mirror of
https://github.com/immich-app/devtools.git
synced 2026-09-30 13:23:00 +08:00
feat: migrate 1pass provider to use connect server (#1454)
This commit is contained in:
@@ -47,7 +47,8 @@ jobs:
|
||||
|
||||
- name: Check terraform fmt
|
||||
env:
|
||||
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_DEV_ENV }}
|
||||
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
|
||||
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_DEV }}
|
||||
ENVIRONMENT: dev
|
||||
run: mise run tf fmt -- -diff -check
|
||||
plan:
|
||||
@@ -72,21 +73,24 @@ jobs:
|
||||
- name: Plan Shared
|
||||
working-directory: ${{ env.working_dir }}/modules/shared
|
||||
env:
|
||||
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_PROD_ENV }}
|
||||
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
|
||||
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }}
|
||||
ENVIRONMENT: prod
|
||||
run: mise run tf:plan
|
||||
|
||||
- name: Plan Dev
|
||||
working-directory: ${{ env.working_dir }}/modules/scoped
|
||||
env:
|
||||
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_DEV_ENV }}
|
||||
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
|
||||
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_DEV }}
|
||||
ENVIRONMENT: dev
|
||||
run: mise run tf:plan
|
||||
|
||||
- name: Plan Prod
|
||||
working-directory: ${{ env.working_dir }}/modules/scoped
|
||||
env:
|
||||
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_PROD_ENV }}
|
||||
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
|
||||
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }}
|
||||
ENVIRONMENT: prod
|
||||
run: |
|
||||
mise run tf:init
|
||||
@@ -114,21 +118,24 @@ jobs:
|
||||
- name: Deploy Shared
|
||||
working-directory: ${{ env.working_dir }}/modules/shared
|
||||
env:
|
||||
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_PROD_ENV }}
|
||||
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
|
||||
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }}
|
||||
ENVIRONMENT: prod
|
||||
run: mise run tf:apply
|
||||
|
||||
- name: Deploy Dev
|
||||
working-directory: ${{ env.working_dir }}/modules/scoped
|
||||
env:
|
||||
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_DEV_ENV }}
|
||||
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
|
||||
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_DEV }}
|
||||
ENVIRONMENT: dev
|
||||
run: mise run tf:apply
|
||||
|
||||
- name: Deploy Prod
|
||||
working-directory: ${{ env.working_dir }}/modules/scoped
|
||||
env:
|
||||
OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_PROD_ENV }}
|
||||
OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }}
|
||||
OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }}
|
||||
ENVIRONMENT: prod
|
||||
run: |
|
||||
mise run tf:init
|
||||
|
||||
+2
-2
@@ -16,8 +16,8 @@ yamlfmt = "0.21.0"
|
||||
KUBECONFIG = "{{config_root}}/.mise/kube.config"
|
||||
|
||||
[tasks.tg]
|
||||
run = "op run '--env-file={{config_root}}/tf/deployment/.env' -- terragrunt"
|
||||
description = "Wrapper for terragrunt"
|
||||
run = "op run '--env-file={{config_root}}/tf/deployment/.env' -- env -u OP_CONNECT_HOST -u OP_CONNECT_TOKEN -u OP_SERVICE_ACCOUNT_TOKEN -- terragrunt"
|
||||
description = "Wrapper for terragrunt, op run resolves secrets then env -u strips op auth vars so they don't conflict with terraform providers"
|
||||
dir = "{{cwd}}"
|
||||
|
||||
[tasks."tg:fmt"]
|
||||
|
||||
+2
-1
@@ -6,7 +6,8 @@ export TF_VAR_github_app_installation_id="op://tf/GITHUB_APP_IMMICH_TOFU/install
|
||||
export TF_VAR_github_app_id="op://tf/GITHUB_APP_IMMICH_TOFU/app_id"
|
||||
export TF_VAR_github_app_pem_file="op://tf/GITHUB_APP_IMMICH_TOFU/pkcs1"
|
||||
export TF_VAR_github_owner="op://tf/GITHUB_APP_IMMICH_TOFU/owner"
|
||||
export TF_VAR_op_service_account_token="op://tf/1pass_service_account/superuser_token"
|
||||
export TF_VAR_op_connect_url="op://tf/1pass_connect/url"
|
||||
export TF_VAR_op_connect_token="op://tf/1pass_connect/token"
|
||||
export TF_VAR_futo_op_service_account_token="op://tf_$ENVIRONMENT/yucca_futo_1pass_superuser_service_account/password"
|
||||
export TF_VAR_discord_token="op://tf/IMMICH_TF_DISCORD_BOT_TOKEN/password"
|
||||
export TF_VAR_zitadel_profile_json="op://tf/ZITADEL_PROFILE_JSON/password"
|
||||
|
||||
@@ -3,5 +3,6 @@ provider "discord" {
|
||||
}
|
||||
|
||||
provider "onepassword" {
|
||||
service_account_token = var.op_service_account_token
|
||||
url = var.op_connect_url
|
||||
token = var.op_connect_token
|
||||
}
|
||||
|
||||
@@ -1,6 +1,9 @@
|
||||
variable "tf_state_postgres_conn_str" {}
|
||||
|
||||
variable "op_service_account_token" {}
|
||||
variable "op_connect_url" {}
|
||||
variable "op_connect_token" {
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "discord_token" {}
|
||||
|
||||
|
||||
@@ -4,6 +4,7 @@ provider "grafana" {
|
||||
}
|
||||
|
||||
provider "onepassword" {
|
||||
service_account_token = var.op_service_account_token
|
||||
url = var.op_connect_url
|
||||
token = var.op_connect_token
|
||||
}
|
||||
|
||||
|
||||
@@ -1,6 +1,9 @@
|
||||
variable "tf_state_postgres_conn_str" {}
|
||||
|
||||
variable "op_service_account_token" {}
|
||||
variable "op_connect_url" {}
|
||||
variable "op_connect_token" {
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "grafana_url" {}
|
||||
variable "grafana_token" {}
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
provider "onepassword" {
|
||||
service_account_token = var.op_service_account_token
|
||||
url = var.op_connect_url
|
||||
token = var.op_connect_token
|
||||
}
|
||||
|
||||
@@ -1 +1,4 @@
|
||||
variable "op_service_account_token" {}
|
||||
variable "op_connect_url" {}
|
||||
variable "op_connect_token" {
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
@@ -8,5 +8,6 @@ provider "cloudflare" {
|
||||
}
|
||||
|
||||
provider "onepassword" {
|
||||
service_account_token = var.op_service_account_token
|
||||
url = var.op_connect_url
|
||||
token = var.op_connect_token
|
||||
}
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
variable "cloudflare_account_id" {}
|
||||
variable "cloudflare_api_token" {}
|
||||
variable "tf_state_postgres_conn_str" {}
|
||||
variable "op_service_account_token" {}
|
||||
variable "op_connect_url" {}
|
||||
variable "op_connect_token" {
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
@@ -3,5 +3,6 @@ provider "cloudflare" {
|
||||
}
|
||||
|
||||
provider "onepassword" {
|
||||
service_account_token = var.op_service_account_token
|
||||
url = var.op_connect_url
|
||||
token = var.op_connect_token
|
||||
}
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
variable "op_service_account_token" {}
|
||||
variable "op_connect_url" {}
|
||||
variable "op_connect_token" {
|
||||
sensitive = true
|
||||
}
|
||||
variable "cloudflare_api_token" {}
|
||||
variable "cloudflare_account_id" {}
|
||||
|
||||
|
||||
@@ -9,5 +9,6 @@ provider "github" {
|
||||
}
|
||||
|
||||
provider "onepassword" {
|
||||
service_account_token = var.op_service_account_token
|
||||
url = var.op_connect_url
|
||||
token = var.op_connect_token
|
||||
}
|
||||
|
||||
@@ -5,7 +5,10 @@ variable "github_app_installation_id" {}
|
||||
variable "github_app_pem_file" {}
|
||||
variable "github_owner" {}
|
||||
|
||||
variable "op_service_account_token" {}
|
||||
variable "op_connect_url" {}
|
||||
variable "op_connect_token" {
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "users_data_file_path" {
|
||||
description = "The path to the JSON file containing user data. This path should be resolvable from the Terragrunt execution directory or be an absolute path."
|
||||
|
||||
@@ -9,5 +9,6 @@ provider "github" {
|
||||
}
|
||||
|
||||
provider "onepassword" {
|
||||
service_account_token = var.op_service_account_token
|
||||
url = var.op_connect_url
|
||||
token = var.op_connect_token
|
||||
}
|
||||
|
||||
@@ -5,4 +5,7 @@ variable "github_app_installation_id" {}
|
||||
variable "github_app_pem_file" {}
|
||||
variable "github_owner" {}
|
||||
|
||||
variable "op_service_account_token" {}
|
||||
variable "op_connect_url" {}
|
||||
variable "op_connect_token" {
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
@@ -9,5 +9,6 @@ provider "github" {
|
||||
}
|
||||
|
||||
provider "onepassword" {
|
||||
service_account_token = var.op_service_account_token
|
||||
url = var.op_connect_url
|
||||
token = var.op_connect_token
|
||||
}
|
||||
|
||||
@@ -3,4 +3,7 @@ variable "github_app_installation_id" {}
|
||||
variable "github_app_pem_file" {}
|
||||
variable "github_owner" {}
|
||||
|
||||
variable "op_service_account_token" {}
|
||||
variable "op_connect_url" {}
|
||||
variable "op_connect_token" {
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
@@ -5,5 +5,6 @@ provider "zitadel" {
|
||||
}
|
||||
|
||||
provider "onepassword" {
|
||||
service_account_token = var.op_service_account_token
|
||||
url = var.op_connect_url
|
||||
token = var.op_connect_token
|
||||
}
|
||||
|
||||
@@ -1,6 +1,9 @@
|
||||
variable "tf_state_postgres_conn_str" {}
|
||||
|
||||
variable "op_service_account_token" {}
|
||||
variable "op_connect_url" {}
|
||||
variable "op_connect_token" {
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "zitadel_profile_json" {}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user