +``` +main_net_dns_router -> project-setup -> dmarc-reports +``` + +```bash +tofu init +tofu plan -out=dmarc-reports.plan +tofu apply dmarc-reports.plan +``` + +Then regenerate the ansible inventory in `infrastructure-playbooks`: + +```bash +ansible-playbook tofu-inventory.yml --diff +``` diff --git a/s2i2s/dmarc-reports/main.tf b/s2i2s/dmarc-reports/main.tf new file mode 100644 index 0000000..9ba8ebd --- /dev/null +++ b/s2i2s/dmarc-reports/main.tf @@ -0,0 +1,80 @@ +# DMARC reports service of the S2I2S OpenStack project: parsedmarc, OpenSearch +# and OpenSearch Dashboards on one VM. +# +# The resources are in ../../modules/dmarc_reports, which also carries the +# sizing (m1.large: RAM 8 - VCPUs 4, 50 GB of SSD for the indexes) and the +# service port. Only what belongs to this project is set here: the address on +# the main private network, taken from the address plan in ../variables, and the +# IDs that come from the other workspaces. +# +# Apply order: main_net_dns_router -> project-setup -> this one. + +data "terraform_remote_state" "privnet_dns_router" { + backend = "local" + config = { + path = "../main_net_dns_router/terraform.tfstate" + } +} + +data "terraform_remote_state" "project_setup" { + backend = "local" + config = { + path = "../project-setup/terraform.tfstate" + } +} + +module "labs_common_variables" { + source = "../../modules/labs_common_variables" +} + +module "project_variables" { + source = "../variables" +} + +module "ssh_settings" { + source = "../../modules/ssh-key-ref" +} + +locals { + # From the network/DNS state + dns_zone = data.terraform_remote_state.privnet_dns_router.outputs.dns_zone + dns_zone_id = data.terraform_remote_state.privnet_dns_router.outputs.dns_zone_id + main_private_network_id = data.terraform_remote_state.privnet_dns_router.outputs.main_private_network_id + main_private_subnet_id = data.terraform_remote_state.privnet_dns_router.outputs.main_subnet_network_id + + # From the project setup state + default_security_group_id = data.terraform_remote_state.project_setup.outputs.default_security_group_id + main_haproxy_l7_ip = data.terraform_remote_state.project_setup.outputs.main_haproxy_l7_ip + main_loadbalancer_name = data.terraform_remote_state.project_setup.outputs.main_loadbalancer_hostname + + # From the common and project variables + availability_zone = module.labs_common_variables.availability_zones_names.availability_zone_no_gpu + ubuntu_2404 = module.labs_common_variables.ubuntu_2404 + ubuntu2404_data_file = module.labs_common_variables.ubuntu2404_data_file + basic_services_ip = module.project_variables.basic_services_ip +} + +module "dmarc_reports" { + source = "../../modules/dmarc_reports" + + # Address plan of the project. The sizing comes from the module defaults + dmarc_reports_main_ip = local.basic_services_ip.dmarc_reports + + main_private_network_id = local.main_private_network_id + main_private_subnet_id = local.main_private_subnet_id + default_security_group_id = local.default_security_group_id + haproxy_l7_ip = local.main_haproxy_l7_ip + + availability_zone = local.availability_zone + image = { + uuid = local.ubuntu_2404.uuid + user_data_file = local.ubuntu2404_data_file + } + ssh_key_name = module.ssh_settings.ssh_key_name + + # dmarc.s2i2s.cloud.isti.cnr.it, a CNAME of the main load balancer + dns_zone_id = local.dns_zone_id + dns_zone_name = local.dns_zone.name + dmarc_reports_public_name = "dmarc" + dmarc_reports_cname_target = local.main_loadbalancer_name +} diff --git a/s2i2s/dmarc-reports/outputs.tf b/s2i2s/dmarc-reports/outputs.tf new file mode 100644 index 0000000..6246a96 --- /dev/null +++ b/s2i2s/dmarc-reports/outputs.tf @@ -0,0 +1,39 @@ +output "dmarc_reports_instance_id" { + value = module.dmarc_reports.dmarc_reports_instance_id +} + +output "dmarc_reports_server_name" { + value = module.dmarc_reports.dmarc_reports_server_name +} + +output "dmarc_reports_server_data" { + value = module.dmarc_reports.dmarc_reports_data +} + +output "dmarc_reports_main_ip" { + description = "Address on the main private network. Used by the ansible inventory" + value = module.dmarc_reports.dmarc_reports_main_ip +} + +output "dmarc_reports_data_volume_id" { + value = module.dmarc_reports.dmarc_reports_data_volume_id +} + +output "traffic_to_dmarc_reports_security_group_id" { + value = module.dmarc_reports.traffic_to_dmarc_reports_security_group_id +} + +output "dmarc_reports_hostname" { + description = "Internal name, on the main private network address" + value = module.dmarc_reports.dmarc_reports_hostname +} + +output "dmarc_reports_public_hostname" { + description = "Public name, a CNAME of the main load balancer" + value = module.dmarc_reports.dmarc_reports_public_hostname +} + +# Re-exported