Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

modules/klops/variables.tf

Raw
variable "wg_peer_private_key" {
  description = "WireGuard peer private key"
  type        = string
  sensitive   = true
}

variable "wg_peer_ip" {
  description = "WireGuard peer IP"
  type        = string
  default     = "10.100.0.2"
}

variable "wg_peer_ipv6" {
  description = "WireGuard peer ULA IPv6 address"
  type        = string
  default     = "fd00:100::2"
}

variable "wg_server_public_key" {
  description = "WireGuard server public key"
  type        = string
  sensitive   = true
}

variable "wg_server_endpoint" {
  description = "WireGuard server endpoint"
  type        = string
  default     = "bugabinga.net"
}

variable "wg_server_endpoint_port" {
  description = "WireGuard server port"
  type        = number
  default     = 51820
}

variable "wg_allowed_ips" {
  description = "Allowed IPs for WireGuard"
  type        = string
  default     = "0.0.0.0/0"
}

variable "wg_mtu" {
  description = "WireGuard interface MTU"
  type        = number
  default     = 1280
}

variable "relay_ipv4" {
  description = "Public IPv4 address of the relay for DNS updates"
  type        = string
}

variable "relay_ipv6" {
  description = "Public IPv6 address of the relay for DNS updates"
  type        = string
}

variable "klops_ssh_host" {
  description = "SSH host for klops"
  type        = string
}

variable "klops_ssh_port" {
  description = "SSH port for klops"
  type        = number
  default     = 22
}

variable "klops_ssh_user" {
  description = "SSH user for klops"
  type        = string
  default     = "oli"
}

variable "base_domain" {
  description = "Base domain used for public service routing"
  type        = string
  default     = "bugabinga.net"
}

variable "soft_serve_initial_admin_key" {
  description = "Initial Soft Serve admin SSH public key"
  type        = string
  sensitive   = true
}

variable "vcs_ssh_peer_port" {
  description = "TCP port on klops that receives forwarded Git SSH traffic for Soft Serve"
  type        = number
  default     = 2222
}

variable "luci_ssh_peer_port" {
  description = "TCP port on klops that receives forwarded Luci SSH CLI traffic"
  type        = number
  default     = 2223
}

variable "zot_htpasswd_content" {
  description = "htpasswd file content for zot OCI registry users"
  type        = string
  sensitive   = true
}

variable "homepage_jellyfin_api_key" {
  description = "Jellyfin API key used by Homepage widgets. Leave empty to disable the Jellyfin widget."
  type        = string
  default     = ""
  sensitive   = true
  nullable    = false
}

variable "homepage_paperless_api_token" {
  description = "Paperless-ngx API token used by Homepage widgets. Leave empty to disable the Paperless-ngx widget."
  type        = string
  default     = ""
  sensitive   = true
  nullable    = false
}

variable "paperless_secret_key" {
  description = "Django secret key used by Paperless-ngx. Keep stable across restarts."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.paperless_secret_key) != ""
    error_message = "Paperless secret key must not be empty."
  }
}

variable "hallucygenie_minimax_api_key" {
  description = "MiniMax API key used by HallucyGenie."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.hallucygenie_minimax_api_key) != ""
    error_message = "HallucyGenie MiniMax API key must not be empty."
  }
}

variable "hallucygenie_basic_auth_users" {
  description = "Caddy basic-auth user lines for HallucyGenie, formatted as '<username> <bcrypt-hash>'."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.hallucygenie_basic_auth_users) != ""
    error_message = "HallucyGenie basic-auth users must not be empty."
  }
}

variable "toad_basic_auth_users" {
  description = "Caddy basic-auth user lines for the Toad dashboard, formatted as '<username> <bcrypt-hash>'."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.toad_basic_auth_users) != ""
    error_message = "Toad basic-auth users must not be empty."
  }
}

variable "quest_log_editor_password_hash" {
  description = "Argon2 password hash for Quest Log editor login."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.quest_log_editor_password_hash) != ""
    error_message = "Quest Log editor password hash must not be empty."
  }
}