Files
devtools/tf/deployment/modules/shared/1password/account/providers.tf
T
Zack 2c6e29c3b7 refactor(1password): write the futo immich vaults over connect
Service accounts are only for pulling original secrets into .env files; vault
writes go through a per-project Connect server. Point the immich_* copies at
immich's own Connect server in the FUTO account instead of the shared service
account token, which had write access to every vault in that account.

github-apps-shared.tf still uses the service account for shared_tf — converting
the remaining futo service-account usages is a separate change.
2026-07-22 11:45:15 +01:00

22 lines
785 B
Terraform

provider "onepassword" {
url = var.op_connect_url
token = var.op_connect_token
}
# Second 1Password account (FUTO), used to mirror the github app credentials
# into the FUTO shared_tf vault alongside the immich tf copy.
provider "onepassword" {
alias = "futo"
service_account_token = var.futo_op_service_account_token
}
# The immich_* vaults in the FUTO account are written through immich's own
# Connect server, not a service account: service accounts exist only to pull the
# original secrets into .env files. Same shape as the immich-account Connect
# provider above, pointed at the per-project Connect server instead.
provider "onepassword" {
alias = "futo_immich"
url = var.futo_immich_op_connect_url
token = var.futo_immich_op_connect_token
}