From b7a1689aeb800d0d3b036c34d9051d4a0815f81a Mon Sep 17 00:00:00 2001 From: Grraahaam <72856427+Grraahaam@users.noreply.github.com> Date: Mon, 13 Mar 2023 19:49:17 +0100 Subject: [PATCH] feat(chart): env variables auto-generation --- .../templates/backend-deployment.yaml | 35 ++++++++++------ .../templates/frontend-deployment.yaml | 16 ++++++-- helm-charts/infisical/values.yaml | 40 ++++++++++++------- 3 files changed, 60 insertions(+), 31 deletions(-) diff --git a/helm-charts/infisical/templates/backend-deployment.yaml b/helm-charts/infisical/templates/backend-deployment.yaml index 3378d8f5b..fca05b2a3 100644 --- a/helm-charts/infisical/templates/backend-deployment.yaml +++ b/helm-charts/infisical/templates/backend-deployment.yaml @@ -3,7 +3,7 @@ apiVersion: apps/v1 kind: Deployment metadata: name: {{ include "infisical.backend.fullname" . }} - {{- with .Values.backend.deploymentAnnotations }} + {{- with $backend.deploymentAnnotations }} annotations: {{- toYaml . | nindent 8 }} {{- end }} @@ -15,7 +15,7 @@ spec: matchLabels: {{- include "infisical.backend.matchLabels" . | nindent 6 }} template: - metadata: + metadata: labels: {{- include "infisical.backend.matchLabels" . | nindent 8 }} {{- with $backend.podAnnotations }} @@ -38,9 +38,6 @@ spec: envFrom: - secretRef: name: {{ $backend.kubeSecretRef | default (include "infisical.backend.fullname" .) }} - env: - - name: MONGO_URL - value: {{ include "infisical.mongodb.connectionString" . | quote }} --- @@ -55,15 +52,15 @@ metadata: {{- toYaml . | nindent 4 }} {{- end }} spec: - type: {{ .Values.backend.service.type }} + type: {{ $backend.service.type }} selector: {{- include "infisical.backend.matchLabels" . | nindent 8 }} ports: - protocol: TCP port: 4000 targetPort: 4000 # container port - {{- if eq .Values.backend.service.type "NodePort" }} - nodePort: {{ .Values.backend.service.nodePort }} + {{- if eq $backend.service.type "NodePort" }} + nodePort: {{ $backend.service.nodePort }} {{- end }} --- @@ -72,10 +69,24 @@ spec: apiVersion: v1 kind: Secret metadata: - name: {{ $backend.kubeSecretRef | default (include "infisical.backend.fullname" .) }} + name: {{ include "infisical.backend.fullname" . }} + annotations: + "helm.sh/resource-policy": "keep" type: Opaque data: - {{- range $key, $value := $backend.secrets }} - {{ $key }}: {{ $value | quote | b64enc }} - {{- end }} + {{- $requiredVars := dict "ENCRYPTION_KEY" (randAlphaNum 32 | lower) + "JWT_SIGNUP_SECRET" (randAlphaNum 32 | lower) + "JWT_REFRESH_SECRET" (randAlphaNum 32 | lower) + "JWT_AUTH_SECRET" (randAlphaNum 32 | lower) + "JWT_SERVICE_SECRET" (randAlphaNum 32 | lower) + "JWT_MFA_SECRET" (randAlphaNum 32 | lower) }} + {{- $secretObj := (lookup "v1" "Secret" .Release.Namespace (include "infisical.backend.fullname" .)) | default dict }} + {{- $secretData := (get $secretObj "data") | default dict }} + {{ range $key, $value := .Values.backendEnvironmentVariables }} + {{- $default := get $requiredVars $key -}} + {{- $current := get $secretData $key | b64dec -}} + {{- $v := $value | default ($current | default $default) -}} + {{ $key }}: {{ $v | quote | b64enc }} + {{ end -}} + MONGO_URL: {{ include "infisical.mongodb.connectionString" . | quote | b64enc }} {{- end }} diff --git a/helm-charts/infisical/templates/frontend-deployment.yaml b/helm-charts/infisical/templates/frontend-deployment.yaml index 4d6401539..e6f0a70b6 100644 --- a/helm-charts/infisical/templates/frontend-deployment.yaml +++ b/helm-charts/infisical/templates/frontend-deployment.yaml @@ -69,10 +69,18 @@ spec: apiVersion: v1 kind: Secret metadata: - name: {{ $frontend.kubeSecretRef | default (include "infisical.frontend.fullname" .) }} + name: {{ include "infisical.frontend.fullname" . }} + annotations: + "helm.sh/resource-policy": "keep" type: Opaque data: - {{- range $key, $value := $frontend.secrets }} - {{ $key }}: {{ $value | quote | b64enc }} - {{- end }} + {{- $requiredVars := dict }} + {{- $secretObj := (lookup "v1" "Secret" .Release.Namespace (include "infisical.frontend.fullname" .)) | default dict }} + {{- $secretData := (get $secretObj "data") | default dict }} + {{ range $key, $value := .Values.frontendEnvironmentVariables }} + {{- $default := get $requiredVars $key -}} + {{- $current := get $secretData $key | b64dec -}} + {{- $v := $value | default ($current | default $default) -}} + {{ $key }}: {{ $v | quote | b64enc }} + {{ end -}} {{- end }} \ No newline at end of file diff --git a/helm-charts/infisical/values.yaml b/helm-charts/infisical/values.yaml index d569e7c31..8253aba21 100644 --- a/helm-charts/infisical/values.yaml +++ b/helm-charts/infisical/values.yaml @@ -46,6 +46,8 @@ frontend: ## @param frontend.kubeSecretRef Backend secret resource reference name (containing required [frontend configuration variables](https://infisical.com/docs/self-hosting/configuration/envars)) ## kubeSecretRef: "" + ## Frontend service + ## service: ## @param frontend.service.annotations Backend service annotations ## @@ -103,6 +105,8 @@ backend: ## @param backend.kubeSecretRef Backend secret resource reference name (containing required [backend configuration variables](https://infisical.com/docs/self-hosting/configuration/envars)) ## kubeSecretRef: "" + ## Backend service + ## service: ## @param backend.service.annotations Backend service annotations ## @@ -118,20 +122,22 @@ backend: ## Documentation : https://infisical.com/docs/self-hosting/configuration/envars ## backendEnvironmentVariables: - ## @param backendEnvironmentVariables.ENCRYPTION_KEY **Required** Backend encryption key (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)) + ## @param backendEnvironmentVariables.ENCRYPTION_KEY **Required** Backend encryption key (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)). auto-generated variable (if not provided, and not found in an existing secret) ## Command to generate the required value (linux) : 'hexdump -vn16 -e'4/4 "%08X" 1 "\n"' /dev/urandom', 'openssl rand -hex 16' ## - ENCRYPTION_KEY: MUST_REPLACE - ## @param backendEnvironmentVariables.JWT_SIGNUP_SECRET **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)) - ## @param backendEnvironmentVariables.JWT_REFRESH_SECRET **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)) - ## @param backendEnvironmentVariables.JWT_AUTH_SECRET **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)) - ## @param backendEnvironmentVariables.JWT_SERVICE_SECRET **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)) + ENCRYPTION_KEY: "" + ## @param backendEnvironmentVariables.JWT_SIGNUP_SECRET **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)). auto-generated variable (if not provided, and not found in an existing secret) + ## @param backendEnvironmentVariables.JWT_REFRESH_SECRET **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)). auto-generated variable (if not provided, and not found in an existing secret) + ## @param backendEnvironmentVariables.JWT_AUTH_SECRET **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)). auto-generated variable (if not provided, and not found in an existing secret) + ## @param backendEnvironmentVariables.JWT_SERVICE_SECRET **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)). auto-generated variable (if not provided, and not found in an existing secret) + ## @param backendEnvironmentVariables.JWT_MFA_SECRET **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057)). auto-generated variable (if not provided, and not found in an existing secret) ## Command to generate the required value (linux) : 'hexdump -vn16 -e'4/4 "%08X" 1 "\n"' /dev/urandom', 'openssl rand -hex 16' ## - JWT_SIGNUP_SECRET: MUST_REPLACE - JWT_REFRESH_SECRET: MUST_REPLACE - JWT_AUTH_SECRET: MUST_REPLACE - JWT_SERVICE_SECRET: MUST_REPLACE + JWT_SIGNUP_SECRET: "" + JWT_REFRESH_SECRET: "" + JWT_AUTH_SECRET: "" + JWT_SERVICE_SECRET: "" + JWT_MFA_SECRET: "" ## @param backendEnvironmentVariables.SMTP_HOST **Required** Hostname to connect to for establishing SMTP connections ## @param backendEnvironmentVariables.SMTP_PORT Port to connect to for establishing SMTP connections ## @param backendEnvironmentVariables.SMTP_SECURE If true, use TLS when connecting to host. If false, TLS will be used if STARTTLS is supported @@ -140,13 +146,13 @@ backendEnvironmentVariables: ## @param backendEnvironmentVariables.SMTP_USERNAME **Required** Credential to connect to host (e.g. team@infisical.com) ## @param backendEnvironmentVariables.SMTP_PASSWORD **Required** Credential to connect to host ## - SMTP_HOST: MUST_REPLACE + SMTP_HOST: "" SMTP_PORT: 587 SMTP_SECURE: false SMTP_FROM_NAME: Infisical - SMTP_FROM_ADDRESS: MUST_REPLACE - SMTP_USERNAME: MUST_REPLACE - SMTP_PASSWORD: MUST_REPLACE + SMTP_FROM_ADDRESS: "" + SMTP_USERNAME: "" + SMTP_PASSWORD: "" ## @param backendEnvironmentVariables.SITE_URL Absolute URL including the protocol (e.g. https://app.infisical.com) ## SITE_URL: infisical.local @@ -209,8 +215,12 @@ mongodb: ## databases: - "infisical" - rootPassword: root + ## @param mongodb.auth.rootPassword Database root user name + ## rootUser: root + ## @param mongodb.auth.rootPassword Database root user password + ## + rootPassword: root ## MongoDB persistence configuration ## persistence: