#!/usr/bin/env bash # Generates apps/vikunja/vikunja-sealedsecret.yaml from a freshly-created random # VIKUNJA_SERVICE_SECRET, sealed with the cluster's sealed-secrets controller. # # Run from the repository root: # apps/vikunja/generate-secret.sh # # Requirements: kubectl (with access to the cluster), kubeseal, openssl. # The real secret value is never printed to stdout. set -euo pipefail REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)" OUT="${REPO_ROOT}/apps/vikunja/vikunja-sealedsecret.yaml" NAMESPACE="vikunja" SECRET_NAME="vikunja-secret" # Controller is deployed as: kubectl -n kube-system get svc sealed-secrets-controller CONTROLLER_NAME="${SEALED_SECRETS_CONTROLLER_NAME:-sealed-secrets-controller}" CONTROLLER_NAMESPACE="${SEALED_SECRETS_CONTROLLER_NAMESPACE:-kube-system}" # Build the Secret object client-side only (nothing is applied to the cluster), # then seal it. kubeseal carries the secret name/namespace into the output's # spec.template so the controller recreates the Secret with the right metadata. SECRET="$(openssl rand -hex 64)" kubectl create secret generic "${SECRET_NAME}" \ --namespace "${NAMESPACE}" \ --from-literal=VIKUNJA_SERVICE_SECRET="${SECRET}" \ --dry-run=client -o yaml \ | kubeseal \ --controller-name "${CONTROLLER_NAME}" \ --controller-namespace "${CONTROLLER_NAMESPACE}" \ --format yaml \ --namespace "${NAMESPACE}" \ --name "${SECRET_NAME}" \ > "${OUT}" unset SECRET echo "Wrote ${OUT}" echo "Commit the generated file before Argo CD syncs the vikunja app."