for the ansible inventory generator +output "dns_zone" { + value = local.dns_zone +} diff --git a/s2i2s/dmarc-reports/provider.tf b/s2i2s/dmarc-reports/provider.tf new file mode 100644 index 0000000..a890a41 --- /dev/null +++ b/s2i2s/dmarc-reports/provider.tf @@ -0,0 +1,14 @@ +# Define required providers +terraform { + required_version = ">= 0.14.0" + required_providers { + openstack = { + source = "terraform-provider-openstack/openstack" + version = ">= 2.0.0" + } + } +} + +provider "openstack" { + cloud = "s2i2s" +} diff --git a/s2i2s/dmarc-reports/terraform.tfstate b/s2i2s/dmarc-reports/terraform.tfstate new file mode 100644 index 0000000..6491eb6 --- /dev/null +++ b/s2i2s/dmarc-reports/terraform.tfstate @@ -0,0 +1 @@ +{"version":4,"terraform_version":"1.11.6","serial":3,"lineage":"715bc9a2-81e1-fc1d-cffe-c3c402b195cc","outputs":{"dmarc_reports_data_volume_id":{"value":"e0fd9dc1-3dc4-4f8d-8ec7-b42ada09f40b","type":"string"},"dmarc_reports_hostname":{"value":"opensearch-dmarc.s2i2s.cloud.isti.cnr.it.","type":"string"},"dmarc_reports_instance_id":{"value":"4e9298b9-575f-408f-a551-d295783b6939","type":"string"},"dmarc_reports_main_ip":{"value":"10.10.0.166","type":"string"},"dmarc_reports_public_hostname":{"value":"dmarc.s2i2s.cloud.isti.cnr.it.","type":"string"},"dmarc_reports_server_data":{"value":{"boot_vol_size":20,"description":"DMARC reports: parsedmarc, OpenSearch and OpenSearch Dashboards","flavor":"m1.large","name":"opensearch-dmarc","service_ports":[5601],"vol_data_device":"/dev/vdb","vol_data_name":"opensearch-dmarc-data","vol_data_size":50,"volume_type":"CephSSD"},"type":["object",{"boot_vol_size":"number","description":"string","flavor":"string","name":"string","service_ports":["list","number"],"vol_data_device":"string","vol_data_name":"string","vol_data_size":"number","volume_type":"string"}]},"dmarc_reports_server_name":{"value":"opensearch-dmarc","type":"string"},"dns_zone":{"value":{"attributes":{},"description":"DNS primary zone for the S2I2S project","disable_status_check":false,"email":"postmaster@isti.cnr.it","id":"e826e777-0196-4f63-b2a9-df07f70e618f","masters":[],"name":"s2i2s.cloud.isti.cnr.it.","project_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","region":"isti_area_pi_1","timeouts":null,"ttl":8600,"type":"PRIMARY","value_specs":null},"type":["object",{"attributes":["map","string"],"description":"string","disable_status_check":"bool","email":"string","id":"string","masters":["set","string"],"name":"string","project_id":"string","region":"string","timeouts":["object",{"create":"string","delete":"string","update":"string"}],"ttl":"number","type":"string","value_specs":["map","string"]}]},"traffic_to_dmarc_reports_security_group_id":{"value":"54ebcf6d-8218-4721-82e3-1a12afeba6d0","type":"string"}},"resources":[{"mode":"data","type":"terraform_remote_state","name":"privnet_dns_router","provider":"provider[\"terraform.io/builtin/terraform\"]","instances":[{"schema_version":0,"attributes":{"backend":"local","config":{"value":{"path":"../main_net_dns_router/terraform.tfstate"},"type":["object",{"path":"string"}]},"defaults":null,"outputs":{"value":{"almalinux_9":{"name":"AlmaLinux-9.8 20260526","user_data_file":"../../s2i2s_openstack_vm_data_scripts/almalinux9.sh","uuid":"172f1c52-fa06-4d7d-9db7-0735ab6ef403"},"availability_zone_no_gpu_name":"cnr-isti-nova-a","availability_zone_with_gpu_name":"cnr-isti-nova-gpu-a","availability_zones_names":{"availability_zone_no_gpu":"cnr-isti-nova-a","availability_zone_with_gpu":"cnr-isti-nova-gpu-a"},"centos_7":{"name":"CentOS-7","user_data_file":"../../s2i2s_openstack_vm_data_scripts/el.sh","uuid":"f0187a99-64f6-462a-ab5f-ef52fe62f2ca"},"default_security_group_name":"default_for_all","dns_zone":{"attributes":{},"description":"DNS primary zone for the S2I2S project","disable_status_check":false,"email":"postmaster@isti.cnr.it","id":"e826e777-0196-4f63-b2a9-df07f70e618f","masters":[],"name":"s2i2s.cloud.isti.cnr.it.","project_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","region":"isti_area_pi_1","timeouts":null,"ttl":8600,"type":"PRIMARY","value_specs":null},"dns_zone_id":"e826e777-0196-4f63-b2a9-df07f70e618f","el7_data_file":"../../s2i2s_openstack_vm_data_scripts/el.sh","external_gateway_ip":[{"ip_address":"146.48.30.6","subnet_id":"57f87509-4016-46fb-b8c3-25fca7f72ccb"}],"external_network":{"id":"1d2ff137-6ff7-4017-be2b-0d6c4af2353b","name":"external-network"},"external_network_id":"1d2ff137-6ff7-4017-be2b-0d6c4af2353b","flavor_list":{"c1_large":"c1.large","c1_medium":"c1.medium","c1_small":"c1.small","c2_large":"c2.large","m1_large":"m1.large","m1_medium":"m1.medium","m1_xlarge":"m1.xlarge","m1_xxl":"m1.xxl","m2_large":"m2.large","m2_medium":"m2.medium","m2_small":"m2.small","m3_large":"m3.large"},"floating_ip_pools":{"main_public_ip_pool":"external-network"},"main_private_network":{"admin_state_up":true,"all_tags":[],"availability_zone_hints":[],"description":"S2I2S private network (use this as the main network)","dns_domain":"s2i2s.cloud.isti.cnr.it.","external":false,"id":"f371c239-6d5d-4ac8-a17e-af607752d82c","mtu":8942,"name":"s2i2s-proj-main","port_security_enabled":true,"qos_policy_id":"","region":"isti_area_pi_1","segments":[{"network_type":"geneve","physical_network":"","segmentation_id":47850}],"shared":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null,"transparent_vlan":false,"value_specs":null},"main_private_network_id":"f371c239-6d5d-4ac8-a17e-af607752d82c","main_region":"isti_area_pi_1","main_subnet_network":{"all_tags":[],"allocation_pool":[{"end":"10.10.7.254","start":"10.10.1.1"}],"cidr":"10.10.0.0/21","description":"S2I2S main private subnet","dns_nameservers":["146.48.29.97","146.48.29.98","146.48.29.99"],"dns_publish_fixed_ip":false,"enable_dhcp":true,"gateway_ip":"10.10.0.1","id":"19c649ee-96ea-438b-ac0c-512afdf5046d","ip_version":4,"ipv6_address_mode":"","ipv6_ra_mode":"","name":"s2i2s-proj-main-subnet","network_id":"f371c239-6d5d-4ac8-a17e-af607752d82c","no_gateway":false,"prefix_length":null,"region":"isti_area_pi_1","segment_id":"","service_types":[],"subnetpool_id":"","tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null,"value_specs":null},"main_subnet_network_id":"19c649ee-96ea-438b-ac0c-512afdf5046d","mtu_size":8942,"os_project_data":{"id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","name":"s2i2s-proj-cloud"},"policy_list":{"affinity":"affinity","anti_affinity":"anti-affinity","soft_affinity":"soft-affinity","soft_anti_affinity":"soft-anti-affinity"},"resolvers_ip":["146.48.29.97","146.48.29.98","146.48.29.99"],"ssh_sources":{"d4s_vpn_1_cidr":"146.48.122.27/32","d4s_vpn_2_cidr":"146.48.122.49/32","infrascience_net_cidr":"146.48.122.0/23","isti_net_cidr":"146.48.80.0/21","isti_vpn_gw1":"146.48.80.101/32","isti_vpn_gw2":"146.48.80.102/32","isti_vpn_gw3":"146.48.80.103/32","s2i2s_net_cidr":"146.48.28.0/22","s2i2s_vpn_1_cidr":"146.48.28.10/32","s2i2s_vpn_2_cidr":"146.48.28.11/32","shell_d4s_cidr":"146.48.122.95/32"},"ubuntu2204_data_file":"../../s2i2s_openstack_vm_data_scripts/ubuntu2204.sh","ubuntu_2204":{"name":"Ubuntu-Jammy-22.04","user_data_file":"../../s2i2s_openstack_vm_data_scripts/ubuntu2204.sh","uuid":"54768889-8556-4be4-a2eb-82a4d9b34627"}},"type":["object",{"almalinux_9":["map","string"],"availability_zone_no_gpu_name":"string","availability_zone_with_gpu_name":"string","availability_zones_names":["map","string"],"centos_7":["map","string"],"default_security_group_name":"string","dns_zone":["object",{"attributes":["map","string"],"description":"string","disable_status_check":"bool","email":"string","id":"string","masters":["set","string"],"name":"string","project_id":"string","region":"string","timeouts":["object",{"create":"string","delete":"string","update":"string"}],"ttl":"number","type":"string","value_specs":["map","string"]}],"dns_zone_id":"string","el7_data_file":"string","external_gateway_ip":["list",["object",{"ip_address":"string","subnet_id":"string"}]],"external_network":["map","string"],"external_network_id":"string","flavor_list":["map","string"],"floating_ip_pools":["map","string"],"main_private_network":["object",{"admin_state_up":"bool","all_tags":["set","string"],"availability_zone_hints":["set","string"],"description":"string","dns_domain":"string","external":"bool","id":"string","mtu":"number","name":"string","port_security_enabled":"bool","qos_policy_id":"string","region":"string","segments":["set",["object",{"network_type":"string","physical_network":"string","segmentation_id":"number"}]],"shared":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"create":"string","delete":"string"}],"transparent_vlan":"bool","value_specs":["map","string"]}],"main_private_network_id":"string","main_region":"string","main_subnet_network":["object",{"all_tags":["set","string"],"allocation_pool":["set",["object",{"end":"string","start":"string"}]],"cidr":"string","description":"string","dns_nameservers":["list","string"],"dns_publish_fixed_ip":"bool","enable_dhcp":"bool","gateway_ip":"string","id":"string","ip_version":"number","ipv6_address_mode":"string","ipv6_ra_mode":"string","name":"string","network_id":"string","no_gateway":"bool","prefix_length":"number","region":"string","segment_id":"string","service_types":["list","string"],"subnetpool_id":"string","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"create":"string","delete":"string"}],"value_specs":["map","string"]}],"main_subnet_network_id":"string","mtu_size":"number","os_project_data":["map","string"],"policy_list":["map","string"],"resolvers_ip":["list","string"],"ssh_sources":["map","string"],"ubuntu2204_data_file":"string","ubuntu_2204":["map","string"]}]},"workspace":null},"sensitive_attributes":[]}]},{"mode":"data","type":"terraform_remote_state","name":"project_setup","provider":"provider[\"terraform.io/builtin/terraform\"]","instances":[{"schema_version":0,"attributes":{"backend":"local","config":{"value":{"path":"../project-setup/terraform.tfstate"},"type":["object",{"path":"string"}]},"defaults":null,"outputs":{"value":{"access_to_the_jump_proxy":{"all_tags":[],"delete_default_rules":true,"description":"Security