fix: drone-pipelines secret

This commit is contained in:
auricom
2022-07-03 12:16:45 +02:00
parent dca3c4fe2e
commit 42f35ffc67
7 changed files with 75 additions and 15 deletions

View File

@@ -81,9 +81,9 @@ spec:
volumeMounts:
- name: secret
mountPath: /opt/id_rsa
subPath: deployment-rsa-priv-key
subPath: deployment_rsa_priv_key
volumes:
- name: secret
secret:
secretName: drone-pipelines
secretName: gitea-secrets
restartPolicy: Never

View File

@@ -1,6 +1,7 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- backup-job.yaml
- helm-release.yaml
- secrets.yaml
- volume.yaml
- helm-release.yaml
- backup-job.yaml

View File

@@ -0,0 +1,58 @@
kind: Secret
apiVersion: v1
metadata:
name: gitea-secrets
namespace: developement
stringData:
deployment_rsa_priv_key: ENC[AES256_GCM,data:mu0ks6G/LA3Sr66K7v1tdOQWSz5jrtBVYV8LcmpVmKpKeNh5dhPf95ShWSq1FWP/CzFBx/3857usRd0yPrGJocEig+/MTbLHTAXe9sVoWSIEHkl4fUAT7qFCU0seZgNLynw2EtH9hBsPSS7e849DSjN1fMO4OLCFkCcAE2Zsz2j15cs/MztlwwJTHMYQ3A2Ek9G07mVAITAKiX3s/r1tPwNKD8kHUUDsaGOB1964Js9wYqvvdIQl/uGsQvJe6sro2xGMOlhpaOpKEY3t93CIi4ywBPviS7olcZs9XEybXttcrWfJWX0auq48NS8GQDhHRT2v1oZPHBI84XssNmnVott3ngCGFoXfTDWdjazKsNcq2iOtwRJLxCkLagnv7Jyvu48rQtQFOYsHw/Lpp7WIAep4WUu+5MABYcn1BeX3H/hAHjvauNXdwK5kbVLCrfN1jzW7qgkBVKOdxUBHs13bjL+3AC5EzuFd9tXhCDngn4uOvIvRswWBVw1D301UrEArjBnarEfPibYMJADoXtTlp0ypUK5qs6yMsGYV970UgAhemRFZJ9a3WdlQIxscALba8hXyDHpSj/U2ZDzcBLDDpUHMYJaxfgG2RQacJijg9CNFGksCbSVnyBBieOBBBmv1YKWRNByeCPivQRyrmXWkg5pLCuM2bqyhxcOTyZXlq6gUzoyKzwhPPu4nUYBK661ARzwaLTk7zibjcPIjUPA5CYWRGONGalm4oY3mNCdML8tc/1HK1ijHqZ2ZivSZl5L8iKv4H8DWjCELIhT+X+X5ztTyzU2fNYqgyiK643bSVnZ9Dj+Aq7w9QnM7zcvkajtJCWbuItw8hILbAZ/Xyl/gWdGxG6SXvb7zNICxsf+rjNQrrR2Kug1/tfj/2L1uMvZIKSGnJqj41eVR4U6zZ5O3ArTgaQddjav8EwERKysc2a++WocdHNFokm8LuNzWwZFPGYdocAAVCMGm/67JHUYOj1w0vh1/+2ZFouxUkvvcmwJMr8VVc0VahUeqxE8se3HyEsbxG6RKAhIu1q5RfzcACiFYjne3KPbRzOAOe788WufScbLE9FEx+GG9wnqzG34gk315pgz6NTObPXnwcmr002AkG0UXRTviqWC5vsm7/SWcV77UEH+Q0vKHt2xy7mVSPb0EIO9Jxi6CiMWfnM/14XA/nLiJnrbe707EyOrr01dF++aIJ0SycIz+rzJaUoJL3naUvE08JPld94Kk2e7AnH7NX3XnBJoeY+/hcjxMV8f59uC8999yJHu806P6LGJjqc5uEhn7CGILtwnxEm5ySaGtRIu5xMJWiEE0C7CwytQD2lYb2GQ7Jsp25Gm1BbgxbtiEZ9nWPlpY9WvmDhIPytzAUu84ustW3i4VPu239tvnooqSfgBeTg/H4Zz9jIb+9TtJhE5yMhmK8qeJomJ7NPkGL9+czoSkHlUPvKkyONfBTqnrXIFa9PwszNGAO4Tw6hiKCKhmepTM7zxNIGz86uJs3lmPsbulVNnkmXwogbvgi5OrMXMylBzPF7aGGoSwI35CQxeQGLQh/1tw9AGrRp2SGtYBZdAlkNNcCdYDiBppaSAAUCyUYlw/FabCfN0pYQHy83A46+O5FRfmU5UBnujTwtt/CRFPsULxjZH2GMjzzxkTU4BsFS71Syu2gMSIIT1CHpOAhTtID2KAc6VPd+EgVZqtRDi86tnEHJqnraBgT+H0RjexzsIpWiqM5EcdZ6aIbvlAIyucPAXp6TS0rHU/FgEJguSZfMCxYB5VAj9O8oE6FwrsiK7vnV5iX6MrxviB8HUekk4bfr4y9oduK/FYs+oh24uQQGMWo6Cgn5guWaLpx3CH6cAEe/NGR5LHaSVxmweIWq+RkktK2zDC4QQ483+XMQ51SvaPrCYcH12eXjsjGKd0NK9P1h7OXLJ2SbiJ2gwnjcbjzTAOVx2lcXIax4WaOiSepM/TQbAogL4OnkHNd/xWrBZfPy9uY/lxUaPA3JwaNLzcGAkLa3S8kUNlRthFn0UNOfcrtpaavNxutY/Ml/OrBkXB9x94qrcC593pJMurf93FgFSDwl7GhB2Up0nUSrvLhnjpfvF/0/Blr8QQtR95AO2vc1IkiZvrGw7p/7FAC+GPVNBHMJuBDmWSUqwRl82I9nR2ni3oQx/Gx+SkIBeQIeEOmVOn8lZZHZIM5DldGfsukO/5TA6t/YSVK6C3IveY5jTJNhXYEIRGdfK+qYRzWli9sl98t7p2RRC7JufGi/43GsxuGPCR0MeID5l+KQxvJmF9CXVRKXVjXsvBqUoFBPL1v3Goc8g6iEexNZSzL4zCawc7HcHuO4WNyctfmB1k3JCZ9IaRhri6zbJSVvzf6YlDQoP2aBgvjWR8SdqgJsuUc6/pHfEeyPtaUSqimB7gSvrvQSg5cDEs+N1JFdVhA5iIWvfqqMRYvUViVWB0BHbPqIlz+Nt/DXC0Av0FIzrLTh3cY3x3ZbzItDLUIPKqxgqCTFrKpXgoHyfCwzPA2XUPLBj5ihyzpNsoRZ9jJIrNUWewEhIpSVW8OKGxBkIE82/mHWjQGD25rpE8W4PnuThS3YCAVFWzowaVdpVR/hv0TxXUBEJnM7wVsXRYYazA18pha3UydqVyS4uPMZxAPsWN7O6KBTUP9RdMOyvXi2WveJvY99ifnQmLYWWRnKfIqJJ136Zo8WJmXS/iqyswXQMnJCpUIfMNHa94QHlVGmQjhL20THtzT2w4c+BW3YxaeD8OYa9HQkaTZZSCqA25Tyu+lJPcDfEqWyzFAmN7RCir/Gfs8miEnMitZ4TWZvvtqhP5BAFvm7j2py9/9wrsRm4XJjeO58l0qin/HDq5L7EZGdf+kebjaGQbVQkmTpgCnobxse4v4uyZqU6QaeA35rUaIleuOcvQlpLH33OEF9FDEMjww2k7A8/ymFy4muTdDT4sFNydEKRvVj0duLo6EZ6iEpsAo0RinQO1pBQ8b3T3L8d8GRKdljlsN7WyxmfbJ5IfbQtH4q3HnFG0TdqDIeg5zZeFddoSC+MjPMwCTGt7XqEIUVbAdSmT0tG69M+r8Gxc8Z2eWVnUYu95GBNoJSyNaPKcSk5xoGWBAlP1+Qz14eGl72kBLa7YUSUArUCcWowbOztjjD7/bmIBuOWJlokjv0bHIJao6vy9qHHwqWLHT2ByGGv1UcoYqEhtKsXnqx1IFUnI0RlsAOURMmQMW207eQDddUdgwC9pIpKLJPHtf2F+rGqWtDlHkjvx3yJGleRVV7e/oHlZN5WW4aKIR9ntkQar75moDywVxEMBRnBPzwwNOGFAf/LUaHnaIpgP0qQetY/DHNMeUKVPcPsDWeppqKBxFW9Uhr8Oc3QmgwAnIdTMlWr4a8NgSn1WKcbvOiJyFu2mU8UXBZ3ZEazG53ZRkvViy9TGhD+e1O/3GLlUo6psiSkQt6Vn3YScErf2IPOdDpdfeXP7K4ndBVcb0tcRY1NHynpSfySp,iv:majin48BvzBk04GDahOnaxkDcxLsFKVEtijncxfKkl0=,tag:J7M/IYKppIXG4LDPpY+8Bw==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age: []
lastmodified: "2022-07-03T10:26:28Z"
