Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

secrets.tf

Raw
# Declarations of all the secret values
# Does NOT contain the secret values!
# Use `secrets.auto.tfvars` to define the values as exlained in the README.md.
# All variables in here MUST use `sensitive = true`, to prevent the tofu logger from printing them!

variable "hcloud_token" {
  description = "Hetzner Cloud API Token"
  type        = string
  sensitive   = true
}

variable "ssh_public_key" {
  description = "SSH Public Key for the operator user"
  type        = string
  sensitive   = true
}

# Host Keys (Pre-generated)
variable "ssh_host_key_ed25519_private" {
  description = "SSH Host Private Key (ED25519)"
  type        = string
  sensitive   = true
}

variable "ssh_host_key_ed25519_public" {
  description = "SSH Host Public Key (ED25519)"
  type        = string
  sensitive   = true
}

# WireGuard Keys
variable "wg_server_private_key" {
  description = "WireGuard Server Private Key"
  type        = string
  sensitive   = true
}

variable "wg_server_public_key" {
  description = "WireGuard Server Public Key"
  type        = string
  sensitive   = true
}

variable "wg_peer_private_key" {
  description = "WireGuard Peer Private Key (Home Server)"
  type        = string
  sensitive   = true
}

variable "wg_peer_public_key" {
  description = "WireGuard Peer Public Key (Home Server)"
  type        = string
  sensitive   = true
}

variable "zot_htpasswd_content" {
  description = "htpasswd file content for zot OCI registry users"
  type        = string
  sensitive   = true
}

variable "github_pat" {
  description = "GitHub personal access token for repository mirroring"
  type        = string
  default     = ""
  sensitive   = true
  nullable    = false
}

variable "homepage_jellyfin_api_key" {
  description = "Jellyfin API key used by Homepage widgets. Leave empty to disable the Jellyfin widget."
  type        = string
  default     = ""
  sensitive   = true
  nullable    = false
}

variable "homepage_paperless_api_token" {
  description = "Paperless-ngx API token used by Homepage widgets. Leave empty to disable the Paperless-ngx widget."
  type        = string
  default     = ""
  sensitive   = true
  nullable    = false
}

variable "paperless_secret_key" {
  description = "Django secret key used by Paperless-ngx. Keep stable across restarts."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.paperless_secret_key) != ""
    error_message = "Paperless secret key must not be empty."
  }
}

variable "hallucygenie_minimax_api_key" {
  description = "MiniMax API key used by HallucyGenie."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.hallucygenie_minimax_api_key) != ""
    error_message = "HallucyGenie MiniMax API key must not be empty."
  }
}

variable "hallucygenie_basic_auth_users" {
  description = "Caddy basic-auth user lines for HallucyGenie, formatted as '<username> <bcrypt-hash>'."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.hallucygenie_basic_auth_users) != ""
    error_message = "HallucyGenie basic-auth users must not be empty. Run `just generate basic-auth-user USER`."
  }
}

variable "toad_basic_auth_users" {
  description = "Caddy basic-auth user lines for the Toad dashboard, formatted as '<username> <bcrypt-hash>'."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.toad_basic_auth_users) != ""
    error_message = "Toad basic-auth users must not be empty."
  }
}

variable "quest_log_editor_password_hash" {
  description = "Argon2 password hash for Quest Log editor login."
  type        = string
  sensitive   = true
  nullable    = false

  validation {
    condition     = trimspace(var.quest_log_editor_password_hash) != ""
    error_message = "Quest Log editor password hash must not be empty."
  }
}