# Template only -- the real value lives in vikunja-sealedsecret.yaml, which is # produced by apps/vikunja/generate-secret.sh (sealed with the cluster's # sealed-secrets key). Do not commit this as a live secret. # # VIKUNJA_SERVICE_SECRET signs Vikunja JWTs and other cryptographic data. Without a # stable value Vikunja would generate a new random secret on every restart, # invalidating all issued session tokens. Use at least 64 hex chars (the generator # uses `openssl rand -hex 64`). apiVersion: v1 kind: Secret metadata: name: vikunja-secret namespace: vikunja type: Opaque stringData: VIKUNJA_SERVICE_SECRET: "REPLACE_WITH_LONG_RANDOM_HEX"