477c65cb4e
Replace the out-of-band cephrgw-credentials Secret with a VSO-managed one so the operator's Ceph dashboard credentials come from Vault. - Add apps/base/cephrgw-system/vaultauth.yaml: VaultAuth (k8s/au/syd1 mount, role cephrgw-operator, SA cephrgw-operator, connection vso-system/default). - Add apps/base/cephrgw-system/vaultstaticsecret.yaml: renders the KV path service/cephrgw/dashboard-credentials into the cephrgw-credentials Secret (keys copied verbatim, consumed by the Deployment via envFrom). - Reference both from the base kustomization. Requires the Vault role/policy from terraform-vault #95 and the KV values to be seeded (see the operator's docs/ceph-setup.md).
14 lines
408 B
YAML
14 lines
408 B
YAML
---
|
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
resources:
|
|
- namespace.yaml
|
|
# CRDs are pulled from the cephrgw-operator repo at the matching tag rather
|
|
# than vendored here, so they never drift from the operator.
|
|
- https://git.unkin.net/unkin/cephrgw-operator/raw/tag/v0.1.0/config/crd/install.yaml
|
|
- rbac.yaml
|
|
- deployment.yaml
|
|
- vaultauth.yaml
|
|
- vaultstaticsecret.yaml
|