--- # ClickHouse credentials for the `vector` user. # # Seed the Vault KV entry once (values are NOT stored in git), e.g.: # PW=$(openssl rand -base64 24) # HASH=$(printf '%s' "$PW" | sha256sum | cut -d' ' -f1) # vault kv put kv/kubernetes/namespace/logging/default/clickhouse-credentials \ # username=vector password="$PW" password_sha256_hex="$HASH" # # The `logging/default` ServiceAccount reads this path via the templated # `policies/kv/kubernetes/default.yaml` policy (k8s auth role `default`), so no # terraform-vault change is required — only the value above must be written. apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultStaticSecret metadata: name: clickhouse-credentials namespace: logging spec: destination: create: true name: clickhouse-credentials overwrite: true hmacSecretData: true mount: kv path: kubernetes/namespace/logging/default/clickhouse-credentials refreshAfter: 5m type: kv-v2 vaultAuthRef: default --- # ClickHouse credentials for the read-only `logreader` user (CLI tools + # logviewer UI). Seeded the same way as clickhouse-credentials above: # PW=$(openssl rand -hex 24) # HASH=$(printf '%s' "$PW" | sha256sum | cut -d' ' -f1) # vault kv put kv/kubernetes/namespace/logging/default/clickhouse-logreader \ # username=logreader password="$PW" password_sha256_hex="$HASH" apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultStaticSecret metadata: name: clickhouse-logreader namespace: logging spec: destination: create: true name: clickhouse-logreader overwrite: true hmacSecretData: true mount: kv path: kubernetes/namespace/logging/default/clickhouse-logreader refreshAfter: 5m type: kv-v2 vaultAuthRef: default --- # NATS JetStream auth. Distinct passwords for the producer (edge), consumer # (transform tier + archiver) and admin (bootstrap Job) users. Seed once: # for k in admin producer consumer; do declare P_$k=$(openssl rand -base64 24); done # vault kv put kv/kubernetes/namespace/logging/default/nats-auth \ # admin_password="$P_admin" producer_password="$P_producer" consumer_password="$P_consumer" apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultStaticSecret metadata: name: nats-auth namespace: logging spec: destination: create: true name: nats-auth overwrite: true hmacSecretData: true mount: kv path: kubernetes/namespace/logging/default/nats-auth refreshAfter: 5m type: kv-v2 vaultAuthRef: default