feat(infra): plumb postmark config into staging and prod (#493)

This commit is contained in:
Antoine Lecompte
2026-08-24 06:45:00 -04:00
committed by GitHub
parent 30166e0733
commit 4d3990e7f3
9 changed files with 44 additions and 0 deletions
+5
View File
@@ -42,6 +42,11 @@ export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADE
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
# Postmark server token for invite/transactional email. Mint the 1P item, then
# uncomment; while commented the TF var defaults to "" and admin-api logs and
# skips sends (docs/email.md).
# export TF_VAR_yucca_postmark_server_token="op://yucca_tf_staging/POSTMARK_SERVER_TOKEN/password"
# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
+5
View File
@@ -63,6 +63,11 @@ export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_O
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
# Postmark server token for invite/transactional email. Mint the 1P item, then
# uncomment; while commented the TF var defaults to "" and admin-api logs and
# skips sends (docs/email.md).
# export TF_VAR_yucca_postmark_server_token="op://yucca_tf_prod/POSTMARK_SERVER_TOKEN/password"
# michael → spice RGW (svc-yucca-restic, out-of-band contract items).
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"
@@ -165,6 +165,9 @@ resource "kubernetes_secret_v1" "yucca_admin_api" {
# bench): deliberately the yucca_jwt SIGNING key — michael only accepts
# tokens from that keypair. Admin session JWTs stay on yucca_admin_jwt.
RESTIC_JWT_PRIVATE_KEY = tls_private_key.yucca_jwt.private_key_pem_pkcs8
# Empty until the 1P ref is minted — admin-api then logs and skips sends
# instead of crashing (see docs/email.md).
POSTMARK_SERVER_TOKEN = var.yucca_postmark_server_token
}
lifecycle {
@@ -188,6 +188,13 @@ variable "yucca_oidc_admin_client_secret" {
default = ""
}
variable "yucca_postmark_server_token" {
description = "Postmark server API token for invite/transactional email (ref stays commented in tf/.env.prod until minted; empty token = admin-api logs and skips sends)."
type = string
sensitive = true
default = ""
}
variable "yucca_rgw_access_key_id" {
description = "Spice RGW (S3) access key for michael (svc-yucca-restic, out-of-band contract item)."
type = string
@@ -171,6 +171,9 @@ resource "kubernetes_secret_v1" "yucca_admin_api" {
# bench): deliberately the yucca_jwt SIGNING key — michael only accepts
# tokens from that keypair. Admin session JWTs stay on yucca_admin_jwt.
RESTIC_JWT_PRIVATE_KEY = tls_private_key.yucca_jwt[0].private_key_pem_pkcs8
# Empty until the 1P ref is minted — admin-api then logs and skips sends
# instead of crashing (see docs/email.md).
POSTMARK_SERVER_TOKEN = var.yucca_postmark_server_token
}
lifecycle {
@@ -84,6 +84,13 @@ variable "yucca_oidc_admin_client_secret" {
default = ""
}
variable "yucca_postmark_server_token" {
description = "Postmark server API token for invite/transactional email (ref stays commented in tf/.env until minted; empty token = admin-api logs and skips sends). Injected via TF_VAR from 1P."
type = string
sensitive = true
default = ""
}
# michael S3 credentials — the `svc-yucca-restic` RGW user on the bare-metal
# Ceph (sietch / dev Ceph), created by the ceph Ansible with predetermined keys;
# duplicated into yucca_tf_staging (op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_