GKE: register Vault as an Application
Fresh install, unlike the homelab's adoption of a running Vault, so there is no live state to diff against. nameOverride pins the release to "vault" in namespace "vault" because Terraform's Workload Identity binding names that exact pair; a different release name renames the service account and leaves Vault sealed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
This commit is contained in:
co-authored by
Claude Opus 5
parent
3a16433e37
commit
a3429adf2c
@@ -51,6 +51,17 @@ appSpec:
|
||||
# Contour's HTTPProxy CRD embeds a large schema, same 256KiB
|
||||
# last-applied-configuration problem as cert-manager's.
|
||||
serverSideApply: true
|
||||
- name: vault
|
||||
# Fresh install here, unlike the homelab's adoption of a running Vault.
|
||||
# nameOverride pinned so the release is "vault" in namespace "vault":
|
||||
# the Workload Identity binding Terraform created names that exact
|
||||
# namespace/serviceaccount pair, and a different release name renames
|
||||
# the service account, which leaves Vault unable to reach KMS and
|
||||
# therefore sealed.
|
||||
nameOverride: vault
|
||||
namespace: vault
|
||||
chartDir: vault
|
||||
valuesDir: vault
|
||||
- name: cert-manager
|
||||
nameOverride: cert-manager
|
||||
namespace: cert-manager
|
||||
|
||||
Reference in New Issue
Block a user