mirror of
https://github.com/auricom/home-cluster.git
synced 2025-10-03 09:09:01 +02:00
fixup! ♻️ migration externalsecrets
This commit is contained in:
34
kubernetes/apps/default/joplin/app/externalsecret.yaml
Normal file
34
kubernetes/apps/default/joplin/app/externalsecret.yaml
Normal file
@@ -0,0 +1,34 @@
|
||||
---
|
||||
# yaml-language-server: $schema=https://kubernetes-schemas.devbu.io/external-secrets.io/externalsecret_v1beta1.json
|
||||
apiVersion: external-secrets.io/v1beta1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: joplin
|
||||
namespace: default
|
||||
spec:
|
||||
secretStoreRef:
|
||||
kind: ClusterSecretStore
|
||||
name: onepassword-connect
|
||||
target:
|
||||
name: joplin-secret
|
||||
creationPolicy: Owner
|
||||
template:
|
||||
engineVersion: v2
|
||||
data:
|
||||
# App
|
||||
POSTGRES_DATABASE: &dbName joplin
|
||||
POSTGRES_HOST: &dbHost postgres-rw.default.svc.cluster.local.
|
||||
POSTGRES_PORT: "5432"
|
||||
POSTGRES_USER: &dbUser "{{ .POSTGRES_USER }}"
|
||||
POSTGRES_PASSWORD: &dbPass "{{ .POSTGRES_PASSWORD }}"
|
||||
# Postgres Init
|
||||
INIT_POSTGRES_DBNAME: *dbName
|
||||
INIT_POSTGRES_HOST: *dbHost
|
||||
INIT_POSTGRES_USER: *dbUser
|
||||
INIT_POSTGRES_PASS: *dbPass
|
||||
INIT_POSTGRES_SUPER_PASS: "{{ .POSTGRES_SUPER_PASS }}"
|
||||
dataFrom:
|
||||
- extract:
|
||||
key: cloudnative-pg
|
||||
- extract:
|
||||
key: joplin
|
@@ -6,7 +6,7 @@ metadata:
|
||||
name: &app joplin
|
||||
namespace: default
|
||||
spec:
|
||||
interval: 15m
|
||||
interval: 30m
|
||||
chart:
|
||||
spec:
|
||||
chart: app-template
|
||||
@@ -15,7 +15,7 @@ spec:
|
||||
kind: HelmRepository
|
||||
name: bjw-s
|
||||
namespace: flux-system
|
||||
maxHistory: 3
|
||||
maxHistory: 2
|
||||
install:
|
||||
createNamespace: true
|
||||
remediation:
|
||||
@@ -29,6 +29,9 @@ spec:
|
||||
values:
|
||||
global:
|
||||
nameOverride: *app
|
||||
controller:
|
||||
annotations:
|
||||
reloader.stakater.com/auto: "true"
|
||||
image:
|
||||
repository: joplin/server
|
||||
tag: 2.11.2-beta
|
||||
@@ -36,9 +39,6 @@ spec:
|
||||
APP_BASE_URL: https://joplin.${SECRET_CLUSTER_DOMAIN}
|
||||
APP_PORT: &port 8080
|
||||
DB_CLIENT: pg
|
||||
POSTGRES_HOST: ${POSTGRES_HOST}
|
||||
POSTGRES_PORT: ${POSTGRES_PORT}
|
||||
POSTGRES_DATABASE: joplin
|
||||
MAILER_ENABLED: 1
|
||||
MAILER_HOST: smtp-relay.default.svc.cluster.local.
