Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ROX-22599: Move secrets to RH GCP #1299

Merged
merged 1 commit into from
Jun 3, 2024

Conversation

gavin-stackrox
Copy link
Contributor

Changes the deploy script to use secrets from the RH GCP project. Testing detailed in https://github.com/stackrox/automation-iac/pull/121.

@gavin-stackrox gavin-stackrox requested a review from a team as a code owner May 23, 2024 17:04
@rhacs-bot
Copy link
Contributor

rhacs-bot commented May 23, 2024

A single node development cluster (infra-pr-1299) was allocated in production infra for this PR.

CI will attempt to deploy quay.io/rhacs-eng/infra-server:0.9.51-1-ga5d7855f63 to it.

🔌 You can connect to this cluster with:

gcloud container clusters get-credentials infra-pr-1299 --zone us-central1-a --project acs-team-temp-dev

🛠️ And pull infractl from the deployed dev infra-server with:

nohup kubectl -n infra port-forward svc/infra-server-service 8443:8443 &
make pull-infractl-from-dev-server

🚲 You can then use the dev infra instance e.g.:

bin/infractl -k -e localhost:8443 whoami

⚠️ Any clusters that you start using your dev infra instance should have a lifespan shorter then the development cluster instance. Otherwise they will not be destroyed when the dev infra instance ceases to exist when the development cluster is deleted. ⚠️

Further Development

☕ If you make changes, you can commit and push and CI will take care of updating the development cluster.

🚀 If you only modify configuration (chart/infra-server/configuration) or templates (chart/infra-server/{static,templates}), you can get a faster update with:

make install-local

Logs

Logs for the development infra depending on your @redhat.com authuser:

Or:

kubectl -n infra logs -l app=infra-server --tail=1 -f

@gavin-stackrox gavin-stackrox force-pushed the gavin/ROX-22599/move-secrets-to-RH-GCP branch from 25b3d7b to a5d7855 Compare May 23, 2024 17:13
@@ -257,23 +257,23 @@ bounce-argo-pods:
## Secrets ##
#############
.PHONY: secrets-download
secrets-download: pre-check
Copy link
Contributor Author

@gavin-stackrox gavin-stackrox May 23, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the context of secrets this precheck only has usefulness (IMO) to check that ENVIRONMENT is set and that is handled by the secrets.sh script. Intent of change: be able to manage secrets without being connected to the dev/prod cluster.

@gavin-stackrox gavin-stackrox merged commit ad9caa8 into master Jun 3, 2024
18 checks passed
@gavin-stackrox gavin-stackrox deleted the gavin/ROX-22599/move-secrets-to-RH-GCP branch June 3, 2024 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants