mirror of
https://github.com/awatertrevi/macos-configuration.git
synced 2026-09-22 13:39:38 +00:00
Add AWS profile config and resoftware-iac OpenTofu state runbook
Track ~/.aws/config (profiles only, never credentials) as a copied config: setup.sh restores it, update.fish refreshes it. Document the S3 state backend setup for resoftware-iac in the README, including the config/credentials profile-header gotcha behind "failed to get shared config profile". Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
61
README.md
61
README.md
@@ -8,7 +8,7 @@ Two kinds of files live here:
|
|||||||
- **Symlinked** — the file in this repo *is* the live config (fish, starship, ssh,
|
- **Symlinked** — the file in this repo *is* the live config (fish, starship, ssh,
|
||||||
kube, npm, NuGet). Edit either side, they're the same file.
|
kube, npm, NuGet). Edit either side, they're the same file.
|
||||||
- **Copied** — files that can't be symlinked (`/etc/hosts`, Claude/Serena settings,
|
- **Copied** — files that can't be symlinked (`/etc/hosts`, Claude/Serena settings,
|
||||||
the brewfile). Refresh them from the machine with `./update.fish`.
|
the AWS config, the brewfile). Refresh them from the machine with `./update.fish`.
|
||||||
|
|
||||||
## Fresh machine setup — the fast way
|
## Fresh machine setup — the fast way
|
||||||
|
|
||||||
@@ -84,12 +84,16 @@ ln -sf $(pwd)/NuGet.Config ~/.nuget/NuGet/NuGet.Config
|
|||||||
### 6. Restore the copied configs
|
### 6. Restore the copied configs
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
mkdir -p ~/.claude ~/.serena
|
mkdir -p ~/.claude ~/.serena ~/.aws
|
||||||
cp claude-settings.json ~/.claude/settings.json
|
cp claude-settings.json ~/.claude/settings.json
|
||||||
cp serena_config.yml ~/.serena/serena_config.yml
|
cp serena_config.yml ~/.serena/serena_config.yml
|
||||||
|
cp aws-config ~/.aws/config
|
||||||
sudo cp hosts /etc/hosts
|
sudo cp hosts /etc/hosts
|
||||||
```
|
```
|
||||||
|
|
||||||
|
(`aws-config` only holds profile definitions — the actual AWS credentials are
|
||||||
|
set up later, in the "AWS + OpenTofu state access" step.)
|
||||||
|
|
||||||
### 7. Set fish as the default shell
|
### 7. Set fish as the default shell
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@@ -123,13 +127,57 @@ Clones every repo in the `resoftware` GitHub org via SSH into
|
|||||||
`~/Repositories/{customer-number}/{repo-name}`, based on each repo's
|
`~/Repositories/{customer-number}/{repo-name}`, based on each repo's
|
||||||
`customer-number` custom property. Safe to re-run — existing clones are skipped.
|
`customer-number` custom property. Safe to re-run — existing clones are skipped.
|
||||||
|
|
||||||
### 11. WireGuard tunnel to home network (optional)
|
### 11. AWS + OpenTofu state access (resoftware-iac)
|
||||||
|
|
||||||
|
All OpenTofu state for `resoftware-iac` lives in the S3 bucket
|
||||||
|
`resoftware-iac-state` (eu-north-1); the backend blocks in that repo reference
|
||||||
|
the `resoftware-iac` AWS profile, so `tofu init` fails with *"failed to get
|
||||||
|
shared config profile resoftware-iac"* until that profile exists.
|
||||||
|
|
||||||
|
The `aws-config` restored in step 6 already defines both profiles in
|
||||||
|
`~/.aws/config`:
|
||||||
|
|
||||||
|
- `resoftware-iac` — the `iac` IAM user; used for the S3 state backend and plans.
|
||||||
|
- `default` — a root login session (account 693091788121); used for applies via
|
||||||
|
`aws configure export-credentials`.
