Skip to main content

Create a fixed configuration cloud server with dedicated cores and a bootable network volume via Terraform

We recommend creating resources in order. If you create all resources at once, Terraform will account for dependencies between resources that you specified in the configuration file. If dependencies are not specified, resources will be created in parallel, which may lead to errors. For instance, a resource required for creating another resource might not have been created yet.


  1. Optional: configure providers.

  2. Add a public SSH key.

  3. Create a private network and subnet.

  4. Create a cloud router connected to the internet.

  5. Create a port for the cloud server.

  6. Get an image.

  7. Create a boot network volume.

  8. Create a cloud server.

  9. Create a public floating IP address.

  10. Associate the public and private IP addresses of the cloud server.

  11. Get the cloud server address.

Configuration files

Example file for configuring providers
terraform {
required_providers {
selectel = {
source = "selectel/selectel"
version = "~> 6.0"
}
openstack = {
source = "terraform-provider-openstack/openstack"
version = "2.1.0"
}
}
}

provider "selectel" {
domain_name = "123456"
username = "user"
password = "password"
auth_region = "ru-7"
auth_url = "https://cloud.api.selcloud.ru/identity/v3/"
}

resource "selectel_vpc_project_v2" "project_1" {
name = "project"
}

resource "selectel_iam_serviceuser_v1" "serviceuser_1" {
name = "username"
password = "password"
role {
role_name = "member"
scope = "project"
project_id = selectel_vpc_project_v2.project_1.id
}
}

provider "openstack" {
auth_url = "https://cloud.api.selcloud.ru/identity/v3"
domain_name = "123456"
tenant_id = selectel_vpc_project_v2.project_1.id
user_name = selectel_iam_serviceuser_v1.serviceuser_1.name
password = selectel_iam_serviceuser_v1.serviceuser_1.password
region = "ru-7"
}
Example file for creating a server with dedicated cores

resource "selectel_vpc_keypair_v2" "keypair_1" {
name = "keypair"
public_key = file("~/.ssh/id_rsa.pub")
user_id = selectel_iam_serviceuser_v1.serviceuser_1.id
}

resource "openstack_networking_network_v2" "network_1" {
name = "private-network"
admin_state_up = "true"
}

resource "openstack_networking_subnet_v2" "subnet_1" {
network_id = openstack_networking_network_v2.network_1.id
cidr = "192.168.199.0/24"
}

data "openstack_networking_network_v2" "external_network_1" {
external = true
}

resource "openstack_networking_router_v2" "router_1" {
name = "router"
external_network_id = data.openstack_networking_network_v2.external_network_1.id
}

resource "openstack_networking_router_interface_v2" "router_interface_1" {
router_id = openstack_networking_router_v2.router_1.id
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}

resource "openstack_networking_port_v2" "port_1" {
name = "port"
network_id = openstack_networking_network_v2.network_1.id

fixed_ip {
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}
}

data "openstack_images_image_v2" "image_1" {
name = "Ubuntu 20.04 LTS 64-bit"
most_recent = true
visibility = "public"
}

resource "openstack_blockstorage_volume_v3" "volume_1" {
name = "boot-volume-for-server"
size = "5"
image_id = data.openstack_images_image_v2.image_1.id
volume_type = "fast.ru-7b"
availability_zone = "ru-7b"
enable_online_resize = true

lifecycle {
ignore_changes = [image_id]
}

}

resource "openstack_compute_instance_v2" "server_1" {
name = "server"
flavor_id = "1063"
key_pair = selectel_vpc_keypair_v2.keypair_1.name
availability_zone = "ru-7b"

network {
port = openstack_networking_port_v2.port_1.id
}

lifecycle {
ignore_changes = [image_id]
}

block_device {
uuid = openstack_blockstorage_volume_v3.volume_1.id
source_type = "volume"
destination_type = "volume"
boot_index = 0
}

vendor_options {
ignore_resize_confirmation = true
}
}

resource "openstack_networking_floatingip_v2" "floatingip_1" {
pool = "external-network"
}

resource "openstack_networking_floatingip_associate_v2" "association_1" {
port_id = openstack_networking_port_v2.port_1.id
floating_ip = openstack_networking_floatingip_v2.floatingip_1.address
}

output "public_ip_address" {
value = openstack_networking_floatingip_v2.floatingip_1.fixed_ip
}

1. Optional: configure providers

If you have already configured Selectel and OpenStack providers, skip this step.

