--- # yaml-language-server: $schema=https://kubernetes-schemas.devbu.io/external-secrets.io/externalsecret_v1beta1.json apiVersion: external-secrets.io/v1beta1 kind: ExternalSecret metadata: name: gitea namespace: default spec: secretStoreRef: kind: ClusterSecretStore name: onepassword-connect target: name: gitea-secret creationPolicy: Owner template: engineVersion: v2 data: # App GITEA_ADMIN_EMAIL: "{{ .GITEA_ADMIN_EMAIL }}" GITEA_ADMIN_PASSWORD: "{{ .GITEA_ADMIN_PASSWORD }}" GITEA_AWS_S3_ACCESS_KEY: "{{ .GITEA_AWS_S3_ACCESS_KEY }}" GITEA_AWS_S3_SECRET_KEY: "{{ .GITEA_AWS_S3_SECRET_KEY }}" GITEA_DEPLOYMENT_PRIVATE_KEY: "{{ .GITEA_DEPLOYMENT_PRIVATE_KEY }}" POSTGRES_USERNAME: &dbUser "{{ .POSTGRES_USERNAME }}" POSTGRES_PASSWORD: &dbPass "{{ .POSTGRES_PASSWORD }}" # Postgres Init INIT_POSTGRES_DBNAME: gitea INIT_POSTGRES_HOST: postgres-rw.default.svc.cluster.local INIT_POSTGRES_USER: *dbUser INIT_POSTGRES_PASS: *dbPass INIT_POSTGRES_SUPER_PASS: "{{ .POSTGRES_SUPER_PASS }}" dataFrom: - extract: key: cloudnative-pg - extract: key: gitea