Skip to content

fix(k8s): remove plaintext backend Secret; wire External Secrets - #624

Open
woahwhattheheck wants to merge 5 commits into
Protocol-Guild:mainfrom
woahwhattheheck:type/payd-560-external-secrets
Open

woahwhattheheck wants to merge 5 commits into
Protocol-Guild:mainfrom
woahwhattheheck:type/payd-560-external-secrets

Conversation

@woahwhattheheck

Copy link
Copy Markdown

Closes #560

Removes the committed CHANGE_ME Kubernetes Secret from k8s/base/ and applies secrets through External Secrets Operator instead (secret-store.yaml + external-secret.yaml → AWS Secrets Manager). Missing provider/config leaves the ExternalSecret unready, so workloads that need payd-backend-secrets fail closed.

An examples-only manifest remains under k8s/examples/ for local kubectl create secret flows. Deployment and k8s README updated to match.

Verify: k8s/base/ has no Secret with stringData credentials; kustomization lists the ESO resources; docs describe the fail-closed path.

woahwhattheheck and others added 4 commits September 24, 2026 15:38
Stop applying CHANGE_ME credentials from git. Base now uses SecretStore +
ExternalSecret against AWS Secrets Manager so missing provider config fails
closed. Keep an examples/ reference for local kubectl create flows.
GitHub Actions does not accept retention-days as a workflow root key.
That made every push parse-fail with zero jobs. Artifact retention stays
on upload-artifact steps; repo retention stays in Settings.
GitHub rejects retention-days on the workflow root (Unexpected value),
so checks completed with 0 jobs. Keep artifact-level retention only.
GitHub Actions rejects retention-days at the workflow root, so these runs failed before any job started. Artifact retention stays on upload-artifact; repo run retention is a settings toggle.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix k8s Secret manifest with plaintext CHANGE_ME placeholders

1 participant