3.2 KiB
3.2 KiB
Required values
This stack needs two kinds of inputs:
- Bootstrap / infra values for OpenTofu.
- Runtime secrets for Ansible and the services it configures.
OpenTofu / infrastructure
| Variable | Required | Where used | Notes |
|---|---|---|---|
AWS_ACCESS_KEY_ID |
Yes | tofu init / state backend |
Cloudflare R2 access key for the OpenTofu state bucket. |
AWS_SECRET_ACCESS_KEY |
Yes | tofu init / state backend |
Cloudflare R2 secret key for the OpenTofu state bucket. |
hcloud_token |
Yes | Hetzner API provider | Hetzner Cloud API token with read/write access. |
hetzner_s3_access_key |
Yes | Hetzner Object Storage provider | S3 access key for the telemetry buckets. |
hetzner_s3_secret_key |
Yes | Hetzner Object Storage provider | S3 secret key for the telemetry buckets. |
ssh_public_key |
Yes | Hetzner SSH key / initial root access | ed25519 public key used to reach the server on first boot. |
admin_allow_ipv4 |
Usually | Host firewall / WireGuard allow list | CIDRs allowed to reach SSH and WireGuard. Default is 0.0.0.0/0, but you should tighten it. |
admin_allow_ipv6 |
Usually | Host firewall / WireGuard allow list | IPv6 version of the same allow list. Default is ::/0. |
Ansible vault values
Store these in ansible/group_vars/all/vault.yml and encrypt it with ansible-vault:
| Variable | Required | Where used | Notes |
|---|---|---|---|
vault_hetzner_s3_access_key |
Yes | Runtime S3 credentials | Written to /etc/observability/secrets/s3.env. |
vault_hetzner_s3_secret_key |
Yes | Runtime S3 credentials | Written to /etc/observability/secrets/s3.env. |
vault_grafana_admin_password |
Yes | Grafana admin login | Used by Grafana and tenant onboarding playbooks. |
vault_wireguard_server_private_key |
Yes | WireGuard server config | Server private key for wg0. |
vault_wireguard_server_public_key |
Yes | WireGuard server config | Server public key shared with clients. |
vault_wireguard_peers |
Yes | WireGuard client config | At least one peer entry is needed if you want to connect remotely. |
Each peer entry in vault_wireguard_peers should contain:
| Field | Required | Notes |
|---|---|---|
name |
Yes | Friendly peer name. |
public_key |
Yes | Client WireGuard public key. |
allowed_ips |
Yes | Usually a /32 from 10.8.0.0/24. |
preshared_key |
No | Optional extra protection. |
Service passwords / tokens
| Variable | Required | Where used | Notes |
|---|---|---|---|
grafana_admin_password |
Yes | Grafana UI and API | Bootstraps Grafana admin access. |
Minimum set to get the stack running
To fully deploy and log in, you need at least:
AWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEYhcloud_tokenhetzner_s3_access_keyandhetzner_s3_secret_keyssh_public_keyvault_hetzner_s3_access_keyandvault_hetzner_s3_secret_keyvault_grafana_admin_passwordvault_wireguard_server_private_keyandvault_wireguard_server_public_key- one
vault_wireguard_peersentry
What is not secret
These are still required, but they do not need to be treated as secrets:
admin_allow_ipv4admin_allow_ipv6bucket_prefixserver_namelocationserver_type