Zack 2c6e29c3b7 refactor(1password): write the futo immich vaults over connect
Service accounts are only for pulling original secrets into .env files; vault
writes go through a per-project Connect server. Point the immich_* copies at
immich's own Connect server in the FUTO account instead of the shared service
account token, which had write access to every vault in that account.

github-apps-shared.tf still uses the service account for shared_tf — converting
the remaining futo service-account usages is a separate change.
2026-07-22 11:45:15 +01:00
2026-07-13 12:18:20 +02:00
2024-07-05 13:51:24 +00:00
2024-07-05 13:51:50 +00:00
2025-05-08 15:34:37 +01:00

Devtools

This repository holds various tooling used by the Immich maintainer team. That includes tofu modules, as well as kubernetes manifests for a Hetzner-hosted dedicated machine used for builds and testing environments.

Mise

This repository uses mise for managing the development environment. After installing and activating mise, most things should Just Work™.
You can list the available tasks with mise task ls.

Secrets are managed through the 1password cli. You can activate it with op account add and then eval $(op signin).

After that is set up, any terraform commands can be run through mise run tf <command>.
Kubectl is set up to get secrets from onepassword and should work out of the box while you're in this folder.

S
Description
Various tooling used by the Immich maintainer team
Readme
9.2 MiB
Languages
HCL 56.9%
TypeScript 26.4%
Dockerfile 8.2%
JavaScript 6%
Shell 2.5%