Example of creating infrastructure with a cloud load balancer via Terraform
We recommend creating resources sequentially. If you create all resources at the same time, Terraform will take into account the dependencies between resources that you specified in the configuration file. If dependencies are not specified, resources will be created in parallel, which may lead to errors. For example, a resource required to create another resource may not be created yet.
- Optional: configure the providers.
- Create a private network and subnet.
- Create a cloud router connected to the internet.
- Create a cloud server.
- Create a cloud load balancer.
- Create a public floating IP address and attach it to the load balancer.
- Get the load balancer IP address.
Configuration files
Example file for configuring providers
terraform {
required_providers {
servercore = {
source = "terraform.servercore.com/servercore/servercore"
version = "~> 6.0"
}
openstack = {
source = "terraform-provider-openstack/openstack"
version = "2.1.0"
}
}
}
provider "servercore" {
domain_name = "123456"
username = "user"
password = "password"
auth_region = "uz-1"
auth_url = "https://cloud.api.servercore.com/identity/v3/"
}
resource "servercore_project_v2" "project_1" {
name = "project"
}
resource "servercore_iam_serviceuser_v1" "serviceuser_1" {
name = "username"
password = "password"
role {
role_name = "member"
scope = "project"
project_id = servercore_project_v2.project_1.id
}
}
provider "openstack" {
auth_url = "https://cloud.api.servercore.com/identity/v3"
domain_name = "123456"
tenant_id = servercore_project_v2.project_1.id
user_name = servercore_iam_serviceuser_v1.serviceuser_1.name
password = servercore_iam_serviceuser_v1.serviceuser_1.password
region = "uz-1"
}
Example file for creating infrastructure with a cloud load balancer
resource "openstack_networking_network_v2" "network_1" {
name = "private-network"
admin_state_up = "true"
}
resource "openstack_networking_subnet_v2" "subnet_1" {
name = "private-subnet"
network_id = openstack_networking_network_v2.network_1.id
cidr = "192.168.199.0/24"
}
data "openstack_networking_network_v2" "external_network_1" {
external = true
}
resource "openstack_networking_router_v2" "router_1" {
name = "router"
external_network_id = data.openstack_networking_network_v2.external_network_1.id
}
resource "openstack_networking_router_interface_v2" "router_interface_1" {
router_id = openstack_networking_router_v2.router_1.id
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}
resource "servercore_keypair_v2" "keypair_1" {
name = "keypair"
public_key = file("~/.ssh/id_rsa.pub")
user_id = servercore_iam_serviceuser_v1.serviceuser_1.id
}
resource "openstack_networking_port_v2" "port_1" {
name = "port"
network_id = openstack_networking_network_v2.network_1.id
fixed_ip {
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}
}
data "openstack_images_image_v2" "image_1" {
name = "Ubuntu 20.04 LTS 64-bit"
most_recent = true
visibility = "public"
}
resource "openstack_blockstorage_volume_v3" "volume_1" {
name = "boot-volume-for-server"
size = "5"
image_id = data.openstack_images_image_v2.image_1.id
volume_type = "fast.uz-1a"
availability_zone = "uz-1a"
enable_online_resize = true
lifecycle {
ignore_changes = [image_id]
}
}
resource "openstack_compute_instance_v2" "server_1" {
name = "server"
flavor_id = "4011"
key_pair = servercore_keypair_v2.keypair_1.name
availability_zone = "uz-1a"
network {
port = openstack_networking_port_v2.port_1.id
}
lifecycle {
ignore_changes = [image_id]
}
block_device {
uuid = openstack_blockstorage_volume_v3.volume_1.id
source_type = "volume"
destination_type = "volume"
boot_index = 0
}
vendor_options {
ignore_resize_confirmation = true
}
}
resource "openstack_lb_loadbalancer_v2" "load_balancer_1" {
name = "load-balancer"
vip_subnet_id = openstack_networking_subnet_v2.subnet_1.id
flavor_id = "7d56905c-92ce-49e8-986e-f656f7b44cda"
}
resource "openstack_lb_listener_v2" "listener_1" {
name = "listener"
protocol = "TCP"
protocol_port = "80"
loadbalancer_id = openstack_lb_loadbalancer_v2.load_balancer_1.id
}
resource "openstack_lb_pool_v2" "pool_1" {
name = "pool"
protocol = "PROXY"
lb_method = "ROUND_ROBIN"
listener_id = openstack_lb_listener_v2.listener_1.id
}
resource "openstack_lb_member_v2" "member_1" {
name = "member"
subnet_id = openstack_networking_subnet_v2.subnet_1.id
pool_id = openstack_lb_pool_v2.pool_1.id
address = "192.168.199.4"
protocol_port = "80"
}
resource "openstack_lb_monitor_v2" "monitor_1" {
name = "monitor"
pool_id = openstack_lb_pool_v2.pool_1.id
type = "HTTP"
delay = "10"
timeout = "4"
max_retries = "5"
}
resource "openstack_networking_floatingip_v2" "floatingip_1" {
pool = "external-network"
port_id = openstack_lb_loadbalancer_v2.load_balancer_1.vip_port_id
}
output "public_ip_address" {
value = openstack_networking_floatingip_v2.floatingip_1.fixed_ip
}
1. Optional: configure providers
If you configured the providers for Servercore and OpenStack, skip this step.
