Skip to content

chore: add Hero WARP enrollment credentials - #63

Merged
xnoto merged 2 commits into
mainfrom
chore/hero-host-config-warp-secret-source
Sep 6, 2026
Merged

chore: add Hero WARP enrollment credentials#63
xnoto merged 2 commits into
mainfrom
chore/hero-host-config-warp-secret-source

Conversation

@xnoto

@xnoto xnoto commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Carry forward the exact owner-authored, SOPS-encrypted Hero WARP enrollment entries from chore/hero-host-config-warp-secret-source without reading, decrypting, or changing their ciphertext.

This is split from conflicted PR #62 because current main refactored the non-secret catalog from main.tf into secrets.tf. A follow-up PR will add the two non-secret distribution references after these encrypted fields are present on main.

Fixes #

None.

Type of change

  • Bug fix
  • Feature / enhancement
  • Documentation
  • Infrastructure (OpenTofu root or module)
  • GitOps desired state (manifests, kustomize, charts, SOPS/KSOPS secrets)
  • Container image
  • CI / reusable workflow
  • Refactor / cleanup
  • Breaking change

Validation

  • Required pull-request checks pass — pending: opentofu / test and opentofu / plan are the validation authority.
  • No target repository file, Actions secret distribution, or workflow was changed; this PR preserves the owner-authored encrypted source file exactly.

No local OpenTofu init, plan, apply, import, state, or secret-decryption operation was run or claimed by the agent.

Impact and rollout

Producer: this PR changes only the canonical SOPS-encrypted source file in tfroot-github.

Consumer: none until a separate reviewed change adds the secrets.tf mappings and a later environment-gated apply runs. It does not distribute a GitHub Actions secret, alter Cloudflare Access, enroll WARP, execute a workflow, or mutate Hero.

Delivery stages: authored and submitted. Pull-request CI is automatic and pending. Merge remains confirmation-gated; a main apply is a separate confirmation-gated live mutation.

Rollback: close or revert this PR before any apply. The SOPS source remains encrypted throughout.

Safety and secrets

  • Contains only already-encrypted SOPS ciphertext; no plaintext secrets, decrypted SOPS values, state files, kubeconfigs, tokens, or private endpoints are present.
  • No local OpenTofu init/plan/apply/destroy/import/state operations were run or claimed — plans come from pull-request checks.
  • No live system is changed by this PR; merge and any future main apply are separately gated.

AI-assisted change: an OpenCode agent created this replacement pull request without retrieving or changing the encrypted source material.

@xnoto
xnoto requested a review from a team as a code owner September 6, 2026 21:03
@github-actions

github-actions Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

OpenTofu Test

OpenTofu test passed.

View the workflow run.

View run output
Terraform validate.......................................................Passed
Terraform validate with tflint...........................................Passed
Checkov..................................................................Passed
Terraform fmt............................................................Passed
Terraform docs...........................................................Passed
Detect hardcoded secrets.................................................Passed
check for case conflicts.................................................Passed
check for merge conflicts................................................Passed
check for broken symlinks............................(no files to check)Skipped
check vcs permalinks.....................................................Passed
detect destroyed symlinks................................................Passed
detect private key.......................................................Passed
fix end of files.........................................................Passed
mixed line ending........................................................Passed
trim trailing whitespace.................................................Passed
don't commit to branch..................................................Skipped
check for added large files..............................................Passed

@github-actions

github-actions Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

OpenTofu Plan

OpenTofu plan passed.

View the workflow run.

View run output
OpenTofu will perform the following actions:

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

Plan: 0 to add, 9 to change, 0 to destroy.
OpenTofu will perform the following actions:

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
[REDACTED: potentially sensitive plan output]
      ~ plaintext_value   = (sensitive value)
        # (7 unchanged attributes hidden)
    }

Plan: 0 to add, 9 to change, 0 to destroy.

@xnoto
xnoto merged commit 4e3f27d into main Sep 6, 2026
3 checks passed
@xnoto
xnoto deleted the chore/hero-host-config-warp-secret-source branch September 6, 2026 21:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant