apiVersion: v1 kind: Secret metadata: name: poimen-memory-auth namespace: poimen labels: app.kubernetes.io/name: poimen-memory type: Opaque stringData: # Authentik Service Account - OAuth2 client credentials # These are obtained from Authentik admin panel: # Settings → Applications → poimen-memory → Service Account AUTHENTIK_ISSUER: "https://authentik.riotpiao.com/application/o/memory" AUTHENTIK_AUDIENCE: "poimen-memory" AUTHENTIK_CLIENT_ID: "${AUTHENTIK_SERVICE_ACCOUNT_CLIENT_ID}" AUTHENTIK_CLIENT_SECRET: "${AUTHENTIK_SERVICE_ACCOUNT_SECRET}" # LLM API Key # Generated by Authentik service account with permissions to LLM gateway LLM_API_KEY: "${LLM_API_KEY_FROM_AUTHENTIK}" # S3 Credentials for backups (Velero) S3_ACCESS_KEY: "${MINIO_ACCESS_KEY}" S3_SECRET_KEY: "${MINIO_SECRET_KEY}"