|
| 1 | +apiVersion: batch/v1 |
| 2 | +kind: Job |
| 3 | +metadata: |
| 4 | + name: sync-secrets-job |
| 5 | + namespace: {{ .Values.global.namespace }} |
| 6 | +spec: |
| 7 | + template: |
| 8 | + spec: |
| 9 | + serviceAccountName: {{ .Values.global.serviceAccountName }} |
| 10 | + restartPolicy: Never |
| 11 | + containers: |
| 12 | + - name: sync-secrets |
| 13 | + image: bitnami/kubectl:latest |
| 14 | + command: |
| 15 | + - /bin/sh |
| 16 | + - -c |
| 17 | + - | |
| 18 | + set -e |
| 19 | + echo "Extracting ServiceAccount Secret from source..." |
| 20 | + kubectl get secret {{ .Values.global.serviceAccountName }} -n {{ .Values.global.namespace }} -o yaml > /tmp/sa-secret.yaml |
| 21 | +
|
| 22 | + {{- range .Values.destinations }} |
| 23 | + echo "Syncing credentials and ClusterSecretStore to {{ .name }}..." |
| 24 | + KUBECONFIG=/kubeconfigs/{{ .name }}/config \ |
| 25 | + kubectl -n {{ .namespace }} apply -f /tmp/sa-secret.yaml |
| 26 | + |
| 27 | + cat <<EOF | KUBECONFIG=/kubeconfigs/{{ .name }}/config kubectl apply -f - |
| 28 | + apiVersion: external-secrets.io/v1 |
| 29 | + kind: ClusterSecretStore |
| 30 | + metadata: |
| 31 | + name: dex-sso-sync-{{ .name }} |
| 32 | + spec: |
| 33 | + provider: |
| 34 | + kubernetes: |
| 35 | + remoteNamespace: {{ $.Values.global.targetNamespace }} |
| 36 | + server: |
| 37 | + url: {{ .apiServerURL | quote }} |
| 38 | + caProvider: |
| 39 | + type: Secret |
| 40 | + name: {{ $.Values.global.serviceAccountName }} |
| 41 | + key: ca.crt |
| 42 | + namespace: {{ .namespace }} |
| 43 | + auth: |
| 44 | + token: |
| 45 | + bearerToken: |
| 46 | + name: {{ $.Values.global.serviceAccountName }} |
| 47 | + key: token |
| 48 | + namespace: {{ .namespace }} |
| 49 | + EOF |
| 50 | + {{- end }} |
| 51 | + volumeMounts: |
| 52 | + {{- range .Values.destinations }} |
| 53 | + - name: kubeconfig-{{ .name }} |
| 54 | + mountPath: /kubeconfigs/{{ .name }} |
| 55 | + {{- end }} |
| 56 | + volumes: |
| 57 | + {{- range .Values.destinations }} |
| 58 | + - name: kubeconfig-{{ .name }} |
| 59 | + secret: |
| 60 | + secretName: {{ .kubeconfigSecret }} |
| 61 | + {{- end }} |
0 commit comments