chore(k8s-peterg): Switch to Vault secretstore

This commit is contained in:
Peter 2026-01-27 16:15:13 +01:00
parent 10b1c1efd0
commit 229739f938
Signed by: Peter
SSH key fingerprint: SHA256:B5tYaxBExaDm74r1px9iVeZ6F/ZDiyiy9SbBqfZYrvg
6 changed files with 56 additions and 21 deletions

View file

@ -10,7 +10,7 @@ spec:
kubernetes.io/metadata.name: kube-system
externalSecretSpec:
secretStoreRef:
name: 1password-wheatley
name: vault-wheatley
kind: ClusterSecretStore
target:
name: tls-wildcard-peterg-nl
@ -20,15 +20,11 @@ spec:
tls.crt: "{{ .crt }}"
tls.key: "{{ .key }}"
data:
- secretKey: key
remoteRef:
key: tls-wildcard-peterg-nl/key
metadataPolicy: None
conversionStrategy: Default
decodingStrategy: None
- secretKey: crt
remoteRef:
key: tls-wildcard-peterg-nl/crt
metadataPolicy: None
conversionStrategy: Default
decodingStrategy: None
key: secrets/provisioned/tls-wildcard-peterg-nl
property: crt
- secretKey: key
remoteRef:
key: secrets/provisioned/tls-wildcard-peterg-nl
property: key

View file

@ -3,5 +3,12 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../../kustomize-bases/external-secrets-operator
- clustersecrets.yaml
- namespace.yaml
- secretstore.yaml
helmCharts:
- name: external-secrets
repo: https://charts.external-secrets.io
namespace: external-secrets
releaseName: external-secrets
version: 1.0.0

View file

@ -0,0 +1,5 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: external-secrets

View file

@ -0,0 +1,23 @@
---
apiVersion: external-secrets.io/v1beta1
kind: ClusterSecretStore
metadata:
name: vault-wheatley
spec:
provider:
vault:
server: "https://vault.wheatley.in"
namespace: "wheatley"
path: "kv/k8s-peterg"
version: "v2"
auth:
appRole:
path: approle
roleRef:
namespace: secret-operator
name: vault-wheatley-approle
key: approle_id
secretRef:
namespace: secret-operator
name: vault-wheatley-approle
key: approle_secret