Skip to content

Add Cloudflare OpenTofu infrastructure scaffold - #17

Merged
dills122 merged 2 commits into
mainfrom
codex/infra-opentofu
Jun 9, 2026
Merged

dills122 merged 2 commits into
mainfrom
codex/infra-opentofu

Conversation

@dills122

@dills122 dills122 commented Jun 9, 2026

Copy link
Copy Markdown
Owner

Summary

  • Adds an OpenTofu/Terraform scaffold for Forage’s Cloudflare hosting infrastructure.
  • Keeps secrets, GitHub App setup, and repository data outside IaC state.

What Changed

  • Added infra/opentofu with Cloudflare provider config, variables, outputs, tfvars example, and README.
  • Manages Pages project config, Pages domains, settings KV namespaces, and optional Worker custom domains.
  • Adds outputs for GitHub App URLs, Worker env vars, Pages env vars, KV namespace IDs, and required secret names.
  • Documents the IaC split in docs/22-infrastructure-as-code.md and updates hosting docs.
  • Adds pnpm infra:fmt and pnpm infra:fmt:check.

Validation

  • pnpm check
  • pnpm infra:fmt:check
  • npm run check:docs
  • npm run check:workspace
  • npm run lint

Scope Notes

  • OpenTofu/Terraform provider init succeeded, but full provider schema validation failed locally due a Cloudflare provider plugin handshake issue on this machine.
  • Worker code deployment remains Wrangler-owned for MVP so Durable Object migrations stay aligned with apps/worker/wrangler.toml.
  • GitHub App creation and Worker secret values remain manual/operator-controlled and are intentionally not stored in IaC.

@dills122
dills122 merged commit 84bb59a into main Jun 9, 2026
1 check passed
@dills122
dills122 deleted the codex/infra-opentofu branch June 9, 2026 01:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant