mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-07-27 08:00:46 +00:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| fde6b5f23a |
@@ -55,7 +55,6 @@ updates:
|
|||||||
- "/kubernetes/system/blocky"
|
- "/kubernetes/system/blocky"
|
||||||
- "/kubernetes/system/caddy"
|
- "/kubernetes/system/caddy"
|
||||||
- "/kubernetes/system/cert-manager"
|
- "/kubernetes/system/cert-manager"
|
||||||
- "/kubernetes/system/cert-manager-webhook-ovh"
|
|
||||||
- "/kubernetes/system/coredns"
|
- "/kubernetes/system/coredns"
|
||||||
- "/kubernetes/system/csi-driver-nfs"
|
- "/kubernetes/system/csi-driver-nfs"
|
||||||
- "/kubernetes/system/external-dns"
|
- "/kubernetes/system/external-dns"
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
# This file contains all route definitions, imported by the main Caddyfile.
|
# This file contains all route definitions, imported by the main Caddyfile.
|
||||||
# Edit this file to add/modify routes.
|
# Edit this file to add/modify routes.
|
||||||
#
|
#
|
||||||
# Certificate files are mounted from cert-manager-managed TLS Secrets
|
# Certificate files are mounted from the caddy-certificates Secret
|
||||||
# at /etc/caddy/certs/
|
# at /etc/caddy/certs/
|
||||||
|
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
|
|||||||
File diff suppressed because one or more lines are too long
@@ -10,7 +10,7 @@ image:
|
|||||||
repository: caddy
|
repository: caddy
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
tagSuffix: ""
|
tagSuffix: ""
|
||||||
tag: 2.11.2
|
tag: 2.11.4
|
||||||
service:
|
service:
|
||||||
type: LoadBalancer
|
type: LoadBalancer
|
||||||
externalTrafficPolicy: Local
|
externalTrafficPolicy: Local
|
||||||
@@ -125,4 +125,4 @@ sops:
|
|||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
||||||
version: 3.10.2
|
version: 3.10.2
|
||||||
@@ -22,23 +22,19 @@ spec:
|
|||||||
dnsZones:
|
dnsZones:
|
||||||
- vhaudiquet.fr
|
- vhaudiquet.fr
|
||||||
- buildpath.win
|
- buildpath.win
|
||||||
# OVH solver for semery.fr (via cert-manager-webhook-ovh)
|
# OVH solver for semery.fr
|
||||||
- dns01:
|
- dns01:
|
||||||
webhook:
|
ovh:
|
||||||
groupName: acme.aureq.com
|
endpoint: ovh-eu
|
||||||
solverName: ovh
|
applicationKeyRef:
|
||||||
config:
|
name: ovh-credentials
|
||||||
endpoint: ovh-eu
|
key: applicationKey
|
||||||
authenticationMethod: application
|
applicationSecretRef:
|
||||||
applicationKeyRef:
|
name: ovh-credentials
|
||||||
name: ovh-credentials
|
key: applicationSecret
|
||||||
key: applicationKey
|
consumerKeyRef:
|
||||||
applicationSecretRef:
|
name: ovh-credentials
|
||||||
name: ovh-credentials
|
key: consumerKey
|
||||||
key: applicationSecret
|
|
||||||
applicationConsumerKeyRef:
|
|
||||||
name: ovh-credentials
|
|
||||||
key: consumerKey
|
|
||||||
selector:
|
selector:
|
||||||
dnsZones:
|
dnsZones:
|
||||||
- semery.fr
|
- semery.fr
|
||||||
|
|||||||
@@ -3,5 +3,3 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
- clusterissuer.yaml
|
- clusterissuer.yaml
|
||||||
- ovh-credentials-secret.yaml
|
|
||||||
- ovh-secret-reader-rbac.yaml
|
|
||||||
|
|||||||
@@ -1,50 +0,0 @@
|
|||||||
# OVH API Credentials for DNS-01 Challenges
|
|
||||||
#
|
|
||||||
# OVH API credentials with the following permissions:
|
|
||||||
# - GET, POST, PUT, DELETE on /domain/zone/*
|
|
||||||
#
|
|
||||||
# The secret MUST live in the cert-manager-webhook-ovh namespace (cert-manager),
|
|
||||||
# because for a ClusterIssuer cert-manager sets the webhook's ResourceNamespace
|
|
||||||
# to the webhook's own namespace, and the webhook looks up credential secrets
|
|
||||||
# there (see ch.ResourceNamespace in the webhook's ovhClient() function).
|
|
||||||
#
|
|
||||||
# SOPS will encrypt the stringData fields on pre-commit.
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: ovh-credentials
|
|
||||||
namespace: cert-manager
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: cert-manager-webhook-ovh
|
|
||||||
app.kubernetes.io/component: ovh-credentials
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
applicationKey: ENC[AES256_GCM,data:0+y+m8n/eup5lY/vGW5ASQ==,iv:VSIhfNAvSNOLq92TVcaW54ygU1wgAv+u35HZ0cbP6UU=,tag:KD+cyIesTQgqEzGMro8xyA==,type:str]
|
|
||||||
applicationSecret: ENC[AES256_GCM,data:sP0febHRFF/atAFlRM6sYXoM+Lp6Rnf7d0IQKcsa0vY=,iv:nHYMHSsOclkZmQJSjcz2oXMHsDTct5hTmJz1L7xgvpA=,tag:oCGoRP7R0W+PTNRCeLFvyg==,type:str]
|
|
||||||
consumerKey: ENC[AES256_GCM,data:vw/Q39CpSc5o1ntPDMT3844aLbTHQrSYH8RhoZFFZrQ=,iv:6B0F9Zq56inpW7AS8okbpqJkRK3WkBjX6sIqclOP9Hs=,tag:nnbgwBMBM4JZg/IEYzRvVw==,type:str]
|
|
||||||
sops:
|
|
||||||
lastmodified: "2026-07-10T05:06:52Z"
|
|
||||||
mac: ENC[AES256_GCM,data:0/VEDE1ZuIyzkaleosS/KHYX44762TbScrJGJylwV21d7U6YgpwRMOXvU9xn3rHsDXnh5IAmAtrXQTYJFN1vcF1DNw5O9+TQKVoO6B5rsel/YyKRU4s7aYcfDgbW9dO1wn33K65KFtM+0Qv187DzEn1by449TgWIWP/M5U40PE4=,iv:hIGzMwsas8VxC4941ABeoocYWSlVSz9KW7a5tTAoRXI=,tag:n/EJEkEBL20carqVesMBsw==,type:str]
|
|
||||||
pgp:
|
|
||||||
- created_at: "2026-07-10T05:06:52Z"
|
|
||||||
enc: |-
|
|
||||||
-----BEGIN PGP MESSAGE-----
|
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiARAAu0va03SPYOU23iUjoTMiXJ6+nMhIX8lsurvmCvi+wIqk
|
|
||||||
c7qu0lTfXv62IjkY6fIKtOE7TN9TiipjzXG2QJaK94QeiFpe9M90qNo09qEIje9m
|
|
||||||
DepTrLfyINFT0SY2eihl+nXhBXuEDSiD5K60OsXGPN92hJMwCad5jJuB7xpmrX0m
|
|
||||||
X0A1Bl9orce/do/YJoy5hq0persB/VSeCKlptNzqpmpRIA3J6AdCDKXQOMqAymXN
|
|
||||||
FXAxbjEQNcXhfU12Y/cVpa1hS7ap5OJCnWOPkFEA8y1ESVnPpryuTIfVlFUhW3/Z
|
|
||||||
Dhpb9OXKdi2IVYdbaY8+3UfSsXxTVOge7jCMbJq3aa7ZvGt5fTjXG4zc9A6RqSGh
|
|
||||||
ASOPSkRRSZB0d97NhUQJGgfcaWFvsfkaTAUVB2Ip/+Udnt/tGIE99RGJizxSVO9N
|
|
||||||
2aVJIukqng8aNPfth8mgWYJpCETMb4piLmVg2ptDqelCqXlUAskxWzMWtAhyzOgw
|
|
||||||
lZ2dcAn7aj9YtLaKAW9rjV8EqHEqQg0ychRNMeyRiN/CnNJp6Q2wl1/EyQUpzb0a
|
|
||||||
1I/ifFAW8FbWTVIbZv6njkl1XNaoav54qEn1qSABcljM0h1Ulb9WKMJiXH4368jf
|
|
||||||
Yhl38JDAn5NZBEzxpuaih1XK5yVri0/1ascpuMvfOxLKniUR9tla8+WEL97+aejS
|
|
||||||
XgGsrH+/uzRVSAT+44rExi43MWCAwNRUaVrX8UiGjA/z8qPVdwBVih4CMKgfQ8VW
|
|
||||||
1KewStOY217BXuVrDbvHEAkuOotEP0Jnan0epoWs47DSasNgzAcWrBgom0l/avI=
|
|
||||||
=Gdou
|
|
||||||
-----END PGP MESSAGE-----
|
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
|
||||||
encrypted_regex: ^(data|stringData|.*.key|.*.crt)$
|
|
||||||
version: 3.10.2
|
|
||||||
@@ -1,41 +0,0 @@
|
|||||||
# RBAC granting the cert-manager-webhook-ovh service account read access to the
|
|
||||||
# OVH credentials secret.
|
|
||||||
#
|
|
||||||
# The cert-manager-webhook-ovh chart only auto-creates this secret-reader Role
|
|
||||||
# when using its built-in `issuers[]` mechanism. Since we manage the
|
|
||||||
# ClusterIssuer and the credentials secret manually, we declare the RBAC here.
|
|
||||||
#
|
|
||||||
# The webhook runs in the cert-manager namespace under the
|
|
||||||
# `cert-manager-webhook-ovh` service account (created by the Helm release).
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh:ovh-secret-reader
|
|
||||||
namespace: cert-manager
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: cert-manager-webhook-ovh
|
|
||||||
app.kubernetes.io/component: ovh-secret-reader
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["secrets"]
|
|
||||||
verbs: ["get", "watch"]
|
|
||||||
resourceNames:
|
|
||||||
- ovh-credentials
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh:ovh-secret-reader
|
|
||||||
namespace: cert-manager
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: cert-manager-webhook-ovh
|
|
||||||
app.kubernetes.io/component: ovh-secret-reader
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: cert-manager-webhook-ovh:ovh-secret-reader
|
|
||||||
subjects:
|
|
||||||
- apiGroup: ""
|
|
||||||
kind: ServiceAccount
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: cert-manager
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
namespace: cert-manager
|
|
||||||
resources:
|
|
||||||
- repository.yaml
|
|
||||||
- release.yaml
|
|
||||||
secretGenerator:
|
|
||||||
- name: cert-manager-webhook-ovh-values
|
|
||||||
files:
|
|
||||||
- values.yaml=values.yaml
|
|
||||||
configurations:
|
|
||||||
- kustomizeconfig.yaml
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
nameReference:
|
|
