feat(secrets): make fresh database credentials recoverable
This commit is contained in:
parent
12a395a33c
commit
32d2373650
6 changed files with 34 additions and 6 deletions
11
README.md
11
README.md
|
|
@ -348,11 +348,12 @@ Sealed Secrets and kube-prometheus-stack. The separation is deliberate:
|
||||||
Terraform owns machines and cluster-wide controllers, Ansible owns the hosts,
|
Terraform owns machines and cluster-wide controllers, Ansible owns the hosts,
|
||||||
and Kustomize owns the application.
|
and Kustomize owns the application.
|
||||||
|
|
||||||
Sealed Secrets and Discord alert routing are configured, but real encrypted
|
Sealed Secrets and Discord alert routing are configured. The database
|
||||||
values cannot be committed until the owner supplies them. `deploy/secrets/README.md`
|
`SealedSecret` is committed for fresh deployments; the Discord resource still
|
||||||
keeps both plaintext values in local pipelines and commits only encrypted
|
awaits its owner-provided webhook. `deploy/secrets/README.md` keeps plaintext
|
||||||
`SealedSecret` resources. The controller key must be backed up outside this
|
values in local pipelines and commits only encrypted resources. The controller
|
||||||
repository before it becomes the recovery path.
|
key must be backed up outside this repository before it becomes the recovery
|
||||||
|
path.
|
||||||
|
|
||||||
The remaining acceptance gap is environmental: the reproducible fresh-VM path
|
The remaining acceptance gap is environmental: the reproducible fresh-VM path
|
||||||
has not been rerun on a second workstation with no dependencies installed.
|
has not been rerun on a second workstation with no dependencies installed.
|
||||||
|
|
|
||||||
|
|
@ -8,6 +8,7 @@ namespace: nereus
|
||||||
resources:
|
resources:
|
||||||
- ../../base
|
- ../../base
|
||||||
- ../../rollouts
|
- ../../rollouts
|
||||||
|
- ../../secrets
|
||||||
|
|
||||||
images:
|
images:
|
||||||
- name: nereus-api
|
- name: nereus-api
|
||||||
|
|
|
||||||
|
|
@ -44,6 +44,13 @@ Commit only `nereus-db-sealed.yaml` and add it to the prod overlay. Back up the
|
||||||
controller key outside the repository before relying on sealed secrets for
|
controller key outside the repository before relying on sealed secrets for
|
||||||
recovery. Losing that key makes every committed `SealedSecret` undecryptable.
|
recovery. Losing that key makes every committed `SealedSecret` undecryptable.
|
||||||
|
|
||||||
|
On a cluster that already has a manually created `nereus-db` Secret, do not
|
||||||
|
apply the sealed replacement in place. PostgreSQL keeps the password used when
|
||||||
|
its data directory was initialized. Cut over during a deliberate database
|
||||||
|
reset: remove the old Secret and disposable PVC, apply the `SealedSecret`, then
|
||||||
|
start PostgreSQL against the empty volume. Fresh clusters can apply the prod
|
||||||
|
overlay directly.
|
||||||
|
|
||||||
## Discord alert routing
|
## Discord alert routing
|
||||||
|
|
||||||
Alertmanager reads its Discord webhook from the `nereus-discord` Secret as a
|
Alertmanager reads its Discord webhook from the `nereus-discord` Secret as a
|
||||||
|
|
|
||||||
5
deploy/secrets/kustomization.yaml
Normal file
5
deploy/secrets/kustomization.yaml
Normal file
|
|
@ -0,0 +1,5 @@
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- nereus-db-sealed.yaml
|
||||||
14
deploy/secrets/nereus-db-sealed.yaml
Normal file
14
deploy/secrets/nereus-db-sealed.yaml
Normal file
|
|
@ -0,0 +1,14 @@
|
||||||
|
---
|
||||||
|
apiVersion: bitnami.com/v1alpha1
|
||||||
|
kind: SealedSecret
|
||||||
|
metadata:
|
||||||
|
name: nereus-db
|
||||||
|
namespace: nereus
|
||||||
|
spec:
|
||||||
|
encryptedData:
|
||||||
|
DATABASE_URL: AgBYadb8AxzvkAIu3JumuybqEGw1rxowhl6RjAOBWl0talN1Fx1+VuMWhb2Thvl0ood8oDbY5fvGx0jD3zEctq3Vxl+22BEzFcea+KLdiOPbJ4tKoOSz3m8MCRbd95DhZwISChhxjBEwoZBdkKQ4rorDFJytx2cmhTlnIxlUKE+m3FHhYYZ/firF74EbhjP9Udk05Dg7COCyrlhyKEXvYv9md/e/PJe7LmMSFHudhV4k8lvg5Uv4helkTDis35GubdICfF1n4BefxIUbyV+uy8XcjU0RBh3lN3o03ZBV/OmL9n2aC1zJIRQZpl1PogWDf5QsUK/AUtlZdB8L1v06sWCk/U4IeQXNEo24HcwKDToL7yVjU8ykF5X5aGLEO+5ATdPKCnB2LsnMF3g1xDiw6p9q8IexLag3c7aUSHwDFmj8Q3j8ky8IgB2cGIb3QzHBFQkGrPvgTdxdeWPcQ+k2vIoOuBOkG6W3W0plJcN72i1/vPnF4ge9xFAzEe2a4Jmiq7gk0dwSZArFPesLeLRZBfTM776WGgrCpNv8PRl+f76KhxaP0hi0F85UClIR6z97H9WdtD/ZvE7gTCjAryz0SnB1yOt79cUlYYmxsqYkYPCmtdlVR+s6vzljr6uUOum3fHeRMzIO2w58g4vqGQF+Uwojk3vmjkUROncf+BRP1Hcd3pBy/OadBkxXInt27ezJcDyoH89HdmBukx7keXonUl3QbVN3ReHwqqAoqSGfwxtYYz5+puSdgzaDqS98r8PhooeNTJaEPvbmYtNMUiTkMv1ZsWgYXltnTZGdjweCJue1xRVIg3SCtWp5vODK3rJg
|
||||||
|
POSTGRES_PASSWORD: AgBtyba0ZixyNnSL5rmn9QdlSWaVHL9Nx29KMKI5lpgu0JLdvRgXbQkZWCYnFi+gLul4FU3eQVsqqvHPxisYe0O0gKj6POToP8dFT5snJWD5ikU0SZX6PWPp94VXrAeLlsYW33V1eoWXxKLbWjX33pCExGVwDoSu0pAEuixtuaUjtv32FsHMAd70SY2uPlcJWeHhi6696agBH9Q3/sBR0m0fikRF4OFz3OC77HQ7GDDkda71KU34uqHs9Cbz30ePmu+xys0HM41Pi3ahguXYg4J1jdwTrjyAde5cAo61efrFNaqRteXFNkDenh4T7QaRfAZbkNYGXQ6Gtt85B3h1AM9592Mo3yBzjuEsAXr5HevITwFM6KZhoK8nVCzmqqSBlNU6DkHyRJxE3q+QWUu17vuG4bAWrd01ua6NfbzFwZb1q4sfszMLp62W1DI3y3S4vg5z9Zhnb9Sa78uPAAR5OTqGx/zMSseJrJX8FXBkA/raMtXFbUn1j1JnLfxmdsOW3LrjhTm7SoMH1Hr4IRf4iYAGgpmak4a/2gSFw9fN77LJI8GlJ/qRN9GcE4mmaLw2gojb60nav+PW0iBRbdHxTcxYiwdyvc7WxFGOHqrkZkEYcVZ2B7lJQMD3uNwC0Xd5rIVpE+lwX4gHMBRbCI6+4OZMGzKnUOWqSsoKS4RptQruKe1b8sXRB4hQYpZ4qhewujM01NSamdz6ZW5Ttp7IlBA2s0yVbOlXQfesDXg77tQ0iQ==
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
name: nereus-db
|
||||||
|
namespace: nereus
|
||||||
|
|
@ -208,7 +208,7 @@ task. Mark a task `[x]` only after its stated verification passes.
|
||||||
- [H] Create the real error-rate AnalysisTemplate. Agent-authored 2026-08-21; PromQL never evaluated against real series.
|
- [H] Create the real error-rate AnalysisTemplate. Agent-authored 2026-08-21; PromQL never evaluated against real series.
|
||||||
- [H] Configure blue-green promotion and automated rollback. Agent-authored 2026-08-21; promotion and abort paths untested with the real API.
|
- [H] Configure blue-green promotion and automated rollback. Agent-authored 2026-08-21; promotion and abort paths untested with the real API.
|
||||||
- [H] Maintain Forgejo Actions and GitHub mirror workflows.
|
- [H] Maintain Forgejo Actions and GitHub mirror workflows.
|
||||||
- [~] Install Sealed Secrets and document off-repository sealing; real encrypted values await owner-provided secrets.
|
- [~] Install Sealed Secrets and commit the encrypted database resource; safe cutover awaits a fresh database volume.
|
||||||
|
|
||||||
## Forgejo CI/CD
|
## Forgejo CI/CD
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue