Commit Graph
13 Commits
Author SHA1 Message Date
arcodange 6a859d942a Revert "fix(ci) : l'IaC de factory tourne aussi sur le runner du Mac — résolution figée des noms du lab dans le job"
This reverts commit 41641e56ad.
2026-10-08 10:38:16 +02:00
arcodangeandClaude Opus 5.5 41641e56ad fix(ci) : l'IaC de factory tourne aussi sur le runner du Mac — résolution figée des noms du lab dans le job
Le runner du laptop ne résout pas *.arcodange.lab dans ses conteneurs de job (curl sort en 6 sur webapp.arcodange.lab pendant le passage OIDC, run 10015) ; les runners des pi le font par --add-host. Le job pose la même résolution (ingress 192.168.1.201) seulement si elle manque.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-08 10:33:01 +02:00
arcodangeandClaude Opus 5.5 ef74673037 fix(ci) : l'IaC de factory tourne de nouveau — OpenTofu dans le conteneur du job, et un mode « plan »
dflook/terraform-apply est une action CONTENEUR ; depuis 93e7abf (2026-08-26) les conteneurs de job reçoivent --add-host, et Docker refuse de lancer le conteneur de l'action dans le réseau du job (« conflicting options: custom host-to-IP mapping and the network mode », run 10014 sur pi3). Le dernier apply réussi datait du 2026-07-24 (pi1). OpenTofu s'installe désormais par opentofu/setup-opentofu (JavaScript) et tourne dans ubuntu-latest-ca. Un dispatch peut demander mode=plan pour lire le plan sans rien appliquer ; un push applique comme avant.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-08 10:20:55 +02:00
arcodange fc28c52b85 Merge pull request 'fix(iac): pin cloudflare provider + lockfile, trust homelab CA in gitea provider' (#12) from arcodange/iac-provider-fixes into main 2026-06-24 13:03:16 +02:00
arcodangeandClaude Opus 4.8 9b545e6f8f fix(iac): pin cloudflare provider + lockfile, trust homelab CA in gitea provider
With the runner CA fix (#11) the iac workflow now runs far enough to apply,
which exposed two provider problems:

cloudflare drift — `cloudflare/cloudflare` floated on `~> 5` with no committed
lock file, so CI pulled v5.21.1 where `cloudflare_account_token.policies[].resources`
is a JSON string, not a map ("Incorrect attribute value type"). Fix:
- pin to `~> 5.21` and commit a multi-platform `.terraform.lock.hcl`
  (linux_arm64 for the runner + darwin_arm64 for local);
- `jsonencode(...)` the module's policy resources;
- bind the cloudflare_token module to `cloudflare/cloudflare` explicitly (it was
  defaulting to `hashicorp/cloudflare`, pulling a redundant provider);
- stop `.gitignore` from hiding the lock file (the old `.terraform.*` rule did).

gitea provider TLS — it runs inside the dflook/terraform-apply container, which
doesn't trust the homelab CA (only the ubuntu-latest-ca runner does), so it
failed `x509: certificate signed by unknown authority` reaching
gitea.arcodange.lab. Fix: feed it the homelab CA via the provider's `cacert_file`
(TF_VAR_gitea_cacert_file -> the homelab.pem the workflow already materializes).

Validated locally with `tofu validate` + provider-schema inspection (no prod
calls). Complements #11. Out of scope (need a live run / operator): the OVH
consumer-key scope, and the R2 bucket "not found" on refresh (a state reconcile).

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-24 12:56:46 +02:00
arcodangeandClaude Opus 4.8 e5c537a967 fix(ci): run factory tofu workflows on the CA-trusting runner
After the move to the self-signed internal DNS (gitea.arcodange.lab /
vault.arcodange.lab), the default `ubuntu-latest` runner image does not
trust the homelab CA, so the `uses:` clone of the vault-action over HTTPS
fails TLS verification. webapp's workflows already moved to the
`ubuntu-latest-ca` runner (whose image ships the homelab CA); apply the
same to the factory `iac` and `postgres` tofu workflows.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-24 11:22:54 +02:00
arcodange 07e5ff460b use self signed cert 2026-01-02 18:17:53 +01:00
arcodange 5b3c896a25 use self signed cert for internal domain arcodange.lab 2025-12-31 17:38:04 +01:00
arcodange b6d240ce31 configure ovh client and allow cms project to access zoho client 2025-11-07 13:54:52 +01:00
arcodange 140dab4f1d cloudflare management for cms 2025-10-30 10:17:14 +01:00
arcodange 6d3adb5834 setup cron local mail reporting and longhorn recurring backup job 2025-09-08 13:25:02 +02:00
arcodange 561331b825 fixes 2025-08-07 15:51:53 +02:00
arcodange fa0df6f175 create gitea tofu bot user 2024-11-05 23:31:13 +01:00