diff options
Diffstat (limited to 'cluster/prod/app/plume')
7 files changed, 10 insertions, 6 deletions
diff --git a/cluster/prod/app/plume/secrets.toml b/cluster/prod/app/plume/secrets.toml new file mode 100644 index 0000000..4d68a5c --- /dev/null +++ b/cluster/prod/app/plume/secrets.toml @@ -0,0 +1,10 @@ +[service_user."plume"] +password_secret = "plume/pgsql_pw" + + +[secrets."plume/secret_key"] +type = 'command' +rotate = true +command = 'openssl rand -base64 32' + + diff --git a/cluster/prod/app/plume/secrets/plume/backup_aws_access_key_id b/cluster/prod/app/plume/secrets/plume/backup_aws_access_key_id deleted file mode 100644 index 9235e53..0000000 --- a/cluster/prod/app/plume/secrets/plume/backup_aws_access_key_id +++ /dev/null @@ -1 +0,0 @@ -USER Backup AWS access key ID diff --git a/cluster/prod/app/plume/secrets/plume/backup_aws_secret_access_key b/cluster/prod/app/plume/secrets/plume/backup_aws_secret_access_key deleted file mode 100644 index f34677e..0000000 --- a/cluster/prod/app/plume/secrets/plume/backup_aws_secret_access_key +++ /dev/null @@ -1 +0,0 @@ -USER Backup AWS secret access key diff --git a/cluster/prod/app/plume/secrets/plume/backup_restic_password b/cluster/prod/app/plume/secrets/plume/backup_restic_password deleted file mode 100644 index fbaa5fa..0000000 --- a/cluster/prod/app/plume/secrets/plume/backup_restic_password +++ /dev/null @@ -1 +0,0 @@ -USER Restic password to encrypt backups diff --git a/cluster/prod/app/plume/secrets/plume/backup_restic_repository b/cluster/prod/app/plume/secrets/plume/backup_restic_repository deleted file mode 100644 index 3f6cb93..0000000 --- a/cluster/prod/app/plume/secrets/plume/backup_restic_repository +++ /dev/null @@ -1 +0,0 @@ -USER Restic repository, eg. s3:https://s3.garage.tld diff --git a/cluster/prod/app/plume/secrets/plume/pgsql_pw b/cluster/prod/app/plume/secrets/plume/pgsql_pw deleted file mode 100644 index 0f831bb..0000000 --- a/cluster/prod/app/plume/secrets/plume/pgsql_pw +++ /dev/null @@ -1 +0,0 @@ -SERVICE_PASSWORD plume diff --git a/cluster/prod/app/plume/secrets/plume/secret_key b/cluster/prod/app/plume/secrets/plume/secret_key deleted file mode 100644 index 978be54..0000000 --- a/cluster/prod/app/plume/secrets/plume/secret_key +++ /dev/null @@ -1 +0,0 @@ -CMD openssl rand -base64 32 |