work getting pg cluster root pass in place
This commit is contained in:
parent
d049799ae3
commit
4ff30eff67
|
|
@ -3,3 +3,4 @@ kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
- pg-cluster.yaml
|
- pg-cluster.yaml
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
|
- secret.yaml
|
||||||
|
|
|
||||||
|
|
@ -8,3 +8,6 @@ spec:
|
||||||
|
|
||||||
storage:
|
storage:
|
||||||
size: 20Gi
|
size: 20Gi
|
||||||
|
|
||||||
|
superuserSecret:
|
||||||
|
name: pg-cluster-root-password
|
||||||
|
|
|
||||||
23
infrastructure/databases/cnpg-clusters/secret.yaml
Normal file
23
infrastructure/databases/cnpg-clusters/secret.yaml
Normal file
|
|
@ -0,0 +1,23 @@
|
||||||
|
apiVersion: external-secrets.io/v1
|
||||||
|
kind: ExternalSecret
|
||||||
|
metadata:
|
||||||
|
name: pg-cluster-secrets
|
||||||
|
namespace: pg-databases
|
||||||
|
spec:
|
||||||
|
refreshInterval: 1h
|
||||||
|
secretStoreRef:
|
||||||
|
name: bitwarden
|
||||||
|
kind: ClusterSecretStore
|
||||||
|
target:
|
||||||
|
name: pg-cluster-secrets
|
||||||
|
creationPolicy: Owner
|
||||||
|
template:
|
||||||
|
engineVersion: v2
|
||||||
|
mergePolicy: Merge
|
||||||
|
data:
|
||||||
|
password: '{{ index . "pg-cluster-root-password" }}'
|
||||||
|
data:
|
||||||
|
- secretKey: pg-cluster-root-password
|
||||||
|
remoteRef:
|
||||||
|
key: pg-cluster-root-password
|
||||||
|
property: password
|
||||||
Loading…
Reference in a new issue