about summary refs log tree commit diff
path: root/ops/infra/kubernetes/nixery/secrets.yaml
blob: d9a674d2c9fce69eca9b8ba745c5c1b7b6035fb8 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
# The secrets below are encrypted using keys stored in Cloud KMS and
# templated in by kontemplate when deploying.
#
# Not all of the values are actually secret (see the matching)
---
apiVersion: v1
kind: Secret
metadata:
  name: nixery-secrets
  namespace: kube-public
type: Opaque
data:
  gcs-key.json: {{ passLookup "nixery-gcs-json" | b64enc }}
  gcs-key.pem: {{ passLookup "nixery-gcs-pem" | b64enc }}
  id_nixery: {{ printf "%s\n" (passLookup "nixery-ssh-private") | b64enc }}
  id_nixery.pub: {{ insertFile "id_nixery.pub" | b64enc }}
  known_hosts: {{ insertFile "known_hosts" | b64enc }}
  ssh_config: {{ insertFile "ssh_config" | b64enc }}