Files
devtools/tf/deployment/modules/shared/1password/account/variables.tf
T
Zack 2c6e29c3b7 refactor(1password): write the futo immich vaults over connect
Service accounts are only for pulling original secrets into .env files; vault
writes go through a per-project Connect server. Point the immich_* copies at
immich's own Connect server in the FUTO account instead of the shared service
account token, which had write access to every vault in that account.

github-apps-shared.tf still uses the service account for shared_tf — converting
the remaining futo service-account usages is a separate change.
2026-07-22 11:45:15 +01:00

18 lines
445 B
Terraform

variable "op_connect_url" {}
variable "op_connect_token" {
sensitive = true
}
variable "futo_op_service_account_token" {
sensitive = true
}
variable "futo_immich_op_connect_url" {
description = "URL of immich's Connect server in the FUTO account"
}
variable "futo_immich_op_connect_token" {
description = "Connect token with write access to the immich_* vaults in the FUTO account (1PASS_CONNECT_IMMICH_WRITE)"
sensitive = true
}