From 888b33fa772bc75af511d1f251e45ae3522487f9 Mon Sep 17 00:00:00 2001 From: Victor Roest Date: Fri, 29 Oct 2021 20:21:25 +0200 Subject: [PATCH] external-secrets: add vault store --- .../external-secrets/kustomization.yaml | 1 + .../external-secrets/vault-secret-store.yaml | 26 +++++++++++++++++++ 2 files changed, 27 insertions(+) create mode 100644 cluster/core/external-secrets/external-secrets/vault-secret-store.yaml diff --git a/cluster/core/external-secrets/external-secrets/kustomization.yaml b/cluster/core/external-secrets/external-secrets/kustomization.yaml index 2fa2de2..28844c0 100644 --- a/cluster/core/external-secrets/external-secrets/kustomization.yaml +++ b/cluster/core/external-secrets/external-secrets/kustomization.yaml @@ -3,3 +3,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - helm-release.yaml + - vault-secret-store diff --git a/cluster/core/external-secrets/external-secrets/vault-secret-store.yaml b/cluster/core/external-secrets/external-secrets/vault-secret-store.yaml new file mode 100644 index 0000000..929866e --- /dev/null +++ b/cluster/core/external-secrets/external-secrets/vault-secret-store.yaml @@ -0,0 +1,26 @@ +apiVersion: external-secrets.io/v1alpha1 +kind: ClusterSecretStore +metadata: + name: vault + namespace: external-secrets +spec: + provider: + vault: + server: "http://10.42.42.6:8200" + path: "k8s" + version: "v2" + auth: + # VaultAppRole authenticates with Vault using the + # App Role auth mechanism + # https://www.vaultproject.io/docs/auth/approle + appRole: + # Path where the App Role authentication backend is mounted + path: "approle" + # RoleID configured in the App Role authentication backend + roleId: "bb841a0e-45c1-9dab-36f0-f72647d6aff0" + # Reference to a key in a K8 Secret that contains the App Role SecretId + # (not commited in git) + secretRef: + name: "vault-secret-id" + namespace: "external-secrets" + key: "secret-id"