Skip to content

Move ingress credentials into ingress.sops.yaml - #6

Merged
samcm merged 1 commit into
masterfrom
ingress-sops-split
Oct 8, 2026
Merged

samcm merged 1 commit into
masterfrom
ingress-sops-split

Conversation

@samcm

@samcm samcm commented Oct 8, 2026

Copy link
Copy Markdown
Member

Moves secret_prometheus_remote_write and secret_loki out of each inventory's all.sops.yaml into a new ingress.sops.yaml in the same folder. A new .sops.yaml rule encrypts ingress.sops.yaml to the platform ArgoCD age key as well as the usual PGP keys; all.sops.yaml is still PGP-only. Platform builds each network's ingress users from that file. Ansible loads every *.sops.yaml under group_vars/all, so the nodes get the same variables as before.

secret_prometheus_remote_write and secret_loki (the logs/metrics gateway
login) move out of each inventory's all.sops.yaml into its own
ingress.sops.yaml, which .sops.yaml also encrypts to the platform ArgoCD age
key. Platform reads that file to create the network's ingress users, so new
networks (of any type) need no platform change. ArgoCD still cannot open
all.sops.yaml (mnemonics, MEV and tooling keys).

Ansible loads every *.sops.yaml under group_vars/all, so the variables the
nodes see are unchanged.
@redpandabot

redpandabot Bot commented Oct 8, 2026

Copy link
Copy Markdown

Summary

The PR cleanly splits the logs/metrics gateway credentials out of each inventory's all.sops.yaml into a new ingress.sops.yaml encrypted to the platform ArgoCD age key plus the usual PGP keys. I verified sops' first-matching-rule and key-group semantics, Ansible's *.sops.yaml discovery via community.sops, and that the moved values re-encrypted without length changes, so the change is functionally sound; the only loose end is a stale developer doc.

Issues

  • 🟢 README.md — README still tells contributors to put ingress secrets in all.sops.yaml — The Secret Configuration section (README lines 104-135) still lists secret_prometheus_remote_write and secret_loki as living in all.sops.yaml and says to encrypt them there. After this split they belong in ingress.sops.yaml; anyone following the guide would re-add them to the PGP-only file, which the platform's ArgoCD key cannot read.

Reviewed @ f4d2899a
"Friday deploys are a personality flaw."

@samcm
samcm merged commit cf73425 into master Oct 8, 2026
1 check passed
@samcm
samcm deleted the ingress-sops-split branch October 8, 2026 08:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant