Files
homelab/k8s/bootstrap/phase4-argocd/argocd-cmp-cm.yaml
T

31 lines
946 B
YAML

# ArgoCD CMP plugin for SOPS secret decryption
apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-cmp-cm
namespace: argocd
data:
sops-secrets-v1.0.yaml: |
apiVersion: argoproj.io/v1alpha1
kind: ConfigManagementPlugin
metadata:
name: sops-secrets-v1.0
spec:
generate:
command: [sh, -c]
args:
- |
# Find all .enc.yaml files and decrypt them, separating multi-doc output.
# Skip files that aren't full K8s manifests (no top-level "kind:") — some
# .enc.yaml files hold raw Helm values, not standalone Secret objects.
find . -name '*.enc.yaml' -type f | while read -r file; do
decrypted=$(sops -d "$file")
if echo "$decrypted" | grep -q '^kind:'; then
echo "---"
echo "$decrypted"
fi
done
discover:
find:
glob: "**/*.enc.yaml"