Skip to content

Sample Deployment

A reference OpenTofu configuration that composes the Merkalis Azure modules by hand — networking, secrets, objectstore, queue, compute, gateway, and telemetry wired together directly, so that every connection between modules is visible. It provisions the same stack shown in the reference deployment diagram.

The configuration is consumed from the Distribution Registry as signed OCI module packages, which is the same route every external consumer uses.

Page Contents
Configuration The full configuration files: main.tf, variables.tf, and the per-environment values
Walkthrough Module sources, build order, the wiring you own, prerequisites, and gotchas

For the per-edge output→input tables, see Module Dependencies.

What it covers

Object storage shards, the shared storage-accessor identity, Key Vault secret injection into container apps, CORS between two apps, internal-only ingress, cron-triggered container jobs, the event notification queue and its queue_writer wiring, and the mTLS gateway proxy with enable_grafana = false telemetry.

What it omits on purpose

The reverse proxy container app and the Cloudflare Tunnel (proxy_enabled = false, cloudflared_enabled = false), file store and share mounts (see the appendix in Walkthrough), the optional database module, workload profiles other than the Consumption default, and Grafana telemetry wiring.

Intentionally not applied as-is

This is a teaching configuration: the state backend block is commented out so the configuration validates without provisioning state storage, and it is not meant to be applied directly. Adapt the naming, backend, and environment values to your own subscription before planning.

Validation

docker login acrmerkalisdist0c66.azurecr.io   # OpenTofu reads ~/.docker/config.json
tofu init -backend=false
tofu fmt -check
tofu validate

tofu plan additionally needs a real subscription, an ACR containing the referenced application images (kastoria-ohif, kastoria-health, kastoria-smart-launch-api, kastoria-consoleapi, kastoria-consoleui, kastoria-studyprocessor, kastoria-eventnotification, kastoria-proxy and kastoria-proxy-mtls), and the Key Vault secrets described in Walkthrough.