fix: move LLM config to encrypted ConfigMap (CI-friendly)
Problem: LLM_API_URL hardcoded to external HTTPS endpoint - https://api.riotpiao.com/v1/chat/completions (TLS hairpin through nginx) - Not externalizable for CI or environment-specific deployment Solution: Move to SOPS-encrypted ConfigMap with in-cluster endpoint - LLM_API_URL: http://api-gateway.api.svc.cluster.local:8080/v1/chat/completions - No TLS overhead, direct cluster communication - Encrypted for security (SOPS + age key) - Externalizable: CI can update values without app redeployment Changes: 1. Create configmap.enc.yaml (SOPS-encrypted) - Data: LLM_API_URL, LLM_MODEL - Encrypted with .sops.yaml age key 2. Update deployment.yaml - Change from 'value:' to 'valueFrom: configMapKeyRef' - Reference portfolio-llm-config ConfigMap 3. Update kustomization.yaml - Add configmap.enc.yaml to resources - Add sops: version: 3 for decryption Benefits: - ArgoCD auto-decrypts via SOPS before applying - CI can auto-patch ConfigMap without app changes - Environment-specific config (dev/staging/prod) - Secrets encrypted in git (never plain text)
This commit is contained in:
@@ -3,6 +3,11 @@ kind: Kustomization
|
||||
namespace: portfolio
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- configmap.enc.yaml
|
||||
- deployment.yaml
|
||||
- service.yaml
|
||||
- ingress.yaml
|
||||
|
||||
# Decrypt secrets via SOPS before applying
|
||||
sops:
|
||||
version: 3
|
||||
|
||||
Reference in New Issue
Block a user