Files
yucca/tf/.env.prod
T

99 lines
7.3 KiB
Bash

# Prod env file for the htz-fsn1 fabric stack — op:// references only, NO literal
# secrets. Resolved by `op run --env-file=tf/.env.prod` (account: team-futo).
# The `fabric:*` mise tasks set OP_ENV_FILE=tf/.env.prod automatically and, in
# addition, render the NETCONF SSH key to a temp file (op run can't write files).
# ── State backend (shared yucca-tf-state bucket, OVH Paris) ──────────────────
export AWS_ACCESS_KEY_ID=op://yucca_tf/TF_STATE_S3_ACCESS_KEY/password
export AWS_SECRET_ACCESS_KEY=op://yucca_tf/TF_STATE_S3_SECRET_KEY/password
# ── NetBird admin PAT (deployment/prod/netbird) ──────────────────────────────
# Same shared PAT as tf/.env (one NetBird Cloud account; objects namespaced
# "yucca-prod-…"). The netbird provider reads NB_PAT directly.
export NB_PAT=op://shared_tf/NETBIRD_TF_PAT/password
# ── NetBox API token ────────────────────────────────────────────────────────
# TODO: create this item in yucca_tf_prod (PASSWORD category) and confirm the path.
export TF_VAR_netbox_token=op://yucca_tf/NETBOX_API_TOKEN/password
# ── NETCONF SSH key ─────────────────────────────────────────────────────────
# Stored at op://yucca_tf_prod/NET_SWITCHES_TERRAFORM_SSH_PRIVATE_KEY/password.
# NOT exported here as content — the fabric mise task renders it to a 0600 temp
# file and exports TF_VAR_netconf_ssh_key_path=<that path>.
# ── Hetzner Robot API (mgmt-host reprovisioning, zack/hetzner provider) ───────
# The provider reads these env vars directly (no provider config block needed).
export HETZNER_ROBOT_USERNAME=op://yucca_tf_prod/HETZNER_WEBSERVICE_API_USER/password
export HETZNER_ROBOT_PASSWORD=op://yucca_tf_prod/HETZNER_WEBSERVICE_API_PASSWORD/password
# --- Cloudflare API token (deployment/prod/global/dns) ---
# futo.cloud zone (Zone:Read + DNS:Edit). Same zone as staging; the item must be
# created in yucca_tf_prod (copy the staging token value or mint a prod-scoped
# one). The cloudflare provider reads CLOUDFLARE_API_TOKEN directly.
export CLOUDFLARE_API_TOKEN=op://yucca_tf_prod/CLOUDFLARE_API_TOKEN/password
# ── NetBird setup keys (prod/htz-fsn1/talos — node-level overlay) ─────────────
# Minted by the netbird stack. WORKER key (group: talos) — joins the bare-metal
# workers to the prod htz-fsn1 NetBird network.
export TF_VAR_netbird_talos_setup_key=op://yucca_tf_prod/NETBIRD_YUCCA_PROD_HTZ_FSN1_TALOS_SETUP_KEY/password
# CP key (groups: talos + talos_cp — talos_cp is also the kube-cp router group).
export TF_VAR_netbird_talos_cp_setup_key=op://yucca_tf_prod/NETBIRD_YUCCA_PROD_HTZ_FSN1_TALOS_CP_SETUP_KEY/password
# netops fabric login password hash (looking glass / password-only tools).
export TF_VAR_netops_password_hash=op://yucca_tf_prod/NETOPS_FABRIC_PASSWORD/hash
# ─── Flux commit-status GitHub App (flux.tf) — SHARED push-o-matic (see tf/.env) ──
export TF_VAR_flux_github_app_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/app_id"
export TF_VAR_flux_github_app_installation_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/installation_id"
export TF_VAR_flux_github_app_private_key="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/pkcs1"
# ─── cert-manager DNS-01 (flux tree cert-manager-issuer; futo.network zone) ──
# NB: the BOOTSTRAP token (broad, all FUTO zones) — shared_tf/CLOUDFLARE_API_TOKEN
# sees no zones. TODO: mint a least-privilege token (Zone:Read + DNS:Edit on
# futo.network only) and swap this ref.
export TF_VAR_cloudflare_api_token="op://shared_tf/FUTO_BOOTSTRAP_CLOUDFLARE_API_TOKEN/password"
# ─── App secrets (prod/htz-fsn1/talos secrets.tf) ────────────────────────────
# yucca-api OIDC client (prod Zitadel) + device-flow public client.
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_WEB/password"
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_WEB/password"
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_ORCHESTRATOR/password"
# yucca-admin-api OIDC client — the shared internal-tooling app on
# https://auth.internal.futo.org; items live in shared_tf (readable by every
# env SA), one registration serves staging + prod.
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
# Postmark server token for invite/transactional email (docs/email.md); one
# server token in yucca_tf serves staging + prod.
export TF_VAR_yucca_postmark_server_token="op://yucca_tf/POSTMARK_API_TOKEN/password"
# michael → spice RGW (svc-yucca-restic, out-of-band contract items).
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"
# yucca-metrics-worker → spice RGW admin API.
export TF_VAR_spice_metrics_worker_access_key="op://yucca_tf_prod/SPICE_METRICS_WORKER_ACCESS_KEY/password"
export TF_VAR_spice_metrics_worker_secret_key="op://yucca_tf_prod/SPICE_METRICS_WORKER_SECRET_KEY/password"
# CNPG database backups → spice RGW (svc-yucca-db-backup, TF-minted by the
# ceph stack). The cert is the DR item `mise run capture` snapshots from the
# bootstrap node's /etc/ceph/rgw-ssl.crt; barman needs it as a CA bundle.
export TF_VAR_spice_db_backup_access_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_DB_BACKUP_ACCESS_KEY/password"
export TF_VAR_spice_db_backup_secret_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_DB_BACKUP_SECRET_KEY/password"
export TF_VAR_spice_rgw_tls_cert="op://yucca_tf_prod/SPICE_CEPH_RGW_TLS_CERT/password"
# vmagent/logs remote-write bearer for o11y prod vmauth.
export TF_VAR_vmauth_remote_write_password="op://shared_tf_prod/O11Y_VICTORIAMETRICS_VMAUTH_PASSWORD/password"
# futo-backups-bot (Discord support, docs/discord-support.md). The internal-API
# secret is TF-generated (secrets.tf); the transcripts keys are TF-minted by the
# ceph stack (rgw-users.tf svc-yucca-transcripts) — uncomment after its first
# apply. The token item comes from core-infra-tf's yucca-manual-secrets. Until
# then the Secret lands with empty values and the bot idles.
# export TF_VAR_yucca_discord_bot_token="op://yucca_tf_prod/YUCCA_DISCORD_BOT_TOKEN/password"
# export TF_VAR_yucca_discord_guild_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/guild_id"
# export TF_VAR_yucca_discord_staff_role_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/staff_role_id"
# export TF_VAR_yucca_discord_support_channel_id="op://yucca_tf_prod/YUCCA_DISCORD_SUPPORT_IDS/discord/support_channel_id"
# export TF_VAR_spice_transcripts_access_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_TRANSCRIPTS_ACCESS_KEY/password"
# export TF_VAR_spice_transcripts_secret_key="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_TRANSCRIPTS_SECRET_KEY/password"