Files
iac/main.tf
Melchior Reimers d9f510f361
Some checks failed
Deployment / deploy-docker (push) Failing after 13s
source instead of destination ips
2026-02-04 20:03:41 +01:00

96 lines
2.2 KiB
HCL
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# SSH Key
resource "hcloud_ssh_key" "default" {
name = local.ssh_key_name
public_key = var.ssh_public_key
}
# Cloud-init script
locals {
ssh_key_name = length(trimspace(var.ssh_key_name)) > 0 ? var.ssh_key_name : "${var.server_name}-ssh-key"
user_data = templatefile("${path.module}/scripts/cloud-init.sh", {
username = var.username
ssh_public_key = var.ssh_public_key
distro_id = var.distro_id
distro_codename = var.distro_codename
})
}
# Server
resource "hcloud_server" "vps" {
name = var.server_name
image = var.image
server_type = data.hcloud_server_type.selected.name
location = data.hcloud_location.selected.name
ssh_keys = concat([hcloud_ssh_key.default.id])
user_data = local.user_data
labels = {
app = "openclaw"
os = "ubuntu24"
virt = "docker"
managed-by = "terraform"
environment = var.environment
}
}
# Firewall – locked down by default
resource "hcloud_firewall" "vps" {
name = "${var.server_name}-firewall"
# ICMP for diagnostics
rule {
direction = "in"
protocol = "icmp"
source_ips = ["0.0.0.0/0", "::/0"]
description = "ICMP (ping)"
}
# Egress – allow all (Hetzner default, but explicit is better)
rule {
direction = "out"
protocol = "tcp"
port = "1-65535"
destination_ips = ["0.0.0.0/0", "::/0"]
description = "All TCP outbound"
}
rule {
direction = "out"
protocol = "udp"
port = "1-65535"
source_ips = ["0.0.0.0/0", "::/0"]
description = "All UDP outbound"
}
rule {
direction = "out"
protocol = "icmp"
destination_ips = ["0.0.0.0/0", "::/0"]
description = "ICMP outbound"
}
rule {
direction = "in"
protocol = "tcp"
port = "22"
destination_ips = ["0.0.0.0/0", "::/0"]
description = "ssh outbound"
}
}
resource "hcloud_firewall_attachment" "vps" {
firewall_id = hcloud_firewall.vps.id
server_ids = [hcloud_server.vps.id]
}
variable "distro_id" {
type = string
default = "ubuntu"
}
variable "distro_codename" {
type = string
default = "noble" # Das wäre der Codename für Ubuntu 24.04
}