feat(staging): normalize logs (#164)

This commit is contained in:
Antoine Lecompte
2026-06-25 17:55:33 +00:00
committed by GitHub
parent b5a0b97bcb
commit bc8136def5
17 changed files with 110 additions and 110 deletions
+2 -2
View File
@@ -25,8 +25,8 @@ export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_O
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"
# vmagent + vlagent → o11y vmauth bearer token.
export TF_VAR_vmauth_remote_write_password="op://yucca_tf_staging/VICTORIAMETRICS_VMAUTH_PASSWORD/password"
# vmagent + collector → o11y staging vmauth bearer token.
export TF_VAR_vmauth_remote_write_password="op://o11y_tf_staging/VICTORIAMETRICS_VMAUTH_PASSWORD/password"
# Cloudflare API token for cert-manager DNS-01 (same item, TF_VAR form).
export TF_VAR_cloudflare_api_token="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"
+1 -1
View File
@@ -8,7 +8,7 @@
# with the public one — they MUST be the same pair).
# • OIDC / RGW — externally issued, human-managed in 1P; read via TF_VAR
# (op:// refs in tf/.env) and written into the app Secrets.
# • vmauth token — shared o11y credential (o11y_tf_prod), for vmagent egress.
# • vmauth token — shared o11y credential (o11y_tf_staging), for vmagent egress.
#
# Each Secret is named after its chart's fullnameOverride so the chart's own
# `secretData` fixture (nulled in the staging HelmRelease) cedes the name and
+3 -3
View File
@@ -32,7 +32,7 @@ variable "flux_github_app_private_key" {
# ─── App secrets (secrets.tf) ───────────────────────────────────────────
#
# Externally-issued / human-managed secrets. Live in 1P (yucca_tf_staging_manual
# for app creds, o11y_tf_prod for the shared vmauth token) and are injected via
# for app creds, o11y_tf_staging for the shared vmauth token) and are injected via
# TF_VAR from op:// refs in tf/.env. Empty defaults keep `tofu validate` clean
# and let the staging slice deploy before the real values are populated — the
# apps come up, just without working OIDC / object storage / metrics egress.
@@ -87,10 +87,10 @@ variable "yucca_rgw_secret_access_key" {
}
# Bearer token vmagent uses to remote-write metrics to o11y's vmauth. This is
# the shared VICTORIAMETRICS_VMAUTH_PASSWORD from the o11y_tf_prod vault (the
# the shared VICTORIAMETRICS_VMAUTH_PASSWORD from the o11y_tf_staging vault (the
# `remote-clusters` VMUser authenticates remote clusters with it).
variable "vmauth_remote_write_password" {
description = "o11y vmauth bearer token for vmagent remote-write. Injected via TF_VAR from 1P (o11y_tf_prod/VICTORIAMETRICS_VMAUTH_PASSWORD)."
description = "o11y vmauth bearer token for vmagent remote-write. Injected via TF_VAR from 1P (o11y_tf_staging/VICTORIAMETRICS_VMAUTH_PASSWORD)."
type = string
sensitive = true
default = ""