mac: ENC[AES256_GCM,data:S3Ah3gz5kwlM2o3X7yXa8O+e/vL+Qr8eQZj6IdLvA3XiSN17/TSzs5bKLduomqAEN8KGFzDVnmj88t+iY0bBOoHVlq6JjUpgsJurtXtpwUE0UCRnl29/csCd9ndHzS6uh4p2hdA4/ruyy3jJXzI91YmeXqiqt8ObOJEM/B6GIxA=,iv:10nMOyq34eoUv2TCukL78E1lSFcTMm77plWC8+IkKnI=,tag:vQC//Bj3fTvDqhgVL4cJLw==,type:str]
pgp:
- created_at: "2021-07-17T21:15:45Z"
enc: |
-----BEGIN PGP MESSAGE-----
hQIMA6nQR2zACjUjAQ//fQ863OpprkOuu7ZzjHoq9ereZ+wu7jYg/rQ/1VbI9QL2
WzC8o/Csc2qrN1adnTx9s61HPGkAyqzsSJLmBrVufc+I1sGcJsCg8kzezO0HYau9
xV30mazw2sPca80fjbqeUY6hcp4oPcDg8METk9/TZ955UILit2nUWdCTOX+C6yxw
R206DfKb/UvQ3zLKpbeSvarf8+pyp7TpEmPnPjC9jYMzftD+lhqwRmaFjeeGjWIJ
NyeybL50kFBFJYou7AHxhLT7Ona2IASJCYvUj8kjwMc/MedjjcHdh+CysYlRgt0D
Ces7cUI+PVRdvWY2hi/EO/VCaD60bDEfy6zB8KHPRE+E53A4GlMvnvYF7QI5z4qC
HdCsQ8v2IOpU0/e/32eiAKtJmMqy+v1hVFavh+5u4epc5iFuJzoTAEdDg45FfQap
Kq6tDFWXP30Y3HfOc+7BBz9lep49zJB5cK47WvNM8Tfazb3DpHFXDbFgLyAkWuaq
QvZIijHeH2P5advD2gONUY9gDlVV8/HxYHNQVgwWyaVdmXXvzFtgpZQtIvIHA+Di
EhNrw8L/qtOW6B/uM+FzvcuGVTF3nnU4g43Y0XkTOd7JxP/l7CC78pcjl4IdgGbK
nb+1+/ShzjRJA3n0fvlkrbiMdep9hMQUWJlzsG15rRlvtLTxTZjNHX0kacn/4yTS
XgGKX2C4ZX3Pxdq/Mkr7muGZbLZIOHXL0OPouDzs8E64UPR0u8ayDDlsX9SYZ8hq
kvAL3ktnKNf1R3shWGKMcra8skjIKIoSmzEXf7RgCoNnewjt8wAqBY3+RGiaBUA=
=jwm/
-----END PGP MESSAGE-----
fp: 19B850FBA7685A526CF11E5F9BBE834259976EE8
- created_at: "2021-07-17T21:15:45Z"
enc: |
-----BEGIN PGP MESSAGE-----
hQIMA98IrODHuiZ9ARAAk2hc8IbzfVSagc4qeymEpDBwME2MpzYv7a6RPK7vS/VR
8PGYJT4DuJ0op4N/IiTKUeO1DVlqfZvzKBfAKDNdpojzaheNdy/L4nIKMN2klfx+
7BAXljRpqzyRjC2lyMFbDWgMMWcJG4PZIuCRQCm6ej0LOFwkoL4EitpfltdHj5tt
/qUWGICXSlgN882axw23Z9ZpfKmLLn2tKplFmgKErrPaXQxiqRHjPFzXh1JkGnaG
wtxBMdgX4eMDWGcSgiVqPFzMuecIA34u2bSnCrU4xmLGglHgm2oWpL9PZcdWBR1U
H9OzDrFNDD2X3Hey5jv5v3h64YwbFnZ89Y51lUbP8fbv65OrVGMQKE0ZQ7ueVwLk
H/IM9FnVDfkQ615ykPxUtr0AT47l9mffi6Iy1/XBmrqiCnaKhT5PEbSywmaKzOD9
9B7UG4l6kLh9F/bqNRsQWkarYlSmGf8BvAQNFH7ZtzyfRxTAP2wKxvaHA5/sqMO8
em0WDxvdeVtHSVYx/Kbu50RW0eDJRDD21P5neb2Jj7rZTVYD+L5Dxne+JXpTbI+8
jKesyEk3RYGzpthHHyWPZAo76cidqYVRvENfPFJljaRHpxcQLkYECTvyDmgyRNz0
uMHnQ76ZqeyGQ9NrYflcqd3XakTOvAmrwKz0p1zhmTlSgrUmGCUaZT8VXwRjsnDS
XgF3B6c9YDZz8f7wmtJqj0DTgxdgWGoQBrJowkyHhTxQetj++7EYaH0hdzrI+5bt
ZTM5I8y6zRrCAfvLKzKlMeh0R4XRREmNCyVzRuAfwjnVzXRVtcxRN8IAJR2mCNQ=
=vETF
-----END PGP MESSAGE-----
fp: 5749D0AE39445C1CCA6006DF8913091C690BDD69
encrypted_regex: ^(data|stringData)$
version: 3.7.3

View File

@@ -2,6 +2,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- namespace.yaml
- drone-pipelines.yaml
- docker-registry
- drone
- drone-runner-kube

View File

@@ -41,10 +41,10 @@ stringData:
SECRET_DRONE_RPC_SECRET: ENC[AES256_GCM,data:ib22K+Z32Xq+wt4zTwCFiNywupQy+Ze/ncbY5UKxp0M=,iv:9q0ffcEcWZ3Mm2UiO1zFo3nlY4usBQZlDe5O3d25PSY=,tag:6eiak9+lLqoVo+Q0TeClsw==,type:str]
SECRET_DOCKER_REGISTRY_HTPASSWD: ENC[AES256_GCM,data:ipfXjv8fa76Abi3I+5CGehBGc260rqFDCNFl1qkTwUH6W6zAcdzUNMLCI0+3WoiqO4b+Fz9fS2auqo8wZsx0NuRscQU=,iv:zWLM0IVQzc8d8gqvkrRyzrtD+8JzSe3QIMtFsI8RRFc=,tag:xYeWhSWlhIoamMCZNfU4VQ==,type:str]
SECRET_EMQX_ADMIN_PASSWORD: ENC[AES256_GCM,data:CoccfeM49hs6Nv15zy01iy5v7c6JPR+5,iv:iuRCUGANQJBOq2sZ/RWwbmT8WX4Y1TyXFDjORTWdmjY=,tag:i2WsMlnCjavk8vPN0fPjAg==,type:str]
SECRET_GITEA_ADMIN_EMAIL: ENC[AES256_GCM,data:EfkmLcBIZ0YBPDPbXTW/qtMKGNOy,iv:MTEas5mr4oi2hqkVnlxFP8VdYhvccogrgIXaVkyfLkU=,tag:/0vv4YjD6LUCAQw8FZFYOA==,type:str]
SECRET_GITEA_ADMIN_PASSWORD: ENC[AES256_GCM,data:X9SOGUxTFbOFxJiXmQY=,iv:QtzX8IjJ1QicGFwem5wp6plzE1Cs7t/3ggaaAu99UlM=,tag:lwmWJ8CC7Yt/slrs39D6Rg==,type:str]
SECRET_GITEA_API_TOKEN: ENC[AES256_GCM,data:G40oKgSVS0fo/PMzstQkDxX2PQNF+2pMWtcAxjkeYfPk8vSdP7Ku8g==,iv:LbzoKrN9D29D38q4FQ0rer+Y4Y4zZls4NCad8zQCXec=,tag:4SnX95QMCjL/kKsxubR/gA==,type:str]
SECRET_GITEA_DB_PASSWORD: ENC[AES256_GCM,data:oATkleJl4rrQS9rKuVk=,iv:OLp2TZ6RxGZLQm6sr0I7W1HJZeQ7MDrFVD2QKBIwUzs=,tag:3Qp9HkeHeepgOYXJxRNfrg==,type:str]
SECRET_GITEA_ADMIN_EMAIL: ENC[AES256_GCM,data:8COo5zSGBW8gjtUy2Kif/z9wDZ9D,iv:TA/cp/vmc2/31DIp1Hilg1GweFf5nBNYwxbyAjSflPE=,tag:SzcNh+o5xjhe5he84b8luQ==,type:str]
SECRET_GITEA_ADMIN_PASSWORD: ENC[AES256_GCM,data:gkcQTvMd78a5VfP5CGo=,iv:qEonzIVYBJqcFX5qDJZkyKJNK3U+nDdDBQTkhzbgTto=,tag:N6eNqb1rI+6gTm8pqc8f4A==,type:str]
