forked from DevFW-CICD/stacks
Compare commits
112 commits
developmen
...
IPCEICIS-2
Author | SHA1 | Date | |
---|---|---|---|
934d182042 | |||
b0834b73cc | |||
ed0d1debf4 | |||
b89cfa49fd | |||
0771b1deb9 | |||
f71729c074 | |||
07ff00fce1 | |||
32f084fcb6 | |||
cee7ba8ff3 | |||
feae2ff010 | |||
86fb4eefa3 | |||
596a234192 | |||
7e2243d52d | |||
9c8cdbf7a4 | |||
01a9c0e0e6 | |||
58fd63da54 | |||
d1355e47c8 | |||
20a6113403 | |||
1abbd9b646 | |||
7dfefa8ac9 | |||
135844644d | |||
4d20aeeaac | |||
84d4f0af07 | |||
700c242cdd | |||
e1da09b2cc | |||
d45c89c0b8 | |||
3f6ec41ece | |||
40d1d025a6 | |||
1268e3ea24 | |||
d17861bc87 | |||
87ce37972d | |||
350e3a804c | |||
a9ae743de9 | |||
529182ee3d | |||
dd9ddc8fdb | |||
6811280b92 | |||
949cf77c4e | |||
a11947c5e7 | |||
853ce17354 | |||
8b6b29cb9f | |||
4553289695 | |||
0f229f7adb | |||
cfb473659d | |||
795d575d5e | |||
c754dc80bc | |||
1a85de6cda | |||
5db72e2dc0 | |||
ca9fd7ba39 | |||
48fb2c1481 | |||
a2d2bd9b87 | |||
49fdf90dd8 | |||
b5a515c6f9 | |||
485e772016 | |||
71a45cc0b8 | |||
5200aa748c | |||
29ec426778 | |||
7b8ea2de6b | |||
ee630c88b9 | |||
fc6ee8bcae | |||
c9d72e9f90 | |||
7cc75f0095 | |||
37a9a73664 | |||
ad76195004 | |||
d3b60c036a | |||
de3194062d | |||
cda3fc8179 | |||
2dc751b5e3 | |||
12a4ed37f7 | |||
77b571b768 | |||
6df0858cdf | |||
06fb6d223f | |||
4f8eb0bc8b | |||
1164768b9f | |||
f66f437cdf | |||
ce5bdf0226 | |||
56c5cc2620 | |||
458414e779 | |||
8eae08aaa9 | |||
ba9452e03c | |||
888d32c403 | |||
6f3effeaf5 | |||
fd02d55dda | |||
63b17c9e32 | |||
f13bf825ff | |||
abd7da5cd3 | |||
a42df6275c | |||
5a802be864 | |||
bc6ed363e2 | |||
631be775f5 | |||
0107666fe2 | |||
e5ccae1aab | |||
f6d1842876 | |||
508ecd3f12 | |||
5e47caaee1 | |||
0485a8fb76 | |||
17f578dde2 | |||
a35aefc376 | |||
398c94fbc8 | |||
30f0c6f218 | |||
06303ef355 | |||
08471dee47 | |||
881b65fcec | |||
3853370a8c | |||
6acd284b83 | |||
c79114f463 | |||
6a5be1257c | |||
1cb714aabb | |||
450b5ff1a8 | |||
aaaf905edc | |||
bd89c91d52 | |||
a9ad7c1c5c | |||
d057e9dae1 |
15 changed files with 242 additions and 186 deletions
|
@ -1,29 +0,0 @@
|
||||||
apiVersion: external-secrets.io/v1beta1
|
|
||||||
kind: ExternalSecret
|
|
||||||
metadata:
|
|
||||||
name: forgejo-access-token
|
|
||||||
namespace: argocd
|
|
||||||
spec:
|
|
||||||
secretStoreRef:
|
|
||||||
name: gitea
|
|
||||||
kind: ClusterSecretStore
|
|
||||||
refreshInterval: "0"
|
|
||||||
target:
|
|
||||||
name: forgejo-access-token
|
|
||||||
template:
|
|
||||||
engineVersion: v2
|
|
||||||
data:
|
|
||||||
forgejo_username: "{{.FORGEJO_ACCESS_USERNAME}}"
|
|
||||||
forgejo_token: "{{.FORGEJO_ACCESS_TOKEN}}"
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/part-of: argocd
|
|
||||||
data:
|
|
||||||
- secretKey: FORGEJO_ACCESS_USERNAME
|
|
||||||
remoteRef:
|
|
||||||
key: forgejo-access-token
|
|
||||||
property: username
|
|
||||||
- secretKey: FORGEJO_ACCESS_TOKEN
|
|
||||||
remoteRef:
|
|
||||||
key: forgejo-access-token
|
|
||||||
property: token
|
|
|
@ -1,54 +0,0 @@
|
||||||
---
|
|
||||||
apiVersion: batch/v1
|
|
||||||
kind: Job
|
|
||||||
metadata:
|
|
||||||
name: argocd-config
|
|
||||||
namespace: argocd
|
|
||||||
spec:
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
generateName: argocd-config-
|
|
||||||
spec:
|
|
||||||
restartPolicy: OnFailure
|
|
||||||
containers:
|
|
||||||
- name: push
|
|
||||||
image: docker.io/library/ubuntu:22.04
|
|
||||||
env:
|
|
||||||
- name: FORGEJO_USER
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: forgejo-access-token
|
|
||||||
key: forgejo_username
|
|
||||||
- name: FORGEJO_TOKEN
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: forgejo-access-token
|
|
||||||
key: forgejo_token
|
|
||||||
command: ["/bin/bash", "-c"]
|
|
||||||
args:
|
|
||||||
- |
|
|
||||||
#! /bin/bash
|
|
||||||
|
|
||||||
apt -qq update
|
|
||||||
apt -qq install git wget -y
|
|
||||||
if [[ "$(uname -m)" == "x86_64" ]]; then
|
|
||||||
wget https://github.com/mikefarah/yq/releases/download/v4.44.3/yq_linux_amd64
|
|
||||||
install yq_linux_amd64 /usr/local/bin/yq
|
|
||||||
rm yq_linux_amd64
|
|
||||||
else
|
|
||||||
wget https://github.com/mikefarah/yq/releases/download/v4.44.3/yq_linux_arm64
|
|
||||||
install yq_linux_arm64 /usr/local/bin/yq
|
|
||||||
rm yq_linux_arm64
|
|
||||||
fi
|
|
||||||
|
|
||||||
git config --global user.email "bot@bots.de"
|
|
||||||
git config --global user.name "bot"
|
|
||||||
|
|
||||||
git clone https://${FORGEJO_USER}:${FORGEJO_TOKEN}@{{{ .Env.DOMAIN_GITEA }}}/giteaAdmin/edfbuilder.git
|
|
||||||
cd edfbuilder
|
|
||||||
yq eval '.configs.cm."oidc.config" = "name: Keycloak\nissuer: https://{{{ .Env.DOMAIN }}}/keycloak/realms/cnoe\nclientID: argocd\nclientSecret: $auth-generic-oauth-secret:client_secret\nrequestedScopes: [\"openid\", \"profile\", \"email\", \"groups\"]"' -i stacks/core/argocd/values.yaml
|
|
||||||
|
|
||||||
git add stacks/core/argocd/values.yaml
|
|
||||||
git commit -m "adds Forgejo SSO config"
|
|
||||||
git push
|
|
||||||
backoffLimit: 99
|
|
|
@ -1,26 +0,0 @@
|
||||||
apiVersion: external-secrets.io/v1beta1
|
|
||||||
kind: ExternalSecret
|
|
||||||
metadata:
|
|
||||||
name: forgejo-access-token
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
secretStoreRef:
|
|
||||||
name: gitea
|
|
||||||
kind: ClusterSecretStore
|
|
||||||
refreshInterval: "0"
|
|
||||||
target:
|
|
||||||
name: forgejo-access-token
|
|
||||||
template:
|
|
||||||
engineVersion: v2
|
|
||||||
data:
|
|
||||||
forgejo_username: "{{.FORGEJO_ACCESS_USERNAME}}"
|
|
||||||
forgejo_token: "{{.FORGEJO_ACCESS_TOKEN}}"
|
|
||||||
data:
|
|
||||||
- secretKey: FORGEJO_ACCESS_USERNAME
|
|
||||||
remoteRef:
|
|
||||||
key: forgejo-access-token
|
|
||||||
property: username
|
|
||||||
- secretKey: FORGEJO_ACCESS_TOKEN
|
|
||||||
remoteRef:
|
|
||||||
key: forgejo-access-token
|
|
||||||
property: token
|
|
|
@ -1,76 +0,0 @@
|
||||||
---
|
|
||||||
apiVersion: batch/v1
|
|
||||||
kind: Job
|
|
||||||
metadata:
|
|
||||||
name: forgejo-config
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
generateName: forgejo-config-
|
|
||||||
spec:
|
|
||||||
restartPolicy: OnFailure
|
|
||||||
containers:
|
|
||||||
- name: push
|
|
||||||
image: docker.io/library/ubuntu:22.04
|
|
||||||
env:
|
|
||||||
- name: FORGEJO_USER
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: forgejo-access-token
|
|
||||||
key: forgejo_username
|
|
||||||
- name: FORGEJO_TOKEN
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: forgejo-access-token
|
|
||||||
key: forgejo_token
|
|
||||||
command: ["/bin/bash", "-c"]
|
|
||||||
args:
|
|
||||||
- |
|
|
||||||
#! /bin/bash
|
|
||||||
|
|
||||||
apt -qq update
|
|
||||||
apt -qq install git wget -y
|
|
||||||
if [[ "$(uname -m)" == "x86_64" ]]; then
|
|
||||||
wget https://github.com/mikefarah/yq/releases/download/v4.44.3/yq_linux_amd64
|
|
||||||
install yq_linux_amd64 /usr/local/bin/yq
|
|
||||||
rm yq_linux_amd64
|
|
||||||
else
|
|
||||||
wget https://github.com/mikefarah/yq/releases/download/v4.44.3/yq_linux_arm64
|
|
||||||
install yq_linux_arm64 /usr/local/bin/yq
|
|
||||||
rm yq_linux_arm64
|
|
||||||
fi
|
|
||||||
|
|
||||||
git config --global user.email "bot@bots.de"
|
|
||||||
git config --global user.name "giteaAdmin"
|
|
||||||
|
|
||||||
git clone https://${FORGEJO_USER}:${FORGEJO_TOKEN}@{{{ .Env.DOMAIN_GITEA }}}/giteaAdmin/edfbuilder.git
|
|
||||||
cd edfbuilder
|
|
||||||
yq eval ".gitea.oauth = [
|
|
||||||
{
|
|
||||||
\"name\": \"Keycloak\",
|
|
||||||
\"provider\": \"openidConnect\",
|
|
||||||
\"existingSecret\": \"auth-generic-oauth-secret\",
|
|
||||||
\"autoDiscoverUrl\": \"https://{{{ .Env.DOMAIN }}}/keycloak/realms/cnoe/.well-known/openid-configuration\"
|
|
||||||
}
|
|
||||||
] |
|
|
||||||
(.gitea.oauth[] | .name) |= (. style=\"single\")
|
|
||||||
|
|
|
||||||
(.gitea.oauth[] | .provider) |= (. style=\"single\")
|
|
||||||
|
|
|
||||||
(.gitea.oauth[] | .existingSecret) |= (. style=\"single\")
|
|
||||||
|
|
|
||||||
(.gitea.oauth[] | .autoDiscoverUrl) |= (. style=\"single\")
|
|
||||||
" -i stacks/core/forgejo/values.yaml
|
|
||||||
|
|
||||||
yq eval '.gitea.config.oauth2_client =
|
|
||||||
{
|
|
||||||
"ENABLE_AUTO_REGISTRATION" : true,
|
|
||||||
"ACCOUNT_LINKING" : "auto"
|
|
||||||
}
|
|
||||||
' -i stacks/core/forgejo/values.yaml
|
|
||||||
|
|
||||||
git add stacks/core/forgejo/values.yaml
|
|
||||||
git commit -m "adds Forgejo SSO config"
|
|
||||||
git push
|
|
||||||
backoffLimit: 99
|
|
|
@ -18,7 +18,7 @@ spec:
|
||||||
sources:
|
sources:
|
||||||
- repoURL: https://forgejo.edf-bootstrap.cx.fg1.ffm.osc.live/DevFW-CICD/forgejo-helm.git
|
- repoURL: https://forgejo.edf-bootstrap.cx.fg1.ffm.osc.live/DevFW-CICD/forgejo-helm.git
|
||||||
path: .
