mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
fix: rename managedSecretReferneces to managedKubeSecretReferences
This commit is contained in:
@@ -26,7 +26,7 @@ spec:
|
|||||||
name: <service-account-name>
|
name: <service-account-name>
|
||||||
namespace: <service-account-namespace>
|
namespace: <service-account-namespace>
|
||||||
|
|
||||||
managedSecretReferences:
|
managedKubeSecretReferences:
|
||||||
- secretName: managed-secret
|
- secretName: managed-secret
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
creationPolicy: "Orphan"
|
creationPolicy: "Orphan"
|
||||||
@@ -544,29 +544,29 @@ The Infisical operator will automatically create the Kubernetes secret in the sp
|
|||||||
<Note>
|
<Note>
|
||||||
|
|
||||||
The `managedSecretReference` field is deprecated and will be removed in a future release.
|
The `managedSecretReference` field is deprecated and will be removed in a future release.
|
||||||
Replace it with `managedSecretReferences`, which now accepts an array of references to support multiple managed secrets in a single InfisicalSecret CRD.
|
Replace it with `managedKubeSecretReferences`, which now accepts an array of references to support multiple managed secrets in a single InfisicalSecret CRD.
|
||||||
|
|
||||||
Example:
|
Example:
|
||||||
```yaml
|
```yaml
|
||||||
managedSecretReferences:
|
managedKubeSecretReferences:
|
||||||
- secretName: managed-secret
|
- secretName: managed-secret
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
creationPolicy: "Orphan"
|
creationPolicy: "Orphan"
|
||||||
```
|
```
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
<Accordion title="managedSecretReferences">
|
<Accordion title="managedKubeSecretReferences">
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="managedSecretReferences[].secretName">
|
<Accordion title="managedKubeSecretReferences[].secretName">
|
||||||
The name of the managed Kubernetes secret to be created
|
The name of the managed Kubernetes secret to be created
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="managedSecretReferences[].secretNamespace">
|
<Accordion title="managedKubeSecretReferences[].secretNamespace">
|
||||||
The namespace of the managed Kubernetes secret to be created.
|
The namespace of the managed Kubernetes secret to be created.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="managedSecretReferences[].secretType">
|
<Accordion title="managedKubeSecretReferences[].secretType">
|
||||||
Override the default Opaque type for managed secrets with this field. Useful for creating kubernetes.io/dockerconfigjson secrets.
|
Override the default Opaque type for managed secrets with this field. Useful for creating kubernetes.io/dockerconfigjson secrets.
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="managedSecretReferences[].creationPolicy">
|
<Accordion title="managedKubeSecretReferences[].creationPolicy">
|
||||||
Creation polices allow you to control whether or not owner references should be added to the managed Kubernetes secret that is generated by the Infisical operator.
|
Creation polices allow you to control whether or not owner references should be added to the managed Kubernetes secret that is generated by the Infisical operator.
|
||||||
This is useful for tools such as ArgoCD, where every resource requires an owner reference; otherwise, it will be pruned automatically.
|
This is useful for tools such as ArgoCD, where every resource requires an owner reference; otherwise, it will be pruned automatically.
|
||||||
|
|
||||||
@@ -587,18 +587,18 @@ This is useful for tools such as ArgoCD, where every resource requires an owner
|
|||||||
Fetching secrets from Infisical as is via the operator may not be enough. This is where templating functionality may be helpful.
|
Fetching secrets from Infisical as is via the operator may not be enough. This is where templating functionality may be helpful.
|
||||||
Using Go templates, you can format, combine, and create new key-value pairs from secrets fetched from Infisical before storing them as Kubernetes Secrets.
|
Using Go templates, you can format, combine, and create new key-value pairs from secrets fetched from Infisical before storing them as Kubernetes Secrets.
|
||||||
|
|
||||||
<Accordion title="managedSecretReferences[].template">
|
<Accordion title="managedKubeSecretReferences[].template">
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="managedSecretReferences[].template.includeAllSecrets">
|
<Accordion title="managedKubeSecretReferences[].template.includeAllSecrets">
|
||||||
This property controls what secrets are included in your managed secret when using templates.
|
This property controls what secrets are included in your managed secret when using templates.
|
||||||
When set to `true`, all secrets fetched from your Infisical project will be added into your managed Kubernetes secret resource.
|
When set to `true`, all secrets fetched from your Infisical project will be added into your managed Kubernetes secret resource.
|
||||||
**Use this option when you would like to sync all secrets from Infisical to Kubernetes but want to template a subset of them.**
|
**Use this option when you would like to sync all secrets from Infisical to Kubernetes but want to template a subset of them.**
|
||||||
|
|
||||||
When set to `false`, only secrets defined in the `managedSecretReferences[].template.data` field of the template will be included in the managed secret.
|
When set to `false`, only secrets defined in the `managedKubeSecretReferences[].template.data` field of the template will be included in the managed secret.
|
||||||
Use this option when you would like to sync **only** a subset of secrets from Infisical to Kubernetes.
|
Use this option when you would like to sync **only** a subset of secrets from Infisical to Kubernetes.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="managedSecretReferences[].template.data">
|
<Accordion title="managedKubeSecretReferences[].template.data">
|
||||||
Define secret keys and their corresponding templates.
|
Define secret keys and their corresponding templates.
|
||||||
Each data value uses a Golang template with access to all secrets retrieved from the specified scope.
|
Each data value uses a Golang template with access to all secrets retrieved from the specified scope.
|
||||||
|
|
||||||
@@ -614,7 +614,7 @@ type TemplateSecret struct {
|
|||||||
#### Example template configuration:
|
#### Example template configuration:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
managedSecretReferences:
|
managedKubeSecretReferences:
|
||||||
- secretName: managed-secret
|
- secretName: managed-secret
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
template:
|
template:
|
||||||
@@ -666,7 +666,7 @@ The example below assumes that the `BINARY_KEY_BASE64` secret is stored as a bas
|
|||||||
The resulting managed secret will contain the decoded value of `BINARY_KEY_BASE64`.
|
The resulting managed secret will contain the decoded value of `BINARY_KEY_BASE64`.
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
managedSecretReferences:
|
managedKubeSecretReferences:
|
||||||
secretName: managed-secret
|
secretName: managed-secret
|
||||||
secretNamespace: default
|
secretNamespace: default
|
||||||
template:
|
template:
|
||||||
@@ -927,7 +927,7 @@ spec:
|
|||||||
..
|
..
|
||||||
authentication:
|
authentication:
|
||||||
...
|
...
|
||||||
managedSecretReferences:
|
managedKubeSecretReferences:
|
||||||
...
|
...
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
@@ -13,9 +13,9 @@ type: application
|
|||||||
# This is the chart version. This version number should be incremented each time you make changes
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
# to the chart and its templates, including the app version.
|
# to the chart and its templates, including the app version.
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
version: v0.8.5
|
version: v0.8.6
|
||||||
# This is the version number of the application being deployed. This version number should be
|
# This is the version number of the application being deployed. This version number should be
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
# It is recommended to use it with quotes.
|
# It is recommended to use it with quotes.
|
||||||
appVersion: "v0.8.5"
|
appVersion: "v0.8.6"
|
||||||
|
|||||||
@@ -261,46 +261,7 @@ spec:
|
|||||||
hostAPI:
|
hostAPI:
|
||||||
description: Infisical host to pull secrets from
|
description: Infisical host to pull secrets from
|
||||||
type: string
|
type: string
|
||||||
managedSecretReference:
|
managedKubeSecretReferences:
|
||||||
properties:
|
|
||||||
creationPolicy:
|
|
||||||
default: Orphan
|
|
||||||
description: 'The Kubernetes Secret creation policy. Enum with values:
|
|
||||||
''Owner'', ''Orphan''. Owner creates the secret and sets .metadata.ownerReferences
|
|
||||||
of the InfisicalSecret CRD that created it. Orphan will not set
|
|
||||||
the secret owner. This will result in the secret being orphaned
|
|
||||||
and not deleted when the resource is deleted.'
|
|
||||||
type: string
|
|
||||||
secretName:
|
|
||||||
description: The name of the Kubernetes Secret
|
|
||||||
type: string
|
|
||||||
secretNamespace:
|
|
||||||
description: The name space where the Kubernetes Secret is located
|
|
||||||
type: string
|
|
||||||
secretType:
|
|
||||||
default: Opaque
|
|
||||||
description: 'The Kubernetes Secret type (experimental feature).
|
|
||||||
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
|
||||||
type: string
|
|
||||||
template:
|
|
||||||
description: The template to transform the secret data
|
|
||||||
properties:
|
|
||||||
data:
|
|
||||||
additionalProperties:
|
|
||||||
type: string
|
|
||||||
description: The template key values
|
|
||||||
type: object
|
|
||||||
includeAllSecrets:
|
|
||||||
description: This injects all retrieved secrets into the top
|
|
||||||
level of your template. Secrets defined in the template will
|
|
||||||
take precedence over the injected ones.
|
|
||||||
type: boolean
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- secretName
|
|
||||||
- secretNamespace
|
|
||||||
type: object
|
|
||||||
managedSecretReferences:
|
|
||||||
items:
|
items:
|
||||||
properties:
|
properties:
|
||||||
creationPolicy:
|
creationPolicy:
|
||||||
@@ -342,6 +303,45 @@ spec:
|
|||||||
- secretNamespace
|
- secretNamespace
|
||||||
type: object
|
type: object
|
||||||
type: array
|
type: array
|
||||||
|
managedSecretReference:
|
||||||
|
properties:
|
||||||
|
creationPolicy:
|
||||||
|
default: Orphan
|
||||||
|
description: 'The Kubernetes Secret creation policy. Enum with values:
|
||||||
|
''Owner'', ''Orphan''. Owner creates the secret and sets .metadata.ownerReferences
|
||||||
|
of the InfisicalSecret CRD that created it. Orphan will not set
|
||||||
|
the secret owner. This will result in the secret being orphaned
|
||||||
|
and not deleted when the resource is deleted.'
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
secretType:
|
||||||
|
default: Opaque
|
||||||
|
description: 'The Kubernetes Secret type (experimental feature).
|
||||||
|
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
||||||
|
type: string
|
||||||
|
template:
|
||||||
|
description: The template to transform the secret data
|
||||||
|
properties:
|
||||||
|
data:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: The template key values
|
||||||
|
type: object
|
||||||
|
includeAllSecrets:
|
||||||
|
description: This injects all retrieved secrets into the top
|
||||||
|
level of your template. Secrets defined in the template will
|
||||||
|
take precedence over the injected ones.
|
||||||
|
type: boolean
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
resyncInterval:
|
resyncInterval:
|
||||||
default: 60
|
default: 60
|
||||||
type: integer
|
type: integer
|
||||||
|
|||||||
@@ -32,7 +32,7 @@ controllerManager:
|
|||||||
- ALL
|
- ALL
|
||||||
image:
|
image:
|
||||||
repository: infisical/kubernetes-operator
|
repository: infisical/kubernetes-operator
|
||||||
tag: v0.8.5
|
tag: v0.8.6
|
||||||
resources:
|
resources:
|
||||||
limits:
|
limits:
|
||||||
cpu: 500m
|
cpu: 500m
|
||||||
|
|||||||
@@ -138,7 +138,7 @@ type InfisicalSecretSpec struct {
|
|||||||
ManagedSecretReference ManagedKubeSecretConfig `json:"managedSecretReference"`
|
ManagedSecretReference ManagedKubeSecretConfig `json:"managedSecretReference"`
|
||||||
|
|
||||||
// +kubebuilder:validation:Optional
|
// +kubebuilder:validation:Optional
|
||||||
ManagedSecretReferences []ManagedKubeSecretConfig `json:"managedSecretReferences"`
|
ManagedKubeSecretReferences []ManagedKubeSecretConfig `json:"managedKubeSecretReferences"`
|
||||||
|
|
||||||
// +kubebuilder:default:=60
|
// +kubebuilder:default:=60
|
||||||
ResyncInterval int `json:"resyncInterval"`
|
ResyncInterval int `json:"resyncInterval"`
|
||||||
|
|||||||
@@ -565,8 +565,8 @@ func (in *InfisicalSecretSpec) DeepCopyInto(out *InfisicalSecretSpec) {
|
|||||||
out.TokenSecretReference = in.TokenSecretReference
|
out.TokenSecretReference = in.TokenSecretReference
|
||||||
out.Authentication = in.Authentication
|
out.Authentication = in.Authentication
|
||||||
in.ManagedSecretReference.DeepCopyInto(&out.ManagedSecretReference)
|
in.ManagedSecretReference.DeepCopyInto(&out.ManagedSecretReference)
|
||||||
if in.ManagedSecretReferences != nil {
|
if in.ManagedKubeSecretReferences != nil {
|
||||||
in, out := &in.ManagedSecretReferences, &out.ManagedSecretReferences
|
in, out := &in.ManagedKubeSecretReferences, &out.ManagedKubeSecretReferences
|
||||||
*out = make([]ManagedKubeSecretConfig, len(*in))
|
*out = make([]ManagedKubeSecretConfig, len(*in))
|
||||||
for i := range *in {
|
for i := range *in {
|
||||||
(*in)[i].DeepCopyInto(&(*out)[i])
|
(*in)[i].DeepCopyInto(&(*out)[i])
|
||||||
|
|||||||
@@ -261,47 +261,7 @@ spec:
|
|||||||
hostAPI:
|
hostAPI:
|
||||||
description: Infisical host to pull secrets from
|
description: Infisical host to pull secrets from
|
||||||
type: string
|
type: string
|
||||||
managedSecretReference:
|
managedKubeSecretReferences:
|
||||||
properties:
|
|
||||||
creationPolicy:
|
|
||||||
default: Orphan
|
|
||||||
description: 'The Kubernetes Secret creation policy. Enum with
|
|
||||||
values: ''Owner'', ''Orphan''. Owner creates the secret and
|
|
||||||
sets .metadata.ownerReferences of the InfisicalSecret CRD that
|
|
||||||
created it. Orphan will not set the secret owner. This will
|
|
||||||
result in the secret being orphaned and not deleted when the
|
|
||||||
resource is deleted.'
|
|
||||||
type: string
|
|
||||||
secretName:
|
|
||||||
description: The name of the Kubernetes Secret
|
|
||||||
type: string
|
|
||||||
secretNamespace:
|
|
||||||
description: The name space where the Kubernetes Secret is located
|
|
||||||
type: string
|
|
||||||
secretType:
|
|
||||||
default: Opaque
|
|
||||||
description: 'The Kubernetes Secret type (experimental feature).
|
|
||||||
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
|
||||||
type: string
|
|
||||||
template:
|
|
||||||
description: The template to transform the secret data
|
|
||||||
properties:
|
|
||||||
data:
|
|
||||||
additionalProperties:
|
|
||||||
type: string
|
|
||||||
description: The template key values
|
|
||||||
type: object
|
|
||||||
includeAllSecrets:
|
|
||||||
description: This injects all retrieved secrets into the top
|
|
||||||
level of your template. Secrets defined in the template
|
|
||||||
will take precedence over the injected ones.
|
|
||||||
type: boolean
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- secretName
|
|
||||||
- secretNamespace
|
|
||||||
type: object
|
|
||||||
managedSecretReferences:
|
|
||||||
items:
|
items:
|
||||||
properties:
|
properties:
|
||||||
creationPolicy:
|
creationPolicy:
|
||||||
@@ -343,6 +303,46 @@ spec:
|
|||||||
- secretNamespace
|
- secretNamespace
|
||||||
type: object
|
type: object
|
||||||
type: array
|
type: array
|
||||||
|
managedSecretReference:
|
||||||
|
properties:
|
||||||
|
creationPolicy:
|
||||||
|
default: Orphan
|
||||||
|
description: 'The Kubernetes Secret creation policy. Enum with
|
||||||
|
values: ''Owner'', ''Orphan''. Owner creates the secret and
|
||||||
|
sets .metadata.ownerReferences of the InfisicalSecret CRD that
|
||||||
|
created it. Orphan will not set the secret owner. This will
|
||||||
|
result in the secret being orphaned and not deleted when the
|
||||||
|
resource is deleted.'
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
secretType:
|
||||||
|
default: Opaque
|
||||||
|
description: 'The Kubernetes Secret type (experimental feature).
|
||||||
|
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
||||||
|
type: string
|
||||||
|
template:
|
||||||
|
description: The template to transform the secret data
|
||||||
|
properties:
|
||||||
|
data:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: The template key values
|
||||||
|
type: object
|
||||||
|
includeAllSecrets:
|
||||||
|
description: This injects all retrieved secrets into the top
|
||||||
|
level of your template. Secrets defined in the template
|
||||||
|
will take precedence over the injected ones.
|
||||||
|
type: boolean
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
resyncInterval:
|
resyncInterval:
|
||||||
default: 60
|
default: 60
|
||||||
type: integer
|
type: integer
|
||||||
|
|||||||
@@ -72,25 +72,25 @@ func (r *InfisicalSecretReconciler) Reconcile(ctx context.Context, req ctrl.Requ
|
|||||||
}
|
}
|
||||||
|
|
||||||
// It's important we don't directly modify the CRD object, so we create a copy of it and move existing data into it.
|
// It's important we don't directly modify the CRD object, so we create a copy of it and move existing data into it.
|
||||||
managedSecretReferences := infisicalSecretCRD.Spec.ManagedSecretReferences
|
managedKubeSecretReferences := infisicalSecretCRD.Spec.ManagedKubeSecretReferences
|
||||||
|
|
||||||
if infisicalSecretCRD.Spec.ManagedSecretReference.SecretName != "" && managedSecretReferences != nil && len(managedSecretReferences) > 0 {
|
if infisicalSecretCRD.Spec.ManagedSecretReference.SecretName != "" && managedKubeSecretReferences != nil && len(managedKubeSecretReferences) > 0 {
|
||||||
errMessage := "InfisicalSecret CRD cannot have both managedSecretReference and managedSecretReferences"
|
errMessage := "InfisicalSecret CRD cannot have both managedSecretReference and managedKubeSecretReferences"
|
||||||
logger.Error(defaultErrors.New(errMessage), errMessage)
|
logger.Error(defaultErrors.New(errMessage), errMessage)
|
||||||
return ctrl.Result{}, defaultErrors.New(errMessage)
|
return ctrl.Result{}, defaultErrors.New(errMessage)
|
||||||
}
|
}
|
||||||
|
|
||||||
if infisicalSecretCRD.Spec.ManagedSecretReference.SecretName != "" {
|
if infisicalSecretCRD.Spec.ManagedSecretReference.SecretName != "" {
|
||||||
logger.Info("\n\n\nThe field `managedSecretReference` will be deprecated in the near future, please use `managedSecretReferences` instead.\n\nRefer to the documentation for more information: https://infisical.com/docs/integrations/platforms/kubernetes/infisical-secret-crd\n\n\n")
|
logger.Info("\n\n\nThe field `managedSecretReference` will be deprecated in the near future, please use `managedKubeSecretReferences` instead.\n\nRefer to the documentation for more information: https://infisical.com/docs/integrations/platforms/kubernetes/infisical-secret-crd\n\n\n")
|
||||||
|
|
||||||
if managedSecretReferences == nil {
|
if managedKubeSecretReferences == nil {
|
||||||
managedSecretReferences = []secretsv1alpha1.ManagedKubeSecretConfig{}
|
managedKubeSecretReferences = []secretsv1alpha1.ManagedKubeSecretConfig{}
|
||||||
}
|
}
|
||||||
managedSecretReferences = append(managedSecretReferences, infisicalSecretCRD.Spec.ManagedSecretReference)
|
managedKubeSecretReferences = append(managedKubeSecretReferences, infisicalSecretCRD.Spec.ManagedSecretReference)
|
||||||
}
|
}
|
||||||
|
|
||||||
if len(managedSecretReferences) == 0 {
|
if len(managedKubeSecretReferences) == 0 {
|
||||||
errMessage := "InfisicalSecret CRD must have at least one managed secret reference set in the `managedSecretReferences` field"
