MIZOKI Terraform Infrastructure
This directory contains Terraform configurations for deploying and managing MIZOKI infrastructure components.
Directory Structure
terraform/
├── monitoring/ # SLOs, alerts, and dashboards for Cell 6 and SRPVDAL
├── pubsub_cell3_push/ # Pub/Sub topic and OIDC push subscription
├── cell3_secrets/ # Secret Manager for Neo4j credentials
└── (legacy modules) # Original infrastructure modules
Quick Start
1. Pub/Sub Infrastructure (Learn Pipeline)
Creates Pub/Sub topic and push subscription with OIDC authentication to Cell 3:
cd pubsub_cell3_push
terraform init
terraform apply \
-var="project_id=${PROJECT_ID}" \
-var="region=${REGION}" \
-var="cell3_url=https://mizoki-cell3-xxx.run.app" \
-var="push_service_account_email=pubsub-push@${PROJECT_ID}.iam.gserviceaccount.com"
2. Cell 3 Secrets (Neo4j Password) — ⛔ RETIRED, DO NOT APPLY
Owner decision, 2026-08-09: Neo4j is NOT being re-provisioned. Firestore is the knowledge-graph backend, and the Aura host in the
neo4j-urisecret is NXDOMAIN by choice. Cell 3 serves from Firestore — its Neo4j branch is a documented fail-closed no-op (src/cells/cell03/v2/repository_factory.py). Applying this module creates a credential for a database that does not exist and mounts it into a service that will never dial it.The
cell3_secretsmodule is still indeployment/terraform/. Whether to remove it is an infrastructure decision on a protected path, not a documentation one — it is deliberately left in place here, and the retirement is recorded rather than acted on.
Retained for provenance only — do not run:
# OBSOLETE per the 2026-08-09 owner decision.
# cd cell3_secrets
# terraform init
# terraform apply \
# -var="project_id=${PROJECT_ID}" \
# -var="region=${REGION}" \
# -var="cell3_service_account_email=mizoki-cell3@${PROJECT_ID}.iam.gserviceaccount.com" \
# -var="neo4j_password_value=${NEO4J_PASSWORD}"
#
# ./mount-secret.sh ${PROJECT_ID} ${REGION} neo4j-password
3. Monitoring Infrastructure
Creates SLOs, alert policies, and dashboards for Cell 6 (MOE) and SRPVDAL:
cd monitoring
terraform init
# First, get or create notification channels
gcloud alpha monitoring channels list --project=${PROJECT_ID}
# Apply with notification channels
terraform apply \
-var="project_id=${PROJECT_ID}" \
-var="region=${REGION}" \
-var="learn_subscription_id=mizoki-learn-push-cell3" \
-var='notification_channels=["projects/${PROJECT_ID}/notificationChannels/123"]'
Component Details
Monitoring Stack
SLOs: - Cell 6 Availability: 99.9% (30-day rolling) - Cell 6 Latency: P95 ≤ 300ms (99% goal)
Alerts: - MOE error rate > 2% (5 minutes) - P95 latency > 500ms (5 minutes) - Pub/Sub undelivered messages > 0 (5 minutes) - Neo4j errors detected in logs
Dashboard: - MOE execution rates (ok/error) - P95 latency for /api/v1/workflows/execute - HTTP requests by path - Pub/Sub undelivered message count
Pub/Sub Configuration
Topic: mizoki-learn
- Used by SRPVDAL to publish learning outcomes
Subscription: mizoki-learn-push-cell3
- Push endpoint: ${CELL3_URL}/pubsub/push
- OIDC authentication with service account
- Retry policy: 10s-600s backoff
- Dead letter after 10 attempts
Secret Management
Secret: neo4j-password — ⛔ RETIRED 2026-08-09, do not create or rotate.
Neo4j is not being re-provisioned; nothing consumes this value. See the retirement
note under "Cell 3 Secrets" above.
- Automatic replication across regions
- Accessible only by Cell 3 service account
- Mounted as NEO4J_PASSWORD environment variable (Cell 3 reads it, finds no
reachable host, and serves from Firestore — the branch fails closed by design)
Prerequisites
- Service Accounts: ```bash # Create Pub/Sub push service account gcloud iam service-accounts create pubsub-push \ --display-name="Pub/Sub Push Service Account"
# Create Cell 3 service account gcloud iam service-accounts create mizoki-cell3 \ --display-name="Cell 3 Service Account" ```
-
Enable APIs:
bash gcloud services enable \ monitoring.googleapis.com \ pubsub.googleapis.com \ secretmanager.googleapis.com \ run.googleapis.com -
Terraform: - Version 1.0+ required - Google provider ~> 5.0
Environment Variables
Set these before running Terraform:
export PROJECT_ID="your-project-id"
export REGION="us-central1"
export NEO4J_PASSWORD="your-secure-password" # Don't commit!
State Management
For production, configure remote state backend:
terraform {
backend "gcs" {
bucket = "mizoki-terraform-state"
prefix = "terraform/state"
}
}
Validation
After deployment:
-
Test Pub/Sub:
bash gcloud pubsub topics publish mizoki-learn \ --message='{"task":"test","payload":{},"result":{}}' \ --project=${PROJECT_ID} -
Check Secret:
bash gcloud secrets versions list neo4j-password --project=${PROJECT_ID} -
View Dashboard:
bash gcloud monitoring dashboards list --project=${PROJECT_ID} -
Test Alerts: Generate error traffic to Cell 6 and verify alert fires.
Security Notes
- Never commit
neo4j_password_valuein terraform.tfvars - Use environment variables or CI/CD secrets
- ~~Rotate Neo4j password by creating new secret version~~ — retired 2026-08-09; there is no instance to rotate against
- Review IAM bindings regularly
- Enable audit logging for secret access
Legacy Infrastructure
The original Terraform configuration creates base infrastructure:
- GCP APIs: Enables necessary APIs
- Artifact Registry: Docker repository for container images
- IAM Service Account: Dedicated service account for Cloud Run
- IAM Bindings: Necessary roles for the service account
To use legacy modules, see original instructions below.