mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
feat(staging): normalize logs (#164)
This commit is contained in:
@@ -25,8 +25,8 @@ export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_O
|
||||
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
|
||||
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"
|
||||
|
||||
# vmagent + vlagent → o11y vmauth bearer token.
|
||||
export TF_VAR_vmauth_remote_write_password="op://yucca_tf_staging/VICTORIAMETRICS_VMAUTH_PASSWORD/password"
|
||||
# vmagent + collector → o11y staging vmauth bearer token.
|
||||
export TF_VAR_vmauth_remote_write_password="op://o11y_tf_staging/VICTORIAMETRICS_VMAUTH_PASSWORD/password"
|
||||
|
||||
# Cloudflare API token for cert-manager DNS-01 (same item, TF_VAR form).
|
||||
export TF_VAR_cloudflare_api_token="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"
|
||||
|
||||
@@ -8,7 +8,7 @@
|
||||
# with the public one — they MUST be the same pair).
|
||||
# • OIDC / RGW — externally issued, human-managed in 1P; read via TF_VAR
|
||||
# (op:// refs in tf/.env) and written into the app Secrets.
|
||||
# • vmauth token — shared o11y credential (o11y_tf_prod), for vmagent egress.
|
||||
# • vmauth token — shared o11y credential (o11y_tf_staging), for vmagent egress.
|
||||
#
|
||||
# Each Secret is named after its chart's fullnameOverride so the chart's own
|
||||
# `secretData` fixture (nulled in the staging HelmRelease) cedes the name and
|
||||
|
||||
@@ -32,7 +32,7 @@ variable "flux_github_app_private_key" {
|
||||
# ─── App secrets (secrets.tf) ───────────────────────────────────────────
|
||||
#
|
||||
# Externally-issued / human-managed secrets. Live in 1P (yucca_tf_staging_manual
|
||||
# for app creds, o11y_tf_prod for the shared vmauth token) and are injected via
|
||||
# for app creds, o11y_tf_staging for the shared vmauth token) and are injected via
|
||||
# TF_VAR from op:// refs in tf/.env. Empty defaults keep `tofu validate` clean
|
||||
# and let the staging slice deploy before the real values are populated — the
|
||||
# apps come up, just without working OIDC / object storage / metrics egress.
|
||||
@@ -87,10 +87,10 @@ variable "yucca_rgw_secret_access_key" {
|
||||
}
|
||||
|
||||
# Bearer token vmagent uses to remote-write metrics to o11y's vmauth. This is
|
||||
# the shared VICTORIAMETRICS_VMAUTH_PASSWORD from the o11y_tf_prod vault (the
|
||||
# the shared VICTORIAMETRICS_VMAUTH_PASSWORD from the o11y_tf_staging vault (the
|
||||
# `remote-clusters` VMUser authenticates remote clusters with it).
|
||||
variable "vmauth_remote_write_password" {
|
||||
description = "o11y vmauth bearer token for vmagent remote-write. Injected via TF_VAR from 1P (o11y_tf_prod/VICTORIAMETRICS_VMAUTH_PASSWORD)."
|
||||
description = "o11y vmauth bearer token for vmagent remote-write. Injected via TF_VAR from 1P (o11y_tf_staging/VICTORIAMETRICS_VMAUTH_PASSWORD)."
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
|
||||
Reference in New Issue
Block a user