Update Jenkins values.yaml to enable external secret integration and adjust existingSecret configuration for Vault compatibility.
This commit is contained in:
@@ -5,7 +5,7 @@
|
|||||||
apiVersion: external-secrets.io/v1beta1
|
apiVersion: external-secrets.io/v1beta1
|
||||||
kind: ExternalSecret
|
kind: ExternalSecret
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ include "jenkins.fullname" . }}-admin-vault
|
name: {{ include "jenkins.fullname" . }}-admin
|
||||||
namespace: {{ template "jenkins.namespace" . }}
|
namespace: {{ template "jenkins.namespace" . }}
|
||||||
labels:
|
labels:
|
||||||
{{- include "jenkins.labels" . | nindent 4 }}
|
{{- include "jenkins.labels" . | nindent 4 }}
|
||||||
|
|||||||
@@ -99,12 +99,12 @@ controller:
|
|||||||
# -- Must stay true so the controller mounts the admin Secret; when existingSecret is set, the chart does not create that Secret (supply it yourself or via externalSecret).
|
# -- Must stay true so the controller mounts the admin Secret; when existingSecret is set, the chart does not create that Secret (supply it yourself or via externalSecret).
|
||||||
createSecret: true
|
createSecret: true
|
||||||
|
|
||||||
# -- Kubernetes Secret name with keys userKey / passwordKey (created manually, by External Secrets, etc.). Example for Vault: jenkins-admin.
|
# -- Must match ExternalSecret spec.target.name (default in templates/jenkins-admin-externalsecret.yaml is jenkins-admin). If empty, the chart mounts the release fullname Secret instead — not the Vault-backed one.
|
||||||
existingSecret: ""
|
existingSecret: jenkins-admin
|
||||||
|
|
||||||
# -- HashiCorp Vault → ExternalSecret → target Secret (requires External Secrets Operator + ClusterSecretStore). Helm does not read Vault.
|
# -- HashiCorp Vault → ExternalSecret → target Secret (requires External Secrets Operator + ClusterSecretStore). Helm does not read Vault.
|
||||||
externalSecret:
|
externalSecret:
|
||||||
enabled: false
|
enabled: true
|
||||||
refreshInterval: 1h
|
refreshInterval: 1h
|
||||||
secretStoreRef:
|
secretStoreRef:
|
||||||
name: vault
|
name: vault
|
||||||
|
|||||||
Reference in New Issue
Block a user