Skip to content

feat: STACKIT hub and spoke architecture#230

Merged
henryde merged 4 commits into
mainfrom
feature/stackit-hub-spoke
Jul 23, 2026
Merged

feat: STACKIT hub and spoke architecture#230
henryde merged 4 commits into
mainfrom
feature/stackit-hub-spoke

Conversation

@henryde

@henryde henryde commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Scorecard Check

Scorecard run on commit 4580b1e5c464d0bfb48e498e4e18c61f2380dc2a relative to origin/main

📊 meshstack-hub Module Scorecard

Generated: 2026-07-23 | Modules scanned: 3 | Categories: 5

📋 Per-Module Category Summary

Score per category per building block. n/a = category does not apply to this module.

Module Overall Core Structure Integration Azure Backplane STACKIT Backplane Testing
stackit/network 🟢 92% 🟢 100% 🟢 100% n/a 🟢 100% 🔴 33%
stackit/network-area 🟢 92% 🟢 100% 🟢 100% n/a 🟢 100% 🔴 33%
stackit/project 🟢 81% 🟢 100% 🟡 79% n/a 🟢 100% 🔴 33%

⚠️ 3 modules have failing checks — failing categories are expanded below.

Core Structure — ✅ all passing

Basic module file structure and documentation — applies to 3 modules

Module Score 📦 🔗 📋 📝 🖼️ 📌 🔒
stackit/network 🟢 100%
stackit/network-area 🟢 100%
stackit/project 🟢 100%

Core Structure — Summary

Emoji Criterion Coverage Status
📦 buildingblock/ directory exists 3/3 🟢 100%
🔗 meshstack_integration.tf present 3/3 🟢 100%
📋 buildingblock/APP_TEAM_README.md present (no-integration fallback) n/a
📝 buildingblock/README.md with YAML front-matter 3/3 🟢 100%
🖼️ buildingblock/logo.png included 3/3 🟢 100%
📌 buildingblock/versions.tf present 3/3 🟢 100%
🔒 Provider versions use minimum constraint (>=) 3/3 🟢 100%
Integration — some checks failing

meshstack_integration.tf conventions — applies to 3 modules

Module Score 🏷️ 🏢 📤 🔌 📎 🔀 📋 🏷️ 🧱 📖 📝 📊 🚫 🔄
stackit/network 🟢 100%
stackit/network-area 🟢 100%
stackit/project 🟡 79%

Integration — Summary

Emoji Criterion Coverage Status
🏷️ variable "hub" in integration 3/3 🟢 100%
🏢 variable "meshstack" in integration 3/3 🟢 100%
📤 building_block_definition output exposed 3/3 🟢 100%
🔌 meshcloud/meshstack in required_providers 3/3 🟢 100%
📎 backplane source uses var.hub.git_ref 3/3 🟢 100%
🔀 ref_name uses var.hub.git_ref 3/3 🟢 100%
📋 version_spec.draft uses var.hub.bbd_draft 3/3 🟢 100%
🏷️ BBD metadata.tags forwards var.meshstack.tags 3/3 🟢 100%
🧱 BBD input argument vars with optional() have explicit defaults 3/3 🟢 100%
📖 BBD readme field present 2/3 🟡 67%
📝 BBD readme starts with plain-text description (no heading) 2/3 🟡 67%
📊 BBD readme has shared responsibility table (✅/❌) 2/3 🟡 67%
🚫 No documentation_md output in backplane 3/3 🟢 100%
🔄 meshstack_platform has lifecycle ignore_changes = [availability] 1/1 🟢 100%
Azure Backplane — not applicable

Azure UAMI-based automation principal conventions — applies to 0 modules

No applicable modules.

STACKIT Backplane — ✅ all passing

STACKIT WIF-based automation principal conventions — applies to 3 modules

Module Score 🔐 🚫 📤
stackit/network 🟢 100%
stackit/network-area 🟢 100%
stackit/project 🟢 100%

STACKIT Backplane — Summary

Emoji Criterion Coverage Status
🔐 Uses stackit_service_account_federated_identity_provider 3/3 🟢 100%
🚫 No stackit_service_account_key resource 3/3 🟢 100%
📤 Outputs service_account_email (not key) 3/3 🟢 100%
Buildingblock provider uses use_oidc = true 3/3 🟢 100%
Testing — some checks failing

End-to-end test coverage — applies to 3 modules

Module Score ⚙️ 🧪
stackit/network 🔴 33%
stackit/network-area 🔴 33%
stackit/project 🔴 33%

Testing — Summary

Emoji Criterion Coverage Status
⚙️ backplane/ directory (optional tier) 3/3 🟢 100%
🧪 e2e/ test directory exists 0/3 🔴 0%
e2e/ contains .tftest.hcl files 0/3 🔴 0%

📈 Overall Summary

Overall Average Score: 88%

Score Distribution

  • 🟢 High maturity (≥80%): 3 modules
  • 🟡 Medium maturity (50–79%): 0 modules
  • 🔴 Low maturity (<50%): 0 modules

@aws-amplify-eu-central-1

Copy link
Copy Markdown

This pull request is automatically being deployed by Amplify Hosting (learn more).

