189 lines
4.4 KiB
YAML
189 lines
4.4 KiB
YAML
apiVersion: v1
|
|
kind: ServiceAccount
|
|
metadata:
|
|
name: vault-secrets-operator-controller-manager
|
|
namespace: {{ .Release.Namespace }}
|
|
---
|
|
apiVersion: v1
|
|
kind: ServiceAccount
|
|
metadata:
|
|
name: default
|
|
namespace: {{ .Release.Namespace }}
|
|
imagePullSecrets:
|
|
- name: docker-registry-secret
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultConnection
|
|
metadata:
|
|
name: vault-connection-infra-{{ .Release.Namespace }}
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
address: http://vault.{{ .Release.Namespace }}.svc.cluster.local:8200
|
|
skipTLSVerify: true
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultAuth
|
|
metadata:
|
|
name: vault-auth-infra-{{ .Release.Namespace }}
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
vaultConnectionRef: vault-connection-infra-{{ .Release.Namespace }}
|
|
method: kubernetes
|
|
mount: kubernetes
|
|
kubernetes:
|
|
role: shared-role
|
|
serviceAccount: vault-secrets-operator-controller-manager
|
|
audiences:
|
|
- vault
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: kafka-static-user-passwords
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
mount: kvv2
|
|
type: kv-v2
|
|
path: kafka/config
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: kafka-static-user-passwords
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: cassandra-static-user-passwords
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
mount: kvv2
|
|
type: kv-v2
|
|
path: cassandra/config
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: cassandra-static-user-passwords
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: pg-ha-creds
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
mount: kvv2
|
|
type: kv-v2
|
|
path: postgresql-ha/config
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: pg-ha-creds
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: deeplink-secret
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
mount: kvv2
|
|
type: kv-v2
|
|
path: deeplink/config
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: deeplink-secret
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: livekit-secret
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
mount: kvv2
|
|
type: kv-v2
|
|
path: livekit/config
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: livekit-secret
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: s3-static-secret
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
mount: kvv2
|
|
type: kv-v2
|
|
path: s3/config
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: s3-static-secret
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: docker-registry-secret
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
|
mount: kvv2
|
|
path: docker-registry/config
|
|
type: kv-v2
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: docker-registry-secret
|
|
type: kubernetes.io/dockerconfigjson
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: auth-secret
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
mount: kvv2
|
|
type: kv-v2
|
|
path: auth-secret/config
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: auth-secrets
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: co-work-secret
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }}
|
|
mount: kvv2
|
|
path: co-work-secret/config
|
|
type: kv-v2
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: co-work-secret
|
|
type: kubernetes.io/tls
|
|
---
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: recording-secret
|
|
namespace: {{ .Release.Namespace }}
|
|
spec:
|
|
mount: kvv2
|
|
type: kv-v2
|
|
path: recording-secret/config
|
|
refreshAfter: 1h
|
|
destination:
|
|
create: true
|
|
name: recording-secret
|
|
vaultAuthRef: vault-auth-infra-{{ .Release.Namespace }} |