Infraestrutura KVM DCA com Terraform

main.tf

main.tf
terraform {
  required_providers {
    libvirt = {
      source = "dmacvicar/libvirt"
    }
  }
}
 
provider "libvirt" {
  uri = "qemu:///system"
}
 
variable "vms" {
  type = list(map(any))
}
 
# Definir a rede virtual 'ansible'
resource "libvirt_network" "ansible" {
  name      = "ansible"
  mode      = "nat"
  addresses = ["10.4.5.0/24"]
  autostart = true
  dhcp {
    enabled = false
  }
  dns {
    enabled = true
  }
}
 
# Criar volumes de sistema operacional
resource "libvirt_volume" "os_image" {
  for_each = { for vm in var.vms : vm.name => vm }
 
  name   = each.value.os_image_name
  pool   = each.value.storage_pool
  source = each.value.os_image_url
  format = "qcow2"
}
 
# Criar volumes de dados
resource "libvirt_volume" "os_datas" {
  for_each = { for vm in var.vms : vm.name => vm }
 
  name           = each.value.os_datas_name
  base_volume_id = libvirt_volume.os_image[each.key].id
  pool           = each.value.storage_pool
  size           = each.value.disksize * 1024 * 1024 * 1024 // GB to bytes
}
 
# Arquivo de configuração de usuário para Debian/Ubuntu
data "template_file" "user_data_deb" {
  for_each = { for vm in var.vms : vm.name => vm if lookup(vm, "user_data_deb", null) != null }
 
  template = file("${path.module}/${each.value.user_data_deb}")
  vars = {
    hostname = each.value.hostname
  }
}
 
# Arquivo de configuração de usuário para RHEL
data "template_file" "user_data_rhel" {
  for_each = { for vm in var.vms : vm.name => vm if lookup(vm, "user_data_rhel", null) != null }
 
  template = file("${path.module}/${each.value.user_data_rhel}")
  vars = {
    hostname = each.value.hostname
  }
}
 
# Configuração de rede para Debian/Ubuntu
data "template_file" "network_config_deb" {
  for_each = { for vm in var.vms : vm.name => vm if lookup(vm, "network_config_deb", null) != null }
 
  template = file("${path.module}/${each.value.network_config_deb}")
  vars = {
    network_ip = each.value.network_ip
  }
}
 
# Configuração de rede para RHEL
data "template_file" "network_config_rhel" {
  for_each = { for vm in var.vms : vm.name => vm if lookup(vm, "network_config_rhel", null) != null }
 
  template = file("${path.module}/${each.value.network_config_rhel}")
  vars = {
    network_ip = each.value.network_ip
  }
}
 
# Criar discos cloud-init para as VMs Debian/Ubuntu
resource "libvirt_cloudinit_disk" "cloudinit_deb" {
  for_each = { for vm in var.vms : vm.name => vm if lookup(vm, "user_data_deb", null) != null }
 
  name           = "${each.key}_cloudinit.iso"
  user_data      = data.template_file.user_data_deb[each.key].rendered
  network_config = data.template_file.network_config_deb[each.key].rendered
  pool           = each.value.storage_pool
}
 
# Criar discos cloud-init para as VMs RHEL
resource "libvirt_cloudinit_disk" "cloudinit_rhel" {
  for_each = { for vm in var.vms : vm.name => vm if lookup(vm, "user_data_rhel", null) != null }
 
  name           = "${each.key}_cloudinit.iso"
  user_data      = data.template_file.user_data_rhel[each.key].rendered
  network_config = data.template_file.network_config_rhel[each.key].rendered
  pool           = each.value.storage_pool
}
 
# Definir cloudinit de acordo com o sistema operacional
locals {
  cloudinit_disks = {
    for vm in var.vms : vm.name => (
      lookup(vm, "user_data_deb", null) != null ?
      libvirt_cloudinit_disk.cloudinit_deb[vm.name].id :
      libvirt_cloudinit_disk.cloudinit_rhel[vm.name].id
    )
  }
}
 
