chore: Update manifests after change

This commit is contained in:
2026-05-08 22:15:15 +00:00
parent 91a78a9a7c
commit b3621fb4ea
4 changed files with 1 additions and 67 deletions

View File

@@ -15,5 +15,5 @@ spec:
objects: | objects: |
- objectName: .s3cfg - objectName: .s3cfg
fileName: .s3cfg fileName: .s3cfg
secretPath: secret/data/digital-ocean/home-infra/talos-backups secretPath: secret/data/backblaze/home-infra/talos-backups
secretKey: s3cfg secretKey: s3cfg

View File

@@ -57,35 +57,6 @@ spec:
name: snapshot-script name: snapshot-script
subPath: snapshot.sh subPath: snapshot.sh
containers: containers:
- args:
- -ec
- /scripts/backup.sh
command:
- /bin/sh
env:
- name: BUCKET
valueFrom:
secretKeyRef:
key: BUCKET
name: vault-backup-external-config
- name: TARGET
value: External
envFrom:
- secretRef:
name: vault-ntfy-config
image: d3fk/s3cmd:latest@sha256:d66cc5677b30b31a7981f9fde0af064a9072e8b8a57d5e9b4cc02f44f02acbf2
name: s3-backup-external
volumeMounts:
- mountPath: /opt/backup
name: backup
- mountPath: /root/.s3cfg
mountPropagation: None
name: backup-external-config
readOnly: true
subPath: .s3cfg
- mountPath: /scripts/backup.sh
name: backup-script
subPath: backup.sh
- args: - args:
- -ec - -ec
- /scripts/backup.sh - /scripts/backup.sh

View File

@@ -1,18 +0,0 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: vault-backup-external-config
namespace: vault
labels:
app.kubernetes.io/name: vault-backup-external-config
app.kubernetes.io/instance: vault
app.kubernetes.io/part-of: vault
spec:
secretStoreRef:
kind: ClusterSecretStore
name: openbao
data:
- secretKey: BUCKET
remoteRef:
key: /digital-ocean/home-infra/vault-backups
property: BUCKET_PATH

View File

@@ -1,19 +0,0 @@
apiVersion: secrets-store.csi.x-k8s.io/v1
kind: SecretProviderClass
metadata:
name: vault-backup-external-config
namespace: vault
labels:
app.kubernetes.io/name: vault-backup-external-config
app.kubernetes.io/instance: vault
app.kubernetes.io/part-of: vault
spec:
provider: openbao
parameters:
baoAddress: "http://openbao-internal.openbao:8200"
roleName: vault
objects: |
- objectName: .s3cfg
fileName: .s3cfg
secretPath: secret/data/digital-ocean/home-infra/vault-backups
secretKey: s3cfg