Approach. Each parsed secret becomes its own variable "..." { sensitive = true } plus matching github_actions_secret / github_actions_environment_secret resource in the generated wrapper. Iterating per-key (rather than passing a sensitive map(string) into the module) keeps values end-to-end sensitive — no nonsensitive() calls, never used as a for_each key, never in plan output.
Plumbing.
--upload-repo-secrets FILE — repo-level secrets.
--upload-env-secrets DIR — one <env>.tfvars per env in DIR; basename must be in the --env list.
Values are fed to OpenTofu via a temp tfvars file written under /dev/shm (when available) in a chmod 700 dir, cleaned on exit via trap.
Module changes.
New outputs: environments_by_name (so the wrapper can express explicit deps on a specific env resource) and repository_name.
No new variables — secrets aren't a module concern in this design.
Filename fix. Adds a tiny no-extension gh-repo-bootstrap shim that execs gh-repo-bootstrap.sh, restoring gh ext install compatibility (gh requires gh-<name> with no suffix) while keeping the canonical script's .sh name.
State warning documented in README: GitHub stores secrets encrypted, but the OpenTofu state file holds the plaintext values — protect --state-dir.
Adds Actions secrets upload (repo-level + per-environment) sourced from tfvars-style files.
**Approach.** Each parsed secret becomes its own `variable "..." { sensitive = true }` plus matching `github_actions_secret` / `github_actions_environment_secret` resource in the generated wrapper. Iterating per-key (rather than passing a sensitive `map(string)` into the module) keeps values end-to-end sensitive — no `nonsensitive()` calls, never used as a `for_each` key, never in plan output.
**Plumbing.**
- `--upload-repo-secrets FILE` — repo-level secrets.
- `--upload-env-secrets DIR` — one `<env>.tfvars` per env in DIR; basename must be in the `--env` list.
- Values are fed to OpenTofu via a temp tfvars file written under `/dev/shm` (when available) in a `chmod 700` dir, cleaned on exit via trap.
**Module changes.**
- New outputs: `environments_by_name` (so the wrapper can express explicit deps on a specific env resource) and `repository_name`.
- No new variables — secrets aren't a module concern in this design.
**Filename fix.** Adds a tiny no-extension `gh-repo-bootstrap` shim that execs `gh-repo-bootstrap.sh`, restoring `gh ext install` compatibility (gh requires `gh-<name>` with no suffix) while keeping the canonical script's `.sh` name.
**State warning** documented in README: GitHub stores secrets encrypted, but the OpenTofu state file holds the plaintext values — protect `--state-dir`.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Adds Actions secrets upload (repo-level + per-environment) sourced from tfvars-style files.
Approach. Each parsed secret becomes its own
variable "..." { sensitive = true }plus matchinggithub_actions_secret/github_actions_environment_secretresource in the generated wrapper. Iterating per-key (rather than passing a sensitivemap(string)into the module) keeps values end-to-end sensitive — nononsensitive()calls, never used as afor_eachkey, never in plan output.Plumbing.
--upload-repo-secrets FILE— repo-level secrets.--upload-env-secrets DIR— one<env>.tfvarsper env in DIR; basename must be in the--envlist./dev/shm(when available) in achmod 700dir, cleaned on exit via trap.Module changes.
environments_by_name(so the wrapper can express explicit deps on a specific env resource) andrepository_name.Filename fix. Adds a tiny no-extension
gh-repo-bootstrapshim that execsgh-repo-bootstrap.sh, restoringgh ext installcompatibility (gh requiresgh-<name>with no suffix) while keeping the canonical script's.shname.State warning documented in README: GitHub stores secrets encrypted, but the OpenTofu state file holds the plaintext values — protect
--state-dir.