--- # Renders the radosgw credentials from Vault into the cephrgw-credentials # Secret the operator Deployment consumes via envFrom. The KV secret's keys # (CEPH_RGW_ACCESS_KEY/SECRET_KEY, CEPH_RGW_ENDPOINT, optional # CEPH_RGW_ADMIN_ENDPOINT/REGION/CA) are copied verbatim, so they land as the # matching env vars. # # The path sits under the templated default policy # (kv/data/kubernetes/namespace///*), so it needs no dedicated Vault # role or policy. Seed the values with: # vault kv put kv/kubernetes/namespace/cephrgw-system/default/cephrgw-credentials \ # CEPH_RGW_ENDPOINT=https://s3.ceph.unkin.net \ # CEPH_RGW_ADMIN_ENDPOINT=https://radosgw.service.consul:443 \ # CEPH_RGW_ACCESS_KEY=... CEPH_RGW_SECRET_KEY=... apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultStaticSecret metadata: name: cephrgw-credentials namespace: cephrgw-system spec: vaultAuthRef: default mount: kv type: kv-v2 path: kubernetes/namespace/cephrgw-system/default/cephrgw-credentials refreshAfter: 5m hmacSecretData: true destination: name: cephrgw-credentials create: true overwrite: true