secrets.yaml 2.9 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980
  1. {{- $name := .Chart.Name }}
  2. {{- $globalAnnotationsCheck := include "global.annotations.check" . }}
  3. {{- range $index, $val := .Values.items }}
  4. {{- if and $val.imagePullSecrets $val.imagePullSecrets.enabled $val.imagePullSecrets.data }}
  5. apiVersion: v1
  6. kind: Secret
  7. metadata:
  8. labels:
  9. app: {{ $name }}
  10. tier: {{ $val.name | default (print $name) }}-dockerconfig
  11. name: {{ $val.imagePullSecrets.name | default (print $name "-dockerconfig") }}
  12. type: {{ $val.imagePullSecrets.data.type | default (print "kubernetes.io/dockerconfigjson") }}
  13. data:
  14. {{- if and $val.imagePullSecrets.data.registry $val.imagePullSecrets.data.login $val.imagePullSecrets.data.password }}
  15. .dockerconfigjson: {{ printf "{\"auths\":{\"%v\":{\"auth\":\"%v\",\"password\":\"%v\",\"username\":\"%v\"}}}"
  16. $val.imagePullSecrets.data.registry (printf "%v:%v"
  17. $val.imagePullSecrets.data.login
  18. $val.imagePullSecrets.data.password | b64enc)
  19. $val.imagePullSecrets.data.password
  20. $val.imagePullSecrets.data.login | b64enc }}
  21. {{- else }}
  22. {{- with $val.imagePullSecrets.data }}{{- toYaml . | nindent 2 }}{{- end }}
  23. {{- end }}
  24. {{ print "---" }}
  25. {{- end }}{{- end }}
  26. {{- range $index, $val := .Values.items }}
  27. {{- if $val.tls }}
  28. {{- if and $val.tls.enabled $val.tls.data }}
  29. apiVersion: v1
  30. kind: Secret
  31. metadata:
  32. {{- if $val.tls.annotations }}
  33. annotations:
  34. {{- toYaml $val.tls.annotations | nindent 4 }}
  35. {{- end }}
  36. labels:
  37. app: {{ $name }}
  38. tier: {{ $val.name | default (print $name) }}-secret-tls
  39. name: {{ $val.tls.name | default (print $name "-secret-tls") }}
  40. type: {{ $val.tls.data.type | default (print "kubernetes.io/tls") }}
  41. data:
  42. {{- if and $val.tls.data.key $val.tls.data.crt }}
  43. tls.key: {{ printf "%v" $val.tls.data.key | b64enc }}
  44. tls.crt: {{ printf "%v" $val.tls.data.crt | b64enc }}
  45. {{- else }}
  46. {{- with $val.tls.data }}{{- toYaml . | nindent 2 }}{{- end }}
  47. {{- end }}
  48. {{ print "---" }}
  49. {{- end }}{{- end }}{{- end }}
  50. {{- range $index, $val := .Values.items }}
  51. {{- if not (empty $val.containers) }}
  52. {{- range $Index, $Containers := $val.containers }}
  53. {{- if and $Containers.secret $Containers.secret.enabled $Containers.secret.data }}
  54. apiVersion: v1
  55. kind: Secret
  56. metadata:
  57. {{- if or $val.annotations $globalAnnotationsCheck }}
  58. annotations:
  59. {{- if and $val.annotations (not (eq $val.type "global")) }}
  60. {{- toYaml $val.annotations | nindent 4 }}
  61. {{- end }}
  62. {{- if $globalAnnotationsCheck }}
  63. {{- range $Index, $Val := $.Values.items }}
  64. {{- if eq $Val.type "global" }}
  65. {{- toYaml $Val.annotations | nindent 4 }}
  66. {{- end }}{{- end }}{{- end }}
  67. {{- end }}
  68. labels:
  69. app: {{ $name }}
  70. tier: {{ $val.name | default (print $name) }}-secret
  71. name: {{ $Containers.secret.name | default (print $name "-secret") }}
  72. type: Opaque
  73. data:
  74. {{- range $key, $value := $Containers.secret.data }}{{- if $value }}
  75. {{- printf "%v: %v" $key (printf "%v" $value | b64enc) | nindent 2 }}
  76. {{- end }}{{- end }}
  77. {{- end }}{{- end }}{{- end }}
  78. {{ print "---" }}
  79. {{- end }}