mirror of
https://github.com/immich-app/devtools.git
synced 2026-09-30 13:23:00 +08:00
fix/consolidate-legacy-1password-vaults
OpenTofu held one hand-made discord webhook read by the cloudflare R2 billing alerts. Create that webhook in the discord/community module instead and consume its url via remote state, the same way grafana already does — no manual secret at all. cloudflare_notification_policy_webhooks.secret is optional and Cloudflare formats the payload for discord urls, so it's dropped. Github held only push-o-matic-app, an SSH-key item duplicating credentials the github-app module already manages as GITHUB_APP_IMMICH_PUSH_O_MATIC in tf. The provider can't create SSH-key items, so rather than copy it, point the four PUSH_O_MATIC_* org secrets at the existing tf item. Its pkcs8 field is a like-for-like swap for the old .private_key, which is also PKCS#8. Adds the missing client_id to the github-app module (appended last so the positional field indices in convert_certificate/converted/certificates stay valid). Also drops two dead 'OpenTofu' vault data sources that nothing referenced.
Devtools
This repository holds various tooling used by the Immich maintainer team. That includes tofu modules, as well as kubernetes manifests for a Hetzner-hosted dedicated machine used for builds and testing environments.
Mise
This repository uses mise for managing the development environment. After installing and activating mise, most things should Just Work™.
You can list the available tasks with mise task ls.
Secrets are managed through the 1password cli. You can activate it with op account add and then eval $(op signin).
After that is set up, any terraform commands can be run through mise run tf <command>.
Kubectl is set up to get secrets from onepassword and should work out of the box while you're in this folder.
Languages
HCL
56.9%
TypeScript
26.4%
Dockerfile
8.2%
JavaScript
6%
Shell
2.5%