group that allows SSH access to the jump node from a limited set of sources","id":"4c6b6683-77fa-4d1a-8ba2-41acf10a12ba","name":"ssh_access_to_the_jump_node","region":"isti_area_pi_1","stateful":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"acme_challenge_hostname":"_acme-challenge.s2i2s.cloud.isti.cnr.it.","availability_zones_names":{"availability_zone_no_gpu":"cnr-isti-nova-a","availability_zone_with_gpu":"cnr-isti-nova-gpu-a"},"basic_services_ip":{"ca":"10.10.0.4","ca_cidr":"10.10.0.4/32","forgejo":"10.10.0.165","forgejo_cidr":"10.10.0.165/32","haproxy_l7_1":"10.10.0.11","haproxy_l7_1_cidr":"10.10.0.11/32","haproxy_l7_2":"10.10.0.12","haproxy_l7_2_cidr":"10.10.0.12/32","keycloak_1":"10.10.0.163","keycloak_1_cidr":"10.10.0.163/32","keycloak_2":"10.10.0.164","keycloak_2_cidr":"10.10.0.164/32","octavia_main":"10.10.0.20","octavia_main_cidr":"10.10.0.20/32","postgresql":"10.10.0.162","postgresql_cidr":"10.10.0.162/32","prometheus":"10.10.0.10","prometheus_cidr":"10.10.0.10/32","ssh_jump":"10.10.0.5","ssh_jump_cidr":"10.10.0.5/32"},"debugging":{"all_tags":[],"delete_default_rules":true,"description":"Security group that allows web app debugging via tunnel from the ssh jump node","id":"6c21f51b-9cad-4051-99b6-221bed658a83","name":"debugging_from_jump_node","region":"isti_area_pi_1","stateful":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"default_security_group":{"all_tags":[],"delete_default_rules":true,"description":"Default security group with rules for ssh access via jump proxy, prometheus scraping","id":"1ec8a419-f9cf-473f-a022-6499d67d57b8","name":"default_for_all","region":"isti_area_pi_1","stateful":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"default_security_group_id":"1ec8a419-f9cf-473f-a022-6499d67d57b8","default_security_group_name":"default_for_all","dns_zone":{"attributes":{},"description":"DNS primary zone for the S2I2S project","disable_status_check":false,"email":"postmaster@isti.cnr.it","id":"e826e777-0196-4f63-b2a9-df07f70e618f","masters":[],"name":"s2i2s.cloud.isti.cnr.it.","project_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","region":"isti_area_pi_1","timeouts":null,"ttl":8600,"type":"PRIMARY","value_specs":null},"dns_zone_id":"e826e777-0196-4f63-b2a9-df07f70e618f","floating_ip_pools":{"main_public_ip_pool":"external-network"},"haproxy_l7_data":{"flavor":"m1.medium","name":"main-haproxy-l7","vm_count":"2"},"internal_ca_data":{"flavor":"m1.small","name":"ca"},"internal_ca_id":"286b7a4d-33c6-451f-9019-d9fd79265181","main_haproxy_l7_ids":["b42a0e99-6172-4a5d-886c-c0fb016da60e","b770644a-5c39-4db2-8811-fb62751bd789"],"main_haproxy_l7_ip":["10.10.0.11","10.10.0.12"],"main_lb_to_haproxy_l7_security_group":{"all_tags":[],"delete_default_rules":true,"description":"Traffic coming from the main L4 lb (OVN provider, client IP is preserved) directed to the haproxy l7 servers","id":"613cacac-ac46-46ab-ba7a-d66f61cce84d","name":"traffic_from_main_lb_to_haproxy_l7","region":"isti_area_pi_1","stateful":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"main_loadbalancer_hostname":"main-lb.s2i2s.cloud.isti.cnr.it.","main_loadbalancer_id":"44dbe548-a436-4816-927a-2912f443b50f","main_loadbalancer_ip":"10.10.0.20","main_loadbalancer_public_ip":"146.48.30.30","main_private_network":{"admin_state_up":true,"all_tags":[],"availability_zone_hints":[],"description":"S2I2S private network (use this as the main network)","dns_domain":"s2i2s.cloud.isti.cnr.it.","external":false,"id":"f371c239-6d5d-4ac8-a17e-af607752d82c","mtu":8942,"name":"s2i2s-proj-main","port_security_enabled":true,"qos_policy_id":"","region":"isti_area_pi_1","segments":[{"network_type":"geneve","physical_network":"","segmentation_id":47850}],"shared":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null,"transparent_vlan":false,"value_specs":null},"main_private_subnet":{"all_tags":[],"allocation_pool":[{"end":"10.10.7.254","start":"10.10.1.1"}],"cidr":"10.10.0.0/21","description":"S2I2S main private subnet","dns_nameservers":["146.48.29.97","146.48.29.98","146.48.29.99"],"dns_publish_fixed_ip":false,"enable_dhcp":true,"gateway_ip":"10.10.0.1","id":"19c649ee-96ea-438b-ac0c-512afdf5046d","ip_version":4,"ipv6_address_mode":"","ipv6_ra_mode":"","name":"s2i2s-proj-main-subnet","network_id":"f371c239-6d5d-4ac8-a17e-af607752d82c","no_gateway":false,"prefix_length":null,"region":"isti_area_pi_1","segment_id":"","service_types":[],"subnetpool_id":"","tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null,"value_specs":null},"main_region":"isti_area_pi_1","main_subnet_network_id":"19c649ee-96ea-438b-ac0c-512afdf5046d","mtu_size":8942,"os_project_data":{"id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","name":"s2i2s-proj-cloud"},"prometheus_access_from_grafana":{"all_tags":[],"delete_default_rules":true,"description":"The public grafana server must be able to get data from Prometheus","id":"48e9366f-23a8-47df-abcd-66f84d4af395","name":"prometheus_access_from_grafana","region":"isti_area_pi_1","stateful":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"prometheus_hostname":"prometheus.s2i2s.cloud.isti.cnr.it.","prometheus_public_ip":"146.48.31.67","prometheus_server_data":{"flavor":"m1.medium","name":"prometheus","public_grafana_server_cidr":"146.48.28.103/32","vol_data_device":"/dev/vdb","vol_data_name":"prometheus-data","vol_data_size":"100"},"prometheus_server_id":"d2a37e7c-3eaa-4929-b70d-cfb55416d8bc","public_web":{"all_tags":[],"delete_default_rules":true,"description":"Security group that allows HTTPS and HTTP from everywhere, for the services that are not behind any load balancer","id":"31140e64-667a-4044-b388-79afcc6bcb69","name":"public_web_service","region":"isti_area_pi_1","stateful":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"resolvers_ip":["146.48.29.97","146.48.29.98","146.48.29.99"],"restricted_web":{"all_tags":[],"delete_default_rules":true,"description":"Security group that restricts HTTPS sources to the VPN nodes and shell.d4science.org. HTTP is open to all, because letsencrypt","id":"359d7ae7-cdff-47c2-bf69-7d423860d2d2","name":"restricted_web_service","region":"isti_area_pi_1","stateful":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"ssh_jump_proxy":{"flavor":"m2.small","name":"ssh-jump-proxy"},"ssh_jump_proxy_hostname":"ssh-jump-proxy.s2i2s.cloud.isti.cnr.it.","ssh_jump_proxy_id":"6aed1634-ec4e-43b0-a8c6-2da42a27ad25","ssh_jump_proxy_public_ip":"146.48.31.105","ssh_sources":{"d4s_vpn_1_cidr":"146.48.122.27/32","d4s_vpn_2_cidr":"146.48.122.49/32","infrascience_net_cidr":"146.48.122.0/23","isti_net_cidr":"146.48.80.0/21","isti_vpn_gw1":"146.48.80.101/32","isti_vpn_gw2":"146.48.80.102/32","isti_vpn_gw3":"146.48.80.103/32","s2i2s_net_cidr":"146.48.28.0/22","s2i2s_vpn_1_cidr":"146.48.28.10/32","s2i2s_vpn_2_cidr":"146.48.28.11/32","shell_d4s_cidr":"146.48.122.95/32"},"traffic_from_main_haproxy":{"all_tags":[],"delete_default_rules":true,"description":"Allow traffic from the main L7 HAPROXY load balancers","id":"56ba7585-659a-49ac-8d8e-c85ebcb1179f","name":"traffic_from_the_main_load_balancers","region":"isti_area_pi_1","stateful":false,"tags":[],"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"ubuntu2204_data_file":"../../s2i2s_openstack_vm_data_scripts/ubuntu2204.sh","ubuntu2404_data_file":"../../s2i2s_openstack_vm_data_scripts/ubuntu2404.sh","ubuntu_2204":{"name":"Ubuntu-Jammy-22.04","user_data_file":"../../s2i2s_openstack_vm_data_scripts/ubuntu2204.sh","uuid":"54768889-8556-4be4-a2eb-82a4d9b34627"},"ubuntu_2404":{"name":"Ubuntu-Noble-24.04.img","user_data_file":"../../s2i2s_openstack_vm_data_scripts/ubuntu2404.sh","uuid":"fc3f705d-3cf5-4866-8ef6-ff6e2cdd4075"}},"type":["object",{"access_to_the_jump_proxy":["object",{"all_tags":["set","string"],"delete_default_rules":"bool","description":"string","id":"string","name":"string","region":"string","stateful":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"delete":"string"}]}],"acme_challenge_hostname":"string","availability_zones_names":["map","string"],"basic_services_ip":["map","string"],"debugging":["object",{"all_tags":["set","string"],"delete_default_rules":"bool","description":"string","id":"string","name":"string","region":"string","stateful":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"delete":"string"}]}],"default_security_group":["object",{"all_tags":["set","string"],"delete_default_rules":"bool","description":"string","id":"string","name":"string","region":"string","stateful":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"delete":"string"}]}],"default_security_group_id":"string","default_security_group_name":"string","dns_zone":["object",{"attributes":["map","string"],"description":"string","disable_status_check":"bool","email":"string","id":"string","masters":["set","string"],"name":"string","project_id":"string","region":"string","timeouts":["object",{"create":"string","delete":"string","update":"string"}],"ttl":"number","type":"string","value_specs":["map","string"]}],"dns_zone_id":"string","floating_ip_pools":["map","string"],"haproxy_l7_data":["map","string"],"internal_ca_data":["map","string"],"internal_ca_id":"string","main_haproxy_l7_ids":["tuple",["string","string"]],"main_haproxy_l7_ip":["list","string"],"main_lb_to_haproxy_l7_security_group":["object",{"all_tags":["set","string"],"delete_default_rules":"bool","description":"string","id":"string","name":"string","region":"string","stateful":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"delete":"string"}]}],"main_loadbalancer_hostname":"string","main_loadbalancer_id":"string","main_loadbalancer_ip":"string","main_loadbalancer_public_ip":"string","main_private_network":["object",{"admin_state_up":"bool","all_tags":["set","string"],"availability_zone_hints":["set","string"],"description":"string","dns_domain":"string","external":"bool","id":"string","mtu":"number","name":"string","port_security_enabled":"bool","qos_policy_id":"string","region":"string","segments":["set",["object",{"network_type":"string","physical_network":"string","segmentation_id":"number"}]],"shared":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"create":"string","delete":"string"}],"transparent_vlan":"bool","value_specs":["map","string"]}],"main_private_subnet":["object",{"all_tags":["set","string"],"allocation_pool":["set",["object",{"end":"string","start":"string"}]],"cidr":"string","description":"string","dns_nameservers":["list","string"],"dns_publish_fixed_ip":"bool","enable_dhcp":"bool","gateway_ip":"string","id":"string","ip_version":"number","ipv6_address_mode":"string","ipv6_ra_mode":"string","name":"string","network_id":"string","no_gateway":"bool","prefix_length":"number","region":"string","segment_id":"string","service_types":["list","string"],"subnetpool_id":"string","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"create":"string","delete":"string"}],"value_specs":["map","string"]}],"main_region":"string","main_subnet_network_id":"string","mtu_size":"number","os_project_data":["map","string"],"prometheus_access_from_grafana":["object",{"all_tags":["set","string"],"delete_default_rules":"bool","description":"string","id":"string","name":"string","region":"string","stateful":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"delete":"string"}]}],"prometheus_hostname":"string","prometheus_public_ip":"string","prometheus_server_data":["map","string"],"prometheus_server_id":"string","public_web":["object",{"all_tags":["set","string"],"delete_default_rules":"bool","description":"string","id":"string","name":"string","region":"string","stateful":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"delete":"string"}]}],"resolvers_ip":["list","string"],"restricted_web":["object",{"all_tags":["set","string"],"delete_default_rules":"bool","description":"string","id":"string","name":"string","region":"string","stateful":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"delete":"string"}]}],"ssh_jump_proxy":["map","string"],"ssh_jump_proxy_hostname":"string","ssh_jump_proxy_id":"string","ssh_jump_proxy_public_ip":"string","ssh_sources":["map","string"],"traffic_from_main_haproxy":["object",{"all_tags":["set","string"],"delete_default_rules":"bool","description":"string","id":"string","name":"string","region":"string","stateful":"bool","tags":["set","string"],"tenant_id":"string","timeouts":["object",{"delete":"string"}]}],"ubuntu2204_data_file":"string","ubuntu2404_data_file":"string","ubuntu_2204":["map","string"],"ubuntu_2404":["map","string"]}]},"workspace":null},"sensitive_attributes":[]}]},{"module":"module.dmarc_reports","mode":"managed","type":"openstack_blockstorage_volume_v3","name":"dmarc_reports_data_vol","provider":"provider[\"registry.opentofu.org/terraform-provider-openstack/openstack\"]","instances":[{"schema_version":0,"attributes":{"attachment":[],"availability_zone":"nova","backup_id":"","consistency_group_id":null,"description":"OpenSearch data directory of the DMARC reports service","enable_online_resize":true,"id":"e0fd9dc1-3dc4-4f8d-8ec7-b42ada09f40b","image_id":null,"metadata":{},"name":"opensearch-dmarc-data","region":"isti_area_pi_1","scheduler_hints":[],"size":50,"snapshot_id":"","source_replica":null,"source_vol_id":"","timeouts":null,"volume_retype_policy":"never","volume_type":"CephSSD"},"sensitive_attributes":[],"private":"eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiY3JlYXRlIjo2MDAwMDAwMDAwMDAsImRlbGV0ZSI6NjAwMDAwMDAwMDAwfX0="}]},{"module":"module.dmarc_reports","mode":"managed","type":"openstack_compute_instance_v2","name":"dmarc_reports","provider":"provider[\"registry.opentofu.org/terraform-provider-openstack/openstack\"]","instances":[{"schema_version":0,"attributes":{"access_ip_v4":"10.10.0.166","access_ip_v6":"","admin_pass":null,"all_metadata":{},"all_tags":[],"availability_zone":"cnr-isti-nova-a","availability_zone_hints":"cnr-isti-nova-a","block_device":[{"boot_index":0,"delete_on_termination":false,"destination_type":"volume","device_type":"","disk_bus":"","guest_format":"","multiattach":false,"source_type":"image","uuid":"fc3f705d-3cf5-4866-8ef6-ff6e2cdd4075","volume_size":20,"volume_type":""}],"config_drive":null,"created":"2026-09-29 14:17:25 +0000 UTC","flavor_id":"9","flavor_name":"m1.large","force_delete":false,"hypervisor_hostname":"","id":"4e9298b9-575f-408f-a551-d295783b6939","image_id":"Attempt to boot from volume - no image supplied","image_name":null,"key_pair":"adellam","metadata":null,"name":"opensearch-dmarc","network":[{"access_network":false,"fixed_ip_v4":"10.10.0.166","fixed_ip_v6":"","mac":"fa:16:3e:35:4a:a0","name":"s2i2s-proj-main","port":"36c2f572-a3e2-4211-be5d-51b744829cdb","uuid":"f371c239-6d5d-4ac8-a17e-af607752d82c"}],"network_mode":null,"personality":[],"power_state":"active","region":"isti_area_pi_1","scheduler_hints":[],"security_groups":["default_for_all","traffic_to_dmarc_reports_from_the_main_load_balancers"],"stop_before_destroy":false,"tags":null,"timeouts":null,"updated":"2026-09-29 14:18:19 +0000 UTC","user_data":"6d2d5c35b12ecb5b568ebf69dbb05357219ce455","vendor_options":[]},"sensitive_attributes":[[{"type":"get_attr","value":"admin_pass"}]],"private":"eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiY3JlYXRlIjoxODAwMDAwMDAwMDAwLCJkZWxldGUiOjE4MDAwMDAwMDAwMDAsInVwZGF0ZSI6MTgwMDAwMDAwMDAwMH19","dependencies":["data.terraform_remote_state.privnet_dns_router","data.terraform_remote_state.project_setup","module.dmarc_reports.openstack_networking_port_v2.dmarc_reports_main_port","module.dmarc_reports.openstack_networking_secgroup_v2.traffic_to_dmarc_reports"]}]},{"module":"module.dmarc_reports","mode":"managed","type":"openstack_compute_volume_attach_v2","name":"dmarc_reports_data_attach","provider":"provider[\"registry.opentofu.org/terraform-provider-openstack/openstack\"]","instances":[{"schema_version":0,"attributes":{"device":"/dev/vdb","id":"4e9298b9-575f-408f-a551-d295783b6939/e0fd9dc1-3dc4-4f8d-8ec7-b42ada09f40b","instance_id":"4e9298b9-575f-408f-a551-d295783b6939","multiattach":null,"region":"isti_area_pi_1","tag":null,"timeouts":null,"vendor_options":[],"volume_id":"e0fd9dc1-3dc4-4f8d-8ec7-b42ada09f40b"},"sensitive_attributes":[],"private":"eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiY3JlYXRlIjo2MDAwMDAwMDAwMDAsImRlbGV0ZSI6NjAwMDAwMDAwMDAwfX0=","dependencies":["data.terraform_remote_state.privnet_dns_router","data.terraform_remote_state.project_setup","module.dmarc_reports.openstack_blockstorage_volume_v3.dmarc_reports_data_vol","module.dmarc_reports.openstack_compute_instance_v2.dmarc_reports","module.dmarc_reports.openstack_networking_port_v2.dmarc_reports_main_port","module.dmarc_reports.openstack_networking_secgroup_v2.traffic_to_dmarc_reports"]}]},{"module":"module.dmarc_reports","mode":"managed","type":"openstack_dns_recordset_v2","name":"dmarc_reports_public_recordset","provider":"provider[\"registry.opentofu.org/terraform-provider-openstack/openstack\"]","instances":[{"index_key":0,"schema_version":0,"attributes":{"description":"DMARC reports, published by the main load balancer","disable_status_check":false,"id":"e826e777-0196-4f63-b2a9-df07f70e618f/c874ecda-bdc2-4389-88a5-8d72b610a966","name":"dmarc.s2i2s.cloud.isti.cnr.it.","project_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","records":["main-lb.s2i2s.cloud.isti.cnr.it."],"region":"isti_area_pi_1","timeouts":null,"ttl":8600,"type":"CNAME","value_specs":null,"zone_id":"e826e777-0196-4f63-b2a9-df07f70e618f"},"sensitive_attributes":[],"private":"eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiY3JlYXRlIjo2MDAwMDAwMDAwMDAsImRlbGV0ZSI6NjAwMDAwMDAwMDAwLCJ1cGRhdGUiOjYwMDAwMDAwMDAwMH19","dependencies":["data.terraform_remote_state.privnet_dns_router","data.terraform_remote_state.project_setup"]}]},{"module":"module.dmarc_reports","mode":"managed","type":"openstack_dns_recordset_v2","name":"dmarc_reports_recordset","provider":"provider[\"registry.opentofu.org/terraform-provider-openstack/openstack\"]","instances":[{"schema_version":0,"attributes":{"description":"Address of the DMARC reports service on the main private network","disable_status_check":false,"id":"e826e777-0196-4f63-b2a9-df07f70e618f/9fd7ba55-c20d-49a9-bfcb-26e1bedaffe9","name":"opensearch-dmarc.s2i2s.cloud.isti.cnr.it.","project_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","records":["10.10.0.166"],"region":"isti_area_pi_1","timeouts":null,"ttl":8600,"type":"A","value_specs":null,"zone_id":"e826e777-0196-4f63-b2a9-df07f70e618f"},"sensitive_attributes":[],"private":"eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiY3JlYXRlIjo2MDAwMDAwMDAwMDAsImRlbGV0ZSI6NjAwMDAwMDAwMDAwLCJ1cGRhdGUiOjYwMDAwMDAwMDAwMH19","dependencies":["data.terraform_remote_state.privnet_dns_router"]}]},{"module":"module.dmarc_reports","mode":"managed","type":"openstack_networking_port_v2","name":"dmarc_reports_main_port","provider":"provider[\"registry.opentofu.org/terraform-provider-openstack/openstack\"]","instances":[{"schema_version":0,"attributes":{"admin_state_up":true,"all_fixed_ips":["10.10.0.166"],"all_security_group_ids":["1ec8a419-f9cf-473f-a022-6499d67d57b8","54ebcf6d-8218-4721-82e3-1a12afeba6d0"],"all_tags":[],"allowed_address_pairs":[],"binding":[{"host_id":"","profile":"","vif_details":{},"vif_type":"","vnic_type":"normal"}],"description":"Port of the DMARC reports service on the main private network","device_id":"","device_owner":"","dns_assignment":[{"fqdn":"host-10-10-0-166.internal-cloud.isti.cnr.it.","hostname":"host-10-10-0-166","ip_address":"10.10.0.166"}],"dns_name":"","extra_dhcp_option":[],"fixed_ip":[{"ip_address":"10.10.0.166","subnet_id":"19c649ee-96ea-438b-ac0c-512afdf5046d"}],"id":"36c2f572-a3e2-4211-be5d-51b744829cdb","mac_address":"fa:16:3e:35:4a:a0","name":"opensearch-dmarc-main-port","network_id":"f371c239-6d5d-4ac8-a17e-af607752d82c","no_fixed_ip":null,"no_security_groups":null,"port_security_enabled":true,"qos_policy_id":"","region":"isti_area_pi_1","security_group_ids":["1ec8a419-f9cf-473f-a022-6499d67d57b8","54ebcf6d-8218-4721-82e3-1a12afeba6d0"],"tags":null,"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null,"value_specs":null},"sensitive_attributes":[],"private":"eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiY3JlYXRlIjo2MDAwMDAwMDAwMDAsImRlbGV0ZSI6NjAwMDAwMDAwMDAwfX0=","dependencies":["data.terraform_remote_state.privnet_dns_router","data.terraform_remote_state.project_setup","module.dmarc_reports.openstack_networking_secgroup_v2.traffic_to_dmarc_reports"]}]},{"module":"module.dmarc_reports","mode":"managed","type":"openstack_networking_secgroup_rule_v2","name":"haproxy_to_dmarc_reports","provider":"provider[\"registry.opentofu.org/terraform-provider-openstack/openstack\"]","instances":[{"index_key":"10.10.0.11-5601","schema_version":0,"attributes":{"description":"Traffic from the HAPROXY L7 10.10.0.11 to the port 5601","direction":"ingress","ethertype":"IPv4","id":"656c2ffa-eb38-4c1d-a913-98e68bc2849e","port_range_max":5601,"port_range_min":5601,"protocol":"tcp","region":"isti_area_pi_1","remote_address_group_id":"","remote_group_id":"","remote_ip_prefix":"10.10.0.11/32","security_group_id":"54ebcf6d-8218-4721-82e3-1a12afeba6d0","tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"sensitive_attributes":[],"private":"eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiZGVsZXRlIjo2MDAwMDAwMDAwMDB9fQ==","dependencies":["data.terraform_remote_state.project_setup","module.dmarc_reports.openstack_networking_secgroup_v2.traffic_to_dmarc_reports"]},{"index_key":"10.10.0.12-5601","schema_version":0,"attributes":{"description":"Traffic from the HAPROXY L7 10.10.0.12 to the port 5601","direction":"ingress","ethertype":"IPv4","id":"77c20a6d-6423-4546-871c-216e1d0470e0","port_range_max":5601,"port_range_min":5601,"protocol":"tcp","region":"isti_area_pi_1","remote_address_group_id":"","remote_group_id":"","remote_ip_prefix":"10.10.0.12/32","security_group_id":"54ebcf6d-8218-4721-82e3-1a12afeba6d0","tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"sensitive_attributes":[],"private":"eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiZGVsZXRlIjo2MDAwMDAwMDAwMDB9fQ==","dependencies":["data.terraform_remote_state.project_setup","module.dmarc_reports.openstack_networking_secgroup_v2.traffic_to_dmarc_reports"]}]},{"module":"module.dmarc_reports","mode":"managed","type":"openstack_networking_secgroup_v2","name":"traffic_to_dmarc_reports","provider":"provider[\"registry.opentofu.org/terraform-provider-openstack/openstack\"]","instances":[{"schema_version":0,"attributes":{"all_tags":[],"delete_default_rules":true,"description":"Traffic from the main L7 HAPROXY load balancers to OpenSearch Dashboards","id":"54ebcf6d-8218-4721-82e3-1a12afeba6d0","name":"traffic_to_dmarc_reports_from_the_main_load_balancers","region":"isti_area_pi_1","stateful":false,"tags":null,"tenant_id":"d0dcc2b7f3004c9a81b87ab60ec3c0d3","timeouts":null},"sensitive_attributes":[],"private":"eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiZGVsZXRlIjo2MDAwMDAwMDAwMDB9fQ=="}]}],"check_results":null}