Temporarily disable webui-secret-key from ExternalSecret
The 'open-webui' item doesn't exist in 1Password yet. webui-secret-key is manually patched in the secret for now. Re-enable ExternalSecret pull once the 1Password item is created.
This commit is contained in:
@@ -18,15 +18,22 @@ spec:
|
|||||||
engineVersion: v2
|
engineVersion: v2
|
||||||
data:
|
data:
|
||||||
vllm-api-key: "{{ .vllm_api_key }}"
|
vllm-api-key: "{{ .vllm_api_key }}"
|
||||||
webui-secret-key: "{{ .webui_secret_key }}"
|
# NOTE: webui-secret-key is manually managed as a Kubernetes secret patch
|
||||||
|
# until the 'open-webui' item exists in 1Password with a 'secret-key' field.
|
||||||
|
# To re-enable automatic sync:
|
||||||
|
# 1. Add open-webui item to 1Password mk-labs vault
|
||||||
|
# 2. Add secret-key field with a strong random value
|
||||||
|
# 3. Uncomment the data section below and re-apply this manifest
|
||||||
|
webui-secret-key: "{{ .webui_secret_key | default \"PLACEHOLDER\" }}"
|
||||||
data:
|
data:
|
||||||
# vLLM API key from 1Password (mk-labs vault, vllm item, api-key field)
|
# vLLM API key from 1Password (mk-labs vault, vllm item, api-key field)
|
||||||
- secretKey: vllm_api_key
|
- secretKey: vllm_api_key
|
||||||
remoteRef:
|
remoteRef:
|
||||||
key: vllm
|
key: vllm
|
||||||
property: api-key
|
property: api-key
|
||||||
# WebUI JWT signing secret from 1Password (mk-labs vault, open-webui item, secret-key field)
|
# WebUI JWT signing secret - TEMPORARILY DISABLED
|
||||||
- secretKey: webui_secret_key
|
# Uncomment and configure once open-webui item exists in 1Password:
|
||||||
remoteRef:
|
# - secretKey: webui_secret_key
|
||||||
key: open-webui
|
# remoteRef:
|
||||||
property: secret-key
|
# key: open-webui
|
||||||
|
# property: secret-key
|
||||||
|
|||||||
Reference in New Issue
Block a user