diff --git a/modules/gcve-private-cloud/README.md b/modules/gcve-private-cloud/README.md new file mode 100644 index 00000000..8baad718 --- /dev/null +++ b/modules/gcve-private-cloud/README.md @@ -0,0 +1,97 @@ +# Google Cloud VMWare Engine Private Cloud Module + +This module implements the creation and management of a Google Cloud VMWare Engine Private Cloud with its management cluster. If configured, it also creates the vmware engine network or it can work with an existing one. The creation of the private connection with the user VPC requires the execution of the [Google SDK command](https://cloud.google.com/sdk/gcloud/reference/vmware/private-connections/create#--routing-mode) the module provides as an output. + +Be aware that the deployment of this module might requires up to 2 hours depending on the selected private cloud target zone. + +## TOC + + +- [TOC](#toc) +- [Limitations](#limitations) +- [Basic Private Cloud Creation](#basic-private-cloud-creation) +- [Private Cloud Creation with custom nodes and cores count](#private-cloud-creation-with-custom-nodes-and-cores-count) +- [Files](#files) +- [Variables](#variables) + + +## Limitations +At the moment this module doesn't support the following use cases: +- `Single node private cloud` +- `Stretched private cloud` + +## Basic Private Cloud Creation + +```hcl +module "gcve-pc" { + source = "./fabric/modules/gcve-private-cloud" + name = "gcve-pc" + project_id = "gcve-test-project" + zone = "asia-southeast1-a" + management_cidr = "192.168.0.0/24" + + private_connections = { + transit-conn1 = { + name = "transit-conn1", + network_self_link = "projects/test-prj-elia-01/global/networks/default", + peering = "servicenetworking-googleapis-com" + type = "PRIVATE_SERVICE_ACCESS", + routing_mode = "REGIONAL" + } + } +} +# tftest modules=1 resources=2 inventory=basic.yaml +``` +## Private Cloud Creation with custom nodes and cores count + +```hcl +module "gcve-pc" { + source = "./fabric/modules/gcve-private-cloud" + name = "gcve-pc" + project_id = "gcve-test-project" + zone = "asia-southeast1-a" + management_cidr = "192.168.0.0/24" + + management_cluster_config = { + node_type_id = "standard-72" + node_count = 6 + custom_core_count = 28 + } + + private_connections = { + transit-conn1 = { + name = "transit-conn1", + network_self_link = "projects/test-prj-elia-01/global/networks/default", + peering = "servicenetworking-googleapis-com" + type = "PRIVATE_SERVICE_ACCESS", + routing_mode = "REGIONAL" + } + } +} +# tftest modules=1 resources=2 inventory=custom.yaml +``` + + + +## Files + +| name | description | resources | +|---|---|---| +| [main.tf](./main.tf) | Module-level locals and resources. | google_vmwareengine_network · google_vmwareengine_private_cloud | +| [output.tf](./output.tf) | None | | +| [variables.tf](./variables.tf) | Module variables. | | +| [versions.tf](./versions.tf) | Version pins. | | + +## Variables + +| name | description | type | required | default | +|---|---|:---:|:---:|:---:| +| [management_cidr](variables.tf#L23) | vSphere/vSAN subnets CIDR range. | string | ✓ | | +| [name](variables.tf#L42) | Private cloud name. | string | ✓ | | +| [project_id](variables.tf#L74) | Project id. | string | ✓ | | +| [zone](variables.tf#L85) | Private cloud zone. | string | ✓ | | +| [description](variables.tf#L17) | Private cloud description. | string | | "Terraform-managed." | +| [management_cluster_config](variables.tf#L28) | Management cluster configuration. | object({…}) | | {…} | +| [private_connections](variables.tf#L47) | VMWare private connections configuration. It is used to create the gcloud command printed as output. | map(object({…})) | | {} | +| [vmwareengine_network_create](variables.tf#L79) | Create the VMware Engine network. When set to false, it uses a data source to reference an existing VMware Engine network. | bool | | true | + diff --git a/modules/gcve-private-cloud/main.tf b/modules/gcve-private-cloud/main.tf new file mode 100644 index 00000000..3f184475 --- /dev/null +++ b/modules/gcve-private-cloud/main.tf @@ -0,0 +1,74 @@ +/** + * Copyright 2023 Google LLC + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +locals { + region = join("-", slice(split("-", "${var.zone}"), 0, 2)) + vmwareengine_network = ( + var.vmwareengine_network_create + ? try(google_vmwareengine_network.private-cloud-network.0, null) + : try(data.google_vmwareengine_network.private-cloud-network.0, null) + ) + psa_peering = { + for k, v in data.google_compute_network_peering.psa_peering : k => slice(split("/", "${v.peer_network}"), 6, 7)[0] + } +} + +data "google_vmwareengine_network" "private-cloud-network" { + count = var.vmwareengine_network_create ? 0 : 1 + provider = google-beta + project = var.project_id + name = "${local.region}-default" + location = local.region +} + + +data "google_compute_network_peering" "psa_peering" { + for_each = var.private_connections + name = each.value.peering + network = each.value.network_self_link +} + +resource "google_vmwareengine_private_cloud" "private-cloud" { + provider = google-beta + project = var.project_id + location = var.zone + name = var.name + description = var.description + + network_config { + management_cidr = var.management_cidr + vmware_engine_network = local.vmwareengine_network.id + } + + management_cluster { + cluster_id = "${var.name}-mgmt-cluster" + node_type_configs { + node_type_id = var.management_cluster_config.node_type_id + node_count = var.management_cluster_config.node_count + custom_core_count = var.management_cluster_config.custom_core_count + } + } +} + +resource "google_vmwareengine_network" "private-cloud-network" { + count = var.vmwareengine_network_create ? 1 : 0 + provider = google-beta + project = var.project_id + name = "${local.region}-default" + location = local.region + type = "LEGACY" + description = "Private cloud ${var.name} network." +} diff --git a/modules/gcve-private-cloud/output.tf b/modules/gcve-private-cloud/output.tf new file mode 100644 index 00000000..f1af67ec --- /dev/null +++ b/modules/gcve-private-cloud/output.tf @@ -0,0 +1,71 @@ +/** + * Copyright 2023 Google LLC + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +output "hcx" { + description = "Details about a HCX Cloud Manager appliance." + value = google_vmwareengine_private_cloud.private-cloud.hcx +} + +output "id" { + description = "ID of the private cloud" + value = google_vmwareengine_private_cloud.private-cloud.id +} + +output "management_cluster" { + description = "Details of the management cluster of the private cloud" + value = google_vmwareengine_private_cloud.private-cloud.management_cluster +} + +output "network_config" { + description = "Details about the network configuration of the private cloud" + value = google_vmwareengine_private_cloud.private-cloud.network_config +} + +output "nsx" { + description = "Details about a NSX Manager appliance." + value = google_vmwareengine_private_cloud.private-cloud.nsx +} + +output "private-cloud" { + description = "The private cloud resource" + value = google_vmwareengine_private_cloud.private-cloud +} + +output "vcenter" { + description = "Details about a vCenter Server management appliance." + value = google_vmwareengine_private_cloud.private-cloud.vcenter +} + +output "state" { + description = "Details about the state of the private cloud" + value = google_vmwareengine_private_cloud.private-cloud.state +} + +output "private_connections_setup" { + description = "Cloud SDK commands for the private connections manual setup." + value = { + for k, v in var.private_connections : k => <