name: Auto-PR Check/Creation and TF/OpenTofu Plan on: workflow_dispatch: push: branches-ignore: - "main" - "renovate/**" paths: - "cloudflare/**" env: OPENTOFU_VERSION: "1.10.6" HC_VAULT_VERSION: "1.20.4" TEA_VERSION: "0.10.1" jobs: check-and-create-pr: name: Check and Create PR outputs: pr_number: ${{ steps.pr-check-create.outputs.pr_number }} runs-on: ubuntu-latest steps: - name: Checkout Code uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 with: fetch-depth: 1 - name: Setting Vault Token run: | echo "VAULT_TOKEN=${{ secrets.VAULT_GITEA_TOKEN }}" >> $GITHUB_ENV - name: Gotify Notification uses: eikendev/gotify-action@master with: gotify_api_base: "${{ secrets.RUNNER_GOTIFY_URL }}" gotify_app_token: "${{ secrets.RUNNER_GOTIFY_TOKEN }}" notification_title: "GITEA: PR Check @ Rinoa" notification_message: "Checking for existing PR... 🔍" - name: PR Check/Creation id: pr-check-create uses: https://git.trez.wtf/Trez/gitea-auto-pr@main with: url: ${{ secrets.TREZ_GITEA_URL }} token: ${{ secrets.BOT_GITEA_TOKEN }} pr-label: docker-compose,manual assignee: ${{ github.actor }} - name: Gotify Notification uses: eikendev/gotify-action@master with: gotify_api_base: "${{ secrets.RUNNER_GOTIFY_URL }}" gotify_app_token: "${{ secrets.RUNNER_GOTIFY_TOKEN }}" notification_title: "GITEA: PR Check @ Rinoa" notification_message: "PR Check done 🎟️" plan: name: OpenTofu Plan needs: check-and-create-pr runs-on: ubuntu-latest env: VAULT_TOKEN: ${{ secrets.VAULT_GITEA_TOKEN }} outputs: tofu-cloudflare-plan: ${{ steps.tofu_plan.outputs.plan-output }} steps: - name: Checkout uses: actions/checkout@v4 - name: Setup OpenTofu uses: opentofu/setup-opentofu@v1.0.6 with: version: ${{ env.OPENTOFU_VERSION }} tofu_wrapper: true - name: Generate .env from Hashicorp Vault uses: https://git.trez.wtf/Trez/hc-vault-env@main with: HC_VAULT_VERSION: ${{ env.HC_VAULT_VERSION }} HC_VAULT_ADDR: ${{ secrets.TREZ_VAULT_ADDR }} HC_VAULT_AUTH: token HC_VAULT_TOKEN: ${{ env.VAULT_TOKEN }} HC_VAULT_SECRETS_PATH: tar-valon-terraform/env ENV_FILE_NAME: cloudflare/.env - name: Export env vars from Vault .env id: env-vault-vars run: | echo "🧩 Cleaning and loading cloudflare/.env into GitHub Actions environment..." # 1️⃣ Strip any single or double quotes from the file to avoid invalid URIs or extra quoting sed -i 's/[\"'\'']//g' cloudflare/.env # 2️⃣ Load all vars into current shell set -a source cloudflare/.env set +a # 3️⃣ Export to GitHub Actions environment while IFS='=' read -r key value; do if [[ -n "$key" ]]; then echo "$key=$value" >> $GITHUB_ENV fi done < cloudflare/.env repo_name=$(echo "${{ github.repository }}" | awk -F"/" '{print $2}') echo "repo_name=$repo_name" >> "$GITHUB_OUTPUT" - name: Run tofu init uses: dnogu/tofu-init@v1 with: working-directory: . chdir: cloudflare - name: Tofu Plan id: tofu_plan continue-on-error: true uses: dnogu/tofu-plan@v1 with: working-directory: . chdir: cloudflare # destroy: # refresh-only: # refresh: # replace: # target: # target-file: # exclude: # exclude-file: # var: # var-file: out: cloudflare.tfplan # compact-warnings: # detailed-exitcode: # generate-config-out: . # input: true # json: # lock: # lock-timeout: # no-color: # concise: # parallelism: # state: # show-sensitive: # display-plan: - name: Post PR comment uses: borchero/terraform-plan-comment@v2.4.1 with: token: ${{ secrets.BOT_GITEA_TOKEN }} planfile: cloudflare.tfplan terraform-cmd: tofu - name: Wait for manual approval uses: trstringer/manual-approval@v1 with: secret: ${{ secrets.BOT_GITEA_TOKEN }} approvers: WTF minimum-approvals: 1 issue-title: "Tofu Plan for ${{ env.PR_NUMBER }}" issue-body: "Please approve or deny the deployment of the below Tofu plan" issue-body-file-path: relative/file_path/wrt/repo/root exclude-workflow-initiator-as-approver: false fail-on-denial: true additional-approved-words: '' additional-denied-words: '' # - name: PR Comment # uses: https://git.trez.wtf/Trez.One/git-auto-comment@main # env: # DEBUG: true # with: # debug: true # platform: gitea # api_url: https://git.trez.wtf/api/v1 # token: ${{ secrets.BOT_GITEA_TOKEN }} # pr_index: ${{ needs.check-and-create-pr.outputs.pr_number }} # repo_owner: ${{ github.repository_owner }} # repo_name: ${{ steps.env-vault-vars.outputs.repo_name }} # plan_file: cloudflare/cloudflare.tfplan # comment_template: | # 🚀 **Tofu Plan Output** # --- # ${{ steps.tofu_plan.outputs.plan-output }} # Exit Code: ${{ steps.tofu_plan.outputs.exitcode }} apply: name: Apply Tofu Plan needs: approval runs-on: ubuntu-latest if: ${{ needs.approval.result == 'success' }} env: VAULT_TOKEN: ${{ secrets.VAULT_GITEA_TOKEN }} steps: - name: Checkout uses: actions/checkout@v4 - name: Setup OpenTofu uses: opentofu/setup-opentofu@v1.0.6 with: version: ${{ env.OPENTOFU_VERSION }} tofu_wrapper: true - name: Export env from Vault run: | set -a source cloudflare/.env set +a - name: Run Tofu Apply uses: dnogu/tofu-apply@v1 with: working-directory: . chdir: cloudflare plan: cloudflare.tfplan