mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
79 lines
5.3 KiB
Bash
79 lines
5.3 KiB
Bash
# op:// references resolved by `op run --env-file=tf/.env -- ...`
|
|
# Contains NO literal secrets — just pointers to 1P items.
|
|
#
|
|
# OP_SERVICE_ACCOUNT_TOKEN comes from the environment (GH secret / operator), not here.
|
|
|
|
# S3 credentials for the shared `yucca-tf-state` bucket (OVH eu-west-par).
|
|
# Shared infra → yucca_tf (read by every env SA), consumed by OpenTofu's S3
|
|
# backend via standard AWS env vars.
|
|
export AWS_ACCESS_KEY_ID="op://yucca_tf/TF_STATE_S3_ACCESS_KEY/password"
|
|
export AWS_SECRET_ACCESS_KEY="op://yucca_tf/TF_STATE_S3_SECRET_KEY/password"
|
|
|
|
# Cloudflare API token (futo.cloud zone; Zone:Read + DNS:Edit). The cloudflare
|
|
# provider reads this env var directly; cert-manager DNS-01 uses the TF_VAR copy.
|
|
export CLOUDFLARE_API_TOKEN="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"
|
|
|
|
# ─── Flux commit-status GitHub App (flux.tf) — SHARED push-o-matic, in shared_tf ──
|
|
# notification-controller's `github` Provider authenticates as this app to post
|
|
# reconcile results as commit statuses. Numeric App ID + Installation ID + raw
|
|
# PEM private key (NOT the OAuth client id CI uses). Temporary until a dedicated
|
|
# `yucca-flux` app exists; see flux.tf. `pkcs1` is the GitHub-native .pem format
|
|
# (the item also has `pkcs8`; flux's ParseRSAPrivateKeyFromPEM accepts either).
|
|
export TF_VAR_flux_github_app_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/app_id"
|
|
export TF_VAR_flux_github_app_installation_id="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/installation_id"
|
|
export TF_VAR_flux_github_app_private_key="op://shared_tf/GITHUB_APP_IMMICH_PUSH_O_MATIC/pkcs1"
|
|
|
|
# ─── NetBird admin PAT (deployment/<env>/netbird) — SHARED, in shared_tf ─────
|
|
# The netbird provider reads NB_PAT directly. One PAT (one NetBird Cloud account)
|
|
# backs every env/site; the netbird-env module namespaces objects per layer
|
|
# ("yucca_<env>_…" / "yucca_prod_<site>_…"). shared_tf is readable by every env
|
|
# SA, so this line serves the staging stack (prod uses tf/.env.prod).
|
|
# management_url defaults to https://api.netbird.io.
|
|
export NB_PAT="op://shared_tf/NETBIRD_TF_PAT/password"
|
|
|
|
# ─── staging/talos secrets (secrets.tf) — env-specific, in yucca_tf_staging ──
|
|
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID/password"
|
|
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET/password"
|
|
# Public device-flow client id (manually copied from yucca_tf_dev for now).
|
|
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_YUCCA_ORCHESTRATOR/password"
|
|
# admin-api OIDC client not registered yet (admin-api is in-cluster-only).
|
|
# export TF_VAR_yucca_oidc_admin_client_id="op://yucca_tf_staging/.../password"
|
|
# export TF_VAR_yucca_oidc_admin_client_secret="op://yucca_tf_staging/.../password"
|
|
|
|
# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
|
|
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
|
|
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
|
|
export TF_VAR_yucca_rgw_secret_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_RESTIC_SECRET_KEY/password"
|
|
|
|
# yucca-metrics-worker RGW ADMIN creds — separate sietch RGW user with admin caps
|
|
# (per-bucket usage via the RGW admin API; michael's plain S3 user can't). Created
|
|
# by the ceph stack into yucca_tf_staging; TF writes them into the yucca-metrics-rgw
|
|
# Secret (secrets.tf). NOT from CI — the cluster pulls nothing from CI.
|
|
export TF_VAR_sietch_metrics_worker_access_key="op://yucca_tf_staging/SIETCH_METRICS_WORKER_ACCESS_KEY/password"
|
|
export TF_VAR_sietch_metrics_worker_secret_key="op://yucca_tf_staging/SIETCH_METRICS_WORKER_SECRET_KEY/password"
|
|
|
|
# vmagent + collector → o11y staging vmauth bearer token.
|
|
export TF_VAR_vmauth_remote_write_password="op://shared_tf_staging/VICTORIAMETRICS_VMAUTH_PASSWORD/password"
|
|
|
|
# Cloudflare API token for cert-manager DNS-01 (same item, TF_VAR form).
|
|
export TF_VAR_cloudflare_api_token="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"
|
|
|
|
# NetBird, minted by deployment/staging/netbird into yucca_tf_staging.
|
|
# NB: `op run` resolves EVERY ref in this file up front for ANY stack, so a ref
|
|
# to an item that doesn't exist yet fails all plans/applies. Keep a ref commented
|
|
# until the netbird stack has minted its item (same convention as the OIDC lines).
|
|
#
|
|
# • talos setup key → node-level siderolabs/netbird extension (Part A). The
|
|
# item already exists (group `talos` was applied previously), so this is live.
|
|
export TF_VAR_netbird_talos_setup_key="op://yucca_tf_staging/NETBIRD_YUCCA_STAGING_TALOS_SETUP_KEY/password"
|
|
# • k8s_operator API token → in-cluster operator's netbird-mgmt-api-key (Part B).
|
|
# Live now that deployment/staging/netbird has minted the
|
|
# NETBIRD_YUCCA_STAGING_K8S_OPERATOR_API_TOKEN item.
|
|
export TF_VAR_netbird_operator_api_token="op://yucca_tf_staging/NETBIRD_YUCCA_STAGING_K8S_OPERATOR_API_TOKEN/password"
|
|
|
|
# The `yucca_tf_staging` refs above are readable only by the staging SA. CI
|
|
# injects it as OP_SERVICE_ACCOUNT_TOKEN from the repo secret
|
|
# OP_TF_YUCCA_STAGING_ENV (read) / OP_TF_YUCCA_STAGING_ENV_WRITE (apply); see
|
|
# .github/workflows/infra.yml. This file is shared by all stacks; run dev/prod
|
|
# with their own env file (OP_ENV_FILE=tf/.env.<env> tf/op-run.sh ...).
|