♻️ migration externalsecrets

This commit is contained in:
auricom
2023-07-08 23:21:34 +02:00
parent 94b5077db7
commit da5c777c93
16 changed files with 93 additions and 138 deletions

View File

@@ -0,0 +1,18 @@
---
# yaml-language-server: $schema=https://kubernetes-schemas.devbu.io/external-secrets.io/externalsecret_v1beta1.json
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: actions-runner-controller-auth
namespace: actions-runner-system
spec:
secretStoreRef:
kind: ClusterSecretStore
name: onepassword-connect
target:
name: actions-runner-controller-auth-secret
creationPolicy: Owner
dataFrom:
- extract:
# github_app_id, github_app_installation_id, github_app_private_key
key: actions-runner-controller

View File

@@ -4,5 +4,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: actions-runner-system
resources:
- ./externalsecret.yaml
- ./helmrelease.yaml
- ./secrets.sops.yaml

View File

@@ -1,30 +0,0 @@
# yamllint disable
apiVersion: v1
kind: Secret
metadata:
name: actions-runner-controller-auth-secret
namespace: actions-runner-system
stringData:
github_app_id: ENC[AES256_GCM,data:wrVw0yVs,iv:ZGfJy6C3yRdnXonhN5xIVVqFtycW1MI000WdUTzghRM=,tag:F+Z8+BpJrV+dGtW+A0298w==,type:str]
github_app_installation_id: ENC[AES256_GCM,data:xli7LTqZGEs=,iv:BRRVqsjBUqzr8YsWpG0uJ/Xau8D3vkWCNv1DxJCf5nY=,tag:Q6+cGhUYOt+O2nO/vNZd1A==,type:str]
github_app_private_key: ENC[AES256_GCM,data:5rqd/MsKMMDGVZFCs9NALjBDlVbCUJGdRntKevw7DxoNqxnY9ZWI60ie6j+YrhPpm02ltK7xmtHkjmkAheJ5jRAPm0rFyGyleVKOGfCHOcUiODbS0LsTxYbb23cg4JHNDO2LyET9/U2iKg5QRqIQizxNV+xEa6ia9WybID7Fl+OyP1WISJXugxY7BoeE1TtiNn14Awv8uBNnJ5sZ2A6PVnsCfz5rGfln9H8apLF/yuO/PHsL/lrlfeLqRLplPNCA799lpoMk8ZOgIIv+VPT+j/o8aFNJczI8Gicfw4+Uz+z4XHRcNO4QcEp26HL0UP0F7fgJtBtfC9Bl9aqRKh4eN/PAIB85lYewt3vAVDeuc9SXmhUscwpomIxnucs3A+75UR58uPglRVpvb6JmfiXbchDZW2JvNTQX21XkD5ysqFJec/guB//DXDdLYmor1wN6vWvolMMQYGSvOql79Up5JoRMrWa+5rLErqIBMQH5CdbFXjNvOAWP4LwnUYGTGQdk80R/xTEHnxmcZkbydyB/oeiFjWEHTNlI36dJq392tnDbf//86pL/rEbG9Xreio6efzqYat43xpofeXwPKTDrZjF8VRLUHk/rdQaJ1XeD0tkm07D4ADxNURqwUMPswMa/Bpm4AC8/MprTofxUIzNPtEIecIaMnid1zUAzXDSHh0fE8MBFbJdIJMZww8AA5A/D4fNg/icIBEaZUMw2BJ9KT3TaC1lfVEBy0Q8XDACQi0k3bpVHHOLHjxLt9EJsNT8ouNxxsNmOxYJ2tii6LquXqExIWf8grGPrggclQyrlOc2a5KatjQYyHrpHb80trHxxtHiNrAiTViiAuNxW6VmmMLfMuzy4o4osPYKxFQ5Ano4YaoUWi0e5PpHpHOjKIAdMwRbHVql/qb6rNkeS+7FK07qFyFx/4jaxkZxMh8pjUBSyWN66t7cEW2QMf1/DVO64pv0E0vFTTYg7BP2RAOkJJq9jF0exV1IYrRgw4nLk2wJWQhx//kF3wvhj17iCMqOYmgULXym5Yev3hGy2kypfX8fgkJXSHa4+i9Np3t26sPcAt+BEdKroyEQe1D86QFDbC1Kmljn0SvP18NfqqFnqetuNo4iQRbztxiW3sqMOZKnK0ynoyBSqoI53/ki6VbYD/HkmgOFUAPiGFoNGaxrICkKsNuo23v5gSqza9eeCeld/FcWQB18hTq7DiG9XAQSocV3RryebHbWJ79GxSGVZD0zSZxA2PDjAK0/Sudiza305nMnxnIcZ+Egf5wHlHwGKxejaBYs1NCZ9KwOaQvoqBiTSQqASUt1suXYIlysQl6v1hKmuJek6UpCM7744boHs8UGaKgLPwproXjBuxl4iOgXHObSxrzcFjTlf8kDHwGowRYCz+qrXHsQIvjlKjatOP4dcZc8PNWkfb6jHsCaIHiHwwI9vAZnD/Q70I438qhtdJ2ZQJLQ3hn7cCz6R+SCxUOSoxPFHFHIrUzaEX1ISsWiAJFsxgA9uLvOXwWbaJNeJTIVEm9/rdfA0efaW5AJwDioTflX18fE4aQ6tbP6Vf3XkXFZA0jrY4n8geoXsARV3drEDPl81PL7lxFgYyQXqGxmN1Lv31IwQYZwpk0TGqsuAoMc9ctjGW7qMn2dUjPBnNfo1gcqfOPZJZwBd1ElFecGMGlZM4v1bTHCGf17bV1EseypmpXHnFHmgItSUeL6INpwlaOO0jT7qgH0BPNOh8xvTU038ggS4TrMQgwnKsjTeqN5WdRyLVu3k1G8HMq+UYCF1Hl+Q+n8r1ltMKVBMhBaq6myDtrZnulPPRtXvec3ImtgBUdjhpemevyMf1kwjoprG0IWFEMYAXqdRbXL2uOTPg1hDa1u7kjCBQIyLNIwAArD0HdpNE6odWCkyITjwPq+faCZdtULdgbit+HhqEmjWW0qZcwlHBV0Ex+GRpmHZBcGh2vH6HRthk6a0ojFL12/oQ9ed5c8fbAbxOYTd+TEE8ikGPKC2kQrfrA0rpwOYMEQ2umSQ2LFBhp7gFCeF5csBddeZtDzrKzvItYs6x/VpXD9v6cDUoywZT2nAB4tf+UTiC8+NkLtxzE8YUNLt0FJqTY9/sPt2tIa1Vq0ZvgOKg+O63Pc+TV+FouIBKJM3C0b7UnmQP7tTBgWH0mcCDYRycxzxaZxCwLGOFR6K6DnJmXwwRSTX3g1RQ+QI1t1UTYXImZntMrKEWmSm8QCUeL7xqqFTsI8S2isiHjo=,iv:JAdFM1sQoNzB6vwi20NeaUpiUrUzvud1oyDtccCl75U=,tag:GvYrU6X19agbdG3dvWabhg==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age1hhurqwmfvl9m3vh3hk8urulfzcdsrep2ax2neazqt435yhpamu3qj20asg
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBHQmtZeUVvaWtSNzZBWHBx
VWxYMjY0MlFSVEN0cjhvQUFxVWNHbFB2cndzCkZURTNGQXBXSm8yT0hvWVR0aDVC
NmVhRDNaUFh4eWYyUTFqRTZIQ2o5QkUKLS0tIHhuM3lFREZyYnhlZ3JKQUJwVEdX
Z3d6U0dVUWhPTDBZcXY4cFNsRGM3cFUKdIPaiHrS/B4zNHpNaxi9zYrOv+HrZ/oP
NVkIbemYIYGKhcqSjRy53EQhIimu0q4oCxal6KkXahVB0edysD9JBQ==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2023-07-08T07:36:24Z"
mac: ENC[AES256_GCM,data:PekWhW0fxXTmE0yrFPfGuuigc9rxjYEH5Aqcy/PrwSu+Qv5sD33s3j3TzuNm8hFEndUnLU5jYfNwgrNaMPiUSLt4TNe7H0+GNYiBY/1DstvrGd3jNUZaarDvmKsDDTS2CIgw9q2rGscT1Px2eCJYUEtVGcFXh4Xxyp4TV7GrmLY=,iv:qRD0sdKNpzSNkxZxxB02ksI8UDKiS7iMh2tgUtFu0Lk=,tag:J2KiMJqf1MQ5ASejKlPJ1Q==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.7.3

