diff --git a/docs/discord-support.md b/docs/discord-support.md index 910338fa..447ef7ed 100644 --- a/docs/discord-support.md +++ b/docs/discord-support.md @@ -62,8 +62,11 @@ open chat for everyone who sees the category plus customers. The `#general`, skipped when the channel is quiet) runs the same link flow as support and then grants the plain **FUTO Backups** role — linked customers get it instantly, unlinked ones link first. The role unlocks `#customer` (customer chat, also visible to -Admin/Team/Yucca/FUTO). `#support` stays visible to everyone; -ticket threads live under it as before. +Admin/Team/Yucca/FUTO). `#support` is restricted to the same audience plus +the customer role — Discord derives thread permissions from the parent channel, +so a customer needs view on `#support` to reach their own ticket thread. +Granting `@everyone` view there is the rollout switch that opens self-serve +support to the whole server. ## Closed-beta invites diff --git a/tf/.env.prod b/tf/.env.prod index 965b110a..32b7ae99 100644 --- a/tf/.env.prod +++ b/tf/.env.prod @@ -87,18 +87,19 @@ export TF_VAR_vmauth_remote_write_password="op://shared_tf_prod/O11Y_VICTORIAMET # futo-backups-bot (Discord support, docs/discord-support.md). The internal-API # secret is TF-generated (secrets.tf); the transcripts keys are TF-minted by the -# ceph stack (rgw-users.tf svc-yucca-transcripts) — uncomment after its first -# apply. The token item comes from core-infra-tf's yucca-manual-secrets. Until -# then the Secret lands with empty values and the bot idles. -# export TF_VAR_yucca_discord_bot_token="op://yucca_tf_prod/YUCCA_DISCORD_BOT_TOKEN/password" -# export TF_VAR_yucca_discord_guild_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/guild_id" -# export TF_VAR_yucca_discord_staff_role_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/staff_role_id" -# export TF_VAR_yucca_discord_support_channel_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/support_channel_id" -# export TF_VAR_yucca_discord_general_channel_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/general_channel_id" -# export TF_VAR_yucca_discord_chat_channel_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/chat_channel_id" -# export TF_VAR_yucca_discord_customer_role_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/customer_role_id" -# export TF_VAR_spice_transcripts_access_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_TRANSCRIPTS_ACCESS_KEY/password" -# export TF_VAR_spice_transcripts_secret_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_TRANSCRIPTS_SECRET_KEY/password" +# ceph stack (rgw-users.tf svc-yucca-transcripts); the token is the manual +# YUCCA_DISCORD_BOT_TOKEN item; the ids come from core-infra-tf's discord apply. +# The ids resolve only once that apply has bound prod (yucca_support_vaults), +# so these lines and the core-infra-tf binding must land in that order. +export TF_VAR_yucca_discord_bot_token="op://yucca_tf_prod/YUCCA_DISCORD_BOT_TOKEN/password" +export TF_VAR_yucca_discord_guild_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/guild_id" +export TF_VAR_yucca_discord_staff_role_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/staff_role_id" +export TF_VAR_yucca_discord_support_channel_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/support_channel_id" +export TF_VAR_yucca_discord_general_channel_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/general_channel_id" +export TF_VAR_yucca_discord_chat_channel_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/chat_channel_id" +export TF_VAR_yucca_discord_customer_role_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/customer_role_id" +export TF_VAR_spice_transcripts_access_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_TRANSCRIPTS_ACCESS_KEY/password" +export TF_VAR_spice_transcripts_secret_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_TRANSCRIPTS_SECRET_KEY/password" # Freshdesk ticket sync (docs/discord-support.md): the manual YUCCA_FRESHDESK_URL / # YUCCA_FRESHDESK_API_KEY items (core-infra-tf yucca-manual-secrets). The # webhook header secret and URL path segment are TF-generated (secrets.tf).