mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 21:37:50 +08:00
feat(admin): wire up admin (#313)
This commit is contained in:
@@ -36,9 +36,13 @@ export TF_VAR_yucca_oidc_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH
|
||||
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET/password"
|
||||
# Public device-flow client id (manually copied from yucca_tf_dev for now).
|
||||
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_ORCHESTRATOR/password"
|
||||
# admin-api OIDC client not registered yet (admin-api is in-cluster-only).
|
||||
# export TF_VAR_yucca_oidc_admin_client_id="op://yucca_tf_staging/.../password"
|
||||
# export TF_VAR_yucca_oidc_admin_client_secret="op://yucca_tf_staging/.../password"
|
||||
# admin-api OIDC client — the shared internal-tooling app on
|
||||
# https://auth.internal.futo.cloud (one registration serves staging + prod, so
|
||||
# the items live in shared_tf, readable by every env SA).
|
||||
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
|
||||
# Uncomment once the secret item is minted in shared_tf (a ref to a missing
|
||||
# item fails ALL plans/applies up front — see the NetBird note below).
|
||||
# export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
|
||||
|
||||
# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
|
||||
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
|
||||
|
||||
+7
-3
@@ -57,9 +57,13 @@ export TF_VAR_cloudflare_api_token="op://shared_tf/FUTO_BOOTSTRAP_CLOUDFLARE_API
|
||||
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_WEB/password"
|
||||
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_WEB/password"
|
||||
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_ORCHESTRATOR/password"
|
||||
# yucca-admin-api client not registered yet (mirrors staging):
|
||||
# export TF_VAR_yucca_oidc_admin_client_id="op://yucca_tf_prod/.../password"
|
||||
# export TF_VAR_yucca_oidc_admin_client_secret="op://yucca_tf_prod/.../password"
|
||||
# yucca-admin-api OIDC client — the shared internal-tooling app on
|
||||
# https://auth.internal.futo.cloud; items live in shared_tf (readable by every
|
||||
# env SA), one registration serves staging + prod.
|
||||
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
|
||||
# Uncomment once the secret item is minted in shared_tf (a ref to a missing
|
||||
# item fails ALL plans/applies up front).
|
||||
# export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
|
||||
|
||||
# michael → spice RGW (svc-yucca-restic, out-of-band contract items).
|
||||
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
|
||||
|
||||
@@ -60,6 +60,8 @@ locals {
|
||||
oxidized = cidrhost(module.addr_site.lb_internal_cidr, 16)
|
||||
sflow = cidrhost(module.addr_site.lb_internal_cidr, 16)
|
||||
hubble = cidrhost(module.addr_site.lb_internal_cidr, 16)
|
||||
# yucca-admin-api (namespace yucca), routed via the same netops gateway.
|
||||
admin = cidrhost(module.addr_site.lb_internal_cidr, 16)
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -176,13 +176,13 @@ variable "yucca_oidc_device_client_id" {
|
||||
}
|
||||
|
||||
variable "yucca_oidc_admin_client_id" {
|
||||
description = "OIDC client ID for yucca-admin-api — not registered yet (empty mirrors staging)."
|
||||
description = "OIDC client ID for yucca-admin-api (internal-tooling app on auth.internal.futo.cloud; FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING in shared_tf)."
|
||||
type = string
|
||||
default = ""
|
||||
}
|
||||
|
||||
variable "yucca_oidc_admin_client_secret" {
|
||||
description = "OIDC client secret for yucca-admin-api — not registered yet."
|
||||
description = "OIDC client secret for yucca-admin-api (FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING in shared_tf; ref stays commented in tf/.env.prod until minted)."
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
|
||||
@@ -68,15 +68,17 @@ variable "yucca_oidc_device_client_id" {
|
||||
default = ""
|
||||
}
|
||||
|
||||
# yucca-admin-api OIDC client (separate registration from yucca-api).
|
||||
# yucca-admin-api OIDC client (separate registration from yucca-api): the
|
||||
# internal-tooling app on auth.internal.futo.cloud, shared with prod
|
||||
# (FUTO_ZITADEL_OAUTH_*_YUCCA_INTERNAL_TOOLING in shared_tf).
|
||||
variable "yucca_oidc_admin_client_id" {
|
||||
description = "OIDC client ID for yucca-admin-api (staging IdP). Injected via TF_VAR from 1P."
|
||||
description = "OIDC client ID for yucca-admin-api (internal-tooling app). Injected via TF_VAR from 1P."
|
||||
type = string
|
||||
default = ""
|
||||
}
|
||||
|
||||
variable "yucca_oidc_admin_client_secret" {
|
||||
description = "OIDC client secret for yucca-admin-api (staging IdP). Injected via TF_VAR from 1P."
|
||||
description = "OIDC client secret for yucca-admin-api (internal-tooling app; ref stays commented in tf/.env until minted). Injected via TF_VAR from 1P."
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
|
||||
Reference in New Issue
Block a user