View File

@@ -8,6 +8,8 @@ metadata:
labels:
substitution.flux.home.arpa/enabled: "true"
spec:
dependsOn:
- name: cluster-apps-external-secrets-stores
path: ./kubernetes/apps/actions-runner-system/actions-runner-controller/app
prune: true
sourceRef:

View File

@@ -33,6 +33,7 @@ metadata:
spec:
dependsOn:
- name: cluster-apps-cert-manager
- name: cluster-apps-external-secrets-stores
path: ./kubernetes/apps/cert-manager/cert-manager/webhook-ovh
prune: true
sourceRef:

View File

@@ -0,0 +1,18 @@
---
# yaml-language-server: $schema=https://kubernetes-schemas.devbu.io/external-secrets.io/externalsecret_v1beta1.json
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: cert-manager-webhook-ovh
namespace: cert-manager
spec:
secretStoreRef:
kind: ClusterSecretStore
name: onepassword-connect
target:
name: cert-manager-webhook-ovh-secret
creationPolicy: Owner
dataFrom:
- extract:
# applicationKey, applicationSecret, consumerKey
key: cert-manager-webhook-ovh

View File

@@ -40,13 +40,13 @@ spec:
ovhEndpointName: ovh-eu
ovhAuthenticationRef:
applicationKeyRef:
name: ovh-credentials
name: cert-manager-webhook-ovh-secret
key: applicationKey
applicationSecretRef:
name: ovh-credentials
name: cert-manager-webhook-ovh-secret
key: applicationSecret
consumerKeyRef:
name: ovh-credentials
name: cert-manager-webhook-ovh-secret
key: consumerKey
- name: letsencrypt-production
create: true
@@ -56,11 +56,11 @@ spec:
ovhEndpointName: ovh-eu
ovhAuthenticationRef:
applicationKeyRef:
name: ovh-credentials
name: cert-manager-webhook-ovh-secret
key: applicationKey
applicationSecretRef:
name: ovh-credentials
name: cert-manager-webhook-ovh-secret
key: applicationSecret
consumerKeyRef:
name: ovh-credentials
name: cert-manager-webhook-ovh-secret
key: consumerKey

View File

@@ -3,5 +3,5 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./externalsecret.yaml
- ./helmrelease.yaml
- ./secret.sops.yaml

View File

@@ -1,30 +0,0 @@
kind: Secret
apiVersion: v1
metadata:
name: ovh-credentials
namespace: cert-manager
stringData:
applicationKey: ENC[AES256_GCM,data:UYBGsO4gGWA1iPUqVAYnjw==,iv:/rYA+o/EXOLsbU8WUnp53ejYgi+TFb3DJ/fJS6iUjAM=,tag:hEPzYgcefH5iJWS1bF6R5A==,type:str]
applicationSecret: ENC[AES256_GCM,data:QsTdVpgbp/CAqt0mZPRNDINMach/EiM/1+kbgEzxIqE=,iv:/CJVh2tT7wXAdeuxBHN5kM/LidhgGKCTW66hxTcx4QA=,tag:yLw4HpAx7RlZ11LMPMdXtg==,type:str]
consumerKey: ENC[AES256_GCM,data:OmI9kc0tNQWCpM+Bg0oQMdYwhZRsqQDZ87NFpkYFpMo=,iv:7elfo7xvxa57du6IjZRJejdpgIQiSjgoRqhWAtMLzXg=,tag:Zk36lNZ+EcZYAye1W+4gwA==,type:str]
type: Opaque
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age1hhurqwmfvl9m3vh3hk8urulfzcdsrep2ax2neazqt435yhpamu3qj20asg
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSByMWQvSUhwYnFyMHJXVWxQ
cjllMGlCRnRwdGJZRU9DVGdMUHE5ZUQxUEVjCkJnY3NWeDg5MnZOQjN3RDVtOTN2
c1Z0OUNsSm5IZ0k0UGJXRVlVRnRwQzQKLS0tIEtDRGVyN1gyaU9wM3ZLczRVYnBQ
czlyZ2lrYk1LNktxTkZiNUdFb0xHblEKlGExd13zMg6MofRAz+GT9wKL/sEBI6XD
u+dQAsphIoPpptFY0IeehXTLBV8xK4p1Z1/qu6UgJOnQtb2KGYOOvQ==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2022-12-26T23:59:54Z"
mac: ENC[AES256_GCM,data:dnguY6zpQRkj3cV2+CzCdIldBTVGUSIMh5bKoRsJ/cYONp9LjpqGZSmuDfFNRVaWU293M+T12criNH7SndGpquw46YJT48S14g9vi6NeRhK6Rl0z2TbNbtm/7uIUkgmHy1aur8IxfdDdzBScIlq0nfjhcTyYz1RYw/K2bKTwvzA=,iv:TZS0p+IPWqEq9trZxs7FGY7kZ83EaijFH1Kw/IElgjg=,tag:AlIFWcQfDMC9h7sm2WI9zQ==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.7.3

View File

@@ -0,0 +1,36 @@
---
# yaml-language-server: $schema=https://kubernetes-schemas.devbu.io/external-secrets.io/externalsecret_v1beta1.json
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: cloudnative-pg
namespace: default
spec:
secretStoreRef:
kind: ClusterSecretStore
name: onepassword-connect
target:
name: cloudnative-pg-secret
creationPolicy: Owner
template:
engineVersion: v2
metadata:
labels:
cnpg.io/reload: "true"
data:
- secretKey: username
remoteRef:
key: cloudnative-pg
property: POSTGRES_SUPER_USER
- secretKey: password
remoteRef:
key: cloudnative-pg
property: POSTGRES_SUPER_PASS
- secretKey: aws-access-key-id
remoteRef:
key: cloudnative-pg
property: AWS_ACCESS_KEY_ID
- secretKey: aws-secret-access-key
remoteRef:
key: cloudnative-pg
property: AWS_SECRET_ACCESS_KEY

View File

@@ -4,8 +4,8 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: default
resources:
- ./externalsecret.yaml
- ./helmrelease.yaml
- ./secret.sops.yaml
configMapGenerator:
- name: cloudnative-pg-dashboard
files:

View File

@@ -1,29 +0,0 @@
apiVersion: v1
kind: Secret
type: kubernetes.io/basic-auth
metadata:
name: postgres-superuser
namespace: default
stringData:
username: ENC[AES256_GCM,data:oMwUm7mTJ3U=,iv:hfa6GmA8uFC1gPs7Z0wAaddOhVeHu8FmANOd9n/fLok=,tag:FIv7VhkHlVLq4Q+k7N2DDw==,type:str]
password: ENC[AES256_GCM,data:LCUuhRW3wjkeVQgefTuh9Q==,iv:07R0ZUrLQe8jPZo3wFn/15fXg8yc/pa+a03tWkSrjjM=,tag:0YoG2EZ3JbihlY98ay/5eg==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age1hhurqwmfvl9m3vh3hk8urulfzcdsrep2ax2neazqt435yhpamu3qj20asg
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBQand1M1U2SytHclJSN1I3
NzdvdjZMQnJPSW9GUXo1SkZ1elRVY1NvK0FJClpiVk9JVWxHSlIwSXZDSWRoOXI4
YkxVeDR5V09OTS92YmpMeUl2a1QyRlUKLS0tIG9iNGJlaDQ3UW1uelFla0cySXRC
SzhQOGRzNnYzcEVjVG0rOUt1T1ZJQkkKtbXybUgBFr69GvBmo8+7J1xrtxJ7y1wo
ZhV6dzuxc2QSd3o9A6f9J/wg9DHtBHviK5nP0K/edHth9darJw/3Eg==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2022-10-25T23:37:50Z"
mac: ENC[AES256_GCM,data:aU5GLUX3Tml3tRZUzRP451X5oeUSEpB2QFp7ys8pnKlskDidWwwy3gCCTeG0gjsmJbYiZqZFS0qnYe5brT1b9gJgQVLTgVA8xcoXMFJnGQfHm+kmqBxfYR2wPyCzE3T/J4/2e01oITuVS5RKtc3/w1L2en8DwttcBBaezh3vRRM=,iv:a11Hm95soVPiALzZSHMkKx+XEdq7PPmVysfhXHY0+pw=,tag:ITVZQw2WSmD9rmU/cSto4w==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.7.3