||||||
- kind: HelmRepository
|
|
||||||
version: v1
|
|
||||||
fieldSpecs:
|
|
||||||
- path: spec/chart/spec/sourceRef/name
|
|
||||||
kind: HelmRelease
|
|
||||||
- kind: Secret
|
|
||||||
version: v1
|
|
||||||
fieldSpecs:
|
|
||||||
- path: spec/valuesFrom/name
|
|
||||||
kind: HelmRelease
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
apiVersion: helm.toolkit.fluxcd.io/v2
|
|
||||||
kind: HelmRelease
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: cert-manager
|
|
||||||
spec:
|
|
||||||
interval: 1m
|
|
||||||
chart:
|
|
||||||
spec:
|
|
||||||
sourceRef:
|
|
||||||
kind: HelmRepository
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: cert-manager
|
|
||||||
chart: cert-manager-webhook-ovh
|
|
||||||
version: "v0.9.13"
|
|
||||||
interval: 1m
|
|
||||||
valuesFrom:
|
|
||||||
- kind: Secret
|
|
||||||
name: cert-manager-webhook-ovh-values
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
apiVersion: source.toolkit.fluxcd.io/v1
|
|
||||||
kind: HelmRepository
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: cert-manager
|
|
||||||
spec:
|
|
||||||
interval: 1m
|
|
||||||
url: https://aureq.github.io/cert-manager-webhook-ovh
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
# cert-manager-webhook-ovh Values
|
|
||||||
# groupName must match the ClusterIssuer webhook stanza
|
|
||||||
groupName: acme.aureq.com
|
|
||||||
# cert-manager deployment configuration for RBAC
|
|
||||||
# The webhook creates ClusterRole/RoleBinding so cert-manager's
|
|
||||||
# service account can create the "ovh" ChallengePayload resources
|
|
||||||
certManager:
|
|
||||||
namespace: cert-manager
|
|
||||||
serviceAccountName: cert-manager
|
|
||||||
# Pod configuration
|
|
||||||
pod:
|
|
||||||
replicas: 1
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 10m
|
|
||||||
memory: 32Mi
|
|
||||||
limits:
|
|
||||||
cpu: 100m
|
|
||||||
memory: 128Mi
|
|
||||||
sops:
|
|
||||||
lastmodified: "2026-07-09T22:31:08Z"
|
|
||||||
mac: ENC[AES256_GCM,data:QjrNj355tJVZRsYQdkM73Ld7X8EvMM7O/1vF3QnTYJ9vWbh78irLocbtnyBeaR9o3g0mxO6Ugjlukj+S0HhIX/WS1XHEfs/3n3rE0zS/fxGJ0D3Alam/n/WPOsYHUiCBD86JtU83AjgncISY4yp/VheV3kRgSdl+ye4AGAjhq7A=,iv:p8yqNCcskTfDfEGbM5Qyb60C4pFv4BOuLpEApEzHLFY=,tag:KntExeQwJbBREaz2nY+1uQ==,type:str]
|
|
||||||
pgp:
|
|
||||||
- created_at: "2026-07-09T22:31:08Z"
|
|
||||||
enc: |-
|
|
||||||
-----BEGIN PGP MESSAGE-----
|
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiAQ/8Dn4nEIbQXuETxE6RUBkNTO/eN5pHh47lqSwBBbYDSi8C
|
|
||||||
8rcJmdq8P+v00geLdMlM35OcjHFb9UCVeHFsAEYt6Q2jL4QNa2aOEDOqGnhKP+zx
|
|
||||||
KKtW2Ngx76Ow9N2C5JN9DXk9n+PC/qWdPLNJY+GiW/KbPmVxAulJpmYlJHfs1EOh
|
|
||||||
