Fix rotation review evidence and reconcile blocked S1 workplans
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e3b9-b19e-7ba1-9eb4-4faea76af3ea
This commit is contained in:
parent
41f25fe42d
commit
9886567b40
10 changed files with 255 additions and 18 deletions
8
Makefile
8
Makefile
|
|
@ -16,7 +16,7 @@ IMG ?= ubuntu-24.04
|
|||
USER ?= admin
|
||||
|
||||
# Decrypt Hetzner token at runtime (requires SOPS_AGE_KEY or keys.txt locally)
|
||||
HCLOUD_TOKEN := $(shell sops -d --extract '["hetzner"]["token"]' secrets/hetzner-token.yaml 2>/dev/null)
|
||||
HCLOUD_TOKEN = $(shell sops -d --extract '["hetzner"]["token"]' secrets/hetzner-token.yaml 2>/dev/null)
|
||||
|
||||
# ---- Help ----
|
||||
help: ## Show this help
|
||||
|
|
@ -112,7 +112,7 @@ tf-destroy: ## Terraform destroy (exact approval required before init)
|
|||
|
||||
# --- Terraform provider/lockfile helpers ---
|
||||
TF_DIR := terraform/hetzner
|
||||
TF_TOKEN := $(HCLOUD_TOKEN)
|
||||
TF_TOKEN = $(HCLOUD_TOKEN)
|
||||
LOCKFILE := $(TF_DIR)/.terraform.lock.hcl
|
||||
|
||||
tf-lock-commit: ## Commit the current provider lockfile
|
||||
|
|
@ -287,8 +287,8 @@ PLAY := $(ANS_DIR)/playbooks/bootstrap.yaml
|
|||
SSH_USER ?=
|
||||
ANSIBLE_USER_FLAG := $(if $(SSH_USER),-u $(SSH_USER),)
|
||||
|
||||
# Load your SOPS key for decryption when running playbooks (optional if you use keys.txt)
|
||||
export SOPS_AGE_KEY := $(shell cat ~/.config/sops/age/keys.txt 2>/dev/null)
|
||||
# SOPS reads its standard key file itself; preserve an explicitly supplied
|
||||
# SOPS_AGE_KEY without reading/exporting private keys for unrelated Make targets.
|
||||
|
||||
ansible-help: ## Show common Ansible commands
|
||||
@echo "Convergence targets:"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue