mirror of
https://github.com/immich-app/devtools.git
synced 2026-09-30 13:23:00 +08:00
Service accounts are only for pulling original secrets into .env files; vault writes go through a per-project Connect server. Point the immich_* copies at immich's own Connect server in the FUTO account instead of the shared service account token, which had write access to every vault in that account. github-apps-shared.tf still uses the service account for shared_tf — converting the remaining futo service-account usages is a separate change.
22 lines
785 B
Terraform
22 lines
785 B
Terraform
provider "onepassword" {
|
|
url = var.op_connect_url
|
|
token = var.op_connect_token
|
|
}
|
|
|
|
# Second 1Password account (FUTO), used to mirror the github app credentials
|
|
# into the FUTO shared_tf vault alongside the immich tf copy.
|
|
provider "onepassword" {
|
|
alias = "futo"
|
|
service_account_token = var.futo_op_service_account_token
|
|
}
|
|
|
|
# The immich_* vaults in the FUTO account are written through immich's own
|
|
# Connect server, not a service account: service accounts exist only to pull the
|
|
# original secrets into .env files. Same shape as the immich-account Connect
|
|
# provider above, pointed at the per-project Connect server instead.
|
|
provider "onepassword" {
|
|
alias = "futo_immich"
|
|
url = var.futo_immich_op_connect_url
|
|
token = var.futo_immich_op_connect_token
|
|
}
|