Merge pull request #68 from HideyoshiSolutions/develop

develop - feat: adds encryption key for kubernetes secrets
This commit is contained in:
2025-11-07 15:20:36 -03:00
committed by GitHub
4 changed files with 28 additions and 0 deletions

View File

@@ -97,4 +97,14 @@ variable "github_repositories" {
"storage-hideyoshi.com", "storage-hideyoshi.com",
"infra-hideyoshi.com", "infra-hideyoshi.com",
] ]
}
variable "gpg_private_key_encryption" {
type = string
sensitive = true
}
variable "gpg_public_key_encryption" {
type = string
sensitive = true
} }

View File

@@ -14,4 +14,9 @@ variable "github_repositories" {
variable "cluster_kubeconfig" { variable "cluster_kubeconfig" {
type = string type = string
sensitive = true sensitive = true
}
variable "gpg_private_key_encryption" {
type = string
sensitive = true
} }

View File

@@ -18,4 +18,11 @@ resource "github_actions_organization_secret" "cluster_kubeconfig" {
selected_repository_ids = [for repo in data.github_repository.repos : repo.repo_id] selected_repository_ids = [for repo in data.github_repository.repos : repo.repo_id]
secret_name = "PORTFOLIO_KUBECONFIG" secret_name = "PORTFOLIO_KUBECONFIG"
plaintext_value = chomp(var.cluster_kubeconfig) plaintext_value = chomp(var.cluster_kubeconfig)
}
resource "github_actions_organization_secret" "gpg_public_key" {
visibility = "selected"
selected_repository_ids = [for repo in data.github_repository.repos : repo.repo_id]
secret_name = "PORTFOLIO_GPG_PRIVATE_KEY"
plaintext_value = chomp(var.gpg_private_key_encryption)
} }

View File

@@ -101,10 +101,16 @@ module "github" {
github_owner = var.github_owner github_owner = var.github_owner
github_repositories = var.github_repositories github_repositories = var.github_repositories
cluster_kubeconfig = module.kubernetes.cluster_kubeconfig cluster_kubeconfig = module.kubernetes.cluster_kubeconfig
gpg_private_key_encryption = var.gpg_private_key_encryption
} }
output "cluster_kubeconfig" { output "cluster_kubeconfig" {
value = module.kubernetes.cluster_kubeconfig value = module.kubernetes.cluster_kubeconfig
sensitive = true sensitive = true
}
output "gpg_public_key_encryption" {
value = var.gpg_public_key_encryption
sensitive = true
} }