Files
nextgen-be/manifests/secrets.example.yaml

47 lines
1.5 KiB
YAML

# ⚠️ TESTING ONLY — DO NOT COMMIT THIS FILE TO GIT ⚠️
# This file contains (or will contain) plaintext secret values.
# Add "secrets.yaml" to .gitignore before you ever `git add` this directory.
# Once everything works, replace this with Sealed Secrets / SOPS per the
# earlier discussion — this file is a shortcut for getting unblocked now.
apiVersion: v1
kind: Secret
metadata:
name: nextgen-be-db
namespace: nextgen-be
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-2"
type: Opaque
stringData:
# Get this value with:
# kubectl get secret postgresql-prod-app -n postgresql -o jsonpath='{.data.uri}' | base64 -d
DATABASE_URL: "postgresql://radius:kVwBYXzIfS8ZENgEZ0kdql0O9k75d6nflBcPTB5clj1iOmgxNtisIkKychusIQ7k@postgresql-prod-rw.postgresql:5432/radius"
---
apiVersion: v1
kind: Secret
metadata:
name: nextgen-be-jwt
namespace: nextgen-be
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-2"
type: Opaque
stringData:
# Generate with: openssl rand -hex 32
SECRET_KEY: "f0e2684aab93f96557fc2b63ba55e790222d5c516c4dbb3de75d0a2fcc6d0a9b"
---
apiVersion: v1
kind: Secret
metadata:
name: nextgen-be-radius
namespace: nextgen-be
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-2"
type: Opaque
stringData:
# Must match the shared secret configured on the FreeRADIUS side
# (rotate this value before going anywhere near production)
RADIUS_CLIENT_SECRET: "aloulou"