Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ jobs:
GLPA_TF_VAR_server_administration_ssh_port: ${{ secrets.SERVER_ADMINISTRATION_SSH_PORT }}
GLPA_TF_VAR_server_staging_ip: ${{ secrets.SERVER_STAGING_IP }}
GLPA_TF_VAR_server_staging_ssh_port: ${{ secrets.SERVER_STAGING_SSH_PORT }}
GLPA_TF_VAR_stripe_staging_api_key: ${{ secrets.STRIPE_STAGING_API_KEY }}

- name: Find existing comment
uses: peter-evans/find-comment@v4
Expand Down
23 changes: 19 additions & 4 deletions envs/server_staging/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,17 @@ terraform {
version = "5.25.0"
}
gitlab = {
source = "gitlabhq/gitlab"
source = "gitlabhq/gitlab"
version = "19.4.0"
}
docker = {
source = "kreuzwerker/docker"
version = "4.6.0"
}
stripe = {
source = "stripe/stripe"
version = "0.3.0"
}
}
}

Expand All @@ -22,19 +26,30 @@ provider "cloudflare" {
}

provider "gitlab" {
token = var.gitlab_api_token
token = var.gitlab_api_token
base_url = "https://gitlab.com/api/v4/"
}

provider "docker" {
host = "ssh://pipeline@${var.server_staging_ip}:${var.server_staging_ssh_port}"

cert_path = ""

registry_auth {
address = "registry.gitlab.com"
username = "gitlab-ci-token"
password = var.gitlab_api_token
}
}

provider "stripe" {
api_key = var.stripe_staging_api_key
}

module "staging" {
source = "../../system/staging"

cloudflare_account_id = var.cloudflare_account_id
server_staging_ip = var.server_staging_ip
cloudflare_account_id = var.cloudflare_account_id
server_staging_ip = var.server_staging_ip
stripe_staging_api_key = var.stripe_staging_api_key
}
5 changes: 5 additions & 0 deletions envs/server_staging/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,11 @@ variable "gitlab_api_token" {
sensitive = true
}

variable "stripe_staging_api_key" {
type = string
sensitive = true
}

variable "server_staging_ip" {
type = string
sensitive = true
Expand Down
14 changes: 14 additions & 0 deletions manifests/teleport-config/applications.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,17 @@ metadata:
spec:
uri: http://127.0.0.1:15242
public_addr: staging.codezero.build
---
apiVersion: resources.teleport.dev/v1
kind: TeleportAppV3
metadata:
name: cygnus-staging
labels:
application: cygnus
environment: staging
server: staging
spec:
uri: http://127.0.0.1:15243
public_addr: staging-cygnus.codezero.build
required_app_names:
- codezero-staging
2 changes: 1 addition & 1 deletion manifests/teleport-config/roles.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ spec:
logins:
- teleport-user
app_labels:
"application": "codezero"
"application": ["codezero", "cygnus"]
"environment": "staging"
---
apiVersion: resources.teleport.dev/v1
Expand Down
36 changes: 23 additions & 13 deletions modules/docker/cygnus/cygnus.tf
Original file line number Diff line number Diff line change
@@ -1,10 +1,6 @@
data "docker_registry_image" "cygnus" {
name = "ghcr.io/code0-tech/cygnus:2141"
}

resource "docker_image" "cygnus" {
name = data.docker_registry_image.cygnus.name
pull_triggers = [data.docker_registry_image.cygnus.sha256_digest]
name = var.cygnus_image.name
pull_triggers = [var.cygnus_image.sha256_digest]
}

resource "random_password" "payload_secret" {
Expand All @@ -16,7 +12,7 @@ resource "random_password" "payload_user_password" {
}

resource "random_password" "actions_import_secret" {
length = 64
length = 64
}

data "gitlab_project_variable" "ga_measurement_id" {
Expand Down Expand Up @@ -53,7 +49,7 @@ locals {
"DATABASE_URL=postgresql://cygnus:${random_password.db.result}@${docker_container.postgres.hostname}:5432/payload",
"HOSTNAME=0.0.0.0",
"NEXT_PUBLIC_GA_MEASUREMENT_ID=${sensitive(data.gitlab_project_variable.ga_measurement_id.value)}",
"NEXT_PUBLIC_APP_URL=${var.web_urls[0]}",
"PAYLOAD_SERVER_URL=https://${var.web_urls[0]}",
"ACTIONS_IMPORT_SECRET=${random_password.actions_import_secret.result}",

# Cygnus SMTP
Expand All @@ -70,24 +66,38 @@ locals {
}

resource "docker_volume" "cygnus_media" {
name = "cygnus_media"
name = "${var.docker_name_prefix}cygnus_media"
}

resource "docker_container" "cygnus" {
image = docker_image.cygnus.image_id
name = "cygnus_cygnus"
name = "${var.docker_name_prefix}cygnus_cygnus"
restart = "always"

env = local.cygnus_env
env = concat(local.cygnus_env, var.additional_envs)

network_mode = "bridge"

networks_advanced {
name = docker_network.cygnus.name
}

networks_advanced {
name = var.docker_proxy_network_id
dynamic "networks_advanced" {
for_each = compact([var.docker_additional_network_id])

content {
name = networks_advanced.value
}
}

dynamic "ports" {
for_each = compact([var.http_port])

content {
internal = 3000
external = ports.value
ip = var.bind_ip
}
}

volumes {
Expand Down
2 changes: 1 addition & 1 deletion modules/docker/cygnus/network.tf
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
resource "docker_network" "cygnus" {
name = "cygnus"
name = "${var.docker_name_prefix}cygnus"
}
4 changes: 2 additions & 2 deletions modules/docker/cygnus/postgres.tf
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ resource "docker_image" "postgres" {
}

resource "docker_volume" "pgdata" {
name = "cygnus_pgdata"
name = "${var.docker_name_prefix}cygnus_pgdata"
}

resource "random_password" "db" {
Expand All @@ -28,7 +28,7 @@ locals {
//noinspection HILUnresolvedReference
resource "docker_container" "postgres" {
image = docker_image.postgres.image_id
name = "cygnus_postgres"
name = "${var.docker_name_prefix}cygnus_postgres"
restart = "always"

env = local.postgres_env
Expand Down
39 changes: 37 additions & 2 deletions modules/docker/cygnus/variables.tf
Original file line number Diff line number Diff line change
@@ -1,7 +1,42 @@
variable "docker_proxy_network_id" {
type = string
variable "docker_name_prefix" {
type = string
default = ""
}

variable "docker_additional_network_id" {
type = string
default = null
}

variable "web_urls" {
type = list(string)
}

variable "bind_ip" {
description = <<-EOT
Host IP address to bind the published cygnus ports to. Defaults to null,
which binds on all interfaces (0.0.0.0). Set to "127.0.0.1" to expose the
ports on localhost only (e.g. when running behind an external reverse
proxy).
EOT
type = string
default = null
}

variable "http_port" {
description = "Host port mapped to cygnus' internal port 3000. Set to null to not publish HTTP."
type = number
default = null
}

variable "cygnus_image" {
type = object({
name = string
sha256_digest = string
})
}

variable "additional_envs" {
type = list(string)
default = []
}
3 changes: 2 additions & 1 deletion renovate.json
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,8 @@
},
{
"matchFileNames": [
"modules/docker/**"
"modules/docker/**",
"system/**"
],
"matchDatasources": [
"docker"
Expand Down
16 changes: 12 additions & 4 deletions system/administration/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -53,19 +53,27 @@ module "outline" {
docker_proxy_network_id = module.proxy.docker_proxy_network_id
}

data "docker_registry_image" "cygnus" {
name = "ghcr.io/code0-tech/cygnus:2141"
}

module "cygnus" {
source = "../../modules/docker/cygnus"

web_urls = ["codezero.build"]
docker_proxy_network_id = module.proxy.docker_proxy_network_id
web_urls = ["codezero.build"]
docker_additional_network_id = module.proxy.docker_proxy_network_id
cygnus_image = {
name = data.docker_registry_image.cygnus.name
sha256_digest = data.docker_registry_image.cygnus.sha256_digest
}
}

module "sculptor_playground" {
source = "../../modules/docker/sculptor-playground"

hostname = "playground.codezero.build"
hostname = "playground.codezero.build"
playground_frame_ancestors = "'self' https://codezero.build http://localhost:3000"
docker_proxy_network_id = module.proxy.docker_proxy_network_id
docker_proxy_network_id = module.proxy.docker_proxy_network_id
}

module "pyxis" {
Expand Down
Loading
Loading