♻️ postgres

This commit is contained in:
auricom
2022-09-14 19:40:49 +02:00
parent 6120029e69
commit 4aa922b8bf
7 changed files with 10 additions and 8 deletions

View File

@@ -24,6 +24,8 @@ spec:
dependsOn: dependsOn:
- name: glauth - name: glauth
namespace: default namespace: default
- name: postgres
namespace: default
- name: redis - name: redis
namespace: default namespace: default
values: values:

View File

@@ -31,8 +31,7 @@ spec:
AUTHELIA_SESSION_REDIS_DATABASE_INDEX: 14 AUTHELIA_SESSION_REDIS_DATABASE_INDEX: 14
AUTHELIA_SESSION_REDIS_HOST: redis.default.svc.cluster.local AUTHELIA_SESSION_REDIS_HOST: redis.default.svc.cluster.local
AUTHELIA_STORAGE_POSTGRES_DATABASE: authelia AUTHELIA_STORAGE_POSTGRES_DATABASE: authelia
AUTHELIA_STORAGE_POSTGRES_HOST: postgres.${SECRET_DOMAIN} AUTHELIA_STORAGE_POSTGRES_HOST: postgres-rw.default.svc.cluster.local
AUTHELIA_STORAGE_POSTGRES_SSL_MODE: verify-full
AUTHELIA_TELEMETRY_METRICS_ADDRESS: "tcp://0.0.0.0:8080" AUTHELIA_TELEMETRY_METRICS_ADDRESS: "tcp://0.0.0.0:8080"
AUTHELIA_TELEMETRY_METRICS_ENABLED: "true" AUTHELIA_TELEMETRY_METRICS_ENABLED: "true"
AUTHELIA_THEME: grey AUTHELIA_THEME: grey

View File

@@ -22,6 +22,8 @@ spec:
remediation: remediation:
retries: 5 retries: 5
dependsOn: dependsOn:
- name: postgres
namespace: default
- name: redis - name: redis
namespace: default namespace: default
values: values:

View File

@@ -7,4 +7,4 @@ resources:
- helm-release.yaml - helm-release.yaml
patchesStrategicMerge: patchesStrategicMerge:
- patches/env.yaml - patches/env.yaml
# - patches/postgres.yaml - patches/postgres.yaml

View File

@@ -22,7 +22,6 @@ spec:
OIDC_TOKEN_URI: "https://auth.${SECRET_CLUSTER_DOMAIN}/api/oidc/token" OIDC_TOKEN_URI: "https://auth.${SECRET_CLUSTER_DOMAIN}/api/oidc/token"
OIDC_USERINFO_URI: "https://auth.${SECRET_CLUSTER_DOMAIN}/api/oidc/userinfo" OIDC_USERINFO_URI: "https://auth.${SECRET_CLUSTER_DOMAIN}/api/oidc/userinfo"
OIDC_USERNAME_CLAIM: email OIDC_USERNAME_CLAIM: email
PGSSLMODE: require
PORT: 80 PORT: 80
REDIS_URL: ioredis://eyJkYiI6MTUsInNlbnRpbmVscyI6W3siaG9zdCI6InJlZGlzLW5vZGUtMC5yZWRpcy1oZWFkbGVzcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwicG9ydCI6MjYzNzl9LHsiaG9zdCI6InJlZGlzLW5vZGUtMS5yZWRpcy1oZWFkbGVzcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwicG9ydCI6MjYzNzl9LHsiaG9zdCI6InJlZGlzLW5vZGUtMi5yZWRpcy1oZWFkbGVzcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwicG9ydCI6MjYzNzl9XSwibmFtZSI6InJlZGlzLW1hc3RlciJ9 REDIS_URL: ioredis://eyJkYiI6MTUsInNlbnRpbmVscyI6W3siaG9zdCI6InJlZGlzLW5vZGUtMC5yZWRpcy1oZWFkbGVzcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwicG9ydCI6MjYzNzl9LHsiaG9zdCI6InJlZGlzLW5vZGUtMS5yZWRpcy1oZWFkbGVzcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwicG9ydCI6MjYzNzl9LHsiaG9zdCI6InJlZGlzLW5vZGUtMi5yZWRpcy1oZWFkbGVzcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwicG9ydCI6MjYzNzl9XSwibmFtZSI6InJlZGlzLW1hc3RlciJ9
SMTP_HOST: smtp-relay.default.svc.cluster.local SMTP_HOST: smtp-relay.default.svc.cluster.local