# Criar as VMs
resource "libvirt_domain" "domain" {
  for_each = { for vm in var.vms : vm.name => vm }
 
  name   = each.value.name
  memory = each.value.memory
  vcpu   = each.value.cpu
 
  cpu {
    mode = "host-passthrough"
  }
 
  cloudinit = local.cloudinit_disks[each.key]
 
  network_interface {
    network_name = each.value.network_name
  }
 
  disk {
    volume_id = libvirt_volume.os_datas[each.key].id
  }
 
  console {
    type        = "pty"
    target_type = "virtio"
    target_port = "1"
  }
 
  graphics {
    type        = "spice"
    listen_type = "address"
    autoport    = true
  }
}

terraform.tfvars

terraform.tfvars
vms = [
  {
    name               = "dca-manager"
    cpu                = 2
    memory             = 4096
    disksize           = 32
    storage_pool       = "default"
    hostname           = "dca-manager"
    os_image_name      = "dca-manager_image.qcow2"
    os_datas_name      = "dca-manager-datas.qcow2"
    network_name       = "dca"
    user_data_deb      = "cloud-init-deb.yml"
    network_config_deb = "network-config-deb.yml"
    network_ip         = "10.4.5.10"
    os_image_url       = "/home/gean/kvm/templates/ubuntu-22.04-server-cloudimg-amd64.img"
  },
  {
    name                = "dca-wk-01"
    cpu                 = 2
    memory              = 2048
    disksize            = 32
    storage_pool        = "default"
    hostname            = "dca-wk-01"
    os_image_name       = "wk-01-image.qcow2"
    os_datas_name       = "wk-01-datas.qcow2"
    network_name        = "dca"
    user_data_rhel      = "cloud-init-deb.yml"
    network_config_rhel = "network-config-deb.yml"
    network_ip          = "10.4.5.11"
    os_image_url        = "/home/gean/kvm/templates/ubuntu-22.04-server-cloudimg-amd64.img"
  },
  {
    name               = "dca-wk-02"
    cpu                = 2
    memory             = 2048
    disksize           = 32
    storage_pool       = "default"
    hostname           = "dca-wk-02"
    os_image_name      = "wk-02-image.qcow2"
    os_datas_name      = "wk-02-datas.qcow2"
    network_name       = "dca"
    user_data_deb      = "cloud-init-deb.yml"
    network_config_deb = "network-config-deb.yml"
    network_ip         = "10.4.5.12"
    os_image_url       = "/home/gean/kvm/templates/ubuntu-22.04-server-cloudimg-amd64.img"
  },
  {
    name                = "dca-registry"
    cpu                 = 2
    memory              = 2048
    disksize            = 64
    storage_pool        = "default"
    hostname            = "cda-registry"
    os_image_name       = "dca-registry-image.qcow2"
    os_datas_name       = "cda-registry-datas.qcow2"
    network_name        = "dca"
    user_data_rhel      = "cloud-init-rhel.yml"
    network_config_rhel = "network-config-rhel.yml"
    network_ip          = "10.4.5.13"
    os_image_url        = "/home/gean/kvm/templates/OL9U3_x86_64-kvm-b220.qcow2"
  }
]

cloud-init-deb.yml

cloud-init-deb.yml
#cloud-config

hostname: ${hostname}

ssh_pwauth: yes  

users:
  - name: gean
    sudo: ALL=(ALL) NOPASSWD:ALL  
    groups: users, sudo
    shell: /bin/bash
    lock_passwd: false 
    passwd: $6$uGQol.HnKU0nvpEy$YJl94Y7/p1cWZVlu0gsZIeebssh4oHCIQ9VNX721T1/Lx0UbQVbjfbzS2.9.2EGz4Hdxi0ICNKAua8lo/AsuT1 

chpasswd:
  list: |
    root:root
  expire: False 

packages:
  - qemu-guest-agent
  - bash-completion

package_update: true
package_upgrade: true

cloud-init-rhel.yml

cloud-init-rhel.yml
#cloud-config

ssh_pwauth: yes  

users:
  - name: gean
    sudo: ALL=(ALL) NOPASSWD:ALL  
    groups: users, whell
    shell: /bin/bash
    lock_passwd: false  
    passwd: $6$uGQol.HnKU0nvpEy$YJl94Y7/p1cWZVlu0gsZIeebssh4oHCIQ9VNX721T1/Lx0UbQVbjfbzS2.9.2EGz4Hdxi0ICNKAua8lo/AsuT1  

chpasswd:
  list: |
    root:root
  expire: False  

packages:
  - qemu-guest-agent  
  - bash-completion  

package_update: true  
package_upgrade: true  

runcmd:
  - systemctl enable qemu-guest-agent
  - systemctl start qemu-guest-agent
  - hostnamectl set-hostname ${hostname}

network-config-deb.yml

network-config-deb.yml
network-config-deb.yml 
#cloud-config
network:
  version: 2
  ethernets:
    ens3:
      addresses:
        - ${network_ip}/24
      nameservers:
        addresses: 
          - 10.4.5.1
      routes:
        - to: default
          via: 10.4.5.1

network-config-rhel.yml

network-config-rhel.yml
#cloud-config
network:
  version: 1
  config:
    - type: physical
      name: eth0
      subnets:
        - type: static
          address: ${network_ip}/24
          gateway: 10.4.5.1