From f553a87ce63467b2f6b305e6bd95ac6ee56a78fd Mon Sep 17 00:00:00 2001 From: Jason Ross Date: Sat, 10 Oct 2026 15:42:48 +0700 Subject: [PATCH] README: day-to-day make targets need ADC The Makefile derives PROJECT and ZONE from `pulumi config get`, which reads the stack from the GCS backend and so needs Application Default Credentials. Without them the lookup fails silently and every gcloud command runs with `--project=`. The passphrase is not needed for plaintext config values. Co-Authored-By: Claude Opus 5.5 --- README.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/README.md b/README.md index 5d7d12f..acdf077 100644 --- a/README.md +++ b/README.md @@ -100,6 +100,11 @@ make backup # on-demand gitea dump to GCS make ssh # shell via IAP ``` +The targets read the project and zone from the Pulumi stack, which needs +Application Default Credentials (`gcloud auth application-default login`). +Without them `pulumi config get` fails quietly and gcloud runs with an empty +`--project=`; pass `PROJECT=` to skip the lookup. + A push to `main` under `image/**` builds, pushes, rolls out, and gates on `/api/healthz`. A push under `infra/**` or `vm/**` runs `pulumi up` and then re-syncs the VM configuration. Anything else does nothing.