diff --git a/services/teleport-agent/README.md b/services/teleport-agent/README.md index 55c0efb..5bac125 100644 --- a/services/teleport-agent/README.md +++ b/services/teleport-agent/README.md @@ -11,5 +11,5 @@ Using flux for reconciliation. **Encrypt secrets:** ``` bash -sops -e deploy/app/helm-values-secret.dec.yaml > deploy/app/helm-values-secret.yaml +sops -e deploy/app/helm-values.dec.yaml > deploy/app/helm-values.yaml ``` diff --git a/services/teleport-agent/deploy/app/helm-values-secret.yaml b/services/teleport-agent/deploy/app/helm-values-secret.yaml deleted file mode 100644 index 30c66e0..0000000 --- a/services/teleport-agent/deploy/app/helm-values-secret.yaml +++ /dev/null @@ -1,28 +0,0 @@ -apiVersion: v1 -kind: Secret -metadata: - name: node-red-settings - namespace: default -type: Opaque -stringData: - roles: ENC[AES256_GCM,data:LnMmFa1Nw29i4CZxseiI+Gyd,iv:GEYphwL17N6MbV/cw79IQ0XvaF+os3sqLPcihFkoU/o=,tag:B7XjbSiJRBsTzRaWE7PKpQ==,type:str] - authToken: ENC[AES256_GCM,data:LnK+oJdVJV/1/Y9d4vEGTursMEOLvK5BR7alhk2ZsjE=,iv:h/Y93x8e7gx+cOzeH1GZJknNJk0ZmAUACJDvDKXeKHw=,tag:4gpZJqoLUA3AhaOrsNu6fA==,type:str] - proxyAddr: ENC[AES256_GCM,data:o5GMP1gcO7d+xBnu0TY7KCFYbyFm/CNFUF4FXa7PFA==,iv:byC/YaMiCEIoORHs5yp8hebV46pocrR2TjaFGN4SNJ8=,tag:0k9C5JqCSwMlnmcQNGKr0w==,type:str] - kubeClusterName: ENC[AES256_GCM,data:1laDtQ==,iv:oh7BITQ/E07WHraLSnMlalsmfUA3UOVT18h7Z9W4Gxs=,tag:drua4LT1kVdtd6AsvFTllg==,type:str] - labels: - teleport.internal/resource-id: ENC[AES256_GCM,data:JKPmeKERfekLvw5t1OKOvEZ2Pj3PRMFuauxHrv+tomJ0DJif,iv:50hzLHJBnT8/HECXshhnsINY1GMO5xB4zUyKDsMJLng=,tag:kKujkCp2bd2cvtPeuXnJbQ==,type:str] -sops: - age: - - enc: | - -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBkU01YcEZ0YUQ1UEE5djh1 - L09jTitrRjFMRU1Rem9XVW1BYjlZaHl0WkhrClhwenU1eFpMaTRMYm5NUmFrbUN5 - MVFacnM2ak1OTU9qMWlJUlZGQTdEeUEKLS0tIForTTFReTZMWGt1cDV5ZUx0UXNB - WEczQjBad3Z4WVFhZTdBOENBZmMyOWsKIxJmYshgSE+TAPXOVMgibmhgBxk6cZMo - GGfau043oYzsTclKRiZ4Nqvm4xPoK6ROrOtLlwqD3cT5+n024bv/ZQ== - -----END AGE ENCRYPTED FILE----- - recipient: age1f9e4pvp5y8gzuk8mz2s5xm85dd7znxhk56tcpuxqwn78qfjwja0qekwlju - encrypted_regex: ^(data|stringData)$ - lastmodified: "2026-06-07T14:23:19Z" - mac: ENC[AES256_GCM,data:MhTqEKu1mLpcsIzN9UY7ltXPUsqsyb+/oWgi3bwcp6VScERP4tIYeqZyCAzQFw+oOvsR2Ii/PCDPRY536MrkPCQeacrsnneuemYn/FIZfwezZQMPBSGjInncs6IvoUDi8y/0TtL92voYqGqlVv0WuOvcNol83Baj/tKUa7QT8tA=,iv:IZxuNcDOlm+7F1SPILqXtQA8+wQBPv5/C6CWRSn2sxs=,tag:CxveRc4Vp71IXeCk8zJNMw==,type:str] - version: 3.13.1 diff --git a/services/teleport-agent/deploy/app/helm-values.yaml b/services/teleport-agent/deploy/app/helm-values.yaml new file mode 100644 index 0000000..0711958 --- /dev/null +++ b/services/teleport-agent/deploy/app/helm-values.yaml @@ -0,0 +1,27 @@ +apiVersion: v1 +kind: Secret +metadata: + name: teleport-agent-helm-values +type: Opaque +stringData: + roles: ENC[AES256_GCM,data:lgL/ik785QNup/paiaHrSmov,iv:t9ufewD4SUh3kQZsLtJfTalKMNxKaDt/5QvOqRzX3Hg=,tag:ZZZd9GkbCWQVWKSDobasuw==,type:str] + authToken: ENC[AES256_GCM,data:gCKGFmrtOHQ/dJ/QnWTdDFE82JhHYP86Ek5U6p/w77E=,iv:TiYm6GsENIl9JO5dDZbWGegoUrILI6EP3Jam8+tIG+k=,tag:oL0kWqvxM/KSsiKF+JgYTg==,type:str] + proxyAddr: ENC[AES256_GCM,data:wZudJ4LG/6xUev//Dew1aCq8FtVawm4Ysun7TntWew==,iv:02bP/8u4NteJ4uCJvtjE7zscGGwutNIpG3XH2xXXS8s=,tag:NYtg4XDy5Y+6JNfl92b7Vg==,type:str] + kubeClusterName: ENC[AES256_GCM,data:1EKucQ==,iv:v/+Jecxu4b5QEzaeibrGCz8SFVdFvPSO+tyOVpNcaMw=,tag:+ihXFtl150fmm4XXTbFbdw==,type:str] + labels: + teleport.internal/resource-id: ENC[AES256_GCM,data:NEEl4Kc6sXgsglYGVRbq3g9vtFSjQwX4wUrCJRc9FH/LcKfg,iv:T/YS9bZYFYF59YYmuPQs7lfHPTBhhce7Y7o7qTm+jXM=,tag:CUjv33TCDtAD/6gZvGKhow==,type:str] +sops: + age: + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBabWtpaEc3NFVuK2hjbXUv + VVlKWVFNM0d1cDZsY3QzbE1HRmxqWGZZNmdBClg5UVp3K3FVZEZlM0l2SHRWUUc2 + WTRvbkNBa3lXYzB2VktKTkJ2eGxSQTQKLS0tIFpWRm5kWDk4R1lFVUNieFArcmYy + bHl6ejVSRGtlak5FUjdnbFBxK3pHTTAKmwhC+7f2qnGLUpmdBwndzseKfRIBT5cl + 09mo4w2kwJIofQVkGN8aaCSmZbaO9167YdT8Yox8uHdr0kSvPTW5pw== + -----END AGE ENCRYPTED FILE----- + recipient: age1f9e4pvp5y8gzuk8mz2s5xm85dd7znxhk56tcpuxqwn78qfjwja0qekwlju + encrypted_regex: ^(data|stringData)$ + lastmodified: "2026-06-07T14:34:20Z" + mac: ENC[AES256_GCM,data:0JmM8PARCfMb5ISSQigO9vHLshc3HVbsSnwSb97sMUZ5Vs0+de3iiAEcdO0RhE+eywcJSToVaq/BL1n8UY6iHGAEtYTbt09gYhJp0y4Ots8yqIoQYxbWqslEHrCOQp3mMCiVa40xvo3i/LedQb6MnQyb3q+y0dQYCZl8h2ein70=,iv:jYGE9GMix1gB+HCLvO8xYjjexzNBa464wL6V0Uyr9yI=,tag:ZQjW0/HMW76kDue4Q0decw==,type:str] + version: 3.13.1 diff --git a/services/teleport-agent/deploy/app/kustomization.yaml b/services/teleport-agent/deploy/app/kustomization.yaml index 09a14f7..46d144d 100644 --- a/services/teleport-agent/deploy/app/kustomization.yaml +++ b/services/teleport-agent/deploy/app/kustomization.yaml @@ -5,7 +5,7 @@ resources: - helm-repo.yaml # - helm-release.yaml secretGenerator: - - name: teleport-agent-helm-install-values + - name: teleport-agent-helm-values files: - values.yaml=helm-values.yaml generatorOptions: