Keep the ACME contact email in Secret Manager
gitea:acmeEmail sat in Pulumi.prod.yaml, which this public repository publishes, and was then copied into instance metadata. It now lives in a gitea-acme-email secret instead, read by the VM when it renders the Caddyfile. - scripts/bootstrap.sh creates the secret empty and prints how to set it, the same as github-pat: the address is chosen, not generated. - Pulumi grants the VM secretAccessor on it and nothing more. It is kept out of secrets.Names, whose members also get secretVersionAdder and are mapped to `gitea generate secret` by vm/bootstrap.sh. - The gitea:acmeEmail config key and the acme-email metadata entry are gone. - vm/bootstrap.sh renders the whole `email` directive. If the secret is unreadable it renders a comment instead and warns: Caddy still issues certificates under an account with no contact address, whereas an empty `email` would fail to parse and leave nothing serving TLS. Same directive-or-comment pattern as CADDY_PUBLISH_PORTS and CADDY_SYSCTL. README setup gains the secret step, plus two that were missing: ADC login (Pulumi's GCS backend and provider do not use the gcloud login), and exporting PULUMI_CONFIG_PASSPHRASE from Secret Manager before `stack init`. Without the latter, init prompts for a new passphrase and the stack is encrypted with a key Cloud Build's infra trigger never sees. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
+11
-1
@@ -99,6 +99,16 @@ if ! has_version github-pat; then
|
||||
echo " printf %s '<token>' | gcloud secrets versions add github-pat --project=${PROJECT} --data-file=-"
|
||||
fi
|
||||
|
||||
# The ACME contact address Caddy registers with Let's Encrypt. A secret only to
|
||||
# keep it out of this public repository and out of instance metadata. Created
|
||||
# empty: the address is yours to choose, not something to generate.
|
||||
ensure_secret gitea-acme-email
|
||||
if ! has_version gitea-acme-email; then
|
||||
echo " NOTE: secret 'gitea-acme-email' has no value yet. Caddy still issues"
|
||||
echo " certificates without it, but with no contact address. Set it with:"
|
||||
echo " printf %s 'you@example.com' | gcloud secrets versions add gitea-acme-email --project=${PROJECT} --data-file=-"
|
||||
fi
|
||||
|
||||
# Gitea's signing secrets. These MUST come from `gitea generate secret`:
|
||||
# INTERNAL_TOKEN is a JWT, and a random string there produces an instance that
|
||||
# starts and then fails every internal API call in a confusing way.
|
||||
@@ -247,7 +257,7 @@ Next:
|
||||
pulumi stack init prod
|
||||
pulumi config set gcp:project ${PROJECT}
|
||||
pulumi config set gitea:infraBuildServiceAccount ${INFRA_SA_EMAIL}
|
||||
# ...plus domain, dnsZone, acmeEmail, githubOwner, githubAppInstallationId
|
||||
# ...plus domain, dnsZone, githubOwner, githubAppInstallationId
|
||||
pulumi up
|
||||
4. make build # or, spelled out:
|
||||
gcloud builds submit --config cloudbuild/image.yaml --project ${PROJECT} \\
|
||||
|
||||
Reference in New Issue
Block a user