theshire/kubernetes/apps/observability/grafana/app/externalsecret.yaml

40 lines
1.2 KiB
YAML
Raw Normal View History

---
# yaml-language-server: $schema=https://ks.hsn.dev/external-secrets.io/externalsecret_v1beta1.json
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
2024-03-01 08:53:43 -06:00
name: grafana-secret
namespace: observability
spec:
secretStoreRef:
kind: ClusterSecretStore
name: onepassword-connect
target:
name: grafana-secret
2024-03-01 08:25:37 -06:00
creationPolicy: Owner
template:
engineVersion: v2
data:
2024-03-01 08:25:37 -06:00
GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET: "{{ .authentik_grafana_oauth_client_secret }}"
2024-03-01 13:13:23 -06:00
GF_DATE_FORMATS_USE_BROWSER_LOCALE: "true"
GF_SERVER_ROOT_URL: https://grafana.hsn.dev
GF_DATABASE_NAME: ${DB_NAME}
GF_DATABASE_HOST: "grafana-primary.observability.svc:5432"
GF_DATABASE_USER: "{{ .grafana_postgres_user }}"
GF_DATABASE_PASSWORD: "{{ .grafana_postgres_password }}"
2024-03-01 13:27:30 -06:00
GF_DATABASE_SSL_MODE: "require"
GF_DATABASE_TYPE: postgres
dataFrom:
- extract:
2024-03-01 08:25:37 -06:00
key: Authentik
rewrite:
- regexp:
source: "(.*)"
target: "authentik_$1"
2024-03-01 13:13:23 -06:00
- extract:
key: grafana
rewrite:
- regexp:
source: "(.*)"
target: "grafana_$1"