fix(security): move hardcoded test password to GitHub Actions secret

- CI workflow: PVE_PASSWORD now reads from secrets.PVE_TEST_PASSWORD
- variables.tf: removed default password, requires TF_VAR env var
- Integration README: examples use <your-test-password> placeholder
- create-api-token.sh: example IP changed to pve.example.com
- .gitignore: added .env/.env.* exclusion

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Clint Branham
2026-03-23 17:40:47 -05:00
parent 053fd4c06a
commit d5f4e13637
5 changed files with 8 additions and 7 deletions
@@ -3,7 +3,7 @@
# then wait for the PVE API and create an API token.
#
# Usage: create-api-token.sh <parent-pve-endpoint> <parent-api-token> <vm-id> <root-password> [max-wait-seconds]
# parent-pve-endpoint: Full URL e.g. https://172.16.100.150:8006
# parent-pve-endpoint: Full URL e.g. https://pve.example.com:8006
# Outputs two lines:
# IP=<discovered-ip>
# TOKEN=root@pam!integration=<secret>
+1 -2
View File
@@ -66,8 +66,7 @@ variable "network_bridge" {
}
variable "test_vm_password" {
description = "Root password for the nested PVE instances"
description = "Root password for the nested PVE instances. Set via TF_VAR_test_vm_password env var."
type = string
sensitive = true
default = "Testpass123!"
}