Skip to content

Support standalone bastion deployments independently of platform Kubernetes #87

Description

@lweberru

The Configurator exposes platform_kubernetes[*].debug_bastion, but users also need a bastion without a Kubernetes cluster.

Current root wiring calls src/modules/debug-bastion only through src/modules/platform-kubernetes/5-debug-bastion.tf, using the cluster project and SNA network. Moving the UI field alone would misrepresent the deployment contract.

Proposed scope:

  • Add an independent root-level bastion configuration with explicit project/network/region references.
  • Define supported SNA/network combinations and SSH/public-IP access explicitly.
  • Preserve existing cluster-bound resource addresses; document opt-in state migration instead of recreating machines.
  • Add native plan tests for independent use and invalid network references.
  • Expose the independent component in Configurator only when supported by the pinned Accelerator contract.

This does not solve private Kubernetes runner reachability (#37).

Activity

  1. added
    area:acceleratorAccelerator Terraform/OpenTofu roots, modules and examples
    priority:p2Important improvement; schedule after P1 and prerequisites
    effort:mSeveral components or contract changes; estimate excludes external waiting
    enhancementNew feature or request
    on Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:acceleratorAccelerator Terraform/OpenTofu roots, modules and exampleseffort:mSeveral components or contract changes; estimate excludes external waitingenhancementNew feature or requestpriority:p2Important improvement; schedule after P1 and prerequisites

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions