Skip to main content

Create a security group and assign it to a server port via Terraform

Last update:

We recommend creating resources in order. If you create all resources at once, Terraform will account for dependencies between resources that you specified in the configuration file. If dependencies are not specified, resources will be created in parallel, which may lead to errors. For instance, a resource required for creating another resource might not have been created yet.


  1. Optional: configure providers.
  2. Create a private network and a subnet.
  3. Create a security group.
  4. Create a rule.
  5. Create a port in the network.
  6. Assign the group to a port.
  7. Create a server.

Configuration files

Example file for configuring providers
terraform {
required_providers {
selectel = {
source = "selectel/selectel"
version = "~> 6.0"
}
openstack = {
source = "terraform-provider-openstack/openstack"
version = "2.1.0"
}
}
}

provider "selectel" {
domain_name = "123456"
username = "user"
password = "password"
auth_region = "ru-9"
auth_url = "https://cloud.api.selcloud.ru/identity/v3/"
}

resource "selectel_vpc_project_v2" "project_1" {
name = "project"
}

resource "selectel_iam_serviceuser_v1" "serviceuser_1" {
name = "username"
password = "password"
role {
role_name = "member"
scope = "project"
project_id = selectel_vpc_project_v2.project_1.id
}
}

provider "openstack" {
auth_url = "https://cloud.api.selcloud.ru/identity/v3"
domain_name = "123456"
tenant_id = selectel_vpc_project_v2.project_1.id
user_name = selectel_iam_serviceuser_v1.serviceuser_1.name
password = selectel_iam_serviceuser_v1.serviceuser_1.password
region = "ru-9"
}
Example file for creating a security group and assigning it to a server port
resource "openstack_networking_network_v2" "network_1" {
name = "network"
port_security_enabled = "true"
}

resource "openstack_networking_subnet_v2" "subnet_1" {
name = "subnet"
network_id = openstack_networking_network_v2.network_1.id
cidr = "192.168.0.0/24"
}

resource "openstack_networking_secgroup_v2" "security_group_1" {
name = "sg"
description = "Test security group"
}

resource "openstack_networking_secgroup_rule_v2" "security_group_rule_1" {
direction = "ingress"
ethertype = "IPv4"
protocol = "tcp"
port_range_min = 443
port_range_max = 443
remote_ip_prefix = "0.0.0.0/0"
security_group_id = openstack_networking_secgroup_v2.security_group_1.id
}

resource "openstack_networking_port_v2" "port_1" {
name = "port"
network_id = openstack_networking_network_v2.network_1.id
admin_state_up = "true"

fixed_ip {
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}
}

resource "openstack_networking_port_secgroup_associate_v2" "security_group_associate_1" {
port_id = openstack_networking_port_v2.port_1.id
security_group_ids = [openstack_networking_secgroup_v2.security_group_1.id]
}

data "openstack_images_image_v2" "image_1" {
name = "Ubuntu 20.04 LTS 64-bit"
most_recent = true
visibility = "public"
}

resource "selectel_vpc_keypair_v2" "keypair_1" {
name = "keypair"
public_key = file("~/.ssh/id_rsa.pub")
user_id = selectel_iam_serviceuser_v1.serviceuser_1.id
}

resource "openstack_blockstorage_volume_v3" "volume_1" {
name = "boot-volume"
size = "5"
image_id = data.openstack_images_image_v2.image_1.id
volume_type = "fast.ru-9a"
availability_zone = "ru-9a"
enable_online_resize = true

lifecycle {
ignore_changes = [image_id]
}

}

resource "openstack_compute_instance_v2" "server_1" {
name = "server"
flavor_id = "4011"
key_pair = selectel_vpc_keypair_v2.keypair_1.name
availability_zone = "ru-9a"

network {
port = openstack_networking_port_v2.port_1.id
}

lifecycle {
ignore_changes = [image_id]
}

block_device {
uuid = openstack_blockstorage_volume_v3.volume_1.id
source_type = "volume"
destination_type = "volume"
boot_index = 0
}

vendor_options {
ignore_resize_confirmation = true
}
}

1. Optional: configure providers

If you have already configured the Selectel and OpenStack providers, skip this step.

  1. Make sure that in the control panel you have created a service user with the member role in the Account access scope and iam.admin.

