41 lines
1.5 KiB
Bash
Executable File
41 lines
1.5 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Generates apps/vikunja/vikunja-sealedsecret.yaml from a freshly-created random
|
|
# VIKUNJA_SERVICE_SECRET, sealed with the cluster's sealed-secrets controller.
|
|
#
|
|
# Run from the repository root:
|
|
# apps/vikunja/generate-secret.sh
|
|
#
|
|
# Requirements: kubectl (with access to the cluster), kubeseal, openssl.
|
|
# The real secret value is never printed to stdout.
|
|
set -euo pipefail
|
|
|
|
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
|
|
OUT="${REPO_ROOT}/apps/vikunja/vikunja-sealedsecret.yaml"
|
|
NAMESPACE="vikunja"
|
|
SECRET_NAME="vikunja-secret"
|
|
# Controller is deployed as: kubectl -n kube-system get svc sealed-secrets-controller
|
|
CONTROLLER_NAME="${SEALED_SECRETS_CONTROLLER_NAME:-sealed-secrets-controller}"
|
|
CONTROLLER_NAMESPACE="${SEALED_SECRETS_CONTROLLER_NAMESPACE:-kube-system}"
|
|
|
|
# Build the Secret object client-side only (nothing is applied to the cluster),
|
|
# then seal it. kubeseal carries the secret name/namespace into the output's
|
|
# spec.template so the controller recreates the Secret with the right metadata.
|
|
SECRET="$(openssl rand -hex 64)"
|
|
|
|
kubectl create secret generic "${SECRET_NAME}" \
|
|
--namespace "${NAMESPACE}" \
|
|
--from-literal=VIKUNJA_SERVICE_SECRET="${SECRET}" \
|
|
--dry-run=client -o yaml \
|
|
| kubeseal \
|
|
--controller-name "${CONTROLLER_NAME}" \
|
|
--controller-namespace "${CONTROLLER_NAMESPACE}" \
|
|
--format yaml \
|
|
--namespace "${NAMESPACE}" \
|
|
--name "${SECRET_NAME}" \
|
|
> "${OUT}"
|
|
|
|
unset SECRET
|
|
|
|
echo "Wrote ${OUT}"
|
|
echo "Commit the generated file before Argo CD syncs the vikunja app."
|