feat: auto-unseal openbao on start of service #32

Open
thesuperRL wants to merge 1 commit from openbao-auto-unseal into main
thesuperRL commented 2026-07-11 22:04:26 +00:00 (Migrated from codeberg.org)

looks to address #27

looks to address #27
scottylabs-bot commented 2026-07-23 23:43:51 +00:00 (Migrated from codeberg.org)

Ran Plan for 16 projects:

  1. project: posthog dir: . workspace: posthog
  2. project: vaultwarden dir: . workspace: vaultwarden
  3. project: forgejo dir: . workspace: forgejo
  4. project: ricochet dir: . workspace: ricochet
  5. project: garage-webadmin dir: . workspace: garage-webadmin
  6. project: keycloak dir: . workspace: keycloak
  7. project: governance dir: . workspace: governance
  8. project: headscale dir: . workspace: headscale
  9. project: matrix dir: . workspace: matrix
  10. project: atlantis dir: . workspace: atlantis
  11. project: observability dir: . workspace: observability
  12. project: kennel dir: . workspace: kennel
  13. project: openbao dir: . workspace: openbao
  14. project: hosts dir: . workspace: hosts
  15. project: litellm dir: . workspace: litellm
  16. project: webhook dir: . workspace: webhook

1. project: posthog dir: . workspace: posthog

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding latest version of mrparkers/keycloak...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installing mrparkers/keycloak v5.8.0 to the shared cache directory...
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed mrparkers/keycloak v5.8.0 (unauthenticated)
- Using mrparkers/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - mrparkers/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
data.cloudflare_zones.all: Reading...
data.cloudflare_zones.all: Read complete after 1s
cloudflare_dns_record.this["v"]: Refreshing state... [id=a34d75a85d3128693767b2db9b7f233e]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
  • ▶️ To apply this plan, comment:
    atlantis apply -p posthog
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p posthog
    

No changes. Your infrastructure matches the configuration.


2. project: vaultwarden dir: . workspace: vaultwarden

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding latest version of mrparkers/keycloak...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing mrparkers/keycloak v5.8.0 to the shared cache directory...
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed mrparkers/keycloak v5.8.0 (unauthenticated)
- Using mrparkers/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - mrparkers/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
data.cloudflare_zones.all: Reading...
data.cloudflare_zones.all: Read complete after 1s
cloudflare_dns_record.this["vault"]: Refreshing state... [id=7828e0eeb9e7f251c797f565828a47f6]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
  • ▶️ To apply this plan, comment:
    atlantis apply -p vaultwarden
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p vaultwarden
    

No changes. Your infrastructure matches the configuration.


3. project: forgejo dir: . workspace: forgejo

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
data.cloudflare_zones.all: Reading...
garage_key.forgejo: Refreshing state... [id=GKea9810d648000e3e3b8df725]
garage_bucket.forgejo: Refreshing state... [id=65e2f6d77ab1d627c920b8e6bd764551f5f8b0334fd1f67bc47c5f5c30546960]
vault_kv_secret_v2.forgejo_storage: Refreshing state... [id=secret/data/infra/forgejo-storage]
garage_bucket_permission.forgejo: Refreshing state... [id=65e2f6d77ab1d627c920b8e6bd764551f5f8b0334fd1f67bc47c5f5c30546960/GKea9810d648000e3e3b8df725]
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
keycloak_openid_client.forgejo: Refreshing state... [id=110b9b02-18e1-4bac-b5ce-936bbfbc83d6]
keycloak_openid_group_membership_protocol_mapper.forgejo_groups: Refreshing state... [id=72c7154f-372d-4a39-97c0-6516a88d6198]
vault_kv_secret_v2.forgejo_oidc: Refreshing state... [id=secret/data/infra/forgejo-oidc]
data.cloudflare_zones.all: Read complete after 1s
cloudflare_dns_record.this["git"]: Refreshing state... [id=f0fa6f4acf6bf381474c1a9304225f68]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
  • ▶️ To apply this plan, comment:
    atlantis apply -p forgejo
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p forgejo
    

No changes. Your infrastructure matches the configuration.


4. project: ricochet dir: . workspace: ricochet

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding latest version of mrparkers/keycloak...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing mrparkers/keycloak v5.8.0 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed mrparkers/keycloak v5.8.0 (unauthenticated)
- Using mrparkers/keycloak v5.8.0 from the shared cache directory
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - mrparkers/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
data.cloudflare_zones.all: Reading...
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
data.cloudflare_zones.all: Read complete after 1s
cloudflare_dns_record.this["oauth"]: Refreshing state... [id=346fac8950e4873a27d5cfb72104783d]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
  • ▶️ To apply this plan, comment:
    atlantis apply -p ricochet
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p ricochet
    

No changes. Your infrastructure matches the configuration.


5. project: garage-webadmin dir: . workspace: garage-webadmin

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
data.cloudflare_zones.all: Reading...
random_password.garage_webadmin_jwt: Refreshing state... [id=none]
vault_kv_secret_v2.garage_webadmin_jwt: Refreshing state... [id=secret/data/infra/garage-webadmin-jwt]
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
keycloak_openid_client.garage_webadmin: Refreshing state... [id=a48c9f66-cde3-463d-970c-b2d7de716185]
keycloak_openid_group_membership_protocol_mapper.garage_webadmin_groups: Refreshing state... [id=a86e928b-6c7a-4081-a291-637e752fbabf]
vault_kv_secret_v2.garage_webadmin_oidc: Refreshing state... [id=secret/data/infra/garage-webadmin-oidc]
data.cloudflare_zones.all: Read complete after 1s
cloudflare_dns_record.this["garage"]: Refreshing state... [id=4054146ceff1515773704f89136b25f1]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
  • ▶️ To apply this plan, comment:
    atlantis apply -p garage-webadmin
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p garage-webadmin
    

No changes. Your infrastructure matches the configuration.


6. project: keycloak dir: . workspace: keycloak

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
data.vault_kv_secret_v2.forgejo_idp: Reading...
data.vault_kv_secret_v2.keycloak_idp: Reading...
data.vault_kv_secret_v2.keycloak_idp: Read complete after 0s [id=secret/data/infra/keycloak-idp]
data.vault_kv_secret_v2.forgejo_idp: Read complete after 0s [id=secret/data/infra/forgejo-idp]
data.cloudflare_zones.all: Reading...
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
keycloak_oidc_identity_provider.slack: Refreshing state... [id=slack]
keycloak_custom_identity_provider_mapper.github_name: Refreshing state... [id=0d38db58-87ca-46f4-82e5-23cba653dc12]
keycloak_oidc_identity_provider.codeberg: Refreshing state... [id=codeberg]
keycloak_custom_identity_provider_mapper.github_id: Refreshing state... [id=e7462d44-1d0b-49e6-ae64-fb88031492c4]
keycloak_custom_identity_provider_mapper.github_username: Refreshing state... [id=c07573c3-8e48-4084-89cb-3a628e5cdae2]
keycloak_oidc_identity_provider.cmu_git: Refreshing state... [id=cmu-dev]
keycloak_custom_identity_provider_mapper.github_email: Refreshing state... [id=9cdd2173-27de-46ae-bff3-66ee03797ab1]
keycloak_oidc_google_identity_provider.google: Refreshing state... [id=google]
keycloak_custom_identity_provider_mapper.slack_id: Refreshing state... [id=7d6f3768-e0a7-41c2-b252-95d2709c65b7]
keycloak_custom_identity_provider_mapper.slack_email: Refreshing state... [id=ea769c6c-b497-49ec-9a4d-8ba28005e62d]
keycloak_custom_identity_provider_mapper.slack_name: Refreshing state... [id=2e4d5410-12d5-46b3-b3d4-7f5b17ee0556]
keycloak_custom_identity_provider_mapper.cmudev_id: Refreshing state... [id=5944bfd3-9704-482e-ac25-c41a40351cd7]
keycloak_custom_identity_provider_mapper.cmudev_email: Refreshing state... [id=2763e7d7-f102-479e-a560-41704bcf5e4b]
keycloak_custom_identity_provider_mapper.cmudev_username: Refreshing state... [id=8f04fb48-8434-43d6-accd-5b3a1e48e9b2]
keycloak_custom_identity_provider_mapper.cmudev_name: Refreshing state... [id=17703dd7-f88f-4d6b-88f0-e7561e796c8f]
keycloak_custom_identity_provider_mapper.codeberg_email: Refreshing state... [id=2bce1987-97ce-4ee5-adda-0e435c2b49ef]
keycloak_custom_identity_provider_mapper.codeberg_name: Refreshing state... [id=8aa1c7b9-97d8-489f-a2dc-6e427c98fdb5]
keycloak_custom_identity_provider_mapper.google_id: Refreshing state... [id=eda09ecd-d9ce-4ab0-a585-8f7d45dff7de]
keycloak_custom_identity_provider_mapper.google_name: Refreshing state... [id=9d5c678f-df91-493d-a575-be1ce56a34e0]
keycloak_custom_identity_provider_mapper.codeberg_username: Refreshing state... [id=e64e5c0b-d189-414d-b3bd-762d46d30a93]
keycloak_custom_identity_provider_mapper.google_email: Refreshing state... [id=ab2117f2-dcbf-4409-a7b7-c7354317e6cc]
keycloak_custom_identity_provider_mapper.codeberg_id: Refreshing state... [id=850eadbb-9508-4fac-9d43-d0f5cee2fc59]
keycloak_realm_user_profile.scottylabs: Refreshing state... [id=scottylabs]
data.cloudflare_zones.all: Read complete after 2s
cloudflare_dns_record.this["idp"]: Refreshing state... [id=76512b10636c34a8230d5618d365d6bc]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
╷
│ Warning: Deprecated Resource
│ 
│   with data.vault_kv_secret_v2.forgejo_idp,
│   on config.tf.json line 15, in data.vault_kv_secret_v2.forgejo_idp:
│   15:       },
│ 
│ Deprecated. Please use new Ephemeral KVV2 Secret resource
│ `vault_kv_secret_v2` instead
│ 
│ (and 3 more similar warnings elsewhere)
╵
╷
│ Warning: Value derived from a deprecated source
│ 
│   with keycloak_oidc_google_identity_provider.google,
│   on config.tf.json line 274, in resource.keycloak_oidc_google_identity_provider.google:
│  274:       }
│ 
│ This value is derived from data.vault_kv_secret_v2.keycloak_idp, which is
│ deprecated with the following message:
│ 
│ Deprecated. Please use new Ephemeral KVV2 Secret resource
│ `vault_kv_secret_v2` instead
│ 
│ (and one more similar warning elsewhere)
╵
  • ▶️ To apply this plan, comment:
    atlantis apply -p keycloak
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p keycloak
    

No changes. Your infrastructure matches the configuration.


7. project: governance dir: . workspace: governance

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
vault_policy.governance: Refreshing state... [id=governance]
vault_approle_auth_backend_role.governance: Refreshing state... [id=auth/approle/role/governance]
data.cloudflare_zones.all: Reading...
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
keycloak_openid_client.governance_cli: Refreshing state... [id=f19d0308-19a8-4fc4-aa5f-f909fc38c5fe]
data.keycloak_openid_client.realm_management: Reading...
data.keycloak_openid_client.realm_management: Read complete after 0s [id=a0a15f13-b554-4bed-9fb2-3e63e0301278]
keycloak_openid_client_service_account_role.governance_cli_realm_management["manage-clients"]: Refreshing state... [id=90ac5826-08a5-4d89-8855-3d7b249de131/366f6242-2ce3-4be8-b861-3561e3c4b865]
keycloak_openid_client_service_account_role.governance_cli_realm_management["manage-users"]: Refreshing state... [id=90ac5826-08a5-4d89-8855-3d7b249de131/eb96eb71-82eb-4317-b8f5-326472e11484]
keycloak_openid_client_service_account_role.governance_cli_realm_management["query-clients"]: Refreshing state... [id=90ac5826-08a5-4d89-8855-3d7b249de131/16d40468-7ba1-4f17-ba0d-0741880f291a]
keycloak_openid_client_service_account_role.governance_cli_realm_management["view-users"]: Refreshing state... [id=90ac5826-08a5-4d89-8855-3d7b249de131/65f4c673-fc55-430c-b4b6-fd14ed151966]
data.cloudflare_zones.all: Read complete after 1s

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
  • ▶️ To apply this plan, comment:
    atlantis apply -p governance
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p governance
    

No changes. Your infrastructure matches the configuration.


8. project: headscale dir: . workspace: headscale

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
random_password.headplane_cookie: Refreshing state... [id=none]
vault_kv_secret_v2.headplane_cookie: Refreshing state... [id=secret/data/infra/headplane-cookie]
data.cloudflare_zones.all: Reading...
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
keycloak_openid_client.headscale: Refreshing state... [id=f2875c14-dfff-4fd4-b60b-4d1e066aaeb8]
keycloak_openid_client.headplane: Refreshing state... [id=40d2dbf9-409b-4edc-974c-85d5e939efac]
keycloak_openid_group_membership_protocol_mapper.headplane_groups: Refreshing state... [id=fd683ca7-ed77-44f1-b3cc-47241ccb6fb7]
vault_kv_secret_v2.headplane_oidc: Refreshing state... [id=secret/data/infra/headplane-oidc]
vault_kv_secret_v2.headscale_oidc: Refreshing state... [id=secret/data/infra/headscale-oidc]
keycloak_openid_group_membership_protocol_mapper.headscale_groups: Refreshing state... [id=f091397a-9b6e-4887-9913-12fb542d7210]
data.cloudflare_zones.all: Read complete after 1s
cloudflare_dns_record.this["headscale"]: Refreshing state... [id=4207dabef0c8dc1972f9d5aa1cd17a00]
cloudflare_dns_record.this["headplane"]: Refreshing state... [id=9139cfa1f058db85d837defe0460fd20]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
  • ▶️ To apply this plan, comment:
    atlantis apply -p headscale
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p headscale
    

No changes. Your infrastructure matches the configuration.


9. project: matrix dir: . workspace: matrix

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding latest version of mrparkers/keycloak...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installing mrparkers/keycloak v5.8.0 to the shared cache directory...
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed mrparkers/keycloak v5.8.0 (unauthenticated)
- Using mrparkers/keycloak v5.8.0 from the shared cache directory
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - mrparkers/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
data.cloudflare_zones.all: Reading...
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
data.cloudflare_zones.all: Read complete after 2s
cloudflare_dns_record.this["@"]: Refreshing state... [id=63ff3b423afd444f8bd31201db232ada]
cloudflare_dns_record.this["matrix"]: Refreshing state... [id=c37d2e1a4edf950b4af4544574c159a8]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
  • ▶️ To apply this plan, comment:
    atlantis apply -p matrix
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p matrix
    

No changes. Your infrastructure matches the configuration.


10. project: atlantis dir: . workspace: atlantis

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding latest version of mrparkers/keycloak...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installing mrparkers/keycloak v5.8.0 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed mrparkers/keycloak v5.8.0 (unauthenticated)
- Using mrparkers/keycloak v5.8.0 from the shared cache directory
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - mrparkers/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
data.cloudflare_zones.all: Reading...
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
data.cloudflare_zones.all: Read complete after 2s
cloudflare_dns_record.this["atlantis"]: Refreshing state... [id=d0419d10a0c0bb715bcbadc7a1c73cbb]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.
  • ▶️ To apply this plan, comment:
    atlantis apply -p atlantis
    
  • 🚮 To delete this plan and lock, click here
  • 🔁 To plan this project again, comment:
    atlantis plan -p atlantis
    

No changes. Your infrastructure matches the configuration.


11. project: observability dir: . workspace: observability

Show Output
warning: ignoring untrusted flake configuration setting 'extra-substituters'.
Pass '--accept-flake-config' to trust it
warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'.
Pass '--accept-flake-config' to trust it
error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy


Initializing the backend...

Successfully configured the backend "s3"! OpenTofu will automatically
use this backend unless the backend configuration changes.

Initializing provider plugins...
- Finding keycloak/keycloak versions matching "~> 5.0"...
- Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"...
- Finding cloudflare/cloudflare versions matching "~> 5.0"...
- Finding hashicorp/random versions matching "~> 3.0"...
- Finding hashicorp/vault versions matching "~> 5.0"...
- Installing hashicorp/random v3.9.0 to the shared cache directory...
- Installing cloudflare/cloudflare v5.22.0 to the shared cache directory...
- Installing keycloak/keycloak v5.8.0 to the shared cache directory...
- Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory...
- Installing hashicorp/vault v5.10.1 to the shared cache directory...
- Installed hashicorp/random v3.9.0 (unauthenticated)
- Using hashicorp/random v3.9.0 from the shared cache directory
- Installed keycloak/keycloak v5.8.0 (unauthenticated)
- Using keycloak/keycloak v5.8.0 from the shared cache directory
- Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated)
- Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory
- Installed hashicorp/vault v5.10.1 (unauthenticated)
- Using hashicorp/vault v5.10.1 from the shared cache directory
- Installed cloudflare/cloudflare v5.22.0 (unauthenticated)
- Using cloudflare/cloudflare v5.22.0 from the shared cache directory

OpenTofu has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that OpenTofu can guarantee to make the same selections by default when
you run "tofu init" in the future.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ Skip tofu init when using provider development overrides. It is not
│ necessary and may error unexpectedly.
╵

╷
│ Warning: Incomplete lock file information for providers
│ 
│ Due to your customized provider installation methods, OpenTofu was forced
│ to calculate lock file checksums locally for the following providers:
│   - cloudflare/cloudflare
│   - hashicorp/random
│   - hashicorp/vault
│   - keycloak/keycloak
│   - registry.terraform.io/jkossis/garage
│ 
│ The current .terraform.lock.hcl file only includes checksums for
│ linux_amd64, so OpenTofu running on another platform will fail to install
│ these providers.
│ 
│ To calculate additional checksums for another platform, run:
│   tofu providers lock -platform=linux_amd64
│ (where linux_amd64 is the platform to generate)
╵

OpenTofu has been successfully initialized!

You may now begin working with OpenTofu. Try running "tofu plan" to see
any changes that are required for your infrastructure. All OpenTofu commands
should now work.

If you ever set or change modules or backend configuration for OpenTofu,
rerun this command to reinitialize your working directory. If you forget, other
commands will detect it and remind you to do so if necessary.

╷
│ Warning: Provider development overrides are in effect
│ 
│ The following provider development overrides are set in the CLI
│ configuration:
│  - svalabs/forgejo in /tmp/forgejo-provider
│ 
│ The behavior may therefore not match any released version of the provider
│ and applying changes may cause the state to become incompatible with
│ published releases.
╵
random_password.grafana_secret_key: Refreshing state... [id=none]
vault_kv_secret_v2.grafana_secret_key: Refreshing state... [id=secret/data/infra/grafana-secret-key]
data.cloudflare_zones.all: Reading...
garage_key.loki: Refreshing state... [id=GKeed8ed294debe12a38bbd470]
garage_bucket.loki_chunks: Refreshing state... [id=f6c7e9f9881b09dc6bb9e3bce85f425fc97c526343f5b819086ac692339425c3]
garage_key.tempo: Refreshing state... [id=GK9769dcb3b38a1ae26ac62b3c]
garage_bucket.tempo_traces: Refreshing state... [id=d0776d1c829f4fe5cf4e6317d02057fbecc7cf8c39a28f7be5391bba0aaf632c]
garage_bucket_permission.tempo: Refreshing state... [id=d0776d1c829f4fe5cf4e6317d02057fbecc7cf8c39a28f7be5391bba0aaf632c/GK9769dcb3b38a1ae26ac62b3c]
vault_kv_secret_v2.tempo_s3: Refreshing state... [id=secret/data/infra/tempo-s3]
vault_kv_secret_v2.loki_s3: Refreshing state... [id=secret/data/infra/loki-s3]
garage_bucket_permission.loki: Refreshing state... [id=f6c7e9f9881b09dc6bb9e3bce85f425fc97c526343f5b819086ac692339425c3/GKeed8ed294debe12a38bbd470]
data.keycloak_realm.scottylabs: Reading...
data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs]
keycloak_openid_client.grafana: Refreshing state... [id=527e25bc-77c3-43d5-ac28-32aa2f21fa9c]
keycloak_openid_group_membership_prot
Ran Plan for 16 projects: 1. project: `posthog` dir: `.` workspace: `posthog` 1. project: `vaultwarden` dir: `.` workspace: `vaultwarden` 1. project: `forgejo` dir: `.` workspace: `forgejo` 1. project: `ricochet` dir: `.` workspace: `ricochet` 1. project: `garage-webadmin` dir: `.` workspace: `garage-webadmin` 1. project: `keycloak` dir: `.` workspace: `keycloak` 1. project: `governance` dir: `.` workspace: `governance` 1. project: `headscale` dir: `.` workspace: `headscale` 1. project: `matrix` dir: `.` workspace: `matrix` 1. project: `atlantis` dir: `.` workspace: `atlantis` 1. project: `observability` dir: `.` workspace: `observability` 1. project: `kennel` dir: `.` workspace: `kennel` 1. project: `openbao` dir: `.` workspace: `openbao` 1. project: `hosts` dir: `.` workspace: `hosts` 1. project: `litellm` dir: `.` workspace: `litellm` 1. project: `webhook` dir: `.` workspace: `webhook` --- ### 1. project: `posthog` dir: `.` workspace: `posthog` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding latest version of mrparkers/keycloak... - Finding hashicorp/random versions matching "~> 3.0"... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding keycloak/keycloak versions matching "~> 5.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installing mrparkers/keycloak v5.8.0 to the shared cache directory... - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed mrparkers/keycloak v5.8.0 (unauthenticated) - Using mrparkers/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - mrparkers/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] data.cloudflare_zones.all: Reading... data.cloudflare_zones.all: Read complete after 1s cloudflare_dns_record.this["v"]: Refreshing state... [id=a34d75a85d3128693767b2db9b7f233e] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p posthog ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fposthog%252Fposthog) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p posthog ``` No changes. Your infrastructure matches the configuration. --- ### 2. project: `vaultwarden` dir: `.` workspace: `vaultwarden` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding latest version of mrparkers/keycloak... - Finding hashicorp/random versions matching "~> 3.0"... - Finding keycloak/keycloak versions matching "~> 5.0"... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing mrparkers/keycloak v5.8.0 to the shared cache directory... - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed mrparkers/keycloak v5.8.0 (unauthenticated) - Using mrparkers/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - mrparkers/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] data.cloudflare_zones.all: Reading... data.cloudflare_zones.all: Read complete after 1s cloudflare_dns_record.this["vault"]: Refreshing state... [id=7828e0eeb9e7f251c797f565828a47f6] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p vaultwarden ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fvaultwarden%252Fvaultwarden) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p vaultwarden ``` No changes. Your infrastructure matches the configuration. --- ### 3. project: `forgejo` dir: `.` workspace: `forgejo` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding hashicorp/random versions matching "~> 3.0"... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding keycloak/keycloak versions matching "~> 5.0"... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ data.cloudflare_zones.all: Reading... garage_key.forgejo: Refreshing state... [id=GKea9810d648000e3e3b8df725] garage_bucket.forgejo: Refreshing state... [id=65e2f6d77ab1d627c920b8e6bd764551f5f8b0334fd1f67bc47c5f5c30546960] vault_kv_secret_v2.forgejo_storage: Refreshing state... [id=secret/data/infra/forgejo-storage] garage_bucket_permission.forgejo: Refreshing state... [id=65e2f6d77ab1d627c920b8e6bd764551f5f8b0334fd1f67bc47c5f5c30546960/GKea9810d648000e3e3b8df725] data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] keycloak_openid_client.forgejo: Refreshing state... [id=110b9b02-18e1-4bac-b5ce-936bbfbc83d6] keycloak_openid_group_membership_protocol_mapper.forgejo_groups: Refreshing state... [id=72c7154f-372d-4a39-97c0-6516a88d6198] vault_kv_secret_v2.forgejo_oidc: Refreshing state... [id=secret/data/infra/forgejo-oidc] data.cloudflare_zones.all: Read complete after 1s cloudflare_dns_record.this["git"]: Refreshing state... [id=f0fa6f4acf6bf381474c1a9304225f68] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p forgejo ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fforgejo%252Fforgejo) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p forgejo ``` No changes. Your infrastructure matches the configuration. --- ### 4. project: `ricochet` dir: `.` workspace: `ricochet` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding latest version of mrparkers/keycloak... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding keycloak/keycloak versions matching "~> 5.0"... - Finding hashicorp/random versions matching "~> 3.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing mrparkers/keycloak v5.8.0 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed mrparkers/keycloak v5.8.0 (unauthenticated) - Using mrparkers/keycloak v5.8.0 from the shared cache directory - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - mrparkers/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ data.cloudflare_zones.all: Reading... data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] data.cloudflare_zones.all: Read complete after 1s cloudflare_dns_record.this["oauth"]: Refreshing state... [id=346fac8950e4873a27d5cfb72104783d] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p ricochet ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fricochet%252Fricochet) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p ricochet ``` No changes. Your infrastructure matches the configuration. --- ### 5. project: `garage-webadmin` dir: `.` workspace: `garage-webadmin` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding keycloak/keycloak versions matching "~> 5.0"... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding hashicorp/random versions matching "~> 3.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ data.cloudflare_zones.all: Reading... random_password.garage_webadmin_jwt: Refreshing state... [id=none] vault_kv_secret_v2.garage_webadmin_jwt: Refreshing state... [id=secret/data/infra/garage-webadmin-jwt] data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] keycloak_openid_client.garage_webadmin: Refreshing state... [id=a48c9f66-cde3-463d-970c-b2d7de716185] keycloak_openid_group_membership_protocol_mapper.garage_webadmin_groups: Refreshing state... [id=a86e928b-6c7a-4081-a291-637e752fbabf] vault_kv_secret_v2.garage_webadmin_oidc: Refreshing state... [id=secret/data/infra/garage-webadmin-oidc] data.cloudflare_zones.all: Read complete after 1s cloudflare_dns_record.this["garage"]: Refreshing state... [id=4054146ceff1515773704f89136b25f1] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p garage-webadmin ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fgarage-webadmin%252Fgarage-webadmin) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p garage-webadmin ``` No changes. Your infrastructure matches the configuration. --- ### 6. project: `keycloak` dir: `.` workspace: `keycloak` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding hashicorp/random versions matching "~> 3.0"... - Finding keycloak/keycloak versions matching "~> 5.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ data.vault_kv_secret_v2.forgejo_idp: Reading... data.vault_kv_secret_v2.keycloak_idp: Reading... data.vault_kv_secret_v2.keycloak_idp: Read complete after 0s [id=secret/data/infra/keycloak-idp] data.vault_kv_secret_v2.forgejo_idp: Read complete after 0s [id=secret/data/infra/forgejo-idp] data.cloudflare_zones.all: Reading... data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] keycloak_oidc_identity_provider.slack: Refreshing state... [id=slack] keycloak_custom_identity_provider_mapper.github_name: Refreshing state... [id=0d38db58-87ca-46f4-82e5-23cba653dc12] keycloak_oidc_identity_provider.codeberg: Refreshing state... [id=codeberg] keycloak_custom_identity_provider_mapper.github_id: Refreshing state... [id=e7462d44-1d0b-49e6-ae64-fb88031492c4] keycloak_custom_identity_provider_mapper.github_username: Refreshing state... [id=c07573c3-8e48-4084-89cb-3a628e5cdae2] keycloak_oidc_identity_provider.cmu_git: Refreshing state... [id=cmu-dev] keycloak_custom_identity_provider_mapper.github_email: Refreshing state... [id=9cdd2173-27de-46ae-bff3-66ee03797ab1] keycloak_oidc_google_identity_provider.google: Refreshing state... [id=google] keycloak_custom_identity_provider_mapper.slack_id: Refreshing state... [id=7d6f3768-e0a7-41c2-b252-95d2709c65b7] keycloak_custom_identity_provider_mapper.slack_email: Refreshing state... [id=ea769c6c-b497-49ec-9a4d-8ba28005e62d] keycloak_custom_identity_provider_mapper.slack_name: Refreshing state... [id=2e4d5410-12d5-46b3-b3d4-7f5b17ee0556] keycloak_custom_identity_provider_mapper.cmudev_id: Refreshing state... [id=5944bfd3-9704-482e-ac25-c41a40351cd7] keycloak_custom_identity_provider_mapper.cmudev_email: Refreshing state... [id=2763e7d7-f102-479e-a560-41704bcf5e4b] keycloak_custom_identity_provider_mapper.cmudev_username: Refreshing state... [id=8f04fb48-8434-43d6-accd-5b3a1e48e9b2] keycloak_custom_identity_provider_mapper.cmudev_name: Refreshing state... [id=17703dd7-f88f-4d6b-88f0-e7561e796c8f] keycloak_custom_identity_provider_mapper.codeberg_email: Refreshing state... [id=2bce1987-97ce-4ee5-adda-0e435c2b49ef] keycloak_custom_identity_provider_mapper.codeberg_name: Refreshing state... [id=8aa1c7b9-97d8-489f-a2dc-6e427c98fdb5] keycloak_custom_identity_provider_mapper.google_id: Refreshing state... [id=eda09ecd-d9ce-4ab0-a585-8f7d45dff7de] keycloak_custom_identity_provider_mapper.google_name: Refreshing state... [id=9d5c678f-df91-493d-a575-be1ce56a34e0] keycloak_custom_identity_provider_mapper.codeberg_username: Refreshing state... [id=e64e5c0b-d189-414d-b3bd-762d46d30a93] keycloak_custom_identity_provider_mapper.google_email: Refreshing state... [id=ab2117f2-dcbf-4409-a7b7-c7354317e6cc] keycloak_custom_identity_provider_mapper.codeberg_id: Refreshing state... [id=850eadbb-9508-4fac-9d43-d0f5cee2fc59] keycloak_realm_user_profile.scottylabs: Refreshing state... [id=scottylabs] data.cloudflare_zones.all: Read complete after 2s cloudflare_dns_record.this["idp"]: Refreshing state... [id=76512b10636c34a8230d5618d365d6bc] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ╷ │ Warning: Deprecated Resource │ │ with data.vault_kv_secret_v2.forgejo_idp, │ on config.tf.json line 15, in data.vault_kv_secret_v2.forgejo_idp: │ 15: }, │ │ Deprecated. Please use new Ephemeral KVV2 Secret resource │ `vault_kv_secret_v2` instead │ │ (and 3 more similar warnings elsewhere) ╵ ╷ │ Warning: Value derived from a deprecated source │ │ with keycloak_oidc_google_identity_provider.google, │ on config.tf.json line 274, in resource.keycloak_oidc_google_identity_provider.google: │ 274: } │ │ This value is derived from data.vault_kv_secret_v2.keycloak_idp, which is │ deprecated with the following message: │ │ Deprecated. Please use new Ephemeral KVV2 Secret resource │ `vault_kv_secret_v2` instead │ │ (and one more similar warning elsewhere) ╵ ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p keycloak ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fkeycloak%252Fkeycloak) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p keycloak ``` No changes. Your infrastructure matches the configuration. --- ### 7. project: `governance` dir: `.` workspace: `governance` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding hashicorp/random versions matching "~> 3.0"... - Finding keycloak/keycloak versions matching "~> 5.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ vault_policy.governance: Refreshing state... [id=governance] vault_approle_auth_backend_role.governance: Refreshing state... [id=auth/approle/role/governance] data.cloudflare_zones.all: Reading... data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] keycloak_openid_client.governance_cli: Refreshing state... [id=f19d0308-19a8-4fc4-aa5f-f909fc38c5fe] data.keycloak_openid_client.realm_management: Reading... data.keycloak_openid_client.realm_management: Read complete after 0s [id=a0a15f13-b554-4bed-9fb2-3e63e0301278] keycloak_openid_client_service_account_role.governance_cli_realm_management["manage-clients"]: Refreshing state... [id=90ac5826-08a5-4d89-8855-3d7b249de131/366f6242-2ce3-4be8-b861-3561e3c4b865] keycloak_openid_client_service_account_role.governance_cli_realm_management["manage-users"]: Refreshing state... [id=90ac5826-08a5-4d89-8855-3d7b249de131/eb96eb71-82eb-4317-b8f5-326472e11484] keycloak_openid_client_service_account_role.governance_cli_realm_management["query-clients"]: Refreshing state... [id=90ac5826-08a5-4d89-8855-3d7b249de131/16d40468-7ba1-4f17-ba0d-0741880f291a] keycloak_openid_client_service_account_role.governance_cli_realm_management["view-users"]: Refreshing state... [id=90ac5826-08a5-4d89-8855-3d7b249de131/65f4c673-fc55-430c-b4b6-fd14ed151966] data.cloudflare_zones.all: Read complete after 1s No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p governance ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fgovernance%252Fgovernance) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p governance ``` No changes. Your infrastructure matches the configuration. --- ### 8. project: `headscale` dir: `.` workspace: `headscale` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding hashicorp/random versions matching "~> 3.0"... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding keycloak/keycloak versions matching "~> 5.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ random_password.headplane_cookie: Refreshing state... [id=none] vault_kv_secret_v2.headplane_cookie: Refreshing state... [id=secret/data/infra/headplane-cookie] data.cloudflare_zones.all: Reading... data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] keycloak_openid_client.headscale: Refreshing state... [id=f2875c14-dfff-4fd4-b60b-4d1e066aaeb8] keycloak_openid_client.headplane: Refreshing state... [id=40d2dbf9-409b-4edc-974c-85d5e939efac] keycloak_openid_group_membership_protocol_mapper.headplane_groups: Refreshing state... [id=fd683ca7-ed77-44f1-b3cc-47241ccb6fb7] vault_kv_secret_v2.headplane_oidc: Refreshing state... [id=secret/data/infra/headplane-oidc] vault_kv_secret_v2.headscale_oidc: Refreshing state... [id=secret/data/infra/headscale-oidc] keycloak_openid_group_membership_protocol_mapper.headscale_groups: Refreshing state... [id=f091397a-9b6e-4887-9913-12fb542d7210] data.cloudflare_zones.all: Read complete after 1s cloudflare_dns_record.this["headscale"]: Refreshing state... [id=4207dabef0c8dc1972f9d5aa1cd17a00] cloudflare_dns_record.this["headplane"]: Refreshing state... [id=9139cfa1f058db85d837defe0460fd20] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p headscale ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fheadscale%252Fheadscale) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p headscale ``` No changes. Your infrastructure matches the configuration. --- ### 9. project: `matrix` dir: `.` workspace: `matrix` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding hashicorp/random versions matching "~> 3.0"... - Finding latest version of mrparkers/keycloak... - Finding hashicorp/vault versions matching "~> 5.0"... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding keycloak/keycloak versions matching "~> 5.0"... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installing mrparkers/keycloak v5.8.0 to the shared cache directory... - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed mrparkers/keycloak v5.8.0 (unauthenticated) - Using mrparkers/keycloak v5.8.0 from the shared cache directory - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - mrparkers/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ data.cloudflare_zones.all: Reading... data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] data.cloudflare_zones.all: Read complete after 2s cloudflare_dns_record.this["@"]: Refreshing state... [id=63ff3b423afd444f8bd31201db232ada] cloudflare_dns_record.this["matrix"]: Refreshing state... [id=c37d2e1a4edf950b4af4544574c159a8] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p matrix ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fmatrix%252Fmatrix) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p matrix ``` No changes. Your infrastructure matches the configuration. --- ### 10. project: `atlantis` dir: `.` workspace: `atlantis` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding hashicorp/random versions matching "~> 3.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding latest version of mrparkers/keycloak... - Finding keycloak/keycloak versions matching "~> 5.0"... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installing mrparkers/keycloak v5.8.0 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed mrparkers/keycloak v5.8.0 (unauthenticated) - Using mrparkers/keycloak v5.8.0 from the shared cache directory - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - mrparkers/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ data.cloudflare_zones.all: Reading... data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] data.cloudflare_zones.all: Read complete after 2s cloudflare_dns_record.this["atlantis"]: Refreshing state... [id=d0419d10a0c0bb715bcbadc7a1c73cbb] No changes. Your infrastructure matches the configuration. OpenTofu has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` </details> * :arrow_forward: To **apply** this plan, comment: ```shell atlantis apply -p atlantis ``` * :put_litter_in_its_place: To **delete** this plan and lock, click [here](https://atlantis.scottylabs.org/lock?id=ScottyLabs%252Finfrastructure%252F.