variable "wg_peer_private_key" { description = "WireGuard peer private key" type = string sensitive = true } variable "wg_peer_ip" { description = "WireGuard peer IP" type = string default = "10.100.0.2" } variable "wg_peer_ipv6" { description = "WireGuard peer ULA IPv6 address" type = string default = "fd00:100::2" } variable "wg_server_public_key" { description = "WireGuard server public key" type = string sensitive = true } variable "wg_server_endpoint" { description = "WireGuard server endpoint" type = string default = "bugabinga.net" } variable "wg_server_endpoint_port" { description = "WireGuard server port" type = number default = 51820 } variable "wg_allowed_ips" { description = "Allowed IPs for WireGuard" type = string default = "0.0.0.0/0" } variable "wg_mtu" { description = "WireGuard interface MTU" type = number default = 1280 } variable "relay_ipv4" { description = "Public IPv4 address of the relay for DNS updates" type = string } variable "relay_ipv6" { description = "Public IPv6 address of the relay for DNS updates" type = string } variable "klops_ssh_host" { description = "SSH host for klops" type = string } variable "klops_ssh_port" { description = "SSH port for klops" type = number default = 22 } variable "klops_ssh_user" { description = "SSH user for klops" type = string default = "oli" } variable "base_domain" { description = "Base domain used for public service routing" type = string default = "bugabinga.net" } variable "soft_serve_initial_admin_key" { description = "Initial Soft Serve admin SSH public key" type = string sensitive = true } variable "vcs_ssh_peer_port" { description = "TCP port on klops that receives forwarded Git SSH traffic for Soft Serve" type = number default = 2222 } variable "luci_ssh_peer_port" { description = "TCP port on klops that receives forwarded Luci SSH CLI traffic" type = number default = 2223 } variable "zot_htpasswd_content" { description = "htpasswd file content for zot OCI registry users" type = string sensitive = true } variable "homepage_jellyfin_api_key" { description = "Jellyfin API key used by Homepage widgets. Leave empty to disable the Jellyfin widget." type = string default = "" sensitive = true nullable = false } variable "homepage_paperless_api_token" { description = "Paperless-ngx API token used by Homepage widgets. Leave empty to disable the Paperless-ngx widget." type = string default = "" sensitive = true nullable = false } variable "paperless_secret_key" { description = "Django secret key used by Paperless-ngx. Keep stable across restarts." type = string sensitive = true nullable = false validation { condition = trimspace(var.paperless_secret_key) != "" error_message = "Paperless secret key must not be empty." } } variable "hallucygenie_minimax_api_key" { description = "MiniMax API key used by HallucyGenie." type = string sensitive = true nullable = false validation { condition = trimspace(var.hallucygenie_minimax_api_key) != "" error_message = "HallucyGenie MiniMax API key must not be empty." } } variable "hallucygenie_basic_auth_users" { description = "Caddy basic-auth user lines for HallucyGenie, formatted as ' '." type = string sensitive = true nullable = false validation { condition = trimspace(var.hallucygenie_basic_auth_users) != "" error_message = "HallucyGenie basic-auth users must not be empty." } } variable "toad_basic_auth_users" { description = "Caddy basic-auth user lines for the Toad dashboard, formatted as ' '." type = string sensitive = true nullable = false validation { condition = trimspace(var.toad_basic_auth_users) != "" error_message = "Toad basic-auth users must not be empty." } } variable "quest_log_editor_password_hash" { description = "Argon2 password hash for Quest Log editor login." type = string sensitive = true nullable = false validation { condition = trimspace(var.quest_log_editor_password_hash) != "" error_message = "Quest Log editor password hash must not be empty." } }