mirror of
https://github.com/immich-app/devtools.git
synced 2026-09-30 21:27:48 +08:00
fix/pin-org-workflow-refs
zizmor's unpinned-uses flags these @main refs. On public repos that is reported to code scanning and exits 0, so it never blocked anything. On private repos zizmor runs in annotations mode, exits non-zero and fails the required check — correctly, since the finding is real. Pin to a devtools main sha rather than the multi-runner-build-workflow v3.1.0 tag: that tag predates #1894, so pinning to it would reintroduce the code scanning failure on private repos. terraform manages this content for every repo, so bumping the sha here propagates on apply.
Devtools
This repository holds various tooling used by the Immich maintainer team. That includes tofu modules, as well as kubernetes manifests for a Hetzner-hosted dedicated machine used for builds and testing environments.
Mise
This repository uses mise for managing the development environment. After installing and activating mise, most things should Just Work™.
You can list the available tasks with mise task ls.
Secrets are managed through the 1password cli. You can activate it with op account add and then eval $(op signin).
After that is set up, any terraform commands can be run through mise run tf <command>.
Kubectl is set up to get secrets from onepassword and should work out of the box while you're in this folder.
Languages
HCL
56.9%
TypeScript
26.4%
Dockerfile
8.2%
JavaScript
6%
Shell
2.5%