mirror of
https://github.com/immich-app/devtools.git
synced 2026-09-30 13:23:00 +08:00
OpenTofu held one hand-made discord webhook read by the cloudflare R2 billing alerts. Create that webhook in the discord/community module instead and consume its url via remote state, the same way grafana already does — no manual secret at all. cloudflare_notification_policy_webhooks.secret is optional and Cloudflare formats the payload for discord urls, so it's dropped. Github held only push-o-matic-app, an SSH-key item duplicating credentials the github-app module already manages as GITHUB_APP_IMMICH_PUSH_O_MATIC in tf. The provider can't create SSH-key items, so rather than copy it, point the four PUSH_O_MATIC_* org secrets at the existing tf item. Its pkcs8 field is a like-for-like swap for the old .private_key, which is also PKCS#8. Adds the missing client_id to the github-app module (appended last so the positional field indices in convert_certificate/converted/certificates stay valid). Also drops two dead 'OpenTofu' vault data sources that nothing referenced.
104 lines
2.3 KiB
Terraform
104 lines
2.3 KiB
Terraform
locals {
|
|
apps = flatten([
|
|
for app_name in var.app_names : {
|
|
name = "GITHUB_APP_${upper(app_name)}"
|
|
}
|
|
])
|
|
}
|
|
|
|
resource "onepassword_item" "manual" {
|
|
for_each = { for idx, secret in local.apps : secret.name => secret }
|
|
|
|
vault = data.onepassword_vault.manual.uuid
|
|
title = each.value.name
|
|
category = "secure_note"
|
|
|
|
note_value = "Github App with private key. Private key should be reformatted to have \\n instead of newlines."
|
|
|
|
section {
|
|
label = "GitHub App"
|
|
field {
|
|
label = "pem"
|
|
value = "CHANGE_ME"
|
|
type = "CONCEALED"
|
|
}
|
|
field {
|
|
label = "app_id"
|
|
value = "CHANGE_ME"
|
|
}
|
|
field {
|
|
label = "installation_id"
|
|
value = "CHANGE_ME"
|
|
}
|
|
field {
|
|
label = "owner"
|
|
value = "CHANGE_ME"
|
|
}
|
|
// Appended last on purpose: convert_certificate and the converted item below
|
|
// index this section positionally, so existing fields must keep their index.
|
|
field {
|
|
label = "client_id"
|
|
value = "CHANGE_ME"
|
|
}
|
|
}
|
|
|
|
lifecycle {
|
|
ignore_changes = [section[0]]
|
|
}
|
|
}
|
|
|
|
data "external" "convert_certificate" {
|
|
for_each = onepassword_item.manual
|
|
|
|
program = ["bash", "${path.module}/convert_cert.sh"]
|
|
|
|
query = {
|
|
pem_value = each.value.section[0].field[0].value
|
|
}
|
|
}
|
|
|
|
# Create new 1Password items with all certificate formats
|
|
resource "onepassword_item" "converted" {
|
|
for_each = onepassword_item.manual
|
|
|
|
vault = data.onepassword_vault.tf.uuid
|
|
title = each.value.title
|
|
category = "secure_note"
|
|
|
|
note_value = "GitHub App with certificates in multiple formats"
|
|
|
|
section {
|
|
label = "GitHub App"
|
|
field {
|
|
label = "pkcs1"
|
|
value = data.external.convert_certificate[each.key].result.pkcs1
|
|
type = "CONCEALED"
|
|
}
|
|
field {
|
|
label = "pkcs8"
|
|
value = data.external.convert_certificate[each.key].result.pkcs8
|
|
type = "CONCEALED"
|
|
}
|
|
field {
|
|
label = "app_id"
|
|
value = each.value.section[0].field[1].value
|
|
}
|
|
field {
|
|
label = "installation_id"
|
|
value = each.value.section[0].field[2].value
|
|
}
|
|
field {
|
|
label = "owner"
|
|
value = each.value.section[0].field[3].value
|
|
}
|
|
field {
|
|
label = "client_id"
|
|
value = each.value.section[0].field[4].value
|
|
}
|
|
}
|
|
|
|
depends_on = [
|
|
data.external.convert_certificate,
|
|
]
|
|
}
|