feat: migrate 1pass provider to use connect server (#1454)

This commit is contained in:
Zack Pollard
2026-03-24 18:57:48 +00:00
committed by GitHub
parent 53cac29f46
commit 402f24dfa4
21 changed files with 72 additions and 28 deletions
+14 -7
View File
@@ -47,7 +47,8 @@ jobs:
- name: Check terraform fmt
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_DEV_ENV }}
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_DEV }}
ENVIRONMENT: dev
run: mise run tf fmt -- -diff -check
plan:
@@ -72,21 +73,24 @@ jobs:
- name: Plan Shared
working-directory: ${{ env.working_dir }}/modules/shared
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_PROD_ENV }}
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }}
ENVIRONMENT: prod
run: mise run tf:plan
- name: Plan Dev
working-directory: ${{ env.working_dir }}/modules/scoped
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_DEV_ENV }}
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_DEV }}
ENVIRONMENT: dev
run: mise run tf:plan
- name: Plan Prod
working-directory: ${{ env.working_dir }}/modules/scoped
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_PROD_ENV }}
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }}
ENVIRONMENT: prod
run: |
mise run tf:init
@@ -114,21 +118,24 @@ jobs:
- name: Deploy Shared
working-directory: ${{ env.working_dir }}/modules/shared
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_PROD_ENV }}
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }}
ENVIRONMENT: prod
run: mise run tf:apply
- name: Deploy Dev
working-directory: ${{ env.working_dir }}/modules/scoped
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_DEV_ENV }}
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_DEV }}
ENVIRONMENT: dev
run: mise run tf:apply
- name: Deploy Prod
working-directory: ${{ env.working_dir }}/modules/scoped
env:
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_PROD_ENV }}
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }}
ENVIRONMENT: prod
run: |
mise run tf:init
+2 -2
View File
@@ -16,8 +16,8 @@ yamlfmt = "0.21.0"
KUBECONFIG = "{{config_root}}/.mise/kube.config"
[tasks.tg]
run = "op run '--env-file={{config_root}}/tf/deployment/.env' -- terragrunt"
description = "Wrapper for terragrunt"
run = "op run '--env-file={{config_root}}/tf/deployment/.env' -- env -u OP_CONNECT_HOST -u OP_CONNECT_TOKEN -u OP_SERVICE_ACCOUNT_TOKEN -- terragrunt"
description = "Wrapper for terragrunt, op run resolves secrets then env -u strips op auth vars so they don't conflict with terraform providers"
dir = "{{cwd}}"
[tasks."tg:fmt"]
+2 -1
View File
@@ -6,7 +6,8 @@ export TF_VAR_github_app_installation_id="op://tf/GITHUB_APP_IMMICH_TOFU/install
export TF_VAR_github_app_id="op://tf/GITHUB_APP_IMMICH_TOFU/app_id"
export TF_VAR_github_app_pem_file="op://tf/GITHUB_APP_IMMICH_TOFU/pkcs1"
export TF_VAR_github_owner="op://tf/GITHUB_APP_IMMICH_TOFU/owner"
export TF_VAR_op_service_account_token="op://tf/1pass_service_account/superuser_token"
export TF_VAR_op_connect_url="op://tf/1pass_connect/url"
export TF_VAR_op_connect_token="op://tf/1pass_connect/token"
export TF_VAR_futo_op_service_account_token="op://tf_$ENVIRONMENT/yucca_futo_1pass_superuser_service_account/password"
export TF_VAR_discord_token="op://tf/IMMICH_TF_DISCORD_BOT_TOKEN/password"
export TF_VAR_zitadel_profile_json="op://tf/ZITADEL_PROFILE_JSON/password"
@@ -3,5 +3,6 @@ provider "discord" {
}
provider "onepassword" {
service_account_token = var.op_service_account_token
url = var.op_connect_url
token = var.op_connect_token
}
@@ -1,6 +1,9 @@
variable "tf_state_postgres_conn_str" {}
variable "op_service_account_token" {}
variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
variable "discord_token" {}
@@ -4,6 +4,7 @@ provider "grafana" {
}
provider "onepassword" {
service_account_token = var.op_service_account_token
url = var.op_connect_url
token = var.op_connect_token
}
@@ -1,6 +1,9 @@
variable "tf_state_postgres_conn_str" {}
variable "op_service_account_token" {}
variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
variable "grafana_url" {}
variable "grafana_token" {}
@@ -1,3 +1,4 @@
provider "onepassword" {
service_account_token = var.op_service_account_token
url = var.op_connect_url
token = var.op_connect_token
}
@@ -1 +1,4 @@
variable "op_service_account_token" {}
variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
@@ -8,5 +8,6 @@ provider "cloudflare" {
}
provider "onepassword" {
service_account_token = var.op_service_account_token
url = var.op_connect_url
token = var.op_connect_token
}
@@ -1,4 +1,7 @@
variable "cloudflare_account_id" {}
variable "cloudflare_api_token" {}
variable "tf_state_postgres_conn_str" {}
variable "op_service_account_token" {}
variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
@@ -3,5 +3,6 @@ provider "cloudflare" {
}
provider "onepassword" {
service_account_token = var.op_service_account_token
url = var.op_connect_url
token = var.op_connect_token
}
@@ -1,4 +1,7 @@
variable "op_service_account_token" {}
variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
variable "cloudflare_api_token" {}
variable "cloudflare_account_id" {}
@@ -9,5 +9,6 @@ provider "github" {
}
provider "onepassword" {
service_account_token = var.op_service_account_token
url = var.op_connect_url
token = var.op_connect_token
}
@@ -5,7 +5,10 @@ variable "github_app_installation_id" {}
variable "github_app_pem_file" {}
variable "github_owner" {}
variable "op_service_account_token" {}
variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
variable "users_data_file_path" {
description = "The path to the JSON file containing user data. This path should be resolvable from the Terragrunt execution directory or be an absolute path."
@@ -9,5 +9,6 @@ provider "github" {
}
provider "onepassword" {
service_account_token = var.op_service_account_token
url = var.op_connect_url
token = var.op_connect_token
}
@@ -5,4 +5,7 @@ variable "github_app_installation_id" {}
variable "github_app_pem_file" {}
variable "github_owner" {}
variable "op_service_account_token" {}
variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
@@ -9,5 +9,6 @@ provider "github" {
}
provider "onepassword" {
service_account_token = var.op_service_account_token
url = var.op_connect_url
token = var.op_connect_token
}
@@ -3,4 +3,7 @@ variable "github_app_installation_id" {}
variable "github_app_pem_file" {}
variable "github_owner" {}
variable "op_service_account_token" {}
variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
@@ -5,5 +5,6 @@ provider "zitadel" {
}
provider "onepassword" {
service_account_token = var.op_service_account_token
url = var.op_connect_url
token = var.op_connect_token
}
@@ -1,6 +1,9 @@
variable "tf_state_postgres_conn_str" {}
variable "op_service_account_token" {}
variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
variable "zitadel_profile_json" {}