This is the repo that contains all the deployments for ABC projects. This is seperate from their respective repositories to prevent a cyclic problem in CI/CD. We can release new images of the software, and seperately change the config here to accomodate that release. This repository is open source for transparency, not specifically for contributions from outside the ABC. But you are always welcome to open a PR.
There is a folder for each project that the ABC deploys, the teamlead of each project is also the codeowner of that folder. That means that everybody can submit PRs, but only code owners can approve those PRs. The owner of the full project is the ABC Chair/Secr, for meta information.
Each project is free to choose the way they implement, as the size and requirement of each project differs drastically. They will all be sourced from the k8-apps repo. If you want to add a project, you can open a PR there to have it added.
Secrets must be pushed as well, but can (or well should) be encrypted using kubeseal. You can seal them as follows:
-
Fetch the kubeseal public cert (requires GEWIS network access):
curl -s https://sealed-secrets.gewis.nl/v1/cert.pem > ../cert.pem -
Copy a template and fill in real values:
cp env.production.template.yaml env.prod.yaml # Edit env.production.yaml with real values -
Seal the secret:
kubeseal --cert ../cert.pem \ --format yaml \ --scope namespace-wide \ < env.production.yaml \ > /path/to/sealed-backend-env.yaml
-
Delete the plaintext file:
rm backend-env.production.yaml
-
The sealed secret in
path/to/sealed-backend-env.yamlis safe to commit.
Everything that cannot be configured here, can be requested at the CBC.