From 73e82a3dbf3aa0b4100439346657591ed3f68b17 Mon Sep 17 00:00:00 2001 From: EuAndreh Date: Sat, 25 May 2019 13:12:18 -0300 Subject: Don't use pub_key and pvt_key as input variables Embed SSH keypair directly into git-crypt. --- secrets/id_rsa | Bin 0 -> 3403 bytes secrets/id_rsa.pub | Bin 0 -> 763 bytes vps.tf | 11 ++++++----- 3 files changed, 6 insertions(+), 5 deletions(-) create mode 100644 secrets/id_rsa create mode 100644 secrets/id_rsa.pub diff --git a/secrets/id_rsa b/secrets/id_rsa new file mode 100644 index 0000000..8bd910b Binary files /dev/null and b/secrets/id_rsa differ diff --git a/secrets/id_rsa.pub b/secrets/id_rsa.pub new file mode 100644 index 0000000..1301181 Binary files /dev/null and b/secrets/id_rsa.pub differ diff --git a/vps.tf b/vps.tf index 257907b..e5f0884 100644 --- a/vps.tf +++ b/vps.tf @@ -1,6 +1,4 @@ variable "do_token" {} -variable "pub_key" {} -variable "pvt_key" {} variable "ssh_fingerprint" {} provider "digitalocean" { @@ -10,9 +8,12 @@ provider "digitalocean" { resource "digitalocean_droplet" "vps" { image = "ubuntu-18-04-x64" - name = "ubuntu-vps" - region = "nyc2" + name = "sovereignty" + region = "nyc3" size = "512mb" + backups = true + ipv6 = true + monitoring = true ssh_keys = [ "${var.ssh_fingerprint}" ] @@ -20,7 +21,7 @@ resource "digitalocean_droplet" "vps" { connection { user = "root" type = "ssh" - private_key = "${file(var.pvt_key)}" + private_key = "${file("${path.module}/secrets/id_rsa")}" timeout = "2m" } -- cgit v1.2.3