|
||||||
|
|
||||||
|
What can't live in git and must be set up by hand:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
aws configure --profile resoftware-iac
|
||||||
|
```
|
||||||
|
|
||||||
|
Enter the `iac` user's access key (from 1Password or the old machine's
|
||||||
|
`~/.aws/credentials`; or mint a fresh key in the AWS console — IAM is
|
||||||
|
deliberately console-managed, not IaC) and region `eu-north-1`. Beware if
|
||||||
|
editing the files manually instead: `~/.aws/config` section headers carry a
|
||||||
|
`profile ` prefix (`[profile resoftware-iac]`) but `~/.aws/credentials` headers
|
||||||
|
do **not** (`[resoftware-iac]`) — mismatching them causes exactly the
|
||||||
|
"failed to get shared config profile" error. `aws configure` writes both
|
||||||
|
correctly.
|
||||||
|
|
||||||
|
For applies, also establish the root session once:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
aws login
|
||||||
|
```
|
||||||
|
|
||||||
|
Then restore each stack's gitignored `terraform.tfvars` (Infisical
|
||||||
|
machine-identity creds — copy securely from the old machine or refill from
|
||||||
|
Infisical; currently only `infra/cloudflare/terraform.tfvars`), and verify:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
aws sts get-caller-identity --profile resoftware-iac
|
||||||
|
cd ~/Repositories/kl0000/resoftware-iac/infra/cloudflare && tofu init
|
||||||
|
```
|
||||||
|
|
||||||
|
### 12. WireGuard tunnel to home network (optional)
|
||||||
|
|
||||||
`meerkoet-proxy.conf` is a WireGuard client config for the home (Fritz!Box)
|
`meerkoet-proxy.conf` is a WireGuard client config for the home (Fritz!Box)
|
||||||
network. Import it into the WireGuard app (installable from the App Store) via
|
network. Import it into the WireGuard app (installable from the App Store) via
|
||||||
**Import Tunnel(s) from File**.
|
**Import Tunnel(s) from File**.
|
||||||
|
|
||||||
### 12. Manual leftovers
|
### 13. Manual leftovers
|
||||||
|
|
||||||
Things not automated here:
|
Things not automated here:
|
||||||
|
|
||||||
@@ -147,5 +195,6 @@ The symlinked files are always current by construction. Refresh the copied ones
|
|||||||
```
|
```
|
||||||
|
|
||||||
It re-dumps the brewfile (`brew bundle dump --force`) and re-copies
|
It re-dumps the brewfile (`brew bundle dump --force`) and re-copies
|
||||||
`~/.claude/settings.json`, `~/.serena/serena_config.yml`, and `/etc/hosts` into
|
`~/.claude/settings.json`, `~/.serena/serena_config.yml`, `~/.aws/config`, and
|
||||||
the repo. Review `git diff` afterwards and commit.
|
`/etc/hosts` into the repo. Review `git diff` afterwards and commit.
|
||||||
|
(`~/.aws/credentials` is never tracked.)
|
||||||
|
|||||||
5
aws-config
Normal file
5
aws-config
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
[profile resoftware-iac]
|
||||||
|
region = eu-north-1
|
||||||
|
[default]
|
||||||
|
login_session = arn:aws:iam::693091788121:root
|
||||||
|
region = eu-north-1
|
||||||
11
setup.sh
11
setup.sh
@@ -60,9 +60,10 @@ ln -sf "$REPO_HOME/NuGet.Config" ~/.nuget/NuGet/NuGet.Config
|
|||||||
|
|
||||||
# --- 5. Copied configs -------------------------------------------------------
|
# --- 5. Copied configs -------------------------------------------------------
|
||||||
step "Restoring copied configs"
|
step "Restoring copied configs"
|
||||||
mkdir -p ~/.claude ~/.serena
|
mkdir -p ~/.claude ~/.serena ~/.aws
|
||||||
cp "$REPO_HOME/claude-settings.json" ~/.claude/settings.json
|
cp "$REPO_HOME/claude-settings.json" ~/.claude/settings.json
|
||||||
cp "$REPO_HOME/serena_config.yml" ~/.serena/serena_config.yml
|
cp "$REPO_HOME/serena_config.yml" ~/.serena/serena_config.yml
|
||||||
|
cp "$REPO_HOME/aws-config" ~/.aws/config
|
||||||
echo "Updating /etc/hosts (sudo)"
|
echo "Updating /etc/hosts (sudo)"
|
||||||
sudo cp "$REPO_HOME/hosts" /etc/hosts
|
sudo cp "$REPO_HOME/hosts" /etc/hosts
|
||||||
|
|
||||||
@@ -95,7 +96,11 @@ cat <<'EOF'
|
|||||||
and put the *.pub files referenced in ssh-config into ~/.ssh/.
|
and put the *.pub files referenced in ssh-config into ~/.ssh/.
|
||||||
2. iTerm2 > Settings > Profiles > Import JSON Profiles > iterm-profile.json.
|
2. iTerm2 > Settings > Profiles > Import JSON Profiles > iterm-profile.json.
|
||||||
3. gh auth login, then: fish clone-resoftware-repos.fish
|
3. gh auth login, then: fish clone-resoftware-repos.fish
|
||||||
4. Optional: import meerkoet-proxy.conf into the WireGuard app.
|
4. AWS/OpenTofu state access (see README "AWS + OpenTofu state access"):
|
||||||
5. Sign in to iCloud, browsers, Slack, Spark, Google Drive, Docker,
|
aws configure --profile resoftware-iac (iac user key, region eu-north-1)
|
||||||
|
aws login (root session, for applies)
|
||||||
|
and restore the gitignored terraform.tfvars per resoftware-iac stack.
|
||||||
|
5. Optional: import meerkoet-proxy.conf into the WireGuard app.
|
||||||
|
6. Sign in to iCloud, browsers, Slack, Spark, Google Drive, Docker,
|
||||||
Todoist, JetBrains Toolbox; restore Alfred/BTT licenses.
|
Todoist, JetBrains Toolbox; restore Alfred/BTT licenses.
|
||||||
EOF
|
EOF
|
||||||
|
|||||||
10
update.fish
10
update.fish
@@ -6,6 +6,7 @@
|
|||||||
# always current. This script refreshes the ones that are plain copies and
|
# always current. This script refreshes the ones that are plain copies and
|
||||||
# therefore drift out of date:
|
# therefore drift out of date:
|
||||||
#
|
#
|
||||||
|
# * aws-config <- ~/.aws/config (profiles only; credentials never tracked)
|
||||||
# * brewfile <- `brew bundle dump`
|
# * brewfile <- `brew bundle dump`
|
||||||
# * claude-settings.json <- ~/.claude/settings.json
|
# * claude-settings.json <- ~/.claude/settings.json
|
||||||
# * hosts <- /etc/hosts
|
# * hosts <- /etc/hosts
|
||||||
@@ -45,6 +46,15 @@ else
|
|||||||
echo "==> Skipping serena_config.yml ($serena_config not found)"
|
echo "==> Skipping serena_config.yml ($serena_config not found)"
|
||||||
end
|
end
|
||||||
|
|
||||||
|
# --- AWS config (profiles only, ~/.aws/credentials is never tracked) -------
|
||||||
|
set -l aws_config "$HOME/.aws/config"
|
||||||
|
if test -f $aws_config
|
||||||
|
echo "==> Copying $aws_config -> aws-config"
|
||||||
|
cp $aws_config aws-config
|
||||||
|
else
|
||||||
|
echo "==> Skipping aws-config ($aws_config not found)"
|
||||||
|
end
|
||||||
|
|
||||||
# --- /etc/hosts ------------------------------------------------------------
|
# --- /etc/hosts ------------------------------------------------------------
|
||||||
if test -f /etc/hosts
|
if test -f /etc/hosts
|
||||||
echo "==> Copying /etc/hosts -> hosts"
|
echo "==> Copying /etc/hosts -> hosts"
|
||||||
|
|||||||
Reference in New Issue
Block a user