variable "ssh_port" { description = "Port for SSH access" type = number default = 49200 validation { condition = var.ssh_port > 0 && var.ssh_port < 65536 error_message = "Port must be a valid TCP port number." } } variable "vcs_ssh_public_port" { description = "Public TCP port on the relay that forwards Git SSH traffic to Soft Serve on klops" type = number default = 22 validation { condition = var.vcs_ssh_public_port > 0 && var.vcs_ssh_public_port < 65536 error_message = "VCS SSH public port must be a valid TCP port number." } } variable "vcs_ssh_peer_port" { description = "TCP port on klops that receives forwarded Git SSH traffic for Soft Serve" type = number default = 2222 validation { condition = var.vcs_ssh_peer_port > 0 && var.vcs_ssh_peer_port < 65536 error_message = "VCS SSH peer port must be a valid TCP port number." } } variable "luci_ssh_public_port" { description = "Public TCP port on the relay that forwards Luci SSH CLI traffic to klops" type = number default = 2223 validation { condition = var.luci_ssh_public_port > 0 && var.luci_ssh_public_port < 65536 error_message = "Luci SSH public port must be a valid TCP port number." } } variable "luci_ssh_peer_port" { description = "TCP port on klops that receives forwarded Luci SSH CLI traffic" type = number default = 2223 validation { condition = var.luci_ssh_peer_port > 0 && var.luci_ssh_peer_port < 65536 error_message = "Luci SSH peer port must be a valid TCP port number." } } variable "base_domain" { description = "Base domain for the infrastructure" type = string default = "bugabinga.net" } variable "secrets_subdomain" { description = "Subdomain of the secrets service" type = string default = "secrets" } variable "server_image" { description = "OS Image for the server" type = string default = "fedora-43" } variable "server_type" { description = "Hetzner Server Type" type = string default = "cx23" } variable "location" { description = "Hetzner Datacenter Location" type = string default = "hel1" validation { condition = contains(["nbg1", "hel1", "fsn1", "ash", "hil"], var.location) error_message = "Location must be a valid Hetzner Cloud datacenter (nbg1, hel1, fsn1, ash, hil)." } } # WireGuard Configuration variable "wg_server_ip" { description = "WireGuard Tunnel IP for the VPS (Gateway)" type = string default = "10.100.0.1" } variable "wg_peer_ip" { description = "WireGuard Tunnel IP for the Peer (Home Server)" type = string default = "10.100.0.2" } variable "wg_server_ipv6" { description = "WireGuard ULA IPv6 address for the VPS (Gateway)" type = string default = "fd00:100::1" } variable "wg_peer_ipv6" { description = "WireGuard ULA IPv6 address for the Peer (Home Server)" type = string default = "fd00:100::2" } variable "wg_mtu" { description = "WireGuard interface MTU. Lower than default to avoid path MTU blackholes on residential uplinks." type = number default = 1280 validation { condition = var.wg_mtu >= 1280 && var.wg_mtu <= 1420 error_message = "WireGuard MTU must be between 1280 and 1420." } } # Klops (Home Server) Configuration variable "klops_ssh_host" { description = "Hostname or IP of klops home server" type = string default = "klops" } variable "klops_ssh_port" { description = "SSH port for klops" type = number default = 22 } variable "klops_ssh_user" { description = "SSH user for klops" type = string default = "oli" }