diff --git a/apps/templates/blog-helm.yaml b/apps/templates/blog-helm.yaml index fe985c0..e7b81ed 100644 --- a/apps/templates/blog-helm.yaml +++ b/apps/templates/blog-helm.yaml @@ -1,128 +1,128 @@ -# apiVersion: argoproj.io/v1alpha1 -# kind: Application -# metadata: -# name: blog-helm -# namespace: argocd -# finalizers: -# - resources-finalizer.argocd.argoproj.io -# spec: -# destination: -# namespace: blog -# server: https://kubernetes.default.svc -# project: default -# source: -# repoURL: registry-1.docker.io/bitnamicharts -# targetRevision: 22.2.4 -# chart: ghost -# helm: -# values: | -# image: -# debug: true -# ghostUsername: ruben -# ## @param existingSecret Name of existing secret containing Ghost credentials -# ## NOTE: Must contain key `ghost-password` -# ## NOTE: When it's set, the `ghostPassword` parameter is ignored -# existingSecret: ghost-es -# ghostEmail: ruben.hensen@protonmail.com -# ghostBlogTitle: Catch && Compile -# ghostHost: "blog.hensen.io" -# ghostPath: / -# ghostEnableHttps: true -# ## SMTP mail delivery configuration -# ## ref: https://github.com/bitnami/containers/tree/main/bitnami/ghost/#smtp-configuration -# ## @param smtpHost SMTP server host -# ## @param smtpPort SMTP server port -# ## @param smtpUser SMTP username -# ## @param smtpPassword SMTP user password -# ## @param smtpService SMTP service -# ## @param smtpProtocol SMTP protocol (ssl or tls) -# ## -# smtpHost: smtp.hostinger.com -# smtpPort: 465 -# smtpUser: ruben@hensen.io -# smtpPassword: "ignored-but-hast-to-exist-else-password-isnt-passed" -# smtpProtocol: tls -# ## @param smtpExistingSecret The name of an existing secret with SMTP credentials -# ## NOTE: Must contain key `smtp-password` -# ## NOTE: When it's set, the `smtpPassword` parameter is ignored -# ## -# ## @param extraEnvVars Array with extra environment variables to add to the Ghost container -# ## e.g: -# ## extraEnvVars: -# ## - name: FOO -# ## value: "bar" -# ## -# # extraEnvVars: -# # - name: mail__options__secure -# # value: "false" -# ## @param allowEmptyPassword Allow the container to be started with blank passwords -# allowEmptyPassword: false -# resourcesPreset: "micro" -# containerPorts: -# http: 2368 -# https: 2368 -# service: -# type: ClusterIP -# ports: -# http: 80 -# https: 443 -# ingress: -# enabled: true -# ingressClassName: nginx -# hostname: blog.hensen.io -# path: / -# annotations: -# cert-manager.io/cluster-issuer: prod-cluster-issuer -# nginx.ingress.kubernetes.io/proxy-body-size: 1G -# tls: true -# tlsWwwPrefix: false -# selfSigned: false -# persistence: -# enabled: true -# accessModes: -# - ReadWriteOnce -# size: 8Gi -# mysql: -# enabled: true -# architecture: standalone -# ## MySQL Authentication parameters -# ## @param mysql.auth.rootPassword MySQL root password -# ## @param mysql.auth.database MySQL custom database -# ## @param mysql.auth.username MySQL custom user name -# ## @param mysql.auth.password MySQL custom user password -# ## @param mysql.auth.existingSecret Existing secret with MySQL credentials -# ## ref: https://github.com/bitnami/containers/tree/main/bitnami/mysql#setting-the-root-password-on-first-run -# ## https://github.com/bitnami/containers/tree/main/bitnami/mysql/#creating-a-database-on-first-run -# ## https://github.com/bitnami/containers/tree/main/bitnami/mysql/#creating-a-database-user-on-first-run -# auth: -# database: bitnami_ghost -# username: bn_ghost -# existingSecret: ghost-es -# primary: -# ## MySQL Primary Persistence parameters -# ## ref: https://kubernetes.io/docs/concepts/storage/persistent-volumes/ -# ## @param mysql.primary.persistence.enabled Enable