Files
yucca/tf/.env.prod
T
Antoine Lecompte 481c5e920a feat(yucca): add full e2e mgmt provisioning maybe (#182)
* feat(yucca): add full e2e mgmt provisioning maybe

* moar !

* prefer tailscale over public ip if availbale

* ignore files

* fix

* more progress
2026-06-26 14:45:20 -04:00

28 lines
2.0 KiB
Bash

# Prod env file for the htz-fsn1 fabric stack — op:// references only, NO literal
# secrets. Resolved by `op run --env-file=tf/.env.prod` (account: team-futo).
# The `fabric:*` mise tasks set OP_ENV_FILE=tf/.env.prod automatically and, in
# addition, render the NETCONF SSH key to a temp file (op run can't write files).
# ── State backend (shared yucca-tf-state bucket, OVH Paris) ──────────────────
export AWS_ACCESS_KEY_ID=op://yucca_tf/TF_STATE_S3_ACCESS_KEY/password
export AWS_SECRET_ACCESS_KEY=op://yucca_tf/TF_STATE_S3_SECRET_KEY/password
# ── NetBird admin PAT (deployment/prod/netbird) ──────────────────────────────
# Same shared PAT as tf/.env (one NetBird Cloud account; objects namespaced
# "yucca-prod-…"). The netbird provider reads NB_PAT directly.
export NB_PAT=op://shared_tf/NETBIRD_TF_PAT/password
# ── NetBox API token ────────────────────────────────────────────────────────
# TODO: create this item in yucca_tf_prod (PASSWORD category) and confirm the path.
export TF_VAR_netbox_token=op://yucca_tf/NETBOX_API_TOKEN/password
# ── NETCONF SSH key ─────────────────────────────────────────────────────────
# Stored at op://yucca_tf_prod/NET_SWITCHES_TERRAFORM_SSH_PRIVATE_KEY/password.
# NOT exported here as content — the fabric mise task renders it to a 0600 temp
# file and exports TF_VAR_netconf_ssh_key_path=<that path>.
# ── Hetzner Robot API (mgmt-host reprovisioning, zack/hetzner provider) ───────
# The provider reads these env vars directly (no provider config block needed).
export HETZNER_ROBOT_USERNAME=op://yucca_tf_prod/HETZNER_WEBSERVICE_API_USER/password
export HETZNER_ROBOT_PASSWORD=op://yucca_tf_prod/HETZNER_WEBSERVICE_API_PASSWORD/password