# Per-host inputs (all supplied by the root module's for_each). variable "name" { description = "Short host key (e.g. \"prod\", \"dev\"), used in log lines." type = string } variable "host" { description = "IP or hostname to SSH to." type = string } variable "ssh_user" { description = "SSH login user (must be able to sudo)." type = string } variable "ssh_private_key_path" { description = "Path to the private key file for ssh_user." type = string } variable "role" { description = "\"prod\" | \"beta\" | \"dev\" — informational. One module instance is one (host, environment) pair, so vps2 (which runs both prod and beta) gets two instances, each with its own role/app_dir/image tags -- see the root module's `hosts` variable." type = string } variable "git_branch" { description = "This INFRA repo's branch the host checkout is reset to (independent of which app images are deployed — see backend_image_tag / frontend_image_tag)." type = string } variable "backend_image_tag" { description = "Backend image tag to pull (emi/thermograph-backend/app), e.g. \"sha-<12 hex>\" (build-push.yml's tag for the backend-repo commit) or a semver tag. The host has no app-repo checkout to derive this from, so it's always explicit." type = string } variable "frontend_image_tag" { description = "Frontend image tag to pull (emi/thermograph-frontend/app), e.g. \"sha-<12 hex>\" (build-push.yml's tag for the frontend-repo commit) or a semver tag. Always explicit, same as backend_image_tag." type = string } variable "domain" { description = "Public domain. \"\" => no Caddy/TLS (open the app port instead)." type = string } variable "compose_files" { description = "Compose files to layer, in order (dev appends docker-compose.dev.yml)." type = list(string) } variable "openmeteo" { description = "Self-host the ERA5 archive: layer docker-compose.openmeteo.yml + provision the host rclone mount." type = bool default = false } variable "om_data_dir" { description = "Host rclone mount point for the archive bucket (OM_DATA_DIR the overlay bind-mounts)." type = string default = "/mnt/om-archive" } variable "om_bucket_remote" { description = "rclone remote:path for the archive bucket (mounted at om_data_dir)." type = string default = "" } variable "om_rclone_conf" { description = "rclone.conf contents installed to /etc/rclone/rclone.conf. Sensitive." type = string default = "" sensitive = true } variable "om_vfs_cache_max" { description = "rclone --vfs-cache-max-size for the mount's on-disk hot cache." type = string default = "80G" } variable "app_dir" { description = "Checkout path on the host." type = string } variable "repo_root" { description = "Local repo root, used to hash the compose files for the re-apply trigger." type = string } variable "repo_url" { description = "Git remote to clone from if the host has no checkout yet." type = string } variable "app_port" { description = "Port backend binds / is health-checked on." type = number } variable "frontend_port" { description = "Port the frontend SSR service binds / is health-checked on (repo-split Stage 4). Loopback-only, never opened in ufw -- reached via Caddy's path-split or backend's own reverse-proxy fallback, never directly." type = number default = 8080 } # ---- Sizing ------------------------------------------------------------------- variable "workers" { description = "uvicorn worker count (WORKERS)." type = number } variable "app_cpus" { description = "App container CPU cap (APP_CPUS)." type = number } variable "db_cpus" { description = "DB container CPU cap (DB_CPUS)." type = number } variable "db_memory" { description = "DB container memory cap (DB_MEMORY), e.g. \"8g\"." type = string } variable "timescaledb_tag" { description = "TimescaleDB image tag (TIMESCALEDB_TAG), e.g. \"2.17.2-pg18\". \"latest-pg18\" (the default) matches today's behavior; pin an exact minor before any host could ever replicate with another." type = string default = "latest-pg18" } # Secrets (POSTGRES_PASSWORD, THERMOGRAPH_AUTH_SECRET, VAPID keys, REGISTRY_TOKEN, # Discord/SMTP credentials, ...) are no longer Terraform variables -- they're # rendered at deploy time from the SOPS+age vault (deploy/secrets/*.yaml) by # deploy/render-secrets.sh, which deploy.sh calls. See main.tf's remote-exec step 3.