Files
server/infra/modules/dev/main.tf
T

107 lines
2.7 KiB
Terraform

# dev: Gitea + Runner + Traefik (git.luke-else.co.uk, cicd.luke-else.co.uk)
# Port sources: services/dev/*docker-compose.yml (published ports) and services/todo.md
# (the documented UFW allow-list). dev has no firewall in docs/architecture.md, but we
# add one anyway for baseline safety - see conversation history.
resource "hcloud_firewall" "this" {
name = "dev-firewall"
rule { # server ssh - wired to the vpn server's public IP only, see infra/main.tf
direction = "in"
protocol = "tcp"
port = "22"
source_ips = var.allowed_ssh_source_ips
}
rule { # gitea ssh (git.luke-else.co.uk, published as 222:22)
direction = "in"
protocol = "tcp"
port = "222"
source_ips = ["0.0.0.0/0", "::/0"]
}
rule { # Traefik http/https (git.luke-else.co.uk, cicd.luke-else.co.uk)
direction = "in"
protocol = "tcp"
port = "80"
source_ips = ["0.0.0.0/0", "::/0"]
}
rule {
direction = "in"
protocol = "tcp"
port = "443"
source_ips = ["0.0.0.0/0", "::/0"]
}
rule { # traffic from prod over the private network
direction = "in"
protocol = "tcp"
port = "1-65535"
source_ips = [var.network_ip_range]
}
rule {
direction = "in"
protocol = "udp"
port = "1-65535"
source_ips = [var.network_ip_range]
}
}
resource "hcloud_server" "this" {
name = "dev"
server_type = var.server_type
image = var.image
location = var.location
ssh_keys = [var.ssh_key_id]
firewall_ids = [hcloud_firewall.this.id]
network {
network_id = var.network_id
ip = var.private_ip
}
connection {
type = "ssh"
host = self.ipv4_address
user = "root"
private_key = file(var.ssh_private_key_path)
}
provisioner "file" {
content = var.bootstrap_script
destination = "/root/bootstrap.sh"
}
provisioner "remote-exec" {
inline = [
"chmod +x /root/bootstrap.sh",
"/root/bootstrap.sh",
]
}
}
resource "hcloud_volume" "storage" {
name = "dev-storage"
size = var.volume_size
server_id = hcloud_server.this.id
automount = true
format = "ext4"
lifecycle {
prevent_destroy = true
}
}
# Renders services/dev/Runners/docker-compose.yml directly into the repo, with
# one runner service per var.runner_count. This only touches the local working
# tree - deploying the change still goes through the normal scp + spinup.sh flow.
resource "local_file" "runners_compose" {
filename = "${path.root}/../services/dev/Runners/docker-compose.yml"
content = templatefile("${path.module}/templates/runners-docker-compose.yml.tftpl", {
runner_count = var.runner_count
})
file_permission = "0644"
}