feature/sso-hardening #9

Merged
bstein merged 685 commits from feature/sso-hardening into main 2026-01-13 20:23:26 +00:00
2 changed files with 5 additions and 5 deletions
Showing only changes of commit d3c6ddeead - Show all commits

View File

@ -2,7 +2,7 @@
apiVersion: batch/v1 apiVersion: batch/v1
kind: Job kind: Job
metadata: metadata:
name: othrys-synapse-signingkey-ensure-4 name: othrys-synapse-signingkey-ensure-5
namespace: comms namespace: comms
spec: spec:
backoffLimit: 2 backoffLimit: 2
@ -34,9 +34,9 @@ spec:
if kubectl -n comms get secret othrys-synapse-signingkey -o jsonpath='{.data.signing\.key}' 2>/dev/null | grep -q .; then if kubectl -n comms get secret othrys-synapse-signingkey -o jsonpath='{.data.signing\.key}' 2>/dev/null | grep -q .; then
exit 0 exit 0
fi fi
signing_key_b64="$(base64 /work/signing.key | tr -d '\n')" kubectl -n comms create secret generic othrys-synapse-signingkey \
payload="$(printf '{"data":{"signing.key":"%s"}}' "${signing_key_b64}")" --from-file=signing.key=/work/signing.key \
kubectl -n comms patch secret othrys-synapse-signingkey --type=merge -p "${payload}" >/dev/null --dry-run=client -o yaml | kubectl -n comms apply -f - >/dev/null
volumeMounts: volumeMounts:
- name: work - name: work
mountPath: /work mountPath: /work

View File

@ -2,7 +2,7 @@
apiVersion: batch/v1 apiVersion: batch/v1
kind: Job kind: Job
metadata: metadata:
name: synapse-oidc-secret-ensure-3 name: synapse-oidc-secret-ensure-4
namespace: sso namespace: sso
spec: spec:
backoffLimit: 0 backoffLimit: 0