argocd-apps/apps/base/woodpecker/vaultstaticsecret.yaml
Ben Vincent 738a674a2f
All checks were successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
feat: manage woodpecker-agent-secret in vault
- unkin/terraform-vault#60
2026-03-03 23:34:57 +11:00

35 lines
722 B
YAML

---
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: woodpecker-gitea
namespace: woodpecker
spec:
destination:
create: true
name: woodpecker-gitea
overwrite: false
hmacSecretData: true
mount: kv
path: service/woodpecker/woodpecker-gitea
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
---
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: woodpecker-agent-secret
namespace: woodpecker
spec:
destination:
create: true
name: woodpecker-agent-secret
overwrite: true
hmacSecretData: true
mount: kv
path: service/woodpecker/woodpecker-agent-secret
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default