Skip to content

Commit 81e92de

Browse files
promote iris-iam argocd config to prod
1 parent 16c93df commit 81e92de

File tree

4 files changed

+79
-0
lines changed

4 files changed

+79
-0
lines changed

charts/prod/argocd/values.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,11 @@ argo-cd:
2525
2626
oidc.skip.insecure.verify: true
2727

28+
rbac:
29+
policy.csv: |
30+
g, stfc-cloud/team, role:readonly
31+
g, stfc-cloud/admins, role:admin
32+
2833
server:
2934
ingress:
3035
enabled: true
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
creation_rules:
2+
- unencrypted_regex: "^(apiVersion|metadata|kind|type)$"
3+
key_groups:
4+
- age:
5+
# Temporary Key for ArgoCD
6+
- age1p9q4tzawn9jh3evsgkuslklm2d4zhwhyhtcfls7n62a8cdpv8vqq7t9hqv
7+
8+
# Access Keys
9+
# Prod Access Key
10+
- age1cq92796c46d06s43t079xc89exe4vd52rh30c9mcafmne62dxyhqrupl4l
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
argo-cd:
2+
configs:
3+
secret:
4+
extra:
5+
oidc.irisiam.clientID: ENC[AES256_GCM,data:X/HbjE/uVc6C7FxRt44qjKHK4umoxS3ZysNpzQo3dP/roJie,iv:LnqTfWQaAgNw9c6HoSSdd2AwYn/wjjOjoL9BWEdh718=,tag:AKNsg5LNvHERx3VAcHHvIQ==,type:str]
6+
oidc.irisiam.clientSecret: ENC[AES256_GCM,data:ixp/Vd4B/Rew0sMMlcHMjw0TgzZhwfdmIkzqJGetv/tvG3pwfLRn6Df12KrKcDw2nG2omyL6fHlZIDzVLECUSOu1QW3xkD4ihgc3Hz7m8VhBhJvCGZdY,iv:lbjTLWpPrPBINJbbrEss5spYNfyA2/1Pf2H5U+HwzXE=,tag:4EMmU+tr6PqZwJ0XbHOHJQ==,type:str]
7+
#ENC[AES256_GCM,data:s5QWV4qI5mSSvz/PWIM7bRmT4KGNgbakWw==,iv:vfeBx/IKmThX2Mx18hT0mfx0f0FE2vig5F7hSUzKOug=,tag:HIhYH9Ln/bT7nJzh7hz62w==,type:comment]
8+
argocdServerAdminPassword: ENC[AES256_GCM,data:o89wLyz0ZSbLWon9B9c/4DoMACxKBlWHfec3vw3slEe8jcP3fHv13ku62ILWH/WqE8exgncK4Owa4yzY,iv:21lvK6KdRsfwS9Fss4xT4L7ANzxf3tGQhz5yYFxhbHE=,tag:450s1AlvYAadIRSKzeZuSA==,type:str]
9+
sops:
10+
age:
11+
- recipient: age1p9q4tzawn9jh3evsgkuslklm2d4zhwhyhtcfls7n62a8cdpv8vqq7t9hqv
12+
enc: |
13+
-----BEGIN AGE ENCRYPTED FILE-----
14+
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA3T1IveWg2Mk9zMGJ1ODhZ
15+
VTE3eUZjYjhJT290OTI3ZmxENFRTNWpubHhFCm4zT01oN3kxcUJVcktUUDJsRk40
16+
NEN4czJWaFhybW04b3VLelpyZ0JsdkEKLS0tIDdWdmQzWEJ4TCtwelNYc0UxcVky
17+
empUb25xN2JMUnQrWS9valdPNkpUelUKthqTmDtn+ivKQCbbW24Cepmk+Mru6wHe
18+
rBjNLkitJK4ZO7ufvibhYnscjJDvuFexCMr9dmiodyLJ52T7s+2ofQ==
19+
-----END AGE ENCRYPTED FILE-----
20+
- recipient: age1cq92796c46d06s43t079xc89exe4vd52rh30c9mcafmne62dxyhqrupl4l
21+
enc: |
22+
-----BEGIN AGE ENCRYPTED FILE-----
23+
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBPK2hicEJsWjI3YW4zb2Yz
24+
bTlaWWY3SEovRHBOWHE0NGRKSm1wUU80YjBVCnJSYjFob2JoWUV6T3ZTNGJGM2Fa
25+
Sk9HMzB6dTRLYkc5RzJSdHZpais1dkkKLS0tIFhiU3VSTzE0aWxKazhsamN2cFVa
26+
UUNCUlVwYjVySWRPTXlCUENoOW1kUjAK1R/iTB5k9ZIIh2W7iy144CQoXFGYNlaJ
27+
NUTZ7/gPXXSXVFnHsvPI+c+2WK4QMw78Idjr+3U5DcBV3CYTZVFKrQ==
28+
-----END AGE ENCRYPTED FILE-----
