mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-08-03 11:30:44 +00:00
Compare commits
2 Commits
5a77fa64e5
..
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
00357f376e
|
|||
|
49224e8cb4
|
@@ -0,0 +1,214 @@
|
|||||||
|
# Talos control-plane node for the Raspberry Pi 4 — joins the r740 "kube" cluster
|
||||||
|
# as a third etcd member to restore quorum (2-of-3 majority). Unlike the p330
|
||||||
|
# failover node, this node is tainted "quorum" so no user workloads are ever
|
||||||
|
# scheduled on it; only essential DaemonSets (Cilium, etc.) that tolerate the
|
||||||
|
# taint land here for cluster networking.
|
||||||
|
#
|
||||||
|
# Secret handling: the cluster machine secrets are provided via
|
||||||
|
# var.machine_secrets_file (a local, gitignored JSON file in the provider's
|
||||||
|
# machine_secrets format). They are consumed by EPHEMERAL resources and
|
||||||
|
# WRITE-ONLY attributes so they never land in Terraform state. See
|
||||||
|
# variables.tf and scripts/extract-talos-secrets.sh for how to produce the
|
||||||
|
# file from the live r740 node.
|
||||||
|
terraform {
|
||||||
|
required_providers {
|
||||||
|
talos = {
|
||||||
|
source = "siderolabs/talos"
|
||||||
|
version = "0.11.0"
|
||||||
|
}
|
||||||
|
null = {
|
||||||
|
source = "hashicorp/null"
|
||||||
|
version = "3.2.3"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
locals {
|
||||||
|
# Load the machine secrets from the gitignored JSON file. This local is only
|
||||||
|
# ever referenced by ephemeral resources / write-only attributes, so the
|
||||||
|
# values are never persisted to state.
|
||||||
|
machine_secrets = jsondecode(file(var.machine_secrets_file))
|
||||||
|
|
||||||
|
# Network config: static if node_subnet is provided, otherwise Talos DHCPs.
|
||||||
|
# The rpi4 uses DHCP (node_subnet = null), so only nameservers are patched in.
|
||||||
|
static_network = var.node_subnet == null ? {} : {
|
||||||
|
interfaces = [{
|
||||||
|
interface = var.network_interface
|
||||||
|
addresses = [var.node_subnet]
|
||||||
|
routes = var.node_gateway == null ? [] : [{ gateway = var.node_gateway }]
|
||||||
|
}]
|
||||||
|
}
|
||||||
|
|
||||||
|
network_patch = {
|
||||||
|
nameservers = var.nameservers
|
||||||
|
}
|
||||||
|
network_patch_merged = merge(local.network_patch, local.static_network)
|
||||||
|
|
||||||
|
machine_patch = {
|
||||||
|
install = {
|
||||||
|
image = var.installer_image
|
||||||
|
disk = var.install_disk
|
||||||
|
}
|
||||||
|
network = local.network_patch_merged
|
||||||
|
# NOTE: no Longhorn iSCSI/ext4 kernel modules here. This is a quorum-only
|
||||||
|
# node: the quorum taint keeps user workloads (and Longhorn replicas) off
|
||||||
|
# it, so the storage stack is not needed. Essential DaemonSets such as
|
||||||
|
# Cilium still run here for cluster networking and tolerate the taint.
|
||||||
|
sysctls = {
|
||||||
|
"fs.inotify.max_user_instances" = "1024"
|
||||||
|
"fs.inotify.max_user_watches" = "1048576"
|
||||||
|
}
|
||||||
|
kubelet = {
|
||||||
|
# Register the node already tainted so the scheduler never admits user
|
||||||
|
# workloads even before the null_resource below runs. NoSchedule is
|
||||||
|
# sufficient: essential DaemonSets (Cilium, etc.) tolerate it, but no
|
||||||
|
# user pods are admitted.
|
||||||
|
extraArgs = {
|
||||||
|
"register-with-taints" = "${var.quorum_taint_key}=${var.quorum_taint_value}:${var.quorum_taint_effect}"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Ephemeral resources: secrets never stored in state ---------------------
|
||||||
|
#
|
||||||
|
# talos_machine_configuration generates the control-plane join config from the
|
||||||
|
# provided machine_secrets. The output (machine_configuration) is an ephemeral
|
||||||
|
# value — it can only flow into write-only attributes or provisioners, never
|
||||||
|
# into a persisted resource attribute.
|
||||||
|
ephemeral "talos_machine_configuration" "rpi4" {
|
||||||
|
cluster_name = var.cluster_name
|
||||||
|
machine_type = "controlplane"
|
||||||
|
cluster_endpoint = var.cluster_endpoint
|
||||||
|
machine_secrets = local.machine_secrets
|
||||||
|
config_patches = [
|
||||||
|
yamlencode({
|
||||||
|
machine = local.machine_patch
|
||||||
|
}),
|
||||||
|
# Pin the Kubernetes node name via a HostnameConfig document (Talos v1.13+).
|
||||||
|
# The old machine.network.hostname field conflicts with the default
|
||||||
|
# HostnameConfig document ("static hostname is already set"), so we use the
|
||||||
|
# document-based config with auto: off + an explicit hostname instead.
|
||||||
|
yamlencode({
|
||||||
|
apiVersion = "v1alpha1"
|
||||||
|
kind = "HostnameConfig"
|
||||||
|
hostname = var.rpi4_node_name
|
||||||
|
auto = "off"
|
||||||
|
})
|
||||||
|
]
|
||||||
|
}
|
||||||
|
|
||||||
|
# talos_client_configuration generates a Talos client config (talosconfig) from
|
||||||
|
# the machine_secrets, scoped to the rpi4 node. Also ephemeral — used only to
|
||||||
|
# drive the write-only client_configuration_wo on the apply resource.
|
||||||
|
ephemeral "talos_client_configuration" "rpi4" {
|
||||||
|
cluster_name = var.cluster_name
|
||||||
|
machine_secrets = local.machine_secrets
|
||||||
|
nodes = [var.rpi4_host]
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Apply the config to the node (write-only attrs → no secrets in state) --
|
||||||
|
#
|
||||||
|
# machine_configuration_input_wo and client_configuration_wo are write-only:
|
||||||
|
# Terraform uses them during apply but does NOT persist them to state. Only a
|
||||||
|
# hash of the machine config (machine_configuration_hash) is stored, for drift
|
||||||
|
# detection. Because the config patch contains a `machine.install` block, when
|
||||||
|
# Talos receives this config on a node booted from the SD card (maintenance)
|
||||||
|
# image it installs itself to install.disk and reboots into the installed
|
||||||
|
# system. As a controlplane node it then joins the existing etcd cluster as a
|
||||||
|
# new member and runs the control-plane components. With r740 + p330 + rpi4 the
|
||||||
|
# etcd cluster reaches 3 members → 2-of-3 quorum.
|
||||||
|
resource "talos_machine_configuration_apply" "rpi4" {
|
||||||
|
node = var.rpi4_host
|
||||||
|
client_configuration_wo = ephemeral.talos_client_configuration.rpi4.client_configuration
|
||||||
|
machine_configuration_input_wo = ephemeral.talos_machine_configuration.rpi4.machine_configuration
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Write the rendered config to disk for manual use ----------------------
|
||||||
|
#
|
||||||
|
# local_file.content cannot accept an ephemeral value (it would persist to
|
||||||
|
# state), so we use a null_resource local-exec provisioner instead —
|
||||||
|
# provisioners do not persist their arguments to state. This writes rpi4.yaml
|
||||||
|
# so the config can also be applied manually with
|
||||||
|
# `talosctl apply-config --nodes <rpi4_host> --file rpi4.yaml` if needed.
|
||||||
|
resource "null_resource" "rpi4_machine_config_file" {
|
||||||
|
triggers = {
|
||||||
|
# Re-run only when the (non-secret) inputs that shape the config change.
|
||||||
|
node = var.rpi4_node_name
|
||||||
|
install_disk = var.install_disk
|
||||||
|
installer_image = var.installer_image
|
||||||
|
taint = "${var.quorum_taint_key}=${var.quorum_taint_value}:${var.quorum_taint_effect}"
|
||||||
|
}
|
||||||
|
|
||||||
|
provisioner "local-exec" {
|
||||||
|
command = <<-EOT
|
||||||
|
set -euo pipefail
|
||||||
|
cat > "${path.module}/rpi4.yaml" <<'YAMLEOF'
|
||||||
|
${ephemeral.talos_machine_configuration.rpi4.machine_configuration}
|
||||||
|
YAMLEOF
|
||||||
|
echo "Wrote ${path.module}/rpi4.yaml"
|
||||||
|
EOT
|
||||||
|
}
|
||||||
|
|
||||||
|
depends_on = [talos_machine_configuration_apply.rpi4]
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Wait for the node, then label + taint ---------------------------------
|
||||||
|
#
|
||||||
|
# Wait for the node to register with Kubernetes (kubelet creates the Node
|
||||||
|
# object after Talos installs and reboots), then label it and (re)apply the
|
||||||
|
# quorum taint. This is idempotent: kubectl exits 0 if the label/taint already
|
||||||
|
# exists. The taint is also set via kubelet `register-with-taints`, so this
|
||||||
|
# null_resource is a safety net for manual edits / drift. The kubeconfig path
|
||||||
|
# is only used inside the provisioner (not persisted to state).
|
||||||
|
resource "null_resource" "rpi4_node_label_and_taint" {
|
||||||
|
triggers = {
|
||||||
|
node = var.rpi4_node_name
|
||||||
|
key = var.quorum_taint_key
|
||||||
|
value = var.quorum_taint_value
|
||||||
|
effect = var.quorum_taint_effect
|
||||||
|
kubeconfig = var.kubeconfig_path
|
||||||
|
}
|
||||||
|
|
||||||
|
provisioner "local-exec" {
|
||||||
|
# Wait for the node to show up, then label + taint. The wait loop is bounded
|
||||||
|
# by kubectl --timeout; tune it via TF_LOG / re-run if the node is slow to
|
||||||
|
# join (a controlplane node must first complete the etcd join handshake).
|
||||||
|
command = <<-EOT
|
||||||
|
set -euo pipefail
|
||||||
|
KUBECONFIG="${var.kubeconfig_path}"
|
||||||
|
export KUBECONFIG
|
||||||
|
NODE="${var.rpi4_node_name}"
|
||||||
|
|
||||||
|
echo "Waiting for node $NODE to be registered (kubelet creates the Node object once Talos has installed, rebooted and joined etcd)..."
|
||||||
|
# kubectl wait --for=condition=Ready fails instantly with NotFound if the
|
||||||
|
# node object doesn't exist yet, so poll for existence first.
|
||||||
|
# /bin/sh (dash) has no $SECONDS, so count iterations with a bounded loop.
|
||||||
|
tries=240 # 240 * 5s = 20 minutes max
|
||||||
|
until kubectl get node "$NODE" >/dev/null 2>&1; do
|
||||||
|
tries=$((tries - 1))
|
||||||
|
if [ "$tries" -le 0 ]; then
|
||||||
|
echo "Timed out waiting for node $NODE to register." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
sleep 5
|
||||||
|
done
|
||||||
|
echo "Node $NODE registered. Waiting for it to become Ready..."
|
||||||
|
|
||||||
|
# Now wait for Ready (a controlplane node needs etcd joined + apiserver up).
|
||||||
|
kubectl wait --for=condition=Ready "node/$NODE" --timeout=20m || \
|
||||||
|
kubectl wait --for=jsonpath='{.status.conditions[?(@.reason=="KubeletReady")].status}'=True "node/$NODE" --timeout=20m
|
||||||
|
|
||||||
|
# Quorum marker + taint (applied to the controlplane node).
|
||||||
|
kubectl label --overwrite node "$NODE" homeprod.io/quorum=true
|
||||||
|
|
||||||
|
# Apply the taint idempotently (kubectl taint --overwrite is a no-op if it exists).
|
||||||
|
kubectl taint --overwrite node "$NODE" \
|
||||||
|
"${var.quorum_taint_key}=${var.quorum_taint_value}:${var.quorum_taint_effect}"
|
||||||
|
|
||||||
|
echo "Node $NODE ready, labeled and tainted for quorum-only scheduling."
|
||||||
|
EOT
|
||||||
|
}
|
||||||
|
|
||||||
|
depends_on = [talos_machine_configuration_apply.rpi4]
|
||||||
|
}
|
||||||
@@ -0,0 +1,146 @@
|
|||||||
|
# Variables for the Raspberry Pi 4 Talos control-plane node that joins the r740
|
||||||
|
# "kube" cluster as a third etcd member to restore quorum (2-of-3 majority).
|
||||||
|
#
|
||||||
|
# Secret handling: the cluster machine secrets (cluster id/secret, etcd/k8s
|
||||||
|
# certs, bootstrap token) are NOT read from terraform state (the r740 state is
|
||||||
|
# stale) and are NOT generated here (that would create a new, incompatible
|
||||||
|
# cluster). Instead they are provided via `machine_secrets_file` — a local,
|
||||||
|
# gitignored JSON file in the Talos provider's machine_secrets format. The
|
||||||
|
# file is produced once from the live r740 node (see
|
||||||
|
# scripts/extract-talos-secrets.sh) and stored in a real secret manager
|
||||||
|
# (Bitwarden); you paste it back to disk when running this module. Ephemeral
|
||||||
|
# resources + write-only attributes ensure the secrets never land in Terraform
|
||||||
|
# state.
|
||||||
|
|
||||||
|
variable "rpi4_host" {
|
||||||
|
description = "Reachable IP/hostname of the rpi4 Talos node (for Talos API access). With DHCP this is the leased IP (e.g. 10.1.2.135)."
