Skip to content

Commit

Permalink
fix: Sealed Secrets CRD moved to dependencies (#72)
Browse files Browse the repository at this point in the history
* fix: Sealed Secrets CRD moved to dependencies

* Fix
  • Loading branch information
laszlocph authored Oct 9, 2024
1 parent d3dfa30 commit b00d998
Show file tree
Hide file tree
Showing 3 changed files with 173 additions and 2 deletions.
170 changes: 170 additions & 0 deletions dependencies/sealed-secrets-crd.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,170 @@
{{ if .sealedSecrets.enabled -}}
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.15.0
name: sealedsecrets.bitnami.com
spec:
group: bitnami.com
names:
kind: SealedSecret
listKind: SealedSecretList
plural: sealedsecrets
singular: sealedsecret
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .status.conditions[0].message
name: Status
type: string
- jsonPath: .status.conditions[0].status
name: Synced
type: string
- jsonPath: .metadata.creationTimestamp
name: Age
type: date
name: v1alpha1
schema:
openAPIV3Schema:
description: |-
SealedSecret is the K8s representation of a "sealed Secret" - a
regular k8s Secret that has been sealed (encrypted) using the
controller's key.
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: SealedSecretSpec is the specification of a SealedSecret.
properties:
data:
description: Data is deprecated and will be removed eventually. Use
per-value EncryptedData instead.
format: byte
type: string
encryptedData:
additionalProperties:
type: string
type: object
x-kubernetes-preserve-unknown-fields: true
template:
description: |-
Template defines the structure of the Secret that will be
created from this sealed secret.
properties:
data:
additionalProperties:
type: string
description: Keys that should be templated using decrypted data.
nullable: true
type: object
immutable:
description: |-
Immutable, if set to true, ensures that data stored in the Secret cannot
be updated (only object metadata can be modified).
If not set to true, the field can be modified at any time.
Defaulted to nil.
type: boolean
metadata:
description: |-
Standard object's metadata.
More info: https://git.k8s.io/community/contributors/devel/api-conventions.md#metadata
nullable: true
properties:
annotations:
additionalProperties:
type: string
type: object
finalizers:
items:
type: string
type: array
labels:
additionalProperties:
type: string
type: object
name:
type: string
namespace:
type: string
type: object
x-kubernetes-preserve-unknown-fields: true
type:
description: Used to facilitate programmatic handling of secret
data.
type: string
type: object
required:
- encryptedData
type: object
status:
description: SealedSecretStatus is the most recently observed status of
the SealedSecret.
properties:
conditions:
description: Represents the latest available observations of a sealed
secret's current state.
items:
description: SealedSecretCondition describes the state of a sealed
secret at a certain point.
properties:
lastTransitionTime:
description: Last time the condition transitioned from one status
to another.
format: date-time
type: string
lastUpdateTime:
description: The last time this condition was updated.
format: date-time
type: string
message:
description: A human readable message indicating details about
the transition.
type: string
reason:
description: The reason for the condition's last transition.
type: string
status:
description: |-
Status of the condition for a sealed secret.
Valid values for "Synced": "True", "False", or "Unknown".
type: string
type:
description: |-
Type of condition for a sealed secret.
Valid value: "Synced"
type: string
required:
- status
- type
type: object
type: array
observedGeneration:
description: ObservedGeneration reflects the generation most recently
observed by the sealed-secrets controller.
format: int64
type: integer
type: object
required:
- spec
type: object
served: true
storage: true
subresources:
status: {}
{{- end }}
2 changes: 2 additions & 0 deletions helm-releases/sealed-secrets.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,8 @@ metadata:
spec:
interval: 60m
releaseName: sealed-secrets-controller
install:
crds: Skip
chart:
spec:
chart: sealed-secrets
Expand Down
3 changes: 1 addition & 2 deletions stack-definition.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1349,8 +1349,7 @@ components:
}
]
changeLog: |
- 🍏 Gimlet Agent to beta.14, if deployed with Gimlet beta.14 enables support for Docker build contexts and better error handling
- πŸ› fix: updated sealed-secrets version format
- πŸ› fix: Sealed Secrets CRD moved to dependencies. It often prevented applying the gitops repo on new clusters.
message: |
Hey πŸ‘‹ Laszlo here, the founder of Gimlet.io
Expand Down

0 comments on commit b00d998

Please sign in to comment.