titan-iac/services/vaultwarden/deployment.yaml

79 lines
2.2 KiB
YAML
Raw Normal View History

# services/vaultwarden/deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: vaultwarden
namespace: vaultwarden
spec:
replicas: 1
2026-01-03 17:07:48 -03:00
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 0
maxUnavailable: 1
selector:
matchLabels:
app: vaultwarden
template:
metadata:
labels:
app: vaultwarden
spec:
2026-01-14 02:54:59 -03:00
serviceAccountName: vaultwarden-vault
containers:
- name: vaultwarden
image: vaultwarden/server:1.33.2
2026-01-14 02:54:59 -03:00
command: ["/bin/sh", "-c"]
args:
- >-
. /vault/scripts/vaultwarden_vault_env.sh
&& exec /start.sh
env:
- name: SIGNUPS_ALLOWED
value: "false"
- name: INVITATIONS_ALLOWED
value: "true"
2026-01-03 17:44:24 -03:00
- name: DOMAIN
value: "https://vault.bstein.dev"
- name: SMTP_HOST
2026-01-14 10:07:31 -03:00
value: "smtp.postmarkapp.com"
2026-01-03 17:44:24 -03:00
- name: SMTP_PORT
2026-01-14 10:07:31 -03:00
value: "587"
2026-01-03 17:44:24 -03:00
- name: SMTP_SECURITY
value: "starttls"
2026-01-03 17:54:27 -03:00
- name: SMTP_ACCEPT_INVALID_HOSTNAMES
2026-01-14 10:07:31 -03:00
value: "false"
2026-01-03 17:54:27 -03:00
- name: SMTP_ACCEPT_INVALID_CERTS
2026-01-14 10:07:31 -03:00
value: "false"
2026-01-03 17:44:24 -03:00
- name: SMTP_FROM
2026-01-14 10:07:31 -03:00
value: "no-reply-vaultwarden@bstein.dev"
2026-01-03 17:44:24 -03:00
- name: SMTP_FROM_NAME
2026-01-14 10:07:31 -03:00
value: "Vaultwarden"
ports:
- name: http
containerPort: 80
protocol: TCP
volumeMounts:
- name: vaultwarden-data
mountPath: /data
2026-01-14 02:54:59 -03:00
- name: vault-secrets
mountPath: /vault/secrets
readOnly: true
- name: vault-scripts
mountPath: /vault/scripts
readOnly: true
volumes:
- name: vaultwarden-data
persistentVolumeClaim:
claimName: vaultwarden-data
2026-01-14 02:54:59 -03:00
- name: vault-secrets
csi:
driver: secrets-store.csi.k8s.io
readOnly: true
volumeAttributes:
secretProviderClass: vaultwarden-vault
- name: vault-scripts
configMap:
name: vaultwarden-vault-env
defaultMode: 0555