Fills in the values scripts/bootstrap.sh and the existing project provide: the project id, the Cloud DNS zone resource name (main, holding gitea.jasonmross.dev), and the cb-infra Pulumi runner account. encryptionsalt is from `pulumi stack init` with the passphrase already in Secret Manager (pulumi-config-passphrase), so Cloud Build's infra trigger can open the stack with the same key. githubAppInstallationId stays "0" for now: GitHubConfigured() is then false and the Cloud Build triggers are skipped until the GitHub App is installed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
37 lines
1.7 KiB
YAML
37 lines
1.7 KiB
YAML
# Stack configuration for the `prod` stack.
|
|
#
|
|
# `pulumi config set --secret` is unnecessary here: every value is public
|
|
# infrastructure metadata. The Gitea application secrets live in Secret Manager
|
|
# and are never read by this program.
|
|
config:
|
|
gcp:project: gitea-496920
|
|
gcp:region: us-east1
|
|
gitea:domain: gitea.jasonmross.dev
|
|
# The Cloud DNS *resource* name of the existing managed zone, which is not
|
|
# necessarily the DNS name. `gcloud dns managed-zones list` to find it.
|
|
gitea:dnsZone: main
|
|
# us-east1 has zones b, c and d -- there is no us-east1-a.
|
|
gitea:zone: us-east1-b
|
|
# e2-small: 2 shared vCPU, 2 GB RAM. See docs/runbook.md ("Memory on a 2 GB
|
|
# instance") before adding anything else to this host.
|
|
gitea:machineType: e2-small
|
|
gitea:bootDiskGb: "20"
|
|
gitea:dataDiskGb: "30"
|
|
gitea:appName: Gitea
|
|
gitea:requireSigninView: "false"
|
|
gitea:podmanSubnet: 10.89.10.0/24
|
|
# Coraza WAF: On | DetectionOnly | Off.
|
|
# Start in DetectionOnly, review what it flags (docs/waf.md), then switch to
|
|
# On. The fail2ban jail that bans on WAF verdicts follows this value.
|
|
gitea:wafMode: DetectionOnly
|
|
# Cloud Build source. The GitHub App installation id comes from the URL of the
|
|
# app's settings page after you install it on the repository.
|
|
gitea:githubOwner: JMR-dev
|
|
gitea:githubRepo: Gitea
|
|
gitea:githubAppInstallationId: "0"
|
|
gitea:githubPatSecret: github-pat
|
|
# Created by scripts/bootstrap.sh before the first `pulumi up`, because it is
|
|
# the identity that runs Pulumi and therefore cannot be created by Pulumi.
|
|
gitea:infraBuildServiceAccount: cb-infra@gitea-496920.iam.gserviceaccount.com
|
|
encryptionsalt: v1:pIXPmM64Bzc=:v1:0pkb4B2RVM5LFu2v:ZEPaG4RB9ySlpmaHkaBy8v6FQ3paHg==
|