- This commit introduces the Terraform configuration to provision a production environment on Hetzner Cloud, building on the existing test setup. - Key improvements and new features include: * **Multi-node clusters:** Scaling to 3-node Swarm application and database clusters for improved resilience. * **High availability:** Utilizing a Hetzner Floating IP for the application entry point and `spread` placement groups for fault tolerance across physical hosts. * **Enhanced network security:** Internal management services (RabbitMQ, APISIX, Prometheus, Grafana) are restricted to the application subnet, expected to be accessed via an internal reverse proxy (SWAG). * **Internal database replication:** New firewall rules enable PostgreSQL replication and MongoDB replica set traffic within the database subnet. * **Refined test environment:** Updates to align `test` configuration with the new `prod` structure, including a dedicated floating IP and adjusted firewall rules. * **Configuration standardization:** Environment-specific details moved to `locals.tf` for clarity, with upgraded server types and migration to Rocky Linux as the base image. - Updates were also made to the latest version of Terraform to ensure consistency in the documentation
23 lines
529 B
HCL
23 lines
529 B
HCL
resource "hcloud_network" "main" {
|
|
name = "${local.name_prefix}-net"
|
|
ip_range = local.network_cidr
|
|
|
|
labels = {
|
|
environment = local.environment
|
|
}
|
|
}
|
|
|
|
resource "hcloud_network_subnet" "app" {
|
|
network_id = hcloud_network.main.id
|
|
type = "cloud"
|
|
network_zone = local.network_zone
|
|
ip_range = local.app_subnet_cidr
|
|
}
|
|
|
|
resource "hcloud_network_subnet" "db" {
|
|
network_id = hcloud_network.main.id
|
|
type = "cloud"
|
|
network_zone = local.network_zone
|
|
ip_range = local.db_subnet_cidr
|
|
}
|