Skip to content

feat: grant futo the viewer role on grafana o11y#1846

Merged
zackpollard merged 1 commit into
mainfrom
feat/grafana-viewer-role
Jul 23, 2026
Merged

feat: grant futo the viewer role on grafana o11y#1846
zackpollard merged 1 commit into
mainfrom
feat/grafana-viewer-role

Conversation

@zackpollard

Copy link
Copy Markdown
Member

No description provided.

@zackpollard
zackpollard requested a review from a team as a code owner July 23, 2026 13:20
@github-actions

Copy link
Copy Markdown

Terraform Plan

Shared

1password/account — No changes
1password/futo-account — No changes
bunny/futo-account — No changes
cloudflare/account — No changes
cloudflare/api-keys — No changes
cloudflare/futo-account — No changes
cloudflare/futo-api-keys — No changes
docker/org — No changes
⚠️ github/org — Plan: 0 to add, 4 to change, 0 to destroy.
OpenTofu used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  ~ update in-place (current -> planned)
  # github_repository_collaborators.repo_collaborators["immich"] will be updated in-place
  ~ resource "github_repository_collaborators" "repo_collaborators" {
        id             = "455229168"
      ~ invitation_ids = {
          - "koen-futo"  = "286515056"
          - "martabal"   = "284848949"
          - "martyfuhry" = "284848968"
          - "matthinc"   = "284848954"
          - "sudoicezen" = "284848972"
        } -> (known after apply)
        # (2 unchanged attributes hidden)
      - user {
          - permission = "admin" -> null
          - username   = "alextran1502" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "bo0tzz" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "jrasm91" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "zackpollard" -> null
        }
      + user {
          + permission = "maintain"
          + username   = "alextran1502"
        }
      + user {
          + permission = "maintain"
          + username   = "bo0tzz"
        }
      + user {
          + permission = "maintain"
          + username   = "jrasm91"
        }
      + user {
          + permission = "maintain"
          + username   = "zackpollard"
        }
        # (59 unchanged blocks hidden)
    }
  # github_repository_collaborators.repo_collaborators["static-pages"] will be updated in-place
  ~ resource "github_repository_collaborators" "repo_collaborators" {
        id             = "822727374"
      ~ invitation_ids = {
          - "PixelJonas" = "284848947"
          - "fyfrey"     = "284848959"
          - "kennyfuto"  = "288622006"
          - "koen-futo"  = "286515046"
          - "martabal"   = "284848951"
          - "martyfuhry" = "284848969"
          - "matthinc"   = "284848955"
          - "orhan98"    = "315880176"
          - "sudoicezen" = "284848974"
        } -> (known after apply)
        # (2 unchanged attributes hidden)
      - user {
          - permission = "admin" -> null
          - username   = "alextran1502" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "bo0tzz" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "jrasm91" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "zackpollard" -> null
        }
      + user {
          + permission = "maintain"
          + username   = "alextran1502"
        }
      + user {
          + permission = "maintain"
          + username   = "bo0tzz"
        }
      + user {
          + permission = "maintain"
          + username   = "jrasm91"
        }
      + user {
          + permission = "maintain"
          + username   = "zackpollard"
        }
        # (58 unchanged blocks hidden)
    }
  # github_repository_collaborators.repo_collaborators["test-assets"] will be updated in-place
  ~ resource "github_repository_collaborators" "repo_collaborators" {
        id             = "697157116"
      ~ invitation_ids = {
          - "PixelJonas" = "284848946"
          - "fyfrey"     = "284848960"
          - "kennyfuto"  = "288622000"
          - "koen-futo"  = "286515048"
          - "martabal"   = "284848952"
          - "martyfuhry" = "284848970"
          - "matthinc"   = "284848956"
          - "orhan98"    = "315880175"
          - "staticdog"  = "320859393"
          - "sudoicezen" = "284848973"
        } -> (known after apply)
        # (2 unchanged attributes hidden)
      - user {
          - permission = "admin" -> null
          - username   = "alextran1502" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "bo0tzz" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "jrasm91" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "zackpollard" -> null
        }
      + user {
          + permission = "maintain"
          + username   = "alextran1502"
        }
      + user {
          + permission = "maintain"
          + username   = "bo0tzz"
        }
      + user {
          + permission = "maintain"
          + username   = "jrasm91"
        }
      + user {
          + permission = "maintain"
          + username   = "zackpollard"
        }
        # (58 unchanged blocks hidden)
    }
  # github_repository_collaborators.repo_collaborators["walkrs"] will be updated in-place
  ~ resource "github_repository_collaborators" "repo_collaborators" {
        id             = "1156754889"
      ~ invitation_ids = {
          - "C-Otto"          = "307331486"
          - "PixelJonas"      = "307331438"
          - "adamantike"      = "307331464"
          - "dahool"          = "307331471"
          - "ddshd"           = "307331444"
          - "fyfrey"          = "307331463"
          - "github-cli"      = "307331445"
          - "jbaez"           = "307331428"
          - "kennyfuto"       = "307331447"
          - "koen-futo"       = "307331458"
          - "martabal"        = "307331390"
          - "martyfuhry"      = "307331483"
          - "matthinc"        = "307331420"
          - "michelheusschen" = "307331480"
          - "midzelis"        = "309034718"
          - "orhan98"         = "315880173"
          - "samholton"       = "307331386"
          - "schuhbacca"      = "307331432"
          - "skatsubo"        = "307331414"
          - "staticdog"       = "320859390"
        } -> (known after apply)
        # (2 unchanged attributes hidden)
      - user {
          - permission = "admin" -> null
          - username   = "alextran1502" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "bo0tzz" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "jrasm91" -> null
        }
      - user {
          - permission = "admin" -> null
          - username   = "zackpollard" -> null
        }
      + user {
          + permission = "maintain"
          + username   = "alextran1502"
        }
      + user {
          + permission = "maintain"
          + username   = "bo0tzz"
        }
      + user {
          + permission = "maintain"
          + username   = "jrasm91"
        }
      + user {
          + permission = "maintain"
          + username   = "zackpollard"
        }
        # (58 unchanged blocks hidden)
    }
Plan: 0 to add, 4 to change, 0 to destroy.
╷
│ Warning: Argument is deprecated
│ 
│   with github_repository.repositories["justified-layout"],
│   on repositories.tf line 173, in resource "github_repository" "repositories":173:   vulnerability_alerts      = !each.value.archived
│ 
│ Use the github_repository_vulnerability_alerts resource instead. This field
│ will be removed in a future version.
│ 
│ (and 24 more similar warnings elsewhere)
╵
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so OpenTofu can't
guarantee to take exactly these actions if you run "tofu apply" now.
github/secrets — No changes
github/webhooks — No changes
netbird/account — No changes
⚠️ zitadel/cloud — Plan: 16 to add, 0 to change, 1 to destroy.
OpenTofu used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create
-/+ destroy and then create replacement
  # onepassword_item.application_client_secret["YUCCA_INTERNAL_TOOLING"] is tainted, so it must be replaced
-/+ resource "onepassword_item" "application_client_secret" {
      ~ id       = "vaults/ilwk2teati3z264z2szn5cwxia/items/3tkx2ppdtwgxvyzxeu5frap7eq" -> (known after apply)
      - password = (sensitive value) -> null
      ~ uuid     = "3tkx2ppdtwgxvyzxeu5frap7eq" -> (known after apply)
        # (3 unchanged attributes hidden)
    }
  # onepassword_item.application_client_secret_shared["YUCCA_INTERNAL_TOOLING"] will be created
  + resource "onepassword_item" "application_client_secret_shared" {
      + category = "password"
      + id       = (known after apply)
      + title    = "FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING"
      + uuid     = (known after apply)
      + vault    = "rbdsh7aqagdycb5vxlmevqyvwu"
    }
  # zitadel_project_role.project_roles["Grafana O11y_Viewer"] will be created
  + resource "zitadel_project_role" "project_roles" {
      + display_name = "Viewer"
      + id           = (known after apply)
      + org_id       = "364798781738212816"
      + project_id   = "378839135374293015"
      + role_key     = "Viewer"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_129423944"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "364798789506063824"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_202023786"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "364798786435964368"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_234065310"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "369738736788871931"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-105"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "376960707217911536"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-125"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "381080948567018533"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-127"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "381080948566976386"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-146"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "381080948566952997"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-152"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "378857599287703575"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-155"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "383040281458555480"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-177"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "379003612304547139"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-2"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "366545809816182396"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-39"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "378857599287769111"
    }
  # zitadel_user_grant.project_grants["Grafana O11y_gitlab-85"] will be created
  + resource "zitadel_user_grant" "project_grants" {
      + id         = (known after apply)
      + org_id     = "364798781738212816"
      + project_id = "378839135374293015"
      + role_keys  = [
          + "Viewer",
        ]
      + user_id    = "381080948550264706"
    }
Plan: 16 to add, 0 to change, 1 to destroy.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so OpenTofu can't
guarantee to take exactly these actions if you run "tofu apply" now.
zitadel/self-hosted — No changes

Scoped (dev)

discord/community — No changes
monitoring/grafana — No changes
zitadel/customer — No changes

Scoped (prod)

discord/community — No changes
discord/futo — No changes
monitoring/grafana — No changes
⚠️ zitadel/customer — Plan: 0 to add, 1 to change, 0 to destroy.
OpenTofu used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  ~ update in-place (current -> planned)
  # cloudflare_dns_record.customer_auth[0] will be updated in-place
  ~ resource "cloudflare_dns_record" "customer_auth" {
      ~ content     = (sensitive value)
        id          = "b8891ec64061d267a95974afe642413d"
      ~ modified_on = "2026-07-01T21:41:39Z" -> (known after apply)
        name        = "auth.futo.cloud"
        tags        = []
        # (8 unchanged attributes hidden)
    }
Plan: 0 to add, 1 to change, 0 to destroy.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so OpenTofu can't
guarantee to take exactly these actions if you run "tofu apply" now.

Scoped (staging — zitadel customer)

customer — No changes

@zackpollard
zackpollard merged commit 5c092dd into main Jul 23, 2026
26 checks passed
@zackpollard
zackpollard deleted the feat/grafana-viewer-role branch July 23, 2026 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants