mirror of
https://github.com/immich-app/devtools.git
synced 2026-09-30 13:23:00 +08:00
Service accounts are only for pulling original secrets into .env files; vault writes go through a per-project Connect server. Point the immich_* copies at immich's own Connect server in the FUTO account instead of the shared service account token, which had write access to every vault in that account. github-apps-shared.tf still uses the service account for shared_tf — converting the remaining futo service-account usages is a separate change.
18 lines
445 B
Terraform
18 lines
445 B
Terraform
variable "op_connect_url" {}
|
|
variable "op_connect_token" {
|
|
sensitive = true
|
|
}
|
|
|
|
variable "futo_op_service_account_token" {
|
|
sensitive = true
|
|
}
|
|
|
|
variable "futo_immich_op_connect_url" {
|
|
description = "URL of immich's Connect server in the FUTO account"
|
|
}
|
|
|
|
variable "futo_immich_op_connect_token" {
|
|
description = "Connect token with write access to the immich_* vaults in the FUTO account (1PASS_CONNECT_IMMICH_WRITE)"
|
|
sensitive = true
|
|
}
|