Deploy note:
terraform applyrequirescompartment_ocid(your OCI root tenancy OCID — OCI Console → Profile → Tenancy). Terraform prompts for it, or setTF_VAR_compartment_ocid/ pass-var.
changedetection/— changedetection.io inus-ashburn-1(2 OCPU, 12GB, 50GB boot)
Terraform (changedetection/main.tf, etc.):
- Separate Terraform state from root VM
- VCN (10.1.0.0/16) + subnet (10.1.0.0/24) + internet gateway
- VM.Standard.A1.Flex instance (ARM64, 2 OCPU, 12GB RAM, 50GB boot) in us-ashburn-1
NixOS (changedetection/flake.nix, changedetection/configuration.nix):
- Podman containers (declarative via
virtualisation.oci-containers):changedetection— ghcr.io/dgtlmoon/changedetection.io:latest (port 5000)browser-chrome— dgtlmoon/sockpuppetbrowser:latest (Playwright for JS-heavy career pages)
- Tailscale Funnel exposes port 5000 publicly via HTTPS (
https://<hostname>.ts.net) - Firewall: SSH 22, Tailscale UDP 41641 (Funnel traffic arrives via tailscale0, no extra ports needed)
- Auto-upgrades enabled, no auto-reboot
Secrets (secrets.nix — gitignored):
- Contains
{ tailscaleAuthKey = "<auth-key>" }, conditionally imported with null fallback - Each VM needs its own Tailscale auth key
- SSH key (Ed25519) duplicated in
variables.tfandconfiguration.nix— keep in sync