View File

@@ -27,14 +27,14 @@ spec:
serverName: postgres-v7
s3Credentials:
accessKeyId:
name: postgres-minio
key: MINIO_ACCESS_KEY
name: cloudnative-pg-secret
key: aws-access-key-id
secretAccessKey:
name: postgres-minio
key: MINIO_SECRET_KEY
bootstrap:
recovery:
source: postgres-v6
name: cloudnative-pg-secret
key: aws-secret-access-key
# bootstrap:
# recovery:
# source: postgres-v6
externalClusters:
- name: postgres-v6
barmanObjectStore:

View File

@@ -6,5 +6,4 @@ namespace: default
resources:
- backups
- ./cluster.yaml
- ./secret.sops.yaml
- ./scheduledbackup.yaml

View File

@@ -1,31 +0,0 @@
kind: Secret
apiVersion: v1
type: Opaque
metadata:
name: postgres-minio
namespace: default
labels:
k8s.enterprisedb.io/reload: "true"
stringData:
MINIO_ACCESS_KEY: ENC[AES256_GCM,data:lEOKspQaoN5FxOGSnpQuTAzzHrI=,iv:VJQAWK8Sia/wL4iAdpir5fJxBLP1fDQWqj5pBDO6x/g=,tag:5Jf612CStm7NcW1YdrOq1A==,type:str]
MINIO_SECRET_KEY: ENC[AES256_GCM,data:Saad8zdhNfJdCDM/3cwVAtp/Cx8F0R4AFERJA3xT7ZC7M0GptDVaGg==,iv:DnmbB6VCRa2itDLAYwGL3LkTBQlf4sVwu1O5+ZmuukQ=,tag:fG6XMj/rC3moGKVZJn9PBA==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age1hhurqwmfvl9m3vh3hk8urulfzcdsrep2ax2neazqt435yhpamu3qj20asg
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBQand1M1U2SytHclJSN1I3
NzdvdjZMQnJPSW9GUXo1SkZ1elRVY1NvK0FJClpiVk9JVWxHSlIwSXZDSWRoOXI4
YkxVeDR5V09OTS92YmpMeUl2a1QyRlUKLS0tIG9iNGJlaDQ3UW1uelFla0cySXRC
SzhQOGRzNnYzcEVjVG0rOUt1T1ZJQkkKtbXybUgBFr69GvBmo8+7J1xrtxJ7y1wo
ZhV6dzuxc2QSd3o9A6f9J/wg9DHtBHviK5nP0K/edHth9darJw/3Eg==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2022-10-25T23:37:42Z"
mac: ENC[AES256_GCM,data:VZ5+kUZsCJxiWV7JS+Enhi0yNJ6m+Oi5IurYNxI0gb2+CqENqn4uvOSNMgKTZAc3d/stuI5OGdBbRJo0aBu0hZ950cgbGV6gfEbzzTO9HRstgAwqnEZHj6DPRLcXkCs0jP1p2p0WICe2HZ113C2aN3MjP47J1Jau3yaJlGOsOuU=,iv:EaxUx+ivqYgBm1wUXsCscoJt7x6+3pSM0QZY8h9eI6U=,tag:Q5ix3VW7C2rgm2R3AMDuDA==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.7.3

View File

@@ -8,6 +8,8 @@ metadata:
labels:
substitution.flux.home.arpa/enabled: "true"
spec:
dependsOn:
- name: cluster-apps-external-secrets-stores
path: ./kubernetes/apps/default/cloudnative-pg/app
prune: true
sourceRef:
@@ -33,7 +35,6 @@ metadata:
spec:
dependsOn:
- name: cluster-apps-cloudnative-pg-app
- name: cluster-apps-kyverno
path: ./kubernetes/apps/default/cloudnative-pg/cluster
prune: true
sourceRef: