-
Notifications
You must be signed in to change notification settings - Fork 828
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
prow: switch cncf-ci-github-token to ExternalSecret #2219
Merged
k8s-ci-robot
merged 5 commits into
kubernetes:main
from
spiffxp:external-secrets-audit-token
Jun 15, 2021
Merged
prow: switch cncf-ci-github-token to ExternalSecret #2219
k8s-ci-robot
merged 5 commits into
kubernetes:main
from
spiffxp:external-secrets-audit-token
Jun 15, 2021
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
k8s-ci-robot
added
do-not-merge/work-in-progress
Indicates that a PR should not merge because it is a work in progress.
cncf-cla: yes
Indicates the PR's author has signed the CNCF CLA.
labels
Jun 15, 2021
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: spiffxp The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
k8s-ci-robot
added
area/audit
Audit of project resources, audit followup issues, code in audit/
area/terraform
Terraform modules, testing them, writing more of them, code in infra/gcp/clusters/
approved
Indicates a PR has been approved by an approver from all required OWNERS files.
area/prow
Setting up or working with prow in general, prow.k8s.io, prow build clusters
sig/testing
Categorizes an issue or PR as relevant to SIG Testing.
wg/k8s-infra
size/XS
Denotes a PR that changes 0-9 lines, ignoring generated files.
size/S
Denotes a PR that changes 10-29 lines, ignoring generated files.
and removed
size/XS
Denotes a PR that changes 0-9 lines, ignoring generated files.
labels
Jun 15, 2021
specifically cncf-ci-github-token in test-pods namespace
spiffxp
force-pushed
the
external-secrets-audit-token
branch
from
June 15, 2021 19:23
70b9a2c
to
b6e92b6
Compare
k8s-ci-robot
added
size/M
Denotes a PR that changes 30-99 lines, ignoring generated files.
and removed
size/S
Denotes a PR that changes 10-29 lines, ignoring generated files.
labels
Jun 15, 2021
spiffxp
changed the title
[wip] prow: switch cncf-ci-token to ExternalSecret
prow: switch cncf-ci-github-token to ExternalSecret
Jun 15, 2021
k8s-ci-robot
removed
the
do-not-merge/work-in-progress
Indicates that a PR should not merge because it is a work in progress.
label
Jun 15, 2021
30 tasks
Migrating secrets ref: #2220 |
/lgtm |
k8s-ci-robot
added
the
lgtm
"Looks good to me", indicates that a PR is ready to be merged.
label
Jun 15, 2021
This was referenced Jun 15, 2021
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
approved
Indicates a PR has been approved by an approver from all required OWNERS files.
area/audit
Audit of project resources, audit followup issues, code in audit/
area/prow
Setting up or working with prow in general, prow.k8s.io, prow build clusters
area/terraform
Terraform modules, testing them, writing more of them, code in infra/gcp/clusters/
cncf-cla: yes
Indicates the PR's author has signed the CNCF CLA.
lgtm
"Looks good to me", indicates that a PR is ready to be merged.
sig/testing
Categorizes an issue or PR as relevant to SIG Testing.
size/M
Denotes a PR that changes 30-99 lines, ignoring generated files.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Migrate the cncf-ci-github-token Kubernetes
Secret
used by the ci-k8sio-audit job to anExternalSecret
.This let me uncover a few things:
prow-build-trusted
setup the same way asprow-build
for accesskubernetes-external-secrets
service account setup{namespace}-{resource}.yaml
convention forserviceaccounts
andexternalsecrets
Everything here has already been deployed
I exercised by changing the secret value to "monkeys" and seeing the change reflected in-cluster, before changing back.