Files
devtools/tf/deployment/modules/shared/cloudflare/api-keys/1password.tf
T
Zack 4c962a1114 fix(1password): retire the legacy OpenTofu and Github vaults
OpenTofu held one hand-made discord webhook read by the cloudflare R2 billing
alerts. Create that webhook in the discord/community module instead and consume
its url via remote state, the same way grafana already does — no manual secret
at all. cloudflare_notification_policy_webhooks.secret is optional and Cloudflare
formats the payload for discord urls, so it's dropped.

Github held only push-o-matic-app, an SSH-key item duplicating credentials the
github-app module already manages as GITHUB_APP_IMMICH_PUSH_O_MATIC in tf. The
provider can't create SSH-key items, so rather than copy it, point the four
PUSH_O_MATIC_* org secrets at the existing tf item. Its pkcs8 field is a
like-for-like swap for the old .private_key, which is also PKCS#8. Adds the
missing client_id to the github-app module (appended last so the positional
field indices in convert_certificate/converted/certificates stay valid).

Also drops two dead 'OpenTofu' vault data sources that nothing referenced.
2026-07-21 23:43:35 +01:00

43 lines
1.0 KiB
Terraform

data "onepassword_vault" "kubernetes" {
name = "Kubernetes"
}
data "onepassword_vault" "tf" {
name = "tf"
}
resource "onepassword_item" "mich_cloudflare_r2_token" {
vault = data.onepassword_vault.kubernetes.uuid
title = "mich-cloudflare-r2-token"
category = "secure_note"
section {
label = "Cloudflare R2 Token"
field {
label = "id"
type = "STRING"
value = cloudflare_api_token.mich_cloudflare_r2_token.id
}
field {
label = "secret"
type = "STRING"
value = sha256(cloudflare_api_token.mich_cloudflare_r2_token.value)
}
}
}
resource "onepassword_item" "static_bucket_key_id" {
vault = data.onepassword_vault.tf.uuid
title = "STATIC_BUCKET_KEY_ID"
category = "password"
password = cloudflare_api_token.static_bucket_api_token.id
}
resource "onepassword_item" "static_bucket_key_secret" {
vault = data.onepassword_vault.tf.uuid
title = "STATIC_BUCKET_KEY_SECRET"
category = "password"
password = sha256(cloudflare_api_token.static_bucket_api_token.value)
}