Terraform generates the secrets that have no external meaning
(POSTGRES_PASSWORD, AUTH_SECRET, METRICS_TOKEN, INDEXNOW_KEY) via the random
provider instead of requiring the operator to hand-generate and paste each
into terraform.tfvars. Each is pinned with a static keepers value (secrets.tf)
so apply never regenerates a value already in use - the exact incident class
this guards against: every session invalidated, the app<->DB password
mismatched. Rotation is now a deliberate keepers edit, never a side effect.
postgres_password/auth_secret move from required inputs to optional (default
"") - explicit var wins when supplied (seeding an EXISTING live secret during
a migration onto Terraform, hop-1 cutover runbook Stage 0), else Terraform
generates and owns it. metrics_token/indexnow_key are new: neither existed in
Terraform before, both previously left for the app's own fallback generation.
VAPID deliberately stays a required, non-generated input - an EC keypair
where regeneration breaks every existing push subscription outright, unlike
an opaque token.
Sizing tiers: a locals.sizes t-shirt map (nano/small/medium/large ->
{workers, app_cpus, db_cpus, db_memory}), toward the target Proxmox
sizing-tier model (architecture doc SS6) ahead of actually provisioning VMs -
Proxmox itself stays deferred; today a tier just sizes container caps on the
existing SSH-managed hosts. A host can reference one by name (hosts.<name>.
size) or keep hand-picking the four fields, so existing tfvars are
unaffected; prod's example now uses size = "large" (identical numbers),
beta keeps explicit numbers, and a commented uat example demonstrates the
shortcut for a future ephemeral host.
Strengthened terraform/README.md's local-state caveat: more Terraform-
generated secrets landing in tfstate raises the stakes of the existing
never-commit-cleartext-state guidance, not just the sizing.
Verified: terraform validate + fmt clean. A real `terraform plan` against
fake hosts (prod/beta/uat, mixing size="large"/explicit-numbers/size="nano")
resolved every sizing correctly (prod 8/8/4/16g, beta 4/4/2/8g, uat
1/1/1/1g) and planned exactly one instance of each random_password/random_id
resource. Applied just those four resources (real generation, -target to
avoid touching the fake SSH-only host resources) and re-planned: "No
changes" - confirming the keepers pinning holds. Adding an explicit
postgres_password override afterward left the random_password resource
itself completely untouched (0 replace/destroy), confirming the override
path never disturbs the generated resource.
224 lines
4.5 KiB
HCL
224 lines
4.5 KiB
HCL
# Per-host inputs (all supplied by the root module's for_each).
|
|
|
|
variable "name" {
|
|
description = "Short host key (e.g. \"prod\", \"dev\"), used in log lines."
|
|
type = string
|
|
}
|
|
|
|
variable "host" {
|
|
description = "IP or hostname to SSH to."
|
|
type = string
|
|
}
|
|
|
|
variable "ssh_user" {
|
|
description = "SSH login user (must be able to sudo)."
|
|
type = string
|
|
}
|
|
|
|
variable "ssh_private_key_path" {
|
|
description = "Path to the private key file for ssh_user."
|
|
type = string
|
|
}
|
|
|
|
variable "role" {
|
|
description = "\"prod\" | \"dev\" — informational."
|
|
type = string
|
|
}
|
|
|
|
variable "git_branch" {
|
|
description = "Branch the host checkout is reset to."
|
|
type = string
|
|
}
|
|
|
|
variable "domain" {
|
|
description = "Public domain. \"\" => no Caddy/TLS (open the app port instead)."
|
|
type = string
|
|
}
|
|
|
|
variable "compose_files" {
|
|
description = "Compose files to layer, in order (dev appends docker-compose.dev.yml)."
|
|
type = list(string)
|
|
}
|
|
|
|
variable "openmeteo" {
|
|
description = "Self-host the ERA5 archive: layer docker-compose.openmeteo.yml + provision the host rclone mount."
|
|
type = bool
|
|
default = false
|
|
}
|
|
|
|
variable "om_data_dir" {
|
|
description = "Host rclone mount point for the archive bucket (OM_DATA_DIR the overlay bind-mounts)."
|
|
type = string
|
|
default = "/mnt/om-archive"
|
|
}
|
|
|
|
variable "om_bucket_remote" {
|
|
description = "rclone remote:path for the archive bucket (mounted at om_data_dir)."
|
|
type = string
|
|
default = ""
|
|
}
|
|
|
|
variable "om_rclone_conf" {
|
|
description = "rclone.conf contents installed to /etc/rclone/rclone.conf. Sensitive."
|
|
type = string
|
|
default = ""
|
|
sensitive = true
|
|
}
|
|
|
|
variable "om_vfs_cache_max" {
|
|
description = "rclone --vfs-cache-max-size for the mount's on-disk hot cache."
|
|
type = string
|
|
default = "80G"
|
|
}
|
|
|
|
variable "app_dir" {
|
|
description = "Checkout path on the host."
|
|
type = string
|
|
}
|
|
|
|
variable "repo_root" {
|
|
description = "Local repo root, used to hash the compose files for the re-apply trigger."
|
|
type = string
|
|
}
|
|
|
|
variable "repo_url" {
|
|
description = "Git remote to clone from if the host has no checkout yet."
|
|
type = string
|
|
}
|
|
|
|
variable "app_port" {
|
|
description = "Port the app binds / is health-checked on."
|
|
type = number
|
|
}
|
|
|
|
# ---- Sizing -------------------------------------------------------------------
|
|
variable "workers" {
|
|
description = "uvicorn worker count (WORKERS)."
|
|
type = number
|
|
}
|
|
|
|
variable "app_cpus" {
|
|
description = "App container CPU cap (APP_CPUS)."
|
|
type = number
|
|
}
|
|
|
|
variable "db_cpus" {
|
|
description = "DB container CPU cap (DB_CPUS)."
|
|
type = number
|
|
}
|
|
|
|
variable "db_memory" {
|
|
description = "DB container memory cap (DB_MEMORY), e.g. \"8g\"."
|
|
type = string
|
|
}
|
|
|
|
variable "timescaledb_tag" {
|
|
description = "TimescaleDB image tag (TIMESCALEDB_TAG), e.g. \"2.17.2-pg18\". \"latest-pg18\" (the default) matches today's behavior; pin an exact minor before any host could ever replicate with another."
|
|
type = string
|
|
default = "latest-pg18"
|
|
}
|
|
|
|
# ---- Secrets rendered into /etc/thermograph.env -------------------------------
|
|
variable "postgres_password" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "auth_secret" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "metrics_token" {
|
|
type = string
|
|
sensitive = true
|
|
default = ""
|
|
}
|
|
|
|
variable "indexnow_key" {
|
|
type = string
|
|
sensitive = true
|
|
default = ""
|
|
}
|
|
|
|
variable "vapid_private_key" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "vapid_public_key" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "vapid_contact" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "google_verify" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "bing_verify" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "mail_backend" {
|
|
type = string
|
|
}
|
|
|
|
variable "smtp_host" {
|
|
type = string
|
|
}
|
|
|
|
variable "smtp_port" {
|
|
type = string
|
|
}
|
|
|
|
variable "smtp_user" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "smtp_password" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "smtp_starttls" {
|
|
type = string
|
|
}
|
|
|
|
variable "mail_from" {
|
|
type = string
|
|
}
|
|
|
|
variable "mail_reply_to" {
|
|
type = string
|
|
}
|
|
|
|
variable "discord_webhook" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "discord_public_key" {
|
|
type = string
|
|
}
|
|
|
|
variable "discord_app_id" {
|
|
type = string
|
|
}
|
|
|
|
variable "discord_bot_token" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "discord_client_secret" {
|
|
type = string
|
|
sensitive = true
|
|
}
|