Zack eede3f9190 fix(github): pin org workflow refs to a sha
zizmor's unpinned-uses flags these @main refs. On public repos that is
reported to code scanning and exits 0, so it never blocked anything. On
private repos zizmor runs in annotations mode, exits non-zero and fails
the required check — correctly, since the finding is real.

Pin to a devtools main sha rather than the multi-runner-build-workflow
v3.1.0 tag: that tag predates #1894, so pinning to it would reintroduce
the code scanning failure on private repos.

terraform manages this content for every repo, so bumping the sha here
propagates on apply.
2026-08-04 18:32:46 +01:00
2024-07-05 13:51:24 +00:00
2024-07-05 13:51:50 +00:00
2025-05-08 15:34:37 +01:00

Devtools

This repository holds various tooling used by the Immich maintainer team. That includes tofu modules, as well as kubernetes manifests for a Hetzner-hosted dedicated machine used for builds and testing environments.

Mise

This repository uses mise for managing the development environment. After installing and activating mise, most things should Just Work™.
You can list the available tasks with mise task ls.

Secrets are managed through the 1password cli. You can activate it with op account add and then eval $(op signin).

After that is set up, any terraform commands can be run through mise run tf <command>.
Kubectl is set up to get secrets from onepassword and should work out of the box while you're in this folder.

S
Description
Various tooling used by the Immich maintainer team
Readme
9.2 MiB
Languages
HCL 56.9%
TypeScript 26.4%
Dockerfile 8.2%
JavaScript 6%
Shell 2.5%