Repository navigation
Move ingress credentials into ingress.sops.yaml - #6
Merged
Merged
Conversation
secret_prometheus_remote_write and secret_loki (the logs/metrics gateway login) move out of each inventory's all.sops.yaml into its own ingress.sops.yaml, which .sops.yaml also encrypts to the platform ArgoCD age key. Platform reads that file to create the network's ingress users, so new networks (of any type) need no platform change. ArgoCD still cannot open all.sops.yaml (mnemonics, MEV and tooling keys). Ansible loads every *.sops.yaml under group_vars/all, so the variables the nodes see are unchanged.
SummaryThe PR cleanly splits the logs/metrics gateway credentials out of each inventory's all.sops.yaml into a new ingress.sops.yaml encrypted to the platform ArgoCD age key plus the usual PGP keys. I verified sops' first-matching-rule and key-group semantics, Ansible's *.sops.yaml discovery via community.sops, and that the moved values re-encrypted without length changes, so the change is functionally sound; the only loose end is a stale developer doc. Issues
Reviewed @ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves
secret_prometheus_remote_writeandsecret_lokiout of each inventory'sall.sops.yamlinto a newingress.sops.yamlin the same folder. A new.sops.yamlrule encryptsingress.sops.yamlto the platform ArgoCD age key as well as the usual PGP keys;all.sops.yamlis still PGP-only. Platform builds each network's ingress users from that file. Ansible loads every*.sops.yamlundergroup_vars/all, so the nodes get the same variables as before.