feat: Add Outline wiki and PostgreSQL production deployment#1563
Open
LukasCuperDT wants to merge 12 commits into
Open
feat: Add Outline wiki and PostgreSQL production deployment#1563LukasCuperDT wants to merge 12 commits into
LukasCuperDT wants to merge 12 commits into
Conversation
- Add upstream/outline values-prod.yaml (outline-k8s.eco.tsi-dev.otc-service.com) - Add local/outline values-prod.yaml (Redis minimal for prod) - Add upstream/postgresql values-prod.yaml (dedicated Outline DB) - Add local/postgresql values-prod.yaml (TLS cert for postgres.eco.tsi-dev.otc-service.com) - Add ArgoCD applications for postgresql and outline-wiki (prod/otcinfra2)
The otcinfra2 cluster routes docker.io through SWR proxy which requires authentication via the default-secret.
- postgresql:18.3.0 - postgres-exporter:0.19.1 - debian:12 All mirrored to quay.io/opentelekomcloud to bypass SWR proxy auth issues.
- outline:0.84.0 - redis:7-alpine All mirrored to quay.io/opentelekomcloud to bypass SWR proxy auth issues.
Add global.security.allowInsecureImages=true to bypass Bitnami's container verification for quay.io/opentelekomcloud mirrors.
Required for PostgreSQL chart dependency resolution.
Force fresh pull to replace cached arm64 images with amd64.
Force fresh pull to replace cached arm64 images with amd64.
4c2499d to
fd8ea0f
Compare
fd8ea0f to
d230d29
Compare
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 23016484 | Triggered | Generic Database Assignment | 6425fbd | kubernetes/helm_charts/upstream/outline/values-preprod.yaml | View secret |
| 29178534 | Triggered | Generic Database Assignment | 6425fbd | kubernetes/helm_charts/upstream/outline/values-prod.yaml | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secrets safely. Learn here the best practices.
- Revoke and rotate these secrets.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
Contributor
Author
|
recheck |
1 similar comment
Contributor
Author
|
recheck |
…postgresql - outline values: url, logoutUri, ingress host, tls → outline/config#externalURL - postgresql values: commonName, dnsNames → postgresql/admin#externalURL
SebastianGode
approved these changes
May 29, 2026
vladimirhasko
approved these changes
May 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Deploy Outline wiki application and its PostgreSQL database to the production cluster.
Changes
New: Outline production deployment
Fixes applied during deployment
quay.io/opentelekomcloudmirror images for Outline and PostgreSQLimagePullSecretsfor prod cluster registry accessimagePullPolicy: Alwaysfor Outline, Redis, and PostgreSQL imagesscram-sha-256authentication instead ofmd5(PostgreSQL 18 dropped md5 support)Testing