Files
Software/artemis-backup-20260614-1920/terraform-pve/PHASE1-TEST-NOTES.md

2.4 KiB

Phase 1 POC — Test Notes

Date: 2026-06-04

Status: COMPLETE

Test Environment

  • Node: MK33 (192.168.7.33)
  • PVE Cluster: pve-swarm (3-node HA, quorate)
  • Terraform: v1.15.5 + bpg/proxmox v0.70.0 (Docker container)
  • Auth: API Token root@pam!terraform (privsep=0)
  • Template: nas-ct-stor:vztmpl/debian-12-standard_12.12-1_amd64.tar.zst
  • Storage: local (dir-based, NOT local-lvm — verified via live API)

What Was Tested

  1. Single LXC creation via Terraform plan → apply
  2. OS template extraction from NFS-shared storage
  3. Network: static IPv4 192.168.50.50/18, gateway, DNS
  4. Console authentication: root password + SSH key injection
  5. Features: unprivileged=true + nesting=true

Results

  • LXC-5050 created successfully (4s)
  • OS loaded — Debian 12 console accessible
  • Root password "ubuntu" confirmed working
  • SSH key (artemis_key.pub) provisioned
  • No provider warnings or errors

Fixes Applied During POC

Issue Fix
local-lvm storage didn't exist Changed to local (verified via PVE API)
Template auto-downloaded to local Pointed to existing nas-ct-stor NFS share
.env + Docker env mapping broken Replaced with terraform.auto.tfvars (native Terraform)
run.sh didn't forward flags Fixed ${@:2} handling for -auto-approve
features { nesting=true } caused 500 Combined with unprivileged=true — resolved
No console login credentials Added password to user_account block
Provider schema errors Verified all attributes live via terraform providers schema

Blockers / Tabled

  • Pegaprox MK34/MK39 offline: Tabled for Traefik VNC middleware fix
  • Pegaprox console passthrough: Requires Traefik middleware for SPICE/VNC websocket proxy

Files in This Commit

  • Dockerfile — hashicorp/terraform base image
  • docker-compose.yml — volume mounts + working_dir
  • run.sh — wrapper script (executable)
  • terraform/providers.tf — bpg/proxmox provider with API token auth
  • terraform/variables.tf — all configurable parameters
  • terraform/main.tf — single LXC resource
  • terraform/terraform.auto.tfvars — live values (private Gitea)

Next Phase

Phase 2: Modular LXC deployment

  • Extract module: modules/lxc/
  • Auto-derive VMID, name, IP from count + vmid_base
  • Bulk creation: count=4 → lxc-5050..5053