From 6e3bf3b5f47b42fb0776dbcc05fda46d1b4b9077 Mon Sep 17 00:00:00 2001 From: Jacques ROUSSEL Date: Fri, 12 Jul 2024 10:48:33 +0200 Subject: [PATCH] =?UTF-8?q?=F0=9F=94=A7(helm)=20upgrade=20sops=20secrets?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add manuu key --- .sops.yaml | 10 ++++ src/helm/env.d/dev/secrets.enc.yaml | 82 ++++++++++++++++++----------- 2 files changed, 60 insertions(+), 32 deletions(-) create mode 100644 .sops.yaml diff --git a/.sops.yaml b/.sops.yaml new file mode 100644 index 00000000..82e93755 --- /dev/null +++ b/.sops.yaml @@ -0,0 +1,10 @@ +creation_rules: + - key_groups: + - age: + - age15fyxdwmg5mvldtqqus87xspuws2u0cpvwheehrtvkexj4tnsqqysw6re2x #jacques + - age16hnlml8yv4ynwy0seer57g8qww075crd0g7nsundz3pj4wk7m3vqftszg7 #github-repo + - age1plkp8td6zzfcavjusmsfrlk54t9vn8jjxm8zaz7cmnr7kzl2nfnsd54hwg #anthony + - age12g6f5fse25tgrwweleh4jls3qs52hey2edh759smulwmk5lnzadslu2cp3 #antoine + - age1tl80n23wq6zxegupwn70ew0yp225ua5v4dk800x7g2w6pvlxz46qk592pa #marie + - age1qy04neuzwpasmvljqrcvhwnf0kz5cpyteze38c8avp0czewskasszv9pyw #argocd + - age18fgn6j2vwwswqcpv9xpcehq8mrf9zs2sglwkamp3tzwx8d9jq9jsrskrk9 #manuuu diff --git a/src/helm/env.d/dev/secrets.enc.yaml b/src/helm/env.d/dev/secrets.enc.yaml index e64957bf..9ba28a7b 100644 --- a/src/helm/env.d/dev/secrets.enc.yaml +++ b/src/helm/env.d/dev/secrets.enc.yaml @@ -1,10 +1,10 @@ -djangoSecretKey: ENC[AES256_GCM,data:2b4nHO2i/HtaNJYi1d8xJyhCpK1qV7fHD45T6VarWpNg1HkcJgC7zTgHMEvfedRd2tE=,iv:qcHlXG/mNr3CFtZhjbw3AVRbMxkGZaAZPtHtS8ksO58=,tag:mTC6mc5JKqpEQ/9ubggKmA==,type:str] +djangoSecretKey: ENC[AES256_GCM,data:TulkgSxtL5YSXuEbmM0vOrSezj+Qod7TAReBs3zoZak782Dr56stTweiSjz5ngtRNh8=,iv:VciiRV5UPvGiNk9yHaw1uT0GEzglQ/Xn2UUxjiycZas=,tag:2LvoFqy6jpSBV679yagA5Q==,type:str] oidc: - clientId: ENC[AES256_GCM,data:JNeyMxdwJbY48aJ3NmZVB8h0xlwVknFqnJU5bpO6PozfAfCC,iv:wZPT9JJRwIkksjPQrzEcDHyWXusqB9ax6Og64hh1mYo=,tag:WALVMIAlqwzDNpgHesWJLQ==,type:str] - clientSecret: ENC[AES256_GCM,data:KMOAVI8+loZ8hO29Ob+DcTHuXZoytrt6VHNo3MEDx6kgaxXazwZLqDmvynNdsNyyfLg8ZZAqxxvhiOVzOwVZ9w==,iv:1DzGfdVR7b+Ou+x15fk3v0aY9xZJslp2+U3H/H363Wo=,tag:/U7PEqr5b++W9sBuqocutA==,type:str] + clientId: ENC[AES256_GCM,data:7cQzLyVTOqy0OZoL5LEHkBspgqLGzrz02YWma64yzhB+PEj1,iv:vQ49PuVGmms2Y2LIa6uUon0rGO+v0368NuHmpFmqwiE=,tag:39baRMIrS+bvUVpSikgdHg==,type:str] + clientSecret: ENC[AES256_GCM,data:e+FMROduwljv1hJp88WtyOFsYcS6r30D8NB5Eg9lrxVLPZlhXE8KOYDFUhqUCEWb5ZvIk5m90V3lngN1nJJHGA==,iv:kY0rWPFoOFHRpOXQIsaipqjBAnaITfNdPVkU9OtJghk=,tag:cP4cDSOl+W8qMMhXpV+vgA==,type:str] livekit: keys: - devkey: ENC[AES256_GCM,data:4KJotPCU,iv:QHzp9taZFwsYhno11WCjbJKAPB2huV0KkoCrnDSxQRc=,tag:gokHjR9GV56iRbmV0zbWjQ==,type:str] + devkey: ENC[AES256_GCM,data:qlvVa2A1,iv:MNxLlo6Hl3/O/p2JqBLjoe3fmSfhvyAZdv34yKHAHRs=,tag:4rO+fpeweGcyhg93kCN0BA==,type:str] sops: kms: [] gcp_kms: [] @@ -14,50 +14,68 @@ sops: - recipient: age15fyxdwmg5mvldtqqus87xspuws2u0cpvwheehrtvkexj4tnsqqysw6re2x enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBiem9OZTZYQnV5UVpzaHN0 - MlpGL2xaMTVldkVPY2Jub3IxU2FhcVBNYWxvCk1qbHJFa2ZVdmp4Yy9COGFPNzlL - amh5S21qbm1jTlgxZjBZMk5BTllNZlUKLS0tIGM5aTJrbnRSdXZPWVF3RVR2dlRD - NThRV1hpb0k5RElvRlYySTZyMXp3dGsK92FrBnrHAIRcGooyJviJSUA+eHiwvVkm - b1T9jk9bmoipV/8WkXbGyk0TZKYuB4pvPE88eNLrYeotTiRu9tJUNw== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA5LzE5S3h6c3g3WXlpYVRS + V3lwZWl4YVVudncwMWxwL09KQ1IrWUFmZFVnCmRMcXM1ZUtISVBtcU1xU0pVVDVx + NlBYbDVRbUlNQzU4VS9vZEE1U3p5V1EKLS0tIGhDVldDa1crS2hkY2JkQTMxRDVC + SDZXcThPRGJKaXV5aWlheG1NdTY4d1kK5kqtaAlzs8rTYTggpWC0OOk/TOKxxQId + ec3ZLFN8g/JZiakPola/+u4hsIxkV+y0fUs2CwlDFJnEBwdkNPpBQw== -----END AGE ENCRYPTED FILE----- - recipient: age16hnlml8yv4ynwy0seer57g8qww075crd0g7nsundz3pj4wk7m3vqftszg7 enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBxQUhLb2Z4N3ptTjBHZ3N3 - cVBNMDJFS09wck9LcytJR1h4WCtlblZpYkJnCmdBN1laOGdiN1lKbUFBOTdLTUM1 - NHFLZm51M0dLakIxcG1ncnFrb3dCeXMKLS0tIDdWUmlkYy9PSWhoYkRPNXc4aDNa - TWxUMUlqUHhNL3NZL0R2WE9ySU5wcTAKMzwEzXiGSGr4BJNZ78mo68V1Jq4ydOWl - dlSkEe+zv2jYYmLxirBDbLN+dwUwyAA8/eYYidvuMvHw1sfT14GyRw== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBMcU02c2RTcWxIb2gxVVBl + N004cXRIT0FOa0JKeTNaSytsa1BBdTdvaTFZCkFzN0tNcEcvZUpjaHdvR0NBUDNp + M1pRckcyK2IxSnZid2o3bG5hNXl3YjgKLS0tIDNJSHp2YmovZzgwUEU5ZWRkQUtu + ZEFxQ0EzVEJCenVxeVFOMWlrMEd6eTQK8RRV0lbOkJaRrHK1yTTQv8Kly2Bccatu + I3ED05o1CaWP+qPYSDmaChzewAW1J2C0AU9k8dpEd94jRIve3nhQMw== -----END AGE ENCRYPTED FILE----- - recipient: age1plkp8td6zzfcavjusmsfrlk54t9vn8jjxm8zaz7cmnr7kzl2nfnsd54hwg enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBiZFRjVmtiVXpONk4xZktB - TXo5OE1Jam1qREdPTjJSanUvd3R3dWI5SDA0CjZqZDNxZklNZXhvOExSaGlzOW85 - OFYxMzhYMTFDUStpYTdLdEFEdUU3ZW8KLS0tIDVkYmVQMTcvbFhFa0xPb2h6TlFW - TmJUY2hncjg4TkhxOWRxazh5cXQyWHcKgDbgGfl1WQiT6tIG/pmikYUYIF0l4kj7 - ZxlgL+Vn9y3fl5B2LGn/fXfi9B/exgLMCR/GRm3vF4OpPqLYbL0rzw== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBTcWl1alFtSkIyM1BvSnAw + YlAxM2RjOXdzUVRDOTUrUVZIWWFQSmd4dWdBCjQ4SUQ1eXdpSmdzMlM3UnlTTy9D + clBOcFFWOWtaZU9OU1JoRXNCbXJ5SVUKLS0tIG1NbUZKajQ5dno3Z2d6NzJtbUNQ + WXRDM1dEeXB5SU52UmVVaFUxTUVLbkkKS3oAFk1CYB03vbXm9Xb4P24/Xui0LM+h + ++ykAOWuHjZ0mHbvPXOeS6VFXchdVWtQiHYW6eo3ya524Pq3C3l34Q== -----END AGE ENCRYPTED FILE----- - recipient: age12g6f5fse25tgrwweleh4jls3qs52hey2edh759smulwmk5lnzadslu2cp3 enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBWanllM2FDOStFNWVhR1A3 - MVJMRDFCTHY3ZlF3MHg3MGxOWGRtSko0MVd3CmFheUllSkN4VTF5WmZubU1BeWtp - em1tL3dwWGszYmVYSUlwVVZDR3BIK0UKLS0tIDQrWEtuZGVSM3JwM0xYc2N2alpG - eEtzN3Y3UVZkQVlBd0dUWmdVdStSUmcKNQZ0uj0Sj3e7Q9PKsZi4CcS5LEWlD9tL - nOaoMiN1AA307uvePKgFAuChQ5VsAGMcegLJ5M8w516/+yO42yexUw== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBWaGtjcUdZWHFSNGttM1Z3 + VFd3SWQ2OFZBRlc3NEJTMWZUa3BPOW9uMGo0CnZyOHRWazdEVzg0VUdEMVdFVXRy + TDFRWW9QYkVzeVoyRVVJNVNIVVRaUHMKLS0tIEFZU1l6THp5bElSMnlCUVN1VitJ + RnhnaElLMjNhUUpkQURQZm82ZTJxOVEKXCvgYbPMsYWT13TpFTZevGX3ZBKb2/Yd + CaBO0I4Ij2ykyK2X3qqJRAPI1cTKROTVv5GCvilxEZWcq0lLwhfNWQ== + -----END AGE ENCRYPTED FILE----- + - recipient: age1tl80n23wq6zxegupwn70ew0yp225ua5v4dk800x7g2w6pvlxz46qk592pa + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAzbkUrMitDdlJzVUVucFIz + Q2drWDAxcVFhWE5SSDdhVW9wM09oZjI1K1JVClE1MkpYejZxM0dxSTBFWkt0WjR1 + Smo5TkEvNzByaDZ0dmMvS25kMUV4QmMKLS0tIEtkaTMyNmw5LzNESVhKTHZKL0E5 + WnBhdWRZd1N2a1VBdVpuR2JCYUhINk0KaREjyKJ2ieF72TSuFX5as8odtKQacspa + S/Bsu2YI2YnCKyuL2BOHVT0ETZXyv29a70yxLAWFgnZNEj/MYXzLFw== -----END AGE ENCRYPTED FILE----- - recipient: age1qy04neuzwpasmvljqrcvhwnf0kz5cpyteze38c8avp0czewskasszv9pyw enc: | -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAxa0F4VW5oRGFYSVpPOTVW - QjEvL2czQkRwK0tWOStxYkJRaUlHUjlSWWswClE4TW9tLy9oQXZQSVc3R3cwTGU1 - ZGh4UTUzR0FKY0NmMFFaaTFKakVNNlkKLS0tIFRvZ0V5emV6cjBqNlZxOEpwVy8y - N0ZkVmNzTzhhRTA5TDMxc2tGN3BFemMKlyPtb7gfYREoPaU3ZlpynCuqxo4KW0b9 - G+3aGz7SKZ7pcuAaWuuMdyA6XzwS/HOe2L2cW3P5x/0k0JQd2Ie8jA== + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA4U0kzTmw0N3hMK0lxVFZX + MzRuT2k4WGpxZzZyWmV1dUxvMmhqdHhNekJJCnQ3YXpSVUhoYllKc0FBdStIZ2hK + N0o5UWNTMXk3OHlCVldSREJkNTJSR1EKLS0tIEx3NzBjMi9Pa3NsN24yekltaW1h + RnVweWw1L0RmTDVURGZoTEg5czkyem8KA/VyWUoqAO4+2MJeIAwtKo5GVOyUK7Mq + IDUlHULo5kKZ/DglNwcoErV7MzWFunjXCIseXBPieMrZQ1vC5OJrvA== -----END AGE ENCRYPTED FILE----- - lastmodified: "2024-07-02T16:08:28Z" - mac: ENC[AES256_GCM,data:0D1xTZwOpYKfcY94lGQnBgsLOtjxvJwwpja0+IV6zqIb3gO1762AL3btZim0OFRkhYo0SLe1Q6ABQ1tn2txK7GdPkjBaS6eJ3EQ7nuPQ75gelyoQqOOQ92/DxjBhaLkVpupmlB+62w2iMSGIjCU95E3dEc9ivyL/Rd7E0K8Irk4=,iv:c3Sh6iXepP/ptB46CjPZnZJQlNe31EFkRUNCck5sR28=,tag:/LWg/DxgPHME3B++FWGoVQ==,type:str] + - recipient: age18fgn6j2vwwswqcpv9xpcehq8mrf9zs2sglwkamp3tzwx8d9jq9jsrskrk9 + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBJQ1Z2UlozTzJsQlBlbnhS + UzJiZFZwK2lXUTVnQVBEQUIxOVU0QzVDUjE4CllhMWc0Nzh1Z3FOTU1ESkE1bW5B + TFFPUjJRUGxiMnBtUktoYk1LamQ0bmMKLS0tIGdPbWFBdDNUUmpIdnN4dCtmamc2 + MDJiYzhvNlUvQTlsbUdYdmJkYjNaN3MKdccBEm9dj2Cs3km527bx3w2d3b/rJOi2 + QzgHJKaRS3rdCRkXj/cxW0rVgI8twvVj/WV1Into1qKRcAKI6f5zfw== + -----END AGE ENCRYPTED FILE----- + lastmodified: "2024-07-12T08:47:29Z" + mac: ENC[AES256_GCM,data:slPiXUVmoLGwg3VbsFNAENY84+bSCDQset6cEtbf7LJjJx30/Jqrdg0VXOv/aFmIJsb5mLaPUlylLt36MTw8IYxRPKYY5Gj3yXWRz2SaSX7QKZAba0k5z9MvGy0FjCDlSVe0Xm+SXUoA37t6NFKHgz54Bh2+CLX1H8i7EbZA1ak=,iv:pyjiNZBvq/4u5kiXAzlqu1C4qbupjCZez5Z9vRXLnIg=,tag:EXzeWMfPJGNy4uKXmCdAzA==,type:str] pgp: [] unencrypted_suffix: _unencrypted - version: 3.8.1 \ No newline at end of file + version: 3.8.1