@@ -13,20 +13,85 @@ clusterSecretStores: {}
1313 # infisical:
1414 # auth:
1515 # universalAuthCredentials:
16- # secretsPath: "/k8s/platform"
1716 # clientId:
18- # secretRef:
19- # secretName: infisical-auth
20- # key: clientId
17+ # key: clientId
18+ # namespace: argocd
19+ # name: infisical-auth
2120 # clientSecret:
22- # secretRef:
23- # secretName: infisical-auth
24- # key: clientSecret
25- # hostAPI: "https://app.infisical.com/api"
26- # conditions:
27- # - namespaceSelector:
28- # matchLabels:
29- # platform-secrets: "enabled"
21+ # key: clientSecret
22+ # namespace: argocd
23+ # name: infisical-auth
24+ # hostAPI: "https://app.infisical.com"
25+ # secretsScope:
26+ # projectSlug: "my-project"
27+ # environmentSlug: "prod"
28+ # secretsPath: "/k8s/platform"
29+ # recursive: true
30+
31+ # External Secrets - Platform-wide secrets synced from external providers
32+ # These create secrets in specific namespaces for platform services
33+ externalSecrets : {}
34+ # oauth2-proxy-credentials:
35+ # namespace: network
36+ # refreshInterval: "5m"
37+ # secretStoreRef:
38+ # name: infisical-platform
39+ # kind: ClusterSecretStore
40+ # target:
41+ # name: oauth2-proxy-credentials
42+ # creationPolicy: Owner
43+ # data:
44+ # - secretKey: client-id
45+ # remoteRef:
46+ # key: /k8s/platform/oauth2_proxy_github_client_id
47+ # - secretKey: client-secret
48+ # remoteRef:
49+ # key: /k8s/platform/oauth2_proxy_github_client_secret
50+ # - secretKey: cookie-secret
51+ # remoteRef:
52+ # key: /k8s/platform/oauth2_proxy_cookie_secret
53+ #
54+ # cloudflare-cert-manager:
55+ # namespace: cert-manager
56+ # refreshInterval: "5m"
57+ # secretStoreRef:
58+ # name: infisical-platform
59+ # kind: ClusterSecretStore
60+ # target:
61+ # name: cloudflare
62+ # creationPolicy: Owner
63+ # data:
64+ # - secretKey: api-token
65+ # remoteRef:
66+ # key: /k8s/platform/cloudflare_api_token
67+ #
68+ # cloudflare-network:
69+ # namespace: network
70+ # refreshInterval: "5m"
71+ # secretStoreRef:
72+ # name: infisical-platform
73+ # kind: ClusterSecretStore
74+ # target:
75+ # name: cloudflare
76+ # creationPolicy: Owner
77+ # data:
78+ # - secretKey: api-token
79+ # remoteRef:
80+ # key: /k8s/platform/cloudflare_api_token
81+ #
82+ # api-basic-auth:
83+ # namespace: network
84+ # refreshInterval: "5m"
85+ # secretStoreRef:
86+ # name: infisical-platform
87+ # kind: ClusterSecretStore
88+ # target:
89+ # name: api-basic-auth
90+ # creationPolicy: Owner
91+ # data:
92+ # - secretKey: users
93+ # remoteRef:
94+ # key: /k8s/platform/api_basic_auth_users
3095
3196# Cluster Roles - Cluster-wide permissions
3297clusterRoles : {}
@@ -38,10 +103,6 @@ clusterRoles: {}
38103 # - apiGroups: ["external-secrets.io"]
39104 # resources: ["externalsecrets", "secretstores"]
40105 # verbs: ["*"]
41- # aggregationRule:
42- # clusterRoleSelectors:
43- # - matchLabels:
44- # rbac.platform/aggregate-to-operator: "true"
45106
46107# Cluster Role Bindings - Cluster-wide permission assignments
47108clusterRoleBindings : {}
0 commit comments