43 lines
1.1 KiB
Terraform
43 lines
1.1 KiB
Terraform
# vpn: OpenVPN + Traefik. Not attached to the private network (see docs/architecture.md).
|
|
resource "hcloud_firewall" "this" {
|
|
name = "vpn-firewall"
|
|
|
|
rule { # server ssh
|
|
direction = "in"
|
|
protocol = "tcp"
|
|
port = "22"
|
|
source_ips = var.allowed_ssh_source_ips
|
|
}
|
|
|
|
rule { # Traefik http/https (traefik.vpn.luke-else.co.uk)
|
|
direction = "in"
|
|
protocol = "tcp"
|
|
port = "80"
|
|
source_ips = ["0.0.0.0/0", "::/0"]
|
|
}
|
|
|
|
rule {
|
|
direction = "in"
|
|
protocol = "tcp"
|
|
port = "443"
|
|
source_ips = ["0.0.0.0/0", "::/0"]
|
|
}
|
|
|
|
rule { # OpenVPN tunnel - always direct to this server's public IP, never via a load balancer
|
|
direction = "in"
|
|
protocol = "udp"
|
|
port = "1194"
|
|
source_ips = ["0.0.0.0/0", "::/0"]
|
|
}
|
|
}
|
|
|
|
resource "hcloud_server" "this" {
|
|
name = "vpn"
|
|
server_type = var.server_type
|
|
image = var.image
|
|
location = var.location
|
|
ssh_keys = var.ssh_key_ids
|
|
firewall_ids = [hcloud_firewall.this.id]
|
|
labels = { role = "vpn" } # picked up by ansible/inventory/hcloud.yml
|
|
}
|