--- # yaml-language-server: $schema=https://kubernetes-schemas.devbu.io/external-secrets.io/externalsecret_v1beta1.json apiVersion: external-secrets.io/v1beta1 kind: ExternalSecret metadata: name: semaphore namespace: default spec: secretStoreRef: kind: ClusterSecretStore name: onepassword-connect target: name: semaphore-secret creationPolicy: Owner template: data: # Ansible Semaphore SEMAPHORE_DB_USER: &dbUser "{{ .POSTGRES_USER }}" SEMAPHORE_DB_PASS: &dbPass "{{ .POSTGRES_PASS }}" SEMAPHORE_DB_HOST: &dbHost postgres-rw.default.svc.cluster.local SEMAPHORE_DB_PORT: "5432" SEMAPHORE_DB: &dbName semaphore SEMAPHORE_ADMIN: "{{ .username }}" SEMAPHORE_ADMIN_PASSWORD: "{{ .password }}" SEMAPHORE_ADMIN_NAME: "{{ .SEMAPHORE_ADMIN_NAME }}" SEMAPHORE_ACCESS_KEY_ENCRYPTION: "{{ .SEMAPHORE_ACCESS_KEY_ENCRYPTION }}" # Postgres Init INIT_POSTGRES_DBNAME: *dbName INIT_POSTGRES_HOST: *dbHost INIT_POSTGRES_SUPER_PASS: "{{ .POSTGRES_SUPER_PASS }}" INIT_POSTGRES_USER: *dbUser INIT_POSTGRES_PASS: *dbPass dataFrom: - extract: key: cloudnative-pg - extract: key: semaphore