Skip to content

Commit 018ae37

Browse files
authored
fix: avoid hardcoding private key in config (#200)
1 parent 265a91d commit 018ae37

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

pkg/controllers/wireguard_controller.go

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -196,9 +196,9 @@ func (r *WireguardReconciler) updateWireguardPeers(ctx context.Context, req ctrl
196196
newConfig := fmt.Sprintf(`
197197
echo "
198198
[Interface]
199-
PrivateKey = $(kubectl get secret %s-peer --template={{.data.privateKey}} -n %s | base64 -d)
199+
PrivateKey = $(kubectl get secret %s --template={{.data.%s}} -n %s | base64 -d)
200200
Address = %s
201-
DNS = %s`, peer.Name, peer.Namespace, peer.Spec.Address, dnsConfiguration)
201+
DNS = %s`, peer.Spec.PrivateKey.SecretKeyRef.Name, peer.Spec.PrivateKey.SecretKeyRef.Key, peer.Namespace, peer.Spec.Address, dnsConfiguration)
202202

203203
if serverMtu != "" {
204204
newConfig = newConfig + "\nMTU = " + serverMtu

0 commit comments

Comments
 (0)