Files
fedora-infra_ansible/roles/openshift-apps/waiverdb/templates/secret.yml.j2
Ryan Lerch 7086cf3d19 waiverdb - rename yml templates to .j2
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2025-01-14 08:37:30 +10:00

31 lines
1.1 KiB
Django/Jinja

---
apiVersion: v1
kind: Secret
metadata:
name: "waiverdb-secret"
labels:
app: "waiverdb"
stringData:
{% if env == 'staging' %}
flask-secret-key: "{{stg_waiverdb_secret_key}}"
database-password: "{{stg_waiverdb_db_password}}"
{% else %}
flask-secret-key: "{{prod_waiverdb_secret_key}}"
database-password: "{{prod_waiverdb_db_password}}"
{% endif %}
client_secrets.json: |-
{"web": {
"issuer": "https://id{{ env_suffix }}.fedoraproject.org/openidc/",
"redirect_uris": ["{{ waiverdb_oidc_overwrite_redirect_uri }}"],
"token_uri": "https://id{{ env_suffix }}.fedoraproject.org/openidc/Token",
"auth_uri": "https://id{{ env_suffix }}.fedoraproject.org/openidc/Authorization",
{% if env == 'staging' %}
"client_id": "waiverdb-stg",
"client_secret": "{{ stg_waiverdb_oidc_secret }}",
{% else %}
"client_id": "waiverdb",
"client_secret": "{{ prod_waiverdb_oidc_secret }}",
{% endif %}
"userinfo_uri": "https://id{{ env_suffix }}.fedoraproject.org/openidc/UserInfo",
"token_introspection_uri": "https://id{{ env_suffix }}.fedoraproject.org/openidc/TokenInfo"}}