feat: total revamp of homelab configuration

This commit is contained in:
2025-11-15 13:22:49 +05:00
parent c59ee18d09
commit 5d95773722

38
main.ts
View File

@@ -1,9 +1,10 @@
import * as dotenv from "dotenv"; import * as dotenv from "dotenv";
import { cleanEnv, str } from "envalid"; import { cleanEnv, str } from "envalid";
import { Construct } from "constructs"; import { Construct } from "constructs";
import { App, TerraformStack, S3Backend } from "cdktf"; import { App, TerraformStack, LocalBackend } from "cdktf";
import { HelmProvider } from "@cdktf/provider-helm/lib/provider"; import { HelmProvider } from "@cdktf/provider-helm/lib/provider";
import { KubernetesProvider } from "@cdktf/provider-kubernetes/lib/provider"; import { KubernetesProvider } from "@cdktf/provider-kubernetes/lib/provider";
import { NamespaceV1 } from "@cdktf/provider-kubernetes/lib/namespace-v1";
import { GiteaServer } from "./gitea"; import { GiteaServer } from "./gitea";
import { OnePassword } from "./1password"; import { OnePassword } from "./1password";
@@ -12,7 +13,6 @@ import { Longhorn } from "./longhorn";
import { AuthentikServer } from "./authentik"; import { AuthentikServer } from "./authentik";
import { ValkeyCluster } from "./valkey"; import { ValkeyCluster } from "./valkey";
import { CertManager } from "./cert-manager"; import { CertManager } from "./cert-manager";
import { Manifest } from "@cdktf/provider-kubernetes/lib/manifest";
import { Nginx } from "./nginx"; import { Nginx } from "./nginx";
import { Prometheus } from "./prometheus"; import { Prometheus } from "./prometheus";
import { MetalLB } from "./metallb"; import { MetalLB } from "./metallb";
@@ -45,15 +45,10 @@ class Homelab extends TerraformStack {
const namespace = "homelab"; const namespace = "homelab";
const ns = new Manifest(this, "namespace", { new NamespaceV1(this, "namespace", {
provider: kubernetes, provider: kubernetes,
manifest: { metadata: {
kind: "Namespace", name: namespace,
apiVersion: "v1",
metadata: {
name: namespace,
},
spec: {},
}, },
}); });
@@ -65,12 +60,10 @@ class Homelab extends TerraformStack {
}, },
}); });
longhorn.node.addDependency(ns);
new MetalLB(this, "metallb", { new MetalLB(this, "metallb", {
provider: helm, provider: helm,
name: "metallb", name: "metallb",
namespace, namespace: "metallb-system",
}); });
new OnePassword(this, "one-password", { new OnePassword(this, "one-password", {
@@ -121,7 +114,6 @@ class Homelab extends TerraformStack {
kubernetes, kubernetes,
helm, helm,
}, },
storageClass: "longhorn-crypto",
users: ["shahab", "budget-tracker", "authentik", "gitea"], users: ["shahab", "budget-tracker", "authentik", "gitea"],
primaryUser: "shahab", primaryUser: "shahab",
initSecretName: "postgres-password", initSecretName: "postgres-password",
@@ -156,21 +148,9 @@ class Homelab extends TerraformStack {
const app = new App(); const app = new App();
const stack = new Homelab(app, "homelab"); const stack = new Homelab(app, "homelab");
new S3Backend(stack, { new LocalBackend(stack, {
encrypt: true, path: "terraform.tfstate",
bucket: env.BUCKET, workspaceDir: ".",
key: "terraform.tfstate",
region: "auto",
skipCredentialsValidation: true,
skipMetadataApiCheck: true,
skipRegionValidation: true,
skipRequestingAccountId: true,
skipS3Checksum: true,
accessKey: env.R2_ACCESS_KEY_ID,
secretKey: env.R2_SECRET_ACCESS_KEY,
endpoints: {
s3: `${r2Endpoint}/${env.BUCKET}`,
},
}); });
app.synth(); app.synth();