aboutsummaryrefslogtreecommitdiff
path: root/cluster/prod/app/drone-ci/secrets.toml
blob: ac0792667269828c066b258ee9ac88669846c85c (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
# Drone's secrets

[secrets."drone-ci/rpc_secret"]
type = 'command'
command = 'openssl rand -hex 16'
# don't rotate, it would break all runners

[secrets."drone-ci/cookie_secret"]
type = 'command'
rotate = true
command = 'openssl rand -hex 16'

[secrets."drone-ci/db_enc_secret"]
type = 'command'
command = 'openssl rand -hex 16'
# don't rotate, it is used to encrypt data which we would lose if we change this


# Oauth config for gitea

[secrets."drone-ci/oauth_client_secret"]
type = 'user'
description = 'OAuth client secret (for gitea)'

[secrets."drone-ci/oauth_client_id"]
type = 'user'
description = 'OAuth client ID (on Gitea)'


# S3 config for Git LFS storage

[secrets."drone-ci/s3_db_bucket"]
type = 'constant'
value = 'drone-db'

[secrets."drone-ci/s3_sk"]
type = 'user'
description = 'S3 (garage) secret key for Drone'

[secrets."drone-ci/s3_ak"]
type = 'user'
description = 'S3 (garage) access key for Drone'

[secrets."drone-ci/s3_storage_bucket"]
type = 'constant'
value = 'drone-storage'