From ec55dc8437c4218e4fa21a3b4a5ef8e5faebaef1 Mon Sep 17 00:00:00 2001 From: InAnYan Date: Wed, 29 Jul 2026 16:15:14 +0200 Subject: [PATCH] feat: update tofu --- .gitea/workflows/tofu-deploy.yml | 45 ++++++++++++-------------------- 1 file changed, 16 insertions(+), 29 deletions(-) diff --git a/.gitea/workflows/tofu-deploy.yml b/.gitea/workflows/tofu-deploy.yml index dea31af..fcb93aa 100644 --- a/.gitea/workflows/tofu-deploy.yml +++ b/.gitea/workflows/tofu-deploy.yml @@ -3,47 +3,38 @@ on: workflow_call: inputs: vm_id: - description: "The Proxmox VM ID" required: true type: string ip_address: - description: "The static IP address (e.g., 192.168.1.50/24)" required: true type: string - - secrets: - PROXMOX_VE_ENDPOINT: - required: true - PROXMOX_VE_API_TOKEN: - required: true - TF_HTTP_USERNAME: - required: true - TF_HTTP_PASSWORD: - required: true - TF_HTTP_ADDRESS: - required: true - SSH_PUBLIC_KEY: + hostname: required: true + type: string jobs: deploy-to-proxmox: runs-on: ubuntu-latest env: + # Proxmox Auth (Pulled from Org-level secrets) PROXMOX_VE_ENDPOINT: ${{ secrets.PROXMOX_VE_ENDPOINT }} PROXMOX_VE_API_TOKEN: ${{ secrets.PROXMOX_VE_API_TOKEN }} PROXMOX_VE_INSECURE: "true" - TF_HTTP_ADDRESS: ${{ secrets.TF_HTTP_ADDRESS }} - TF_HTTP_LOCK_ADDRESS: "${{ secrets.TF_HTTP_ADDRESS }}/lock" - TF_HTTP_UNLOCK_ADDRESS: "${{ secrets.TF_HTTP_ADDRESS }}/lock" + # Gitea State Backend Configuration + TF_HTTP_ADDRESS: "${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/terraform/state/${{ gitea.event.repository.name }}" + TF_HTTP_LOCK_ADDRESS: "${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/terraform/state/${{ gitea.event.repository.name }}/lock" + TF_HTTP_UNLOCK_ADDRESS: "${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/terraform/state/${{ gitea.event.repository.name }}/lock" TF_HTTP_LOCK_METHOD: "POST" TF_HTTP_UNLOCK_METHOD: "DELETE" - TF_HTTP_USERNAME: ${{ secrets.TF_HTTP_USERNAME }} - TF_HTTP_PASSWORD: ${{ secrets.TF_HTTP_PASSWORD }} + TF_HTTP_USERNAME: ${{ gitea.actor }} + TF_HTTP_PASSWORD: ${{ secrets.GITEA_TOKEN }} + # VM Variables TF_VAR_vm_id: ${{ inputs.vm_id }} TF_VAR_ip_address: ${{ inputs.ip_address }} - TF_VAR_ssh_public_key: ${{ secrets.SSH_PUBLIC_KEY }} + TF_VAR_hostname: ${{ inputs.hostname }} + TF_VAR_ssh_public_key: ${{ secrets.SSH_PUBLIC_KEY }} # (From Org-level) steps: - name: Checkout Code @@ -52,11 +43,7 @@ jobs: - name: Setup OpenTofu uses: opentofu/setup-opentofu@v1 - - name: OpenTofu Init - run: tofu init - - - name: OpenTofu Plan - run: tofu plan -out=tfplan - - - name: OpenTofu Apply - run: tofu apply -auto-approve tfplan \ No newline at end of file + - name: OpenTofu Init & Apply + run: | + tofu init + tofu apply -auto-approve \ No newline at end of file