fix(infrastructure): add oauth keys as secret

This commit is contained in:
2025-10-16 18:18:19 +02:00
parent b6f9ee8fc7
commit 60109c4a35
2 changed files with 27 additions and 5 deletions

View File

@@ -20,7 +20,7 @@ spec:
securityContext: securityContext:
allowPrivilegeEscalation: false allowPrivilegeEscalation: false
capabilities: capabilities:
drop: ["ALL"] drop: [ "ALL" ]
ports: ports:
- containerPort: {{ .Values.app.port }} - containerPort: {{ .Values.app.port }}
env: env:
@@ -53,13 +53,25 @@ spec:
- name: MAIL_QUEUE - name: MAIL_QUEUE
value: {{ .Values.worker.mailQueueName | default "mail_queue" | quote }} value: {{ .Values.worker.mailQueueName | default "mail_queue" | quote }}
- name: MOJEID_CLIENT_ID - name: MOJEID_CLIENT_ID
value: {{ .Values.oauth.mojeid.clientId | quote }} valueFrom:
secretKeyRef:
name: prod
key: MOJEID_CLIENT_ID
- name: MOJEID_CLIENT_SECRET - name: MOJEID_CLIENT_SECRET
value: {{ .Values.oauth.mojeid.clientSecret | quote }} valueFrom:
secretKeyRef:
name: prod
key: MOJEID_CLIENT_SECRET
- name: BANKID_CLIENT_ID - name: BANKID_CLIENT_ID
value: {{ .Values.oauth.bankid.clientId | quote }} valueFrom:
secretKeyRef:
name: prod
key: BANKID_CLIENT_ID
- name: BANKID_CLIENT_SECRET - name: BANKID_CLIENT_SECRET
value: {{ .Values.oauth.bankid.clientSecret | quote }} valueFrom:
secretKeyRef:
name: prod
key: BANKID_CLIENT_SECRET
- name: DOMAIN - name: DOMAIN
value: {{ required "Set .Values.domain" .Values.domain | quote }} value: {{ required "Set .Values.domain" .Values.domain | quote }}
- name: DOMAIN_SCHEME - name: DOMAIN_SCHEME

View File

@@ -0,0 +1,10 @@
apiVersion: v1
kind: Secret
metadata:
name: prod
type: Opaque
stringData:
MOJEID_CLIENT_ID: {{ .Values.oauth.mojeid.clientId | quote }}
MOJEID_CLIENT_SECRET: {{ .Values.oauth.mojeid.clientSecret | quote }}
BANKID_CLIENT_ID: {{ .Values.oauth.bankid.clientId | quote }}
BANKID_CLIENT_SECRET: {{ .Values.oauth.bankid.clientSecret | quote }}