Add Vikunja deployment
This commit is contained in:
Executable
+40
@@ -0,0 +1,40 @@
|
||||
#!/usr/bin/env bash
|
||||
# Generates apps/vikunja/vikunja-sealedsecret.yaml from a freshly-created random
|
||||
# VIKUNJA_SERVICE_SECRET, sealed with the cluster's sealed-secrets controller.
|
||||
#
|
||||
# Run from the repository root:
|
||||
# apps/vikunja/generate-secret.sh
|
||||
#
|
||||
# Requirements: kubectl (with access to the cluster), kubeseal, openssl.
|
||||
# The real secret value is never printed to stdout.
|
||||
set -euo pipefail
|
||||
|
||||
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
|
||||
OUT="${REPO_ROOT}/apps/vikunja/vikunja-sealedsecret.yaml"
|
||||
NAMESPACE="vikunja"
|
||||
SECRET_NAME="vikunja-secret"
|
||||
# Controller is deployed as: kubectl -n kube-system get svc sealed-secrets-controller
|
||||
CONTROLLER_NAME="${SEALED_SECRETS_CONTROLLER_NAME:-sealed-secrets-controller}"
|
||||
CONTROLLER_NAMESPACE="${SEALED_SECRETS_CONTROLLER_NAMESPACE:-kube-system}"
|
||||
|
||||
# Build the Secret object client-side only (nothing is applied to the cluster),
|
||||
# then seal it. kubeseal carries the secret name/namespace into the output's
|
||||
# spec.template so the controller recreates the Secret with the right metadata.
|
||||
SECRET="$(openssl rand -hex 64)"
|
||||
|
||||
kubectl create secret generic "${SECRET_NAME}" \
|
||||
--namespace "${NAMESPACE}" \
|
||||
--from-literal=VIKUNJA_SERVICE_SECRET="${SECRET}" \
|
||||
--dry-run=client -o yaml \
|
||||
| kubeseal \
|
||||
--controller-name "${CONTROLLER_NAME}" \
|
||||
--controller-namespace "${CONTROLLER_NAMESPACE}" \
|
||||
--format yaml \
|
||||
--namespace "${NAMESPACE}" \
|
||||
--name "${SECRET_NAME}" \
|
||||
> "${OUT}"
|
||||
|
||||
unset SECRET
|
||||
|
||||
echo "Wrote ${OUT}"
|
||||
echo "Commit the generated file before Argo CD syncs the vikunja app."
|
||||
Reference in New Issue
Block a user