From 1572b3ce66dd877c9c4f6b08b9cf0403a19d976e Mon Sep 17 00:00:00 2001 From: keyhan Date: Thu, 2 Jul 2026 16:39:06 +0330 Subject: [PATCH] fix(chart): support existingSecret and provide CLUSTER_KUBECONFIG_KEY to backend Backend now fails production validation without CLUSTER_KUBECONFIG_KEY. Add cluster-kubeconfig-key to the chart secret and env, plus secrets.existingSecret so GitOps deployments can use a pre-created (sealed) Secret instead of the lookup/randAlphaNum template that churns under Argo CD's helm template rendering. Co-authored-by: Cursor --- .../helm/cloudhost-platform/templates/_helpers.tpl | 4 ++++ .../templates/backend-deployment.yaml | 5 +++++ .../helm/cloudhost-platform/templates/secret.yaml | 13 +++++++++++++ backend/helm/cloudhost-platform/values.yaml | 7 +++++++ 4 files changed, 29 insertions(+) diff --git a/backend/helm/cloudhost-platform/templates/_helpers.tpl b/backend/helm/cloudhost-platform/templates/_helpers.tpl index 298453c..0ad79c7 100644 --- a/backend/helm/cloudhost-platform/templates/_helpers.tpl +++ b/backend/helm/cloudhost-platform/templates/_helpers.tpl @@ -46,8 +46,12 @@ app.kubernetes.io/instance: {{ .Release.Name }} {{- end }} {{- define "cloudhost-platform.secretName" -}} +{{- if .Values.secrets.existingSecret }} +{{- .Values.secrets.existingSecret }} +{{- else }} {{- printf "%s-secrets" (include "cloudhost-platform.fullname" .) }} {{- end }} +{{- end }} {{- define "cloudhost-platform.tlsSecretName" -}} {{- if .Values.ingress.tls.secretName }} diff --git a/backend/helm/cloudhost-platform/templates/backend-deployment.yaml b/backend/helm/cloudhost-platform/templates/backend-deployment.yaml index c0b2bd0..78aa7cd 100644 --- a/backend/helm/cloudhost-platform/templates/backend-deployment.yaml +++ b/backend/helm/cloudhost-platform/templates/backend-deployment.yaml @@ -82,6 +82,11 @@ spec: secretKeyRef: name: {{ include "cloudhost-platform.secretName" . }} key: jwt-refresh-secret + - name: CLUSTER_KUBECONFIG_KEY + valueFrom: + secretKeyRef: + name: {{ include "cloudhost-platform.secretName" . }} + key: cluster-kubeconfig-key - name: FRONTEND_URL value: {{ include "cloudhost-platform.corsOrigins" . | quote }} {{- range $key, $val := .Values.backend.env }} diff --git a/backend/helm/cloudhost-platform/templates/secret.yaml b/backend/helm/cloudhost-platform/templates/secret.yaml index 91c7322..c760c6d 100644 --- a/backend/helm/cloudhost-platform/templates/secret.yaml +++ b/backend/helm/cloudhost-platform/templates/secret.yaml @@ -1,3 +1,10 @@ +{{- if not .Values.secrets.existingSecret }} +{{/* +NOTE: lookup only works with `helm install/upgrade` (CLI). Argo CD renders with +`helm template` where lookup is always empty, so values would be regenerated on +every sync. For GitOps deployments set secrets.existingSecret and manage the +Secret out-of-band (e.g. SealedSecret in the gitops repo). +*/}} {{- $existing := lookup "v1" "Secret" (include "cloudhost-platform.namespace" .) (include "cloudhost-platform.secretName" .) }} {{- $pgPass := .Values.postgres.password }} {{- if not $pgPass }} @@ -11,6 +18,10 @@ {{- if not $jwtRefresh }} {{- if $existing }}{{- $jwtRefresh = index $existing.data "jwt-refresh-secret" | b64dec }}{{- else }}{{- $jwtRefresh = randAlphaNum 32 }}{{- end }} {{- end }} +{{- $kubeconfigKey := .Values.secrets.clusterKubeconfigKey }} +{{- if not $kubeconfigKey }} +{{- if and $existing (hasKey $existing.data "cluster-kubeconfig-key") }}{{- $kubeconfigKey = index $existing.data "cluster-kubeconfig-key" | b64dec }}{{- else }}{{- $kubeconfigKey = randAlphaNum 32 }}{{- end }} +{{- end }} apiVersion: v1 kind: Secret metadata: @@ -23,3 +34,5 @@ stringData: postgres-password: {{ $pgPass | quote }} jwt-secret: {{ $jwt | quote }} jwt-refresh-secret: {{ $jwtRefresh | quote }} + cluster-kubeconfig-key: {{ $kubeconfigKey | quote }} +{{- end }} diff --git a/backend/helm/cloudhost-platform/values.yaml b/backend/helm/cloudhost-platform/values.yaml index 9c98cb1..2862bc2 100644 --- a/backend/helm/cloudhost-platform/values.yaml +++ b/backend/helm/cloudhost-platform/values.yaml @@ -77,8 +77,15 @@ frontend: # JWT secrets — set in production (values-production.example.yaml) secrets: + # Use a pre-created Secret instead of chart-managed one. Required for GitOps + # (Argo CD renders with `helm template`, so lookup/randAlphaNum regenerate on + # every sync). Secret must contain keys: postgres-password, jwt-secret, + # jwt-refresh-secret, cluster-kubeconfig-key. + existingSecret: "" jwtSecret: "" jwtRefreshSecret: "" + # AES key for encrypting stored kubeconfigs (64 hex chars or any passphrase) + clusterKubeconfigKey: "" ingress: enabled: true