Encrypt DATABASE_URL with age-based SOPS encryption.
File: k8s/test/db-credentials.enc.yaml
- Contains DATABASE_URL with database credentials
- Encrypted with age (SOPS)
- ArgoCD+KSOPS plugin decrypts at deploy time
- Safe to commit to git - no plaintext secrets
Usage in K8s Job:
kubectl apply -f k8s/test/db-credentials.enc.yaml
ArgoCD will decrypt via KSOPS plugin before applying
To view decrypted content:
sops -d k8s/test/db-credentials.enc.yaml
To edit:
sops k8s/test/db-credentials.enc.yaml
Add proper integration test infrastructure:
migrations/run_migrations.sh:
- Database migration runner (used by K8s Job)
- Applies all SQL migrations in order
- Waits for DB to be ready
- Verifies schema creation
- Reports success/failure
k8s/test/integration-test-job.yaml:
- Kubernetes Job manifest for E2E testing
- Two-stage execution:
1. migrate: Apply database migrations
2. test: Run integration test against new pod
- Uses new image SHA from CI build
- Proper secret management via K8s secretKeyRef
(passwords stored in cluster, not in manifests)
- Resource limits and liveness probes
- Cleanup after 1 hour (ttlSecondsAfterFinished)
.gitea/workflows/integration-test.yaml:
- CI workflow that runs after image build
- Validates image exists in registry
- Deploys Job with correct image SHA
- Waits for job completion (10 min timeout)
- Collects pod logs on failure
- Automatic cleanup
Security:
• No plaintext credentials in manifests
• Uses K8s secretKeyRef for DB password
• All secrets encrypted with SOPS/Age (ArgoCD plugin)
• Never embed credentials in git
Usage:
- Automatic: Runs after each CI build on main
- Manual: Trigger with specific image SHA via workflow_dispatch
- Tests: Full E2E ingest + persistence + query
URGENT: Rotate memory-db-app password
(was visible in debugging shell history)