  2. Create a directory to store configuration files and a separate file with the .tf extension to configure providers.

  3. Add the Selectel and OpenStack providers to the file for provider configuration:

    terraform {
    required_providers {
    selectel = {
    source = "selectel/selectel"
    version = "~> 7.1.0"
    }
    openstack = {
    source = "terraform-provider-openstack/openstack"
    version = "2.1.0"
    }
    }
    }

    Here version is the provider version. The current version can be found in the Selectel documentation (in Terraform Registry and GitHub) and OpenStack (in Terraform Registry and GitHub).

    For more information about products, services, and features that can be managed using providers, see the Selectel and OpenStack Providers guide.

  4. Initialize the Selectel provider:

    provider "selectel" {
    domain_name = "123456"
    username = "user"
    password = "password"
    auth_region = "ru-9"
    auth_url = "https://cloud.api.selcloud.ru/identity/v3/"
    }

    Where:

    • domain_name — Selectel account number. You can find it in the control panel in the top-right corner;
    • username — name of the service user with the member role in the Account access scope and iam.admin. You can view it in the control panel: in the top menu, click IAMService Users section (the section is only available to the Account Owner and a user with the iam.admin role);
    • password — service user password. You can view it when creating the user or change it to a new one;
    • auth_regionpool for authorization, for example, ru-9. You can create resources in other pools. A list of available pools can be found in the Availability Matrix guide.
  5. Create a project:

    resource "selectel_vpc_project_v2" "project_1" {
    name = "project"
    }

    See a detailed description of the selectel_vpc_project_v2 resource.

  6. Create a service user to access the project and assign them the member role in the Project access scope:

    resource "selectel_iam_serviceuser_v1" "serviceuser_1" {
    name = "username"
    password = "password"
    role {
    role_name = "member"
    scope = "project"
    project_id = selectel_vpc_project_v2.project_1.id
    }
    }

    Where:

    • username — username;

    • password — user password. The password must be at least 20 characters long and include at least:

      • one uppercase and one lowercase Latin letter (A-Z, a-z);
      • one digit (0-9);
      • one special character from the ASCII Printable 7-Bit Special Characters list:
        !"#$%&'()*+,-./:;<=>?@[]^_{|}~;
    • project_id — project ID. You can find it in the control panel: in the top menu, click Products and select Cloud Servers → open the projects menu → in the row of the target project, click .

    See a detailed description of the selectel_iam_serviceuser_v1 resource.

  7. Initialize the OpenStack provider:

    provider "openstack" {
    auth_url = "https://cloud.api.selcloud.ru/identity/v3"
    domain_name = "123456"
    tenant_id = selectel_vpc_project_v2.project_1.id
    user_name = selectel_iam_serviceuser_v1.serviceuser_1.name
    password = selectel_iam_serviceuser_v1.serviceuser_1.password
    region = "ru-9"
    }

    Where:

    • domain_name — Selectel account number. You can find it in the control panel in the top-right corner;
    • regionpool, for example, ru-9. All resources will be created in this pool. A list of available pools can be found in the Availability Matrix guide.
  8. If you are creating resources while configuring providers, add the depends_on argument for OpenStack resources. For example, for the openstack_networking_network_v2 resource:

    resource "openstack_networking_network_v2" "network_1" {
    name = "private-network"
    admin_state_up = "true"

    depends_on = [
    selectel_vpc_project_v2.project_1,
    selectel_iam_serviceuser_v1.serviceuser_1
    ]
    }
  9. Optional: if you want to use a mirror, create a separate Terraform CLI configuration file and add the following block to it:

    provider_installation {
    network_mirror {
    url = "https://tf-proxy.selectel.ru/mirror/v1/"
    include = ["registry.terraform.io/*/*"]
    }
    direct {
    exclude = ["registry.terraform.io/*/*"]
    }
    }

    Read more about mirror settings in the CLI Configuration File guide in the HashiCorp documentation.

  10. Open the CLI.

  11. Initialize the Terraform configuration in the directory:

    terraform init
  12. Verify that the configuration files are syntactically correct:

    terraform validate
  13. Format the configuration files:

    terraform fmt
  14. Check which resources will be created:

    terraform plan
  15. Apply the changes and create the resources:

    terraform apply
  16. Confirm creation — enter yes and press Enter. The created resources will appear in the control panel.

  17. If quotas were insufficient to create the resources, increase the quotas.

2. Create a private network and a subnet

resource "openstack_networking_network_v2" "network_1" {
name = "network"
port_security_enabled = "true"
}

resource "openstack_networking_subnet_v2" "subnet_1" {
name = "subnet"
network_id = openstack_networking_network_v2.network_1.id
cidr = "192.168.0.0/24"
}

3. Create a security group

resource "openstack_networking_secgroup_v2" "security_group_1" {
name = "sg"
description = "Test security group"
}

See the detailed resource description for openstack_networking_secgroup_v2.

4. Create a rule

resource "openstack_networking_secgroup_rule_v2" "security_group_rule_1" {
direction = "ingress"
ethertype = "IPv4"
protocol = "tcp"
port_range_min = 443
port_range_max = 443
remote_ip_prefix = "0.0.0.0/0"
security_group_id = openstack_networking_secgroup_v2.security_group_1.id
}

Where:

  • direction — traffic direction: ingress for incoming traffic, egress for outgoing;
  • ethertype — protocol type: IPv4 or IPv6;
  • protocol — protocol, for example tcp;
  • port_range_min — the first port in the range of ports allowed for connection, for example 443;
  • port_range_max — the last port in the range;
  • remote_ip_prefix — IP addresses from which traffic is allowed, for example 0.0.0.0/0.

See the detailed resource description for openstack_networking_secgroup_rule_v2.

5. Create a port in the network

resource "openstack_networking_port_v2" "port_1" {
name = "port"
network_id = openstack_networking_network_v2.network_1.id

fixed_ip {
subnet_id = openstack_networking_subnet_v2.subnet_1.id
}
}

See the detailed description of the openstack_networking_port_v2 resource.

6. Assign the group to a port

resource "openstack_networking_port_secgroup_associate_v2" "security_group_associate_1" {
port_id = openstack_networking_port_v2.port_1.id
security_group_ids = [openstack_networking_secgroup_v2.security_group_1.id]
}

See the detailed resource description for openstack_networking_secgroup_associate_v2.

7. Create a cloud server

1. Add a public SSH key

resource "selectel_vpc_keypair_v2" "keypair_1" {
name = "keypair"
public_key = file("~/.ssh/id_rsa.pub")
user_id = selectel_iam_serviceuser_v1.serviceuser_1.id
}

Here public_key is the path to the public SSH key. If SSH keys are not generated, create them.

See the detailed description of the selectel_vpc_keypair_v2 resource.

2. Get an image⁠

data "openstack_images_image_v2" "image_1" {
name = "Ubuntu 20.04 LTS 64-bit"
most_recent = true
visibility = "public"
}

See the detailed description of the openstack_images_image_v2 data source.

3. Create a bootable network volume

resource "openstack_blockstorage_volume_v3" "volume_1" {
name = "boot-volume-for-server"
size = "5"
image_id = data.openstack_images_image_v2.image_1.id
volume_type = "fast.ru-9a"
availability_zone = "ru-9a"
enable_online_resize = true

lifecycle {
ignore_changes = [image_id]
}

}

Here:

See the detailed resource description in openstack_blockstorage_volume_v3.

4. Create a cloud server

resource "openstack_compute_instance_v2" "server_1" {
name = "server"
flavor_id = "1015"
key_pair = selectel_vpc_keypair_v2.keypair_1.name
availability_zone = "ru-9a"

network {
port = openstack_networking_port_v2.port_1.id
}

lifecycle {
ignore_changes = [image_id]
}

block_device {
uuid = openstack_blockstorage_volume_v3.volume_1.id
source_type = "volume"
destination_type = "volume"
boot_index = 0
}

vendor_options {
ignore_resize_confirmation = true
}
}

Where:

  • availability_zonepool segment in which the cloud server will be created, for example ru-9a. The list of available pool segments can be viewed in the Availability Matrix;
  • flavor_id — flavor ID. Flavors correspond to cloud server configurations and define the number of vCPUs, RAM, and the size of the local disk (optional) for the server. You can use fixed-configuration flavors. For example, 1015 is the ID for creating a server with a Standard line fixed configuration with 4 vCPUs and 16 GB of RAM in the ru-9 pool. A list of flavors is available in the table List of fixed-configuration flavors in all pools.

See the detailed description of the openstack_compute_instance_v2 resource.