Sample Deployment
A reference OpenTofu configuration that composes the Merkalis Azure modules by
hand — networking, secrets, objectstore, queue, compute, gateway,
and telemetry wired together directly, so that every connection between modules
is visible. It provisions the same stack shown in the
reference deployment diagram.
The configuration is consumed from the Distribution Registry as signed OCI module packages, which is the same route every external consumer uses.
| Page | Contents |
|---|---|
| Configuration | The full configuration files: main.tf, variables.tf, and the per-environment values |
| Walkthrough | Module sources, build order, the wiring you own, prerequisites, and gotchas |
For the per-edge output→input tables, see Module Dependencies.
What it covers
Object storage shards, the shared storage-accessor identity, Key Vault secret
injection into container apps, CORS between two apps, internal-only ingress,
cron-triggered container jobs, the event notification queue
and its queue_writer wiring, and the mTLS gateway proxy with
enable_grafana = false telemetry.
What it omits on purpose
The reverse proxy container app and the Cloudflare Tunnel
(proxy_enabled = false, cloudflared_enabled = false), file store and share
mounts (see the appendix in
Walkthrough),
the optional database module, workload profiles other than the Consumption
default, and Grafana telemetry wiring.
Intentionally not applied as-is
This is a teaching configuration: the state backend block is commented out so the configuration validates without provisioning state storage, and it is not meant to be applied directly. Adapt the naming, backend, and environment values to your own subscription before planning.
Validation
docker login acrmerkalisdist0c66.azurecr.io # OpenTofu reads ~/.docker/config.json
tofu init -backend=false
tofu fmt -check
tofu validate
tofu plan additionally needs a real subscription, an ACR containing the
referenced application images (kastoria-ohif, kastoria-health,
kastoria-smart-launch-api, kastoria-consoleapi, kastoria-consoleui,
kastoria-studyprocessor, kastoria-eventnotification, kastoria-proxy and
kastoria-proxy-mtls), and the
Key Vault secrets described in
Walkthrough.