Files
devtools/tf/deployment/modules/shared/cloudflare/account/remote-state.tf
T
Zack 4c962a1114 fix(1password): retire the legacy OpenTofu and Github vaults
OpenTofu held one hand-made discord webhook read by the cloudflare R2 billing
alerts. Create that webhook in the discord/community module instead and consume
its url via remote state, the same way grafana already does — no manual secret
at all. cloudflare_notification_policy_webhooks.secret is optional and Cloudflare
formats the payload for discord urls, so it's dropped.

Github held only push-o-matic-app, an SSH-key item duplicating credentials the
github-app module already manages as GITHUB_APP_IMMICH_PUSH_O_MATIC in tf. The
provider can't create SSH-key items, so rather than copy it, point the four
PUSH_O_MATIC_* org secrets at the existing tf item. Its pkcs8 field is a
like-for-like swap for the old .private_key, which is also PKCS#8. Adds the
missing client_id to the github-app module (appended last so the positional
field indices in convert_certificate/converted/certificates stay valid).

Also drops two dead 'OpenTofu' vault data sources that nothing referenced.
2026-07-21 23:43:35 +01:00

18 lines
362 B
Terraform

data "terraform_remote_state" "api_keys_state" {
backend = "pg"
config = {
conn_str = var.tf_state_postgres_conn_str
schema_name = "prod_cloudflare_api_keys"
}
}
data "terraform_remote_state" "discord_community" {
backend = "pg"
config = {
conn_str = var.tf_state_postgres_conn_str
schema_name = "prod_discord_community"
}
}