persistence on MySQL using PVC(s) -# ## @param mysql.primary.persistence.storageClass Persistent Volume storage class -# ## @param mysql.primary.persistence.accessModes [array] Persistent Volume access modes -# ## @param mysql.primary.persistence.size Persistent Volume size -# ## -# persistence: -# enabled: true -# storageClass: "" -# accessModes: -# - ReadWriteOnce -# size: 8Gi -# ## MySQL primary container's resource requests and limits -# ## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/ -# ## We usually recommend not to specify default resources and to leave this as a conscious -# ## choice for the user. This also increases chances charts run on environments with little -# ## resources, such as Minikube. If you do want to specify resources, uncomment the following -# ## lines, adjust them as necessary, and remove the curly braces after 'resources:'. -# ## @param mysql.primary.resourcesPreset Set container resources according to one common preset (allowed values: none, nano, small, medium, large, xlarge, 2xlarge). This is ignored if primary.resources is set (primary.resources is recommended for production) -# resourcesPreset: "small" +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: blog-helm + namespace: argocd + finalizers: + - resources-finalizer.argocd.argoproj.io +spec: + destination: + namespace: blog + server: https://kubernetes.default.svc + project: default + source: + repoURL: registry-1.docker.io/bitnamicharts + targetRevision: 22.2.4 + chart: ghost + helm: + values: | + image: + debug: true + ghostUsername: ruben + ## @param existingSecret Name of existing secret containing Ghost credentials + ## NOTE: Must contain key `ghost-password` + ## NOTE: When it's set, the `ghostPassword` parameter is ignored + existingSecret: ghost-es + ghostEmail: ruben.hensen@protonmail.com + ghostBlogTitle: Catch && Compile + ghostHost: "blog.hensen.io" + ghostPath: / + ghostEnableHttps: true + ## SMTP mail delivery configuration + ## ref: https://github.com/bitnami/containers/tree/main/bitnami/ghost/#smtp-configuration + ## @param smtpHost SMTP server host + ## @param smtpPort SMTP server port + ## @param smtpUser SMTP username + ## @param smtpPassword SMTP user password + ## @param smtpService SMTP service + ## @param smtpProtocol SMTP protocol (ssl or tls) + ## + smtpHost: smtp.hostinger.com + smtpPort: 465 + smtpUser: ruben@hensen.io + smtpPassword: "ignored-but-hast-to-exist-else-password-isnt-passed" + smtpProtocol: tls + ## @param smtpExistingSecret The name of an existing secret with SMTP credentials + ## NOTE: Must contain key `smtp-password` + ## NOTE: When it's set, the `smtpPassword` parameter is ignored + ## + ## @param extraEnvVars Array with extra environment variables to add to the Ghost container + ## e.g: + ## extraEnvVars: + ## - name: FOO + ## value: "bar" + ## + # extraEnvVars: + # - name: mail__options__secure + # value: "false" + ## @param allowEmptyPassword Allow the container to be started with blank passwords + allowEmptyPassword: false + resourcesPreset: "micro" + containerPorts: + http: 2368 + https: 2368 + service: + type: ClusterIP + ports: + http: 80 + https: 443 + ingress: + enabled: true + ingressClassName: nginx + hostname: blog.hensen.io + path: / + annotations: + cert-manager.io/cluster-issuer: prod-cluster-issuer + nginx.ingress.kubernetes.io/proxy-body-size: 1G + tls: true + tlsWwwPrefix: false + selfSigned: false + persistence: + enabled: true + accessModes: + - ReadWriteOnce + size: 8Gi + mysql: + enabled: true + architecture: standalone + ## MySQL Authentication parameters + ## @param mysql.auth.rootPassword MySQL root