Files
k3s-homelab/apps/vikunja/generate-secret.sh
T
2026-09-02 12:54:12 -07:00

41 lines
1.5 KiB
Bash
Executable File

#!/usr/bin/env bash
# Generates apps/vikunja/vikunja-sealedsecret.yaml from a freshly-created random
# VIKUNJA_SERVICE_SECRET, sealed with the cluster's sealed-secrets controller.
#
# Run from the repository root:
# apps/vikunja/generate-secret.sh
#
# Requirements: kubectl (with access to the cluster), kubeseal, openssl.
# The real secret value is never printed to stdout.
set -euo pipefail
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
OUT="${REPO_ROOT}/apps/vikunja/vikunja-sealedsecret.yaml"
NAMESPACE="vikunja"
SECRET_NAME="vikunja-secret"
# Controller is deployed as: kubectl -n kube-system get svc sealed-secrets-controller
CONTROLLER_NAME="${SEALED_SECRETS_CONTROLLER_NAME:-sealed-secrets-controller}"
CONTROLLER_NAMESPACE="${SEALED_SECRETS_CONTROLLER_NAMESPACE:-kube-system}"
# Build the Secret object client-side only (nothing is applied to the cluster),
# then seal it. kubeseal carries the secret name/namespace into the output's
# spec.template so the controller recreates the Secret with the right metadata.
SECRET="$(openssl rand -hex 64)"
kubectl create secret generic "${SECRET_NAME}" \
--namespace "${NAMESPACE}" \
--from-literal=VIKUNJA_SERVICE_SECRET="${SECRET}" \
--dry-run=client -o yaml \
| kubeseal \
--controller-name "${CONTROLLER_NAME}" \
--controller-namespace "${CONTROLLER_NAMESPACE}" \
--format yaml \
--namespace "${NAMESPACE}" \
--name "${SECRET_NAME}" \
> "${OUT}"
unset SECRET
echo "Wrote ${OUT}"
echo "Commit the generated file before Argo CD syncs the vikunja app."