mirror of
https://github.com/immich-app/devtools.git
synced 2026-09-30 13:23:00 +08:00
OpenTofu held one hand-made discord webhook read by the cloudflare R2 billing alerts. Create that webhook in the discord/community module instead and consume its url via remote state, the same way grafana already does — no manual secret at all. cloudflare_notification_policy_webhooks.secret is optional and Cloudflare formats the payload for discord urls, so it's dropped. Github held only push-o-matic-app, an SSH-key item duplicating credentials the github-app module already manages as GITHUB_APP_IMMICH_PUSH_O_MATIC in tf. The provider can't create SSH-key items, so rather than copy it, point the four PUSH_O_MATIC_* org secrets at the existing tf item. Its pkcs8 field is a like-for-like swap for the old .private_key, which is also PKCS#8. Adds the missing client_id to the github-app module (appended last so the positional field indices in convert_certificate/converted/certificates stay valid). Also drops two dead 'OpenTofu' vault data sources that nothing referenced.
43 lines
1.0 KiB
Terraform
43 lines
1.0 KiB
Terraform
data "onepassword_vault" "kubernetes" {
|
|
name = "Kubernetes"
|
|
}
|
|
|
|
data "onepassword_vault" "tf" {
|
|
name = "tf"
|
|
}
|
|
|
|
resource "onepassword_item" "mich_cloudflare_r2_token" {
|
|
vault = data.onepassword_vault.kubernetes.uuid
|
|
title = "mich-cloudflare-r2-token"
|
|
category = "secure_note"
|
|
section {
|
|
label = "Cloudflare R2 Token"
|
|
|
|
field {
|
|
label = "id"
|
|
type = "STRING"
|
|
value = cloudflare_api_token.mich_cloudflare_r2_token.id
|
|
}
|
|
|
|
field {
|
|
label = "secret"
|
|
type = "STRING"
|
|
value = sha256(cloudflare_api_token.mich_cloudflare_r2_token.value)
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "onepassword_item" "static_bucket_key_id" {
|
|
vault = data.onepassword_vault.tf.uuid
|
|
title = "STATIC_BUCKET_KEY_ID"
|
|
category = "password"
|
|
password = cloudflare_api_token.static_bucket_api_token.id
|
|
}
|
|
|
|
resource "onepassword_item" "static_bucket_key_secret" {
|
|
vault = data.onepassword_vault.tf.uuid
|
|
title = "STATIC_BUCKET_KEY_SECRET"
|
|
category = "password"
|
|
password = sha256(cloudflare_api_token.static_bucket_api_token.value)
|
|
}
|