feat(secrets): make fresh database credentials recoverable
This commit is contained in:
parent
12a395a33c
commit
32d2373650
6 changed files with 34 additions and 6 deletions
11
README.md
11
README.md
|
|
@ -348,11 +348,12 @@ Sealed Secrets and kube-prometheus-stack. The separation is deliberate:
|
|||
Terraform owns machines and cluster-wide controllers, Ansible owns the hosts,
|
||||
and Kustomize owns the application.
|
||||
|
||||
Sealed Secrets and Discord alert routing are configured, but real encrypted
|
||||
values cannot be committed until the owner supplies them. `deploy/secrets/README.md`
|
||||
keeps both plaintext values in local pipelines and commits only encrypted
|
||||
`SealedSecret` resources. The controller key must be backed up outside this
|
||||
repository before it becomes the recovery path.
|
||||
Sealed Secrets and Discord alert routing are configured. The database
|
||||
`SealedSecret` is committed for fresh deployments; the Discord resource still
|
||||
awaits its owner-provided webhook. `deploy/secrets/README.md` keeps plaintext
|
||||
values in local pipelines and commits only encrypted resources. The controller
|
||||
key must be backed up outside this repository before it becomes the recovery
|
||||
path.
|
||||
|
||||
The remaining acceptance gap is environmental: the reproducible fresh-VM path
|
||||
has not been rerun on a second workstation with no dependencies installed.
|
||||
|
|
|
|||
|
|
@ -8,6 +8,7 @@ namespace: nereus
|
|||
resources:
|
||||
- ../../base
|
||||
- ../../rollouts
|
||||
- ../../secrets
|
||||
|
||||
images:
|
||||
- name: nereus-api
|
||||
|
|
|
|||
|
|
@ -44,6 +44,13 @@ Commit only `nereus-db-sealed.yaml` and add it to the prod overlay. Back up the
|
|||
controller key outside the repository before relying on sealed secrets for
|
||||
recovery. Losing that key makes every committed `SealedSecret` undecryptable.
|
||||
|
||||
On a cluster that already has a manually created `nereus-db` Secret, do not
|
||||
apply the sealed replacement in place. PostgreSQL keeps the password used when
|
||||
its data directory was initialized. Cut over during a deliberate database
|
||||
reset: remove the old Secret and disposable PVC, apply the `SealedSecret`, then
|
||||
start PostgreSQL against the empty volume. Fresh clusters can apply the prod
|
||||
overlay directly.
|
||||
|
||||
## Discord alert routing
|
||||
|
||||
Alertmanager reads its Discord webhook from the `nereus-discord` Secret as a
|
||||
|
|
|
|||
5
deploy/secrets/kustomization.yaml
Normal file
5
deploy/secrets/kustomization.yaml
Normal file
|
|
@ -0,0 +1,5 @@
|
|||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- nereus-db-sealed.yaml
|
||||
14
deploy/secrets/nereus-db-sealed.yaml
Normal file
14
deploy/secrets/nereus-db-sealed.yaml
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
---
|
||||
apiVersion: bitnami.com/v1alpha1
|
||||
kind: SealedSecret
|
||||
metadata:
|
||||
name: nereus-db
|
||||
namespace: nereus
|
||||
spec:
|
||||
encryptedData:
|
||||
DATABASE_URL: AgBYadb8AxzvkAIu3JumuybqEGw1rxowhl6RjAOBWl0talN1Fx1+VuMWhb2Thvl0ood8oDbY5fvGx0jD3zEctq3Vxl+22BEzFcea+KLdiOPbJ4tKoOSz3m8MCRbd95DhZwISChhxjBEwoZBdkKQ4rorDFJytx2cmhTlnIxlUKE+m3FHhYYZ/firF74EbhjP9Udk05Dg7COCyrlhyKEXvYv9md/e/PJe7LmMSFHudhV4k8lvg5Uv4helkTDis35GubdICfF1n4BefxIUbyV+uy8XcjU0RBh3lN3o03ZBV/OmL9n2aC1zJIRQZpl1PogWDf5QsUK/AUtlZdB8L1v06sWCk/U4IeQXNEo24HcwKDToL7yVjU8ykF5X5aGLEO+5ATdPKCnB2LsnMF3g1xDiw6p9q8IexLag3c7aUSHwDFmj8Q3j8ky8IgB2cGIb3QzHBFQkGrPvgTdxdeWPcQ+k2vIoOuBOkG6W3W0plJcN72i1/vPnF4ge9xFAzEe2a4Jmiq7gk0dwSZArFPesLeLRZBfTM776WGgrCpNv8PRl+f76KhxaP0hi0F85UClIR6z97H9WdtD/ZvE7gTCjAryz0SnB1yOt79cUlYYmxsqYkYPCmtdlVR+s6vzljr6uUOum3fHeRMzIO2w58g4vqGQF+Uwojk3vmjkUROncf+BRP1Hcd3pBy/OadBkxXInt27ezJcDyoH89HdmBukx7keXonUl3QbVN3ReHwqqAoqSGfwxtYYz5+puSdgzaDqS98r8PhooeNTJaEPvbmYtNMUiTkMv1ZsWgYXltnTZGdjweCJue1xRVIg3SCtWp5vODK3rJg
|
||||
POSTGRES_PASSWORD: AgBtyba0ZixyNnSL5rmn9QdlSWaVHL9Nx29KMKI5lpgu0JLdvRgXbQkZWCYnFi+gLul4FU3eQVsqqvHPxisYe0O0gKj6POToP8dFT5snJWD5ikU0SZX6PWPp94VXrAeLlsYW33V1eoWXxKLbWjX33pCExGVwDoSu0pAEuixtuaUjtv32FsHMAd70SY2uPlcJWeHhi6696agBH9Q3/sBR0m0fikRF4OFz3OC77HQ7GDDkda71KU34uqHs9Cbz30ePmu+xys0HM41Pi3ahguXYg4J1jdwTrjyAde5cAo61efrFNaqRteXFNkDenh4T7QaRfAZbkNYGXQ6Gtt85B3h1AM9592Mo3yBzjuEsAXr5HevITwFM6KZhoK8nVCzmqqSBlNU6DkHyRJxE3q+QWUu17vuG4bAWrd01ua6NfbzFwZb1q4sfszMLp62W1DI3y3S4vg5z9Zhnb9Sa78uPAAR5OTqGx/zMSseJrJX8FXBkA/raMtXFbUn1j1JnLfxmdsOW3LrjhTm7SoMH1Hr4IRf4iYAGgpmak4a/2gSFw9fN77LJI8GlJ/qRN9GcE4mmaLw2gojb60nav+PW0iBRbdHxTcxYiwdyvc7WxFGOHqrkZkEYcVZ2B7lJQMD3uNwC0Xd5rIVpE+lwX4gHMBRbCI6+4OZMGzKnUOWqSsoKS4RptQruKe1b8sXRB4hQYpZ4qhewujM01NSamdz6ZW5Ttp7IlBA2s0yVbOlXQfesDXg77tQ0iQ==
|
||||
template:
|
||||
metadata:
|
||||
name: nereus-db
|
||||
namespace: nereus
|
||||
|
|
@ -208,7 +208,7 @@ task. Mark a task `[x]` only after its stated verification passes.
|
|||
- [H] Create the real error-rate AnalysisTemplate. Agent-authored 2026-08-21; PromQL never evaluated against real series.
|
||||
- [H] Configure blue-green promotion and automated rollback. Agent-authored 2026-08-21; promotion and abort paths untested with the real API.
|
||||
- [H] Maintain Forgejo Actions and GitHub mirror workflows.
|
||||
- [~] Install Sealed Secrets and document off-repository sealing; real encrypted values await owner-provided secrets.
|
||||
- [~] Install Sealed Secrets and commit the encrypted database resource; safe cutover awaits a fresh database volume.
|
||||
|
||||
## Forgejo CI/CD
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue