infra
# ~/projects/magellan/infra.yml
infra:
status: active
started: 2026-09-23
tags: [opentofu, ansible, grafana, oracle-cloud]Tofu creates an Oracle Cloud VM, the one I had at hand, and its compute is plenty for Grafana. Ansible then sets up every host: the device service on the boards, and Grafana on the VM, served through Cloudflare. Every host joins a private tailnet for SSH.
Why separate
The device and cloud repositories build software. This one only runs it, so a server change never mixes with a code change. It also holds the private details of the deployment, like addresses and the encrypted secrets, so it stays private while the code does not have to.
Decisions
- A shared baseline. OS, SSH and the other common setup come from ansible-infra, a collection reused across projects. This repository adds only Magellan’s own services.
- Roles by group. A host runs the device service or Grafana because of the group it is in. A new board is an inventory entry and its vault.
- Grafana, not a dashboard of my own. Grafana gives any panel and alert I want without writing a frontend. The price is a VM to run and keep. It reads the cloud’s API like any other client, and its dashboards and alert rules are files in the repository, not clicks in a UI.
- SSH over Tailscale. I reach every host, boards and VM alike, over a tailnet, and the shared baseline hardens sshd.
- Safe to run twice. A second run of a playbook changes nothing, and secrets stay in an encrypted vault.