Skip to content

Move ingress credentials into ingress.sops.yaml - #47

Merged
samcm merged 1 commit into
masterfrom
ingress-sops-split
Oct 8, 2026
Merged

samcm merged 1 commit into
masterfrom
ingress-sops-split

Conversation

@samcm

@samcm samcm commented Oct 8, 2026

Copy link
Copy Markdown
Member

Moves secret_prometheus_remote_write and secret_loki out of each inventory's all.sops.yaml into a new ingress.sops.yaml in the same folder. A new .sops.yaml rule encrypts ingress.sops.yaml to the platform ArgoCD age key as well as the usual PGP keys; all.sops.yaml is still PGP-only. Platform builds each network's ingress users from that file. Ansible loads every *.sops.yaml under group_vars/all, so the nodes get the same variables as before.

secret_prometheus_remote_write and secret_loki (the logs/metrics gateway
login) move out of each inventory's all.sops.yaml into its own
ingress.sops.yaml, which .sops.yaml also encrypts to the platform ArgoCD age
key. Platform reads that file to create the network's ingress users, so new
networks (of any type) need no platform change. ArgoCD still cannot open
all.sops.yaml (mnemonics, MEV and tooling keys).

Ansible loads every *.sops.yaml under group_vars/all, so the variables the
nodes see are unchanged.

@redpandabot redpandabot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This moves the secret_prometheus_remote_write and secret_loki blocks out of each inventory's all.sops.yaml into a new ingress.sops.yaml, and adds a first-position .sops.yaml creation rule for those files that includes the platform age recipient alongside the same nine PGP keys. The move is faithful: exactly those two key blocks leave all.sops.yaml, each new file carries the age recipient and all nine PGP fingerprints, the rule ordering is correct, and the variables remain referenced only from same-inventory group_vars, so the community.sops vars plugin still decrypts and loads them for the nodes. No functional problems found.


Reviewed 9 changed file(s) @ 05f5b0d3 — no blocking issues found.
"Worse is better." — Richard Gabriel

@redpandabot

redpandabot Bot commented Oct 8, 2026

Copy link
Copy Markdown

CI failed @ 05f5b0d3

One failed job: Ansible lint / ansible-lint. It is pre-existing, not caused by this PR. The composite setup action pins asdf-vm/actions/setup v3.0.2, which clones asdf's master branch; asdf master was rewritten in Go and no longer ships bin/asdf, so every asdf call in setup.sh fails with 'command not found' and the job exits 127 before linting. The PR only changes .sops.yaml and ansible/inventories/devnet-/group_vars/all/.sops.yaml, and the same job fails on the base commit 69500af (run 29282049358).

  • Ansible lint / ansible-lint — pre-existing — The composite action .github/actions/setup/action.yaml:7 pins asdf-vm/actions@05e0d2e (v3.0.2). That action defaults asdf_branch to master and runs git clone --depth 1 --branch master https://github.com/asdf-vm/asdf.git /home/runner/.asdf (log lines 157-159), then adds $HOME/.asdf/bin and $HOME/.asdf/shims to PATH. asdf's master branch was rewritten in Go in v0.16.0 and no longer contains the legacy bash bin/asdf (confirmed by cloning asdf master: no bin/ directory, only cmd/, internal/, go.mod), so the PATH entry resolves to nothing. Every asdf invocation in setup.sh then fails: './setup.sh: line 4: asdf: command not found' through 'line 17: asdf: command not found', ending in exit code 127. The lint step never ran. This PR's diff touches only .sops.yaml and ansible/inventories/devnet-*/group_vars/all/{all,ingress}.sops.yaml; it does not touch .github/actions/setup/action.yaml, setup.sh, or .tool-versions, so it cannot have caused the failure. It triggers the workflow only via the ansible/** path filter. Pre-existing evidence: gh run list --branch master shows Ansible lint failing on the base commit 69500af ('deprecate k8s', run 29282049358, headSha matches origin/master) with the same asdf-vm/actions/setup Node 20 deprecation annotation and 'Process completed with exit code 127'; earlier master Ansible lint runs also failed. Those logs are expired (gh run view --log-failed returns HTTP 410), so the annotation match is the evidence. (.github/actions/setup/action.yaml:7) — Bump the pin in .github/actions/setup/action.yaml:7 to asdf-vm/actions@b7bcd02 # v4.0.1 (tag v4), whose setup downloads the prebuilt Go asdf release into $HOME/.asdf/bin so asdf resolves and the Node 20 deprecation warning goes away. Equivalent stopgap: keep v3.0.2 but pass with: asdf_branch: v0.15.0 to clone the last legacy bash asdf.

Diagnosed Ansible lint @ 05f5b0d3
"Worse is better." — Richard Gabriel

@samcm
samcm merged commit 8b5c1c6 into master Oct 8, 2026
1 check failed
@samcm
samcm deleted the ingress-sops-split branch October 8, 2026 08:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant