Skip to content

Commit 3b5b5fc

Browse files
committed
refactor: move OPENSHIFT_TOKEN management to ArgoCD PostSync job
- Remove openshift_token from Terraform-managed secrets - Token will now be synced by ci-token-sync Job in kustomize-cluster - Enables automatic token refresh on cluster recreation
1 parent ac111af commit 3b5b5fc

File tree

2 files changed

+35
-41
lines changed

2 files changed

+35
-41
lines changed

main.tf

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -97,14 +97,9 @@ locals {
9797
"kustomize-cluster"
9898
]
9999
}
100-
"openshift_token" = {
101-
name = "OPENSHIFT_TOKEN"
102-
value = data.sops_file.secret_vars.data["openshift_token"]
103-
repositories = [
104-
"images",
105-
"kustomize-cluster"
106-
]
107-
}
100+
# NOTE: OPENSHIFT_TOKEN is managed by ArgoCD PostSync job (ci-token-sync)
101+
# in kustomize-cluster, not Terraform. This allows automatic token refresh
102+
# when the cluster is recreated.
108103
"sops_age_key" = {
109104
name = "SOPS_AGE_KEY"
110105
value = data.sops_file.secret_vars.data["sops_age_key"]

0 commit comments

Comments
 (0)