29+
lastmodified: "2025-11-04T16:02:36Z"
30+
mac: ENC[AES256_GCM,data:0LJ7Juw8HPFVtIcyzj1JZGp+/riQ6GD5R4Dqap7R/2Ya3UYcfh9ndANfaCc7iznsszdIkj+H5CWDzWbreSqIA6Mn8ojKWAPOl7rtG6YgQkJ6oMlO7LuEDjDBxjpUMlFcrPjcpFrLiY867ZsZEfdJ3qYn4PzIwlu7VNGbADFCIZ8=,iv:7XWAHFwnj4LW8Lo74Zz0K11zRvSKkWwdSXjJYIL4rt8=,tag:Z2lOJoE8YlMZ6kc4w3Fl5g==,type:str]
31+
unencrypted_regex: ^(apiVersion|metadata|kind|type)$
32+
version: 3.11.0
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
argo-cd:
2+
configs:
3+
secret:
4+
extra:
5+
oidc.irisiam.clientID: ENC[AES256_GCM,data:Bu9czzLzimuQdBMBSQyJykssKgNoSBlZz2Qu8S0+fYZEQZOQ,iv:rGNpU0RZOylQDndpmVcxslxeol4v5tltvQnoBDsZFxU=,tag:p4mfuaaaNq0TRYxgCBBBDQ==,type:str]
6+
oidc.irisiam.clientSecret: ENC[AES256_GCM,data:Pf79veV9pbIimjCbgNZYSrW12G7EGhrZnmsvVKZCTsUpDo77DlfxCRZbyhjZDczhtbsINeITCB4ISjs4yf3Pv9iN3TJXCrvQ4Uj6YfOh1ogpthb8hbDa,iv:2682QXKc1+PhcZkTH1c4fIqA9hADV0CcLyXZvNwXmdg=,tag:ZKBqqmKOuyGqnu90pZi6pg==,type:str]
7+
#ENC[AES256_GCM,data:TWScxnB9wm4jB7C9qMu1ybuNhHYOJNtAOQ==,iv:g1EL6UoeqPsxlXLGKxVNHTjF/xTjHytfE3YcpdQu8XE=,tag:y66Dgm//lnMByZF3nhN76Q==,type:comment]
8+
argocdServerAdminPassword: ENC[AES256_GCM,data:knrbvV+pnX+b3TZGGf9w/OAomFsina0WX/tc4+6uCKjS5KJpiOfSDO7HV+y+kHSiMOaXIePbNE9AzQXc,iv:U+Uxhxn8x66rRsN4HVtrnnXWQCPp+M2fEf94+q8qH24=,tag:qXsa3wVFdBC1OqIRJu5whw==,type:str]
9+
sops:
10+
age:
11+
- recipient: age1cpv0ejrvuv2hslsy4nq66zwkmkqrn4c3km66lwfkmcyqpxr8v4wsfajuck
12+
enc: |
13+
-----BEGIN AGE ENCRYPTED FILE-----
14+
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBDYXR4N3RPWlV5RVJyTk1B
15+
Tm5Qb3FjaXZNSW9SdWQxSXY1Q1V0L2huUW04CkkyT01VR3IwNWdFeFp4WXM5TjBW
16+
SUtZTDJhNEJhVHhmTlZEeVdabHMyTGsKLS0tIFlJeGp4b1hTMS9lYUlOL0RMTDRw
17+
T3Z2VG83M2I1bnpDWXBIWm90TXB0SGcK7vT50bI07km4inD3CSLwEYo1zr16hi3y
18+
aUG8nIgfL3cEVK0t08Jc0CZaojKjbIg4HtdprTk5i624gNpiH9rlsA==
19+
-----END AGE ENCRYPTED FILE-----
20+
- recipient: age1cq92796c46d06s43t079xc89exe4vd52rh30c9mcafmne62dxyhqrupl4l
21+
enc: |
22+
-----BEGIN AGE ENCRYPTED FILE-----
23+
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBLc3lmckdmem9hZlp1Skh2
24+
Q1p6MXJUeW5wMkZGeTF2RDlKZWpGNUROSFFrCllNU3JkeDVpNjgxZGd1RVljd1hm
25+
eEFjSTIwUTdnbzJ0U20xRElPZURWT2sKLS0tIGN3ditwVFBkU1ZGcC8ydTJCYzdv
26+
TGZoT0VpV3lmTHJRZmNwM09mclFidnMKm6bLvGEN4Bt9fp+Q9enmn0jF5USE3J9q
27+
N1G/msqxVT6ngrGpjiGDCYisMQvugcOrYEa2M1rRohcAUB/EqNyN9g==
28+
-----END AGE ENCRYPTED FILE-----
29+
lastmodified: "2025-11-04T16:08:53Z"
30+
mac: ENC[AES256_GCM,data:m8t9mgzPUYk6eAYTnfh/B5K2XYPFfj5APza0fQYa4LTYAN/plvS1BKz4fyC0n7TyLJX43fGo16oxvq1VAlt/nnhy9I8lMc7v168w7kuIakAf242RXg2c/X4N9fbpzoWDrhYrpzfmSZv9b28/NQC30mUd+S8j8DWJPrdC1ydqRtY=,iv:4DbnuRWp9xbIU/jY8i8SaVdG2VjXQFc40LzPBWXw+oo=,tag:7fxB+0oDti8cBHoGj23UBg==,type:str]
31+
unencrypted_regex: ^(apiVersion|metadata|kind|type)$
32+
version: 3.11.0

0 commit comments

Comments
 (0)