Setup the external secrets helm charts Convert hard coded secrets to external secrets Add BitWarden CLI for serving external secrets
71 lines
1.9 KiB
YAML
71 lines
1.9 KiB
YAML
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: bitwarden-cli
|
|
labels:
|
|
app.kubernetes.io/instance: bitwarden-cli
|
|
app.kubernetes.io/name: bitwarden-cli
|
|
spec:
|
|
replicas: 1
|
|
strategy:
|
|
type: Recreate
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: bitwarden-cli
|
|
app.kubernetes.io/instance: bitwarden-cli
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: bitwarden-cli
|
|
app.kubernetes.io/instance: bitwarden-cli
|
|
spec:
|
|
containers:
|
|
- name: bitwarden-cli
|
|
image: "registry.thehellings.com/greg/nixos-config/img-bitwarden:latest"
|
|
imagePullPolicy: Always
|
|
env:
|
|
- name: BW_CLIENTID
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: bitwarden-cli
|
|
key: BW_CLIENTID
|
|
- name: BW_CLIENTSECRET
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: bitwarden-cli
|
|
key: BW_CLIENTSECRET
|
|
- name: BW_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: bitwarden-cli
|
|
key: BW_PASSWORD
|
|
ports:
|
|
- name: http
|
|
containerPort: 8087
|
|
protocol: TCP
|
|
livenessProbe:
|
|
exec:
|
|
command:
|
|
- wget
|
|
- -q
|
|
- http://127.0.0.1:8087/sync?force=true
|
|
- --post-data=''
|
|
initialDelaySeconds: 20
|
|
failureThreshold: 3
|
|
timeoutSeconds: 10
|
|
periodSeconds: 120
|
|
readinessProbe:
|
|
tcpSocket:
|
|
port: 8087
|
|
initialDelaySeconds: 20
|
|
failureThreshold: 3
|
|
timeoutSeconds: 1
|
|
periodSeconds: 10
|
|
startupProbe:
|
|
tcpSocket:
|
|
port: 8087
|
|
initialDelaySeconds: 10
|
|
failureThreshold: 30
|
|
timeoutSeconds: 1
|
|
periodSeconds: 5
|