Access this pull request here: https://pr-230.d1o16zfeoh2slu.amplifyapp.com

@henryde
henryde force-pushed the feature/stackit-hub-spoke branch 8 times, most recently from 28fd029 to 5e6bfec Compare July 23, 2026 07:33
@henryde
henryde marked this pull request as ready for review July 23, 2026 08:32
@henryde
henryde requested review from Copilot and grubmeshi July 23, 2026 08:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a STACKIT “hub-and-spoke” reference architecture that bootstraps a sandbox platform plus centralized IPAM (network area hub) and a self-service routed-network building block (spokes), and extends the existing STACKIT sandbox landing zone to optionally propagate a network-area tag into tenant project labels.

Changes:

  • Add new reference-architectures/stackit-hub-spoke runnable reference architecture (meshStack integration + composed building block implementation + docs).
  • Extend stackit-sandbox-landingzone building block to optionally forward a meshStack landing zone tag as the STACKIT networkArea project label input.
  • Fix modules/stackit/network-area to avoid empty-list vs null inconsistencies for default_nameservers.

Reviewed changes

Copilot reviewed 13 out of 14 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
reference-architectures/stackit-sandbox-landingzone/meshstack_integration.tf Updates the BBD symbol URL to the reference-architecture location.
reference-architectures/stackit-sandbox-landingzone/buildingblock/variables.tf Adds network_area_tag_name variable (optional forwarding to nested integration).
reference-architectures/stackit-sandbox-landingzone/buildingblock/README.md Updates generated terraform-docs outputs (inputs table includes new variable).
reference-architectures/stackit-sandbox-landingzone/buildingblock/main.tf Forwards network_area_tag_name into the nested STACKIT integration.
reference-architectures/stackit-hub-spoke/README.md Adds reference-architecture documentation (overview, diagram, responsibilities).
reference-architectures/stackit-hub-spoke/meshstack_integration.tf Registers the “Hub and Spoke Network” BBD (inputs/outputs, inline readme).
reference-architectures/stackit-hub-spoke/buildingblock/versions.tf Declares Terraform/provider constraints for the composed building block.
reference-architectures/stackit-hub-spoke/buildingblock/variables.tf Defines inputs for foundation bootstrap + hub/spoke network parameters.
reference-architectures/stackit-hub-spoke/buildingblock/README.md Adds generated terraform-docs for the new composed building block.
reference-architectures/stackit-hub-spoke/buildingblock/provider.tf Configures the STACKIT provider for the composed building block.
reference-architectures/stackit-hub-spoke/buildingblock/outputs.tf Exposes key outputs from the foundation module.
reference-architectures/stackit-hub-spoke/buildingblock/main.tf Composes foundation + network-area + network modules; provisions hub NA instance; creates networked landing zone tagged with NA id.
modules/stackit/network-area/buildingblock/main.tf Uses a length-check to set default_nameservers to null only when empty.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread reference-architectures/stackit-hub-spoke/buildingblock/README.md Outdated

@grubmeshi grubmeshi left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM from technical point of view (will actually try it out later, once you've addressed little remarks)

Comment thread modules/stackit/network-area/buildingblock/main.tf
Comment thread reference-architectures/stackit-hub-spoke/buildingblock/variables.tf Outdated
Comment thread reference-architectures/stackit-hub-spoke/buildingblock/variables.tf Outdated
Comment thread reference-architectures/stackit-hub-spoke/meshstack_integration.tf
Comment thread reference-architectures/stackit-hub-spoke/buildingblock/main.tf Outdated
Comment thread reference-architectures/stackit-hub-spoke/buildingblock/main.tf Outdated
Comment thread reference-architectures/stackit-hub-spoke/buildingblock/main.tf Outdated
Comment thread reference-architectures/stackit-hub-spoke/buildingblock/main.tf Outdated
@henryde
henryde force-pushed the feature/stackit-hub-spoke branch from 5e6bfec to 134c862 Compare July 23, 2026 10:15
@henryde
henryde force-pushed the feature/stackit-hub-spoke branch from 650a205 to 8e52801 Compare July 23, 2026 12:41
@henryde
henryde merged commit 5c2482c into main Jul 23, 2026
3 checks passed
@henryde
henryde deleted the feature/stackit-hub-spoke branch July 23, 2026 12:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants