Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions tf/deployment/.env
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ export TF_VAR_github_app_id="op://tf/GITHUB_APP_IMMICH_TOFU/app_id"
export TF_VAR_github_app_pem_file="op://tf/GITHUB_APP_IMMICH_TOFU/pkcs1"
export TF_VAR_github_owner="op://tf/GITHUB_APP_IMMICH_TOFU/owner"
export TF_VAR_op_service_account_token="op://tf/1pass_service_account/superuser_token"
export TF_VAR_futo_op_service_account_token="op://tf_$ENVIRONMENT/yucca_futo_1pass_superuser_service_account/password"
export TF_VAR_discord_token="op://tf/IMMICH_TF_DISCORD_BOT_TOKEN/password"
export TF_VAR_zitadel_profile_json="op://tf/ZITADEL_PROFILE_JSON/password"
export TF_VAR_zitadel_github_client_id="op://tf/GITHUB_OAUTH_APP_IMMICH_ZITADEL_CLIENT_ID/password"
Expand Down
14 changes: 2 additions & 12 deletions tf/deployment/modules/shared/1password/account/secrets.tf
Original file line number Diff line number Diff line change
Expand Up @@ -43,12 +43,7 @@ module "manual-secrets" {
"IOS_DEVELOPMENT_PROVISIONING_PROFILE_WIDGET_EXTENSION",
"IOS_DEVELOPMENT_PROVISIONING_PROFILE_SHARE_EXTENSION"
]
dev = [
"MONITORING_GRAFANA_TF_AUTH_TOKEN",
"MONITORING_GRAFANA_URL",
"IMMICH_DISCORD_SERVER_ID",
]
prod = [
scoped = [
"MONITORING_GRAFANA_TF_AUTH_TOKEN",
"MONITORING_GRAFANA_URL",
"IMMICH_DISCORD_SERVER_ID",
Expand All @@ -75,12 +70,7 @@ module "generated-secrets" {
{ name = "OAUTH2_PROXY_COOKIE_SECRET", length = 32 },
{ name = "IMMICH_GITHUB_ACTION_CHECKS_WEBHOOK_SECRET" }
]
dev = [
{ name = "METRICS_READ_TOKEN" },
{ name = "METRICS_WRITE_TOKEN" },
{ name = "METRICS_ADMIN_TOKEN" }
]
prod = [
scoped = [
{ name = "METRICS_READ_TOKEN" },
{ name = "METRICS_WRITE_TOKEN" },
{ name = "METRICS_ADMIN_TOKEN" },
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

21 changes: 21 additions & 0 deletions tf/deployment/modules/shared/1password/futo-account/config.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
terraform {
backend "pg" {
schema_name = "prod_1password_futo_account"
}
required_version = "~> 1.7"

required_providers {
onepassword = {
source = "1Password/onepassword"
version = "~> 2.0"
}
random = {
source = "hashicorp/random"
version = "3.7.2"
}
tls = {
source = "hashicorp/tls"
version = "4.1.0"
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
provider "onepassword" {
service_account_token = var.futo_op_service_account_token
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
terraform {
source = "../../../../../"

extra_arguments custom_vars {
commands = get_terraform_commands_that_need_vars()
}
}

include "root" {
path = find_in_parent_folders("root.hcl")
}
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
variable "futo_op_service_account_token" {}
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
module "yucca-manual-secrets" {
source = "./shared/modules/secrets/manual"

secrets = {
global = [
"TF_STATE_S3_ENDPOINT",
"TF_STATE_S3_BUCKET",
"TF_STATE_S3_REGION",
"TF_STATE_S3_ACCESS_KEY",
"TF_STATE_S3_SECRET_KEY",
"OVH_APPLICATION_KEY",
"OVH_APPLICATION_SECRET",
"OVH_CONSUMER_KEY",
"TAILSCALE_API_KEY",
"TAILSCALE_TAILNET_ID"
]
scoped = []
}
global_vault = "yucca_tf_manual"
copy_global_vault = "yucca_tf"
scoped_vaults = {
"yucca_tf_prod_manual" = "yucca_tf_prod"
"yucca_tf_staging_manual" = "yucca_tf_staging"
"yucca_tf_dev_manual" = "yucca_tf_dev"
}
}

module "generated-secrets" {
source = "./shared/modules/secrets/generated"

secrets = {
global = []
scoped = []
}

global_vault = "yucca_tf"
scoped_vaults = toset([
"yucca_tf_prod",
"yucca_tf_staging",
"yucca_tf_dev",
])
}
13 changes: 5 additions & 8 deletions tf/shared/modules/secrets/generated/data.tf
Original file line number Diff line number Diff line change
@@ -1,11 +1,8 @@
data "onepassword_vault" "tf" {
name = "tf"
data "onepassword_vault" "global" {
name = var.global_vault
}

data "onepassword_vault" "tf_dev" {
name = "tf_dev"
}

data "onepassword_vault" "tf_prod" {
name = "tf_prod"
data "onepassword_vault" "scoped" {
for_each = var.scoped_vaults
name = each.value
}
28 changes: 11 additions & 17 deletions tf/shared/modules/secrets/generated/secrets.tf
Original file line number Diff line number Diff line change
Expand Up @@ -2,28 +2,22 @@ locals {
secrets = concat(
var.secrets.global != null ? [
for secret_obj in var.secrets.global : {
vault = data.onepassword_vault.tf
vault = data.onepassword_vault.global
name = secret_obj.name
length = secret_obj.length
type = secret_obj.type
}
] : [],
var.secrets.dev != null ? [
for secret_obj in var.secrets.dev : {
vault = data.onepassword_vault.tf_dev
name = secret_obj.name
length = secret_obj.length
type = secret_obj.type
}
] : [],
var.secrets.prod != null ? [
for secret_obj in var.secrets.prod : {
vault = data.onepassword_vault.tf_prod
name = secret_obj.name
length = secret_obj.length
type = secret_obj.type
}
] : []
var.secrets.scoped != null ? flatten([
for vault_name in var.scoped_vaults : [
for secret_obj in var.secrets.scoped : {
vault = data.onepassword_vault.scoped[vault_name]
name = secret_obj.name
length = secret_obj.length
type = secret_obj.type
}
]
]) : []
)
}

Expand Down
19 changes: 13 additions & 6 deletions tf/shared/modules/secrets/generated/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -5,19 +5,26 @@ variable "secrets" {
length = optional(number)
type = optional(string, "alphanumeric")
})))
dev = optional(list(object({
name = string
length = optional(number)
type = optional(string, "alphanumeric")
})))
prod = optional(list(object({
scoped = optional(list(object({
name = string
length = optional(number)
type = optional(string, "alphanumeric")
})))
})
}

variable "global_vault" {
type = string
description = "Name of the vault for storing global secrets"
default = "tf"
}

variable "scoped_vaults" {
type = set(string)
description = "Names of the vaults for storing scoped secrets"
default = ["tf_prod", "tf_dev"]
}

variable "default_secret_length" {
type = number
description = "The default length for generated secrets if not specified per secret."
Expand Down
26 changes: 10 additions & 16 deletions tf/shared/modules/secrets/manual/data.tf
Original file line number Diff line number Diff line change
@@ -1,23 +1,17 @@
data "onepassword_vault" "manual" {
name = "tf_manual"
data "onepassword_vault" "manual_global" {
name = var.global_vault
}

data "onepassword_vault" "manual_dev" {
name = "tf_dev_manual"
data "onepassword_vault" "manual_scoped" {
for_each = var.scoped_vaults
name = each.key
}

data "onepassword_vault" "manual_prod" {
name = "tf_prod_manual"
data "onepassword_vault" "copy_global" {
name = var.copy_global_vault
}

data "onepassword_vault" "tf" {
name = "tf"
}

data "onepassword_vault" "tf_dev" {
name = "tf_dev"
}

data "onepassword_vault" "tf_prod" {
name = "tf_prod"
data "onepassword_vault" "copy_scoped" {
for_each = var.scoped_vaults
name = each.value
}
27 changes: 11 additions & 16 deletions tf/shared/modules/secrets/manual/secrets.tf
Original file line number Diff line number Diff line change
Expand Up @@ -2,25 +2,20 @@ locals {
secrets = concat(
var.secrets.global != null ? [
for name in var.secrets.global : {
manual_vault = data.onepassword_vault.manual
vault = data.onepassword_vault.tf
manual_vault = data.onepassword_vault.manual_global
vault = data.onepassword_vault.copy_global
name = name
}
] : [],
var.secrets.dev != null ? [
for name in var.secrets.dev : {
manual_vault = data.onepassword_vault.manual_dev
vault = data.onepassword_vault.tf_dev
name = name
}
] : [],
var.secrets.prod != null ? [
for name in var.secrets.prod : {
manual_vault = data.onepassword_vault.manual_prod
vault = data.onepassword_vault.tf_prod
name = name
}
] : []
var.secrets.scoped != null ? flatten([
for manual_vault, copy_vault in var.scoped_vaults : [
for name in var.secrets.scoped : {
manual_vault = data.onepassword_vault.manual_scoped[manual_vault]
vault = data.onepassword_vault.copy_scoped[manual_vault]
name = name
}
]
]) : []
)
}

Expand Down
24 changes: 22 additions & 2 deletions tf/shared/modules/secrets/manual/variables.tf
Original file line number Diff line number Diff line change
@@ -1,7 +1,27 @@
variable "secrets" {
type = object({
global = optional(list(string))
dev = optional(list(string))
prod = optional(list(string))
scoped = optional(list(string))
})
}

variable "global_vault" {
type = string
description = "Name of the vault for storing global manual secrets"
default = "tf_manual"
}

variable "copy_global_vault" {
type = string
description = "Name of the vault for copying global secrets to"
default = "tf"
}

variable "scoped_vaults" {
type = map(string)
description = "Map of manual vault names to copy vault names for scoped secrets"
default = {
"tf_prod_manual" = "tf_prod"
"tf_dev_manual" = "tf_dev"
}
}
Loading