  1. Make sure that in the control panel you created a service user with the roles member in the Account scope and iam.admin.

  2. Create a directory to store configuration files and a separate file with the .tf extension for configuring providers.

  3. Add the Selectel and OpenStack providers to the provider configuration file:

    terraform {
    required_providers {
    selectel = {
    source = "selectel/selectel"
    version = "~> 6.0"
    }
    openstack = {
    source = "terraform-provider-openstack/openstack"
    version = "2.1.0"
    }
    }
    }

    Here, version is provider versions. The current version can be found in the Selectel documentation (in Terraform Registry and GitHub) and OpenStack (in Terraform Registry and GitHub).

    For more information about products, options, and services that can be managed using providers, see the Selectel and OpenStack Providers instructions.

  4. Initialize the Selectel provider:

    provider "selectel" {
    domain_name = "123456"
    username = "user"
    password = "password"
    auth_region = "ru-7"
    auth_url = "https://cloud.api.selcloud.ru/identity/v3/"
    }

    Where:

    • domain_name — Selectel account ID. It can be found in the control panel in the top-right corner;
    • username — the name of the service user with the member role in the Account access scope and the iam.admin role. You can view it in the control panel: in the top menu, click IAM → Service users section (available only to the account owner and users with the iam.admin role);
    • password — service user password. You can view it when creating the user or change it to a new one;
    • auth_region — pool for authorization in the ru-7 format, do not use pools in the SPB-2 format. The authorization pool might not match the pool in which you create resources. The list of available pools can be found in the Product availability by location instructions.
  5. Create a project:

    resource "selectel_vpc_project_v2" "project_1" {
    name = "project"
    }

    See a detailed description of the selectel_vpc_project_v2 resource.

  6. Create a service user for project access and assign them the member role in the Project access scope:

    resource "selectel_iam_serviceuser_v1" "serviceuser_1" {
    name = "username"
    password = "password"
    role {
    role_name = "member"
    scope = "project"
    project_id = selectel_vpc_project_v2.project_1.id
    }
    }

    Where:

    • username — user name;
    • password — user password. The password must be at least eight characters long and contain uppercase and lowercase Latin letters and digits;
    • project_id — project ID. You can view it in the control panel: from the top menu, click Products and select Cloud Servers → open the project menu → in the row with the desired project, click .

    See a detailed description of the selectel_iam_serviceuser_v1 resource.

  7. Initialize the OpenStack provider:

    provider "openstack" {
    auth_url = "https://cloud.api.selcloud.ru/identity/v3"
    domain_name = "123456"
    tenant_id = selectel_vpc_project_v2.project_1.id
    user_name = selectel_iam_serviceuser_v1.serviceuser_1.name
    password = selectel_iam_serviceuser_v1.serviceuser_1.password
    region = "ru-7"
    }

    Where:

    • domain_name — Selectel account number. You can view it in the control panel in the upper-right corner;
    • region — pool, for example, ru-7. All resources will be created in this pool. The list of available pools can be found in the Product availability by location instructions.
  8. If you create resources while configuring providers, add the depends_on argument for OpenStack resources. For example, for the openstack_networking_network_v2 resource:

    resource "openstack_networking_network_v2" "network_1" {
    name = "private-network"
    admin_state_up = "true"

    depends_on = [
    selectel_vpc_project_v2.project_1,
    selectel_iam_serviceuser_v1.serviceuser_1
    ]
    }
  9. Optional: if you want to use a mirror, create a separate Terraform CLI configuration file and add the following block to it:

    provider_installation {
    network_mirror {
    url = "https://tf-proxy.selectel.ru/mirror/v1/"
    include = ["registry.terraform.io/*/*"]
    }
    direct {
    exclude = ["registry.terraform.io/*/*"]
    }
    }

    For more information about mirror settings, see the CLI Configuration File guide in the HashiCorp documentation.

