homelab-nomad/services/main.tf

182 lines
4.3 KiB
HCL

# module "nextcloud" {
# source = "./nextcloud"
#
# depends_on = [module.databases]
# }
module "backups" {
source = "./backups"
# In parent module
# depends_on = [module.databases]
}
module "media" {
source = "./media"
}
resource "nomad_job" "whoami" {
hcl2 {
enabled = true
vars = {
"count" = 1,
# "count" = "${2 * length(data.consul_service.nomad.service)}",
}
}
jobspec = file("${path.module}/whoami.nomad")
}
resource "nomad_job" "ipdvr" {
jobspec = file("${path.module}/ip-dvr.nomad")
}
resource "consul_config_entry" "nzbget_intents" {
depends_on = [nomad_job.ipdvr]
name = "nzbget"
kind = "service-intentions"
config_json = jsonencode({
Sources = [
{
Action = "allow"
Name = "sonarr"
Precedence = 9
Type = "consul"
},
]
})
}
module "minitor" {
source = "./service"
name = "minitor"
args = ["-metrics", "-config=$${NOMAD_TASK_DIR}/config.yml"]
image = "iamthefij/minitor-go:1.1"
service_port = 8080
metrics_port_name = "main"
healthcheck_path = "/metrics"
use_vault = true
templates = [
{
data = <<EOF
{{ with secret "kv/data/mailgun_api" -}}
MAILGUN_API_KEY={{ .Data.data.key }}
{{ end -}}
EOF
dest = "env"
dest_prefix = "$${NOMAD_SECRETS_DIR}/"
env = true
},
{
data = file("${path.module}/minitor-config.yml")
left_delimiter = "[["
right_delimiter = "]]"
dest = "config.yml"
mount = false
},
]
}
module "photoprism_module" {
source = "./service"
name = "photoprism"
image = "photoprism/photoprism:221105-jammy"
ingress = true
service_port = 2342
sticky_disk = true
healthcheck_path = "/library/login"
env = {
# UI
PHOTOPRISM_SITE_CAPTION = "AI-Powered Photos App"
PHOTOPRISM_SITE_DESCRIPTION = "Fijolek home photos"
PHOTOPRISM_SITE_TITLE = "PhotoPrism"
PHOTOPRISM_SITE_URL = "https://photoprism.thefij.rocks/"
PHOTOPRISM_SPONSOR = "true"
# Worker config
PHOTOPRISM_WORKERS = 2
# Paths
PHOTOPRISM_ORIGINALS_PATH = "/photoprism-media/Library"
PHOTOPRISM_IMPORT_PATH = "/photoprism-media/Import"
PHOTOPRISM_STORAGE_PATH = "$${NOMAD_TASK_DIR}/storage" # Storage PATH for generated files like cache and index
# Unix permissions
PHOTOPRISM_UID = 500
PHOTOPRISM_GID = 100
PHOTOPRISM_UMASK = 0000
}
resources = {
cpu = 1000
memory = 2000
# memory_max = 2000
}
use_mysql = true
use_vault = true
host_volumes = [
{
name = "photoprism-media"
dest = "/photoprism-media"
read_only = false
},
]
mysql_bootstrap = {
vault_key = "kv/data/photoprism"
}
templates = [
{
data = <<EOF
{{ with secret "kv/data/photoprism" -}}
PHOTOPRISM_ADMIN_USER={{ .Data.data.admin_user }}
PHOTOPRISM_ADMIN_PASSWORD={{ .Data.data.admin_password }}
PHOTOPRISM_DATABASE_DRIVER=mysql
PHOTOPRISM_DATABASE_NAME={{ .Data.data.db_name }}
PHOTOPRISM_DATABASE_USER={{ .Data.data.db_user }}
PHOTOPRISM_DATABASE_PASSWORD={{ .Data.data.db_pass }}
PHOTOPRISM_DATABASE_SERVER="{{ env "NOMAD_UPSTREAM_ADDR_mysql_server" }}"
{{ end -}}
EOF
dest_prefix = "$${NOMAD_SECRETS_DIR}/"
dest = "env"
env = true
mount = false
},
]
}
module "diun" {
source = "./service"
name = "diun"
image = "crazymax/diun:4.24"
args = ["serve", "--log-level=debug"]
env = {
DIUN_DB_PATH = "$${NOMAD_TASK_DIR}/diun.db"
DIUN_WATCH_SCHEDULE = "0 */6 * * *"
DIUN_PROVIDERS_NOMAD_WATCHBYDEFAULT = true
# Nomad API
NOMAD_ADDR = "http://$${attr.unique.network.ip-address}:4646/"
DIUN_PROVIDERS_NOMAD = true
}
use_vault = true
templates = [
{
data = <<EOF
{{ with secret "kv/data/slack" -}}
DIUN_NOTIF_SLACK_WEBHOOKURL={{ .Data.data.hook_url }}
{{ end -}}
EOF
dest_prefix = "$${NOMAD_SECRETS_DIR}"
dest = "env"
env = true
mount = false
},
]
}