|
||||||
|
type = string
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "rpi4_node_name" {
|
||||||
|
description = "Kubernetes/Talos node name for the rpi4 (e.g. rpi4). Pinned via machine.network.hostname so the node registers with this name regardless of DHCP."
|
||||||
|
type = string
|
||||||
|
default = "rpi4"
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Cluster identity (no terraform_remote_state — state is stale) ----------
|
||||||
|
|
||||||
|
variable "cluster_name" {
|
||||||
|
description = "Name of the existing Talos cluster the rpi4 joins. Must match the cluster the r740 bootstrapped (kube-r740)."
|
||||||
|
type = string
|
||||||
|
default = "kube-r740"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "cluster_endpoint" {
|
||||||
|
description = "Endpoint (host:port) of the Talos/Kubernetes API on the cluster. Must match the r740 bootstrap endpoint."
|
||||||
|
type = string
|
||||||
|
default = "https://kube-r740.lan:6443"
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Secrets (provided manually, never in state) ---------------------------
|
||||||
|
|
||||||
|
variable "machine_secrets_file" {
|
||||||
|
description = <<EOT
|
||||||
|
Path to a local, gitignored JSON file containing the cluster machine secrets in
|
||||||
|
the Talos provider's machine_secrets format (cluster.id, cluster.secret, certs,
|
||||||
|
secrets.bootstrap_token, secrets.secretbox_encryption_secret, trustdinfo.token).
|
||||||
|
Generate it once from the live r740 node with
|
||||||
|
scripts/extract-talos-secrets.sh, store the contents in Bitwarden, and paste it
|
||||||
|
back to this file when running this module. The file MUST be gitignored — it
|
||||||
|
contains the cluster root of trust.
|
||||||
|
EOT
|
||||||
|
type = string
|
||||||
|
default = "secrets.json"
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Install / network -----------------------------------------------------
|
||||||
|
|
||||||
|
variable "installer_image" {
|
||||||
|
description = <<EOT
|
||||||
|
Talos installer image to use on the rpi4 (bare metal, ARM64).
|
||||||
|
Must be an ARM64 Image Factory build (schematic generated at
|
||||||
|
https://factory.talos.dev) for the Raspberry Pi 4 platform. Unlike the x86
|
||||||
|
control-plane nodes, this quorum node does NOT need the iSCSI/Longhorn
|
||||||
|
extensions because no user workloads or Longhorn replicas are scheduled on it
|
||||||
|
(the quorum taint keeps it empty); only essential DaemonSets (Cilium, etc.)
|
||||||
|
land here.
|
||||||
|
EOT
|
||||||
|
type = string
|
||||||
|
default = "factory.talos.dev/installer/ee21ef4a5ef808a9b7484cc0dda0f25075021691c8c09a276591eedb638ea1f9:v1.13.6"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "install_disk" {
|
||||||
|
description = "Block device path to install Talos on. For the rpi4 booting from the SD card this is /dev/mmcblk0."
|
||||||
|
type = string
|
||||||
|
default = "/dev/mmcblk0"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "node_subnet" {
|
||||||
|
description = <<EOT
|
||||||
|
Static IPv4 address in CIDR notation for the rpi4 node (e.g. 10.1.2.135/24).
|
||||||
|
Set to null (default) to use DHCP. The rpi4 uses DHCP, so a static address is
|
||||||
|
not required; the node registers with Kubernetes under rpi4_node_name regardless
|
||||||
|
of the leased IP.
|
||||||
|
EOT
|
||||||
|
type = string
|
||||||
|
default = null
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "node_gateway" {
|
||||||
|
description = "IPv4 gateway for the rpi4 node. Ignored when node_subnet is null (DHCP)."
|
||||||
|
type = string
|
||||||
|
default = null
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "network_interface" {
|
||||||
|
description = <<EOT
|
||||||
|
Primary network interface name on the rpi4. The built-in Ethernet port is eth0.
