Secrets... ugh

This commit is contained in:
Joseph Hanson 2024-03-01 13:13:23 -06:00
parent c7a900045c
commit abdf3f9f63
2 changed files with 14 additions and 17 deletions

View file

@ -16,6 +16,14 @@ spec:
engineVersion: v2
data:
GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET: "{{ .authentik_grafana_oauth_client_secret }}"
GF_DATE_FORMATS_USE_BROWSER_LOCALE: "true"
GF_SERVER_ROOT_URL: https://grafana.hsn.dev
GF_DATABASE_NAME: ${DB_NAME}
GF_DATABASE_HOST: "grafana-primary.observability.svc:5432"
GF_DATABASE_USER: "{{ .grafana_postgres_user }}"
GF_DATABASE_PASSWORD: "{{ .grafana_postgres_password }}"
GF_DATABASE_SSL_MODE: disable
GF_DATABASE_TYPE: postgres
dataFrom:
- extract:
key: Authentik
@ -23,3 +31,9 @@ spec:
- regexp:
source: "(.*)"
target: "authentik_$1"
- extract:
key: grafana
rewrite:
- regexp:
source: "(.*)"
target: "grafana_$1"

View file

@ -30,21 +30,4 @@ spec:
namespace: observability
values:
replicas: 2
env:
GF_DATE_FORMATS_USE_BROWSER_LOCALE: true
GF_SERVER_ROOT_URL: https://grafana.hsn.dev
GF_DATABASE_NAME: ${DB_NAME}
GF_DATABASE_HOST: "grafana-primary.observability.svc:5432"
GF_DATABASE_USER:
valueFrom:
secretKeyRef:
name: "${APP}-pguser-${DB_USER}"
key: user
GF_DATABASE_PASSWORD:
valueFrom:
secretKeyRef:
name: "${APP}-pguser-${DB_USER}"
key: password
GF_DATABASE_SSL_MODE: disable
GF_DATABASE_TYPE: postgres
envFromSecret: grafana-secret