Edit vault-setup.yml added auth-secret, recording-secret
This commit is contained in:
parent
6e6781ccbd
commit
4527db068b
@ -4,22 +4,30 @@ metadata:
|
||||
name: vault-secrets-operator-controller-manager
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: default
|
||||
namespace: {{ .Release.Namespace }}
|
||||
imagePullSecrets:
|
||||
- name: docker-registry-secret
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultConnection
|
||||
metadata:
|
||||
name: vault-connection-infra
|
||||
name: vault-connection-infra-{{ .Release.Namespace }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
address: http://vault:8200
|
||||
address: http://vault.{{ .Release.Namespace }}.svc.cluster.local:8200
|
||||
skipTLSVerify: true
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultAuth
|
||||
metadata:
|
||||
name: vault-auth-infra
|
||||
name: vault-auth-infra-{{ .Release.Namespace }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
vaultConnectionRef: vault-connection-infra
|
||||
vaultConnectionRef: vault-connection-infra-{{ .Release.Namespace }}
|
||||
method: kubernetes
|
||||
mount: kubernetes
|
||||
kubernetes:
|
||||
@ -30,22 +38,6 @@ spec:
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: co-work-secret
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
mount: kvv2
|
||||
type: kv-v2
|
||||
path: tls-secret/config
|
||||
refreshAfter: 5m
|
||||
destination:
|
||||
create: true
|
||||
name: co-work-secret
|
||||
type: kubernetes.io/tls
|
||||
vaultAuthRef: vault-auth-infra
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: kafka-static-user-passwords
|
||||
namespace: {{ .Release.Namespace }}
|
||||
@ -53,11 +45,11 @@ spec:
|
||||
mount: kvv2
|
||||
type: kv-v2
|
||||
path: kafka/config
|
||||
refreshAfter: 5m
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: kafka-static-user-passwords
|
||||
vaultAuthRef: vault-auth-infra
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
@ -68,11 +60,11 @@ spec:
|
||||
mount: kvv2
|
||||
type: kv-v2
|
||||
path: cassandra/config
|
||||
refreshAfter: 5m
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: cassandra-static-user-passwords
|
||||
vaultAuthRef: vault-auth-infra
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
@ -83,11 +75,11 @@ spec:
|
||||
mount: kvv2
|
||||
type: kv-v2
|
||||
path: postgresql-ha/config
|
||||
refreshAfter: 5m
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: pg-ha-creds
|
||||
vaultAuthRef: vault-auth-infra
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
@ -98,11 +90,11 @@ spec:
|
||||
mount: kvv2
|
||||
type: kv-v2
|
||||
path: deeplink/config
|
||||
refreshAfter: 5m
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: deeplink-secret
|
||||
vaultAuthRef: vault-auth-infra
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
@ -113,11 +105,11 @@ spec:
|
||||
mount: kvv2
|
||||
type: kv-v2
|
||||
path: livekit/config
|
||||
refreshAfter: 5m
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: livekit-secret
|
||||
vaultAuthRef: vault-auth-infra
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
@ -128,8 +120,70 @@ spec:
|
||||
mount: kvv2
|
||||
type: kv-v2
|
||||
path: s3/config
|
||||
refreshAfter: 5m
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: s3-static-secret
|
||||
vaultAuthRef: vault-auth-infra
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: docker-registry-secret
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
mount: kvv2
|
||||
path: docker-registry/config
|
||||
type: kv-v2
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: docker-registry-secret
|
||||
type: kubernetes.io/dockerconfigjson
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: auth-secret
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
mount: kvv2
|
||||
type: kv-v2
|
||||
path: auth-secret/config
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: auth-secrets
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: co-work-secret
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
mount: kvv2
|
||||
path: co-work-secret/config
|
||||
type: kv-v2
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: co-work-secret
|
||||
type: kubernetes.io/tls
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: recording-secret
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
mount: kvv2
|
||||
type: kv-v2
|
||||
path: recording-secret/config
|
||||
refreshAfter: 1h
|
||||
destination:
|
||||
create: true
|
||||
name: recording-secret
|
||||
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
||||
Loading…
Reference in New Issue
Block a user