Skip to content
This repository has been archived by the owner on May 3, 2023. It is now read-only.

Commit

Permalink
ci(vault): correct secrets path (#102)
Browse files Browse the repository at this point in the history
  • Loading branch information
annibalsilva authored Mar 15, 2023
1 parent 1af0366 commit daa0211
Showing 1 changed file with 12 additions and 16 deletions.
28 changes: 12 additions & 16 deletions .github/workflows/merge-main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -206,8 +206,7 @@ jobs:
- sonarcloud
- release
runs-on: ubuntu-latest
environment:
name: test
environment: test
env:
ZONE: test
NR_SPAR_ORACLE_API_VERSION: ${{ needs.release.outputs.version }}
Expand All @@ -220,17 +219,16 @@ jobs:
provision_role_id: ${{ secrets.PROVISION_ROLE_ID }}
project_name: spar
app_name: app-spar
environment: test
- name: Import Secrets
id: secrets
id: import-secrets
uses: hashicorp/vault-action@v2.5.0
with:
url: https://vault-iit.apps.silver.devops.gov.bc.ca
token: ${{ steps.broker.outputs.vault_token }}
exportEnv: 'false'
secrets: |
apps/data/test/spar/app-spar/db_proxy_read_only db_username | VAULT_DB_USER;
apps/data/test/spar/app-spar/db_proxy_read_only db_password | VAULT_DB_PASS;
apps/test/spar/app-spar/db_proxy_read_only db_username | VAULT_DB_USER;
apps/test/spar/app-spar/db_proxy_read_only db_password | VAULT_DB_PASS;
- uses: actions/checkout@v3
- name: Print NR_SPAR_ORACLE_API_VERSION env
Expand All @@ -247,8 +245,8 @@ jobs:
-p DATABASE_HOST=${{ secrets.DATABASE_HOST }} \
-p DATABASE_PORT=${{ secrets.DATABASE_PORT }} \
-p SERVICE_NAME=${{ secrets.SERVICE_NAME }} \
-p DATABASE_USER=${{ steps.secrets.outputs.VAULT_DB_USER }} \
-p DATABASE_PASSWORD=${{ steps.secrets.outputs.VAULT_DB_PASS }} \
-p DATABASE_USER=${{ steps.import-secrets.outputs.VAULT_DB_USER }} \
-p DATABASE_PASSWORD=${{ steps.import-secrets.outputs.VAULT_DB_PASS }} \
-p ALLOWED_ORIGINS=${{ secrets.ALLOWED_ORIGINS }} \
-p KEYCLOAK_REALM_URL=${{ secrets.KEYCLOAK_REALM_URL }} \
-p PROMOTE=${{ github.repository }}:${{ env.ZONE }}-service-api | oc apply -f -
Expand Down Expand Up @@ -396,8 +394,7 @@ jobs:
- trivy-repo
- release
runs-on: ubuntu-latest
environment:
name: prod
environment: prod
env:
ZONE: prod
PREV: test
Expand All @@ -421,17 +418,16 @@ jobs:
provision_role_id: ${{ secrets.PROVISION_ROLE_ID }}
project_name: spar
app_name: app-spar
environment: prod
- name: Import Secrets
id: secrets
id: import-secrets
uses: hashicorp/vault-action@v2.5.0
with:
url: https://vault-iit.apps.silver.devops.gov.bc.ca
token: ${{ steps.broker.outputs.vault_token }}
exportEnv: 'false'
secrets: |
apps/data/prod/spar/app-spar/db_proxy_read_only db_username | VAULT_DB_USER;
apps/data/prod/spar/app-spar/db_proxy_read_only db_password | VAULT_DB_PASS;
apps/prod/spar/app-spar/db_proxy_read_only db_username | VAULT_DB_USER;
apps/prod/spar/app-spar/db_proxy_read_only db_password | VAULT_DB_PASS;
- uses: actions/checkout@v3
- name: Print NR_SPAR_ORACLE_API_VERSION env
Expand All @@ -454,8 +450,8 @@ jobs:
-p DATABASE_HOST=${{ secrets.DATABASE_HOST }} \
-p DATABASE_PORT=${{ secrets.DATABASE_PORT }} \
-p SERVICE_NAME=${{ secrets.SERVICE_NAME }} \
-p DATABASE_USER=${{ steps.secrets.outputs.VAULT_DB_USER }} \
-p DATABASE_PASSWORD=${{ steps.secrets.outputs.VAULT_DB_PASS }} \
-p DATABASE_USER=${{ steps.import-secrets.outputs.VAULT_DB_USER }} \
-p DATABASE_PASSWORD=${{ steps.import-secrets.outputs.VAULT_DB_PASS }} \
-p ALLOWED_ORIGINS=${{ secrets.ALLOWED_ORIGINS }} \
-p KEYCLOAK_REALM_URL=${{ secrets.KEYCLOAK_REALM_URL }} \
-p PROMOTE=${{ github.repository }}:${{ env.PREV }}-service-api | oc apply -f -
Expand Down

0 comments on commit daa0211

Please sign in to comment.