Files
devtools/tf/shared/modules/secrets/github-app/secrets.tf
T
Zack 4c962a1114 fix(1password): retire the legacy OpenTofu and Github vaults
OpenTofu held one hand-made discord webhook read by the cloudflare R2 billing
alerts. Create that webhook in the discord/community module instead and consume
its url via remote state, the same way grafana already does — no manual secret
at all. cloudflare_notification_policy_webhooks.secret is optional and Cloudflare
formats the payload for discord urls, so it's dropped.

Github held only push-o-matic-app, an SSH-key item duplicating credentials the
github-app module already manages as GITHUB_APP_IMMICH_PUSH_O_MATIC in tf. The
provider can't create SSH-key items, so rather than copy it, point the four
PUSH_O_MATIC_* org secrets at the existing tf item. Its pkcs8 field is a
like-for-like swap for the old .private_key, which is also PKCS#8. Adds the
missing client_id to the github-app module (appended last so the positional
field indices in convert_certificate/converted/certificates stay valid).

Also drops two dead 'OpenTofu' vault data sources that nothing referenced.
2026-07-21 23:43:35 +01:00

104 lines
2.3 KiB
Terraform

locals {
apps = flatten([
for app_name in var.app_names : {
name = "GITHUB_APP_${upper(app_name)}"
}
])
}
resource "onepassword_item" "manual" {
for_each = { for idx, secret in local.apps : secret.name => secret }
vault = data.onepassword_vault.manual.uuid
title = each.value.name
category = "secure_note"
note_value = "Github App with private key. Private key should be reformatted to have \\n instead of newlines."
section {
label = "GitHub App"
field {
label = "pem"
value = "CHANGE_ME"
type = "CONCEALED"
}
field {
label = "app_id"
value = "CHANGE_ME"
}
field {
label = "installation_id"
value = "CHANGE_ME"
}
field {
label = "owner"
value = "CHANGE_ME"
}
// Appended last on purpose: convert_certificate and the converted item below
// index this section positionally, so existing fields must keep their index.
field {
label = "client_id"
value = "CHANGE_ME"
}
}
lifecycle {
ignore_changes = [section[0]]
}
}
data "external" "convert_certificate" {
for_each = onepassword_item.manual
program = ["bash", "${path.module}/convert_cert.sh"]
query = {
pem_value = each.value.section[0].field[0].value
}
}
# Create new 1Password items with all certificate formats
resource "onepassword_item" "converted" {
for_each = onepassword_item.manual
vault = data.onepassword_vault.tf.uuid
title = each.value.title
category = "secure_note"
note_value = "GitHub App with certificates in multiple formats"
section {
label = "GitHub App"
field {
label = "pkcs1"
value = data.external.convert_certificate[each.key].result.pkcs1
type = "CONCEALED"
}
field {
label = "pkcs8"
value = data.external.convert_certificate[each.key].result.pkcs8
type = "CONCEALED"
}
field {
label = "app_id"
value = each.value.section[0].field[1].value
}
field {
label = "installation_id"
value = each.value.section[0].field[2].value
}
field {
label = "owner"
value = each.value.section[0].field[3].value
}
field {
label = "client_id"
value = each.value.section[0].field[4].value
}
}
depends_on = [
data.external.convert_certificate,
]
}