|
||||||
|
EOT
|
||||||
|
type = string
|
||||||
|
default = "eth0"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "nameservers" {
|
||||||
|
description = "DNS nameservers configured on the node (must work independently of kube)."
|
||||||
|
type = list(string)
|
||||||
|
default = ["10.1.2.148", "1.1.1.1"]
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Quorum taint ----------------------------------------------------------
|
||||||
|
|
||||||
|
variable "quorum_taint_key" {
|
||||||
|
description = "Taint key applied to the node to reserve it as a quorum-only member (no user workloads)."
|
||||||
|
type = string
|
||||||
|
default = "dedicated"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "quorum_taint_value" {
|
||||||
|
description = "Taint value applied to the node."
|
||||||
|
type = string
|
||||||
|
default = "quorum"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "quorum_taint_effect" {
|
||||||
|
description = "Taint effect applied to the node. NoSchedule is sufficient: essential DaemonSets (Cilium, etc.) tolerate it for networking, but no user workloads are admitted."
|
||||||
|
type = string
|
||||||
|
default = "NoSchedule"
|
||||||
|
|
||||||
|
validation {
|
||||||
|
condition = contains(["NoSchedule", "PreferNoSchedule", "NoExecute"], var.quorum_taint_effect)
|
||||||
|
error_message = "quorum_taint_effect must be NoSchedule, PreferNoSchedule or NoExecute."
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Kubeconfig for the label/taint null_resource --------------------------
|
||||||
|
|
||||||
|
variable "kubeconfig_path" {
|
||||||
|
description = <<EOT
|
||||||
|
Path to a kubeconfig for the cluster, used by the null_resource that waits for
|
||||||
|
the node and applies the quorum label/taint. This is NOT stored in state — it is
|
||||||
|
only referenced inside a local-exec provisioner. Point it at the r740 kube
|
||||||
|
module's kubeconfig (../../r740/kube/kubeconfig) or any valid kubeconfig for the
|
||||||
|
cluster.
|
||||||
|
EOT
|
||||||
|
type = string
|
||||||
|
default = "../../r740/kube/kubeconfig"
|
||||||
|
}
|
||||||
@@ -24,9 +24,6 @@ loki:
|
|||||||
tsdb_shipper:
|
tsdb_shipper:
|
||||||
active_index_directory: /var/loki/index
|
active_index_directory: /var/loki/index
|
||||||
cache_location: /var/loki/index-cache
|
cache_location: /var/loki/index-cache
|
||||||
filesystem:
|
|
||||||
chunks_directory: /var/loki/chunks
|
|
||||||
rules_directory: /var/loki/rules
|
|
||||||
monolithic:
|
monolithic:
|
||||||
persistence:
|
persistence:
|
||||||
storageClassName: longhorn
|
storageClassName: longhorn
|
||||||
@@ -59,27 +56,27 @@ gateway:
|
|||||||
minio:
|
minio:
|
||||||
enabled: false
|
enabled: false
|
||||||
sops:
|
sops:
|
