fix: keep microservices doppler token out of gitea
This commit is contained in:
@@ -227,7 +227,6 @@ jobs:
|
|||||||
-e "tailscale_oauth_client_id=${{ secrets.TAILSCALE_OAUTH_CLIENT_ID }}" \
|
-e "tailscale_oauth_client_id=${{ secrets.TAILSCALE_OAUTH_CLIENT_ID }}" \
|
||||||
-e "tailscale_oauth_client_secret=${{ secrets.TAILSCALE_OAUTH_CLIENT_SECRET }}" \
|
-e "tailscale_oauth_client_secret=${{ secrets.TAILSCALE_OAUTH_CLIENT_SECRET }}" \
|
||||||
-e "doppler_hetznerterra_service_token=${{ secrets.DOPPLER_HETZNERTERRA_SERVICE_TOKEN }}" \
|
-e "doppler_hetznerterra_service_token=${{ secrets.DOPPLER_HETZNERTERRA_SERVICE_TOKEN }}" \
|
||||||
-e "doppler_openstaticfish_microservices_service_token=${{ secrets.DOPPLER_MICROSERVICES_SERVICE_TOKEN }}" \
|
|
||||||
-e "ghcr_username=${{ secrets.GHCR_USERNAME }}" \
|
-e "ghcr_username=${{ secrets.GHCR_USERNAME }}" \
|
||||||
-e "ghcr_read_token=${{ secrets.GHCR_READ_TOKEN }}" \
|
-e "ghcr_read_token=${{ secrets.GHCR_READ_TOKEN }}" \
|
||||||
-e "tailscale_api_key=${{ secrets.TAILSCALE_API_KEY }}" \
|
-e "tailscale_api_key=${{ secrets.TAILSCALE_API_KEY }}" \
|
||||||
|
|||||||
@@ -12,12 +12,6 @@
|
|||||||
- ghcr_read_token | default("") | length > 0
|
- ghcr_read_token | default("") | length > 0
|
||||||
fail_msg: ghcr_username and ghcr_read_token must be provided for private MicroServices image pulls.
|
fail_msg: ghcr_username and ghcr_read_token must be provided for private MicroServices image pulls.
|
||||||
|
|
||||||
- name: Ensure OpenStaticFish MicroServices Doppler token is provided
|
|
||||||
assert:
|
|
||||||
that:
|
|
||||||
- doppler_openstaticfish_microservices_service_token | default("") | length > 0
|
|
||||||
fail_msg: doppler_openstaticfish_microservices_service_token must be provided for MicroServices runtime secrets.
|
|
||||||
|
|
||||||
- name: Ensure external-secrets namespace exists
|
- name: Ensure external-secrets namespace exists
|
||||||
shell: kubectl create namespace external-secrets --dry-run=client -o yaml | kubectl apply -f -
|
shell: kubectl create namespace external-secrets --dry-run=client -o yaml | kubectl apply -f -
|
||||||
changed_when: true
|
changed_when: true
|
||||||
@@ -34,14 +28,6 @@
|
|||||||
changed_when: true
|
changed_when: true
|
||||||
no_log: true
|
no_log: true
|
||||||
|
|
||||||
- name: Apply OpenStaticFish MicroServices Doppler service token secret
|
|
||||||
shell: >-
|
|
||||||
kubectl -n external-secrets create secret generic doppler-openstaticfish-microservices-service-token
|
|
||||||
--from-literal=dopplerToken='{{ doppler_openstaticfish_microservices_service_token | default("") }}'
|
|
||||||
--dry-run=client -o yaml | kubectl apply -f -
|
|
||||||
changed_when: true
|
|
||||||
no_log: true
|
|
||||||
|
|
||||||
- name: Apply GHCR pull secret for private MicroServices images
|
- name: Apply GHCR pull secret for private MicroServices images
|
||||||
shell: >-
|
shell: >-
|
||||||
kubectl -n microservices create secret docker-registry ghcr-pull-secret
|
kubectl -n microservices create secret docker-registry ghcr-pull-secret
|
||||||
|
|||||||
Reference in New Issue
Block a user