# vpn: OpenVPN + Traefik. Not attached to the private network (see docs/architecture.md). resource "hcloud_firewall" "this" { name = "vpn-firewall" rule { # server ssh direction = "in" protocol = "tcp" port = "22" source_ips = var.allowed_ssh_source_ips } rule { # Traefik http/https (traefik.vpn.luke-else.co.uk) direction = "in" protocol = "tcp" port = "80" source_ips = ["0.0.0.0/0", "::/0"] } rule { direction = "in" protocol = "tcp" port = "443" source_ips = ["0.0.0.0/0", "::/0"] } rule { # OpenVPN tunnel - always direct to this server's public IP, never via a load balancer direction = "in" protocol = "udp" port = "1194" source_ips = ["0.0.0.0/0", "::/0"] } } resource "hcloud_server" "this" { name = "vpn" server_type = var.server_type image = var.image location = var.location ssh_keys = [var.ssh_key_id] firewall_ids = [hcloud_firewall.this.id] connection { type = "ssh" host = self.ipv4_address user = "root" private_key = file(var.ssh_private_key_path) } provisioner "file" { content = var.bootstrap_script destination = "/root/bootstrap.sh" } provisioner "remote-exec" { inline = [ "chmod +x /root/bootstrap.sh", "/root/bootstrap.sh", ] } }