mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 20:27:12 +00:00
Add support for existing pg secret
This commit is contained in:
@@ -55,6 +55,13 @@ spec:
|
|||||||
ports:
|
ports:
|
||||||
- containerPort: 8080
|
- containerPort: 8080
|
||||||
env:
|
env:
|
||||||
|
{{- if .Values.postgresql.useExistingPostgresSecret.enabled }}
|
||||||
|
- name: DB_CONNECTION_URI
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.postgresql.useExistingPostgresSecret.existingConnectionStringSecret.name }}
|
||||||
|
key: {{ .Values.postgresql.useExistingPostgresSecret.existingConnectionStringSecret.key }}
|
||||||
|
{{- end }}
|
||||||
{{- if .Values.postgresql.enabled }}
|
{{- if .Values.postgresql.enabled }}
|
||||||
- name: DB_CONNECTION_URI
|
- name: DB_CONNECTION_URI
|
||||||
value: {{ include "infisical.postgresDBConnectionString" . }}
|
value: {{ include "infisical.postgresDBConnectionString" . }}
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ apiVersion: rbac.authorization.k8s.io/v1
|
|||||||
kind: Role
|
kind: Role
|
||||||
metadata:
|
metadata:
|
||||||
name: k8s-wait-for-infisical-schema-migration
|
name: k8s-wait-for-infisical-schema-migration
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
rules:
|
rules:
|
||||||
- apiGroups: ["batch"]
|
- apiGroups: ["batch"]
|
||||||
resources: ["jobs"]
|
resources: ["jobs"]
|
||||||
@@ -10,11 +11,12 @@ rules:
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
name: default
|
name: infisical-database-schema-migration
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: default
|
name: {{ .Values.infisical.databaseSchemaMigrationJob.serviceAccountName | default "default" }}
|
||||||
namespace: {{ .Release.Namespace }}
|
namespace: {{ .Values.infisical.databaseSchemaMigrationJob.serviceAccountNamespace | default .Release.Namespace }}
|
||||||
roleRef:
|
roleRef:
|
||||||
kind: Role
|
kind: Role
|
||||||
name: k8s-wait-for-infisical-schema-migration
|
name: k8s-wait-for-infisical-schema-migration
|
||||||
|
|||||||
@@ -16,6 +16,7 @@ spec:
|
|||||||
app.kubernetes.io/instance: {{ .Release.Name | quote }}
|
app.kubernetes.io/instance: {{ .Release.Name | quote }}
|
||||||
helm.sh/chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
helm.sh/chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||||
spec:
|
spec:
|
||||||
|
serviceAccountName: {{ .Values.infisical.databaseSchemaMigrationJob.serviceAccountName | default "default" }}
|
||||||
{{- if $infisicalValues.image.imagePullSecrets }}
|
{{- if $infisicalValues.image.imagePullSecrets }}
|
||||||
imagePullSecrets:
|
imagePullSecrets:
|
||||||
{{- toYaml $infisicalValues.image.imagePullSecrets | nindent 6 }}
|
{{- toYaml $infisicalValues.image.imagePullSecrets | nindent 6 }}
|
||||||
@@ -26,6 +27,13 @@ spec:
|
|||||||
image: "{{ $infisicalValues.image.repository }}:{{ $infisicalValues.image.tag }}"
|
image: "{{ $infisicalValues.image.repository }}:{{ $infisicalValues.image.tag }}"
|
||||||
command: ["npm", "run", "migration:latest"]
|
command: ["npm", "run", "migration:latest"]
|
||||||
env:
|
env:
|
||||||
|
{{- if .Values.postgresql.useExistingPostgresSecret.enabled }}
|
||||||
|
- name: DB_CONNECTION_URI
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.postgresql.useExistingPostgresSecret.existingConnectionStringSecret.name }}
|
||||||
|
key: {{ .Values.postgresql.useExistingPostgresSecret.existingConnectionStringSecret.key }}
|
||||||
|
{{- end }}
|
||||||
{{- if .Values.postgresql.enabled }}
|
{{- if .Values.postgresql.enabled }}
|
||||||
- name: DB_CONNECTION_URI
|
- name: DB_CONNECTION_URI
|
||||||
value: {{ include "infisical.postgresDBConnectionString" . }}
|
value: {{ include "infisical.postgresDBConnectionString" . }}
|
||||||
|
|||||||
@@ -5,6 +5,10 @@ infisical:
|
|||||||
enabled: true
|
enabled: true
|
||||||
name: infisical
|
name: infisical
|
||||||
autoDatabaseSchemaMigration: true
|
autoDatabaseSchemaMigration: true
|
||||||
|
databaseSchemaMigrationJob:
|
||||||
|
serviceAccountNamespace: default
|
||||||
|
serviceAccountName: default
|
||||||
|
|
||||||
fullnameOverride: ""
|
fullnameOverride: ""
|
||||||
podAnnotations: {}
|
podAnnotations: {}
|
||||||
deploymentAnnotations: {}
|
deploymentAnnotations: {}
|
||||||
@@ -18,6 +22,7 @@ infisical:
|
|||||||
|
|
||||||
affinity: {}
|
affinity: {}
|
||||||
kubeSecretRef: "infisical-secrets"
|
kubeSecretRef: "infisical-secrets"
|
||||||
|
|
||||||
service:
|
service:
|
||||||
annotations: {}
|
annotations: {}
|
||||||
type: ClusterIP
|
type: ClusterIP
|
||||||
@@ -43,6 +48,7 @@ ingress:
|
|||||||
# - some.domain.com
|
# - some.domain.com
|
||||||
|
|
||||||
postgresql:
|
postgresql:
|
||||||
|
# -- When enabled, this will start up a in cluster Postgres
|
||||||
enabled: true
|
enabled: true
|
||||||
name: "postgresql"
|
name: "postgresql"
|
||||||
fullnameOverride: "postgresql"
|
fullnameOverride: "postgresql"
|
||||||
@@ -50,6 +56,15 @@ postgresql:
|
|||||||
username: infisical
|
username: infisical
|
||||||
password: root
|
password: root
|
||||||
database: infisicalDB
|
database: infisicalDB
|
||||||
|
useExistingPostgresSecret:
|
||||||
|
# -- When this is enabled, postgresql.enabled needs to be false
|
||||||
|
enabled: false
|
||||||
|
# -- The name from where to get the existing postgresql connection string
|
||||||
|
existingConnectionStringSecret:
|
||||||
|
# -- The name of the secret that contains the postgres connection string
|
||||||
|
name: ""
|
||||||
|
# -- Secret key name that contains the postgres connection string
|
||||||
|
key: ""
|
||||||
|
|
||||||
redis:
|
redis:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
|||||||
Reference in New Issue
Block a user