thermograph/terraform/modules/thermograph-host/variables.tf
Emi Griffith a26ca72834 Self-host the ERA5 archive via Open-Meteo (object storage) (#224)
Get the 45-year historical record off the rate-limited public Open-Meteo
archive API by running a private Open-Meteo instance that serves the
era5_seamless blend (0.1° ERA5-Land + 0.25° ERA5 for gusts) from the
compressed .om archive in object storage, mounted on the host with rclone.

- climate.py: make ARCHIVE_URL env-driven (THERMOGRAPH_ARCHIVE_URL) and pin
  models=era5_seamless on the archive fetches only, so a self-hosted instance
  serves the same 0.1° resolution; forecast path unchanged. The public API's
  default is already seamless, so dev/beta (URL unset) behave identically.
- docker-compose.openmeteo.yml: open-meteo-api + two rolling sync workers
  (era5_land 0.1°, era5 0.25° for gusts), bind-mounting the object-storage
  mount; the overlay points the app at the local instance.
- Makefile: om-up / om-down / om-backfill (one-time full-history backfill).
- Terraform: per-host openmeteo flag layers the overlay, renders OM_DATA_DIR,
  and provisions the host rclone systemd mount from the bucket credentials.
- deploy/openmeteo: operator runbook + rclone mount unit template.
2026-07-20 13:16:56 +00:00

206 lines
4 KiB
HCL

# Per-host inputs (all supplied by the root module's for_each).
variable "name" {
description = "Short host key (e.g. \"prod\", \"dev\"), used in log lines."
type = string
}
variable "host" {
description = "IP or hostname to SSH to."
type = string
}
variable "ssh_user" {
description = "SSH login user (must be able to sudo)."
type = string
}
variable "ssh_private_key_path" {
description = "Path to the private key file for ssh_user."
type = string
}
variable "role" {
description = "\"prod\" | \"dev\" — informational."
type = string
}
variable "git_branch" {
description = "Branch the host checkout is reset to."
type = string
}
variable "domain" {
description = "Public domain. \"\" => no Caddy/TLS (open the app port instead)."
type = string
}
variable "compose_files" {
description = "Compose files to layer, in order (dev appends docker-compose.dev.yml)."
type = list(string)
}
variable "openmeteo" {
description = "Self-host the ERA5 archive: layer docker-compose.openmeteo.yml + provision the host rclone mount."
type = bool
default = false
}
variable "om_data_dir" {
description = "Host rclone mount point for the archive bucket (OM_DATA_DIR the overlay bind-mounts)."
type = string
default = "/mnt/om-archive"
}
variable "om_bucket_remote" {
description = "rclone remote:path for the archive bucket (mounted at om_data_dir)."
type = string
default = ""
}
variable "om_rclone_conf" {
description = "rclone.conf contents installed to /etc/rclone/rclone.conf. Sensitive."
type = string
default = ""
sensitive = true
}
variable "om_vfs_cache_max" {
description = "rclone --vfs-cache-max-size for the mount's on-disk hot cache."
type = string
default = "80G"
}
variable "app_dir" {
description = "Checkout path on the host."
type = string
}
variable "repo_root" {
description = "Local repo root, used to hash the compose files for the re-apply trigger."
type = string
}
variable "repo_url" {
description = "Git remote to clone from if the host has no checkout yet."
type = string
}
variable "app_port" {
description = "Port the app binds / is health-checked on."
type = number
}
# ---- Sizing -------------------------------------------------------------------
variable "workers" {
description = "uvicorn worker count (WORKERS)."
type = number
}
variable "app_cpus" {
description = "App container CPU cap (APP_CPUS)."
type = number
}
variable "db_cpus" {
description = "DB container CPU cap (DB_CPUS)."
type = number
}
variable "db_memory" {
description = "DB container memory cap (DB_MEMORY), e.g. \"8g\"."
type = string
}
# ---- Secrets rendered into /etc/thermograph.env -------------------------------
variable "postgres_password" {
type = string
sensitive = true
}
variable "auth_secret" {
type = string
sensitive = true
}
variable "vapid_private_key" {
type = string
sensitive = true
}
variable "vapid_public_key" {
type = string
sensitive = true
}
variable "vapid_contact" {
type = string
sensitive = true
}
variable "google_verify" {
type = string
sensitive = true
}
variable "bing_verify" {
type = string
sensitive = true
}
variable "mail_backend" {
type = string
}
variable "smtp_host" {
type = string
}
variable "smtp_port" {
type = string
}
variable "smtp_user" {
type = string
sensitive = true
}
variable "smtp_password" {
type = string
sensitive = true
}
variable "smtp_starttls" {
type = string
}
variable "mail_from" {
type = string
}
variable "mail_reply_to" {
type = string
}
variable "discord_webhook" {
type = string
sensitive = true
}
variable "discord_public_key" {
type = string
}
variable "discord_app_id" {
type = string
}
variable "discord_bot_token" {
type = string
sensitive = true
}
variable "discord_client_secret" {
type = string
sensitive = true
}