This commit converts all application secrets to SealedSecrets, preventing plaintext secrets from being stored in git. Changes: - Added .gitignore to prevent future plaintext secret commits - Created 20 SealedSecret manifests across 8 applications: * Stalwart (4 secrets): admin credentials, OAuth proxy, OIDC, S3 backup * Directus (5 secrets): admin, agent token, app secrets, DB, OIDC * Paperclip (4 secrets): main secrets, auth, OIDC, session * Forgejo (2 secrets): postgres, backup * BookStack (2 secrets): OIDC, MySQL * Passbolt (2 secrets): MariaDB, app secrets * Pocket ID (1 secret) - Removed hardcoded secrets from 6 stalwart deployment files - Replaced plaintext credentials with references to sealed secrets All sealed secrets have been applied to the cluster and services verified to be running correctly. Related: DEV-203 Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|---|---|---|
| .. | ||
| mariadb-secret-sealed.yaml | ||
| passbolt-secret-sealed.yaml | ||