password + ## @param mysql.auth.database MySQL custom database + ## @param mysql.auth.username MySQL custom user name + ## @param mysql.auth.password MySQL custom user password + ## @param mysql.auth.existingSecret Existing secret with MySQL credentials + ## ref: https://github.com/bitnami/containers/tree/main/bitnami/mysql#setting-the-root-password-on-first-run + ## https://github.com/bitnami/containers/tree/main/bitnami/mysql/#creating-a-database-on-first-run + ## https://github.com/bitnami/containers/tree/main/bitnami/mysql/#creating-a-database-user-on-first-run + auth: + database: bitnami_ghost + username: bn_ghost + existingSecret: ghost-es + primary: + ## MySQL Primary Persistence parameters + ## ref: https://kubernetes.io/docs/concepts/storage/persistent-volumes/ + ## @param mysql.primary.persistence.enabled Enable persistence on MySQL using PVC(s) + ## @param mysql.primary.persistence.storageClass Persistent Volume storage class + ## @param mysql.primary.persistence.accessModes [array] Persistent Volume access modes + ## @param mysql.primary.persistence.size Persistent Volume size + ## + persistence: + enabled: true + storageClass: "" + accessModes: + - ReadWriteOnce + size: 8Gi + ## MySQL primary container's resource requests and limits + ## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/ + ## We usually recommend not to specify default resources and to leave this as a conscious + ## choice for the user. This also increases chances charts run on environments with little + ## resources, such as Minikube. If you do want to specify resources, uncomment the following + ## lines, adjust them as necessary, and remove the curly braces after 'resources:'. + ## @param mysql.primary.resourcesPreset Set container resources according to one common preset (allowed values: none, nano, small, medium, large, xlarge, 2xlarge). This is ignored if primary.resources is set (primary.resources is recommended for production) + resourcesPreset: "small" -# syncPolicy: -# syncOptions: -# - CreateNamespace=true -# automated: -# selfHeal: true + syncPolicy: + syncOptions: + - CreateNamespace=true + automated: + selfHeal: true diff --git a/secrets/blog.yaml b/secrets/blog.yaml index 9e14a29..19872af 100644 --- a/secrets/blog.yaml +++ b/secrets/blog.yaml @@ -1,33 +1,33 @@ -# apiVersion: external-secrets.io/v1beta1 -# kind: ExternalSecret -# metadata: -# name: hensenio-ghost-secrets -# namespace: blog -# spec: -# refreshInterval: "15m" -# secretStoreRef: -# name: vault-backend -# kind: ClusterSecretStore -# target: -# name: ghost-es -# creationPolicy: Owner -# data: -# - secretKey: mysql-root-password -# remoteRef: -# key: kv/ghost -# property: ghostmsqlrootpw +apiVersion: external-secrets.io/v1beta1 +kind: ExternalSecret +metadata: + name: hensenio-ghost-secrets + namespace: blog +spec: + refreshInterval: "15m" + secretStoreRef: + name: vault-backend + kind: ClusterSecretStore + target: + name: ghost-es + creationPolicy: Owner + data: + - secretKey: mysql-root-password + remoteRef: + key: kv/ghost + property: ghostmsqlrootpw -# - secretKey: mysql-password -# remoteRef: -# key: kv/ghost -# property: ghostmsqlpw + - secretKey: mysql-password + remoteRef: + key: kv/ghost + property: ghostmsqlpw -# - secretKey: ghost-password -# remoteRef: -# key: kv/ghost -# property: ghostpw + - secretKey: ghost-password + remoteRef: + key: kv/ghost + property: ghostpw -# - secretKey: smtp-password -# remoteRef: -# key: kv/hensenio/smtp -# property: password \ No newline at end of file + - secretKey: smtp-password + remoteRef: + key: kv/hensenio/smtp + property: password \ No newline at end of file