--- # yaml-language-server: $schema=https://kubernetes-schemas.devbu.io/external-secrets.io/externalsecret_v1beta1.json apiVersion: external-secrets.io/v1beta1 kind: ExternalSecret metadata: name: attic namespace: default spec: secretStoreRef: kind: ClusterSecretStore name: onepassword-connect target: name: attic-secret creationPolicy: Owner template: engineVersion: v2 data: # App ATTIC_SERVER_TOKEN_HS256_SECRET_BASE64: "{{ .ATTIC_SERVER_TOKEN_HS256_SECRET_BASE64 }}" ATTIC_SERVER_DATABASE_URL: "postgresql://{{ .POSTGRES_USER }}:{{ .POSTGRES_PASS }}@postgres-rw.default.svc.cluster.local:5432/attic" AWS_ACCESS_KEY_ID: "{{ .ATTIC_AWS_ACCESS_KEY_ID }}" AWS_SECRET_ACCESS_KEY: "{{ .AWS_SECRET_ACCESS_KEY }}" # Postgres Init INIT_POSTGRES_DBNAME: attic INIT_POSTGRES_HOST: postgres-rw.default.svc.cluster.local INIT_POSTGRES_USER: "{{ .POSTGRES_USER }}" INIT_POSTGRES_PASS: "{{ .POSTGRES_PASS }}" INIT_POSTGRES_SUPER_PASS: "{{ .POSTGRES_SUPER_PASS }}" dataFrom: - extract: key: attic - extract: key: cloudnative-pg