repositories / bugabinga.net
bugabinga.net
personal infrastructure for bugabinga!
owned by admin
modules/klops/variables.tf
Rawvariable "wg_peer_private_key" {
description = "WireGuard peer private key"
type = string
sensitive = true
}
variable "wg_peer_ip" {
description = "WireGuard peer IP"
type = string
default = "10.100.0.2"
}
variable "wg_peer_ipv6" {
description = "WireGuard peer ULA IPv6 address"
type = string
default = "fd00:100::2"
}
variable "wg_server_public_key" {
description = "WireGuard server public key"
type = string
sensitive = true
}
variable "wg_server_endpoint" {
description = "WireGuard server endpoint"
type = string
default = "bugabinga.net"
}
variable "wg_server_endpoint_port" {
description = "WireGuard server port"
type = number
default = 51820
}
variable "wg_allowed_ips" {
description = "Allowed IPs for WireGuard"
type = string
default = "0.0.0.0/0"
}
variable "wg_mtu" {
description = "WireGuard interface MTU"
type = number
default = 1280
}
variable "relay_ipv4" {
description = "Public IPv4 address of the relay for DNS updates"
type = string
}
variable "relay_ipv6" {
description = "Public IPv6 address of the relay for DNS updates"
type = string
}
variable "klops_ssh_host" {
description = "SSH host for klops"
type = string
}
variable "klops_ssh_port" {
description = "SSH port for klops"
type = number
default = 22
}
variable "klops_ssh_user" {
description = "SSH user for klops"
type = string
default = "oli"
}
variable "base_domain" {
description = "Base domain used for public service routing"
type = string
default = "bugabinga.net"
}
variable "soft_serve_initial_admin_key" {
description = "Initial Soft Serve admin SSH public key"
type = string
sensitive = true
}
variable "vcs_ssh_peer_port" {
description = "TCP port on klops that receives forwarded Git SSH traffic for Soft Serve"
type = number
default = 2222
}
variable "luci_ssh_peer_port" {
description = "TCP port on klops that receives forwarded Luci SSH CLI traffic"
type = number
default = 2223
}
variable "zot_htpasswd_content" {
description = "htpasswd file content for zot OCI registry users"
type = string
sensitive = true
}
variable "homepage_jellyfin_api_key" {
description = "Jellyfin API key used by Homepage widgets. Leave empty to disable the Jellyfin widget."
type = string
default = ""
sensitive = true
nullable = false
}
variable "homepage_paperless_api_token" {
description = "Paperless-ngx API token used by Homepage widgets. Leave empty to disable the Paperless-ngx widget."
type = string
default = ""
sensitive = true
nullable = false
}
variable "paperless_secret_key" {
description = "Django secret key used by Paperless-ngx. Keep stable across restarts."
type = string
sensitive = true
nullable = false
validation {
condition = trimspace(var.paperless_secret_key) != ""
error_message = "Paperless secret key must not be empty."
}
}
variable "hallucygenie_minimax_api_key" {
description = "MiniMax API key used by HallucyGenie."
type = string
sensitive = true
nullable = false
validation {
condition = trimspace(var.hallucygenie_minimax_api_key) != ""
error_message = "HallucyGenie MiniMax API key must not be empty."
}
}
variable "hallucygenie_basic_auth_users" {
description = "Caddy basic-auth user lines for HallucyGenie, formatted as '<username> <bcrypt-hash>'."
type = string
sensitive = true
nullable = false
validation {
condition = trimspace(var.hallucygenie_basic_auth_users) != ""
error_message = "HallucyGenie basic-auth users must not be empty."
}
}
variable "toad_basic_auth_users" {
description = "Caddy basic-auth user lines for the Toad dashboard, formatted as '<username> <bcrypt-hash>'."
type = string
sensitive = true
nullable = false
validation {
condition = trimspace(var.toad_basic_auth_users) != ""
error_message = "Toad basic-auth users must not be empty."
}
}
variable "quest_log_editor_password_hash" {
description = "Argon2 password hash for Quest Log editor login."
type = string
sensitive = true
nullable = false
validation {
condition = trimspace(var.quest_log_editor_password_hash) != ""
error_message = "Quest Log editor password hash must not be empty."
}
}