From e174e259ebad24f2fd6d1dc3ae710ff7b761d9f5 Mon Sep 17 00:00:00 2001 From: Bastian de Byl Date: Mon, 14 Sep 2026 16:21:04 -0400 Subject: [PATCH] SCRUM-196: Read GA4 key from fulfillr_ga4_credentials_json Match the vault variable name holding the service-account key file. Co-Authored-By: Claude Opus 5 --- ansible/roles/podman/defaults/main.yml | 2 +- ansible/roles/podman/templates/fulfillr/dev.json.j2 | 6 +++--- ansible/roles/podman/templates/fulfillr/production.json.j2 | 6 +++--- 3 files changed, 7 insertions(+), 7 deletions(-) diff --git a/ansible/roles/podman/defaults/main.yml b/ansible/roles/podman/defaults/main.yml index 87a0773..327d6d3 100644 --- a/ansible/roles/podman/defaults/main.yml +++ b/ansible/roles/podman/defaults/main.yml @@ -327,5 +327,5 @@ cifs_watchdog_mounts: - "{{ photos_path }}/immich" # GA4 property for the fulfillr portal Traffic & funnel tab (SCRUM-196, non-secret). -# Shared by dev and prod. The service-account key `fulfillr_ga4_credentials` lives in the vault. +# Shared by dev and prod. The service-account key `fulfillr_ga4_credentials_json` lives in the vault. fulfillr_ga4_property_id: "353859448" diff --git a/ansible/roles/podman/templates/fulfillr/dev.json.j2 b/ansible/roles/podman/templates/fulfillr/dev.json.j2 index cb5d8fb..fedb5ac 100644 --- a/ansible/roles/podman/templates/fulfillr/dev.json.j2 +++ b/ansible/roles/podman/templates/fulfillr/dev.json.j2 @@ -53,13 +53,13 @@ "recovery": { "schedule_name": "cart-recovery-dev", "schedule_group": "default" - }{%- if fulfillr_ga4_credentials is defined %}, + }{%- if fulfillr_ga4_credentials_json is defined %}, {# GA4 Data API for the portal Traffic & funnel tab (SCRUM-196). Renders only once the - service-account key `fulfillr_ga4_credentials` (the key JSON, as a mapping or string) + service-account key `fulfillr_ga4_credentials_json` (the key JSON, as a mapping or string) is in the vault; without it the traffic endpoint reports configured:false. #} "analytics": { "ga4_property_id": "{{ fulfillr_ga4_property_id }}", - "ga4_credentials": {{ (fulfillr_ga4_credentials if fulfillr_ga4_credentials is mapping else (fulfillr_ga4_credentials | from_json)) | to_json }} + "ga4_credentials": {{ (fulfillr_ga4_credentials_json if fulfillr_ga4_credentials_json is mapping else (fulfillr_ga4_credentials_json | from_json)) | to_json }} } {%- endif %} } diff --git a/ansible/roles/podman/templates/fulfillr/production.json.j2 b/ansible/roles/podman/templates/fulfillr/production.json.j2 index 6a315eb..8619764 100644 --- a/ansible/roles/podman/templates/fulfillr/production.json.j2 +++ b/ansible/roles/podman/templates/fulfillr/production.json.j2 @@ -53,13 +53,13 @@ "recovery": { "schedule_name": "cart-recovery-prod", "schedule_group": "default" - }{%- if fulfillr_ga4_credentials is defined %}, + }{%- if fulfillr_ga4_credentials_json is defined %}, {# GA4 Data API for the portal Traffic & funnel tab (SCRUM-196). Renders only once the - service-account key `fulfillr_ga4_credentials` (the key JSON, as a mapping or string) + service-account key `fulfillr_ga4_credentials_json` (the key JSON, as a mapping or string) is in the vault; without it the traffic endpoint reports configured:false. #} "analytics": { "ga4_property_id": "{{ fulfillr_ga4_property_id }}", - "ga4_credentials": {{ (fulfillr_ga4_credentials if fulfillr_ga4_credentials is mapping else (fulfillr_ga4_credentials | from_json)) | to_json }} + "ga4_credentials": {{ (fulfillr_ga4_credentials_json if fulfillr_ga4_credentials_json is mapping else (fulfillr_ga4_credentials_json | from_json)) | to_json }} } {%- endif %} }