cephrgw-system: source cephrgw-credentials from Vault via VSO #262

Merged
benvin merged 2 commits from benvin/cephrgw-vault-vso into main 2026-07-18 23:18:01 +10:00
3 changed files with 41 additions and 0 deletions
Showing only changes of commit 477c65cb4e - Show all commits
@@ -9,3 +9,5 @@ resources:
- https://git.unkin.net/unkin/cephrgw-operator/raw/tag/v0.1.0/config/crd/install.yaml
- rbac.yaml
- deployment.yaml
- vaultauth.yaml
- vaultstaticsecret.yaml
+18
View File
@@ -0,0 +1,18 @@
---
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultAuth
metadata:
name: default
namespace: cephrgw-system
spec:
method: kubernetes
mount: k8s/au/syd1
vaultConnectionRef: vso-system/default
allowedNamespaces:
- cephrgw-system
kubernetes:
role: cephrgw-operator
serviceAccount: cephrgw-operator
audiences:
- vault
tokenExpirationSeconds: 600
@@ -0,0 +1,21 @@
---
# Renders the Ceph dashboard credentials from Vault into the cephrgw-credentials
# Secret the operator Deployment consumes via envFrom. The KV secret's keys
# (CEPH_DASHBOARD_URL/USERNAME/PASSWORD, optional CEPH_RGW_ENDPOINT/CA) are
# copied verbatim, so they land as the matching env vars.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: cephrgw-credentials
namespace: cephrgw-system
spec:
vaultAuthRef: default
mount: kv
type: kv-v2
path: service/cephrgw/dashboard-credentials
refreshAfter: 5m
hmacSecretData: true
destination:
name: cephrgw-credentials
create: true
overwrite: true