diff --git a/.gitignore b/.gitignore index 1d18d15..929aaa1 100644 --- a/.gitignore +++ b/.gitignore @@ -52,6 +52,9 @@ Thumbs.db *.tmp *.temp +# Kubernetes secrets (sops-encrypted original stays local) +k8s/secret.yaml + # Melange / apko build artifacts packages/ melange.rsa diff --git a/k8s/configmap.yaml b/k8s/configmap.yaml deleted file mode 100644 index c2324c3..0000000 --- a/k8s/configmap.yaml +++ /dev/null @@ -1,17 +0,0 @@ -apiVersion: v1 -kind: ConfigMap -metadata: - name: apcupsd-client-config - namespace: apcupsd - labels: - app.kubernetes.io/name: apcupsd-client - app.kubernetes.io/part-of: apcupsd-client -data: - REDIS_URL: "redis://redis:6379/0" - LOG_LEVEL: "info" - TZ: "UTC" - ALLOW_PRIVATE_IPS: "true" - TRUST_PROXY: "true" - RATE_LIMIT_ENABLED: "true" - ADMIN_USERNAME: "admin" - SESSION_MAX_AGE_SECONDS: "86400" diff --git a/k8s/deployment.yaml b/k8s/deployment.yaml index ee31917..0c664b9 100644 --- a/k8s/deployment.yaml +++ b/k8s/deployment.yaml @@ -33,8 +33,6 @@ spec: - containerPort: 8000 protocol: TCP envFrom: - - configMapRef: - name: apcupsd-client-config - secretRef: name: apcupsd-client-secret livenessProbe: diff --git a/k8s/kustomization.yaml b/k8s/kustomization.yaml index 1552ade..321d22e 100644 --- a/k8s/kustomization.yaml +++ b/k8s/kustomization.yaml @@ -3,7 +3,6 @@ kind: Kustomization resources: - namespace.yaml - - configmap.yaml - secret.yaml - redis-statefulset.yaml - redis-service.yaml diff --git a/k8s/secret.yaml b/k8s/secret.yaml deleted file mode 100644 index 8a39968..0000000 --- a/k8s/secret.yaml +++ /dev/null @@ -1,14 +0,0 @@ -apiVersion: v1 -kind: Secret -metadata: - name: apcupsd-client-secret - namespace: apcupsd - labels: - app.kubernetes.io/name: apcupsd-client - app.kubernetes.io/part-of: apcupsd-client -type: Opaque -stringData: - SESSION_SECRET: "CHANGE_ME_TO_A_RANDOM_SECRET" - # Optional — uncomment and set as needed: - # SMTP_PASSWORD: "" - # ADMIN_PASSWORD_HASH: "" diff --git a/k8s/secret.yaml.example b/k8s/secret.yaml.example new file mode 100644 index 0000000..529b988 --- /dev/null +++ b/k8s/secret.yaml.example @@ -0,0 +1,31 @@ +apiVersion: v1 +kind: Secret +metadata: + name: apcupsd-client-secret + namespace: apcupsd + labels: + app.kubernetes.io/name: apcupsd-client + app.kubernetes.io/part-of: apcupsd-client +type: Opaque +stringData: + # Auth (required in production) + # Generate with: python -c "import secrets; print(secrets.token_urlsafe(32))" + SESSION_SECRET: "" + ADMIN_USERNAME: "admin" + # Generate with: python -c "from passlib.hash import argon2; print(argon2.hash('yourpassword'))" + ADMIN_PASSWORD_HASH: "" + SESSION_MAX_AGE_SECONDS: "1209600" + TRUST_PROXY: "false" + # Redis + REDIS_URL: "redis://redis:6379/0" + # SMTP (optional) + SMTP_PASSWORD: "" + # Network + ALLOW_PRIVATE_IPS: "true" + # Observability + LOG_LEVEL: "INFO" + RATE_LIMIT_ENABLED: "true" + # Locale + TZ: "UTC" + # Legacy migration (unused unless /config is mounted) + UPS_CONFIG_PATH: "/config/ups.yaml"