- authelia: postgresql → storage/postgresql, authelia → security/authelia - external-secrets: zot → storage/zot (ClusterExternalSecret) - vault: secret/data/vault/config → security/vault, authelia → security/authelia Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
19 lines
405 B
YAML
19 lines
405 B
YAML
apiVersion: external-secrets.io/v1
|
|
kind: ExternalSecret
|
|
metadata:
|
|
name: vault-oidc-secret
|
|
namespace: vault
|
|
spec:
|
|
refreshInterval: 1h
|
|
secretStoreRef:
|
|
kind: ClusterSecretStore
|
|
name: vault-backend
|
|
target:
|
|
name: vault-oidc-secret
|
|
creationPolicy: Owner
|
|
data:
|
|
- secretKey: VAULT_CLIENT_SECRET
|
|
remoteRef:
|
|
key: security/authelia
|
|
property: VAULT_CLIENT_SECRET
|