|
||||
MAILER_PORT: 2525
|
||||
@@ -47,9 +47,7 @@ spec:
|
||||
MAILER_NOREPLY_EMAIL: joplin@${SECRET_DOMAIN}
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: *app
|
||||
podAnnotations:
|
||||
secret.reloader.stakater.com/reload: *app
|
||||
name: joplin-secret
|
||||
service:
|
||||
main:
|
||||
ports:
|
||||
|
@@ -4,7 +4,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
namespace: default
|
||||
resources:
|
||||
- ./externalsecret.yaml
|
||||
- ./helmrelease.yaml
|
||||
- ./secret.sops.yaml
|
||||
patchesStrategicMerge:
|
||||
- ./patches/postgres.yaml
|
||||
|
@@ -1,32 +0,0 @@
|
||||
---
|
||||
# yaml-language-server: $schema=https://kubernetes-schemas.devbu.io/helm.toolkit.fluxcd.io/helmrelease_v2beta1.json
|
||||
apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
||||
kind: HelmRelease
|
||||
metadata:
|
||||
name: joplin
|
||||
namespace: default
|
||||
spec:
|
||||
values:
|
||||
initContainers:
|
||||
init-db:
|
||||
image: ghcr.io/onedr0p/postgres-initdb:14.8
|
||||
env:
|
||||
- name: POSTGRES_HOST
|
||||
value: ${POSTGRES_HOST}
|
||||
- name: POSTGRES_DB
|
||||
value: joplin
|
||||
- name: POSTGRES_SUPER_PASS
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: postgres-superuser
|
||||
key: password
|
||||
- name: POSTGRES_USER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: joplin
|
||||
key: POSTGRES_USER
|
||||
- name: POSTGRES_PASS
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: joplin
|
||||
key: POSTGRES_PASSWORD
|
@@ -1,30 +0,0 @@
|
||||
# yamllint disable
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: joplin
|
||||
namespace: default
|
||||
type: Opaque
|
||||
stringData:
|
||||
POSTGRES_USER: ENC[AES256_GCM,data:jNdktSC6,iv:MMJlnCvXm5w5fWU/oe3bJINrZNbzkJIs3bAqGswrEFA=,tag:iw38sQO32V1eR8XNyAV2gQ==,type:str]
|
||||
POSTGRES_PASSWORD: ENC[AES256_GCM,data:cDAlN/Hr30o+sWpaSQNHMw==,iv:0/eswlxH8w2IQc3ca7XWcEmEojUnJQ6bo61NK+ip1pg=,tag:CnI75YyzApe9n5o8m7MZKw==,type:str]
|
||||
sops:
|
||||
kms: []
|
||||
gcp_kms: []
|
||||
azure_kv: []
|
||||
hc_vault: []
|
||||
age:
|
||||
- recipient: age1hhurqwmfvl9m3vh3hk8urulfzcdsrep2ax2neazqt435yhpamu3qj20asg
|
||||
enc: |
|
||||
-----BEGIN AGE ENCRYPTED FILE-----
|
||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBJaU16anJNV2pBZmxPR3h2
|
||||
bWREUnpjcTFvd05ZQ2E4VVBDdm1FL2k4WEYwCkdQSStTNWtpdjNkUW51WS9MekdC
|
||||
VkpTUUFjSjY2a1JMOUtqOVh5M0JRR2sKLS0tIDRmcWpJSEVvaUp4U1lsaTZYZGNw
|
||||
OGVKWU0zNUZJSFh4aFJxQWFsYm1VeFkKaDeI/hl7z0Qh8t5W39Kxu9ert1dt4xo+
|
||||
LX+MjpVqxiZNcfwROD4bkWeQSN+VsxoGOOyj4L15BlggNnlg+L7Hww==
|
||||
-----END AGE ENCRYPTED FILE-----
|
||||
lastmodified: "2022-09-15T21:00:13Z"
|
||||
mac: ENC[AES256_GCM,data:MLJDC9OZG0lgOSI93kOso4XDwnh6plwn3RddjS5zG34Ja/T+i5BG52HwdYs+XUgQWFvawX9ZUGwarCrNmJTMaYAJzjDBEF4TzR+sF9pGAlAtraL5RKM5H8cr9Hwy7UkQxNvVJu1kZ7rCUDWhYp7x9jEuGzXpiZwlwDq+C1XwD3A=,iv:GAc/oGqtc8gkHM1XCuAB+N7+T8vxBHQ7WPQxXOSZUIY=,tag:JlXR6ANyyEZZHrONHkNSTg==,type:str]
|
||||
pgp: []
|
||||
encrypted_regex: ^(data|stringData)$
|
||||
version: 3.7.3
|
Reference in New Issue
Block a user