# op:// references resolved by `op run --env-file=tf/.env -- ...`
# Contains NO literal secrets — just pointers to 1P items.
#
# OP_SERVICE_ACCOUNT_TOKEN comes from the environment (GH secret / operator), not here.

# S3 credentials for the shared `yucca-tf-state` bucket (OVH eu-west-par).
# Shared infra → yucca_tf (read by every env SA), consumed by OpenTofu's S3
# backend via standard AWS env vars.
export AWS_ACCESS_KEY_ID="op://yucca_tf/TF_STATE_S3_ACCESS_KEY/password"
export AWS_SECRET_ACCESS_KEY="op://yucca_tf/TF_STATE_S3_SECRET_KEY/password"

# Cloudflare API token (futo.cloud zone; Zone:Read + DNS:Edit). The cloudflare
# provider reads this env var directly; cert-manager DNS-01 uses the TF_VAR copy.
export CLOUDFLARE_API_TOKEN="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"

# ─── staging/talos secrets (secrets.tf) — env-specific, in yucca_tf_staging ──
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID/password"
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET/password"
# admin-api OIDC client not registered yet (admin-api is in-cluster-only).
# export TF_VAR_yucca_oidc_admin_client_id="op://yucca_tf_staging/.../password"
# export TF_VAR_yucca_oidc_admin_client_secret="op://yucca_tf_staging/.../password"

# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"

# vmagent + collector → o11y staging vmauth bearer token.
export TF_VAR_vmauth_remote_write_password="op://o11y_tf_staging/VICTORIAMETRICS_VMAUTH_PASSWORD/password"

# Cloudflare API token for cert-manager DNS-01 (same item, TF_VAR form).
export TF_VAR_cloudflare_api_token="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"

# The `yucca_tf_staging` refs above are readable only by the staging SA. CI
# injects it as OP_SERVICE_ACCOUNT_TOKEN from the repo secret
# OP_TF_YUCCA_STAGING_ENV (read) / OP_TF_YUCCA_STAGING_ENV_WRITE (apply); see
# .github/workflows/infra.yml. This file is shared by all stacks; run dev/prod
# with their own env file (OP_ENV_FILE=tf/.env.<env> tf/op-run.sh ...).
