Add grafana appSpec entry and its admin-credentials ExternalSecret

Matches the chart-side addition in devops-infra-helm-charts. The
ExternalSecret needs its Vault path populated before either this or
the grafana Application syncs — see that file's own header for the
exact vault kv put command, same requirement postgres and every other
admin credential in this repo already has.

app-of-secretstores.yaml is automated (prune: true), so this new
secretstore file needs no separate manual sync of its own — only that
app-of-apps wrapper, same as any other new file under secretstores/.

Verified with `helm template` against generic-argo-apps-chart and this
values file: 12 Applications render, grafana present and correctly
formed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Wajog7nELA3i8JWTjxYGHF
This commit is contained in:
Mukul Sharma
2026-09-06 08:57:42 +05:30
co-authored by Claude Opus 5
parent 919ebd5ab8
commit cab110c268
2 changed files with 59 additions and 1 deletions
@@ -0,0 +1,41 @@
# Grafana's admin login, from Vault — same pattern as every other admin
# credential in this repo (gitea-admin-credentials, harbor-admin-credentials,
# jenkins-admin-credentials).
#
# Put the credential in Vault BEFORE syncing this. External Secrets cannot
# create a Secret for a path that does not exist, and Grafana will start with
# a randomly-generated admin password nobody has if this Secret is missing
# when it first boots (the chart's own fallback, not a failure to start —
# worth knowing so a missing Secret doesn't look like a crash):
#
# kubectl -n vault exec -i vault-0 -- sh -lc '
# vault login <root-token> >/dev/null &&
# vault kv put secret/grafana/admin \
# username=admin \
# password=<a long alphanumeric password>'
#
# Remember that `kubectl exec` into Vault is unauthenticated by default —
# without the `vault login` the commands fail with a "preflight capability
# check" error that reads like a permissions bug rather than a missing login.
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: grafana-admin-credentials
namespace: monitoring
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-backend
kind: ClusterSecretStore
target:
name: grafana-admin-credentials
creationPolicy: Owner
data:
- secretKey: username
remoteRef:
key: grafana/admin
property: username
- secretKey: password
remoteRef:
key: grafana/admin
property: password