Files
auricom-home-cluster/kubernetes/apps/default/tandoor/app/externalsecret.yaml
2025-04-15 23:09:59 +02:00

45 lines
1.2 KiB
YAML

---
# yaml-language-server: $schema=https://kubernetes-schemas.pages.dev/external-secrets.io/externalsecret_v1.json
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: tandoor
spec:
secretStoreRef:
kind: ClusterSecretStore
name: onepassword-connect
target:
name: tandoor-secret
template:
data:
SECRET_KEY: "{{ .TANDOOR_SECRET_KEY }}"
dataFrom:
- extract:
key: cloudnative-pg
- extract:
key: tandoor
---
# yaml-language-server: $schema=https://kubernetes-schemas.pages.dev/external-secrets.io/externalsecret_v1.json
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: tandoor-db
spec:
secretStoreRef:
kind: ClusterSecretStore
name: crunchy-pgo-secrets
target:
name: tandoor-db-secret
template:
engineVersion: v2
data:
DB_ENGINE: django.db.backends.postgresql_psycopg2
POSTGRES_HOST: '{{ index . "host" }}'
POSTGRES_PORT: '{{ index . "port" }}'
POSTGRES_DB: '{{ index . "dbname" }}'
POSTGRES_USER: '{{ index . "user" }}'
POSTGRES_PASSWORD: '{{ index . "password" }}'
dataFrom:
- extract:
key: postgres-pguser-tandoor