resource "hcloud_ssh_key" "default" { name = "operator-key" public_key = var.ssh_public_key } resource "hcloud_primary_ip" "relay_ipv4" { name = "bugabinga-relay-ipv4" type = "ipv4" location = var.location auto_delete = false } resource "hcloud_primary_ip" "relay_ipv6" { name = "bugabinga-relay-ipv6" type = "ipv6" location = var.location auto_delete = false } resource "hcloud_firewall" "this" { name = "bugabinga-firewall" # Allow SSH (Management) - New High Port rule { direction = "in" protocol = "tcp" port = var.ssh_port source_ips = [ "0.0.0.0/0", "::/0" ] } # Allow Git SSH for Soft Serve (forwarded to klops) rule { direction = "in" protocol = "tcp" port = var.vcs_ssh_public_port source_ips = [ "0.0.0.0/0", "::/0" ] } # Allow Luci SSH CLI (forwarded to klops) rule { direction = "in" protocol = "tcp" port = var.luci_ssh_public_port source_ips = [ "0.0.0.0/0", "::/0" ] } # Allow WireGuard UDP rule { direction = "in" protocol = "udp" port = "51820" source_ips = [ "0.0.0.0/0", "::/0" ] } # Web Services rule { direction = "in" protocol = "tcp" port = "80" source_ips = [ "0.0.0.0/0", "::/0" ] } rule { direction = "in" protocol = "tcp" port = "443" source_ips = [ "0.0.0.0/0", "::/0" ] } } resource "hcloud_server" "this" { name = "bugabinga-relay" image = var.server_image server_type = var.server_type location = var.location ssh_keys = [hcloud_ssh_key.default.id] firewall_ids = [hcloud_firewall.this.id] # Enable both IPv4 and IPv6 for maximum compatibility as a Relay public_net { ipv4_enabled = true ipv6_enabled = true ipv4 = hcloud_primary_ip.relay_ipv4.id ipv6 = hcloud_primary_ip.relay_ipv6.id } user_data = templatefile("${path.module}/templates/cloud-init.yaml.tftpl", { ssh_public_key = var.ssh_public_key ssh_port = var.ssh_port ssh_host_key_ed25519_private = var.ssh_host_key_ed25519_private ssh_host_key_ed25519_public = var.ssh_host_key_ed25519_public wg_server_private_key = var.wg_server_private_key wg_peer_public_key = var.wg_peer_public_key wg_server_ip = var.wg_server_ip wg_peer_ip = var.wg_peer_ip wg_server_ipv6 = var.wg_server_ipv6 wg_peer_ipv6 = var.wg_peer_ipv6 wg_mtu = var.wg_mtu vcs_ssh_public_port = var.vcs_ssh_public_port vcs_ssh_peer_port = var.vcs_ssh_peer_port luci_ssh_public_port = var.luci_ssh_public_port luci_ssh_peer_port = var.luci_ssh_peer_port }) } module "klops" { source = "./modules/klops" wg_peer_private_key = var.wg_peer_private_key wg_peer_ip = var.wg_peer_ip wg_peer_ipv6 = var.wg_peer_ipv6 wg_server_public_key = var.wg_server_public_key wg_server_endpoint = hcloud_server.this.ipv4_address wg_server_endpoint_port = 51820 wg_allowed_ips = "0.0.0.0/0, ::/0" wg_mtu = var.wg_mtu relay_ipv4 = hcloud_server.this.ipv4_address relay_ipv6 = hcloud_server.this.ipv6_address klops_ssh_host = var.klops_ssh_host klops_ssh_port = var.klops_ssh_port klops_ssh_user = var.klops_ssh_user base_domain = var.base_domain soft_serve_initial_admin_key = var.ssh_public_key vcs_ssh_peer_port = var.vcs_ssh_peer_port luci_ssh_peer_port = var.luci_ssh_peer_port zot_htpasswd_content = var.zot_htpasswd_content homepage_jellyfin_api_key = var.homepage_jellyfin_api_key homepage_paperless_api_token = var.homepage_paperless_api_token paperless_secret_key = var.paperless_secret_key hallucygenie_minimax_api_key = var.hallucygenie_minimax_api_key hallucygenie_basic_auth_users = var.hallucygenie_basic_auth_users toad_basic_auth_users = var.toad_basic_auth_users quest_log_editor_password_hash = var.quest_log_editor_password_hash }