From ce0d9dedf42b83580f08ae71f751cf10e8144b11 Mon Sep 17 00:00:00 2001 From: dvirlabs Date: Thu, 21 May 2026 19:27:23 +0300 Subject: [PATCH] add charts/secrets, secrets-mail-services app, standardize raw-resources app --- argocd-apps/raw-resources-mail-services.yaml | 26 +++++-------------- argocd-apps/secrets-mail-services.yaml | 23 ++++++++++++++++ charts/secrets/Chart.yaml | 6 +++++ charts/secrets/templates/external-secret.yaml | 23 ++++++++++++++++ manifests/secrets-mail-services/values.yaml | 5 ++++ 5 files changed, 64 insertions(+), 19 deletions(-) create mode 100644 argocd-apps/secrets-mail-services.yaml create mode 100644 charts/secrets/Chart.yaml create mode 100644 charts/secrets/templates/external-secret.yaml create mode 100644 manifests/secrets-mail-services/values.yaml diff --git a/argocd-apps/raw-resources-mail-services.yaml b/argocd-apps/raw-resources-mail-services.yaml index 9715db4..b2d25bd 100644 --- a/argocd-apps/raw-resources-mail-services.yaml +++ b/argocd-apps/raw-resources-mail-services.yaml @@ -3,32 +3,20 @@ kind: Application metadata: name: raw-resources-mail-services namespace: argocd - finalizers: - - resources-finalizer.argocd.argoproj.io spec: - project: default - + project: mail-services source: - repoURL: https://git.dvirlabs.com/dvirlabs/mail-services.git + repoURL: ssh://git@gitea-ssh.dev-tools.svc.cluster.local:2222/dvirlabs/mail-services.git targetRevision: HEAD path: manifests/raw-resources-mail-services - + directory: + recurse: true destination: server: https://kubernetes.default.svc namespace: mail-services - - ignoreDifferences: - - group: "" - kind: Service - jsonPointers: - - /metadata/annotations/argocd.argoproj.io~1tracking-id - syncPolicy: + automated: + prune: true + selfHeal: true syncOptions: - CreateNamespace=true - retry: - limit: 5 - backoff: - duration: 5s - factor: 2 - maxDuration: 3m diff --git a/argocd-apps/secrets-mail-services.yaml b/argocd-apps/secrets-mail-services.yaml new file mode 100644 index 0000000..cee1735 --- /dev/null +++ b/argocd-apps/secrets-mail-services.yaml @@ -0,0 +1,23 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: secrets-mail-services + namespace: argocd +spec: + project: mail-services + source: + repoURL: ssh://git@gitea-ssh.dev-tools.svc.cluster.local:2222/dvirlabs/mail-services.git + targetRevision: HEAD + path: charts/secrets + helm: + valueFiles: + - ../../manifests/secrets-mail-services/values.yaml + destination: + server: https://kubernetes.default.svc + namespace: mail-services + syncPolicy: + automated: + prune: true + selfHeal: true + syncOptions: + - CreateNamespace=true diff --git a/charts/secrets/Chart.yaml b/charts/secrets/Chart.yaml new file mode 100644 index 0000000..402fec2 --- /dev/null +++ b/charts/secrets/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: secrets +description: Generic ExternalSecret resources chart +type: application +version: 0.1.0 +appVersion: "1.0.0" diff --git a/charts/secrets/templates/external-secret.yaml b/charts/secrets/templates/external-secret.yaml new file mode 100644 index 0000000..8ff0912 --- /dev/null +++ b/charts/secrets/templates/external-secret.yaml @@ -0,0 +1,23 @@ +{{- range .Values.externalSecrets }} +--- +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: {{ .name }} + namespace: {{ .namespace }} +spec: + refreshInterval: {{ .refreshInterval | default "1h" }} + secretStoreRef: + name: {{ $.Values.secretStore.name }} + kind: {{ $.Values.secretStore.kind }} + target: + name: {{ .targetName }} + creationPolicy: {{ .creationPolicy | default "Owner" }} + data: +{{- range .data }} + - secretKey: {{ .secretKey }} + remoteRef: + key: {{ .remoteKey }} + property: {{ .property }} +{{- end }} +{{- end }} diff --git a/manifests/secrets-mail-services/values.yaml b/manifests/secrets-mail-services/values.yaml new file mode 100644 index 0000000..b7db6dd --- /dev/null +++ b/manifests/secrets-mail-services/values.yaml @@ -0,0 +1,5 @@ +secretStore: + name: vault + kind: ClusterSecretStore + +externalSecrets: []