Skip to content

Commit f45e230

Browse files
install tekton and external-secrets
1 parent ce2d096 commit f45e230

File tree

5 files changed

+74
-0
lines changed

5 files changed

+74
-0
lines changed
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
---
2+
apiVersion: cert-manager.io/v1
3+
kind: ClusterIssuer
4+
metadata:
5+
name: letsencrypt-dns-prod
6+
namespace: cert-manager
7+
spec:
8+
acme:
9+
10+
server: https://acme-v02.api.letsencrypt.org/directory
11+
privateKeySecretRef:
12+
name: letsencrypt-account-key-route53
13+
solvers:
14+
- selector:
15+
dnsZones:
16+
- "svc.dd.soeren.cloud"
17+
dns01:
18+
route53:
19+
region: us-east-1
20+
hostedZoneID: "Z04750743ET6H1ZBQ5JJT"
21+
accessKeyIDSecretRef:
22+
name: route53-credentials
23+
key: access-key-id
24+
secretAccessKeySecretRef:
25+
name: route53-credentials
26+
key: access-key-secret
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
apiVersion: kustomize.config.k8s.io/v1beta1
3+
kind: Kustomization
4+
resources:
5+
- ../../../../infra/cert-manager
6+
- clusterissuer.yaml
7+
- external-secret-cert-manager.yaml
8+
namespace: cert-manager
9+
patches:
10+
- target:
11+
kind: Deployment
12+
name: cert-manager
13+
patch: |-
14+
- op: add
15+
path: /spec/template/spec/containers/0/args/-
16+
value: "--dns01-recursive-nameservers-only"
17+
- op: add
18+
path: /spec/template/spec/containers/0/args/-
19+
value: "--dns01-recursive-nameservers=8.8.8.8:53,1.1.1.1:53"
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
---
2+
apiVersion: kustomize.config.k8s.io/v1beta1
3+
kind: Kustomization
4+
resources:
5+
- ../../../../infra/external-secrets
6+
- vault.yaml
7+
components:
8+
- ../../../../infra/external-secrets/components/resources
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
---
2+
apiVersion: "external-secrets.io/v1beta1"
3+
kind: "ClusterSecretStore"
4+
metadata:
5+
name: "vault"
6+
namespace: "external-secrets"
7+
spec:
8+
provider:
9+
vault:
10+
server: "https://vault.ha.soeren.cloud"
11+
path: "secret"
12+
version: "v2"
13+
auth:
14+
kubernetes:
15+
mountPath: "svc.dd.soeren.cloud"
16+
role: "external-secrets"
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
apiVersion: kustomize.config.k8s.io/v1beta1
3+
kind: Kustomization
4+
resources:
5+
- ../../../../infra/tekton-operator

0 commit comments

Comments
 (0)