- gitea-db-credentials is now a VaultDynamicSecret reading from database/static-creds/gitea (OpenBao static role, 24h password rotation). Replaces the previous KV-based Secret that used a hardcoded localdev password. - gitea-admin-credentials and gitea-s3-credentials remain VaultStaticSecrets synced from secret/gitea and secret/seaweedfs respectively. - gitea-values.yaml adds gitea.admin.existingSecret so the chart reads the admin username/password from the VSO-managed Secret instead of values.
20 lines
536 B
YAML
20 lines
536 B
YAML
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
namespace: devtools
|
|
|
|
resources:
|
|
- namespace.yaml
|
|
- vault-secrets.yaml
|
|
|
|
helmCharts:
|
|
# helm repo add gitea-charts https://dl.gitea.com/charts/
|
|
# Note: Gitea chart v10+ replaced Redis with Valkey-cluster by default.
|
|
# We disable bundled DB/cache (external CloudNativePG + Redis — see gitea-values.yaml).
|
|
- name: gitea
|
|
repo: https://dl.gitea.com/charts/
|
|
version: "12.5.0"
|
|
releaseName: gitea
|
|
namespace: devtools
|
|
valuesFile: gitea-values.yaml
|