2.4 KiB
2.4 KiB
Phase 1 POC — Test Notes
Date: 2026-06-04
Status: COMPLETE
Test Environment
- Node: MK33 (192.168.7.33)
- PVE Cluster: pve-swarm (3-node HA, quorate)
- Terraform: v1.15.5 + bpg/proxmox v0.70.0 (Docker container)
- Auth: API Token
root@pam!terraform(privsep=0) - Template:
nas-ct-stor:vztmpl/debian-12-standard_12.12-1_amd64.tar.zst - Storage:
local(dir-based, NOT local-lvm — verified via live API)
What Was Tested
- Single LXC creation via Terraform plan → apply
- OS template extraction from NFS-shared storage
- Network: static IPv4 192.168.50.50/18, gateway, DNS
- Console authentication: root password + SSH key injection
- Features: unprivileged=true + nesting=true
Results
- ✅ LXC-5050 created successfully (4s)
- ✅ OS loaded — Debian 12 console accessible
- ✅ Root password "ubuntu" confirmed working
- ✅ SSH key (artemis_key.pub) provisioned
- ✅ No provider warnings or errors
Fixes Applied During POC
| Issue | Fix |
|---|---|
local-lvm storage didn't exist |
Changed to local (verified via PVE API) |
| Template auto-downloaded to local | Pointed to existing nas-ct-stor NFS share |
.env + Docker env mapping broken |
Replaced with terraform.auto.tfvars (native Terraform) |
run.sh didn't forward flags |
Fixed ${@:2} handling for -auto-approve |
features { nesting=true } caused 500 |
Combined with unprivileged=true — resolved |
| No console login credentials | Added password to user_account block |
| Provider schema errors | Verified all attributes live via terraform providers schema |
Blockers / Tabled
- Pegaprox MK34/MK39 offline: Tabled for Traefik VNC middleware fix
- Pegaprox console passthrough: Requires Traefik middleware for SPICE/VNC websocket proxy
Files in This Commit
Dockerfile— hashicorp/terraform base imagedocker-compose.yml— volume mounts + working_dirrun.sh— wrapper script (executable)terraform/providers.tf— bpg/proxmox provider with API token authterraform/variables.tf— all configurable parametersterraform/main.tf— single LXC resourceterraform/terraform.auto.tfvars— live values (private Gitea)
Next Phase
Phase 2: Modular LXC deployment
- Extract module:
modules/lxc/ - Auto-derive VMID, name, IP from count + vmid_base
- Bulk creation:
count=4→ lxc-5050..5053