forgejo/terraform/variables.tf
Adam Moussa e4982b87ad
feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100)
* feat(terraform): migrate forgejo to HCP Terraform

Move the prod host onto workspace forgejo-prod in the After Hours VPC and freeze CDK push deploys so cutover can happen without applying into seahaven-prod.

* fix(terraform): restore forgejo.db from the dump tarball

Boot restore was copying data/ and repos/ and leaving the sqlite file at the archive root, so a volume restore started Forgejo with no database.
2026-09-29 22:49:21 +00:00

64 lines
2.2 KiB
HCL

variable "aws_region" {
type = string
description = "Primary region. The replica bucket provider is fixed to us-west-2."
default = "us-east-1"
validation {
condition = var.aws_region == "us-east-1"
error_message = "Forgejo primary region is us-east-1."
}
}
variable "ami_id" {
type = string
description = "Pinned Amazon Linux 2023 arm64 AMI. Do not switch this to most_recent. Changing it replaces the instance; the data volume is reattached."
default = "ami-0eb45f74aa8a20238"
validation {
condition = can(regex("^ami-[0-9a-f]+$", var.ami_id))
error_message = "ami_id must be an AMI id."
}
}
variable "forgejo_version" {
type = string
description = "Forgejo release installed by user data. Changing it replaces the instance."
default = "10.0.1"
validation {
condition = can(regex("^[0-9]+\\.[0-9]+\\.[0-9]+$", var.forgejo_version))
error_message = "forgejo_version must be a dotted numeric version."
}
}
variable "existing_vpc_id" {
type = string
description = "After Hours VPC in seahaven-prod (10.70.0.0/16). Set from the afterhours-shift-manager output vpc_id. HCP workspace variable."
validation {
condition = can(regex("^vpc-[0-9a-f]+$", var.existing_vpc_id))
error_message = "existing_vpc_id must be a VPC id."
}
}
variable "existing_public_subnet_ids" {
type = list(string)
description = "Public subnet IDs in existing_vpc_id, at least two AZs. The instance and its data volume use the first subnet's AZ. Set from the afterhours-shift-manager output public_subnet_ids."
validation {
condition = length(var.existing_public_subnet_ids) >= 2
error_message = "ALB requires at least two public subnets."
}
}
variable "enable_https" {
type = bool
description = "Forward the ALB on HTTPS. Leave false until the ACM DNS validation record exists in the mgmt seahaven.com zone and the certificate is Issued."
default = false
}
variable "enable_schedules" {
type = bool
description = "Enable backup-verification schedules and alarms. Leave false until cutover so a disabled checker does not page site-alerts."
default = false
}