Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

.system/research/BB-RESEARCH-4D80C31E-infrastructure-platform-choices/index.md

Raw
Rendered preview

id: BB-RESEARCH-4D80C31E type: research title: Infrastructure platform choices

Infrastructure platform choices

Conclusions

  • OpenTofu provides the required open-source Terraform-compatible workflow.
  • Hetzner Cloud provides suitable public connectivity, retained addresses, and an OpenTofu provider.
  • WireGuard carries selected web and SSH ingress between the relay and klops while preserving source addresses through DNAT.
  • nftables provides stateful, default-deny IPv4 and IPv6 filtering and NAT.
  • Rootless Podman Quadlets provide systemd-managed service lifecycle on klops.
  • SSH remains the provisioning boundary for the existing physical klops host, avoiding another configuration-management stack.

Alternatives, historical service inventories, provider sizing, and prices are non-binding. Current behavior is defined by the linked specifications and implementation.

Provenance

Migrated from ADR-000 through ADR-005. Claims were reconciled with current OpenTofu, cloud-init, klops modules, Quadlets, and deployment scripts.

---
id: BB-RESEARCH-4D80C31E
type: research
title: Infrastructure platform choices
---

# Infrastructure platform choices

## Conclusions

- OpenTofu provides the required open-source Terraform-compatible workflow.
- Hetzner Cloud provides suitable public connectivity, retained addresses, and an OpenTofu provider.
- WireGuard carries selected web and SSH ingress between the relay and klops while preserving source addresses through DNAT.
- nftables provides stateful, default-deny IPv4 and IPv6 filtering and NAT.
- Rootless Podman Quadlets provide systemd-managed service lifecycle on klops.
- SSH remains the provisioning boundary for the existing physical klops host, avoiding another configuration-management stack.

Alternatives, historical service inventories, provider sizing, and prices are non-binding.
Current behavior is defined by the linked specifications and implementation.

## Provenance

Migrated from ADR-000 through ADR-005.
Claims were reconciled with current OpenTofu, cloud-init, klops modules, Quadlets, and deployment scripts.