MIZOKI Terraform Infrastructure

This directory contains Terraform configurations for deploying and managing MIZOKI infrastructure components.

Directory Structure

terraform/
├── monitoring/           # SLOs, alerts, and dashboards for Cell 6 and SRPVDAL
├── pubsub_cell3_push/   # Pub/Sub topic and OIDC push subscription
├── cell3_secrets/       # Secret Manager for Neo4j credentials
└── (legacy modules)     # Original infrastructure modules

Quick Start

1. Pub/Sub Infrastructure (Learn Pipeline)

Creates Pub/Sub topic and push subscription with OIDC authentication to Cell 3:

cd pubsub_cell3_push
terraform init
terraform apply \
  -var="project_id=${PROJECT_ID}" \
  -var="region=${REGION}" \
  -var="cell3_url=https://mizoki-cell3-xxx.run.app" \
  -var="push_service_account_email=pubsub-push@${PROJECT_ID}.iam.gserviceaccount.com"

2. Cell 3 Secrets (Neo4j Password) — ⛔ RETIRED, DO NOT APPLY

Owner decision, 2026-08-09: Neo4j is NOT being re-provisioned. Firestore is the knowledge-graph backend, and the Aura host in the neo4j-uri secret is NXDOMAIN by choice. Cell 3 serves from Firestore — its Neo4j branch is a documented fail-closed no-op (src/cells/cell03/v2/repository_factory.py). Applying this module creates a credential for a database that does not exist and mounts it into a service that will never dial it.

The cell3_secrets module is still in deployment/terraform/. Whether to remove it is an infrastructure decision on a protected path, not a documentation one — it is deliberately left in place here, and the retirement is recorded rather than acted on.

Retained for provenance only — do not run:

# OBSOLETE per the 2026-08-09 owner decision.
# cd cell3_secrets
# terraform init
# terraform apply \
#   -var="project_id=${PROJECT_ID}" \
#   -var="region=${REGION}" \
#   -var="cell3_service_account_email=mizoki-cell3@${PROJECT_ID}.iam.gserviceaccount.com" \
#   -var="neo4j_password_value=${NEO4J_PASSWORD}"
#
# ./mount-secret.sh ${PROJECT_ID} ${REGION} neo4j-password

3. Monitoring Infrastructure

Creates SLOs, alert policies, and dashboards for Cell 6 (MOE) and SRPVDAL:

cd monitoring
terraform init

# First, get or create notification channels
gcloud alpha monitoring channels list --project=${PROJECT_ID}

# Apply with notification channels
terraform apply \
  -var="project_id=${PROJECT_ID}" \
  -var="region=${REGION}" \
  -var="learn_subscription_id=mizoki-learn-push-cell3" \
  -var='notification_channels=["projects/${PROJECT_ID}/notificationChannels/123"]'

Component Details

Monitoring Stack

SLOs: - Cell 6 Availability: 99.9% (30-day rolling) - Cell 6 Latency: P95 ≤ 300ms (99% goal)

Alerts: - MOE error rate > 2% (5 minutes) - P95 latency > 500ms (5 minutes) - Pub/Sub undelivered messages > 0 (5 minutes) - Neo4j errors detected in logs

Dashboard: - MOE execution rates (ok/error) - P95 latency for /api/v1/workflows/execute - HTTP requests by path - Pub/Sub undelivered message count

Pub/Sub Configuration

Topic: mizoki-learn - Used by SRPVDAL to publish learning outcomes

Subscription: mizoki-learn-push-cell3 - Push endpoint: ${CELL3_URL}/pubsub/push - OIDC authentication with service account - Retry policy: 10s-600s backoff - Dead letter after 10 attempts

Secret Management

Secret: neo4j-password — ⛔ RETIRED 2026-08-09, do not create or rotate. Neo4j is not being re-provisioned; nothing consumes this value. See the retirement note under "Cell 3 Secrets" above. - Automatic replication across regions - Accessible only by Cell 3 service account - Mounted as NEO4J_PASSWORD environment variable (Cell 3 reads it, finds no reachable host, and serves from Firestore — the branch fails closed by design)

Prerequisites

  1. Service Accounts: ```bash # Create Pub/Sub push service account gcloud iam service-accounts create pubsub-push \ --display-name="Pub/Sub Push Service Account"

# Create Cell 3 service account gcloud iam service-accounts create mizoki-cell3 \ --display-name="Cell 3 Service Account" ```

  1. Enable APIs: bash gcloud services enable \ monitoring.googleapis.com \ pubsub.googleapis.com \ secretmanager.googleapis.com \ run.googleapis.com

  2. Terraform: - Version 1.0+ required - Google provider ~> 5.0

Environment Variables

Set these before running Terraform:

export PROJECT_ID="your-project-id"
export REGION="us-central1"
export NEO4J_PASSWORD="your-secure-password"  # Don't commit!

State Management

For production, configure remote state backend:

terraform {
  backend "gcs" {
    bucket = "mizoki-terraform-state"
    prefix = "terraform/state"
  }
}

Validation

After deployment:

  1. Test Pub/Sub: bash gcloud pubsub topics publish mizoki-learn \ --message='{"task":"test","payload":{},"result":{}}' \ --project=${PROJECT_ID}

  2. Check Secret: bash gcloud secrets versions list neo4j-password --project=${PROJECT_ID}

  3. View Dashboard: bash gcloud monitoring dashboards list --project=${PROJECT_ID}

  4. Test Alerts: Generate error traffic to Cell 6 and verify alert fires.

Security Notes


Legacy Infrastructure

The original Terraform configuration creates base infrastructure:

To use legacy modules, see original instructions below.

← All docsView source on GitHub →