SECRET_GITEA_API_TOKEN: ENC[AES256_GCM,data:0EmooDnLR3rDEAZ2KSeBXNivm0DVuUM/C1R5O3EnnvGDgaFWhrFjcA==,iv:hGVvznqwB8FvlBijHey3ePLDJi/8/7+YbB1diy7ew/M=,tag:tw79GxBb7bOjqoMdits4ow==,type:str]
SECRET_GITEA_DB_PASSWORD: ENC[AES256_GCM,data:rsOEXHvTtmKgz9g82WU=,iv:ss1YTKM3TbKN13H1Z0Qihq930y5/xd3spLuQwIHe/wY=,tag:2VCZYXOypSCuX7Mkt9dAhA==,type:str]
SECRET_HASS_DB_URL: ENC[AES256_GCM,data:8nvkhm+kgmbFCywZuSwqA1aC8dxgGr2n81aWLpjoJZRAm/wpaIwDN7HN0hdadOBZgX3oXlJatAldOKUw1CARzEky4YiTxJintJn1xXuTAQ==,iv:z5CEjBwufaT1uEph+aRvtn4mbMXfb+sTYfQ3TEcXw3Y=,tag:GmHUFg0/V6E2vhARayN5FA==,type:str]
SECRET_HASS_LATITUDE: ENC[AES256_GCM,data:W/Kn0QcRwKYYkt6/4SGKsSg=,iv:uuWzxB9UW/AIgH72pLVRwzSZwfJl1Pr4K/PlaYNnOcI=,tag:KtOgs9eC4FkjNSYtYybPsg==,type:str]
SECRET_HASS_LONGITUDE: ENC[AES256_GCM,data:lZHZvVNNqnincmkvxElCxhA=,iv:aSqGTbBk7+YV1frdFtD/nn4/xOg5C8vKxMAA7wRFMrM=,tag:qFhf9NeTs7AAnUd3Q4f5Vw==,type:str]
@@ -94,8 +94,8 @@ sops:
azure_kv: []
hc_vault: []
age: []
lastmodified: "2022-07-03T09:39:32Z"
mac: ENC[AES256_GCM,data:PI4BF33mdUILTgc63gAJC88SJpooh6N9bsFKeI0vn0oePon7H6/02JNtC5JPI3DrjcWatIovyGgcptE0Os++LZdimlr8fDcmEFv/j8uE0IHAx8GrmNTuRaLHAu5EN6hbZpsx6YN7Yx+10VNyLDzvrFvbU9n3E6ykHjhVeo2k5Hc=,iv:F4hqraL8ZXr/e+9MvC9bm2WNr8M95Z+4NkZCpnahXoY=,tag:iWuoLSxn4LIWR/Qm6jEYrg==,type:str]
lastmodified: "2022-07-03T10:25:54Z"
mac: ENC[AES256_GCM,data:GiwZJ8JMG5akGmaxQ6mMWiqc+ERU2MbQ+Tjt9DSLkoO/lGaLEXluk75rtEyqX3bB4YAx7jIJMhF97TS2zIlL8DywUXyzceDDOZKaTMB0gmZ4g9lY2WxIaOdG4KOm2gROFCJXpjULqgj67c0vm5DS5puZEJpISOUyZj8Tj+OEQts=,iv:FHWeq8PKB7pLvA/q1538ZEKNIVFpdl1lyzwmHDXg6IE=,tag:rwoOUleZnQuFz12T2w37QQ==,type:str]
pgp:
- created_at: "2022-07-03T09:37:47Z"
enc: |

