Compare commits
7
Commits
5680053c91
..
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ba011d1e05 | ||
|
|
411625ec40 | ||
|
|
158afef5a8 | ||
|
|
d49aa7916a | ||
|
|
76c65d187a | ||
|
|
c2e930b753 | ||
|
|
344ad565db |
@@ -62,6 +62,7 @@ jobs:
|
||||
-schema-location default \
|
||||
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}{{.KindSuffix}}.json' \
|
||||
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
|
||||
-ignore-missing-schemas \
|
||||
-summary
|
||||
|
||||
- name: Helm template
|
||||
|
||||
@@ -1,59 +1,26 @@
|
||||
# sealed-secrets
|
||||
|
||||
GitOps source-of-truth repository for the cluster Sealed Secrets controller.
|
||||
GitOps source for the cluster Sealed Secrets controller.
|
||||
|
||||
This repo follows the same dormant-bootstrap pattern as the other application
|
||||
repositories, but the runtime payload is a pinned upstream Helm chart instead of
|
||||
raw kustomize manifests. The controller is installed in `kube-system` with the
|
||||
name `sealed-secrets-controller` so `kubeseal` works with its default controller
|
||||
name assumptions.
|
||||
## Current deployment
|
||||
|
||||
## Layout
|
||||
|
||||
```text
|
||||
.
|
||||
├── .gitea/
|
||||
│ └── workflows/validate.yaml
|
||||
├── .gitignore
|
||||
├── bootstrap/
|
||||
│ ├── applicationset.yaml
|
||||
│ └── config.yaml
|
||||
├── manifest/
|
||||
│ └── overlays/
|
||||
│ └── production/
|
||||
│ └── helm-values/
|
||||
│ └── values.yaml
|
||||
└── README.md
|
||||
```
|
||||
|
||||
## Bootstrap activation model
|
||||
|
||||
1. Prepare the repo on `init`.
|
||||
2. Keep `bootstrap/config.yaml` set to `enabled: false` while validating.
|
||||
3. Promote the repo to `main`.
|
||||
4. Change `bootstrap/config.yaml` to `enabled: true` on `main`.
|
||||
5. Let the bootstrap workflow apply `bootstrap/applicationset.yaml`.
|
||||
|
||||
## Controller decisions
|
||||
|
||||
- Namespace: `kube-system`
|
||||
- Bootstrap: `enabled: true`, applied from `main`
|
||||
- Argo application: `sealed-secrets-production`
|
||||
- Target namespace: `kube-system`
|
||||
- Helm chart: `bitnami-labs/sealed-secrets`
|
||||
- Chart version pin: `2.18.5`
|
||||
- Controller name override: `sealed-secrets-controller`
|
||||
- Chart version: `2.18.5`
|
||||
- Helm release name: `sealed-secrets-controller`
|
||||
|
||||
The name override matters because the chart defaults to `sealed-secrets`, while
|
||||
`kubeseal` expects `sealed-secrets-controller` unless you pass explicit flags.
|
||||
## Runtime
|
||||
|
||||
Argo CD renders the upstream Helm chart with values from
|
||||
`manifest/overlays/production/helm-values/values.yaml`. The controller name is
|
||||
kept as `sealed-secrets-controller` so `kubeseal` works with its default
|
||||
controller-name assumptions.
|
||||
|
||||
## Secret migration workflow
|
||||
|
||||
1. Install `kubeseal` locally.
|
||||
2. Fetch the controller cert:
|
||||
`kubeseal --fetch-cert --controller-namespace kube-system > sealed-secrets.pem`
|
||||
3. Convert an existing Secret manifest:
|
||||
`kubeseal --format yaml --cert sealed-secrets.pem < secret.yaml > sealed-secret.yaml`
|
||||
4. Commit the resulting `SealedSecret` manifest in the owning app repo.
|
||||
5. Remove the old SOPS-backed secret generator entry only after the app is
|
||||
syncing from the new `SealedSecret` path.
|
||||
|
||||
Use the default `strict` scope unless a secret must survive renames inside the
|
||||
same namespace. Avoid `cluster-wide` scope unless there is a concrete need.
|
||||
Fetch the controller cert with `kubeseal --fetch-cert --controller-namespace
|
||||
kube-system`, seal app secrets into the owning app repo, then remove old
|
||||
SOPS/KSOPS secret generator entries only after the app syncs from the new
|
||||
`SealedSecret` path.
|
||||
|
||||
@@ -4,6 +4,9 @@ metadata:
|
||||
name: sealed-secrets
|
||||
namespace: argocd
|
||||
spec:
|
||||
ignoreApplicationDifferences:
|
||||
- jsonPointers:
|
||||
- /spec/syncPolicy
|
||||
goTemplate: true
|
||||
goTemplateOptions:
|
||||
- missingkey=error
|
||||
@@ -13,7 +16,7 @@ spec:
|
||||
- environment: production
|
||||
namespace: kube-system
|
||||
path: manifest/overlays/production
|
||||
chartVersion: 2.18.5
|
||||
chartVersion: 2.19.0
|
||||
template:
|
||||
metadata:
|
||||
name: 'sealed-secrets-{{ .environment }}'
|
||||
@@ -23,7 +26,7 @@ spec:
|
||||
spec:
|
||||
project: default
|
||||
sources:
|
||||
- repoURL: https://bitnami-labs.github.io/sealed-secrets
|
||||
- repoURL: https://bitnami.github.io/sealed-secrets
|
||||
chart: sealed-secrets
|
||||
targetRevision: '{{ .chartVersion }}'
|
||||
helm:
|
||||
@@ -38,6 +41,7 @@ spec:
|
||||
namespace: '{{ .namespace }}'
|
||||
syncPolicy:
|
||||
automated:
|
||||
enabled: true
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
|
||||
Reference in New Issue
Block a user