Skip to content

Dev#111

Open
ProjectInitiative wants to merge 15 commits into
mainfrom
dev
Open

Dev#111
ProjectInitiative wants to merge 15 commits into
mainfrom
dev

Conversation

@ProjectInitiative

Copy link
Copy Markdown
Owner

No description provided.

@github-actions

Copy link
Copy Markdown

Manifest Changes Detected

Click to expand diff
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-10 04:15:18.724539657 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-10 04:15:32.352738743 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_cc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-argo.yaml
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-kubevirt.yaml
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-10 04:15:18.723539644 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-10 04:15:32.351738728 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_mc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-10 04:15:18.723539644 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-10 04:15:32.351738728 +0000
@@ -31,9 +31,70 @@
   - path: bootstrap/base/openbao/config
     repoURL: https://github.com/projectinitiative/homelab.git
     targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultAuth
+          metadata:
+            name: placeholder-auth
+            namespace: openbao
+          spec:
+            kubernetes:
+              audiences:
+              - vault
+              role: openbao-secrets-operator
+              serviceAccount: operator-auth-sa
+            method: kubernetes
+            mount: kubernetes_cluster_mc
+            namespace: production
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth"}]'
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth-sa"}]'
+        target:
+          kind: ServiceAccount
+          name: placeholder-sa
+    path: bootstrap/base/common/vault-resources/auth
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultStaticSecret
+          metadata:
+            name: placeholder-secret
+            namespace: openbao
+          spec:
+            destination:
+              create: true
+              name: openbao-snapshot-s3
+            mount: k8s
+            namespace: production
+            path: openbao-snapshot/s3
+            type: kv-v2
+            vaultAuthRef: operator-auth
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "openbao-snapshot-s3"}]'
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+    path: bootstrap/base/common/vault-resources/secret
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
   syncPolicy:
     automated:
       prune: true
       selfHeal: true
+    managedNamespaceMetadata:
+      labels:
+        vault-auth: enabled
     syncOptions:
     - CreateNamespace=true

@github-actions

Copy link
Copy Markdown

Manifest Changes Detected

Click to expand diff
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-11 03:46:34.872549047 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-11 03:46:47.719430174 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_cc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-argo.yaml
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-kubevirt.yaml
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-11 03:46:34.871549056 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-11 03:46:47.718430184 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_mc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-11 03:46:34.872549047 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-11 03:46:47.718430184 +0000
@@ -31,9 +31,70 @@
   - path: bootstrap/base/openbao/config
     repoURL: https://github.com/projectinitiative/homelab.git
     targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultAuth
+          metadata:
+            name: placeholder-auth
+            namespace: openbao
+          spec:
+            kubernetes:
+              audiences:
+              - vault
+              role: openbao-secrets-operator
+              serviceAccount: operator-auth-sa
+            method: kubernetes
+            mount: kubernetes_cluster_mc
+            namespace: production
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth"}]'
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth-sa"}]'
+        target:
+          kind: ServiceAccount
+          name: placeholder-sa
+    path: bootstrap/base/common/vault-resources/auth
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultStaticSecret
+          metadata:
+            name: placeholder-secret
+            namespace: openbao
+          spec:
+            destination:
+              create: true
+              name: openbao-snapshot-s3
+            mount: k8s
+            namespace: production
+            path: openbao-snapshot/s3
+            type: kv-v2
+            vaultAuthRef: operator-auth
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "openbao-snapshot-s3"}]'
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+    path: bootstrap/base/common/vault-resources/secret
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
   syncPolicy:
     automated:
       prune: true
       selfHeal: true
+    managedNamespaceMetadata:
+      labels:
+        vault-auth: enabled
     syncOptions:
     - CreateNamespace=true

@github-actions

Copy link
Copy Markdown

Manifest Changes Detected

Click to expand diff
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-16 01:24:13.590860178 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-16 01:24:26.570887130 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_cc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-argo.yaml
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-kubevirt.yaml
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-16 01:24:13.590860178 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-16 01:24:26.569887128 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_mc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-16 01:24:13.590860178 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-16 01:24:26.569887128 +0000
@@ -31,9 +31,70 @@
   - path: bootstrap/base/openbao/config
     repoURL: https://github.com/projectinitiative/homelab.git
     targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultAuth
+          metadata:
+            name: placeholder-auth
+            namespace: openbao
+          spec:
+            kubernetes:
+              audiences:
+              - vault
+              role: openbao-secrets-operator
+              serviceAccount: operator-auth-sa
+            method: kubernetes
+            mount: kubernetes_cluster_mc
+            namespace: production
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth"}]'
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth-sa"}]'
+        target:
+          kind: ServiceAccount
+          name: placeholder-sa
+    path: bootstrap/base/common/vault-resources/auth
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultStaticSecret
+          metadata:
+            name: placeholder-secret
+            namespace: openbao
+          spec:
+            destination:
+              create: true
+              name: openbao-snapshot-s3
+            mount: k8s
+            namespace: production
+            path: openbao-snapshot/s3
+            type: kv-v2
+            vaultAuthRef: operator-auth
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "openbao-snapshot-s3"}]'
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+    path: bootstrap/base/common/vault-resources/secret
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
   syncPolicy:
     automated:
       prune: true
       selfHeal: true
+    managedNamespaceMetadata:
+      labels:
+        vault-auth: enabled
     syncOptions:
     - CreateNamespace=true

@github-actions

Copy link
Copy Markdown

Manifest Changes Detected

Click to expand diff
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-16 01:34:16.995143006 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-16 01:34:30.949173352 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_cc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-argo.yaml
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-kubevirt.yaml
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-16 01:34:16.994143004 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-16 01:34:30.948173350 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_mc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-16 01:34:16.994143004 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-16 01:34:30.948173350 +0000
@@ -31,9 +31,70 @@
   - path: bootstrap/base/openbao/config
     repoURL: https://github.com/projectinitiative/homelab.git
     targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultAuth
+          metadata:
+            name: placeholder-auth
+            namespace: openbao
+          spec:
+            kubernetes:
+              audiences:
+              - vault
+              role: openbao-secrets-operator
+              serviceAccount: operator-auth-sa
+            method: kubernetes
+            mount: kubernetes_cluster_mc
+            namespace: production
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth"}]'
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth-sa"}]'
+        target:
+          kind: ServiceAccount
+          name: placeholder-sa
+    path: bootstrap/base/common/vault-resources/auth
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultStaticSecret
+          metadata:
+            name: placeholder-secret
+            namespace: openbao
+          spec:
+            destination:
+              create: true
+              name: openbao-snapshot-s3
+            mount: k8s
+            namespace: production
+            path: openbao-snapshot/s3
+            type: kv-v2
+            vaultAuthRef: operator-auth
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "openbao-snapshot-s3"}]'
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+    path: bootstrap/base/common/vault-resources/secret
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
   syncPolicy:
     automated:
       prune: true
       selfHeal: true
+    managedNamespaceMetadata:
+      labels:
+        vault-auth: enabled
     syncOptions:
     - CreateNamespace=true

