Files
ci-cd/.gitea/workflows/tofu-deploy.yml
T
2026-07-29 16:15:14 +02:00

49 lines
1.7 KiB
YAML

name: Reusable OpenTofu Deploy Template
on:
workflow_call:
inputs:
vm_id:
required: true
type: string
ip_address:
required: true
type: string
hostname:
required: true
type: string
jobs:
deploy-to-proxmox:
runs-on: ubuntu-latest
env:
# Proxmox Auth (Pulled from Org-level secrets)
PROXMOX_VE_ENDPOINT: ${{ secrets.PROXMOX_VE_ENDPOINT }}
PROXMOX_VE_API_TOKEN: ${{ secrets.PROXMOX_VE_API_TOKEN }}
PROXMOX_VE_INSECURE: "true"
# Gitea State Backend Configuration
TF_HTTP_ADDRESS: "${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/terraform/state/${{ gitea.event.repository.name }}"
TF_HTTP_LOCK_ADDRESS: "${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/terraform/state/${{ gitea.event.repository.name }}/lock"
TF_HTTP_UNLOCK_ADDRESS: "${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/terraform/state/${{ gitea.event.repository.name }}/lock"
TF_HTTP_LOCK_METHOD: "POST"
TF_HTTP_UNLOCK_METHOD: "DELETE"
TF_HTTP_USERNAME: ${{ gitea.actor }}
TF_HTTP_PASSWORD: ${{ secrets.GITEA_TOKEN }}
# VM Variables
TF_VAR_vm_id: ${{ inputs.vm_id }}
TF_VAR_ip_address: ${{ inputs.ip_address }}
TF_VAR_hostname: ${{ inputs.hostname }}
TF_VAR_ssh_public_key: ${{ secrets.SSH_PUBLIC_KEY }} # (From Org-level)
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Setup OpenTofu
uses: opentofu/setup-opentofu@v1
- name: OpenTofu Init & Apply
run: |
tofu init
tofu apply -auto-approve