carlos2
Member
OP
- Joined:
- Jun 2024
- Posts:
- 158
- From:
- Medellín, CO
Been grinding for months but I got it. Full repo with Terraform + Ansible for my infra on Contabo and GreenCloudVPS. Spin up environment in ~8 minutes from zero.
Keys are in Vault, state in S3 with locking, the works. If anyone wants to audit or use as reference, link below. Still rough around edges but it deploys.
Looking for feedback especially on:
- module structure (too nested?)
- whether to keep monorepo or split by env
Also which providers take XMR for compute? Asking for a friend who doesn't like paper trails.
not your keys, not your coins
ana_mad
Member
- Joined:
- Jun 2024
- Posts:
- 298
- From:
- Madrid, ES
Sent ticket yesterday to Contabo about their API rate limits, they were very helpful!
Looked at repo, nice work on the Vault integration! One thing: I saw AWS keys in variables.tf? Made test order with same pattern last month and almost got burned. Cheers
swimming upstream since 2019 🐟
haroldgsm
Member
Grumpy Old Sysadmin
- Joined:
- May 2024
- Posts:
- 329
- From:
- Ohio, US
Mark my words, that key has already been scraped by three bots. Rotate it, rotate the rotation policy, then buy a proper secret scanner. The pessimist in me says you'll commit another one within six months.
IPv4, IRC, and irssi — fight me
mediaaustin
Member
Deliverability Nerd
- Joined:
- Jul 2024
- Posts:
- 276
- From:
- Austin, US
Your SPF record on that notification domain is ~all with no DKIM. For what it's worth, your automation could deploy the best infra in the world and your alerts would still hit Gmail's spam folder.
I audited the repo for email hygiene specifically. No DMARC, no TLS-RPT, and that hardcoded key? It's in your SES configuration block. That's how you get on a blocklist before you send message one.
Fix the secrets first. Then fix the mail. Order matters.
SPF, DKIM, DMARC — holy trinity ✉️