fix(chart): support existingSecret and provide CLUSTER_KUBECONFIG_KEY to backend
Build and Deploy Platform / build-and-deploy (push) Failing after 50m25s

Backend now fails production validation without CLUSTER_KUBECONFIG_KEY.
Add cluster-kubeconfig-key to the chart secret and env, plus
secrets.existingSecret so GitOps deployments can use a pre-created
(sealed) Secret instead of the lookup/randAlphaNum template that churns
under Argo CD's helm template rendering.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
keyhan
2026-07-02 16:39:06 +03:30
parent abfe858909
commit 1572b3ce66
4 changed files with 29 additions and 0 deletions
@@ -1,3 +1,10 @@
{{- if not .Values.secrets.existingSecret }}
{{/*
NOTE: lookup only works with `helm install/upgrade` (CLI). Argo CD renders with
`helm template` where lookup is always empty, so values would be regenerated on
every sync. For GitOps deployments set secrets.existingSecret and manage the
Secret out-of-band (e.g. SealedSecret in the gitops repo).
*/}}
{{- $existing := lookup "v1" "Secret" (include "cloudhost-platform.namespace" .) (include "cloudhost-platform.secretName" .) }}
{{- $pgPass := .Values.postgres.password }}
{{- if not $pgPass }}
@@ -11,6 +18,10 @@
{{- if not $jwtRefresh }}
{{- if $existing }}{{- $jwtRefresh = index $existing.data "jwt-refresh-secret" | b64dec }}{{- else }}{{- $jwtRefresh = randAlphaNum 32 }}{{- end }}
{{- end }}
{{- $kubeconfigKey := .Values.secrets.clusterKubeconfigKey }}
{{- if not $kubeconfigKey }}
{{- if and $existing (hasKey $existing.data "cluster-kubeconfig-key") }}{{- $kubeconfigKey = index $existing.data "cluster-kubeconfig-key" | b64dec }}{{- else }}{{- $kubeconfigKey = randAlphaNum 32 }}{{- end }}
{{- end }}
apiVersion: v1
kind: Secret
metadata:
@@ -23,3 +34,5 @@ stringData:
postgres-password: {{ $pgPass | quote }}
jwt-secret: {{ $jwt | quote }}
jwt-refresh-secret: {{ $jwtRefresh | quote }}
cluster-kubeconfig-key: {{ $kubeconfigKey | quote }}
{{- end }}