diff options
Diffstat (limited to 'cluster/prod/app/garage')
-rw-r--r-- | cluster/prod/app/garage/secrets.toml | 14 | ||||
-rw-r--r-- | cluster/prod/app/garage/secrets/garage/admin_token | 1 | ||||
-rw-r--r-- | cluster/prod/app/garage/secrets/garage/metrics_token | 1 | ||||
-rw-r--r-- | cluster/prod/app/garage/secrets/garage/rpc_secret | 1 |
4 files changed, 14 insertions, 3 deletions
diff --git a/cluster/prod/app/garage/secrets.toml b/cluster/prod/app/garage/secrets.toml new file mode 100644 index 0000000..e616091 --- /dev/null +++ b/cluster/prod/app/garage/secrets.toml @@ -0,0 +1,14 @@ +[secrets."garage/rpc_secret"] +type = 'command' +command = 'openssl rand -hex 32' +# can't auto-rotate, because we still have some nodes outside of Nomad + +[secrets."garage/admin_token"] +type = 'command' +command = 'openssl rand -hex 32' +rotate = true + +[secrets."garage/metrics_token"] +type = 'command' +command = 'openssl rand -hex 32' +rotate = true diff --git a/cluster/prod/app/garage/secrets/garage/admin_token b/cluster/prod/app/garage/secrets/garage/admin_token deleted file mode 100644 index d831d53..0000000 --- a/cluster/prod/app/garage/secrets/garage/admin_token +++ /dev/null @@ -1 +0,0 @@ -CMD_ONCE openssl rand -hex 32 diff --git a/cluster/prod/app/garage/secrets/garage/metrics_token b/cluster/prod/app/garage/secrets/garage/metrics_token deleted file mode 100644 index d831d53..0000000 --- a/cluster/prod/app/garage/secrets/garage/metrics_token +++ /dev/null @@ -1 +0,0 @@ -CMD_ONCE openssl rand -hex 32 diff --git a/cluster/prod/app/garage/secrets/garage/rpc_secret b/cluster/prod/app/garage/secrets/garage/rpc_secret deleted file mode 100644 index d831d53..0000000 --- a/cluster/prod/app/garage/secrets/garage/rpc_secret +++ /dev/null @@ -1 +0,0 @@ -CMD_ONCE openssl rand -hex 32 |