fix: keep microservices doppler token out of gitea
Deploy Cluster / Terraform (push) Waiting to run
Deploy Cluster / Ansible (push) Blocked by required conditions

This commit is contained in:
2026-05-05 04:06:19 +00:00
parent 8e4060aa5a
commit 2cf2005100
2 changed files with 0 additions and 15 deletions
-1
View File
@@ -227,7 +227,6 @@ jobs:
-e "tailscale_oauth_client_id=${{ secrets.TAILSCALE_OAUTH_CLIENT_ID }}" \ -e "tailscale_oauth_client_id=${{ secrets.TAILSCALE_OAUTH_CLIENT_ID }}" \
-e "tailscale_oauth_client_secret=${{ secrets.TAILSCALE_OAUTH_CLIENT_SECRET }}" \ -e "tailscale_oauth_client_secret=${{ secrets.TAILSCALE_OAUTH_CLIENT_SECRET }}" \
-e "doppler_hetznerterra_service_token=${{ secrets.DOPPLER_HETZNERTERRA_SERVICE_TOKEN }}" \ -e "doppler_hetznerterra_service_token=${{ secrets.DOPPLER_HETZNERTERRA_SERVICE_TOKEN }}" \
-e "doppler_openstaticfish_microservices_service_token=${{ secrets.DOPPLER_MICROSERVICES_SERVICE_TOKEN }}" \
-e "ghcr_username=${{ secrets.GHCR_USERNAME }}" \ -e "ghcr_username=${{ secrets.GHCR_USERNAME }}" \
-e "ghcr_read_token=${{ secrets.GHCR_READ_TOKEN }}" \ -e "ghcr_read_token=${{ secrets.GHCR_READ_TOKEN }}" \
-e "tailscale_api_key=${{ secrets.TAILSCALE_API_KEY }}" \ -e "tailscale_api_key=${{ secrets.TAILSCALE_API_KEY }}" \
@@ -12,12 +12,6 @@
- ghcr_read_token | default("") | length > 0 - ghcr_read_token | default("") | length > 0
fail_msg: ghcr_username and ghcr_read_token must be provided for private MicroServices image pulls. fail_msg: ghcr_username and ghcr_read_token must be provided for private MicroServices image pulls.
- name: Ensure OpenStaticFish MicroServices Doppler token is provided
assert:
that:
- doppler_openstaticfish_microservices_service_token | default("") | length > 0
fail_msg: doppler_openstaticfish_microservices_service_token must be provided for MicroServices runtime secrets.
- name: Ensure external-secrets namespace exists - name: Ensure external-secrets namespace exists
shell: kubectl create namespace external-secrets --dry-run=client -o yaml | kubectl apply -f - shell: kubectl create namespace external-secrets --dry-run=client -o yaml | kubectl apply -f -
changed_when: true changed_when: true
@@ -34,14 +28,6 @@
changed_when: true changed_when: true
no_log: true no_log: true
- name: Apply OpenStaticFish MicroServices Doppler service token secret
shell: >-
kubectl -n external-secrets create secret generic doppler-openstaticfish-microservices-service-token
--from-literal=dopplerToken='{{ doppler_openstaticfish_microservices_service_token | default("") }}'
--dry-run=client -o yaml | kubectl apply -f -
changed_when: true
no_log: true
- name: Apply GHCR pull secret for private MicroServices images - name: Apply GHCR pull secret for private MicroServices images
shell: >- shell: >-
kubectl -n microservices create secret docker-registry ghcr-pull-secret kubectl -n microservices create secret docker-registry ghcr-pull-secret