Compare commits

8 Commits
Author SHA1 Message Date
olb042 ba011d1e05 update version
Validate manifests / validate (push) Failing after 4s
2026-06-25 22:12:51 +01:00
olb042 411625ec40 bitnami https github
Validate manifests / validate (push) Failing after 6s
2026-06-25 22:11:44 +01:00
olb042 158afef5a8 update chart url
Validate manifests / validate (push) Failing after 26s
2026-06-25 22:05:32 +01:00
olb042 d49aa7916a update readme.md
Validate manifests / validate (push) Successful in 10s
2026-05-13 15:20:58 +01:00
olb042 76c65d187a fix git internal ref
Validate manifests / validate (push) Successful in 1m17s
2026-05-10 02:32:52 +01:00
olb042 c2e930b753 update validate 2026-05-08 15:29:45 +01:00
olb042 344ad565db add badge link 2026-04-26 00:36:39 +01:00
olb042 5680053c91 Enable bootstrap on main
Validate manifests / validate (push) Failing after 9s
2026-04-20 12:40:07 +01:00
4 changed files with 25 additions and 53 deletions
+1
View File
@@ -62,6 +62,7 @@ jobs:
-schema-location default \ -schema-location default \
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}{{.KindSuffix}}.json' \ -schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}{{.KindSuffix}}.json' \
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \ -schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
-ignore-missing-schemas \
-summary -summary
- name: Helm template - name: Helm template
+17 -50
View File
@@ -1,59 +1,26 @@
# sealed-secrets # sealed-secrets
GitOps source-of-truth repository for the cluster Sealed Secrets controller. GitOps source for the cluster Sealed Secrets controller.
This repo follows the same dormant-bootstrap pattern as the other application ## Current deployment
repositories, but the runtime payload is a pinned upstream Helm chart instead of
raw kustomize manifests. The controller is installed in `kube-system` with the
name `sealed-secrets-controller` so `kubeseal` works with its default controller
name assumptions.
## Layout - Bootstrap: `enabled: true`, applied from `main`
- Argo application: `sealed-secrets-production`
```text - Target namespace: `kube-system`
.
├── .gitea/
│ └── workflows/validate.yaml
├── .gitignore
├── bootstrap/
│ ├── applicationset.yaml
│ └── config.yaml
├── manifest/
│ └── overlays/
│ └── production/
│ └── helm-values/
│ └── values.yaml
└── README.md
```
## Bootstrap activation model
1. Prepare the repo on `init`.
2. Keep `bootstrap/config.yaml` set to `enabled: false` while validating.
3. Promote the repo to `main`.
4. Change `bootstrap/config.yaml` to `enabled: true` on `main`.
5. Let the bootstrap workflow apply `bootstrap/applicationset.yaml`.
## Controller decisions
- Namespace: `kube-system`
- Helm chart: `bitnami-labs/sealed-secrets` - Helm chart: `bitnami-labs/sealed-secrets`
- Chart version pin: `2.18.5` - Chart version: `2.18.5`
- Controller name override: `sealed-secrets-controller` - Helm release name: `sealed-secrets-controller`
The name override matters because the chart defaults to `sealed-secrets`, while ## Runtime
`kubeseal` expects `sealed-secrets-controller` unless you pass explicit flags.
Argo CD renders the upstream Helm chart with values from
`manifest/overlays/production/helm-values/values.yaml`. The controller name is
kept as `sealed-secrets-controller` so `kubeseal` works with its default
controller-name assumptions.
## Secret migration workflow ## Secret migration workflow
1. Install `kubeseal` locally. Fetch the controller cert with `kubeseal --fetch-cert --controller-namespace
2. Fetch the controller cert: kube-system`, seal app secrets into the owning app repo, then remove old
`kubeseal --fetch-cert --controller-namespace kube-system > sealed-secrets.pem` SOPS/KSOPS secret generator entries only after the app syncs from the new
3. Convert an existing Secret manifest: `SealedSecret` path.
`kubeseal --format yaml --cert sealed-secrets.pem < secret.yaml > sealed-secret.yaml`
4. Commit the resulting `SealedSecret` manifest in the owning app repo.
5. Remove the old SOPS-backed secret generator entry only after the app is
syncing from the new `SealedSecret` path.
Use the default `strict` scope unless a secret must survive renames inside the
same namespace. Avoid `cluster-wide` scope unless there is a concrete need.
+6 -2
View File
@@ -4,6 +4,9 @@ metadata:
name: sealed-secrets name: sealed-secrets
namespace: argocd namespace: argocd
spec: spec:
ignoreApplicationDifferences:
- jsonPointers:
- /spec/syncPolicy
goTemplate: true goTemplate: true
goTemplateOptions: goTemplateOptions:
- missingkey=error - missingkey=error
@@ -13,7 +16,7 @@ spec:
- environment: production - environment: production
namespace: kube-system namespace: kube-system
path: manifest/overlays/production path: manifest/overlays/production
chartVersion: 2.18.5 chartVersion: 2.19.0
template: template:
metadata: metadata:
name: 'sealed-secrets-{{ .environment }}' name: 'sealed-secrets-{{ .environment }}'
@@ -23,7 +26,7 @@ spec:
spec: spec:
project: default project: default
sources: sources:
- repoURL: https://bitnami-labs.github.io/sealed-secrets - repoURL: https://bitnami.github.io/sealed-secrets
chart: sealed-secrets chart: sealed-secrets
targetRevision: '{{ .chartVersion }}' targetRevision: '{{ .chartVersion }}'
helm: helm:
@@ -38,6 +41,7 @@ spec:
namespace: '{{ .namespace }}' namespace: '{{ .namespace }}'
syncPolicy: syncPolicy:
automated: automated:
enabled: true
prune: true prune: true
selfHeal: true selfHeal: true
syncOptions: syncOptions:
+1 -1
View File
@@ -1,3 +1,3 @@
enabled: false enabled: true
target_namespace: argocd target_namespace: argocd
apply_from_branch: main apply_from_branch: main