Skip to content

Commit 40e8062

Browse files
authored
prevent Postgres secret from being overwritten on upgrade (#105)
* prevent postgres secret from being overwritten * bump version * add helm annotations to remaining secrets
1 parent 7c15115 commit 40e8062

File tree

4 files changed

+15
-11
lines changed

4 files changed

+15
-11
lines changed

charts/defguard/Chart.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ name: defguard
33
description: Defguard is an open-source enterprise WireGuard VPN with MFA and SSO
44

55
type: application
6-
version: 0.13.0
6+
version: 0.13.1
77
appVersion: 1.5.2
88

99
dependencies:

charts/defguard/templates/defguard-secret.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,8 @@ metadata:
1616
name: {{ include "defguard.jwtSecretName" . }}
1717
labels:
1818
{{- include "defguard.labels" . | nindent 4 }}
19+
annotations:
20+
"helm.sh/resource-policy": keep
1921
type: Opaque
2022
data:
2123
auth: {{ $auth }}

charts/defguard/templates/openid-secret.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@ metadata:
1010
name: {{ include "defguard.openidSecretName" . }}
1111
labels:
1212
{{- include "defguard.labels" . | nindent 4 }}
13+
annotations:
14+
"helm.sh/resource-policy": keep
1315
type: Opaque
1416
data:
1517
openid-key: {{ $openIdKey }}
Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,19 +1,19 @@
11
{{ if .Values.postgresql.enabled }}
2-
{{- $password := (randAlpha 16) | b64enc | quote }}
3-
{{- $postgresPassword := (randAlpha 16) | b64enc | quote }}
4-
{{- $secret := (lookup "v1" "Secret" .Release.Namespace .Values.postgresql.auth.existingSecret) }}
5-
{{- if $secret }}
6-
{{- $password = index $secret.data "password" }}
7-
{{- $postgresPassword = index $secret.data "postgres-password" }}
8-
{{- end }}
2+
{{- $secretName := .Values.postgresql.auth.existingSecret | default (printf "%s-postgresql" .Release.Name) }}
3+
{{- $existingSecret := (lookup "v1" "Secret" .Release.Namespace $secretName) }}
4+
5+
{{- if not $existingSecret }}
96
apiVersion: v1
107
kind: Secret
118
metadata:
12-
name: {{ .Values.postgresql.auth.existingSecret }}
9+
name: {{ $secretName }}
1310
labels:
1411
{{- include "defguard.labels" . | nindent 4 }}
12+
annotations:
13+
"helm.sh/resource-policy": keep
1514
type: Opaque
1615
data:
17-
password: {{ $password }}
18-
postgres-password: {{ $postgresPassword }}
16+
password: {{ randAlpha 16 | b64enc | quote }}
17+
postgres-password: {{ randAlpha 16 | b64enc | quote }}
18+
{{- end }}
1919
{{- end }}

0 commit comments

Comments
 (0)