Merge pull request #9 from Peltarion/parmus/helm-secret

feat: add support for using an existing token secret
This commit is contained in:
Arne Diekmann 2021-03-25 10:11:35 +01:00 committed by GitHub
commit 61c77c010b
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
5 changed files with 13 additions and 4 deletions

View file

@ -46,3 +46,7 @@ Create chart name and version as used by the chart label.
{{- define "dnsimple-webhook.servingCertificate" -}}
{{ printf "%s-webhook-tls" (include "dnsimple-webhook.fullname" .) }}
{{- end -}}
{{- define "dnsimple-webhook.tokenSecretName" -}}
{{- default (include "dnsimple-webhook.fullname" .) (.Values.dnsimple.tokenSecretName) -}}
{{- end -}}

View file

@ -20,7 +20,7 @@ spec:
config:
tokenSecretRef:
key: token
name: {{ include "dnsimple-webhook.fullname" . }}
name: {{ include "dnsimple-webhook.tokenSecretName" . }}
groupName: {{ .Values.groupName }}
solverName: dnsimple
{{- end -}}

View file

@ -1,7 +1,8 @@
{{- if not .Values.dnsimple.existingTokenSecret -}}
apiVersion: v1
kind: Secret
metadata:
name: {{ include "dnsimple-webhook.fullname" . }}
name: {{ include "dnsimple-webhook.tokenSecretName" . }}
labels:
app: {{ include "dnsimple-webhook.name" . }}
chart: {{ include "dnsimple-webhook.chart" . }}
@ -10,6 +11,7 @@ metadata:
type: Opaque
data:
token: {{ .Values.dnsimple.token | b64enc }}
{{- end }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
@ -23,7 +25,7 @@ metadata:
rules:
- apiGroups: [""] # indicates the core API group
resources: ["secrets"]
resourceNames: ["{{ include "dnsimple-webhook.fullname" . }}"]
resourceNames: ["{{ include "dnsimple-webhook.tokenSecretName" . }}"]
verbs: ["get", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1

View file

@ -20,7 +20,7 @@ spec:
config:
tokenSecretRef:
key: token
name: {{ include "dnsimple-webhook.fullname" . }}
name: {{ include "dnsimple-webhook.tokenSecretName" . }}
groupName: {{ .Values.groupName }}
solverName: dnsimple
{{- end -}}

View file

@ -13,6 +13,9 @@ certManager:
# logLevel: 3
dnsimple:
token: ""
# existingTokenSecret: false
# tokenSecretName:
clusterIssuer:
email: name@example.com
staging: