mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
feat(infra): plumb postmark config into staging and prod (#493)
This commit is contained in:
@@ -42,6 +42,11 @@ export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADE
|
||||
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
|
||||
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
|
||||
|
||||
# Postmark server token for invite/transactional email. Mint the 1P item, then
|
||||
# uncomment; while commented the TF var defaults to "" and admin-api logs and
|
||||
# skips sends (docs/email.md).
|
||||
# export TF_VAR_yucca_postmark_server_token="op://yucca_tf_staging/POSTMARK_SERVER_TOKEN/password"
|
||||
|
||||
# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
|
||||
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
|
||||
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
|
||||
|
||||
@@ -63,6 +63,11 @@ export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_O
|
||||
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
|
||||
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
|
||||
|
||||
# Postmark server token for invite/transactional email. Mint the 1P item, then
|
||||
# uncomment; while commented the TF var defaults to "" and admin-api logs and
|
||||
# skips sends (docs/email.md).
|
||||
# export TF_VAR_yucca_postmark_server_token="op://yucca_tf_prod/POSTMARK_SERVER_TOKEN/password"
|
||||
|
||||
# michael → spice RGW (svc-yucca-restic, out-of-band contract items).
|
||||
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
|
||||
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"
|
||||
|
||||
@@ -165,6 +165,9 @@ resource "kubernetes_secret_v1" "yucca_admin_api" {
|
||||
# bench): deliberately the yucca_jwt SIGNING key — michael only accepts
|
||||
# tokens from that keypair. Admin session JWTs stay on yucca_admin_jwt.
|
||||
RESTIC_JWT_PRIVATE_KEY = tls_private_key.yucca_jwt.private_key_pem_pkcs8
|
||||
# Empty until the 1P ref is minted — admin-api then logs and skips sends
|
||||
# instead of crashing (see docs/email.md).
|
||||
POSTMARK_SERVER_TOKEN = var.yucca_postmark_server_token
|
||||
}
|
||||
|
||||
lifecycle {
|
||||
|
||||
@@ -188,6 +188,13 @@ variable "yucca_oidc_admin_client_secret" {
|
||||
default = ""
|
||||
}
|
||||
|
||||
variable "yucca_postmark_server_token" {
|
||||
description = "Postmark server API token for invite/transactional email (ref stays commented in tf/.env.prod until minted; empty token = admin-api logs and skips sends)."
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
}
|
||||
|
||||
variable "yucca_rgw_access_key_id" {
|
||||
description = "Spice RGW (S3) access key for michael (svc-yucca-restic, out-of-band contract item)."
|
||||
type = string
|
||||
|
||||
@@ -171,6 +171,9 @@ resource "kubernetes_secret_v1" "yucca_admin_api" {
|
||||
# bench): deliberately the yucca_jwt SIGNING key — michael only accepts
|
||||
# tokens from that keypair. Admin session JWTs stay on yucca_admin_jwt.
|
||||
RESTIC_JWT_PRIVATE_KEY = tls_private_key.yucca_jwt[0].private_key_pem_pkcs8
|
||||
# Empty until the 1P ref is minted — admin-api then logs and skips sends
|
||||
# instead of crashing (see docs/email.md).
|
||||
POSTMARK_SERVER_TOKEN = var.yucca_postmark_server_token
|
||||
}
|
||||
|
||||
lifecycle {
|
||||
|
||||
@@ -84,6 +84,13 @@ variable "yucca_oidc_admin_client_secret" {
|
||||
default = ""
|
||||
}
|
||||
|
||||
variable "yucca_postmark_server_token" {
|
||||
description = "Postmark server API token for invite/transactional email (ref stays commented in tf/.env until minted; empty token = admin-api logs and skips sends). Injected via TF_VAR from 1P."
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
}
|
||||
|
||||
# michael S3 credentials — the `svc-yucca-restic` RGW user on the bare-metal
|
||||
# Ceph (sietch / dev Ceph), created by the ceph Ansible with predetermined keys;
|
||||
# duplicated into yucca_tf_staging (op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_
|
||||
|
||||
Reference in New Issue
Block a user