View File

@@ -11,7 +11,7 @@ spec:
image: ghcr.io/onedr0p/postgres-initdb:14.5 image: ghcr.io/onedr0p/postgres-initdb:14.5
env: env:
- name: POSTGRES_HOST - name: POSTGRES_HOST
value: postgres.${SECRET_DOMAIN} value: postgres-rw.default.svc.cluster.local
- name: POSTGRES_DB - name: POSTGRES_DB
value: *app value: *app
- name: POSTGRES_SUPER_PASS - name: POSTGRES_SUPER_PASS

View File

@@ -10,7 +10,7 @@ stringData:
AWS_SECRET_ACCESS_KEY: ENC[AES256_GCM,data:2GGPneKPmFEtq3A9X7fskiv/FnKv5deoyzNx0/euYrTOJKrRiTgj8g==,iv:u1LLrjxP1GwWcM1FJLjB9OpUFTPI0D9IZEX86IHGpmU=,tag:7vq4QeQagU2B9+WShheDKg==,type:str] AWS_SECRET_ACCESS_KEY: ENC[AES256_GCM,data:2GGPneKPmFEtq3A9X7fskiv/FnKv5deoyzNx0/euYrTOJKrRiTgj8g==,iv:u1LLrjxP1GwWcM1FJLjB9OpUFTPI0D9IZEX86IHGpmU=,tag:7vq4QeQagU2B9+WShheDKg==,type:str]
SECRET_KEY: ENC[AES256_GCM,data:RUjf4wghv9PnDdSNWeytoDRzH+A7wa8RNYDP+MYIf8KHjOGyVNzZwEuS8ah8wy8tvBWAE9kykOC1KhP+wFofIA==,iv:3z7NZ87ILlyrkx4YMWQ9uFL2W31bTmwZFkJxOHgSVvo=,tag:umplfrhjvCZX9Ucneo7Q+Q==,type:str] SECRET_KEY: ENC[AES256_GCM,data:RUjf4wghv9PnDdSNWeytoDRzH+A7wa8RNYDP+MYIf8KHjOGyVNzZwEuS8ah8wy8tvBWAE9kykOC1KhP+wFofIA==,iv:3z7NZ87ILlyrkx4YMWQ9uFL2W31bTmwZFkJxOHgSVvo=,tag:umplfrhjvCZX9Ucneo7Q+Q==,type:str]
UTILS_SECRET: ENC[AES256_GCM,data:r5DADkQbM5fEBsWs7ddUx2PXnt+ePiQcJZgKMmHYpkddmPFeS5xpJGgbhun7v409aKJLQRm/tUIysBlxHlnSbA==,iv:cP2KQeUmgjoXuY7UnQ57M4tBUeO0hELGe+HrSB5RJ3Q=,tag:HD4lccnbZXjllmOLyEHY3Q==,type:str] UTILS_SECRET: ENC[AES256_GCM,data:r5DADkQbM5fEBsWs7ddUx2PXnt+ePiQcJZgKMmHYpkddmPFeS5xpJGgbhun7v409aKJLQRm/tUIysBlxHlnSbA==,iv:cP2KQeUmgjoXuY7UnQ57M4tBUeO0hELGe+HrSB5RJ3Q=,tag:HD4lccnbZXjllmOLyEHY3Q==,type:str]
DATABASE_URL: ENC[AES256_GCM,data:AUz6cKjfad72wYR1usNxTayRJiUP6Q9N4dASz4A2siHwA6Whw4Rzg5uS22EvHLtq5Oy4m6b5tLn5XmowiDiEV8dOSOhqRyC62w==,iv:/2sOo0we0MpzCqmr57zFEQh9Uj5X1xP1BR/rNKO2sVo=,tag:ArT+VVdfnWt7MAJliG6AyQ==,type:str] DATABASE_URL: ENC[AES256_GCM,data:GQDEa98NXUyrReZlVpVf83n66QTe0eZAfYSQ2C6ukeRlALZTcpuhC0RxVrZJT6/L4GrZsqZ/VIWJlm9fStY+6ulNJPyBcfkDZOuVKXnhsT1oZfNy4JJAJXVq,iv:hvCEii7DnubCuZ7sm5j7e+iPgZQHNooPhjtjBvCFD+s=,tag:ZNla57lzZrud3JdBbO+zmQ==,type:str]
POSTGRES_USER: ENC[AES256_GCM,data:4FlwiUkmmQ==,iv:f/mOMCV34bvseHAJ37AaUIZUYcBobtdIAYN/5ONhGbg=,tag:HFvPkQh2i/BtnynAjP0uhg==,type:str] POSTGRES_USER: ENC[AES256_GCM,data:4FlwiUkmmQ==,iv:f/mOMCV34bvseHAJ37AaUIZUYcBobtdIAYN/5ONhGbg=,tag:HFvPkQh2i/BtnynAjP0uhg==,type:str]
POSTGRES_PASS: ENC[AES256_GCM,data:HTbSg+yj1iKqlGmPPwql+GD+psM=,iv:fMHU+AYZ/NfgtCstuQIfnBmKRD2n3hMmFKSqC5akB/c=,tag:v16K+iZZVQZ9gpBIBWgyfQ==,type:str] POSTGRES_PASS: ENC[AES256_GCM,data:HTbSg+yj1iKqlGmPPwql+GD+psM=,iv:fMHU+AYZ/NfgtCstuQIfnBmKRD2n3hMmFKSqC5akB/c=,tag:v16K+iZZVQZ9gpBIBWgyfQ==,type:str]
sops: sops:
@@ -28,8 +28,8 @@ sops:
eGsyL3NhNS8xdUp0VlNQbWRYbHFLYW8KeMc82BlegMJMtAF/WGMbXhpf2MVvUP5q eGsyL3NhNS8xdUp0VlNQbWRYbHFLYW8KeMc82BlegMJMtAF/WGMbXhpf2MVvUP5q
ehHCSwpe3a8WwXEBNu1u5IPcnMO4Fo5HhjLbMx6H1Ynd6KdyDXUKEg== ehHCSwpe3a8WwXEBNu1u5IPcnMO4Fo5HhjLbMx6H1Ynd6KdyDXUKEg==
-----END AGE ENCRYPTED FILE----- -----END AGE ENCRYPTED FILE-----
lastmodified: "2022-09-12T23:37:43Z" lastmodified: "2022-09-14T17:45:25Z"
mac: ENC[AES256_GCM,data:c2zSv11F3d5uO9tgxnWe0hj7N9rcd1MLpiXjwwi0PR6T3waarThCrdpf5EPy5jv/kKc+4DiyxDZRbj7sM7OzU+puDa4SV10uB33XRKzW5ktx9VPt0ykVsSc1/L9akrk2DLxzOTDwHwBj+2aEpzPef0a/w0t49vy+SULiudvB7iM=,iv:5ZMobXcA3ErqpuvFiT8xA1MJjdzpylAD0t8+eX+6jGI=,tag:ffE4iRg7w2/l5CgKZKfhsg==,type:str] mac: ENC[AES256_GCM,data:gJm7NfuIi4ftbxKpJInh3Le4p0F8BIr2LYbTqWeR3posJAqkEs1By7GtXbu8TWeeIpP2vmqul4iHKNgCp74ghyEkSDSCfRhuumz/mf+2bwqG2JxUtrl+WMtn5hmepAvxj3LUXUskC8YqGwHmd8cqnnSxbx9w8L5I4E8ODBNG0cw=,iv:2gjQZJxhj+xTEuudePJlQjovjBwqcjoNXmE+Mu+033E=,tag:rOz33EGi+sRSjrW2ByoRcw==,type:str]
pgp: [] pgp: []
encrypted_regex: ^(data|stringData)$ encrypted_regex: ^(data|stringData)$
version: 3.7.3 version: 3.7.3