-
Make sure that in the control panel you have created a service user with the
memberroles in the Account scope andiam.admin. -
Create a directory to store configuration files and a separate file with the
.tfextension to configure providers. -
Add the Servercore and OpenStack providers to the file for provider configuration:
terraform {required_providers {servercore = {source = "terraform.servercore.com/servercore/servercore"version = "~> 7.1.0"}openstack = {source = "terraform-provider-openstack/openstack"version = "2.1.0"}}}Here
versionis provider versions. You can check the current version of the OpenStack provider in the Terraform Registry and GitHub.For more information about products, services, and features that can be managed using providers, see the Servercore and OpenStack Providers instructions.
-
Initialize the Servercore provider:
provider "servercore" {domain_name = "123456"username = "user"password = "password"auth_region = "uz-1"auth_url = "https://cloud.api.servercore.com/identity/v3/"}Where:
domain_name— Servercore account number. You can find it in the control panel in the upper-right corner;username— name of the service user with thememberroles in the Account scope andiam.admin. You can find it in the control panel: in the top menu, click IAM → Service Users (the section is available only to the Account Owner and a user with theiam.adminrole);password— password of the service user. You can view it when creating the user or change it to a new one;auth_region— pool for authorization in theuz-1format; do not use pools in theSPB-2format. The pool for authorization may differ from the pool where you create resources. You can check the list of available pools in the Product Availability by Location instructions.
-
Create a project:
resource "servercore_project_v2" "project_1" {name = "project"}See the detailed description of the servercore_project_v2 resource.
-
Create a service user to access the project and assign them the
memberrole in the Project scope:resource "servercore_iam_serviceuser_v1" "serviceuser_1" {name = "username"password = "password"role {role_name = "member"scope = "project"project_id = servercore_project_v2.project_1.id}}Where:
-
username— username; -
password— user password. The password must be at least 20 characters long and include at least:- one uppercase and one lowercase Latin letter (
A-Z,a-z); - one digit (
0-9); - one special character from the ASCII Printable 7-Bit Special Characters list:
!"#$%&'()*+,-./:;<=>?@[]^_{|}~;
- one uppercase and one lowercase Latin letter (
-
project_id— project ID. You can find it in the control panel: in the top menu, click IAM → Projects → in the row of the desired project, click .
See the detailed description of the servercore_iam_serviceuser_v1 resource.
-
-
Initialize the OpenStack provider:
provider "openstack" {auth_url = "https://cloud.api.servercore.com/identity/v3"domain_name = "123456"tenant_id = servercore_project_v2.project_1.iduser_name = servercore_iam_serviceuser_v1.serviceuser_1.namepassword = servercore_iam_serviceuser_v1.serviceuser_1.passwordregion = "uz-1"}Where:
domain_name— Servercore account number. You can find it in the control panel in the upper-right corner;region— pool, for example,uz-1. All resources will be created in this pool. You can check the list of available pools in the Product Availability by Location instructions.
-
If you create resources at the same time as configuring providers, add the
depends_onargument for OpenStack resources. For example, for the openstack_networking_network_v2 resource:resource "openstack_networking_network_v2" "network_1" {name = "private-network"admin_state_up = "true"depends_on = [servercore_project_v2.project_1,servercore_iam_serviceuser_v1.serviceuser_1]} -
Open the CLI.
-
Initialize the Terraform configuration in the directory:
terraform init -
Verify that the configuration files are syntactically correct:
terraform validate -
Format the configuration files:
terraform fmt -
Check which resources will be created:
terraform plan -
Apply the changes and create the resources:
terraform apply -
Confirm the creation — enter yes and press Enter. The created resources will appear in the control panel.
-
If there are not enough quotas to create resources, increase quotas.
2. Create a private network and subnet
resource "openstack_networking_network_v2" "network_1" {
name = "private-network"
admin_state_up = "true"
}
resource "openstack_networking_subnet_v2" "subnet_1" {
name = "private-subnet"
network_id = openstack_networking_network_v2.network_1.id
cidr = "192.168.199.0/24"
}
Here, cidr is the CIDR of the private subnet, for example, 192.168.199.0/24.
See the detailed resource description:
3. Create a cloud router connected to the internet
A cloud router connected to the internet performs 1:1 NAT for access from a private network to the internet via the router's external IP address.
data "openstack_networking_network_v2" "external_network_1" {
external = true
}
resource "openstack_networking_router_v2" "router_1" {
name = "router"
external_network_id = data.openstack_networking_network_v2.external_network_1.id
}
resource "openstack_networking_router_interface_v2" "router_interface_1" {
router_id = openstack_networking_router_v2.router_1.id
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}
See the detailed resource description:
- openstack_networking_network_v2;
- openstack_networking_router_v2;
- openstack_networking_router_interface_v2.
4. Create a cloud server
- Add a public SSH key.
- Create a port for the cloud server.
- Get the image.
- Create a boot network volume.
- Create a cloud server.
1. Add a public SSH key
resource "servercore_keypair_v2" "keypair_1" {
name = "keypair"
public_key = file("~/.ssh/id_rsa.pub")
user_id = servercore_iam_serviceuser_v1.serviceuser_1.id
}
Here, public_key is the path to the public SSH key. If SSH keys have not been generated, create them.
View the detailed description of the servercore_keypair_v2 resource.
2. Create a port for the cloud server
resource "openstack_networking_port_v2" "port_1" {
name = "port"
network_id = openstack_networking_network_v2.network_1.id
fixed_ip {
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}
}
See the detailed description of the openstack_networking_port_v2 resource.
3. Get an image
data "openstack_images_image_v2" "image_1" {
name = "Ubuntu 20.04 LTS 64-bit"
most_recent = true
visibility = "public"
}
See the detailed description of the openstack_images_image_v2 data source.
4. Create a bootable network volume
resource "openstack_blockstorage_volume_v3" "volume_1" {
name = "boot-volume-for-server"
size = "5"
image_id = data.openstack_images_image_v2.image_1.id
volume_type = "fast.uz-1a"
availability_zone = "uz-1a"
enable_online_resize = true
lifecycle {
ignore_changes = [image_id]
}
}
Here:
size— disk size in GB. Consider the network volume limits on the maximum size;volume_type— ID or name of the network volume type. For example,fast.uz-1ais the name for creating a network volume with the Fast SSD type in the pool segment uz-1a. For a list of types, see the table List of network volume types across all pool segments;availability_zone— pool segment where the network volume will be created, for example,uz-1a. You can find the list of available pool segments in the instructions Product availability by location.
See the detailed description of the resource openstack_blockstorage_volume_v3.
5. Create a cloud server
resource "openstack_compute_instance_v2" "server_1" {
name = "server"
flavor_id = "1015"
key_pair = servercore_keypair_v2.keypair_1.name
availability_zone = "uz-1a"
network {
port = openstack_networking_port_v2.port_1.id
}
lifecycle {
ignore_changes = [image_id]
}
block_device {
uuid = openstack_blockstorage_volume_v3.volume_1.id
source_type = "volume"
destination_type = "volume"
boot_index = 0
}
vendor_options {
ignore_resize_confirmation = true
}
}
Where:
availability_zone— pool segment where the cloud server will be created, for exampleuz-1a. You can find the list of available pool segments in the Product availability by location manual;flavor_id— flavor ID. Flavors correspond to cloud server configurations and determine the number of vCPUs, RAM, and local disk size (optional) of the server. You can use fixed configuration flavors. For example,1015is an ID for creating a server with a fixed configuration from the Standard line with 4 vCPUs and 16 GB RAM in the uz-1 pool. You can view the list of flavors in the List of fixed configuration flavors across all pools table.
See the detailed description of the openstack_compute_instance_v2 resource.
5. Create a cloud load balancer
- Create a load balancer.
- Create a rule.
- Create a target group.
- Add the server to the target group.
- Create a health check.
1. Create a cloud load balancer
resource "openstack_lb_loadbalancer_v2" "load_balancer_1" {
name = "load-balancer"
vip_subnet_id = openstack_networking_subnet_v2.subnet_1.id
flavor_id = "7d56905c-92ce-49e8-986e-f656f7b44cda"
}
Here, flavor_id is the flavor ID. Flavors correspond to load balancer types and determine the number of vCPUs, RAM, and the number of load balancer instances. For example, 7d56905c-92ce-49e8-986e-f656f7b44cda is the ID for creating an Advanced with redundancy load balancer in pool uz-1. You can view the list of flavors in the List of load balancer flavors in all pools table.
See the detailed description of the openstack_lb_loadbalancer_v2 resource.
2. Create a rule
resource "openstack_lb_listener_v2" "listener_1" {
name = "listener"
protocol = "TCP"
protocol_port = "80"
loadbalancer_id = openstack_lb_loadbalancer_v2.load_balancer_1.id
}
Where:
protocol— load balancer protocol, for example,TCP. See available load balancer and server protocol combinations;protocol_port— incoming traffic port for the load balancer.
See the detailed description of the openstack_lb_listener_v2 resource.
3. Create a target group
resource "openstack_lb_pool_v2" "pool_1" {
name = "pool"
protocol = "PROXY"
lb_method = "ROUND_ROBIN"
listener_id = openstack_lb_listener_v2.listener_1.id
}
Where:
protocol— protocol for servers, for example,PROXY. See available protocol combinations for the load balancer and server;lb_method— request distribution algorithm. Available algorithms areROUND_ROBINandLEAST_CONNECTIONS.
See the detailed description of the openstack_lb_pool_v2 resource.
4. Add the server to the target group
resource "openstack_lb_member_v2" "member_1" {
name = "member"
subnet_id = openstack_networking_subnet_v2.subnet_1.id
pool_id = openstack_lb_pool_v2.pool_1.id
address = "192.168.199.4"
protocol_port = "80"
}
Here:
address— private IP address of the server, for example192.168.199.4;protocol_port— port for servers in the rule.
See the detailed description of the openstack_lb_member_v2 resource.
5. Create an availability check
resource "openstack_lb_monitor_v2" "monitor_1" {
name = "monitor"
pool_id = openstack_lb_pool_v2.pool_1.id
type = "HTTP"
delay = "10"
timeout = "4"
max_retries = "5"
}
Here:
type— check type, for example,HTTP;delay— interval in seconds at which the load balancer sends check requests to servers;timeout— connection timeout (response wait time);max_retries— number of consecutive successful requests after which the server is switched to the operational state (success threshold).
See the detailed description of the openstack_lb_monitor_v2 resource.
6. Create a public floating IP address and attach to the load balancer
The public floating IP address will be connected to the load balancer port and associated with the private IP.
resource "openstack_networking_floatingip_v2" "floatingip_1" {
pool = "external-network"
port_id = openstack_lb_loadbalancer_v2.load_balancer_1.vip_port_id
}
See the detailed description of the openstack_networking_floatingip_v2 resource.
7. Get the load balancer IP address
output "public_ip_address" {
value = openstack_networking_floatingip_v2.floatingip_1.fixed_ip
}