forked from pixie-io/pixie
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathload_cloud_secrets.sh
executable file
·56 lines (48 loc) · 1.69 KB
/
load_cloud_secrets.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
#!/usr/bin/env bash
# Copyright 2018- The Pixie Authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# SPDX-License-Identifier: Apache-2.0
set -e
if [ "$#" -ne 2 ]; then
echo "This script requires exactly two argument: <namespace> <secret type : dev, prod, etc.>"
fi
namespace=$1
secret_type=$2
workspace=$(bazel info workspace 2> /dev/null)
credentials_path=${workspace}/private/credentials/k8s/${secret_type}
monitoring_path=${workspace}/private/credentials/k8s/monitoring/${secret_type}
if [ ! -d "${credentials_path}" ]; then
echo "Credentials path \"${credentials_path}\" does not exist. Did you slect the right secret type?"
exit 1
fi
shopt -s nullglob
# Apply configs.
for yaml in "${credentials_path}"/configs/*.yaml; do
echo "Loading: ${yaml}"
sops --decrypt "${yaml}" | kubectl apply -n "${namespace}" -f -
done
# Apply secrets.
for yaml in "${credentials_path}"/*.yaml; do
echo "Loading: ${yaml}"
sops --decrypt "${yaml}" | kubectl apply -n "${namespace}" -f -
done
if [ ! -d "${monitoring_path}" ]; then
exit 0
fi
# Apply monitoring secrets.
for yaml in "${monitoring_path}"/*.yaml; do
echo "Loading: ${yaml}"
sops --decrypt "${yaml}" | kubectl apply -n "${namespace}-monitoring" -f -
done