Add --upload-repo-secrets and --upload-env-secrets #1

Merged
JMR-dev merged 2 commits from feat-secrets-upload into main 2026-04-30 00:09:14 +00:00
JMR-dev commented 2026-04-30 00:06:44 +00:00 (Migrated from github.com)

Adds Actions secrets upload (repo-level + per-environment) sourced from tfvars-style files.

Approach. Each parsed secret becomes its own variable "..." { sensitive = true } plus matching github_actions_secret / github_actions_environment_secret resource in the generated wrapper. Iterating per-key (rather than passing a sensitive map(string) into the module) keeps values end-to-end sensitive — no nonsensitive() calls, never used as a for_each key, never in plan output.

Plumbing.

  • --upload-repo-secrets FILE — repo-level secrets.
  • --upload-env-secrets DIR — one <env>.tfvars per env in DIR; basename must be in the --env list.
  • Values are fed to OpenTofu via a temp tfvars file written under /dev/shm (when available) in a chmod 700 dir, cleaned on exit via trap.

Module changes.

  • New outputs: environments_by_name (so the wrapper can express explicit deps on a specific env resource) and repository_name.
  • No new variables — secrets aren't a module concern in this design.

Filename fix. Adds a tiny no-extension gh-repo-bootstrap shim that execs gh-repo-bootstrap.sh, restoring gh ext install compatibility (gh requires gh-<name> with no suffix) while keeping the canonical script's .sh name.

State warning documented in README: GitHub stores secrets encrypted, but the OpenTofu state file holds the plaintext values — protect --state-dir.

Adds Actions secrets upload (repo-level + per-environment) sourced from tfvars-style files. **Approach.** Each parsed secret becomes its own `variable "..." { sensitive = true }` plus matching `github_actions_secret` / `github_actions_environment_secret` resource in the generated wrapper. Iterating per-key (rather than passing a sensitive `map(string)` into the module) keeps values end-to-end sensitive — no `nonsensitive()` calls, never used as a `for_each` key, never in plan output. **Plumbing.** - `--upload-repo-secrets FILE` — repo-level secrets. - `--upload-env-secrets DIR` — one `<env>.tfvars` per env in DIR; basename must be in the `--env` list. - Values are fed to OpenTofu via a temp tfvars file written under `/dev/shm` (when available) in a `chmod 700` dir, cleaned on exit via trap. **Module changes.** - New outputs: `environments_by_name` (so the wrapper can express explicit deps on a specific env resource) and `repository_name`. - No new variables — secrets aren't a module concern in this design. **Filename fix.** Adds a tiny no-extension `gh-repo-bootstrap` shim that execs `gh-repo-bootstrap.sh`, restoring `gh ext install` compatibility (gh requires `gh-<name>` with no suffix) while keeping the canonical script's `.sh` name. **State warning** documented in README: GitHub stores secrets encrypted, but the OpenTofu state file holds the plaintext values — protect `--state-dir`.
Sign in to join this conversation.