Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions components/build-templates/staging/e2e-quay-push-secret.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/build/tekton-ci/quay-push-secret
metadataPolicy: None
refreshInterval: 15m
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/qe/ci-helper-app-secrets
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
22 changes: 15 additions & 7 deletions components/cluster-as-a-service/staging/external-secrets.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,10 +7,16 @@ metadata:
hypershift.openshift.io/safe-to-delete-with-cluster: "false"
spec:
dataFrom:
- extract:
key: staging/eaas/stage-eaas-serviceaccount
- extract:
key: staging/eaas/konflux-eaas-stage
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/eaas/stage-eaas-serviceaccount
metadataPolicy: None
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/eaas/konflux-eaas-stage
metadataPolicy: None
refreshInterval: 5m
secretStoreRef:
kind: ClusterSecretStore
Expand All @@ -28,7 +34,6 @@ spec:
pull-secret: "{{ .ocp_pull_secret }}"
ssh-privatekey: unused
ssh-publickey: unused

---
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
Expand All @@ -37,8 +42,11 @@ metadata:
namespace: local-cluster
spec:
dataFrom:
- extract:
key: staging/eaas/stage-eaas-bucket-s3
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/eaas/stage-eaas-bucket-s3
metadataPolicy: None
refreshInterval: 5m
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: # will be added by the overlays
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@ spec:
namespace: crossplane-system
name: eaas-cluster
key: kubeconfig

---
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
Expand All @@ -25,7 +24,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/eaas/eaas-stage-kubeconfig
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: production/openshift-ci/appci-cluster
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/qe/exporters-secret
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
3 changes: 3 additions & 0 deletions components/has/base/external-secrets/has-github-token.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/has/github-token
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/build/image-controller
metadataPolicy: None
refreshInterval: 5m
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/pipeline-service/github-app
metadataPolicy: None
refreshInterval: 5m
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: "production/integration-service/tekton-ci/clair-in-ci-db-github-token"
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: "production/build/tekton-ci/github-read-only"
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/build/tekton-ci/infra-deployments-pr-creator
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: production/build/tekton-ci/konflux-ci-repo-creator
metadataPolicy: None
refreshInterval: 15m
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/build/tekton-ci/quay-push-secret-konflux-ci
metadataPolicy: None
refreshInterval: 15m
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: production/build/tekton-ci/registry-redhat-io-pull-secret
metadataPolicy: None
refreshInterval: 15m
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: "production/build/tekton-ci/slack-webhook-notification-secret"
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: "staging/build/tekton-ci/snyk-shared-secret" # will be added by the overlays
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,11 @@ metadata:
namespace: konflux-kite
spec:
dataFrom:
- extract:
key: "" # will be added by a patch specific to each cluster
- extract:
conversionStrategy: Default
decodingStrategy: None
key: "" # will be added by a patch specific to each cluster
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
3 changes: 3 additions & 0 deletions components/kubearchive/staging/base/external-secret.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/kubearchive/logging
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: integrations-output/external-resources/appsres09ue1/stone-stage-p01/stone-stage-p01-kube-archive-rds
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: integrations-output/external-resources/appsres09ue1/stonesoup-infra-stage/kube-archive-staging-rds
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/pipeline-service/github-app
metadataPolicy: None
refreshInterval: 5m
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: # will be added by the overlays
metadataPolicy: None
refreshInterval: 15m
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,11 @@ metadata:
argocd.argoproj.io/sync-wave: "-1"
spec:
dataFrom:
- extract:
key: "" # will be added by the overlays
- extract:
conversionStrategy: Default
decodingStrategy: None
key: "" # will be added by the overlays
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
name: appsre-stonesoup-vault
Expand All @@ -26,8 +29,11 @@ metadata:
argocd.argoproj.io/sync-wave: "-1"
spec:
dataFrom:
- extract:
key: "" # will be added by the overlays
- extract:
conversionStrategy: Default
decodingStrategy: None
key: "" # will be added by the overlays
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
name: appsre-stonesoup-vault
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,4 +20,7 @@ spec:
deletionPolicy: Delete
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/monitoring/logging/dynatrace
metadataPolicy: None
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: # will be added by the overlays
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/infrastructure/multi-platform-controller/stone-stage-p01/aws-account
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand All @@ -34,7 +37,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/infrastructure/multi-platform-controller/stone-stage-p01/aws-ssh-key
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand All @@ -57,7 +63,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/infrastructure/multi-platform-controller/stone-stage-p01/ibm-ppc64le-ssh-key
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand All @@ -80,7 +89,10 @@ metadata:
spec:
dataFrom:
- extract:
conversionStrategy: Default
decodingStrategy: None
key: staging/infrastructure/multi-platform-controller/stone-stage-p01/ibm-s390x-ssh-key
metadataPolicy: None
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
Expand Down
Loading
Loading