blumeops/argocd/manifests/forgejo-runner/external-secret.yaml

27 lines
670 B
YAML
Raw Normal View History

# ExternalSecret for Forgejo Runner credentials
#
# 1Password item: "Forgejo Secrets" in blumeops vault
# Fields: runner_k8s_uuid, runner_k8s_token
#
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: forgejo-runner-env
namespace: forgejo-runner
spec:
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
name: onepassword-blumeops
target:
name: forgejo-runner-env
creationPolicy: Owner
data:
- secretKey: FORGEJO_RUNNER_UUID
remoteRef:
key: Forgejo Secrets
property: runner_k8s_uuid
- secretKey: FORGEJO_RUNNER_TOKEN
remoteRef:
key: Forgejo Secrets
property: runner_k8s_token