--- # Same idempotent secret-bootstrap pattern as home's # infrastructure/authentik/manifests/presync-job.yaml, scoped to a # dedicated ServiceAccount here (no shared argocd-hook-sa exists on the # vps-standby cluster the way it does at home). apiVersion: v1 kind: ServiceAccount metadata: name: authentik-hook namespace: authentik --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: authentik-hook namespace: authentik rules: - apiGroups: [""] resources: ["secrets"] verbs: ["get", "create"] - apiGroups: ["postgresql.cnpg.io"] resources: ["clusters"] verbs: ["get"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: authentik-hook namespace: authentik subjects: - kind: ServiceAccount name: authentik-hook namespace: authentik roleRef: kind: Role name: authentik-hook apiGroup: rbac.authorization.k8s.io --- apiVersion: batch/v1 kind: Job metadata: name: authentik-presync namespace: authentik annotations: argocd.argoproj.io/hook: PreSync argocd.argoproj.io/hook-delete-policy: BeforeHookCreation spec: backoffLimit: 3 template: spec: serviceAccountName: authentik-hook restartPolicy: Never securityContext: runAsNonRoot: true runAsUser: 65534 seccompProfile: type: RuntimeDefault containers: - name: presync image: alpine/k8s:1.32.13 securityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"] command: - /bin/bash - -c - | set -euo pipefail echo "=== Authentik (VPS) PreSync ===" # NOTE: does NOT wait for pg-authentik to be "Healthy" the way # home's presync-job does - a replica cluster in continuous # recovery never reports Healthy in that sense (it's # perpetually catching up / read-only), and server/worker are # at replicas: 0 anyway so nothing actually needs the DB yet. if ! kubectl -n authentik get secret authentik >/dev/null 2>&1; then echo "Creating authentik secret (literal env:// placeholder -" echo "matches home's values.yaml exactly, see values.yaml comment)..." kubectl -n authentik create secret generic authentik \ --from-literal=AUTHENTIK_SECRET_KEY="env://AUTHENTIK_SECRET_KEY" else echo "authentik secret already exists" fi echo "=== Done ==="