Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

main.tf

Raw
resource "hcloud_ssh_key" "default" {
  name       = "operator-key"
  public_key = var.ssh_public_key
}

resource "hcloud_primary_ip" "relay_ipv4" {
  name        = "bugabinga-relay-ipv4"
  type        = "ipv4"
  location    = var.location
  auto_delete = false
}

resource "hcloud_primary_ip" "relay_ipv6" {
  name        = "bugabinga-relay-ipv6"
  type        = "ipv6"
  location    = var.location
  auto_delete = false
}

resource "hcloud_firewall" "this" {
  name = "bugabinga-firewall"

  # Allow SSH (Management) - New High Port
  rule {
    direction = "in"
    protocol  = "tcp"
    port      = var.ssh_port
    source_ips = [
      "0.0.0.0/0",
      "::/0"
    ]
  }

  # Allow Git SSH for Soft Serve (forwarded to klops)
  rule {
    direction = "in"
    protocol  = "tcp"
    port      = var.vcs_ssh_public_port
    source_ips = [
      "0.0.0.0/0",
      "::/0"
    ]
  }

  # Allow Luci SSH CLI (forwarded to klops)
  rule {
    direction = "in"
    protocol  = "tcp"
    port      = var.luci_ssh_public_port
    source_ips = [
      "0.0.0.0/0",
      "::/0"
    ]
  }

  # Allow WireGuard UDP
  rule {
    direction = "in"
    protocol  = "udp"
    port      = "51820"
    source_ips = [
      "0.0.0.0/0",
      "::/0"
    ]
  }

  # Web Services
  rule {
    direction = "in"
    protocol  = "tcp"
    port      = "80"
    source_ips = [
      "0.0.0.0/0",
      "::/0"
    ]
  }

  rule {
    direction = "in"
    protocol  = "tcp"
    port      = "443"
    source_ips = [
      "0.0.0.0/0",
      "::/0"
    ]
  }

}

resource "hcloud_server" "this" {
  name         = "bugabinga-relay"
  image        = var.server_image
  server_type  = var.server_type
  location     = var.location
  ssh_keys     = [hcloud_ssh_key.default.id]
  firewall_ids = [hcloud_firewall.this.id]


  # Enable both IPv4 and IPv6 for maximum compatibility as a Relay
  public_net {
    ipv4_enabled = true
    ipv6_enabled = true
    ipv4         = hcloud_primary_ip.relay_ipv4.id
    ipv6         = hcloud_primary_ip.relay_ipv6.id
  }

  user_data = templatefile("${path.module}/templates/cloud-init.yaml.tftpl", {
    ssh_public_key               = var.ssh_public_key
    ssh_port                     = var.ssh_port
    ssh_host_key_ed25519_private = var.ssh_host_key_ed25519_private
    ssh_host_key_ed25519_public  = var.ssh_host_key_ed25519_public
    wg_server_private_key        = var.wg_server_private_key
    wg_peer_public_key           = var.wg_peer_public_key
    wg_server_ip                 = var.wg_server_ip
    wg_peer_ip                   = var.wg_peer_ip
    wg_server_ipv6               = var.wg_server_ipv6
    wg_peer_ipv6                 = var.wg_peer_ipv6
    wg_mtu                       = var.wg_mtu
    vcs_ssh_public_port          = var.vcs_ssh_public_port
    vcs_ssh_peer_port            = var.vcs_ssh_peer_port
    luci_ssh_public_port         = var.luci_ssh_public_port
    luci_ssh_peer_port           = var.luci_ssh_peer_port
  })
}

module "klops" {
  source = "./modules/klops"

  wg_peer_private_key     = var.wg_peer_private_key
  wg_peer_ip              = var.wg_peer_ip
  wg_peer_ipv6            = var.wg_peer_ipv6
  wg_server_public_key    = var.wg_server_public_key
  wg_server_endpoint      = hcloud_server.this.ipv4_address
  wg_server_endpoint_port = 51820
  wg_allowed_ips          = "0.0.0.0/0, ::/0"
  wg_mtu                  = var.wg_mtu
  relay_ipv4              = hcloud_server.this.ipv4_address
  relay_ipv6              = hcloud_server.this.ipv6_address

  klops_ssh_host = var.klops_ssh_host
  klops_ssh_port = var.klops_ssh_port
  klops_ssh_user = var.klops_ssh_user

  base_domain                    = var.base_domain
  soft_serve_initial_admin_key   = var.ssh_public_key
  vcs_ssh_peer_port              = var.vcs_ssh_peer_port
  luci_ssh_peer_port             = var.luci_ssh_peer_port
  zot_htpasswd_content           = var.zot_htpasswd_content
  homepage_jellyfin_api_key      = var.homepage_jellyfin_api_key
  homepage_paperless_api_token   = var.homepage_paperless_api_token
  paperless_secret_key           = var.paperless_secret_key
  hallucygenie_minimax_api_key   = var.hallucygenie_minimax_api_key
  hallucygenie_basic_auth_users  = var.hallucygenie_basic_auth_users
  toad_basic_auth_users          = var.toad_basic_auth_users
  quest_log_editor_password_hash = var.quest_log_editor_password_hash
}