Repository navigation
Move ingress credentials into ingress.sops.yaml - #47
Conversation
secret_prometheus_remote_write and secret_loki (the logs/metrics gateway login) move out of each inventory's all.sops.yaml into its own ingress.sops.yaml, which .sops.yaml also encrypts to the platform ArgoCD age key. Platform reads that file to create the network's ingress users, so new networks (of any type) need no platform change. ArgoCD still cannot open all.sops.yaml (mnemonics, MEV and tooling keys). Ansible loads every *.sops.yaml under group_vars/all, so the variables the nodes see are unchanged.
There was a problem hiding this comment.
This moves the secret_prometheus_remote_write and secret_loki blocks out of each inventory's all.sops.yaml into a new ingress.sops.yaml, and adds a first-position .sops.yaml creation rule for those files that includes the platform age recipient alongside the same nine PGP keys. The move is faithful: exactly those two key blocks leave all.sops.yaml, each new file carries the age recipient and all nine PGP fingerprints, the rule ordering is correct, and the variables remain referenced only from same-inventory group_vars, so the community.sops vars plugin still decrypts and loads them for the nodes. No functional problems found.
Reviewed 9 changed file(s) @ 05f5b0d3 — no blocking issues found.
"Worse is better." — Richard Gabriel
CI failed @
|
Moves
secret_prometheus_remote_writeandsecret_lokiout of each inventory'sall.sops.yamlinto a newingress.sops.yamlin the same folder. A new.sops.yamlrule encryptsingress.sops.yamlto the platform ArgoCD age key as well as the usual PGP keys;all.sops.yamlis still PGP-only. Platform builds each network's ingress users from that file. Ansible loads every*.sops.yamlundergroup_vars/all, so the nodes get the same variables as before.