Keep the ACME contact email in Secret Manager

gitea:acmeEmail sat in Pulumi.prod.yaml, which this public repository
publishes, and was then copied into instance metadata. It now lives in a
gitea-acme-email secret instead, read by the VM when it renders the
Caddyfile.

- scripts/bootstrap.sh creates the secret empty and prints how to set
  it, the same as github-pat: the address is chosen, not generated.
- Pulumi grants the VM secretAccessor on it and nothing more. It is kept
  out of secrets.Names, whose members also get secretVersionAdder and are
  mapped to `gitea generate secret` by vm/bootstrap.sh.
- The gitea:acmeEmail config key and the acme-email metadata entry are
  gone.
- vm/bootstrap.sh renders the whole `email` directive. If the secret is
  unreadable it renders a comment instead and warns: Caddy still issues
  certificates under an account with no contact address, whereas an
  empty `email` would fail to parse and leave nothing serving TLS. Same
  directive-or-comment pattern as CADDY_PUBLISH_PORTS and CADDY_SYSCTL.

README setup gains the secret step, plus two that were missing: ADC
login (Pulumi's GCS backend and provider do not use the gcloud login),
and exporting PULUMI_CONFIG_PASSPHRASE from Secret Manager before
`stack init`. Without the latter, init prompts for a new passphrase and
the stack is encrypted with a key Cloud Build's infra trigger never sees.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-10 14:39:44 +07:00
co-authored by Claude Opus 5.5
parent 367b188eae
commit f0e7a3b66f
10 changed files with 67 additions and 21 deletions
+11 -1
View File
@@ -99,6 +99,16 @@ if ! has_version github-pat; then
echo " printf %s '<token>' | gcloud secrets versions add github-pat --project=${PROJECT} --data-file=-"
fi
# The ACME contact address Caddy registers with Let's Encrypt. A secret only to
# keep it out of this public repository and out of instance metadata. Created
# empty: the address is yours to choose, not something to generate.
ensure_secret gitea-acme-email
if ! has_version gitea-acme-email; then
echo " NOTE: secret 'gitea-acme-email' has no value yet. Caddy still issues"
echo " certificates without it, but with no contact address. Set it with:"
echo " printf %s 'you@example.com' | gcloud secrets versions add gitea-acme-email --project=${PROJECT} --data-file=-"
fi
# Gitea's signing secrets. These MUST come from `gitea generate secret`:
# INTERNAL_TOKEN is a JWT, and a random string there produces an instance that
# starts and then fails every internal API call in a confusing way.
@@ -247,7 +257,7 @@ Next:
pulumi stack init prod
pulumi config set gcp:project ${PROJECT}
pulumi config set gitea:infraBuildServiceAccount ${INFRA_SA_EMAIL}
# ...plus domain, dnsZone, acmeEmail, githubOwner, githubAppInstallationId
# ...plus domain, dnsZone, githubOwner, githubAppInstallationId
pulumi up
4. make build # or, spelled out:
gcloud builds submit --config cloudbuild/image.yaml --project ${PROJECT} \\