mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 21:37:50 +08:00
83 lines
6.0 KiB
Bash
83 lines
6.0 KiB
Bash
# Prod env file for the htz-fsn1 fabric stack — op:// references only, NO literal
|
|
# secrets. Resolved by `op run --env-file=tf/.env.prod` (account: team-futo).
|
|
# The `fabric:*` mise tasks set OP_ENV_FILE=tf/.env.prod automatically and, in
|
|
# addition, render the NETCONF SSH key to a temp file (op run can't write files).
|
|
|
|
# ── State backend (shared yucca-tf-state bucket, OVH Paris) ──────────────────
|
|
export AWS_ACCESS_KEY_ID=op://yucca_tf/TF_STATE_S3_ACCESS_KEY/password
|
|
export AWS_SECRET_ACCESS_KEY=op://yucca_tf/TF_STATE_S3_SECRET_KEY/password
|
|
|
|
# ── NetBird admin PAT (deployment/prod/netbird) ──────────────────────────────
|
|
# Same shared PAT as tf/.env (one NetBird Cloud account; objects namespaced
|
|
# "yucca-prod-…"). The netbird provider reads NB_PAT directly.
|
|
export NB_PAT=op://shared_tf/NETBIRD_TF_PAT/password
|
|
|
|
# ── NetBox API token ────────────────────────────────────────────────────────
|
|
# TODO: create this item in yucca_tf_prod (PASSWORD category) and confirm the path.
|
|
export TF_VAR_netbox_token=op://yucca_tf/NETBOX_API_TOKEN/password
|
|
|
|
# ── NETCONF SSH key ─────────────────────────────────────────────────────────
|
|
# Stored at op://yucca_tf_prod/NET_SWITCHES_TERRAFORM_SSH_PRIVATE_KEY/password.
|
|
# NOT exported here as content — the fabric mise task renders it to a 0600 temp
|
|
# file and exports TF_VAR_netconf_ssh_key_path=<that path>.
|
|
|
|
# ── Hetzner Robot API (mgmt-host reprovisioning, zack/hetzner provider) ───────
|
|
# The provider reads these env vars directly (no provider config block needed).
|
|
export HETZNER_ROBOT_USERNAME=op://yucca_tf_prod/HETZNER_WEBSERVICE_API_USER/password
|
|
export HETZNER_ROBOT_PASSWORD=op://yucca_tf_prod/HETZNER_WEBSERVICE_API_PASSWORD/password
|
|
|
|
# --- Cloudflare API token (deployment/prod/global/dns) ---
|
|
# futo.cloud zone (Zone:Read + DNS:Edit). Same zone as staging; the item must be
|
|
# created in yucca_tf_prod (copy the staging token value or mint a prod-scoped
|
|
# one). The cloudflare provider reads CLOUDFLARE_API_TOKEN directly.
|
|
export CLOUDFLARE_API_TOKEN=op://yucca_tf_prod/CLOUDFLARE_API_TOKEN/password
|
|
|
|
# ── NetBird setup keys (prod/htz-fsn1/talos — node-level overlay) ─────────────
|
|
# Minted by the netbird stack. WORKER key (group: talos) — joins the bare-metal
|
|
# workers to the prod htz-fsn1 NetBird network.
|
|
export TF_VAR_netbird_talos_setup_key=op://yucca_tf_prod/NETBIRD_YUCCA_PROD_HTZ_FSN1_TALOS_SETUP_KEY/password
|
|
# CP key (groups: talos + talos_cp — talos_cp is also the kube-cp router group).
|
|
export TF_VAR_netbird_talos_cp_setup_key=op://yucca_tf_prod/NETBIRD_YUCCA_PROD_HTZ_FSN1_TALOS_CP_SETUP_KEY/password
|
|
# netops fabric login password hash (looking glass / password-only tools).
|
|
export TF_VAR_netops_password_hash=op://yucca_tf_prod/NETOPS_FABRIC_PASSWORD/hash
|
|
|
|
# ─── Flux commit-status GitHub App (flux.tf) — SHARED push-o-matic (see tf/.env) ──
|
|
export TF_VAR_flux_github_app_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/app_id"
|
|
export TF_VAR_flux_github_app_installation_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/installation_id"
|
|
export TF_VAR_flux_github_app_private_key="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/pkcs1"
|
|
|
|
# ─── cert-manager DNS-01 (flux tree cert-manager-issuer; futo.network zone) ──
|
|
# NB: the BOOTSTRAP token (broad, all FUTO zones) — shared_tf/CLOUDFLARE_API_TOKEN
|
|
# sees no zones. TODO: mint a least-privilege token (Zone:Read + DNS:Edit on
|
|
# futo.network only) and swap this ref.
|
|
export TF_VAR_cloudflare_api_token="op://shared_tf/FUTO_BOOTSTRAP_CLOUDFLARE_API_TOKEN/password"
|
|
|
|
# ─── App secrets (prod/htz-fsn1/talos secrets.tf) ────────────────────────────
|
|
# yucca-api OIDC client (prod Zitadel) + device-flow public client.
|
|
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_WEB/password"
|
|
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_WEB/password"
|
|
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_ORCHESTRATOR/password"
|
|
# yucca-admin-api OIDC client — the shared internal-tooling app on
|
|
# https://auth.internal.futo.org; items live in shared_tf (readable by every
|
|
# env SA), one registration serves staging + prod.
|
|
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
|
|
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
|
|
|
|
# michael → spice RGW (svc-yucca-restic, out-of-band contract items).
|
|
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
|
|
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"
|
|
|
|
# yucca-metrics-worker → spice RGW admin API.
|
|
export TF_VAR_spice_metrics_worker_access_key="op://yucca_tf_prod/SPICE_METRICS_WORKER_ACCESS_KEY/password"
|
|
export TF_VAR_spice_metrics_worker_secret_key="op://yucca_tf_prod/SPICE_METRICS_WORKER_SECRET_KEY/password"
|
|
|
|
# CNPG database backups → spice RGW (svc-yucca-db-backup, TF-minted by the
|
|
# ceph stack). The cert is the DR item `mise run capture` snapshots from the
|
|
# bootstrap node's /etc/ceph/rgw-ssl.crt; barman needs it as a CA bundle.
|
|
export TF_VAR_spice_db_backup_access_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_DB_BACKUP_ACCESS_KEY/password"
|
|
export TF_VAR_spice_db_backup_secret_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_DB_BACKUP_SECRET_KEY/password"
|
|
export TF_VAR_spice_rgw_tls_cert="op://yucca_tf_prod/SPICE_CEPH_RGW_TLS_CERT/password"
|
|
|
|
# vmagent/logs remote-write bearer for o11y prod vmauth.
|
|
export TF_VAR_vmauth_remote_write_password="op://shared_tf_prod/O11Y_VICTORIAMETRICS_VMAUTH_PASSWORD/password"
|