Add AWS profile config and resoftware-iac OpenTofu state runbook

Track ~/.aws/config (profiles only, never credentials) as a copied
config: setup.sh restores it, update.fish refreshes it. Document the
S3 state backend setup for resoftware-iac in the README, including
the config/credentials profile-header gotcha behind "failed to get
shared config profile".

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Trevi Awater
2026-09-07 21:25:22 +02:00
parent 250baaaba1
commit 600f163cfd
4 changed files with 78 additions and 9 deletions

View File

@@ -8,7 +8,7 @@ Two kinds of files live here:
- **Symlinked** — the file in this repo *is* the live config (fish, starship, ssh, - **Symlinked** — the file in this repo *is* the live config (fish, starship, ssh,
kube, npm, NuGet). Edit either side, they're the same file. kube, npm, NuGet). Edit either side, they're the same file.
- **Copied** — files that can't be symlinked (`/etc/hosts`, Claude/Serena settings, - **Copied** — files that can't be symlinked (`/etc/hosts`, Claude/Serena settings,
the brewfile). Refresh them from the machine with `./update.fish`. the AWS config, the brewfile). Refresh them from the machine with `./update.fish`.
## Fresh machine setup — the fast way ## Fresh machine setup — the fast way
@@ -84,12 +84,16 @@ ln -sf $(pwd)/NuGet.Config ~/.nuget/NuGet/NuGet.Config
### 6. Restore the copied configs ### 6. Restore the copied configs
```bash ```bash
mkdir -p ~/.claude ~/.serena mkdir -p ~/.claude ~/.serena ~/.aws
cp claude-settings.json ~/.claude/settings.json cp claude-settings.json ~/.claude/settings.json
cp serena_config.yml ~/.serena/serena_config.yml cp serena_config.yml ~/.serena/serena_config.yml
cp aws-config ~/.aws/config
sudo cp hosts /etc/hosts sudo cp hosts /etc/hosts
``` ```
(`aws-config` only holds profile definitions — the actual AWS credentials are
set up later, in the "AWS + OpenTofu state access" step.)
### 7. Set fish as the default shell ### 7. Set fish as the default shell
```bash ```bash
@@ -123,13 +127,57 @@ Clones every repo in the `resoftware` GitHub org via SSH into
`~/Repositories/{customer-number}/{repo-name}`, based on each repo's `~/Repositories/{customer-number}/{repo-name}`, based on each repo's
`customer-number` custom property. Safe to re-run — existing clones are skipped. `customer-number` custom property. Safe to re-run — existing clones are skipped.
### 11. WireGuard tunnel to home network (optional) ### 11. AWS + OpenTofu state access (resoftware-iac)
All OpenTofu state for `resoftware-iac` lives in the S3 bucket
`resoftware-iac-state` (eu-north-1); the backend blocks in that repo reference
the `resoftware-iac` AWS profile, so `tofu init` fails with *"failed to get
shared config profile resoftware-iac"* until that profile exists.
The `aws-config` restored in step 6 already defines both profiles in
`~/.aws/config`:
- `resoftware-iac` — the `iac` IAM user; used for the S3 state backend and plans.
- `default` — a root login session (account 693091788121); used for applies via
`aws configure export-credentials`.
What can't live in git and must be set up by hand:
```bash
aws configure --profile resoftware-iac
```
Enter the `iac` user's access key (from 1Password or the old machine's
`~/.aws/credentials`; or mint a fresh key in the AWS console — IAM is
deliberately console-managed, not IaC) and region `eu-north-1`. Beware if
editing the files manually instead: `~/.aws/config` section headers carry a
`profile ` prefix (`[profile resoftware-iac]`) but `~/.aws/credentials` headers
do **not** (`[resoftware-iac]`) — mismatching them causes exactly the
"failed to get shared config profile" error. `aws configure` writes both
correctly.
For applies, also establish the root session once:
```bash
aws login
```
Then restore each stack's gitignored `terraform.tfvars` (Infisical
machine-identity creds — copy securely from the old machine or refill from
Infisical; currently only `infra/cloudflare/terraform.tfvars`), and verify:
```bash
aws sts get-caller-identity --profile resoftware-iac
cd ~/Repositories/kl0000/resoftware-iac/infra/cloudflare && tofu init
```
### 12. WireGuard tunnel to home network (optional)
`meerkoet-proxy.conf` is a WireGuard client config for the home (Fritz!Box) `meerkoet-proxy.conf` is a WireGuard client config for the home (Fritz!Box)
network. Import it into the WireGuard app (installable from the App Store) via network. Import it into the WireGuard app (installable from the App Store) via
**Import Tunnel(s) from File**. **Import Tunnel(s) from File**.
### 12. Manual leftovers ### 13. Manual leftovers
Things not automated here: Things not automated here:
@@ -147,5 +195,6 @@ The symlinked files are always current by construction. Refresh the copied ones
``` ```
It re-dumps the brewfile (`brew bundle dump --force`) and re-copies It re-dumps the brewfile (`brew bundle dump --force`) and re-copies
`~/.claude/settings.json`, `~/.serena/serena_config.yml`, and `/etc/hosts` into `~/.claude/settings.json`, `~/.serena/serena_config.yml`, `~/.aws/config`, and
the repo. Review `git diff` afterwards and commit. `/etc/hosts` into the repo. Review `git diff` afterwards and commit.
(`~/.aws/credentials` is never tracked.)

5
aws-config Normal file
View File

@@ -0,0 +1,5 @@
[profile resoftware-iac]
region = eu-north-1
[default]
login_session = arn:aws:iam::693091788121:root
region = eu-north-1

View File

@@ -60,9 +60,10 @@ ln -sf "$REPO_HOME/NuGet.Config" ~/.nuget/NuGet/NuGet.Config
# --- 5. Copied configs ------------------------------------------------------- # --- 5. Copied configs -------------------------------------------------------
step "Restoring copied configs" step "Restoring copied configs"
mkdir -p ~/.claude ~/.serena mkdir -p ~/.claude ~/.serena ~/.aws
cp "$REPO_HOME/claude-settings.json" ~/.claude/settings.json cp "$REPO_HOME/claude-settings.json" ~/.claude/settings.json
cp "$REPO_HOME/serena_config.yml" ~/.serena/serena_config.yml cp "$REPO_HOME/serena_config.yml" ~/.serena/serena_config.yml
cp "$REPO_HOME/aws-config" ~/.aws/config
echo "Updating /etc/hosts (sudo)" echo "Updating /etc/hosts (sudo)"
sudo cp "$REPO_HOME/hosts" /etc/hosts sudo cp "$REPO_HOME/hosts" /etc/hosts
@@ -95,7 +96,11 @@ cat <<'EOF'
and put the *.pub files referenced in ssh-config into ~/.ssh/. and put the *.pub files referenced in ssh-config into ~/.ssh/.
2. iTerm2 > Settings > Profiles > Import JSON Profiles > iterm-profile.json. 2. iTerm2 > Settings > Profiles > Import JSON Profiles > iterm-profile.json.
3. gh auth login, then: fish clone-resoftware-repos.fish 3. gh auth login, then: fish clone-resoftware-repos.fish
4. Optional: import meerkoet-proxy.conf into the WireGuard app. 4. AWS/OpenTofu state access (see README "AWS + OpenTofu state access"):
5. Sign in to iCloud, browsers, Slack, Spark, Google Drive, Docker, aws configure --profile resoftware-iac (iac user key, region eu-north-1)
aws login (root session, for applies)
and restore the gitignored terraform.tfvars per resoftware-iac stack.
5. Optional: import meerkoet-proxy.conf into the WireGuard app.
6. Sign in to iCloud, browsers, Slack, Spark, Google Drive, Docker,
Todoist, JetBrains Toolbox; restore Alfred/BTT licenses. Todoist, JetBrains Toolbox; restore Alfred/BTT licenses.
EOF EOF

View File

@@ -6,6 +6,7 @@
# always current. This script refreshes the ones that are plain copies and # always current. This script refreshes the ones that are plain copies and
# therefore drift out of date: # therefore drift out of date:
# #
# * aws-config <- ~/.aws/config (profiles only; credentials never tracked)
# * brewfile <- `brew bundle dump` # * brewfile <- `brew bundle dump`
# * claude-settings.json <- ~/.claude/settings.json # * claude-settings.json <- ~/.claude/settings.json
# * hosts <- /etc/hosts # * hosts <- /etc/hosts
@@ -45,6 +46,15 @@ else
echo "==> Skipping serena_config.yml ($serena_config not found)" echo "==> Skipping serena_config.yml ($serena_config not found)"
end end
# --- AWS config (profiles only, ~/.aws/credentials is never tracked) -------
set -l aws_config "$HOME/.aws/config"
if test -f $aws_config
echo "==> Copying $aws_config -> aws-config"
cp $aws_config aws-config
else
echo "==> Skipping aws-config ($aws_config not found)"
end
# --- /etc/hosts ------------------------------------------------------------ # --- /etc/hosts ------------------------------------------------------------
if test -f /etc/hosts if test -f /etc/hosts
echo "==> Copying /etc/hosts -> hosts" echo "==> Copying /etc/hosts -> hosts"