Compare commits

..
7 Commits
Author SHA1 Message Date
olb042 ba011d1e05 update version
Validate manifests / validate (push) Failing after 4s
2026-06-25 22:12:51 +01:00
olb042 411625ec40 bitnami https github
Validate manifests / validate (push) Failing after 6s
2026-06-25 22:11:44 +01:00
olb042 158afef5a8 update chart url
Validate manifests / validate (push) Failing after 26s
2026-06-25 22:05:32 +01:00
olb042 d49aa7916a update readme.md
Validate manifests / validate (push) Successful in 10s
2026-05-13 15:20:58 +01:00
olb042 76c65d187a fix git internal ref
Validate manifests / validate (push) Successful in 1m17s
2026-05-10 02:32:52 +01:00
olb042 c2e930b753 update validate 2026-05-08 15:29:45 +01:00
olb042 344ad565db add badge link 2026-04-26 00:36:39 +01:00
3 changed files with 24 additions and 52 deletions
+1
View File
@@ -62,6 +62,7 @@ jobs:
-schema-location default \
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}{{.KindSuffix}}.json' \
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
-ignore-missing-schemas \
-summary
- name: Helm template
+17 -50
View File
@@ -1,59 +1,26 @@
# sealed-secrets
GitOps source-of-truth repository for the cluster Sealed Secrets controller.
GitOps source for the cluster Sealed Secrets controller.
This repo follows the same dormant-bootstrap pattern as the other application
repositories, but the runtime payload is a pinned upstream Helm chart instead of
raw kustomize manifests. The controller is installed in `kube-system` with the
name `sealed-secrets-controller` so `kubeseal` works with its default controller
name assumptions.
## Current deployment
## Layout
```text
.
├── .gitea/
│ └── workflows/validate.yaml
├── .gitignore
├── bootstrap/
│ ├── applicationset.yaml
│ └── config.yaml
├── manifest/
│ └── overlays/
│ └── production/
│ └── helm-values/
│ └── values.yaml
└── README.md
```
## Bootstrap activation model
1. Prepare the repo on `init`.
2. Keep `bootstrap/config.yaml` set to `enabled: false` while validating.
3. Promote the repo to `main`.
4. Change `bootstrap/config.yaml` to `enabled: true` on `main`.
5. Let the bootstrap workflow apply `bootstrap/applicationset.yaml`.
## Controller decisions
- Namespace: `kube-system`
- Bootstrap: `enabled: true`, applied from `main`
- Argo application: `sealed-secrets-production`
- Target namespace: `kube-system`
- Helm chart: `bitnami-labs/sealed-secrets`
- Chart version pin: `2.18.5`
- Controller name override: `sealed-secrets-controller`
- Chart version: `2.18.5`
- Helm release name: `sealed-secrets-controller`
The name override matters because the chart defaults to `sealed-secrets`, while
`kubeseal` expects `sealed-secrets-controller` unless you pass explicit flags.
## Runtime
Argo CD renders the upstream Helm chart with values from
`manifest/overlays/production/helm-values/values.yaml`. The controller name is
kept as `sealed-secrets-controller` so `kubeseal` works with its default
controller-name assumptions.
## Secret migration workflow
1. Install `kubeseal` locally.
2. Fetch the controller cert:
`kubeseal --fetch-cert --controller-namespace kube-system > sealed-secrets.pem`
3. Convert an existing Secret manifest:
`kubeseal --format yaml --cert sealed-secrets.pem < secret.yaml > sealed-secret.yaml`
4. Commit the resulting `SealedSecret` manifest in the owning app repo.
5. Remove the old SOPS-backed secret generator entry only after the app is
syncing from the new `SealedSecret` path.
Use the default `strict` scope unless a secret must survive renames inside the
same namespace. Avoid `cluster-wide` scope unless there is a concrete need.
Fetch the controller cert with `kubeseal --fetch-cert --controller-namespace
kube-system`, seal app secrets into the owning app repo, then remove old
SOPS/KSOPS secret generator entries only after the app syncs from the new
`SealedSecret` path.
+6 -2
View File
@@ -4,6 +4,9 @@ metadata:
name: sealed-secrets
namespace: argocd
spec:
ignoreApplicationDifferences:
- jsonPointers:
- /spec/syncPolicy
goTemplate: true
goTemplateOptions:
- missingkey=error
@@ -13,7 +16,7 @@ spec:
- environment: production
namespace: kube-system
path: manifest/overlays/production
chartVersion: 2.18.5
chartVersion: 2.19.0
template:
metadata:
name: 'sealed-secrets-{{ .environment }}'
@@ -23,7 +26,7 @@ spec:
spec:
project: default
sources:
- repoURL: https://bitnami-labs.github.io/sealed-secrets
- repoURL: https://bitnami.github.io/sealed-secrets
chart: sealed-secrets
targetRevision: '{{ .chartVersion }}'
helm:
@@ -38,6 +41,7 @@ spec:
namespace: '{{ .namespace }}'
syncPolicy:
automated:
enabled: true
prune: true
selfHeal: true
syncOptions: