forked from vhaudiquet/homeprod
fix(renovate): decrypt values BEFORE renovate edits them (retract broken post-bump round-trip)
The prior postUpgradeTasks command 'sops -d ... && sops -e' was wrong: Renovate has no preUpgradeTasks hook, and postUpgradeTasks runs AFTER Renovate rewrites the file. These values.yaml are SOPS documents whose sops.mac authenticates the whole file, so editing a plaintext image.tag invalidates the MAC and 'sops -d' then fails (data-integrity error). The claimed decrypt-after-bump therefore could never work. boot.sh now decrypts every values.yaml in the checkout BEFORE Renovate extracts/edits them, committing the decrypted tree locally (never pushed, so no plaintext secrets enter remote git). postUpgradeTasks is reduced to 'sops -e -i' only (the file is already plaintext when Renovate edits it). Validated: kustomize build passes for the whole kubernetes/ tree.
This commit is contained in:
@@ -10,13 +10,14 @@ configMapGenerator:
|
||||
- name: renovate-config
|
||||
files:
|
||||
- config.json=config.json
|
||||
- boot.sh=boot.sh
|
||||
secretGenerator:
|
||||
- name: renovate-secrets
|
||||
envs:
|
||||
- renovate.env
|
||||
# SOPS PGP private key needed by the renovate runner to re-encrypt
|
||||
# values.yaml during postUpgradeTasks. Mounted into the pod and imported
|
||||
# into the container gpg keyring at startup.
|
||||
# SOPS PGP private key needed by the renovate runner to decrypt values.yaml
|
||||
# at boot and to re-encrypt them during postUpgradeTasks. Mounted into the
|
||||
# pod and imported into the container gpg keyring at startup.
|
||||
- name: renovate-gpg
|
||||
files:
|
||||
- git-renovate-gpg.key
|
||||
|
||||
Reference in New Issue
Block a user