Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Migrate all Opaque kubernetes Secrets on k8s-infra clusters to ExternalSecrets #2220

Closed
30 tasks done
spiffxp opened this issue Jun 15, 2021 · 6 comments
Closed
30 tasks done
Assignees
Labels
area/prow Setting up or working with prow in general, prow.k8s.io, prow build clusters priority/important-soon Must be staffed and worked on either currently, or very soon, ideally in time for the next release. sig/k8s-infra Categorizes an issue or PR as relevant to SIG K8s Infra. sig/testing Categorizes an issue or PR as relevant to SIG Testing.
Milestone

Comments

@spiffxp
Copy link
Member

spiffxp commented Jun 15, 2021

* new secret, not a migration, but tracking here anyway

@spiffxp
Copy link
Member Author

spiffxp commented Jun 15, 2021

/wg k8s-infra
/sig testing
/area prow
/priority important-soon
/milestone v1.22
/assign

@k8s-ci-robot k8s-ci-robot added wg/k8s-infra sig/testing Categorizes an issue or PR as relevant to SIG Testing. area/prow Setting up or working with prow in general, prow.k8s.io, prow build clusters labels Jun 15, 2021
@k8s-ci-robot k8s-ci-robot added this to the v1.22 milestone Jun 15, 2021
@k8s-ci-robot k8s-ci-robot added the priority/important-soon Must be staffed and worked on either currently, or very soon, ideally in time for the next release. label Jun 15, 2021
@spiffxp
Copy link
Member Author

spiffxp commented Jun 15, 2021

#2219 is a first attempt at migrating a secret for k8s-infra-prow-build-trusted

@ameukam
Copy link
Member

ameukam commented Jun 15, 2021

cc @chaodaiG

@spiffxp
Copy link
Member Author

spiffxp commented Aug 3, 2021

/milestone v1.23

@spiffxp
Copy link
Member Author

spiffxp commented Oct 1, 2021

/close
All secrets in our kubernetes clusters now come from Google Secret Manager (or could come from other secret systems). This is great for DR, since if a cluster disappears, we can re-provision it with the existing secrets. Also nice for safe rotation, since new secret values can be added without implicitly deleting old values.

We could use some docs updates here, and kubernetes-public is still managed via bash instead of terraform. Will continue to track that work under #1731

@k8s-ci-robot
Copy link
Contributor

@spiffxp: Closing this issue.

In response to this:

/close
All secrets in our kubernetes clusters now come from Google Secret Manager (or could come from other secret systems). This is great for DR, since if a cluster disappears, we can re-provision it with the existing secrets. Also nice for safe rotation, since new secret values can be added without implicitly deleting old values.

We could use some docs updates here, and kubernetes-public is still managed via bash instead of terraform. Will continue to track that work under #1731

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/prow Setting up or working with prow in general, prow.k8s.io, prow build clusters priority/important-soon Must be staffed and worked on either currently, or very soon, ideally in time for the next release. sig/k8s-infra Categorizes an issue or PR as relevant to SIG K8s Infra. sig/testing Categorizes an issue or PR as relevant to SIG Testing.
Projects
None yet
Development

No branches or pull requests

3 participants