diff --git a/cluster/applications/open-webui/externalsecret.yaml b/cluster/applications/open-webui/externalsecret.yaml index 93afbf5..d0f332e 100644 --- a/cluster/applications/open-webui/externalsecret.yaml +++ b/cluster/applications/open-webui/externalsecret.yaml @@ -18,15 +18,22 @@ spec: engineVersion: v2 data: vllm-api-key: "{{ .vllm_api_key }}" - webui-secret-key: "{{ .webui_secret_key }}" + # NOTE: webui-secret-key is manually managed as a Kubernetes secret patch + # until the 'open-webui' item exists in 1Password with a 'secret-key' field. + # To re-enable automatic sync: + # 1. Add open-webui item to 1Password mk-labs vault + # 2. Add secret-key field with a strong random value + # 3. Uncomment the data section below and re-apply this manifest + webui-secret-key: "{{ .webui_secret_key | default \"PLACEHOLDER\" }}" data: # vLLM API key from 1Password (mk-labs vault, vllm item, api-key field) - secretKey: vllm_api_key remoteRef: key: vllm property: api-key - # WebUI JWT signing secret from 1Password (mk-labs vault, open-webui item, secret-key field) - - secretKey: webui_secret_key - remoteRef: - key: open-webui - property: secret-key + # WebUI JWT signing secret - TEMPORARILY DISABLED + # Uncomment and configure once open-webui item exists in 1Password: + # - secretKey: webui_secret_key + # remoteRef: + # key: open-webui + # property: secret-key