mirror of
https://gitea.fenix-dev.com/fenix-gitea-admin/iac-opentofu-private.git
synced 2025-10-27 15:53:06 +00:00
get via vaultwarden
This commit is contained in:
@ -37,12 +37,12 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
path: infra/iac
|
path: infra/iac
|
||||||
|
|
||||||
- name: cloning iac secrets repository
|
#- name: cloning iac secrets repository
|
||||||
uses: actions/checkout@v4
|
# uses: actions/checkout@v4
|
||||||
with:
|
# with:
|
||||||
repository: fenix-gitea-admin/iac-opentofu-private-secrets
|
# repository: fenix-gitea-admin/iac-opentofu-private-secrets
|
||||||
token: ${{ secrets.GGITEA_TOKEN }}
|
# token: ${{ secrets.GGITEA_TOKEN }}
|
||||||
path: infra/secrets
|
# path: infra/secrets
|
||||||
|
|
||||||
|
|
||||||
- name: Install cloudflare prerequisites
|
- name: Install cloudflare prerequisites
|
||||||
@ -125,6 +125,28 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
BW_SESSION=$(bw login)
|
BW_SESSION=$(bw login)
|
||||||
|
|
||||||
|
|
||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
- name: vaultwarden getsecrets
|
||||||
|
working-directory: infra
|
||||||
|
run: |
|
||||||
|
bw sync
|
||||||
|
# Ler o arquivo de referência
|
||||||
|
for secret in $(jq -c '.secrets[]' iac/secrets/vault-secrets-map.json); do
|
||||||
|
name=$(echo "$secret" | jq -r '.name')
|
||||||
|
type=$(echo "$secret" | jq -r '.type')
|
||||||
|
output=$(echo "$secret" | jq -r '.output')
|
||||||
|
|
||||||
|
item_id=$(bw get item "$name" | jq -r '.id')
|
||||||
|
|
||||||
|
if [ "$type" == "attachment" ]; then
|
||||||
|
bw get attachment "$output" --itemid "$item_id" --output "$output"
|
||||||
|
elif [ "$type" == "note" ]; then
|
||||||
|
bw get item "$name" | jq -r '.notes' > "$output"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
- name: Set up Python
|
- name: Set up Python
|
||||||
uses: actions/setup-python@v4
|
uses: actions/setup-python@v4
|
||||||
with:
|
with:
|
||||||
|
|||||||
19
secrets/vault-secrets-map.json
Normal file
19
secrets/vault-secrets-map.json
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
{
|
||||||
|
"secrets": [
|
||||||
|
{
|
||||||
|
"name": "iac.opentofu.consul.secrets",
|
||||||
|
"type": "attachment",
|
||||||
|
"output": "iac/secrets/consul.secrets.tfvars"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "iac.opentofu.proxmox.secrets",
|
||||||
|
"type": "attachment",
|
||||||
|
"output": "iac/secrets/proxmox.secrets.tfvars"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "iac.opentofu.vaultwarden.secrets",
|
||||||
|
"type": "attachment",
|
||||||
|
"output": "iac/secrets/vaultwarden.secrets.tfvars"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user