|
errMessage := "InfisicalSecret CRD must have at least one managed secret reference set in the `managedKubeSecretReferences` field"
|
||||||
logger.Error(defaultErrors.New(errMessage), errMessage)
|
logger.Error(defaultErrors.New(errMessage), errMessage)
|
||||||
return ctrl.Result{}, defaultErrors.New(errMessage)
|
return ctrl.Result{}, defaultErrors.New(errMessage)
|
||||||
}
|
}
|
||||||
@@ -151,7 +151,7 @@ func (r *InfisicalSecretReconciler) Reconcile(ctx context.Context, req ctrl.Requ
|
|||||||
api.API_CA_CERTIFICATE = ""
|
api.API_CA_CERTIFICATE = ""
|
||||||
}
|
}
|
||||||
|
|
||||||
err = r.ReconcileInfisicalSecret(ctx, logger, infisicalSecretCRD, managedSecretReferences)
|
err = r.ReconcileInfisicalSecret(ctx, logger, infisicalSecretCRD, managedKubeSecretReferences)
|
||||||
r.SetReadyToSyncSecretsConditions(ctx, &infisicalSecretCRD, err)
|
r.SetReadyToSyncSecretsConditions(ctx, &infisicalSecretCRD, err)
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -162,7 +162,7 @@ func (r *InfisicalSecretReconciler) Reconcile(ctx context.Context, req ctrl.Requ
|
|||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
numDeployments, err := controllerhelpers.ReconcileDeploymentsWithMultipleManagedSecrets(ctx, r.Client, logger, managedSecretReferences)
|
numDeployments, err := controllerhelpers.ReconcileDeploymentsWithMultipleManagedSecrets(ctx, r.Client, logger, managedKubeSecretReferences)
|
||||||
r.SetInfisicalAutoRedeploymentReady(ctx, logger, &infisicalSecretCRD, numDeployments, err)
|
r.SetInfisicalAutoRedeploymentReady(ctx, logger, &infisicalSecretCRD, numDeployments, err)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
logger.Error(err, fmt.Sprintf("unable to reconcile auto redeployment. Will requeue after [requeueTime=%v]", requeueTime))
|
logger.Error(err, fmt.Sprintf("unable to reconcile auto redeployment. Will requeue after [requeueTime=%v]", requeueTime))
|
||||||
|
|||||||
@@ -337,7 +337,7 @@ func (r *InfisicalSecretReconciler) updateResourceVariables(infisicalSecret v1al
|
|||||||
infisicalSecretResourceVariablesMap[string(infisicalSecret.UID)] = resourceVariables
|
infisicalSecretResourceVariablesMap[string(infisicalSecret.UID)] = resourceVariables
|
||||||
}
|
}
|
||||||
|
|
||||||
func (r *InfisicalSecretReconciler) ReconcileInfisicalSecret(ctx context.Context, logger logr.Logger, infisicalSecret v1alpha1.InfisicalSecret, managedSecretReferences []v1alpha1.ManagedKubeSecretConfig) error {
|
func (r *InfisicalSecretReconciler) ReconcileInfisicalSecret(ctx context.Context, logger logr.Logger, infisicalSecret v1alpha1.InfisicalSecret, managedKubeSecretReferences []v1alpha1.ManagedKubeSecretConfig) error {
|
||||||
|
|
||||||
resourceVariables := r.getResourceVariables(infisicalSecret)
|
resourceVariables := r.getResourceVariables(infisicalSecret)
|
||||||
infisicalClient := resourceVariables.InfisicalClient
|
infisicalClient := resourceVariables.InfisicalClient
|
||||||
@@ -361,7 +361,7 @@ func (r *InfisicalSecretReconciler) ReconcileInfisicalSecret(ctx context.Context
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, managedSecretReference := range managedSecretReferences {
|
for _, managedSecretReference := range managedKubeSecretReferences {
|
||||||
// Look for managed secret by name and namespace
|
// Look for managed secret by name and namespace
|
||||||
managedKubeSecret, err := util.GetKubeSecretByNamespacedName(ctx, r.Client, types.NamespacedName{
|
managedKubeSecret, err := util.GetKubeSecretByNamespacedName(ctx, r.Client, types.NamespacedName{
|
||||||
Name: managedSecretReference.SecretName,
|
Name: managedSecretReference.SecretName,
|
||||||
|
|||||||
Reference in New Issue
Block a user