Files
sbbb/base/data/openbao-keys-placeholder.yaml
Sienna Meridian Satterwhite 361661e965 fix(data): remove empty data field from OpenBao placeholder Secret
kubectl apply --server-side was managing the `data: {}` field, which
caused it to wipe the key/root-token entries written by the seed script
on subsequent applies. Removing the field entirely means server-side
apply never touches data, so seed-written keys survive re-applies.
2026-03-02 18:32:02 +00:00

11 lines
372 B
YAML

# Placeholder secret — seed script writes real key/root-token data after init.
# Exists so the auto-unseal sidecar volume mount doesn't block pod startup.
# `data` is intentionally omitted so server-side apply never manages (or wipes)
# the key fields written by the seed script.
apiVersion: v1
kind: Secret
metadata:
name: openbao-keys
namespace: data
type: Opaque