mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-07 04:42:08 +00:00
docs(terraform): document staging token scope
This commit is contained in:
parent
4ae6d02d55
commit
65c1ed86e1
1 changed files with 10 additions and 4 deletions
|
|
@ -160,10 +160,16 @@ and GitHub deploys on pushes to `staging` and on manual `workflow_dispatch`.
|
||||||
|
|
||||||
### Credentials and enablement
|
### Credentials and enablement
|
||||||
|
|
||||||
Store a dedicated HCP team token only as the GitHub `dev` environment secret
|
Store dedicated HCP team tokens as the GitHub environment secret `TF_API_TOKEN`:
|
||||||
`TF_API_TOKEN`. Scope it to workspace `shoc-backend-dev`. Plan JSON download
|
|
||||||
requires workspace admin on that one workspace. Do not grant project admin,
|
- `dev`: use a token scoped only to workspace `shoc-backend-dev`.
|
||||||
workspace create/move/delete, or staging access. Rotate at least every 90 days.
|
- `staging`: use a separate token scoped only to workspace
|
||||||
|
`shoc-backend-staging`.
|
||||||
|
|
||||||
|
Plan JSON download requires workspace admin on the corresponding workspace. Do
|
||||||
|
not grant project admin or workspace create/move/delete permissions. Do not rely
|
||||||
|
on a repository-level token or reuse the dev-scoped token for staging. Rotate
|
||||||
|
each token at least every 90 days.
|
||||||
|
|
||||||
Repository variable `TERRAFORM_APP_CD_ENABLED` starts unset/false so pushes to
|
Repository variable `TERRAFORM_APP_CD_ENABLED` starts unset/false so pushes to
|
||||||
`dev` do not deploy. `workflow_dispatch` on `dev` still runs a release for the
|
`dev` do not deploy. `workflow_dispatch` on `dev` still runs a release for the
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue