| Name | Version |
|---|---|
| terraform | > 1.3 |
| cloudflare | ~> 5.0 |
| Name | Version |
|---|---|
| cloudflare | ~> 5.0 |
| sops | n/a |
No modules.
No inputs.
| Name | Description |
|---|---|
| hero_host_config_warp_service_token_client_id | Cloudflare Access service-token client ID for hero-host-config WARP enrollment |
| hero_host_config_warp_service_token_client_secret | Cloudflare Access service-token client secret for hero-host-config WARP enrollment |
| mcp_gateway_service_token_client_id | CF-Access-Client-Id for MCP gateway clients |
| mcp_gateway_service_token_client_secret | CF-Access-Client-Secret for MCP gateway clients |
| tunnel_ids | Cloudflare Tunnel IDs for reference in kustomize-cluster ConfigMaps |
This root manages the Cloudflare side of kubectl connectivity:
cf-warp.tfdefines the GitHub identity provider andmakeitworkcloud:adminsAccess group.cf-access-k3s.tfapplies that group to the migration fallback atk3s.makeitwork.cloud.cf-tunnels.tfowns theapiandk3sCNAMEs.- The
ClusterTunnelandTunnelBindingmanifests inkustomize-cluster/workloads/kubectl-tunnelown their routes with DNS updates disabled.
Normal kubectl access connects directly to https://api.makeitwork.cloud and
relies on a Dex-issued OIDC token plus Kubernetes RBAC. Cloudflare Access still
protects the legacy TCP route at k3s.makeitwork.cloud during migration. The
canonical kubeconfig and kubelogin procedure lives in the
kustomize-cluster README.
Do not store kubeconfigs, Access tokens, client certificates, or Cloudflare
credentials in this repository.
This root owns only the bootstrap tunnel DNS required to reach the Kubernetes
API before cluster workloads are available. TunnelBinding owns workload
tunnel DNS, including the MCP gateway endpoints. Do not add a workload hostname
to this OpenTofu root.
cf-opencode-hsts.tf configures the zone response-header ruleset with a rule
matching only HTTPS requests to opencode.makeitwork.cloud. It sets
Strict-Transport-Security: max-age=86400 (one day), without
includeSubDomains or preload. Native OpenCode authentication and existing
HTTPS redirection are unchanged. No Cloudflare Access, workload DNS/tunnel,
or AWX cleanup is included.
This root owns the response-header entrypoint. Review and preserve its full
rule list before adding other header rules; do not create a competing
entrypoint or adopt an existing one without reviewing its rules. PR CI plans
validate the proposed changes; main runs a fresh environment-associated
apply, not the saved PR plan. Merge and apply authorization are separate.
After approved apply, verify the HTTPS UI and unauthenticated API responses carry the header, native phone login and session continuity still work, and sibling hostnames are unaffected. A successful plan is not live verification.
For rollback, first serve max-age=0 over HTTPS through this rule, then remove
it after the rollback has been reviewed and applied. Simply removing the
header does not clear browser policies; they otherwise expire up to one day
after their last receipt. Preserve HTTPS throughout.