# op:// references resolved by `op run --env-file=tf/.env -- ...`
# Contains NO literal secrets — just pointers to 1P items.
#
# OP_SERVICE_ACCOUNT_TOKEN comes from the environment (GH secret / operator), not here.

# S3 credentials for the shared `yucca-tf-state` bucket (OVH eu-west-par).
# Shared infra → yucca_tf (read by every env SA), consumed by OpenTofu's S3
# backend via standard AWS env vars.
export AWS_ACCESS_KEY_ID="op://yucca_tf/TF_STATE_S3_ACCESS_KEY/password"
export AWS_SECRET_ACCESS_KEY="op://yucca_tf/TF_STATE_S3_SECRET_KEY/password"

# Cloudflare API token (futo.cloud zone; Zone:Read + DNS:Edit). The cloudflare
# provider reads this env var directly; cert-manager DNS-01 uses the TF_VAR copy.
export CLOUDFLARE_API_TOKEN="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"

# ─── Flux commit-status GitHub App (flux.tf) — SHARED push-o-matic, in shared_tf ──
# notification-controller's `github` Provider authenticates as this app to post
# reconcile results as commit statuses. Numeric App ID + Installation ID + raw
# PEM private key (NOT the OAuth client id CI uses). Temporary until a dedicated
# `yucca-flux` app exists; see flux.tf. `pkcs1` is the GitHub-native .pem format
# (the item also has `pkcs8`; flux's ParseRSAPrivateKeyFromPEM accepts either).
export TF_VAR_flux_github_app_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/app_id"
export TF_VAR_flux_github_app_installation_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/installation_id"
export TF_VAR_flux_github_app_private_key="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/pkcs1"

# ─── NetBird admin PAT (deployment/<env>/netbird) — SHARED, in shared_tf ─────
# The netbird provider reads NB_PAT directly. One PAT (one NetBird Cloud account)
# backs every env/site; the netbird-env module namespaces objects per layer
# ("yucca_<env>_…" / "yucca_prod_<site>_…"). shared_tf is readable by every env
# SA, so this line serves the staging stack (prod uses tf/.env.prod).
# management_url defaults to https://api.netbird.io.
export NB_PAT="op://shared_tf/NETBIRD_TF_PAT/password"

# ─── staging/talos secrets (secrets.tf) — env-specific, in yucca_tf_staging ──
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID/password"
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET/password"
# Public device-flow client id (manually copied from yucca_tf_dev for now).
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_ORCHESTRATOR/password"
# admin-api OIDC client — the shared internal-tooling app on
# https://auth.internal.futo.org (one registration serves staging + prod, so
# the items live in shared_tf, readable by every env SA).
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"

# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"

# yucca-metrics-worker RGW ADMIN creds — separate sietch RGW user with admin caps
# (per-bucket usage via the RGW admin API; michael's plain S3 user can't). Created
# by the ceph stack into yucca_tf_staging; TF writes them into the yucca-metrics-rgw
# Secret (secrets.tf). NOT from CI — the cluster pulls nothing from CI.
export TF_VAR_sietch_metrics_worker_access_key="op://yucca_tf_staging/SIETCH_METRICS_WORKER_ACCESS_KEY/password"
export TF_VAR_sietch_metrics_worker_secret_key="op://yucca_tf_staging/SIETCH_METRICS_WORKER_SECRET_KEY/password"

# CNPG database backups → sietch RGW (svc-yucca-db-backup, TF-minted by the
# ceph stack). The cert is the DR item `mise run capture` snapshots from the
# bootstrap node's /etc/ceph/rgw-ssl.crt; barman needs it as a CA bundle.
export TF_VAR_sietch_db_backup_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_DB_BACKUP_ACCESS_KEY/password"
export TF_VAR_sietch_db_backup_secret_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_DB_BACKUP_SECRET_KEY/password"
export TF_VAR_sietch_rgw_tls_cert="op://yucca_tf_staging/SIETCH_CEPH_RGW_TLS_CERT/password"

# Cloudflare API token for cert-manager DNS-01 (same item, TF_VAR form).
export TF_VAR_cloudflare_api_token="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"

# NetBird, minted by deployment/staging/netbird into yucca_tf_staging.
# NB: `op run` resolves EVERY ref in this file up front for ANY stack, so a ref
# to an item that doesn't exist yet fails all plans/applies. Keep a ref commented
# until the netbird stack has minted its item (same convention as the OIDC lines).
#
#   • talos setup key → node-level siderolabs/netbird extension. The item
#     already exists (group `talos` was applied previously), so this is live.
export TF_VAR_netbird_talos_setup_key="op://yucca_tf_staging/NETBIRD_YUCCA_STAGING_TALOS_SETUP_KEY/password"

# The `yucca_tf_staging` refs above are readable only by the staging SA. CI
# injects it as OP_SERVICE_ACCOUNT_TOKEN from the repo secret
# OP_TF_YUCCA_STAGING_ENV (read) / OP_TF_YUCCA_STAGING_ENV_WRITE (apply); see
# .github/workflows/infra.yml. This file is shared by all stacks; run dev/prod
# with their own env file (OP_ENV_FILE=tf/.env.<env> tf/op-run.sh ...).
