mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
* impl. local kube * add support for op injected oidc secrets * ci: set least-privilege workflow token permissions
100 lines
3.4 KiB
TOML
100 lines
3.4 KiB
TOML
[tools]
|
|
node = "25.4.0"
|
|
pnpm = "10.28.1"
|
|
go = "1.24"
|
|
restic = "0.18.0"
|
|
|
|
gh = "2.25.0"
|
|
"github:git-town/git-town" = "22.4.0"
|
|
|
|
k3d = "5.8.3"
|
|
kubectl = "1.32.2"
|
|
helm = "3.17.0"
|
|
tilt = "0.34.5"
|
|
|
|
# Static validation of the k8s surface (mise run k8s:validate, used by CI).
|
|
# flux-local runs via `uvx` (see .mise/tasks/k8s/validate): uv auto-fetches a
|
|
# Python matching its requires-python, so the host's Python version (3.12 on
|
|
# GitHub runners, 3.14 on dev machines) doesn't matter.
|
|
kubeconform = "0.8.0"
|
|
kustomize = "5.8.1" # flux-local shells out to it
|
|
flux2 = "2.7.5" # ...and to the flux CLI
|
|
uv = "0.9.18"
|
|
|
|
# Infrastructure tooling (added for tf/ and ansible/ subtrees)
|
|
opentofu = "1.11.5"
|
|
terragrunt = "0.99.4"
|
|
|
|
[tasks.dev]
|
|
description = "Start all services in development mode"
|
|
depends = ["install:deps", "common:build", "docker:start"]
|
|
run = [{ task = "*:dev" }]
|
|
|
|
[tasks.build]
|
|
description = "Build all packages"
|
|
depends = ["*:build"]
|
|
|
|
[tasks."common:build"]
|
|
description = "Build all common packages"
|
|
depends = ["install:deps", "common:*:build"]
|
|
|
|
[tasks.test]
|
|
description = "Run all unit tests"
|
|
depends = ["*:test"]
|
|
|
|
[tasks."test:integration"]
|
|
description = "Run all integration tests"
|
|
# NB: mise flags must precede the task pattern — anything after it is forwarded
|
|
# to the tasks themselves (jest/go test choke on a stray --jobs).
|
|
run = "mise run --jobs 1 '*:test:integration'"
|
|
|
|
[tasks."test:e2e:web"]
|
|
description = "Run all web e2e tests"
|
|
run = [{ task = "test:e2e:wait" }, { task = "*:test:e2e:web" }]
|
|
|
|
[tasks."prepare"]
|
|
description = "Install and build packages"
|
|
run = [{ task = "install:frozen" }, { task = "build" }]
|
|
|
|
[tasks."check"]
|
|
description = "Run checks & unit tests"
|
|
run = [{ tasks = ["lint", "*:check"] }, { task = "format" }, { task = "test" }]
|
|
|
|
[tasks.fix]
|
|
description = "Run all possible code fixes"
|
|
run = [{ task = "*:fix" }, { task = "web:lingui" }]
|
|
|
|
# ─── Infrastructure (tf + ansible) ──────────────────────────────────────────
|
|
# All tf:* tasks wrap terragrunt with `op run --env-file=tf/.env` so the
|
|
# OP_SERVICE_ACCOUNT_TOKEN is injected from 1Password at invocation time.
|
|
# No literal secrets in the .env file — just op:// references.
|
|
|
|
[tasks."tf:init"]
|
|
description = "Terragrunt init for a given stack (default: deployment/dev/ceph)"
|
|
run = "op run --env-file=tf/.env -- terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} init"
|
|
|
|
[tasks."tf:plan"]
|
|
description = "Terragrunt plan for a given stack"
|
|
run = "op run --env-file=tf/.env -- terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} plan"
|
|
|
|
[tasks."tf:apply"]
|
|
description = "Terragrunt apply for a given stack"
|
|
run = "op run --env-file=tf/.env -- terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} apply"
|
|
|
|
[tasks."tf:destroy"]
|
|
description = "Terragrunt destroy for a given stack (use with care)"
|
|
run = "op run --env-file=tf/.env -- terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/dev/ceph} destroy"
|
|
|
|
[tasks."tf:fmt"]
|
|
description = "Format terraform + terragrunt files recursively"
|
|
run = "tofu fmt -recursive tf/ && terragrunt hcl format --working-dir tf/"
|
|
|
|
[env]
|
|
NODE_ENV = "development"
|
|
LOG_LEVEL = "debug"
|
|
|
|
OTLP_METRICS_ENDPOINT = "localhost:8428"
|
|
OTLP_METRICS_URL_PATH = "/opentelemetry/v1/metrics"
|
|
OTLP_LOGS_ENDPOINT = "localhost:9428"
|
|
OTLP_LOGS_URL_PATH = "/insert/opentelemetry/v1/logs"
|