fix: add ACTUAL_E2E_PASSWORD_1 to actual-budget-exporter

Budget is E2E-encrypted; exporter fails with 'File ... is encrypted' without
this. Sourced from the same hand-created Secret as the other credentials.
This commit is contained in:
2026-09-03 15:44:19 +07:00
parent e9fa39f3f4
commit 26526ecc50
3 changed files with 20 additions and 9 deletions
+9 -5
View File
@@ -86,16 +86,20 @@ Visit `http://ignis.fireflylab.local` once the pod is Ready.
- No HTTPRoute — this only serves `/metrics`. A `ServiceMonitor` (labeled - No HTTPRoute — this only serves `/metrics`. A `ServiceMonitor` (labeled
`release: kube-prometheus-stack` to match that stack's default selector) `release: kube-prometheus-stack` to match that stack's default selector)
gets it scraped by the cluster Prometheus instead. gets it scraped by the cluster Prometheus instead.
- `ACTUAL_PASSWORD` / `ACTUAL_BUDGET_ID_1` are **not** in `values.yaml` - `ACTUAL_PASSWORD` / `ACTUAL_BUDGET_ID_1` / `ACTUAL_E2E_PASSWORD_1` are
plaintext Actual credentials don't belong in a git-committed file. They **not** in `values.yaml` plaintext Actual credentials don't belong in a
come from a Secret you create by hand once, after the Application syncs git-committed file. They come from a Secret you create by hand once, after
and the `actualbudget` namespace exists: the Application syncs and the `actualbudget` namespace exists.
`ACTUAL_E2E_PASSWORD_1` is required if the budget has E2E encryption
enabled — the exporter fails with `File ... is encrypted. Please provide a
password.` otherwise; pass an empty string if the budget isn't encrypted:
```bash ```bash
kubectl create secret generic actual-budget-exporter-secrets \ kubectl create secret generic actual-budget-exporter-secrets \
-n actualbudget \ -n actualbudget \
--from-literal=ACTUAL_PASSWORD='<your actual budget password>' \ --from-literal=ACTUAL_PASSWORD='<your actual budget password>' \
--from-literal=ACTUAL_BUDGET_ID_1='<sync ID from Settings → Show advanced settings>' --from-literal=ACTUAL_BUDGET_ID_1='<sync ID from Settings → Show advanced settings>' \
--from-literal=ACTUAL_E2E_PASSWORD_1='<E2E encryption password, empty string if none>'
``` ```
Restart the deployment after creating/rotating it: Restart the deployment after creating/rotating it:
@@ -34,6 +34,11 @@ spec:
secretKeyRef: secretKeyRef:
name: {{ .Values.secret.name }} name: {{ .Values.secret.name }}
key: ACTUAL_BUDGET_ID_1 key: ACTUAL_BUDGET_ID_1
- name: ACTUAL_E2E_PASSWORD_1
valueFrom:
secretKeyRef:
name: {{ .Values.secret.name }}
key: ACTUAL_E2E_PASSWORD_1
resources: resources:
{{- toYaml .Values.resources | nindent 12 }} {{- toYaml .Values.resources | nindent 12 }}
# No documented dedicated health endpoint; /metrics is the route # No documented dedicated health endpoint; /metrics is the route
@@ -15,11 +15,13 @@ service:
env: env:
ACTUAL_SERVER_URL: "http://192.168.1.41:8002" ACTUAL_SERVER_URL: "http://192.168.1.41:8002"
# ACTUAL_BUDGET_NAME_1: "" # optional, adds a friendly name to the prometheus label # ACTUAL_BUDGET_NAME_1: "" # optional, adds a friendly name to the prometheus label
# ACTUAL_E2E_PASSWORD_1: "" # optional, only if E2E encryption is enabled on the budget
# ACTUAL_PASSWORD and ACTUAL_BUDGET_ID_1 are NOT set here — plaintext Actual # ACTUAL_PASSWORD, ACTUAL_BUDGET_ID_1, and ACTUAL_E2E_PASSWORD_1 are NOT set
# credentials in a git-committed values.yaml is not acceptable. They're read # here — plaintext Actual credentials don't belong in a git-committed
# from a Secret you create by hand once (see README.md), never committed. # values.yaml. They're read from a Secret you create by hand once (see
# README.md), never committed. ACTUAL_E2E_PASSWORD_1 is required whenever the
# budget has E2E encryption enabled (exporter fails with "File ... is
# encrypted" otherwise) — leave the key empty in the Secret if it isn't.
secret: secret:
name: actual-budget-exporter-secrets name: actual-budget-exporter-secrets