Add support for existing pg secret

This commit is contained in:
Maidul Islam
2024-10-09 23:43:37 -07:00
parent fd254fbeec
commit f186ce9649
4 changed files with 35 additions and 3 deletions
@@ -55,6 +55,13 @@ spec:
ports: ports:
- containerPort: 8080 - containerPort: 8080
env: env:
{{- if .Values.postgresql.useExistingPostgresSecret.enabled }}
- name: DB_CONNECTION_URI
valueFrom:
secretKeyRef:
name: {{ .Values.postgresql.useExistingPostgresSecret.existingConnectionStringSecret.name }}
key: {{ .Values.postgresql.useExistingPostgresSecret.existingConnectionStringSecret.key }}
{{- end }}
{{- if .Values.postgresql.enabled }} {{- if .Values.postgresql.enabled }}
- name: DB_CONNECTION_URI - name: DB_CONNECTION_URI
value: {{ include "infisical.postgresDBConnectionString" . }} value: {{ include "infisical.postgresDBConnectionString" . }}
@@ -2,6 +2,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: Role kind: Role
metadata: metadata:
name: k8s-wait-for-infisical-schema-migration name: k8s-wait-for-infisical-schema-migration
namespace: {{ .Release.Namespace }}
rules: rules:
- apiGroups: ["batch"] - apiGroups: ["batch"]
resources: ["jobs"] resources: ["jobs"]
@@ -10,11 +11,12 @@ rules:
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
metadata: metadata:
name: default name: infisical-database-schema-migration
namespace: {{ .Release.Namespace }}
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: default name: {{ .Values.infisical.databaseSchemaMigrationJob.serviceAccountName | default "default" }}
namespace: {{ .Release.Namespace }} namespace: {{ .Values.infisical.databaseSchemaMigrationJob.serviceAccountNamespace | default .Release.Namespace }}
roleRef: roleRef:
kind: Role kind: Role
name: k8s-wait-for-infisical-schema-migration name: k8s-wait-for-infisical-schema-migration
@@ -16,6 +16,7 @@ spec:
app.kubernetes.io/instance: {{ .Release.Name | quote }} app.kubernetes.io/instance: {{ .Release.Name | quote }}
helm.sh/chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" helm.sh/chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
spec: spec:
serviceAccountName: {{ .Values.infisical.databaseSchemaMigrationJob.serviceAccountName | default "default" }}
{{- if $infisicalValues.image.imagePullSecrets }} {{- if $infisicalValues.image.imagePullSecrets }}
imagePullSecrets: imagePullSecrets:
{{- toYaml $infisicalValues.image.imagePullSecrets | nindent 6 }} {{- toYaml $infisicalValues.image.imagePullSecrets | nindent 6 }}
@@ -26,6 +27,13 @@ spec:
image: "{{ $infisicalValues.image.repository }}:{{ $infisicalValues.image.tag }}" image: "{{ $infisicalValues.image.repository }}:{{ $infisicalValues.image.tag }}"
command: ["npm", "run", "migration:latest"] command: ["npm", "run", "migration:latest"]
env: env:
{{- if .Values.postgresql.useExistingPostgresSecret.enabled }}
- name: DB_CONNECTION_URI
valueFrom:
secretKeyRef:
name: {{ .Values.postgresql.useExistingPostgresSecret.existingConnectionStringSecret.name }}
key: {{ .Values.postgresql.useExistingPostgresSecret.existingConnectionStringSecret.key }}
{{- end }}
{{- if .Values.postgresql.enabled }} {{- if .Values.postgresql.enabled }}
- name: DB_CONNECTION_URI - name: DB_CONNECTION_URI
value: {{ include "infisical.postgresDBConnectionString" . }} value: {{ include "infisical.postgresDBConnectionString" . }}
@@ -5,6 +5,10 @@ infisical:
enabled: true enabled: true
name: infisical name: infisical
autoDatabaseSchemaMigration: true autoDatabaseSchemaMigration: true
databaseSchemaMigrationJob:
serviceAccountNamespace: default
serviceAccountName: default
fullnameOverride: "" fullnameOverride: ""
podAnnotations: {} podAnnotations: {}
deploymentAnnotations: {} deploymentAnnotations: {}
@@ -18,6 +22,7 @@ infisical:
affinity: {} affinity: {}
kubeSecretRef: "infisical-secrets" kubeSecretRef: "infisical-secrets"
service: service:
annotations: {} annotations: {}
type: ClusterIP type: ClusterIP
@@ -43,6 +48,7 @@ ingress:
# - some.domain.com # - some.domain.com
postgresql: postgresql:
# -- When enabled, this will start up a in cluster Postgres
enabled: true enabled: true
name: "postgresql" name: "postgresql"
fullnameOverride: "postgresql" fullnameOverride: "postgresql"
@@ -50,6 +56,15 @@ postgresql:
username: infisical username: infisical
password: root password: root
database: infisicalDB database: infisicalDB
useExistingPostgresSecret:
# -- When this is enabled, postgresql.enabled needs to be false
enabled: false
# -- The name from where to get the existing postgresql connection string
existingConnectionStringSecret:
# -- The name of the secret that contains the postgres connection string
name: ""
# -- Secret key name that contains the postgres connection string
key: ""
redis: redis:
enabled: true enabled: true