Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018BAUeCFpDkRD6tU5wGsc1C
121 lines
3.6 KiB
HCL
121 lines
3.6 KiB
HCL
variable "hcloud_token" {
|
|
description = "Token API Hetzner Cloud (Read & Write), projet xpeditis-prod uniquement."
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
variable "project_name" {
|
|
description = "Prefixe applique a toutes les ressources."
|
|
type = string
|
|
default = "xpeditis-prod"
|
|
}
|
|
|
|
variable "location" {
|
|
description = "Datacenter Hetzner. fsn1 = Falkenstein (DE), nbg1 = Nuremberg (DE), hel1 = Helsinki (FI). Rester dans l'UE pour le RGPD."
|
|
type = string
|
|
default = "fsn1"
|
|
|
|
validation {
|
|
condition = contains(["fsn1", "nbg1", "hel1"], var.location)
|
|
error_message = "Le RGPD impose de rester en UE : fsn1, nbg1 ou hel1."
|
|
}
|
|
}
|
|
|
|
# --- Dimensionnement (cf. Xpeditis_Previsions_Couts.xlsx, feuille Hetzner) ---
|
|
|
|
variable "app_server_type" {
|
|
description = "Type du noeud applicatif (k3s server + pods). CPX41 = 8 vCPU / 16 Go / 240 Go."
|
|
type = string
|
|
default = "cpx41"
|
|
}
|
|
|
|
variable "db_server_type" {
|
|
description = "Type du noeud de donnees (PostgreSQL + Redis). CPX31 = 4 vCPU / 8 Go / 160 Go."
|
|
type = string
|
|
default = "cpx31"
|
|
}
|
|
|
|
variable "image" {
|
|
description = "Image systeme de base."
|
|
type = string
|
|
default = "ubuntu-24.04"
|
|
}
|
|
|
|
variable "db_volume_size" {
|
|
description = "Volume dedie aux donnees PostgreSQL, en Go. Detache du disque systeme : on peut agrandir, snapshotter et reattacher sans toucher au serveur."
|
|
type = number
|
|
default = 50
|
|
}
|
|
|
|
variable "enable_hetzner_backups" {
|
|
description = "Snapshots automatiques Hetzner (+20% du prix du serveur). Ce n'est PAS une strategie de sauvegarde suffisante : cf. 12-sauvegardes-restauration.md."
|
|
type = bool
|
|
default = true
|
|
}
|
|
|
|
# --- Reseau ------------------------------------------------------------------
|
|
|
|
variable "network_cidr" {
|
|
description = "CIDR du reseau prive Hetzner."
|
|
type = string
|
|
default = "10.10.0.0/16"
|
|
}
|
|
|
|
variable "subnet_cidr" {
|
|
description = "CIDR du sous-reseau."
|
|
type = string
|
|
default = "10.10.1.0/24"
|
|
}
|
|
|
|
variable "app_private_ip" {
|
|
description = "IP privee fixe du noeud applicatif."
|
|
type = string
|
|
default = "10.10.1.10"
|
|
}
|
|
|
|
variable "db_private_ip" {
|
|
description = "IP privee fixe du noeud de donnees."
|
|
type = string
|
|
default = "10.10.1.20"
|
|
}
|
|
|
|
# --- Acces administrateur ----------------------------------------------------
|
|
|
|
variable "ssh_public_key" {
|
|
description = "Cle publique SSH (ed25519) de l'administrateur. C'est la seule methode d'authentification autorisee sur les serveurs."
|
|
type = string
|
|
}
|
|
|
|
variable "admin_ip_allowlist" {
|
|
description = <<-EOT
|
|
IPs/CIDR autorises a atteindre SSH (22) et l'API Kubernetes (6443).
|
|
Mettez votre IP fixe ou celle de votre VPN, JAMAIS 0.0.0.0/0.
|
|
Format CIDR obligatoire, ex. ["203.0.113.7/32"].
|
|
EOT
|
|
type = list(string)
|
|
|
|
validation {
|
|
condition = !contains(var.admin_ip_allowlist, "0.0.0.0/0")
|
|
error_message = "Ouvrir SSH et l'API k3s au monde entier est interdit. Renseignez votre IP en /32."
|
|
}
|
|
}
|
|
|
|
variable "deploy_user" {
|
|
description = "Compte non-root utilise pour l'administration et les deploiements."
|
|
type = string
|
|
default = "deploy"
|
|
}
|
|
|
|
# --- Cloudflare --------------------------------------------------------------
|
|
|
|
variable "restrict_http_to_cloudflare" {
|
|
description = <<-EOT
|
|
Si true, seuls les rangs d'IP Cloudflare peuvent joindre 80/443 sur le noeud
|
|
applicatif : impossible de contourner le WAF en tapant l'IP d'origine.
|
|
Mettre a false UNIQUEMENT le temps d'emettre le premier certificat en HTTP-01
|
|
ou si le proxy Cloudflare (nuage orange) est desactive.
|
|
EOT
|
|
type = bool
|
|
default = true
|
|
}
|