From 5ae9618b22d06785ee2a62cf1eaf1869eec3f737 Mon Sep 17 00:00:00 2001 From: Khue Doan Date: Mon, 29 Dec 2025 13:59:34 +0700 Subject: [PATCH] chore: move demo Vault secret to example app --- apps/test/example/production.yaml | 4 ++++ infra/_modules/bootstrap/vault-test.yaml | 25 ------------------------ infra/_modules/bootstrap/vault.tf | 4 ++-- 3 files changed, 6 insertions(+), 27 deletions(-) delete mode 100644 infra/_modules/bootstrap/vault-test.yaml diff --git a/apps/test/example/production.yaml b/apps/test/example/production.yaml index 075ff2a..7784ea2 100644 --- a/apps/test/example/production.yaml +++ b/apps/test/example/production.yaml @@ -10,6 +10,10 @@ controllers: image: repository: zot.zot.svc.cluster.local/example-service tag: 828c31f942e8913ab2af53a2841c180586c5b7e1 + env: + # TODO this secret was created manually in vault + # vault kv put secret/test/example MANUALLY_CREATED_EXAMPLE_SECRET=s3cr3t + EXAMPLE_SECRET: vault:secret/data/test/example#MANUALLY_CREATED_EXAMPLE_SECRET service: main: controller: main diff --git a/infra/_modules/bootstrap/vault-test.yaml b/infra/_modules/bootstrap/vault-test.yaml deleted file mode 100644 index 1dab555..0000000 --- a/infra/_modules/bootstrap/vault-test.yaml +++ /dev/null @@ -1,25 +0,0 @@ -# TODO vault kv put secret/demosecret/aws AWS_SECRET_ACCESS_KEY=s3cr3t -# TODO kubectl apply -f test-vault.yaml -apiVersion: apps/v1 -kind: Deployment -metadata: - name: vault-test - namespace: default -spec: - replicas: 1 - selector: - matchLabels: - app.kubernetes.io/name: vault - template: - metadata: - labels: - app.kubernetes.io/name: vault - spec: - serviceAccountName: default - containers: - - name: alpine - image: alpine - command: ["sh", "-c", "echo $AWS_SECRET_ACCESS_KEY && echo going to sleep... && sleep 10000"] - env: - - name: AWS_SECRET_ACCESS_KEY - value: vault:secret/data/demosecret/aws#AWS_SECRET_ACCESS_KEY diff --git a/infra/_modules/bootstrap/vault.tf b/infra/_modules/bootstrap/vault.tf index dafbc30..2618456 100644 --- a/infra/_modules/bootstrap/vault.tf +++ b/infra/_modules/bootstrap/vault.tf @@ -135,8 +135,8 @@ resource "kubectl_manifest" "vault" { { # TODO optimize this name = "default" - bound_service_account_names = ["default"] - bound_service_account_namespaces = ["default"] + bound_service_account_names = ["*"] + bound_service_account_namespaces = ["*"] policies = ["allow_secrets"] ttl = "1h" } -- 2.51.2