From b822a820c75ef9757f503c4ffc42be06db75e574 Mon Sep 17 00:00:00 2001 From: dawn <90008@klbr.net> Date: Thu, 24 Sep 2026 02:15:58 +0300 Subject: [PATCH] tf: give cloud run services env from secret manager Signed-off-by: dawn --- terraform/modules/cloud-run-app/main.tf | 14 ++++++++ terraform/modules/cloud-run-app/variables.tf | 1 + terraform/modules/control/main.tf | 35 +++++++++++++++++++- terraform/modules/environment/main.tf | 4 ++- terraform/modules/environment/variables.tf | 7 ++-- 5 files changed, 56 insertions(+), 5 deletions(-) diff --git a/terraform/modules/cloud-run-app/main.tf b/terraform/modules/cloud-run-app/main.tf index b081cb0..f2f4435 100644 --- a/terraform/modules/cloud-run-app/main.tf +++ b/terraform/modules/cloud-run-app/main.tf @@ -50,6 +50,20 @@ resource "google_cloud_run_v2_service" "this" { } } + # env name to a secret manager secret in the same project, always its latest version + dynamic "env" { + for_each = var.service.secrets + content { + name = env.key + value_source { + secret_key_ref { + secret = env.value + version = "latest" + } + } + } + } + startup_probe { http_get { path = var.service.probe diff --git a/terraform/modules/cloud-run-app/variables.tf b/terraform/modules/cloud-run-app/variables.tf index c2fde48..47bec9b 100644 --- a/terraform/modules/cloud-run-app/variables.tf +++ b/terraform/modules/cloud-run-app/variables.tf @@ -21,6 +21,7 @@ variable "service" { egress = optional(string, "PRIVATE_RANGES_ONLY") })) env = map(string) + secrets = optional(map(string), {}) ingress = string }) description = "one cloud run service, as described by modules/environment local.services" diff --git a/terraform/modules/control/main.tf b/terraform/modules/control/main.tf index f476e64..d34bd06 100644 --- a/terraform/modules/control/main.tf +++ b/terraform/modules/control/main.tf @@ -95,13 +95,46 @@ resource "google_service_account_iam_member" "ci_acts_as_deployment" { } resource "google_project_service" "this" { - for_each = toset(["certificatemanager.googleapis.com"]) + for_each = toset(["certificatemanager.googleapis.com", "secretmanager.googleapis.com"]) project = local.project service = each.value disable_on_destroy = false } +# the secrets services read live here, outside the blueprint, so a value can be added +# (gcloud secrets versions add) before any revision needs it and never reaches state. +# readers are named the way modules/environment names its service accounts +locals { + secret_reads = merge([ + for svc, s in local.env.services : { + for _, id in try(s.secrets, {}) : "${id}/${svc}" => { id = id, svc = svc } + } + ]...) +} + +resource "google_secret_manager_secret" "this" { + for_each = toset([for r in local.secret_reads : r.id]) + + project = local.project + secret_id = each.value + + replication { + auto {} + } + + depends_on = [google_project_service.this] +} + +resource "google_secret_manager_secret_iam_member" "readers" { + for_each = local.secret_reads + + project = local.project + secret_id = google_secret_manager_secret.this[each.value.id].secret_id + role = "roles/secretmanager.secretAccessor" + member = "serviceAccount:${each.value.svc}-${local.env.env_suffix}@${local.project}.iam.gserviceaccount.com" +} + locals { ci_oidc = try(local.env.ci_oidc, null) ci_wif = local.ci_oidc == null ? toset([]) : toset(["spindle"]) diff --git a/terraform/modules/environment/main.tf b/terraform/modules/environment/main.tf index f6fd49c..fa90100 100644 --- a/terraform/modules/environment/main.tf +++ b/terraform/modules/environment/main.tf @@ -25,7 +25,8 @@ locals { BOBBIN_LOG = "info" BOBBIN_LOG_FORMAT = "json" }, var.env.services.bobbin.env)) - public = var.env.services.bobbin.public + secrets = var.env.services.bobbin.secrets + public = var.env.services.bobbin.public } svfe = { name = local.svfe_name @@ -41,6 +42,7 @@ locals { cpu_idle = true vpc = false env = tomap(var.env.services.svfe.env) + secrets = var.env.services.svfe.secrets public = var.env.services.svfe.public } } diff --git a/terraform/modules/environment/variables.tf b/terraform/modules/environment/variables.tf index d41bdaf..fa42e3b 100644 --- a/terraform/modules/environment/variables.tf +++ b/terraform/modules/environment/variables.tf @@ -19,9 +19,10 @@ variable "env" { hostnames = optional(map(string), {}) services = map(object({ - image = string - public = bool - env = map(string) + image = string + public = bool + env = map(string) + secrets = optional(map(string), {}) })) }) description = "one modules/envs entry, its services carrying the image ref to run; the regions key set is the cell set" -- 2.51.2