feat(admin): wire up admin (#313)

This commit is contained in:
Antoine Lecompte
2026-07-23 13:43:48 +00:00
committed by GitHub
parent 16d2f452e0
commit 8afa3059ee
10 changed files with 97 additions and 17 deletions
+7 -3
View File
@@ -36,9 +36,13 @@ export TF_VAR_yucca_oidc_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET/password"
# Public device-flow client id (manually copied from yucca_tf_dev for now).
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_ORCHESTRATOR/password"
# admin-api OIDC client not registered yet (admin-api is in-cluster-only).
# export TF_VAR_yucca_oidc_admin_client_id="op://yucca_tf_staging/.../password"
# export TF_VAR_yucca_oidc_admin_client_secret="op://yucca_tf_staging/.../password"
# admin-api OIDC client — the shared internal-tooling app on
# https://auth.internal.futo.cloud (one registration serves staging + prod, so
# the items live in shared_tf, readable by every env SA).
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
# Uncomment once the secret item is minted in shared_tf (a ref to a missing
# item fails ALL plans/applies up front — see the NetBird note below).
# export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
+7 -3
View File
@@ -57,9 +57,13 @@ export TF_VAR_cloudflare_api_token="op://shared_tf/FUTO_BOOTSTRAP_CLOUDFLARE_API
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_WEB/password"
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_WEB/password"
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_ORCHESTRATOR/password"
# yucca-admin-api client not registered yet (mirrors staging):
# export TF_VAR_yucca_oidc_admin_client_id="op://yucca_tf_prod/.../password"
# export TF_VAR_yucca_oidc_admin_client_secret="op://yucca_tf_prod/.../password"
# yucca-admin-api OIDC client — the shared internal-tooling app on
# https://auth.internal.futo.cloud; items live in shared_tf (readable by every
# env SA), one registration serves staging + prod.
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
# Uncomment once the secret item is minted in shared_tf (a ref to a missing
# item fails ALL plans/applies up front).
# export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
# michael → spice RGW (svc-yucca-restic, out-of-band contract items).
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
@@ -60,6 +60,8 @@ locals {
oxidized = cidrhost(module.addr_site.lb_internal_cidr, 16)
sflow = cidrhost(module.addr_site.lb_internal_cidr, 16)
hubble = cidrhost(module.addr_site.lb_internal_cidr, 16)
# yucca-admin-api (namespace yucca), routed via the same netops gateway.
admin = cidrhost(module.addr_site.lb_internal_cidr, 16)
}
}
@@ -176,13 +176,13 @@ variable "yucca_oidc_device_client_id" {
}
variable "yucca_oidc_admin_client_id" {
description = "OIDC client ID for yucca-admin-api — not registered yet (empty mirrors staging)."
description = "OIDC client ID for yucca-admin-api (internal-tooling app on auth.internal.futo.cloud; FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING in shared_tf)."
type = string
default = ""
}
variable "yucca_oidc_admin_client_secret" {
description = "OIDC client secret for yucca-admin-api — not registered yet."
description = "OIDC client secret for yucca-admin-api (FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING in shared_tf; ref stays commented in tf/.env.prod until minted)."
type = string
sensitive = true
default = ""
@@ -68,15 +68,17 @@ variable "yucca_oidc_device_client_id" {
default = ""
}
# yucca-admin-api OIDC client (separate registration from yucca-api).
# yucca-admin-api OIDC client (separate registration from yucca-api): the
# internal-tooling app on auth.internal.futo.cloud, shared with prod
# (FUTO_ZITADEL_OAUTH_*_YUCCA_INTERNAL_TOOLING in shared_tf).
variable "yucca_oidc_admin_client_id" {
description = "OIDC client ID for yucca-admin-api (staging IdP). Injected via TF_VAR from 1P."
description = "OIDC client ID for yucca-admin-api (internal-tooling app). Injected via TF_VAR from 1P."
type = string
default = ""
}
variable "yucca_oidc_admin_client_secret" {
description = "OIDC client secret for yucca-admin-api (staging IdP). Injected via TF_VAR from 1P."
description = "OIDC client secret for yucca-admin-api (internal-tooling app; ref stays commented in tf/.env until minted). Injected via TF_VAR from 1P."
type = string
sensitive = true
default = ""