From e70a5beac47a8a3e44331d5176d937585a82e0da Mon Sep 17 00:00:00 2001 From: Jason Ross Date: Sat, 10 Oct 2026 14:41:58 +0700 Subject: [PATCH] Configure the prod stack for gitea-496920 Fills in the values scripts/bootstrap.sh and the existing project provide: the project id, the Cloud DNS zone resource name (main, holding gitea.jasonmross.dev), and the cb-infra Pulumi runner account. encryptionsalt is from `pulumi stack init` with the passphrase already in Secret Manager (pulumi-config-passphrase), so Cloud Build's infra trigger can open the stack with the same key. githubAppInstallationId stays "0" for now: GitHubConfigured() is then false and the Cloud Build triggers are skipped until the GitHub App is installed. Co-Authored-By: Claude Opus 5.5 --- infra/Pulumi.prod.yaml | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/infra/Pulumi.prod.yaml b/infra/Pulumi.prod.yaml index af8eeb2..5effe9a 100644 --- a/infra/Pulumi.prod.yaml +++ b/infra/Pulumi.prod.yaml @@ -4,14 +4,12 @@ # infrastructure metadata. The Gitea application secrets live in Secret Manager # and are never read by this program. config: - gcp:project: CHANGEME-gitea-project-id + gcp:project: gitea-496920 gcp:region: us-east1 - gitea:domain: gitea.jasonmross.dev # The Cloud DNS *resource* name of the existing managed zone, which is not # necessarily the DNS name. `gcloud dns managed-zones list` to find it. - gitea:dnsZone: CHANGEME-managed-zone-name - + gitea:dnsZone: main # us-east1 has zones b, c and d -- there is no us-east1-a. gitea:zone: us-east1-b # e2-small: 2 shared vCPU, 2 GB RAM. See docs/runbook.md ("Memory on a 2 GB @@ -19,23 +17,20 @@ config: gitea:machineType: e2-small gitea:bootDiskGb: "20" gitea:dataDiskGb: "30" - gitea:appName: Gitea gitea:requireSigninView: "false" gitea:podmanSubnet: 10.89.10.0/24 - # Coraza WAF: On | DetectionOnly | Off. # Start in DetectionOnly, review what it flags (docs/waf.md), then switch to # On. The fail2ban jail that bans on WAF verdicts follows this value. gitea:wafMode: DetectionOnly - # Cloud Build source. The GitHub App installation id comes from the URL of the # app's settings page after you install it on the repository. gitea:githubOwner: JMR-dev gitea:githubRepo: Gitea gitea:githubAppInstallationId: "0" gitea:githubPatSecret: github-pat - # Created by scripts/bootstrap.sh before the first `pulumi up`, because it is # the identity that runs Pulumi and therefore cannot be created by Pulumi. - gitea:infraBuildServiceAccount: CHANGEME@CHANGEME.iam.gserviceaccount.com + gitea:infraBuildServiceAccount: cb-infra@gitea-496920.iam.gserviceaccount.com +encryptionsalt: v1:pIXPmM64Bzc=:v1:0pkb4B2RVM5LFu2v:ZEPaG4RB9ySlpmaHkaBy8v6FQ3paHg==