Skip to content

Commit a72ecec

Browse files
ziv-codefresheti-codefreshdaniel-codefresh
authored
add sealed secrets (#352)
* add sealed secrets * add sealed secrets * bump * for local testing * add pods to app-proxy role * . * ready for production Signed-off-by: Daniel Soifer <daniel.soifer@codefresh.io> * add sealed-secrets to manifests * bump app-proxy 1.1302.0 Co-authored-by: Eti Zaguri <eti.zaguri@codefresh.io> Co-authored-by: Daniel Soifer <daniel.soifer@codefresh.io>
1 parent 946e44b commit a72ecec

File tree

7 files changed

+38
-5
lines changed

7 files changed

+38
-5
lines changed

Makefile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
VERSION=v0.0.376
1+
VERSION=v0.0.377
22

33
OUT_DIR=dist
44
YEAR?=$(shell date +"%Y")

docs/releases/release_notes.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ cf version
2323

2424
```bash
2525
# download and extract the binary
26-
curl -L --output - https://github.com/codefresh-io/cli-v2/releases/download/v0.0.376/cf-linux-amd64.tar.gz | tar zx
26+
curl -L --output - https://github.com/codefresh-io/cli-v2/releases/download/v0.0.377/cf-linux-amd64.tar.gz | tar zx
2727

2828
# move the binary to your $PATH
2929
mv ./cf-linux-amd64 /usr/local/bin/cf
@@ -36,7 +36,7 @@ cf version
3636

3737
```bash
3838
# download and extract the binary
39-
curl -L --output - https://github.com/codefresh-io/cli-v2/releases/download/v0.0.376/cf-darwin-amd64.tar.gz | tar zx
39+
curl -L --output - https://github.com/codefresh-io/cli-v2/releases/download/v0.0.377/cf-darwin-amd64.tar.gz | tar zx
4040

4141
# move the binary to your $PATH
4242
mv ./cf-darwin-amd64 /usr/local/bin/cf

manifests/app-proxy/app-proxy.role.yaml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,11 +10,21 @@ rules:
1010
resources:
1111
- secrets
1212
- configmap
13+
- pods
1314
verbs:
1415
- get
1516
- create
1617
- delete
18+
- deletecollection
1719
- update
1820
- patch
1921
- list
2022
- watch
23+
- apiGroups:
24+
- ""
25+
resources:
26+
- services
27+
verbs:
28+
- get
29+
- list
30+

manifests/app-proxy/kustomization.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ kind: Kustomization
33
images:
44
- name: quay.io/codefresh/cap-app-proxy
55
newName: quay.io/codefresh/cap-app-proxy
6-
newTag: 1.1300.0
6+
newTag: 1.1302.0
77
resources:
88
- app-proxy.deploy.yaml
99
- app-proxy.svc.yaml
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
apiVersion: kustomize.config.k8s.io/v1beta1
2+
kind: Kustomization
3+
bases:
4+
- ../../sealed-secrets

manifests/runtime.yaml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ metadata:
55
namespace: "{{ namespace }}"
66
spec:
77
defVersion: 1.0.1
8-
version: 0.0.376
8+
version: 0.0.377
99
bootstrapSpecifier: github.com/codefresh-io/cli-v2/manifests/argo-cd
1010
components:
1111
- name: events
@@ -21,3 +21,6 @@ spec:
2121
- name: app-proxy
2222
type: kustomize
2323
url: github.com/codefresh-io/cli-v2/manifests/app-proxy
24+
- name: sealed-secrets
25+
type: kustomize
26+
url: github.com/codefresh-io/cli-v2/manifests/sealed-secrets
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
apiVersion: kustomize.config.k8s.io/v1beta1
2+
kind: Kustomization
3+
resources:
4+
- https://github.com/bitnami-labs/sealed-secrets/releases/download/v0.17.5/controller.yaml
5+
6+
patches:
7+
- target:
8+
group: apps
9+
version: v1
10+
kind: Deployment
11+
name: sealed-secrets-controller
12+
patch: |-
13+
- op: add
14+
path: /spec/template/spec/containers/0/args/-
15+
value: --key-renew-period=720h
16+

0 commit comments

Comments
 (0)