flux: kb act runner running
This commit is contained in:
@@ -30,11 +30,16 @@ ops-scripts/apply-flux.sh
|
|||||||
**sops / age:**
|
**sops / age:**
|
||||||
|
|
||||||
``` bash
|
``` bash
|
||||||
age-keygen -o deploy/clusters/prod/flux-system/.env.d/age.agekey
|
age-keygen -o deploy/flux/.env.d/age.agekey
|
||||||
cat deploy/clusters/prod/flux-system/.env.d/age.agekey | \
|
cat deploy/flux/.env.d/age.agekey | \
|
||||||
kubectl create secret generic flux-sops-age \
|
kubectl create secret generic flux-sops-age \
|
||||||
--namespace=git-limbosolutions-com \
|
--namespace=git-limbosolutions-com \
|
||||||
--from-file=age.agekey=/dev/stdin
|
--from-file=age.agekey=/dev/stdin
|
||||||
|
cat deploy/flux/.env.d/age.agekey | \
|
||||||
|
kubectl create secret generic flux-sops-age \
|
||||||
|
--namespace=kb-cicd \
|
||||||
|
--from-file=age.agekey=/dev/stdin
|
||||||
|
|
||||||
```
|
```
|
||||||
|
|
||||||
**Encrypt secrets:**
|
**Encrypt secrets:**
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ spec:
|
|||||||
kind: GitRepository
|
kind: GitRepository
|
||||||
name: git-limbosolutions-com
|
name: git-limbosolutions-com
|
||||||
namespace: git-limbosolutions-com
|
namespace: git-limbosolutions-com
|
||||||
path: act-runners/kb/app
|
path: deploy/act-runners/kb/app
|
||||||
prune: true
|
prune: true
|
||||||
decryption:
|
decryption:
|
||||||
provider: sops
|
provider: sops
|
||||||
|
|||||||
@@ -8,9 +8,11 @@ resources:
|
|||||||
- act-runner-kb-sync.yaml
|
- act-runner-kb-sync.yaml
|
||||||
secretGenerator:
|
secretGenerator:
|
||||||
- name: flux-repo-ssh-credentials
|
- name: flux-repo-ssh-credentials
|
||||||
|
namespace: git-limbosolutions-com
|
||||||
files:
|
files:
|
||||||
- "identity=./.env.d/flux-repo-ssh-key"
|
- "identity=./.env.d/flux-repo-ssh-key"
|
||||||
- "known_hosts=./.env.d/flux-repo-ssh-known_hosts"
|
- "known_hosts=./.env.d/flux-repo-ssh-known_hosts"
|
||||||
- "pubkey=./.env.d/flux-repo-ssh-key.pub"
|
- "pubkey=./.env.d/flux-repo-ssh-key.pub"
|
||||||
|
|
||||||
generatorOptions:
|
generatorOptions:
|
||||||
disableNameSuffixHash: true
|
disableNameSuffixHash: true
|
||||||
Reference in New Issue
Block a user