* Split web/worker duties with THERMOGRAPH_ROLE Background work (the subscription notifier) is welded to the same process that serves requests, so scaling the web tier to N replicas would also scale notifier instances unless something restricts it further than leader election alone. Add THERMOGRAPH_ROLE (web|worker|all, default all - unchanged single-process behavior). Every replica runs the same image; ROLE only gates whether a process is allowed to own the notifier at all, layered on top of the existing leader election: web replicas never start it even if they'd win leader election, worker replicas start it if they win. The decision is pulled into _should_run_notifier() so it's unit-testable without booting the full app (DB init, places index, neighbor warmer). Add a minimal /healthz liveness route (no DB/upstream I/O, not under BASE) so a worker replica - which serves no real traffic - still has something Swarm can health-check. * Add the Swarm interim stack file, a pinnable TimescaleDB tag, and a Caddy health-gate Three changes toward the hop-1 interim cutover, all inert until Track B stands up the platform: docker-stack.yml: the Swarm stack file for the interim cutover, distinct from docker-compose.yml (today's plain-compose deploy, unaffected). Pulls a pre-built image (IMAGE_TAG) instead of building in place; app/worker publish no host port (127.0.0.1:8137:8137 has no Swarm equivalent - Swarm's routing mesh publishes on 0.0.0.0, which would expose the plaintext app un-fronted), reaching Caddy only over an MTU-lowered overlay network (VXLAN-over-WireGuard needs a smaller MTU or large payloads silently stall); db is placement- pinned to a labelled node; app/worker skip inline migrations (RUN_MIGRATIONS=0) so the runbook's one-shot migrate task is the only thing that ever runs Alembic; secrets are real Swarm secrets mounted at /run/secrets, read by the entrypoint shim rather than plain env vars. TIMESCALEDB_TAG: docker-compose.yml's db image now reads this (default latest-pg18, today's behavior unchanged), wired through Terraform (timescaledb_tag, default "latest-pg18") so it can actually be pinned to an exact minor without hand-editing the host - required before any host of the stack could replicate with another (a floating tag risks mismatched extension minors, which blocks a physical replica and risks compressed- chunk corruption on restore). Caddy active health-gate: both the Terraform-rendered Caddyfile and the live deploy/Caddyfile now health-check the app on the same cheap /healthz route its own Docker HEALTHCHECK uses (now /healthz instead of the SSR homepage, so it's cheap enough for a tight interval and works identically for a worker replica, which serves no public traffic at all) - Caddy won't forward into a container that's still booting or unhealthy. Verified live: built and booted the real image via docker compose - both containers report healthy via the new /healthz-based HEALTHCHECK, and GET / still renders the full SSR homepage unchanged. Both Caddyfiles validated with the real caddy binary. docker-stack.yml validated with docker compose config (required-var guards fire with clear messages; secrets correctly mount at /run/secrets/<name>, matching the entrypoint shim's mapping). docker-compose.yml validated with and without TIMESCALEDB_TAG set, alongside the existing openmeteo overlay. terraform validate + fmt clean.
212 lines
4.3 KiB
HCL
212 lines
4.3 KiB
HCL
# Per-host inputs (all supplied by the root module's for_each).
|
|
|
|
variable "name" {
|
|
description = "Short host key (e.g. \"prod\", \"dev\"), used in log lines."
|
|
type = string
|
|
}
|
|
|
|
variable "host" {
|
|
description = "IP or hostname to SSH to."
|
|
type = string
|
|
}
|
|
|
|
variable "ssh_user" {
|
|
description = "SSH login user (must be able to sudo)."
|
|
type = string
|
|
}
|
|
|
|
variable "ssh_private_key_path" {
|
|
description = "Path to the private key file for ssh_user."
|
|
type = string
|
|
}
|
|
|
|
variable "role" {
|
|
description = "\"prod\" | \"dev\" — informational."
|
|
type = string
|
|
}
|
|
|
|
variable "git_branch" {
|
|
description = "Branch the host checkout is reset to."
|
|
type = string
|
|
}
|
|
|
|
variable "domain" {
|
|
description = "Public domain. \"\" => no Caddy/TLS (open the app port instead)."
|
|
type = string
|
|
}
|
|
|
|
variable "compose_files" {
|
|
description = "Compose files to layer, in order (dev appends docker-compose.dev.yml)."
|
|
type = list(string)
|
|
}
|
|
|
|
variable "openmeteo" {
|
|
description = "Self-host the ERA5 archive: layer docker-compose.openmeteo.yml + provision the host rclone mount."
|
|
type = bool
|
|
default = false
|
|
}
|
|
|
|
variable "om_data_dir" {
|
|
description = "Host rclone mount point for the archive bucket (OM_DATA_DIR the overlay bind-mounts)."
|
|
type = string
|
|
default = "/mnt/om-archive"
|
|
}
|
|
|
|
variable "om_bucket_remote" {
|
|
description = "rclone remote:path for the archive bucket (mounted at om_data_dir)."
|
|
type = string
|
|
default = ""
|
|
}
|
|
|
|
variable "om_rclone_conf" {
|
|
description = "rclone.conf contents installed to /etc/rclone/rclone.conf. Sensitive."
|
|
type = string
|
|
default = ""
|
|
sensitive = true
|
|
}
|
|
|
|
variable "om_vfs_cache_max" {
|
|
description = "rclone --vfs-cache-max-size for the mount's on-disk hot cache."
|
|
type = string
|
|
default = "80G"
|
|
}
|
|
|
|
variable "app_dir" {
|
|
description = "Checkout path on the host."
|
|
type = string
|
|
}
|
|
|
|
variable "repo_root" {
|
|
description = "Local repo root, used to hash the compose files for the re-apply trigger."
|
|
type = string
|
|
}
|
|
|
|
variable "repo_url" {
|
|
description = "Git remote to clone from if the host has no checkout yet."
|
|
type = string
|
|
}
|
|
|
|
variable "app_port" {
|
|
description = "Port the app binds / is health-checked on."
|
|
type = number
|
|
}
|
|
|
|
# ---- Sizing -------------------------------------------------------------------
|
|
variable "workers" {
|
|
description = "uvicorn worker count (WORKERS)."
|
|
type = number
|
|
}
|
|
|
|
variable "app_cpus" {
|
|
description = "App container CPU cap (APP_CPUS)."
|
|
type = number
|
|
}
|
|
|
|
variable "db_cpus" {
|
|
description = "DB container CPU cap (DB_CPUS)."
|
|
type = number
|
|
}
|
|
|
|
variable "db_memory" {
|
|
description = "DB container memory cap (DB_MEMORY), e.g. \"8g\"."
|
|
type = string
|
|
}
|
|
|
|
variable "timescaledb_tag" {
|
|
description = "TimescaleDB image tag (TIMESCALEDB_TAG), e.g. \"2.17.2-pg18\". \"latest-pg18\" (the default) matches today's behavior; pin an exact minor before any host could ever replicate with another."
|
|
type = string
|
|
default = "latest-pg18"
|
|
}
|
|
|
|
# ---- Secrets rendered into /etc/thermograph.env -------------------------------
|
|
variable "postgres_password" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "auth_secret" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "vapid_private_key" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "vapid_public_key" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "vapid_contact" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "google_verify" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "bing_verify" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "mail_backend" {
|
|
type = string
|
|
}
|
|
|
|
variable "smtp_host" {
|
|
type = string
|
|
}
|
|
|
|
variable "smtp_port" {
|
|
type = string
|
|
}
|
|
|
|
variable "smtp_user" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "smtp_password" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "smtp_starttls" {
|
|
type = string
|
|
}
|
|
|
|
variable "mail_from" {
|
|
type = string
|
|
}
|
|
|
|
variable "mail_reply_to" {
|
|
type = string
|
|
}
|
|
|
|
variable "discord_webhook" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "discord_public_key" {
|
|
type = string
|
|
}
|
|
|
|
variable "discord_app_id" {
|
|
type = string
|
|
}
|
|
|
|
variable "discord_bot_token" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "discord_client_secret" {
|
|
type = string
|
|
sensitive = true
|
|
}
|