Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(tf): create password for read-only SQL user #1665

Merged
merged 1 commit into from
Jul 8, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion tf/env/production/kubernetes-secrets.tf
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
module "wbaas-k8s-secrets" {
source = "git::ssh://[email protected]/wmde/wbaas-deploy//tf//modules/k8s-secrets?ref=tf-module-k8s-secrets-3"
source = "../../modules/k8s-secrets"
providers = {
kubernetes = kubernetes.wbaas-3
}
Expand All @@ -12,6 +12,7 @@ module "wbaas-k8s-secrets" {
sql_password_api = random_password.sql-passwords["production-api"].result
sql_password_mediawiki_db_manager = random_password.sql-passwords["production-mediawiki-db-manager"].result
sql_password_backup_manager = random_password.sql-passwords["production-backup-manager"].result
sql_password_observer = random_password.sql-passwords["production-observer"].result
redis_password = random_password.redis-password.result
recaptcha_v3_site_key = var.recaptcha_v3_site_key
recaptcha_v3_secret = var.recaptcha_v3_secret
Expand Down
1 change: 1 addition & 0 deletions tf/env/production/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@ variable "sql-passwords" {
"production-api",
"production-mediawiki-db-manager",
"production-backup-manager",
"production-observer"
]
}

Expand Down
2 changes: 1 addition & 1 deletion tf/env/staging/kubernetes-secrets.tf
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
module "wbaas2-k8s-secrets" {
source = "../../modules-next/k8s-secrets"
source = "../../modules/k8s-secrets"
providers = {
kubernetes = kubernetes.wbaas-2
}
Expand Down
189 changes: 0 additions & 189 deletions tf/modules-next/k8s-secrets/main.tf

This file was deleted.

8 changes: 0 additions & 8 deletions tf/modules-next/k8s-secrets/providers.tf

This file was deleted.

116 changes: 0 additions & 116 deletions tf/modules-next/k8s-secrets/variables.tf

This file was deleted.

1 change: 1 addition & 0 deletions tf/modules/k8s-secrets/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,7 @@ resource "kubernetes_secret" "sql-secrets-init-passwords" {
"SQL_INIT_PASSWORD_API" = base64encode(var.sql_password_api)
"SQL_INIT_PASSWORD_MW" = base64encode(var.sql_password_mediawiki_db_manager)
"SQL_INIT_PASSWORD_BACKUPS" = base64encode(var.sql_password_backup_manager)
"SQL_INIT_OBSERVER" = base64encode(var.sql_password_observer)
}

}
Expand Down
5 changes: 5 additions & 0 deletions tf/modules/k8s-secrets/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,11 @@ variable "sql_password_backup_manager" {
sensitive = true
}

variable "sql_password_observer" {
type = string
sensitive = true
}

variable "redis_password" {
type = string
description = "redis password for staging cluster"
Expand Down