mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-09-22 00:43:32 +00:00
Address review feedback on SOPS handling for encrypted values.yaml. - renovate.json: Renovate has NO preUpgradeTasks option (verified against the renovate-schema). Decrypt must therefore happen inside postUpgradeTasks (which run after the tag bump, before the commit): decrypt the values.yaml, then re-encrypt. Encrypting an already-encrypted file would double-encrypt the existing ENC secret values. Only **/values.yaml is re-encrypted; the docker-compose and Chart.yaml files are not SOPS-encrypted here. - kubernetes/code/renovate: self-hosted Renovate runner as a Flux CronJob running the renovatebot/renovate image, with sops allowed as a postUpgradeTask command and the SOPS PGP key loaded to re-encrypt values.yaml. Secrets come from SOPS-encrypted dotenv/env file sources. - Wire code/renovate into the root kubernetes kustomization.
12 lines
312 B
JSON
12 lines
312 B
JSON
{
|
|
"platform": "github",
|
|
"repositories": ["vhaudiquet/homeprod"],
|
|
"autodiscover": false,
|
|
"allowedPostUpgradeCommands": ["^sops"],
|
|
"allowedPostUpgradeCommandsEnv": ["^SOPS_"],
|
|
"onboardingConfigFileName": "renovate.json",
|
|
"dryRun": false,
|
|
"binarySource": "docker",
|
|
"schedule": ["every weekend"]
|
|
}
|