0mSRSS+7sgGLHWmgU362zC508lkKxh8HKxmq1+1lf+fWIe8N7Sl0fx55kq168hae
|
|
||||||
NcdogRpoVT555hRils7eqzj0C/KTVOi7CR4pS7VJyiNy2fu2OASmmcM6UEqCyJfV
|
|
||||||
NTUdMpnjb05UwfbuUnIg6j/FoqS49ufGxKPrM9t7JrFSuyGqduF7P/ifv5zwMuIZ
|
|
||||||
SNeR/X8xUksK6R4/uTmUx5sgF+Jv7tCRvcp+DhsDe1mMmO8czXC5Mt3cR+uwYoms
|
|
||||||
hN+9/oYEZr13qn5Ek0dy9NESkZIzYPCXYXZrx8GLqaHCJEQbpIZCAN+llOyQaQzU
|
|
||||||
jcvPAYbTewBw4ewKUS0KcvLd1pfzvYyvtzwHuMIVJwrf7x5bzhzxAgVOGkEVlVq/
|
|
||||||
7pGO9TYXGl3kD7tf25oCGzAerVC+EVcL11sq4zawvL4PovEZFP9mzhR7EfY3t/3C
|
|
||||||
vGVu6vPmCJOwdis9+Kdr3PKubnMqWGn5KCCX1x13qhsHc239N7cVKkyx3dTBaArS
|
|
||||||
XAG6KxKe/cQicIVC8/N1Cna9uQnTF5ZnFVfJNW1nkYyF1E+ofW6kKDr3ITotKLDP
|
|
||||||
hXXPT+vsB2fL3faBG4xb6owrMuQ1S0DmB3mqjSCXtpS7q0FDg22Tq9BtaEni
|
|
||||||
=x1th
|
|
||||||
-----END PGP MESSAGE-----
|
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
|
||||||
version: 3.10.2
|
|
||||||
@@ -6,6 +6,7 @@ resources:
|
|||||||
- repository.yaml
|
- repository.yaml
|
||||||
- release.yaml
|
- release.yaml
|
||||||
- cloudflare-api-token-secret.yaml
|
- cloudflare-api-token-secret.yaml
|
||||||
|
- ovh-credentials-secret.yaml
|
||||||
secretGenerator:
|
secretGenerator:
|
||||||
- name: cert-manager-values
|
- name: cert-manager-values
|
||||||
files:
|
files:
|
||||||
|
|||||||
@@ -0,0 +1,45 @@
|
|||||||
|
# OVH API Credentials for DNS-01 Challenges
|
||||||
|
#
|
||||||
|
# OVH API credentials with the following permissions:
|
||||||
|
# - GET, POST, PUT, DELETE on /domain/zone/*
|
||||||
|
#
|
||||||
|
# SOPS will encrypt them on pre-commit.
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: ovh-credentials
|
||||||
|
namespace: cert-manager
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: cert-manager
|
||||||
|
app.kubernetes.io/component: ovh-credentials
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
applicationKey: ENC[AES256_GCM,data:YhH6Ty+JJOelaq7G975wLw==,iv:zbwPRv1tdsyoN+rFoOIItzYC7wmv20zMX/ij6RnC8cI=,tag:n+NIrIp9IgunK9ZD15cULA==,type:str]
|
||||||
|
applicationSecret: ENC[AES256_GCM,data:5jxfV5a0jyCtXQKZJjxNmNTiyZ71nLoP0A/KYm+oQ9k=,iv:77SewJ13vouMbEey2oZav32bHsi/cvyKgE1VQapdzhw=,tag:Be58t/rpZrbHun3mMzrWww==,type:str]
|
||||||
|
consumerKey: ENC[AES256_GCM,data:zYTI4cHz36Is5pwUObL9XPDi6XEftonrjz+32jsNkEM=,iv:saNZrLThBa0b+D7S37IO2WpUmnm7ixshMbJaryZzYuE=,tag:v/BhwdJVlxDaeBi570b3Ig==,type:str]
|
||||||
|
sops:
|
||||||
|
lastmodified: "2026-07-09T21:17:10Z"
|
||||||
|
mac: ENC[AES256_GCM,data:pakPqwigSb9Q1nuAcT4w4VumqQ1f1AGGx3WqNASs04eN/RxhWE+LQbY8BgNQ/YUx6HveypU6UH+ppMgPDwCZS7tUwTR/tXpDp/r3WIlhoQghtNGVp/eCpj9Tu91rnjc9Prv9wH8AWaJESeuK5dhZm+LAIvUczP3a+mUhQkXTtok=,iv:WQPfvLOODtvv88+vcTHMfiYcskS394mw+xBPacgCEgw=,tag:l5VMpNnInaeTXWWfkVonrw==,type:str]
