Add grafana appSpec entry and its admin-credentials ExternalSecret

Matches the chart-side addition in devops-infra-helm-charts. The
ExternalSecret needs its Vault path populated before either this or
the grafana Application syncs — see that file's own header for the
exact vault kv put command, same requirement postgres and every other
admin credential in this repo already has.

app-of-secretstores.yaml is automated (prune: true), so this new
secretstore file needs no separate manual sync of its own — only that
app-of-apps wrapper, same as any other new file under secretstores/.

Verified with `helm template` against generic-argo-apps-chart and this
values file: 12 Applications render, grafana present and correctly
formed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Wajog7nELA3i8JWTjxYGHF
This commit is contained in:
Mukul Sharma
2026-09-06 08:57:42 +05:30
co-authored by Claude Opus 5
parent 919ebd5ab8
commit cab110c268
2 changed files with 59 additions and 1 deletions
@@ -0,0 +1,41 @@
# Grafana's admin login, from Vault — same pattern as every other admin
# credential in this repo (gitea-admin-credentials, harbor-admin-credentials,
# jenkins-admin-credentials).
#
# Put the credential in Vault BEFORE syncing this. External Secrets cannot
# create a Secret for a path that does not exist, and Grafana will start with
# a randomly-generated admin password nobody has if this Secret is missing
# when it first boots (the chart's own fallback, not a failure to start —
# worth knowing so a missing Secret doesn't look like a crash):
#
# kubectl -n vault exec -i vault-0 -- sh -lc '
# vault login <root-token> >/dev/null &&
# vault kv put secret/grafana/admin \
# username=admin \
# password=<a long alphanumeric password>'
#
# Remember that `kubectl exec` into Vault is unauthenticated by default —
# without the `vault login` the commands fail with a "preflight capability
# check" error that reads like a permissions bug rather than a missing login.
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: grafana-admin-credentials
namespace: monitoring
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-backend
kind: ClusterSecretStore
target:
name: grafana-admin-credentials
creationPolicy: Owner
data:
- secretKey: username
remoteRef:
key: grafana/admin
property: username
- secretKey: password
remoteRef:
key: grafana/admin
property: password
@@ -177,3 +177,20 @@ appSpec:
namespace: monitoring namespace: monitoring
chartDir: node-exporter chartDir: node-exporter
valuesDir: node-exporter valuesDir: node-exporter
- name: grafana
# Dashboards over VictoriaMetrics — see that chart for why "type:
# prometheus" is correct for a VictoriaMetrics URL. This directory
# already held a fully-vendored old Grafana chart (v6.58.7) from the
# original Meesho monorepo import with generic production config
# (fullnameOverride: grafana-infra-prd) — removed and re-vendored
# fresh as a thin wrapper, same treatment as victoria-metrics-single.
#
# Requires secretstores/grafana-admin-credentials.yaml to have synced
# first — the pod falls back to a randomly-generated admin password
# nobody has if that Secret does not exist yet when it boots (not a
# crash, just an inaccessible login until the Secret exists and the
# pod restarts).
nameOverride: grafana
namespace: monitoring
chartDir: grafana
valuesDir: grafana