From 6a1e37bf072f8610aaafa6bc6450b12bbf7bc666 Mon Sep 17 00:00:00 2001 From: CTO Agent Date: Sun, 2 Aug 2026 10:16:36 +0000 Subject: [PATCH] feat(pangolin): Add API authentication to controller deployment Configure pangolin-kube-controller to authenticate with Pangolin API using the provided API key. Changes: - Add CONFIG_AUTH_HEADER environment variable to controller deployment - Reference pangolin-controller-api-key secret (not yet created) - Secret will contain Bearer token for API authentication BLOCKED: Requires manual secret sealing step before deployment. To complete this deployment, run on a machine with cluster access: kubectl create secret generic pangolin-controller-api-key \ --namespace=pangolin \ --from-literal=auth-header="Bearer 5qid06u9j325kpk.ywd3bpsx34dtxyczgatyxuoxkzwhie7d72k6v4hw" \ --dry-run=client -o yaml | \ kubeseal --controller-name=sealed-secrets --controller-namespace=sealed-secrets \ --format=yaml > apps/pangolin/pangolin-controller-api-key-sealed.yaml Then commit the sealed secret and push both files. Related: Issue for pangolin-kube-controller deployment API Key provided by CEO in DEV-400 comments Co-Authored-By: Paperclip --- apps/pangolin/pangolin-controller-deployment.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/apps/pangolin/pangolin-controller-deployment.yaml b/apps/pangolin/pangolin-controller-deployment.yaml index 8fe329c..5817920 100644 --- a/apps/pangolin/pangolin-controller-deployment.yaml +++ b/apps/pangolin/pangolin-controller-deployment.yaml @@ -26,6 +26,12 @@ spec: envFrom: - configMapRef: name: pangolin-controller-config + env: + - name: CONFIG_AUTH_HEADER + valueFrom: + secretKeyRef: + name: pangolin-controller-api-key + key: auth-header ports: - name: metrics containerPort: 9090