gitea: pin secret/internal token and include secret manifest

This commit is contained in:
Brad Stein 2025-12-14 22:06:25 -03:00
parent fc5b0cccf8
commit 29da4be557
3 changed files with 21 additions and 0 deletions

View File

@ -131,6 +131,16 @@ spec:
value: "trace" value: "trace"
- name: GITEA__service__REQUIRE_SIGNIN_VIEW - name: GITEA__service__REQUIRE_SIGNIN_VIEW
value: "false" value: "false"
- name: GITEA__security__SECRET_KEY
valueFrom:
secretKeyRef:
name: gitea-secret
key: SECRET_KEY
- name: GITEA__security__INTERNAL_TOKEN
valueFrom:
secretKeyRef:
name: gitea-secret
key: INTERNAL_TOKEN
- name: DB_TYPE - name: DB_TYPE
value: "postgres" value: "postgres"
- name: DB_HOST - name: DB_HOST

View File

@ -3,6 +3,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- namespace.yaml - namespace.yaml
- secret.yaml
- deployment.yaml - deployment.yaml
- service.yaml - service.yaml
- pvc.yaml - pvc.yaml

View File

@ -0,0 +1,10 @@
# services/gitea/secret.yaml
apiVersion: v1
kind: Secret
metadata:
name: gitea-secret
namespace: gitea
type: Opaque
stringData:
SECRET_KEY: "QVOarq1Tb8Lxm2esuB7MoWeK7wkNGpdePFRDyBhj1Rc"
INTERNAL_TOKEN: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJuYmYiOjE3NTQ1NzU3Mzd9.QVOarq1Tb8Lxm2esuB7MoWeK7wkNGpdePFRDyBhj1Rc"