-
Notifications
You must be signed in to change notification settings - Fork 854
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
prow: switch cncf-ci-github-token to ExternalSecret #2219
Merged
k8s-ci-robot
merged 5 commits into
kubernetes:main
from
spiffxp:external-secrets-audit-token
Jun 15, 2021
Merged
prow: switch cncf-ci-github-token to ExternalSecret #2219
k8s-ci-robot
merged 5 commits into
kubernetes:main
from
spiffxp:external-secrets-audit-token
Jun 15, 2021
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: spiffxp The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
specifically cncf-ci-github-token in test-pods namespace
70b9a2c
to
b6e92b6
Compare
30 tasks
Migrating secrets ref: #2220 |
/lgtm |
This was referenced Jun 15, 2021
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
approved
Indicates a PR has been approved by an approver from all required OWNERS files.
area/audit
Audit of project resources, audit followup issues, code in audit/
area/prow
Setting up or working with prow in general, prow.k8s.io, prow build clusters
area/terraform
Terraform modules, testing them, writing more of them, code in infra/gcp/clusters/
cncf-cla: yes
Indicates the PR's author has signed the CNCF CLA.
lgtm
"Looks good to me", indicates that a PR is ready to be merged.
sig/testing
Categorizes an issue or PR as relevant to SIG Testing.
size/M
Denotes a PR that changes 30-99 lines, ignoring generated files.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Migrate the cncf-ci-github-token Kubernetes
Secret
used by the ci-k8sio-audit job to anExternalSecret
.This let me uncover a few things:
prow-build-trusted
setup the same way asprow-build
for accesskubernetes-external-secrets
service account setup{namespace}-{resource}.yaml
convention forserviceaccounts
andexternalsecrets
Everything here has already been deployed
I exercised by changing the secret value to "monkeys" and seeing the change reflected in-cluster, before changing back.