Skip to content

Commit dcfb3da

Browse files
author
willemvd
committed
use openshift/kubernetes secrets for storing keys (don't forget to base64 encode the values!)
1 parent 21286b7 commit dcfb3da

File tree

1 file changed

+39
-6
lines changed

1 file changed

+39
-6
lines changed

openshift-postgresql-s3-backup-scheduledJob.yaml

Lines changed: 39 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,21 @@
11
apiVersion: v1
22
kind: List
33
items:
4+
- apiVersion: "v1"
5+
kind: "Secret"
6+
metadata:
7+
name: "aws-s3-secret"
8+
data:
9+
# don't forget to base64 encode your values
10+
aws-access-key-id: ""
11+
aws-secret-access-key: ""
12+
- apiVersion: "v1"
13+
kind: "Secret"
14+
metadata:
15+
name: "openssl-encryption-secret"
16+
data:
17+
# don't forget to base64 encode your values
18+
encryption-pass-phrase: ""
419
- apiVersion: batch/v2alpha1
520
kind: ScheduledJob
621
metadata:
@@ -29,13 +44,22 @@ items:
2944
- name: PGPASSWORD
3045
value:
3146
- name: ENCRYPTION_PASS_PHRASE
32-
value:
47+
valueFrom:
48+
secretKeyRef:
49+
name: openssl-encryption-secret
50+
key: encryption-pass-phrase
3351
- name: OPENSSL_CIPHER_TYPE
3452
value: aes-256-cbc
3553
- name: AWS_ACCESS_KEY_ID
36-
value:
54+
valueFrom:
55+
secretKeyRef:
56+
name: aws-s3-secret
57+
key: aws-access-key-id
3758
- name: AWS_SECRET_ACCESS_KEY
38-
value:
59+
valueFrom:
60+
secretKeyRef:
61+
name: aws-s3-secret
62+
key: aws-secret-access-key
3963
- name: AWS_DEFAULT_REGION
4064
value:
4165
- name: S3_BUCKET_NAME
@@ -71,13 +95,22 @@ items:
7195
- name: PGPASSWORD
7296
value:
7397
- name: ENCRYPTION_PASS_PHRASE
74-
value:
98+
valueFrom:
99+
secretKeyRef:
100+
name: openssl-encryption-secret
101+
key: encryption-pass-phrase
75102
- name: OPENSSL_CIPHER_TYPE
76103
value: aes-256-cbc
77104
- name: AWS_ACCESS_KEY_ID
78-
value:
105+
valueFrom:
106+
secretKeyRef:
107+
name: aws-s3-secret
108+
key: aws-access-key-id
79109
- name: AWS_SECRET_ACCESS_KEY
80-
value:
110+
valueFrom:
111+
secretKeyRef:
112+
name: aws-s3-secret
113+
key: aws-secret-access-key
81114
- name: AWS_DEFAULT_REGION
82115
value:
83116
- name: S3_BUCKET_NAME

0 commit comments

Comments
 (0)