# Secrets are created out-of-band by scripts/bootstrap-secrets.sh. # This file only declares them as data sources; the IAM bindings live in iam.tf. data "google_secret_manager_secret" "secret_key" { secret_id = "forgejo-secret-key" } data "google_secret_manager_secret" "internal_token" { secret_id = "forgejo-internal-token" }