||||||
lastmodified: "2026-07-31T09:43:02Z"
|
lastmodified: "2026-08-01T20:19:42Z"
|
||||||
mac: ENC[AES256_GCM,data:UpLILMOvXsgAcT4HkpYBYyYrLKPQeypQlJlGHzXU+7IE+Y1cWR17NPEwJZack17HMC/2c0IrlRBJtwreHULHqADrx34aQoTHN8cxRpr+XYfszx3o0CSm+Lwo2HupFmE1b6SA8KnV6C9Qqn/Wqvde7bFVaHYenvXxoLvnLOBIYQg=,iv:KBySVRbz5JpzO+8RN+YCR2UkpJ68bWhbRIL74kmMDNQ=,tag:hFW618Zc6oHVIcnkc/yqCw==,type:str]
|
mac: ENC[AES256_GCM,data:KYZQGIimeeOlt2lltCrKttLXzk2b7DOT8KNOhpeVqF/VNNcVxP7Srz6nCR5J7dI6wFSePspof5gNJEZlzP3EGJFQaGBf34hOGhHBUtlcscX8vj2JYmmJ85B+pylHjQNPHaXqLP4tAwIFfhcJi368K+GEAu8tztkxJKk7dtOOyrg=,iv:V24R3eSzW0edwPnPSSwEQqqSfiNrK6+ZyQ368xpJKhg=,tag:LmaMhhGwRIIG+SxTUJf5gQ==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-07-31T09:43:02Z"
|
- created_at: "2026-08-01T20:19:42Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiAQ//cVvg8AJiO7KGD1IyPVccefmfj4KHj7x0mc2W1BW1ZaLj
|
hQIMA7uy4qQr71wiAQ/+PDeQtUHMysWOkTjqU8vNAl1IQzDrwHskeBmLXLI99kdc
|
||||||
NSOef8ajJsRHrzY+DldPzqAOy0MyRYfCJzTEkcKe2OwZTIwCp52erFR5PQy8VLpX
|
hU0afTjzUbomFdMRGvf0QZrcFbnD5OHskw5KRleDbYxOp4aXjzX0RsqSe9elTFAj
|
||||||
85nNnKiWto9k1TdSNPidIPLNLwq24Rc4nkT5j2XcezjVNr9dV0+aWJMXd8MmZBmT
|
ml4XG0UrEV4Ygi4mTNOGzmINaIjobcn0tQd6nZFPUUA//udBcHsczs9x9Rrf+YTv
|
||||||
kyDct+W2rbiMSQMmM5R+apVbDNwGAqxNBS58G1pNcj/F2cC4sRQfLzdN6zdQaQa0
|
XrUdNAhveRlowvbvfNrDIh1OsOgyWyHJEJsKiLbt2b7e47PKhhRQzET+bNwhXzTb
|
||||||
50S76I8HbR1ZM6JWX6OkM0saH8BKigfcuYF6xZbfqSrwGzGXDpWRW/2lBwUKFFVo
|
GMY/w3rVYPddqx1wi5HPtYlhL3emYlmMYLLi1ITr1fKvAsgGKSJpaGS6yu+YkyiB
|
||||||
6abp205VFAzFvIIx2h7jaFOeuJMy1+mcJS9Uz/8gIbP507z7RxgGZEw2dIMII/Uu
|
AJHou+2aCUy1TVk8U/Ne9TSrhsV1AJSIbtr8+iyKAtSsSuodam0Pyzn59uqL4nNd
|
||||||
OQyIIQArJAa6a/cv4kQ4bypYLlTl3mJDT54VJePsmLG9ZYrtLoyI8Q9weAPiWnvZ
|
1S4Nkvm1UDYv97hmSQdAzTGs+Aql6HyB/Wyi+rkMZQ0fl7+hdX5/eEDYZzijD0Nu
|
||||||
yjp8XfImYyhJoTBPrvs5dY8q9l9lbGE1/jkbqWIaV+p3rrYl3SU5YypTt+Lvwdcl
|
Mqk1iFbTn/rXir71VRWNttycIM1PfGAOUmLoyOR+TrL5Ecy0Sx9yx2DS9DecnqtS
|
||||||
7hB0UQISF4BlDgC+3jvptJLoAPgjFkPkW9DmY3XBMJvwRogIApOnJBmxL+RciuuK
|
39YI6UNqiEYdvW8Y+XELSFI/B5cjw7C1A5S9tecUxoOIBGZZSeRQa2WDSWb1dYky
|
||||||
nrTPZ1kYmXiZQqxCZJ3VBt77P2bgQneEaJf98khfDAJ/su3kvLoK6DPsLxT1p4oc
|
Rzvncoeemgjkp8CHQhSqrylB+I4s0Y1HMUWR/q0wxew9juNEIP8ZUkfKcueuCYlm
|
||||||
O8Eqaz4t0dZFBP753YnoKEv4hDf3ySCcuBF1vsPn63ITbi1cgUKvKb44/D3dk3bS
|
5ui/RaeYatMFo8hg+DrxEtQIkbBZ/ILss/QzyHZZG3RMq0i9s/PIn5yipVhOgorS
|
||||||
XgE1/X9jh7smSRPeo+kuvWBSDHg/aQEwobhuK1wOUx2UGDYT00S/3jYNRsoam6CS
|
XAFEeOrVaKpN06LfNP7/HTI+D/5HJL++Twuyz9fwC2Eb5saIIB6gpywiICH8HcD5
|
||||||
LbG9x5v6bGOysfJNpZ1LfCWIz6sP/n6SVEYFCUYkoQsNutNYd9Yz/1MblO7hW84=
|
MRmmhl18x2YU+JdmkAcWNfH5+JHVnx8o+D/y9JqeCf6sle/9LyToazJv58Tc
|
||||||
=jcSy
|
=2u7h
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
||||||
|
|||||||
Reference in New Issue
Block a user