Files
homelab-v/tofu/kubernetes/REMOTE_BACKEND.md
T
Vegard Hagen e94a97e6f3 feat(tofu): refactor tofu-code
Tidying code and clarifying some sections

Signed-off-by: Vegard Hagen <[email protected]>
2025-04-18 13:56:14 +02:00

1.5 KiB

GCS Remote

  1. Create a Service Account named tofu (after enabling the IAM API if needed). Leave the permissions blank.
  2. Create and download the service account key.
  3. Create a GCS bucket for tofu state with public access prevention and versioning as necessary.
  4. In the permissions tab of the bucket, give Storage Object Admin access to the service account.
  5. Copy backend.tf.sample to backend.tf and make necessary changes.
cp remote_backend.tf.sample remote_backend.tf

Encryption key

Generate the encryption key

python3 -c 'import os;import base64;print(base64.b64encode(os.urandom(32)).decode("utf-8"))'

Without the encryption key, your state would not be recoverable. Store in a password manager, if not using any kms like bws.

Environment variables

export GOOGLE_APPLICATION_CREDENTIALS="<YOUR_DOWNLOADED_KEY_PATH>"
export GOOGLE_ENCRYPTION_KEY="<YOUR_GENERATED_ENCRYPTION_KEY>"

Run tofu init / plan / apply as usual.

Bitwarden Secrets Manager

Store the downloaded key contents and generated encryption key into GOOGLE_CREDENTIALS and GOOGLE_ENCRYPTION_KEY respectively in bws.

Run bws run -- tofu init / plan / apply as usual.

Beta Notice

Please treat this as beta and only use for air-gapped installations as of now. Will remove the beta tag after testing it in due course.