|
path: .
|
||||||
targetRevision: v12.0.0-depends
|
targetRevision: v11.0.5-depends
|
||||||
helm:
|
helm:
|
||||||
valueFiles:
|
valueFiles:
|
||||||
- $values/stacks/core/forgejo/values.yaml
|
- $values/stacks/core/forgejo/values.yaml
|
||||||
|
|
|
@ -1,8 +1,21 @@
|
||||||
|
controller:
|
||||||
|
volumes:
|
||||||
|
extra:
|
||||||
|
- name: host-log-storage
|
||||||
|
hostPath:
|
||||||
|
path: /var/log
|
||||||
|
type: Directory
|
||||||
alloy:
|
alloy:
|
||||||
create: false
|
create: false
|
||||||
name: alloy-config
|
name: alloy-config
|
||||||
key: config.alloy
|
key: config.alloy
|
||||||
|
|
||||||
|
mounts:
|
||||||
|
extra:
|
||||||
|
- mountPath: /openbao/logs
|
||||||
|
name: host-log-storage
|
||||||
|
readOnly: true
|
||||||
|
|
||||||
uiPathPrefix: "/alloy"
|
uiPathPrefix: "/alloy"
|
||||||
|
|
||||||
configMap:
|
configMap:
|
||||||
|
@ -72,6 +85,16 @@ alloy:
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
local.file_match "file_logs" {
|
||||||
|
path_targets = [{"__path__" = "/openbao/logs/openbao/*"}]
|
||||||
|
sync_period = "5s"
|
||||||
|
}
|
||||||
|
|
||||||
|
loki.source.file "local_files" {
|
||||||
|
targets = local.file_match.file_logs.targets
|
||||||
|
forward_to = [loki.write.local_loki.receiver]
|
||||||
|
}
|
||||||
|
|
||||||
loki.source.kubernetes "all_pod_logs" {
|
loki.source.kubernetes "all_pod_logs" {
|
||||||
targets = discovery.relabel.pod_logs.output
|
targets = discovery.relabel.pod_logs.output
|
||||||
forward_to = [loki.write.local_loki.receiver]
|
forward_to = [loki.write.local_loki.receiver]
|
||||||
|
|
29
template/stacks/ref-implementation/openbao-logging.yaml
Normal file
29
template/stacks/ref-implementation/openbao-logging.yaml
Normal file
|
@ -0,0 +1,29 @@
|
||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: openbao-logging-setup
|
||||||
|
namespace: argocd
|
||||||
|
labels:
|
||||||
|
env: dev
|
||||||
|
finalizers:
|
||||||
|
- resources-finalizer.argocd.argoproj.io
|
||||||
|
spec:
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
repoURL: https://{{{ .Env.DOMAIN_GITEA }}}/giteaAdmin/edfbuilder
|
||||||
|
targetRevision: HEAD
|
||||||
|
path: "stacks/ref-implementation/openbao-logging"
|
||||||
|
destination:
|
||||||
|
server: "https://kubernetes.default.svc"
|
||||||
|
namespace: openbao
|
||||||
|
syncPolicy:
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
automated:
|
||||||
|
selfHeal: true
|
||||||
|
retry:
|
||||||
|
limit: -1
|
||||||
|
backoff:
|
||||||
|
duration: 15s
|
||||||
|
factor: 1
|
||||||
|
maxDuration: 15s
|
|
@ -0,0 +1,39 @@
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: DaemonSet
|
||||||
|
metadata:
|
||||||
|
name: openbao-logging-dir
|
||||||
|
namespace: openbao
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: openbao-logging-dir
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: openbao-logging-dir
|
||||||
|
spec:
|
||||||
|
initContainers:
|
||||||
|
- name: creator
|
||||||
|
image: busybox
|
||||||
|
command: ["/bin/sh", "-c"]
|
||||||
|
args:
|
||||||
|
- |
|
||||||
|
set -e
|
||||||
|
mkdir -p /var/log/openbao
|
||||||
|
chown 100:100 /var/log/openbao
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 0
|
||||||
|
volumeMounts:
|
||||||
|
- name: host-log
|
||||||
|
mountPath: /var/log
|
||||||
|
containers:
|
||||||
|
- name: running-container
|
||||||
|
image: busybox
|
||||||
|
command: ["sleep", "infinity"]
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 0
|
||||||
|
volumes:
|
||||||
|
- name: host-log
|
||||||
|
hostPath:
|
||||||
|
path: /var/log
|
||||||
|
type: Directory
|
|
@ -0,0 +1,15 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: logrotate-config
|
||||||
|
data:
|
||||||
|
logrotate.conf: |
|
||||||
|
/openbao/logs/openbao/*.log {
|
||||||
|
size 50M
|
||||||
|
rotate 7
|
||||||
|
missingok
|
||||||
|
notifempty
|
||||||
|
postrotate
|
||||||
|
echo -e "POST / HTTP/1.1\r\nHost: sidecar-script-service.openbao.svc.cluster.local:3030\r\nContent-Length: 0\r\n\r\n" | nc sidecar-script-service.openbao.svc.cluster.local 3030
|
||||||
|
endscript
|
||||||
|
}
|
|
@ -0,0 +1,45 @@
|
||||||
|
apiVersion: batch/v1
|
||||||
|
kind: CronJob
|
||||||
|
metadata:
|
||||||
|
name: logrotate-cronjob
|
||||||
|
namespace: openbao
|
||||||
|
spec:
|
||||||
|
schedule: "0 * * * *"
|
||||||
|
successfulJobsHistoryLimit: 1
|
||||||
|
failedJobsHistoryLimit: 1
|
||||||
|
jobTemplate:
|
||||||
|
spec:
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: logrotate
|
||||||
|
image: skymatic/logrotate:latest
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 100
|
||||||
|
command: ["/bin/sh", "-c", "logrotate /etc/logrotate.conf && sleep 10"]
|
||||||
|
volumeMounts:
|
||||||
|
- name: host-log-storage
|
||||||
|
mountPath: /openbao/logs
|
||||||
|
- name: logrotate-config-volume
|
||||||
|
mountPath: /etc/logrotate.conf
|
||||||
|
subPath: logrotate.conf
|
||||||
|
readOnly: true
|
||||||
|
- name: passwd-volume
|
||||||
|
mountPath: /etc/passwd
|
||||||
|
subPath: passwd
|
||||||
|
- name: status
|
||||||
|
mountPath: /var/lib
|
||||||
|
restartPolicy: OnFailure
|
||||||
|
volumes:
|
||||||
|
- name: host-log-storage
|
||||||
|
hostPath:
|
||||||
|
path: /var/log
|
||||||
|
type: Directory
|
||||||
|
- name: logrotate-config-volume
|
||||||
|
configMap:
|
||||||
|
name: logrotate-config
|
||||||
|
- name: passwd-volume
|
||||||
|
configMap:
|
||||||
|
name: passwd-user-configmap
|
||||||
|
- name: status
|
||||||
|
emptyDir: {}
|
|
@ -0,0 +1,8 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: passwd-user-configmap
|
||||||
|
data:
|
||||||
|
passwd: |
|
||||||
|
root:x:0:0:root:/root:/bin/sh
|
||||||
|
openbao:x:100:1000::/home/openbao:/sbin/nologin
|
|
@ -0,0 +1,30 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: signal-sidecar-script
|
||||||
|
namespace: openbao
|
||||||
|
data:
|
||||||
|
sidecar.sh: |
|
||||||
|
#!/bin/sh
|
||||||
|
echo "Sending SIGHUP to OpenBAO..."
|
||||||
|
kill -SIGHUP $(pidof bao) || echo "OpenBAO process not found"
|
||||||
|
|
||||||
|
start.sh: |
|
||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
echo "Starting mini HTTP server on port 3030..."
|
||||||
|
|
||||||
|
while true; do
|
||||||
|
echo "Waiting for HTTP POST..."
|
||||||
|
REQUEST=$(nc -l -p 3030)
|
||||||
|
|
||||||
|
echo "$REQUEST" | grep -q "POST /" && {
|
||||||
|
echo "Received POST request, sending SIGHUP..."
|
||||||
|
/tmp/sidecar.sh
|
||||||
|
RESPONSE="HTTP/1.1 200 OK\r\nContent-Length: 26\r\n\r\nSIGHUP sent to OpenBAO"
|
||||||
|
} || {
|
||||||
|
RESPONSE="HTTP/1.1 405 Method Not Allowed\r\nContent-Length: 18\r\n\r\nMethod Not Allowed"
|
||||||
|
}
|
||||||
|
|
||||||
|
echo -e "$RESPONSE" | nc -N localhost 3031
|
||||||
|
done
|
|
@ -0,0 +1,13 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: sidecar-script-service
|
||||||
|
namespace: openbao
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/instance: openbao
|
||||||
|
component: server
|
||||||
|
ports:
|
||||||
|
- protocol: TCP
|
||||||
|
port: 3030
|
||||||
|
targetPort: 3030
|
|
@ -1,9 +1,46 @@
|
||||||
server:
|
server:
|
||||||
|
shareProcessNamespace: true
|
||||||
|
extraContainers:
|
||||||
|
- name: sidecar
|
||||||
|
image: alpine:latest
|
||||||
|
command: ["/bin/sh", "/tmp/start.sh"]
|
||||||
|
ports:
|
||||||
|
- containerPort: 3030
|
||||||
|
volumeMounts:
|
||||||
|
- name: sidecar-script
|
||||||
|
mountPath: /tmp/start.sh
|
||||||
|
subPath: start.sh
|
||||||
|
- name: sidecar-script
|
||||||
|
mountPath: /tmp/sidecar.sh
|
||||||
|
subPath: sidecar.sh
|
||||||
|
mode: 0755
|
||||||
|
- name: passwd-volume
|
||||||
|
mountPath: /etc/passwd
|
||||||
|
subPath: passwd
|
||||||
|
volumes:
|
||||||
|
- name: passwd-volume
|
||||||
|
configMap:
|
||||||
|
name: passwd-user-configmap
|
||||||
|
- name: host-log-storage
|
||||||
|
hostPath:
|
||||||
|
path: /var/log
|
||||||
|
type: Directory
|
||||||
|
- name: sidecar-script
|
||||||
|
configMap:
|
||||||
|
name: signal-sidecar-script
|
||||||
|
defaultMode: 0755
|
||||||
|
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /openbao/logs
|
||||||
|
name: host-log-storage
|
||||||
|
readOnly: false
|
||||||
|
|
||||||
postStart:
|
postStart:
|
||||||
- sh
|
- sh
|
||||||
- -c
|
- -c
|
||||||
- |
|
- |
|
||||||
sleep 10
|
sleep 10
|
||||||
|
rm -rf /openbao/data/*
|
||||||
bao operator init >> /tmp/init.txt
|
bao operator init >> /tmp/init.txt
|
||||||
cat /tmp/init.txt | grep "Key " | awk '{print $NF}' | xargs -I{} bao operator unseal {}
|
cat /tmp/init.txt | grep "Key " | awk '{print $NF}' | xargs -I{} bao operator unseal {}
|
||||||
echo $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/initial_token.txt
|
echo $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/initial_token.txt
|
||||||
|
@ -12,6 +49,8 @@ server:
|
||||||
echo $(grep "Unseal Key 3:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key3.txt
|
echo $(grep "Unseal Key 3:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key3.txt
|
||||||
echo $(grep "Unseal Key 4:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key4.txt
|
echo $(grep "Unseal Key 4:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key4.txt
|
||||||
echo $(grep "Unseal Key 5:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key5.txt
|
echo $(grep "Unseal Key 5:" /tmp/init.txt | awk '{print $NF}')| cat > /openbao/data/unseal_key5.txt
|
||||||
|
bao login $(grep "Initial Root Token:" /tmp/init.txt | awk '{print $NF}')
|
||||||
rm /tmp/init.txt
|
rm /tmp/init.txt
|
||||||
|
bao audit enable -path="file" file file_path=/openbao/logs/openbao/openbao.log
|
||||||
ui:
|
ui:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
|
Loading…
Reference in a new issue