mirror of
https://github.com/outbackdingo/homelab-v.git
synced 2026-08-25 14:53:19 +00:00
Tidying code and clarifying some sections Signed-off-by: Vegard Hagen <[email protected]>
1.5 KiB
1.5 KiB
GCS Remote
- Create a Service Account named tofu (after enabling the IAM API if needed). Leave the permissions blank.
- Create and download the service account key.
- Create a GCS bucket for tofu state with public access prevention and versioning as necessary.
- In the permissions tab of the bucket, give Storage Object Admin access to the service account.
- Copy backend.tf.sample to backend.tf and make necessary changes.
cp remote_backend.tf.sample remote_backend.tf
Encryption key
Generate the encryption key
python3 -c 'import os;import base64;print(base64.b64encode(os.urandom(32)).decode("utf-8"))'
Without the encryption key, your state would not be recoverable. Store in a password manager, if not using any kms like bws.
Environment variables
export GOOGLE_APPLICATION_CREDENTIALS="<YOUR_DOWNLOADED_KEY_PATH>"
export GOOGLE_ENCRYPTION_KEY="<YOUR_GENERATED_ENCRYPTION_KEY>"
Run tofu init / plan / apply as usual.
Bitwarden Secrets Manager
Store the downloaded key contents and generated encryption key into GOOGLE_CREDENTIALS and GOOGLE_ENCRYPTION_KEY respectively in bws.
Run bws run -- tofu init / plan / apply as usual.
Beta Notice
Please treat this as beta and only use for air-gapped installations as of now. Will remove the beta tag after testing it in due course.