%252Fatlantis%252Fatlantis) * :repeat: To **plan** this project again, comment: ```shell atlantis plan -p atlantis ``` No changes. Your infrastructure matches the configuration. --- ### 11. project: `observability` dir: `.` workspace: `observability` <details><summary>Show Output</summary> ```diff warning: ignoring untrusted flake configuration setting 'extra-substituters'. Pass '--accept-flake-config' to trust it warning: ignoring untrusted flake configuration setting 'extra-trusted-public-keys'. Pass '--accept-flake-config' to trust it error (ignored): SQLite database '/var/lib/atlantis/.cache/nix/eval-cache-v6/527213ef58e5659b640e1822be12ac20d3f59373f319c34d48e78aa9df13c887.sqlite' is busy Initializing the backend... Successfully configured the backend "s3"! OpenTofu will automatically use this backend unless the backend configuration changes. Initializing provider plugins... - Finding keycloak/keycloak versions matching "~> 5.0"... - Finding registry.terraform.io/jkossis/garage versions matching "~> 1.0"... - Finding cloudflare/cloudflare versions matching "~> 5.0"... - Finding hashicorp/random versions matching "~> 3.0"... - Finding hashicorp/vault versions matching "~> 5.0"... - Installing hashicorp/random v3.9.0 to the shared cache directory... - Installing cloudflare/cloudflare v5.22.0 to the shared cache directory... - Installing keycloak/keycloak v5.8.0 to the shared cache directory... - Installing registry.terraform.io/jkossis/garage v1.0.5 to the shared cache directory... - Installing hashicorp/vault v5.10.1 to the shared cache directory... - Installed hashicorp/random v3.9.0 (unauthenticated) - Using hashicorp/random v3.9.0 from the shared cache directory - Installed keycloak/keycloak v5.8.0 (unauthenticated) - Using keycloak/keycloak v5.8.0 from the shared cache directory - Installed registry.terraform.io/jkossis/garage v1.0.5 (unauthenticated) - Using registry.terraform.io/jkossis/garage v1.0.5 from the shared cache directory - Installed hashicorp/vault v5.10.1 (unauthenticated) - Using hashicorp/vault v5.10.1 from the shared cache directory - Installed cloudflare/cloudflare v5.22.0 (unauthenticated) - Using cloudflare/cloudflare v5.22.0 from the shared cache directory OpenTofu has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that OpenTofu can guarantee to make the same selections by default when you run "tofu init" in the future. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ Skip tofu init when using provider development overrides. It is not │ necessary and may error unexpectedly. ╵ ╷ │ Warning: Incomplete lock file information for providers │ │ Due to your customized provider installation methods, OpenTofu was forced │ to calculate lock file checksums locally for the following providers: │ - cloudflare/cloudflare │ - hashicorp/random │ - hashicorp/vault │ - keycloak/keycloak │ - registry.terraform.io/jkossis/garage │ │ The current .terraform.lock.hcl file only includes checksums for │ linux_amd64, so OpenTofu running on another platform will fail to install │ these providers. │ │ To calculate additional checksums for another platform, run: │ tofu providers lock -platform=linux_amd64 │ (where linux_amd64 is the platform to generate) ╵ OpenTofu has been successfully initialized! You may now begin working with OpenTofu. Try running "tofu plan" to see any changes that are required for your infrastructure. All OpenTofu commands should now work. If you ever set or change modules or backend configuration for OpenTofu, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ╷ │ Warning: Provider development overrides are in effect │ │ The following provider development overrides are set in the CLI │ configuration: │ - svalabs/forgejo in /tmp/forgejo-provider │ │ The behavior may therefore not match any released version of the provider │ and applying changes may cause the state to become incompatible with │ published releases. ╵ random_password.grafana_secret_key: Refreshing state... [id=none] vault_kv_secret_v2.grafana_secret_key: Refreshing state... [id=secret/data/infra/grafana-secret-key] data.cloudflare_zones.all: Reading... garage_key.loki: Refreshing state... [id=GKeed8ed294debe12a38bbd470] garage_bucket.loki_chunks: Refreshing state... [id=f6c7e9f9881b09dc6bb9e3bce85f425fc97c526343f5b819086ac692339425c3] garage_key.tempo: Refreshing state... [id=GK9769dcb3b38a1ae26ac62b3c] garage_bucket.tempo_traces: Refreshing state... [id=d0776d1c829f4fe5cf4e6317d02057fbecc7cf8c39a28f7be5391bba0aaf632c] garage_bucket_permission.tempo: Refreshing state... [id=d0776d1c829f4fe5cf4e6317d02057fbecc7cf8c39a28f7be5391bba0aaf632c/GK9769dcb3b38a1ae26ac62b3c] vault_kv_secret_v2.tempo_s3: Refreshing state... [id=secret/data/infra/tempo-s3] vault_kv_secret_v2.loki_s3: Refreshing state... [id=secret/data/infra/loki-s3] garage_bucket_permission.loki: Refreshing state... [id=f6c7e9f9881b09dc6bb9e3bce85f425fc97c526343f5b819086ac692339425c3/GKeed8ed294debe12a38bbd470] data.keycloak_realm.scottylabs: Reading... data.keycloak_realm.scottylabs: Read complete after 0s [id=scottylabs] keycloak_openid_client.grafana: Refreshing state... [id=527e25bc-77c3-43d5-ac28-32aa2f21fa9c] keycloak_openid_group_membership_prot
anish commented 2026-07-27 06:17:04 +00:00 (Migrated from codeberg.org)

atlantis unlock

atlantis unlock
scottylabs-bot commented 2026-07-27 06:17:15 +00:00 (Migrated from codeberg.org)

All Atlantis locks for this PR have been unlocked and plans discarded

All Atlantis locks for this PR have been unlocked and plans discarded
This pull request has changes conflicting with the target branch.
  • modules/hosts/infra-01/openbao.nix
  • secrets.nix
View command line instructions

Manual merge helper

Use this merge commit message when completing the merge manually.

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin openbao-auto-unseal:openbao-auto-unseal
git switch openbao-auto-unseal

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff openbao-auto-unseal
git switch openbao-auto-unseal
git rebase main
git switch main
git merge --ff-only openbao-auto-unseal
git switch openbao-auto-unseal
git rebase main
git switch main
git merge --no-ff openbao-auto-unseal
git switch main
git merge --squash openbao-auto-unseal
git switch main
git merge --ff-only openbao-auto-unseal
git switch main
git merge openbao-auto-unseal
git push origin main
Sign in to join this conversation.
No description provided.