refactor(argocd): simplify secrets approach — use directory source, manual Secrets for Stage 0
Reverts complex CMP plugin setup (helm chart doesn't support repoServer.extraContainers). Instead: sops-secrets Application uses directory source (no plugin), emits placeholder README. Manually-created Secrets (grafana-admin) live in target namespaces. Full CMP plugin work deferred to future stage. Grafana values still wired to admin.existingSecret (no-op until Secret exists, which it now does). This unblocks cluster deployment without waiting for ArgoCD CMP plumbing.
This commit is contained in:
@@ -20,7 +20,6 @@ spec:
|
|||||||
repoURL: http://forgejo.riotpiao.com:3000/riotpiao.com/homelab.git
|
repoURL: http://forgejo.riotpiao.com:3000/riotpiao.com/homelab.git
|
||||||
targetRevision: main
|
targetRevision: main
|
||||||
path: k8s/security/sops-secrets
|
path: k8s/security/sops-secrets
|
||||||
plugin: {}
|
directory: {}
|
||||||
destination:
|
destination:
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
revisionHistoryLimit: 3
|
|
||||||
|
|||||||
@@ -47,15 +47,6 @@ configs:
|
|||||||
g, homelab-admins, role:admin
|
g, homelab-admins, role:admin
|
||||||
policy.default: role:readonly
|
policy.default: role:readonly
|
||||||
|
|
||||||
cmp:
|
|
||||||
plugins:
|
|
||||||
sops-secrets:
|
|
||||||
generate:
|
|
||||||
command: sh
|
|
||||||
args:
|
|
||||||
- -c
|
|
||||||
- /var/run/argocd/plugins/sops-cmp-generate.sh
|
|
||||||
|
|
||||||
server:
|
server:
|
||||||
replicas: 1
|
replicas: 1
|
||||||
deploymentStrategy:
|
deploymentStrategy:
|
||||||
@@ -99,26 +90,6 @@ repoServer:
|
|||||||
enabled: true
|
enabled: true
|
||||||
serviceMonitor:
|
serviceMonitor:
|
||||||
enabled: true
|
enabled: true
|
||||||
extraContainers:
|
|
||||||
- name: sops-cmp
|
|
||||||
image: registry.gitlab.com/argoproj/argocd-helm-charts/argocd-cmp-server:v2.12.1
|
|
||||||
command: [/var/run/argocd/argocd-cmp-server]
|
|
||||||
securityContext:
|
|
||||||
runAsNonRoot: true
|
|
||||||
runAsUser: 999
|
|
||||||
volumeMounts:
|
|
||||||
- mountPath: /var/run/argocd
|
|
||||||
name: var-files
|
|
||||||
- mountPath: /home/argocd/cmp-server/plugins
|
|
||||||
name: plugins
|
|
||||||
- mountPath: /tmp
|
|
||||||
name: tmp
|
|
||||||
- mountPath: /sops-age
|
|
||||||
name: sops-age
|
|
||||||
volumes:
|
|
||||||
- name: sops-age
|
|
||||||
secret:
|
|
||||||
secretName: sops-age
|
|
||||||
|
|
||||||
applicationSet:
|
applicationSet:
|
||||||
replicas: 1
|
replicas: 1
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
# SOPS-Decrypted Secrets
|
||||||
|
|
||||||
|
Placeholder for CMP-generated secrets (pending full CMP plugin setup).
|
||||||
|
|
||||||
|
Currently, manually-created Secrets live in individual namespaces (e.g., grafana-admin in logging/).
|
||||||
|
Once the CMP plugin is wired, this Application will decode *.enc.yaml and emit all Secrets here.
|
||||||
Reference in New Issue
Block a user