Content-change pass following the extraction from the app monorepo (this repo
now stands alone, sourced via git filter-repo to preserve history):
- terraform/variables.tf, secrets.tf, modules/thermograph-host: remove every
app-secret Terraform variable (postgres_password, auth_secret, VAPID keys,
registry_token, Discord/SMTP creds, ...) and the random_password/random_id
generators. The SOPS+age vault (deploy/secrets/*.yaml) is now the sole
source of app secrets, rendered at deploy time by deploy/render-secrets.sh;
Terraform renders only a non-secret /etc/thermograph-topology.env (sizing,
routing) via the renamed thermograph-topology.env.tftpl template.
- hosts gains a required app_image_tag field: the host's own checkout is now
this infra repo, not the app repo, so there is no "current commit" to
derive an image tag from — every host pins one explicitly. repo_url now
points at this repo (private; typically needs an embedded read token).
- deploy.sh: IMAGE_TAG is now required from the environment instead of
derived via `git rev-parse HEAD` of the (now infra-repo) checkout, which
would have silently resolved to the wrong or a nonexistent tag.
- New terraform/modules/gcp-host: creates a GCE VM + minimal VPC/firewall
only, then feeds its IP into the same thermograph-host module every
SSH-managed host already uses — one provisioning path regardless of how a
host came to exist. var.gcp_hosts defaults to {}, so no google_* resource
is planned and the provider is never invoked without it (verified: plan
and validate succeed with no GCP credentials configured).
- terraform/README.md, ACCESS.md (renamed from INFRA.md), README.md: updated
for the new secrets model, the GCP scaffold, and this repo's own identity.
Verified: terraform fmt/validate/init clean; plan succeeds against realistic
dummy hosts (prod+beta shape) and against a populated gcp_hosts entry (plans
6 resources with no live credentials, confirming the composition wires
correctly end to end).
135 lines
4 KiB
HCL
135 lines
4 KiB
HCL
# Per-host inputs (all supplied by the root module's for_each).
|
|
|
|
variable "name" {
|
|
description = "Short host key (e.g. \"prod\", \"dev\"), used in log lines."
|
|
type = string
|
|
}
|
|
|
|
variable "host" {
|
|
description = "IP or hostname to SSH to."
|
|
type = string
|
|
}
|
|
|
|
variable "ssh_user" {
|
|
description = "SSH login user (must be able to sudo)."
|
|
type = string
|
|
}
|
|
|
|
variable "ssh_private_key_path" {
|
|
description = "Path to the private key file for ssh_user."
|
|
type = string
|
|
}
|
|
|
|
variable "role" {
|
|
description = "\"prod\" | \"dev\" — informational."
|
|
type = string
|
|
}
|
|
|
|
variable "git_branch" {
|
|
description = "This INFRA repo's branch the host checkout is reset to (independent of which app image is deployed — see app_image_tag)."
|
|
type = string
|
|
}
|
|
|
|
variable "app_image_tag" {
|
|
description = "App image tag to pull, e.g. \"sha-<12 hex>\" (build-push.yml's tag for the app-repo commit) or a semver tag. The host has no app-repo checkout to derive this from, so it's always explicit."
|
|
type = string
|
|
}
|
|
|
|
variable "domain" {
|
|
description = "Public domain. \"\" => no Caddy/TLS (open the app port instead)."
|
|
type = string
|
|
}
|
|
|
|
variable "compose_files" {
|
|
description = "Compose files to layer, in order (dev appends docker-compose.dev.yml)."
|
|
type = list(string)
|
|
}
|
|
|
|
variable "openmeteo" {
|
|
description = "Self-host the ERA5 archive: layer docker-compose.openmeteo.yml + provision the host rclone mount."
|
|
type = bool
|
|
default = false
|
|
}
|
|
|
|
variable "om_data_dir" {
|
|
description = "Host rclone mount point for the archive bucket (OM_DATA_DIR the overlay bind-mounts)."
|
|
type = string
|
|
default = "/mnt/om-archive"
|
|
}
|
|
|
|
variable "om_bucket_remote" {
|
|
description = "rclone remote:path for the archive bucket (mounted at om_data_dir)."
|
|
type = string
|
|
default = ""
|
|
}
|
|
|
|
variable "om_rclone_conf" {
|
|
description = "rclone.conf contents installed to /etc/rclone/rclone.conf. Sensitive."
|
|
type = string
|
|
default = ""
|
|
sensitive = true
|
|
}
|
|
|
|
variable "om_vfs_cache_max" {
|
|
description = "rclone --vfs-cache-max-size for the mount's on-disk hot cache."
|
|
type = string
|
|
default = "80G"
|
|
}
|
|
|
|
variable "app_dir" {
|
|
description = "Checkout path on the host."
|
|
type = string
|
|
}
|
|
|
|
variable "repo_root" {
|
|
description = "Local repo root, used to hash the compose files for the re-apply trigger."
|
|
type = string
|
|
}
|
|
|
|
variable "repo_url" {
|
|
description = "Git remote to clone from if the host has no checkout yet."
|
|
type = string
|
|
}
|
|
|
|
variable "app_port" {
|
|
description = "Port backend binds / is health-checked on."
|
|
type = number
|
|
}
|
|
|
|
variable "frontend_port" {
|
|
description = "Port the frontend SSR service binds / is health-checked on (repo-split Stage 4). Loopback-only, never opened in ufw -- reached via Caddy's path-split or backend's own reverse-proxy fallback, never directly."
|
|
type = number
|
|
default = 8080
|
|
}
|
|
|
|
# ---- Sizing -------------------------------------------------------------------
|
|
variable "workers" {
|
|
description = "uvicorn worker count (WORKERS)."
|
|
type = number
|
|
}
|
|
|
|
variable "app_cpus" {
|
|
description = "App container CPU cap (APP_CPUS)."
|
|
type = number
|
|
}
|
|
|
|
variable "db_cpus" {
|
|
description = "DB container CPU cap (DB_CPUS)."
|
|
type = number
|
|
}
|
|
|
|
variable "db_memory" {
|
|
description = "DB container memory cap (DB_MEMORY), e.g. \"8g\"."
|
|
type = string
|
|
}
|
|
|
|
variable "timescaledb_tag" {
|
|
description = "TimescaleDB image tag (TIMESCALEDB_TAG), e.g. \"2.17.2-pg18\". \"latest-pg18\" (the default) matches today's behavior; pin an exact minor before any host could ever replicate with another."
|
|
type = string
|
|
default = "latest-pg18"
|
|
}
|
|
|
|
# Secrets (POSTGRES_PASSWORD, THERMOGRAPH_AUTH_SECRET, VAPID keys, REGISTRY_TOKEN,
|
|
# Discord/SMTP credentials, ...) are no longer Terraform variables -- they're
|
|
# rendered at deploy time from the SOPS+age vault (deploy/secrets/*.yaml) by
|
|
# deploy/render-secrets.sh, which deploy.sh calls. See main.tf's remote-exec step 3.
|