Files
yucca/tf/.env
T

115 lines
8.4 KiB
Bash

# op:// references resolved by `op run --env-file=tf/.env -- ...`
# Contains NO literal secrets — just pointers to 1P items.
#
# OP_SERVICE_ACCOUNT_TOKEN comes from the environment (GH secret / operator), not here.
# S3 credentials for the shared `yucca-tf-state` bucket (OVH eu-west-par).
# Shared infra → yucca_tf (read by every env SA), consumed by OpenTofu's S3
# backend via standard AWS env vars.
export AWS_ACCESS_KEY_ID="op://yucca_tf/TF_STATE_S3_ACCESS_KEY/password"
export AWS_SECRET_ACCESS_KEY="op://yucca_tf/TF_STATE_S3_SECRET_KEY/password"
# Cloudflare API token (futo.cloud zone; Zone:Read + DNS:Edit). The cloudflare
# provider reads this env var directly; cert-manager DNS-01 uses the TF_VAR copy.
export CLOUDFLARE_API_TOKEN="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"
# ─── Flux commit-status GitHub App (flux.tf) — SHARED push-o-matic, in shared_tf ──
# notification-controller's `github` Provider authenticates as this app to post
# reconcile results as commit statuses. Numeric App ID + Installation ID + raw
# PEM private key (NOT the OAuth client id CI uses). Temporary until a dedicated
# `yucca-flux` app exists; see flux.tf. `pkcs1` is the GitHub-native .pem format
# (the item also has `pkcs8`; flux's ParseRSAPrivateKeyFromPEM accepts either).
export TF_VAR_flux_github_app_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/app_id"
export TF_VAR_flux_github_app_installation_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/installation_id"
export TF_VAR_flux_github_app_private_key="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/pkcs1"
# ─── NetBird admin PAT (deployment/<env>/netbird) — SHARED, in shared_tf ─────
# The netbird provider reads NB_PAT directly. One PAT (one NetBird Cloud account)
# backs every env/site; the netbird-env module namespaces objects per layer
# ("yucca_<env>_…" / "yucca_prod_<site>_…"). shared_tf is readable by every env
# SA, so this line serves the staging stack (prod uses tf/.env.prod).
# management_url defaults to https://api.netbird.io.
export NB_PAT="op://shared_tf/NETBIRD_TF_PAT/password"
# ─── staging/talos secrets (secrets.tf) — env-specific, in yucca_tf_staging ──
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID/password"
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET/password"
# Public device-flow client id (manually copied from yucca_tf_dev for now).
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_ORCHESTRATOR/password"
# admin-api OIDC client — the shared internal-tooling app on
# https://auth.internal.futo.org (one registration serves staging + prod, so
# the items live in shared_tf, readable by every env SA).
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
# Postmark server token for invite/transactional email (docs/email.md); one
# server token in yucca_tf serves staging + prod.
export TF_VAR_yucca_postmark_server_token="op://yucca_tf/POSTMARK_API_TOKEN/password"
# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"
# yucca-metrics-worker RGW ADMIN creds — separate sietch RGW user with admin caps
# (per-bucket usage via the RGW admin API; michael's plain S3 user can't). Created
# by the ceph stack into yucca_tf_staging; TF writes them into the yucca-metrics-rgw
# Secret (secrets.tf). NOT from CI — the cluster pulls nothing from CI.
export TF_VAR_sietch_metrics_worker_access_key="op://yucca_tf_staging/SIETCH_METRICS_WORKER_ACCESS_KEY/password"
export TF_VAR_sietch_metrics_worker_secret_key="op://yucca_tf_staging/SIETCH_METRICS_WORKER_SECRET_KEY/password"
# CNPG database backups → sietch RGW (svc-yucca-db-backup, TF-minted by the
# ceph stack). The cert is the DR item `mise run capture` snapshots from the
# bootstrap node's /etc/ceph/rgw-ssl.crt; barman needs it as a CA bundle.
export TF_VAR_sietch_db_backup_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_DB_BACKUP_ACCESS_KEY/password"
export TF_VAR_sietch_db_backup_secret_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_DB_BACKUP_SECRET_KEY/password"
export TF_VAR_sietch_rgw_tls_cert="op://yucca_tf_staging/SIETCH_CEPH_RGW_TLS_CERT/password"
# Cloudflare API token for cert-manager DNS-01. The shared bootstrap token, not
# the futo.cloud-scoped staging one: the admin cert (admin.luke.….yucca.futo.
# network, apps/staging/austin/admin) needs DNS:Edit on futo.network — same
# item prod's cert-manager uses.
export TF_VAR_cloudflare_api_token="op://shared_tf/FUTO_BOOTSTRAP_CLOUDFLARE_API_TOKEN/password"
# NetBird, minted by deployment/staging/netbird into yucca_tf_staging.
# NB: `op run` resolves EVERY ref in this file up front for ANY stack, so a ref
# to an item that doesn't exist yet fails all plans/applies. Keep a ref commented
# until the netbird stack has minted its item (same convention as the OIDC lines).
#
# • talos setup key → node-level siderolabs/netbird extension. The item
# already exists (group `talos` was applied previously), so this is live.
export TF_VAR_netbird_talos_setup_key="op://yucca_tf_staging/NETBIRD_YUCCA_STAGING_TALOS_SETUP_KEY/password"
# The `yucca_tf_staging` refs above are readable only by the staging SA. CI
# injects it as OP_SERVICE_ACCOUNT_TOKEN from the repo secret
# OP_TF_YUCCA_STAGING_ENV (read) / OP_TF_YUCCA_STAGING_ENV_WRITE (apply); see
# .github/workflows/infra.yml. This file is shared by all stacks; run dev/prod
# with their own env file (OP_ENV_FILE=tf/.env.<env> tf/op-run.sh ...).
# futo-backups-bot (Discord support, docs/discord-support.md). The internal-API
# secret is TF-generated (secrets.tf); the transcripts keys are TF-minted by the
# ceph stack (rgw-users.tf svc-yucca-transcripts); the token is the manual
# YUCCA_DISCORD_BOT_TOKEN item; the ids come from core-infra-tf's discord apply.
export TF_VAR_yucca_discord_bot_token="op://yucca_tf_staging/YUCCA_DISCORD_BOT_TOKEN/password"
export TF_VAR_yucca_discord_guild_id="op://yucca_tf_staging/YUCCA_DISCORD_SUPPORT_IDS/discord/guild_id"
export TF_VAR_yucca_discord_staff_role_id="op://yucca_tf_staging/YUCCA_DISCORD_SUPPORT_IDS/discord/staff_role_id"
export TF_VAR_yucca_discord_support_channel_id="op://yucca_tf_staging/YUCCA_DISCORD_SUPPORT_IDS/discord/support_channel_id"
export TF_VAR_yucca_discord_general_channel_id="op://yucca_tf_staging/YUCCA_DISCORD_SUPPORT_IDS/discord/general_channel_id"
export TF_VAR_yucca_discord_chat_channel_id="op://yucca_tf_staging/YUCCA_DISCORD_SUPPORT_IDS/discord/chat_channel_id"
export TF_VAR_yucca_discord_customer_role_id="op://yucca_tf_staging/YUCCA_DISCORD_SUPPORT_IDS/discord/customer_role_id"
export TF_VAR_sietch_transcripts_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_TRANSCRIPTS_ACCESS_KEY/password"
export TF_VAR_sietch_transcripts_secret_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_TRANSCRIPTS_SECRET_KEY/password"
# Freshdesk ticket sync (docs/discord-support.md): the manual YUCCA_FRESHDESK_URL /
# YUCCA_FRESHDESK_API_KEY items (core-infra-tf yucca-manual-secrets). The
# webhook header secret and URL path segment are TF-generated (secrets.tf).
export TF_VAR_yucca_freshdesk_url="op://yucca_tf_staging/YUCCA_FRESHDESK_URL/password"
export TF_VAR_yucca_freshdesk_api_key="op://yucca_tf_staging/YUCCA_FRESHDESK_API_KEY/password"
export TF_VAR_yucca_freshdesk_admin_api_key="op://yucca_tf_staging/YUCCA_FRESHDESK_ADMIN_API_KEY/password"
# Minted by the staging/global/freshdesk stack.
export TF_VAR_yucca_freshdesk_webhook_secret="op://yucca_tf_staging/YUCCA_FRESHDESK_WEBHOOK_SECRET/password"
export TF_VAR_yucca_freshdesk_webhook_path="op://yucca_tf_staging/YUCCA_FRESHDESK_WEBHOOK_PATH/password"
export TF_VAR_yucca_freshdesk_group_id="op://yucca_tf_staging/YUCCA_FRESHDESK_GROUP_ID/password"
# Columbo ticket investigations (docs/columbo.md): the manual
# YUCCA_OPENROUTER_API_KEY item (core-infra-tf yucca-manual-secrets).
export TF_VAR_yucca_openrouter_api_key="op://yucca_tf_staging/YUCCA_OPENROUTER_API_KEY/password"