View File

@@ -2,7 +2,7 @@ kind: Secret
apiVersion: v1
metadata:
name: drone-pipelines
namespace: networking
namespace: developement
stringData:
registry-username: ENC[AES256_GCM,data:0feiw+FkNQ==,iv:qlqyZnDaxDWSotJudzuVBnGRv4Nm5BkzcYvtzdXGG/c=,tag:6LpLEQWy9Bl6NrpgqslXVQ==,type:str]
registry-password: ENC[AES256_GCM,data:bXkbSETYKwDpoulIcEE=,iv:kbDngo9bEnY2wuyy42rXb+zUvgFLY3LEpHTmk2sXDog=,tag:Q2rIX1k5tNLLx7sTEOMPXQ==,type:str]
@@ -19,8 +19,8 @@ sops:
azure_kv: []
hc_vault: []
age: []
lastmodified: "2022-03-14T21:46:41Z"
mac: ENC[AES256_GCM,data:JK3+Pl96TBq+k3gEwBz6tTTuDQ3nZ1POR8Bx/PlHGhCbo9gG2YJ/9RkLdFDr6kO0DMMTofzmIUeY7NBqjwP9vBot0fCVdQnX43ByTHFEAN0H+g9Sk5AM5lcjRaoSG8dl+b89vTqUzA+vNbUaCdNKdYqgTdg0vDcdJw44VxGswLg=,iv:yrlSYD1KbPT8ynqBNSQ6rhZnjBTFdLhnaT5KuAR8Dmk=,tag:qg/2bLBS5SrIf2k7AkwVSA==,type:str]
lastmodified: "2022-07-03T10:16:07Z"
mac: ENC[AES256_GCM,data:r22xAu7fHYL2PZD/ejuMmjaMJA2l1pvzwu5FSYVpW+xU5qv1jHbe7NgsLychPFbseDgT4O3JFqpzYnLqVZPd1Q/DZEYvgNKJOtlhdwW/UX9MSMnU7NHjeunxGGQLNaYg60WHaZKVSB5Xmb542YA49cwi8IBSHc6igWTh2pRb3nw=,iv:cGtPq1igvXnpCxYOZ0E/5f+vN5f/nf98HZcvhyznuAw=,tag:G8Gzf5HTkvm6VJixXhySuQ==,type:str]
pgp:
- created_at: "2021-07-17T21:15:45Z"
enc: |
@@ -63,4 +63,4 @@ sops:
-----END PGP MESSAGE-----
fp: 5749D0AE39445C1CCA6006DF8913091C690BDD69
encrypted_regex: ^(data|stringData)$
version: 3.7.2
version: 3.7.3

View File

@@ -2,5 +2,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- cluster-secrets.yaml
#- drone-pipelines.yaml
#-drone-pipelines.yaml
#- regcred.yaml