Files
infrastructure/clusters/cl01tl/manifests/freshrss/ExternalSecret-freshrss-data-backup-secret-external.yaml

48 lines
1.4 KiB
YAML

apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: freshrss-data-backup-secret-external
namespace: freshrss
labels:
helm.sh/chart: volsync-target-data-1.0.0
app.kubernetes.io/instance: freshrss
app.kubernetes.io/part-of: freshrss
app.kubernetes.io/version: "1.0.0"
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: freshrss-data-backup-secret-external
spec:
secretStoreRef:
kind: ClusterSecretStore
name: openbao
target:
template:
mergePolicy: Merge
engineVersion: v2
data:
RESTIC_REPOSITORY: "s3:{{ .ENDPOINT }}/{{ .BUCKET }}/cl01tl/freshrss/freshrss-data"
data:
- secretKey: ENDPOINT
remoteRef:
key: /digital-ocean/config
property: ENDPOINT
- secretKey: BUCKET
remoteRef:
key: /digital-ocean/home-infra/volsync-backups
property: BUCKET
- secretKey: RESTIC_PASSWORD
remoteRef:
key: /digital-ocean/home-infra/volsync-backups
property: RESTIC_PASSWORD
- secretKey: AWS_DEFAULT_REGION
remoteRef:
key: /digital-ocean/home-infra/volsync-backups
property: AWS_REGION
- secretKey: AWS_ACCESS_KEY_ID
remoteRef:
key: /digital-ocean/home-infra/volsync-backups
property: AWS_ACCESS_KEY_ID
- secretKey: AWS_SECRET_ACCESS_KEY
remoteRef:
key: /digital-ocean/home-infra/volsync-backups
property: AWS_SECRET_ACCESS_KEY