Terraform config under terraform/ manages the two existing VPS hosts and hands the app to docker-compose, with local state: - prod: the new 48GB/12-core VPS (release branch, thermograph.org), sized larger. - beta: the old VPS 75.119.132.91 (main branch, testing tier), no public domain. - The LAN dev box stays on deploy/deploy-dev.sh (dev branch) — out of Terraform. A reusable module (modules/thermograph-host) SSHes each host to install docker/ compose/ufw (+ Caddy when a domain is set), sync the checkout to the host's branch, render /etc/thermograph.env from Terraform variables (secrets pushed via provisioner content, never on local disk), `docker compose up -d`, and health-check. Named volumes are preserved on re-apply, so the Postgres data is never recreated. Container resources are now env-driven in docker-compose.yml (APP_CPUS/DB_CPUS/ DB_MEMORY/WORKERS) with unchanged defaults, so Terraform can size each host.
15 lines
350 B
Text
15 lines
350 B
Text
# Terraform working dir + plugins
|
|
.terraform/
|
|
|
|
# Local state (holds secrets — never commit)
|
|
*.tfstate
|
|
*.tfstate.*
|
|
crash.log
|
|
crash.*.log
|
|
|
|
# tfvars carry real secrets — ignore all except the checked-in example
|
|
*.tfvars
|
|
!*.tfvars.example
|
|
|
|
# The dependency lock IS committed (pins provider versions across machines) — keep it.
|
|
!.terraform.lock.hcl
|