A concrete BigConfig once package instance that deploys the live
bigconfig.ai infrastructure.
This is not a library — it is a deployment. The directory was bootstrapped
by the bc-pkg launcher: it pins bigconfig-ai/once at a git SHA and forwards
commands to it. The whole package is a single Babashka run script plus one
small local plugin.
The ai profile provisions:
VM.Standard.A1.Flex (1 OCPU / 6 GB) in eu-frankfurt-1.tf-state-251213589273-eu-west-1).Apps served behind hosts under bigconfig.ai:
| Host | Image | Notes |
|---|---|---|
www.bigconfig.ai |
once-bigconfig |
Main site |
bigconfig.ai |
once-caddy-redirect |
Apex → www redirect |
forms.bigconfig.ai |
once-forms |
Form handler |
marketplace.bigconfig.ai |
once-bigconfig-marketplace |
PocketBase + Litestream to S3, Google OAuth |
bb) — the run script is #!/usr/bin/env bb.direnv — loads the BC_PAR_* secrets from .envrc.gh CLI, authenticated with write access to
the bigconfig-ai org secrets (used by the local plugin to sync SERVER_IP).Copy the secrets template and fill in real values:
cp .envrc.example .envrc
# edit .envrc
direnv allow
Required secrets (see .envrc.example):
BC_PAR_CLOUDFLARE_API_TOKEN
BC_PAR_RESEND_API_KEY
BC_PAR_RESEND_PASSWORD
BC_PAR_LITESTREAM_ACCESS_KEY_ID
BC_PAR_LITESTREAM_SECRET_ACCESS_KEY
BC_PAR_SUPERUSER_PASSWORD
BC_PAR_GOOGLE_CLIENT_ID
BC_PAR_GOOGLE_CLIENT_SECRET
Missing secrets surface as render/apply failures, not crashes.
Run the package through its run script:
./run package build # render the artifact into .dist/<profile>-<hash>/
./run package create # provision + configure (six-stage pipeline)
./run package delete # tear down the four Tofu stages (reversed)
The create pipeline runs six stages:
tofu → tofu-smtp → tofu-dns → tofu-smtp-post → ansible-local → ansible
delete reverses the four Tofu stages. Compute resources default to
prevent_destroy = true; to tear one down:
BC_PAR_COMPUTE_PREVENT_DESTROY=false ./run package delete
| File | Purpose |
|---|---|
run |
The package. Babashka script defining default-profile and calling cli/main*. Edit this to change the deployment. |
src/io/github/bigconfig_ai/once_ai/plugin.clj |
Local BigConfig plugin (see below). |
deps.edn / bb.edn |
Pin io.github.bigconfig-ai/once (:git/url + :git/sha) and carry :bigconfig/* launcher metadata. Bump the SHA in both together. |
.envrc |
Secrets as BC_PAR_* exports (gitignored). |
.envrc.example |
Committed template of required secret names. |
.dist/<profile>-<hash>/ |
Generated rendered artifact. Never edit by hand. |
plans/ |
Scratch task notes, not part of the build. |
once-ai pluginsrc/.../plugin.clj wraps the upstream ansible-local step via BigConfig’s
pluggable step registry. After ansible-local succeeds, it pushes the deployed
VM’s IP to the SERVER_IP GitHub org secret in the bigconfig-ai org via
the gh CLI. It:
192.168.0.1),
guarding against overwriting the live secret with a placeholder.selected; defaulting to all for a missing secret).This is the one piece of deployment logic that lives in this repo rather than
in the upstream once library.
default-profile in
run.once library and re-pin its SHA in both
deps.edn and bb.edn.Keep param keys kebab-case — they map to template variable names; do not convert to snake/camel case.
bigconfig/
workspace and from the once library. Stay on main; do not commit unless
asked.once dependency plus the local
plugin — nothing else in this repo defines runtime behavior.