Skip to content

Conversation

@ElderMatt
Copy link
Contributor

📌 Summary

Replaces secrets withs secretRefs for Harbor and Oauth2-Proxy.

Uses environment Variables for Loki.

merll
merll previously requested changes Dec 17, 2025
Copy link
Contributor

@merll merll left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requested changes as current implementation does not seem to work well when moving on to sealed secrets.

@ElderMatt ElderMatt requested a review from merll December 18, 2025 13:14
@ElderMatt ElderMatt requested a review from CasLubbers December 19, 2025 08:20

resources: {{- $h.resources.core | toYaml | nindent 4 }}
secret: {{ $h | get "core.secret" nil | quote }}
existingSecretKey: harbor-core-secret-key
Copy link
Contributor

@j-zimnowoda j-zimnowoda Dec 30, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

core.existingSecretKey does not exist in the Harbor helm chart. Did you mean core.secretName?

We have not set it before because we are relying on istio mTLS. What is the reason you decided to se it now?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mixed some things together in my notes, should now be fixed.

Copy link
Contributor

@j-zimnowoda j-zimnowoda left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left one inline comment.

While running bin/compare.sh script I noticed that few Loki secretRefs are set to null which does not seem to be right.

spec.template.spec.containers.compactor
  + one map entry added:
    envFrom:
    - name: loki-s3-linode-credentials
    │ secretRef: null


data.config.yaml
  ± value change in multiline text (one insert, one deletion)
    -     s3: https://someaccessKeyId:somesecretvalue@nl-ams-1.linodeobjects.com/my-clusterid-loki
    +     s3: https://${S3_ACCESS_KEY_ID}:${S3_ACCESS_KEY_SECRET}@nl-ams-1.linodeobjects.com/my-clusterid-loki



spec.template.spec.containers.distributor
  + one map entry added:
    envFrom:
    - name: loki-s3-linode-credentials
    │ secretRef: null


spec.template.spec.containers.ingester
  + one map entry added:
    envFrom:
    - name: loki-s3-linode-credentials
    │ secretRef: null


spec.template.spec.containers.querier
  + one map entry added:
    envFrom:
    - name: loki-s3-linode-credentials
    │ secretRef: null


spec.template.spec.containers.query-frontend
  + one map entry added:
    envFrom:
    - name: loki-s3-linode-credentials
    │ secretRef: null

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants