* feat(helm): add existingSecret support Allow users to reference a pre-existing Kubernetes Secret instead of having the chart create one. This enables better secret management through tools like External Secrets Operator or sealed-secrets. Usage: ```yaml existingSecret: "my-pre-created-secret" ``` When existingSecret is set: - The chart skips creating its own Secret resource - Deployments reference the provided secret name - Secret checksum annotation is omitted (no auto-rollout on changes) The existing secret should contain all required keys: - API secrets (e.g., HINDSIGHT_API_LLM_API_KEY) - Control plane secrets - postgres-password (if using external PostgreSQL) * fix(helm): use envFrom for existingSecret and fix env var ordering - Add envFrom to inject all keys from existingSecret as env vars automatically - Fix POSTGRES_PASSWORD ordering (must be before DATABASE_URL for $(VAR) interpolation) - Only use api.secrets/controlPlane.secrets when existingSecret is not set - Update values.yaml documentation for existingSecret usage --------- Co-authored-by: Anatolii Lapytskyi <ala@herobase.com> |
||
|---|---|---|
| .. | ||
| _helpers.tpl | ||
| api-deployment.yaml | ||
| api-service.yaml | ||
| controlplane-deployment.yaml | ||
| controlplane-service.yaml | ||
| hpa.yaml | ||
| ingress.yaml | ||
| NOTES.txt | ||
| postgresql-service.yaml | ||
| postgresql-statefulset.yaml | ||
| secret.yaml | ||
| serviceaccount.yaml | ||