Terraform/OpenTofu-managed infrastructure for the user's Proxmox homelab.
Note
Version numbers are not tracked in this README. For docker-apps services, check the running
container directly (Watchtower updates them without committing changes here). For everything
else, check the pinned version in that module's main.tf/project.auto.tfvars.
This module and its sub-modules setup the Proxmox host. |
Creates the OPNsense router/firewall VM. WAN attaches untagged to var.wan_bridge (gets its address from upstream, e.g. via DHCP during the test phase). LAN attaches untagged/trunk to var.lan_bridge - OPNsense itself defines VLAN sub-interfaces on top of that one interface. |
This module sets up Samba server in an Alpine LXC container using the provided information. |
This module sets up Step-CA in an Alpine LXC container using the provided information. |
This module sets up Proxmox Backup Server in a Debian LXC container, using /mnt/backup/pbs (bind-mounted from the host) as the datastore location. Replaces modules/pbs-vm as the deployed PBS instance -- that module is kept in the repo as a fallback option, but no longer applied. |
This module sets up a Flatcar Linux VM with Docker. |
Registers Proxmox Backup Server as a PVE storage target, creates one dedicated backup job per guest (VM/LXC primary disks), and one host-level folder backup per entry in var.folders (real data the guest-level jobs never touch - bind-mounted LXC state, the family file shares, PVE's own recovery-relevant config). |
Not Terraform-managed - present on the network, documented here for reference only.
Note
Deploying a docker-apps service is two steps: tofu apply in the module's own directory, then docker compose -f docker-compose.yml --env-file stack.env up -d on the Docker VM.
This module creates resources, that are not supposed to be part of a docker-compose.yml. |
This module uses the OIDC module to create the necessary client_id to set up OIDC/OAuth for Traefik (dashboard) with Zitadel. |
Identity and access management (SSO/OIDC) used by every other docker-apps service |
This module uses the OIDC module to create the necessary client_id and client_secret to set up OIDC/OAuth in Portainer with Zitadel. |
Creates the necessary Zitadel resources (project, OIDC app, roles, user grants) for Gitea to authenticate via Zitadel SSO. |
This module uses the OIDC module to create the necessary client_id to set up OIDC/OAuth for Grafana Alloy and Prometheus with Zitadel. |
This module uses the OIDC module to create the necessary client_id to set up OIDC/OAuth in Grafana with Zitadel. |
This module uses the OIDC module to create the necessary client_id and client_secret to set up OIDC/OAuth in Outline with Zitadel. |
This module uses the OIDC module to create the necessary client_id to set up OIDC/OAuth for Jellyfin (dashboard) with Zitadel. |
This module uses the OIDC module to create the necessary client_id and client_secret to set up OIDC/OAuth in Grist with Zitadel. |
Automatically restarts containers when a newer image is pushed |
Mosquitto broker for Tasmota smart plugs, exported to Prometheus via mqtt-exporter |
Automated network topology mapping (L2/L3/workloads) - experimental, unfamiliar tool, evaluate before trusting |
Unified dashboard - container/hardware overview, service bookmarks, per-group boards via SSO |
| common |
| Pi-hole Setup Not currently in use - superseded by OPNsense's Unbound DNS (blocklists, host overrides, reporting). Kept in the repo as a fallback option, not applied. |
| Scanopy Daemon (standalone LXC) Runs a standalone scanopy-daemon in a Debian LXC container, dual-homed onto every VLAN (vmbr1.5/10/20/30/40) so it has genuine ARP-level presence on each subnet - unlike SNMP-relayed discovery (via OPNsense's ARP/routing tables), this catches hosts with no open ports and gets real MACs directly. |