mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 21:37:50 +08:00
39 lines
2.4 KiB
Bash
39 lines
2.4 KiB
Bash
# op:// references resolved by `op run --env-file=tf/.env -- ...`
|
|
# Contains NO literal secrets — just pointers to 1P items.
|
|
#
|
|
# OP_SERVICE_ACCOUNT_TOKEN comes from the environment (GH secret / operator), not here.
|
|
|
|
# S3 credentials for the shared `yucca-tf-state` bucket (OVH eu-west-par).
|
|
# Shared infra → yucca_tf (read by every env SA), consumed by OpenTofu's S3
|
|
# backend via standard AWS env vars.
|
|
export AWS_ACCESS_KEY_ID="op://yucca_tf/TF_STATE_S3_ACCESS_KEY/password"
|
|
export AWS_SECRET_ACCESS_KEY="op://yucca_tf/TF_STATE_S3_SECRET_KEY/password"
|
|
|
|
# Cloudflare API token (futo.cloud zone; Zone:Read + DNS:Edit). The cloudflare
|
|
# provider reads this env var directly; cert-manager DNS-01 uses the TF_VAR copy.
|
|
export CLOUDFLARE_API_TOKEN="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"
|
|
|
|
# ─── staging/talos secrets (secrets.tf) — env-specific, in yucca_tf_staging ──
|
|
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID/password"
|
|
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET/password"
|
|
# admin-api OIDC client not registered yet (admin-api is in-cluster-only).
|
|
# export TF_VAR_yucca_oidc_admin_client_id="op://yucca_tf_staging/.../password"
|
|
# export TF_VAR_yucca_oidc_admin_client_secret="op://yucca_tf_staging/.../password"
|
|
|
|
# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
|
|
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
|
|
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
|
|
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"
|
|
|
|
# vmagent + vlagent → o11y vmauth bearer token.
|
|
export TF_VAR_vmauth_remote_write_password="op://yucca_tf_staging/VICTORIAMETRICS_VMAUTH_PASSWORD/password"
|
|
|
|
# Cloudflare API token for cert-manager DNS-01 (same item, TF_VAR form).
|
|
export TF_VAR_cloudflare_api_token="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"
|
|
|
|
# The `yucca_tf_staging` refs above are readable only by the staging SA. CI
|
|
# injects it as OP_SERVICE_ACCOUNT_TOKEN from the repo secret
|
|
# OP_TF_YUCCA_STAGING_ENV (read) / OP_TF_YUCCA_STAGING_ENV_WRITE (apply); see
|
|
# .github/workflows/infra.yml. This file is shared by all stacks; run dev/prod
|
|
# with their own env file (OP_ENV_FILE=tf/.env.<env> tf/op-run.sh ...).
|