  10. Open the CLI.

  11. Initialize the Terraform configuration in the directory:

    terraform init
  12. Verify that the configuration files are syntactically correct:

    terraform validate
  13. Format the configuration files:

    terraform fmt
  14. Check which resources will be created:

    terraform plan
  15. Apply the changes and create the resources:

    terraform apply
  16. Confirm creation — enter yes and press Enter. The created resources will appear in the control panel.

  17. If quotas are insufficient to create resources, increase the quotas.

2. Create an SSH key pair

resource "selectel_vpc_keypair_v2" "keypair_1" {
name = "keypair"
public_key = file("~/.ssh/id_rsa.pub")
user_id = selectel_iam_serviceuser_v1.serviceuser_1.id
}

Here, public_key is the path to the public SSH key. If SSH keys have not been generated, create them.

View the detailed description of the selectel_vpc_keypair_v2 resource.

3. Create a private network and a subnet

resource "openstack_networking_network_v2" "network_1" {
name = "private-network"
admin_state_up = "true"
}

resource "openstack_networking_subnet_v2" "subnet_1" {
name = "private-subnet"
network_id = openstack_networking_network_v2.network_1.id
cidr = "192.168.199.0/24"
}

Here cidr is the private subnet CIDR, for example 192.168.199.0/24.

See the detailed resource description:

4. Create a cloud router connected to the internet

A cloud router connected to the internet performs 1:1 NAT for access from a private network to the internet via the router's external IP address.

data "openstack_networking_network_v2" "external_network_1" {
external = true
}

resource "openstack_networking_router_v2" "router_1" {
name = "router"
external_network_id = data.openstack_networking_network_v2.external_network_1.id
}

resource "openstack_networking_router_interface_v2" "router_interface_1" {
router_id = openstack_networking_router_v2.router_1.id
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}

See the detailed resource description:

5. Create a port for the cloud server

resource "openstack_networking_port_v2" "port_1" {
name = "port"
network_id = openstack_networking_network_v2.network_1.id

fixed_ip {
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}
}

See the detailed description of the openstack_networking_port_v2 resource.

6. Get an image

data "openstack_images_image_v2" "image_1" {
name = "Ubuntu 20.04 LTS 64-bit"
most_recent = true
visibility = "public"
}

See the detailed description of the openstack_images_image_v2 data source.

7. Create a bootable network volume

resource "openstack_blockstorage_volume_v3" "volume_1" {
name = "boot-volume-for-server"
size = "5"
image_id = data.openstack_images_image_v2.image_1.id
volume_type = "fast.ru-7b"
availability_zone = "ru-7b"
enable_online_resize = true

lifecycle {
ignore_changes = [image_id]
}

}

8. Create a cloud server


resource "openstack_compute_instance_v2" "server_1" {
name = "server"
flavor_id = "1063"
key_pair = selectel_vpc_keypair_v2.keypair_1.name
availability_zone = "ru-7b"

network {
port = openstack_networking_port_v2.port_1.id
}

lifecycle {
ignore_changes = [image_id]
}

block_device {
uuid = openstack_blockstorage_volume_v3.volume_1.id
source_type = "volume"
destination_type = "volume"
boot_index = 0
}

vendor_options {
ignore_resize_confirmation = true
}
}

Where:

See a detailed description of the openstack_compute_instance_v2 resource.

9. Create a public floating IP address

resource "openstack_networking_floatingip_v2" "floatingip_1" {
pool = "external-network"
}

See the detailed description of the resource openstack_networking_floatingip_v2.

10. Associate the cloud server’s public and private IP addresses

The public floating IP address will be connected to the cloud server port and associated with the private IP.

resource "openstack_networking_floatingip_associate_v2" "association_1" {
port_id = openstack_networking_port_v2.port_1.id
floating_ip = openstack_networking_floatingip_v2.floatingip_1.address
}

See the detailed description of the openstack_networking_floatingip_associate_v2 resource.

11. Get the cloud server’s IP address

output "public_ip_address" {
value = openstack_networking_floatingip_v2.floatingip_1.fixed_ip
}