Terraform config under terraform/ manages the two existing VPS hosts and hands the app to docker-compose, with local state: - prod: the new 48GB/12-core VPS (release branch, thermograph.org), sized larger. - beta: the old VPS 75.119.132.91 (main branch, testing tier), no public domain. - The LAN dev box stays on deploy/deploy-dev.sh (dev branch) — out of Terraform. A reusable module (modules/thermograph-host) SSHes each host to install docker/ compose/ufw (+ Caddy when a domain is set), sync the checkout to the host's branch, render /etc/thermograph.env from Terraform variables (secrets pushed via provisioner content, never on local disk), `docker compose up -d`, and health-check. Named volumes are preserved on re-apply, so the Postgres data is never recreated. Container resources are now env-driven in docker-compose.yml (APP_CPUS/DB_CPUS/ DB_MEMORY/WORKERS) with unchanged defaults, so Terraform can size each host.
175 lines
3.2 KiB
HCL
175 lines
3.2 KiB
HCL
# Per-host inputs (all supplied by the root module's for_each).
|
|
|
|
variable "name" {
|
|
description = "Short host key (e.g. \"prod\", \"dev\"), used in log lines."
|
|
type = string
|
|
}
|
|
|
|
variable "host" {
|
|
description = "IP or hostname to SSH to."
|
|
type = string
|
|
}
|
|
|
|
variable "ssh_user" {
|
|
description = "SSH login user (must be able to sudo)."
|
|
type = string
|
|
}
|
|
|
|
variable "ssh_private_key_path" {
|
|
description = "Path to the private key file for ssh_user."
|
|
type = string
|
|
}
|
|
|
|
variable "role" {
|
|
description = "\"prod\" | \"dev\" — informational."
|
|
type = string
|
|
}
|
|
|
|
variable "git_branch" {
|
|
description = "Branch the host checkout is reset to."
|
|
type = string
|
|
}
|
|
|
|
variable "domain" {
|
|
description = "Public domain. \"\" => no Caddy/TLS (open the app port instead)."
|
|
type = string
|
|
}
|
|
|
|
variable "compose_files" {
|
|
description = "Compose files to layer, in order (dev appends docker-compose.dev.yml)."
|
|
type = list(string)
|
|
}
|
|
|
|
variable "app_dir" {
|
|
description = "Checkout path on the host."
|
|
type = string
|
|
}
|
|
|
|
variable "repo_root" {
|
|
description = "Local repo root, used to hash the compose files for the re-apply trigger."
|
|
type = string
|
|
}
|
|
|
|
variable "repo_url" {
|
|
description = "Git remote to clone from if the host has no checkout yet."
|
|
type = string
|
|
}
|
|
|
|
variable "app_port" {
|
|
description = "Port the app binds / is health-checked on."
|
|
type = number
|
|
}
|
|
|
|
# ---- Sizing -------------------------------------------------------------------
|
|
variable "workers" {
|
|
description = "uvicorn worker count (WORKERS)."
|
|
type = number
|
|
}
|
|
|
|
variable "app_cpus" {
|
|
description = "App container CPU cap (APP_CPUS)."
|
|
type = number
|
|
}
|
|
|
|
variable "db_cpus" {
|
|
description = "DB container CPU cap (DB_CPUS)."
|
|
type = number
|
|
}
|
|
|
|
variable "db_memory" {
|
|
description = "DB container memory cap (DB_MEMORY), e.g. \"8g\"."
|
|
type = string
|
|
}
|
|
|
|
# ---- Secrets rendered into /etc/thermograph.env -------------------------------
|
|
variable "postgres_password" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "auth_secret" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "vapid_private_key" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "vapid_public_key" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "vapid_contact" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "google_verify" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "bing_verify" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "mail_backend" {
|
|
type = string
|
|
}
|
|
|
|
variable "smtp_host" {
|
|
type = string
|
|
}
|
|
|
|
variable "smtp_port" {
|
|
type = string
|
|
}
|
|
|
|
variable "smtp_user" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "smtp_password" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "smtp_starttls" {
|
|
type = string
|
|
}
|
|
|
|
variable "mail_from" {
|
|
type = string
|
|
}
|
|
|
|
variable "mail_reply_to" {
|
|
type = string
|
|
}
|
|
|
|
variable "discord_webhook" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "discord_public_key" {
|
|
type = string
|
|
}
|
|
|
|
variable "discord_app_id" {
|
|
type = string
|
|
}
|
|
|
|
variable "discord_bot_token" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "discord_client_secret" {
|
|
type = string
|
|
sensitive = true
|
|
}
|