REFACTOR(app): migrate to vault secrets
- Migrate from SealedSecret to Vault - Use ExternalSecrets operator
This commit is contained in:
17
deploy/k8s/overlays/prod/externalsecret.yaml
Normal file
17
deploy/k8s/overlays/prod/externalsecret.yaml
Normal file
@@ -0,0 +1,17 @@
|
||||
apiVersion: external-secrets.io/v1beta1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: todo-secrets
|
||||
spec:
|
||||
refreshInterval: 1h
|
||||
secretStoreRef:
|
||||
name: vault-backend
|
||||
kind: SecretStore
|
||||
target:
|
||||
name: todo-secrets
|
||||
creationPolicy: Owner
|
||||
data:
|
||||
- secretKey: database-url
|
||||
remoteRef:
|
||||
key: todo/prod
|
||||
property: DATABASE_URL
|
||||
Reference in New Issue
Block a user