Manage Gitea users; add teabot personality bot accounts
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Add a data-driven 'user' config kind so Gitea accounts are declared as
config/git.unkin.net/user/<name>.yaml, mirroring the existing repository
and team kinds. Wire the yaml into a new modules/user submodule that
creates a gitea_user (provider go-gitea/gitea 0.7.0, already pinned).

The provider's user resource requires a password; generate a per-user
random_password so nothing sensitive is hardcoded and only a placeholder
lives in state (tokens come later from vault-plugin-secrets-gitea).

Provision teabot's implementer and reviewer personality accounts with a
conservative posture: not site admins, no org creation, no repo creation,
limited profile visibility.

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
This commit is contained in:
2026-07-27 17:22:19 +10:00
parent ee08fd5585
commit fd82876f5f
10 changed files with 198 additions and 0 deletions
+19
View File
@@ -64,6 +64,25 @@ variable "branch_protection" {
}
variable "user" {
description = "Map of Gitea user accounts to create"
type = map(object({
username = string
email = string
login_name = optional(string)
full_name = optional(string, "")
description = optional(string, "")
visibility = optional(string, "limited")
admin = optional(bool, false)
restricted = optional(bool, false)
active = optional(bool, true)
allow_create_organization = optional(bool, false)
max_repo_creation = optional(number, 0)
must_change_password = optional(bool, false)
}))
default = {}
}
variable "team" {
description = "Map of teams to create"
type = map(object({