|
||||||
|
pgp:
|
||||||
|
- created_at: "2026-07-09T21:17:10Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMA7uy4qQr71wiARAAn1Wjcdq7Asc920TamGFdlQiDJa4T5iZKJohtXWbJXMSK
|
||||||
|
fqdDgMGWb5OdiCFprRkysckxsY0sWBzc/lOXlj2rw0UV2q66Rxrq19esvUDTfGfK
|
||||||
|
K1cKJ/tegcQ4heQsC+QUgC9SBZlqiA88yDGSO9j9hyBcaSWgkeTUWvrEBFeyLHDn
|
||||||
|
Yha0gxJibNSqmv+B6d5HepkwW6tpESXNX1NFJbYCx46nA6nrttbZCOxzQbS/oBKC
|
||||||
|
pmG4NzU6rQE57zcGpZOGYX8sQWjas0mhPiSAgFOdCdINuWFnONC1jUj5EnBM4LZH
|
||||||
|
+pkZtVmEl7D2SpPNtslTqJKCUbyIHGabblM76p2NKVL8vrTR3k2AM+aL5jS4536d
|
||||||
|
fRRWiWZihsn9PUHsSVLGZPkFe2ceHtM1JjGaX/M+0ZDag3gDUSCR8GdVbDd/95Xs
|
||||||
|
GeGGcVzmuTP16bYsTkXOMixvx7/q3yqAWP2FDvgJqJ3oataRlYwpVZBWDQo50eSb
|
||||||
|
w1fzARbMRz+OWNd+uFgWiHddFR12Xow1tfCSog9WAFjZQ++yjrRsqMH/x8NgWb0l
|
||||||
|
oq/vkHAg4WDqlKUa47vW56c8pZqsiWP8d8V/7b8avhHDdCb+SNOSe5QxO2AA8EAr
|
||||||
|
bjdwSpsErZNFWasYKqfs5ye4ct2tpCI5llRoR6WwnmM3mJflZAt983TPiZC8QLLS
|
||||||
|
XAHLR9ap5zx2shcdyyGOV5+7VmkDaSeB1baxeiORaQKK7CvVblhuIz0ZS097KUI5
|
||||||
|
HBTYvvIdEdXMn3hRalYzyuayKCiC6WEl/UKzXLiCiu94ijbaKqlOtW07anP/
|
||||||
|
=B+/W
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
|
encrypted_regex: ^(data|stringData|.*.key|.*.crt)$
|
||||||
|
version: 3.10.2
|
||||||
@@ -14,7 +14,6 @@ spec:
|
|||||||
path: ./kubernetes/system/cert-manager-issuer
|
path: ./kubernetes/system/cert-manager-issuer
|
||||||
dependsOn:
|
dependsOn:
|
||||||
- name: cert-manager
|
- name: cert-manager
|
||||||
- name: cert-manager-webhook-ovh
|
|
||||||
decryption:
|
decryption:
|
||||||
provider: sops
|
provider: sops
|
||||||
secretRef:
|
secretRef:
|
||||||
|
|||||||
@@ -1,20 +0,0 @@
|
|||||||
# Flux Kustomization for cert-manager-webhook-ovh
|
|
||||||
# Depends on cert-manager being fully operational (CRDs installed)
|
|
||||||
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
|
||||||
kind: Kustomization
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: flux-system
|
|
||||||
spec:
|
|
||||||
interval: 10m
|
|
||||||
prune: true
|
|
||||||
sourceRef:
|
|
||||||
kind: GitRepository
|
|
||||||
name: homeprod
|
|
||||||
path: ./kubernetes/system/cert-manager-webhook-ovh
|
|
||||||
dependsOn:
|
|
||||||
- name: cert-manager
|
|
||||||
decryption:
|
|
||||||
provider: sops
|
|
||||||
secretRef:
|
|
||||||
name: flux-sops
|
|
||||||
@@ -5,5 +5,4 @@ kind: Kustomization
|
|||||||
resources:
|
resources:
|
||||||
- webhook.yaml
|
- webhook.yaml
|
||||||
- cert-manager.yaml
|
- cert-manager.yaml
|
||||||
- cert-manager-webhook-ovh.yaml
|
|
||||||
- cert-manager-issuer.yaml
|
- cert-manager-issuer.yaml
|
||||||
|
|||||||
Reference in New Issue
Block a user