Files
Gitea/infra/Pulumi.prod.yaml
T
JMR-devandClaude Opus 5.5 e70a5beac4 Configure the prod stack for gitea-496920
Fills in the values scripts/bootstrap.sh and the existing project
provide: the project id, the Cloud DNS zone resource name (main, holding
gitea.jasonmross.dev), and the cb-infra Pulumi runner account.

encryptionsalt is from `pulumi stack init` with the passphrase already in
Secret Manager (pulumi-config-passphrase), so Cloud Build's infra trigger
can open the stack with the same key.

githubAppInstallationId stays "0" for now: GitHubConfigured() is then
false and the Cloud Build triggers are skipped until the GitHub App is
installed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-10 04:04:18 -05:00

37 lines
1.7 KiB
YAML

# Stack configuration for the `prod` stack.
#
# `pulumi config set --secret` is unnecessary here: every value is public
# infrastructure metadata. The Gitea application secrets live in Secret Manager
# and are never read by this program.
config:
gcp:project: gitea-496920
gcp:region: us-east1
gitea:domain: gitea.jasonmross.dev
# The Cloud DNS *resource* name of the existing managed zone, which is not
# necessarily the DNS name. `gcloud dns managed-zones list` to find it.
gitea:dnsZone: main
# us-east1 has zones b, c and d -- there is no us-east1-a.
gitea:zone: us-east1-b
# e2-small: 2 shared vCPU, 2 GB RAM. See docs/runbook.md ("Memory on a 2 GB
# instance") before adding anything else to this host.
gitea:machineType: e2-small
gitea:bootDiskGb: "20"
gitea:dataDiskGb: "30"
gitea:appName: Gitea
gitea:requireSigninView: "false"
gitea:podmanSubnet: 10.89.10.0/24
# Coraza WAF: On | DetectionOnly | Off.
# Start in DetectionOnly, review what it flags (docs/waf.md), then switch to
# On. The fail2ban jail that bans on WAF verdicts follows this value.
gitea:wafMode: DetectionOnly
# Cloud Build source. The GitHub App installation id comes from the URL of the
# app's settings page after you install it on the repository.
gitea:githubOwner: JMR-dev
gitea:githubRepo: Gitea
gitea:githubAppInstallationId: "0"
gitea:githubPatSecret: github-pat
# Created by scripts/bootstrap.sh before the first `pulumi up`, because it is
# the identity that runs Pulumi and therefore cannot be created by Pulumi.
gitea:infraBuildServiceAccount: cb-infra@gitea-496920.iam.gserviceaccount.com
encryptionsalt: v1:pIXPmM64Bzc=:v1:0pkb4B2RVM5LFu2v:ZEPaG4RB9ySlpmaHkaBy8v6FQ3paHg==