@github-actions

Copy link
Copy Markdown

Manifest Changes Detected

Click to expand diff
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-16 02:13:55.061637029 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-16 02:14:08.468508252 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_cc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-argo.yaml
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-kubevirt.yaml
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-16 02:13:55.061637029 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-16 02:14:08.467508262 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_mc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-16 02:13:55.060637038 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-16 02:14:08.467508262 +0000
@@ -31,9 +31,70 @@
   - path: bootstrap/base/openbao/config
     repoURL: https://github.com/projectinitiative/homelab.git
     targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultAuth
+          metadata:
+            name: placeholder-auth
+            namespace: openbao
+          spec:
+            kubernetes:
+              audiences:
+              - vault
+              role: openbao-secrets-operator
+              serviceAccount: operator-auth-sa
+            method: kubernetes
+            mount: kubernetes_cluster_mc
+            namespace: production
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth"}]'
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth-sa"}]'
+        target:
+          kind: ServiceAccount
+          name: placeholder-sa
+    path: bootstrap/base/common/vault-resources/auth
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultStaticSecret
+          metadata:
+            name: placeholder-secret
+            namespace: openbao
+          spec:
+            destination:
+              create: true
+              name: openbao-snapshot-s3
+            mount: k8s
+            namespace: production
+            path: openbao-snapshot/s3
+            type: kv-v2
+            vaultAuthRef: operator-auth
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "openbao-snapshot-s3"}]'
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+    path: bootstrap/base/common/vault-resources/secret
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
   syncPolicy:
     automated:
       prune: true
       selfHeal: true
+    managedNamespaceMetadata:
+      labels:
+        vault-auth: enabled
     syncOptions:
     - CreateNamespace=true

…t on lighthouse nodes, vsftpd with rclone FUSE
@github-actions

Copy link
Copy Markdown

Manifest Changes Detected

Click to expand diff
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-17 21:41:44.093180038 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-cc-openbao-secrets-operator.yaml	2026-06-17 21:41:58.987075363 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_cc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-argo.yaml
Only in manifests-pr/1-manifest: argoproj.io_v1alpha1-application-argocd-mc-kubevirt.yaml
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-17 21:41:44.091180053 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao-secrets-operator.yaml	2026-06-17 21:41:58.987075363 +0000
@@ -20,8 +20,8 @@
             path: kubernetes_cluster_mc
             role: openbao-secrets-operator
     path: chart
-    repoURL: https://github.com/openbao/openbao-secrets-operator.git
-    targetRevision: main
+    repoURL: https://github.com/hashicorp/vault-secrets-operator.git
+    targetRevision: v1.4.0
   syncPolicy:
     automated:
       prune: true
diff -r -u manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml
--- manifests-main/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-17 21:41:44.091180053 +0000
+++ manifests-pr/1-manifest/argoproj.io_v1alpha1-application-argocd-mc-openbao.yaml	2026-06-17 21:41:58.986075370 +0000
@@ -31,9 +31,70 @@
   - path: bootstrap/base/openbao/config
     repoURL: https://github.com/projectinitiative/homelab.git
     targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultAuth
+          metadata:
+            name: placeholder-auth
+            namespace: openbao
+          spec:
+            kubernetes:
+              audiences:
+              - vault
+              role: openbao-secrets-operator
+              serviceAccount: operator-auth-sa
+            method: kubernetes
+            mount: kubernetes_cluster_mc
+            namespace: production
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth"}]'
+        target:
+          kind: VaultAuth
+          name: placeholder-auth
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "operator-auth-sa"}]'
+        target:
+          kind: ServiceAccount
+          name: placeholder-sa
+    path: bootstrap/base/common/vault-resources/auth
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
+  - kustomize:
+      patches:
+      - patch: |
+          apiVersion: secrets.hashicorp.com/v1beta1
+          kind: VaultStaticSecret
+          metadata:
+            name: placeholder-secret
+            namespace: openbao
+          spec:
+            destination:
+              create: true
+              name: openbao-snapshot-s3
+            mount: k8s
+            namespace: production
+            path: openbao-snapshot/s3
+            type: kv-v2
+            vaultAuthRef: operator-auth
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+      - patch: '[{"op": "replace", "path": "/metadata/name", "value": "openbao-snapshot-s3"}]'
+        target:
+          kind: VaultStaticSecret
+          name: placeholder-secret
+    path: bootstrap/base/common/vault-resources/secret
+    repoURL: https://github.com/projectinitiative/homelab.git
+    targetRevision: HEAD
   syncPolicy:
     automated:
       prune: true
       selfHeal: true
+    managedNamespaceMetadata:
+      labels:
+        vault-auth: enabled
     syncOptions:
     - CreateNamespace=true

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant