grafana(host): move secrets to SOPS
Some checks failed
/ Ansible Lint (push) Failing after 1m49s

This commit is contained in:
June 2025-05-03 22:18:26 +02:00
commit 97b8386878
Signed by: june
SSH key fingerprint: SHA256:o9EAq4Y9N9K0pBQeBTqhSDrND5E7oB+60ZNx0U1yPe0
8 changed files with 269 additions and 9 deletions

View file

@ -11,7 +11,7 @@ auto_login = true
name = id.hamburg.ccc.de
allow_sign_up = true
client_id = grafana
client_secret = {{ lookup("community.general.passwordstore", "noc/vm-secrets/chaosknoten/grafana/KEYCLOAK_SECRET", create=false, missing="error") }}
client_secret = {{ lookup("community.sops.sops", "resources/chaosknoten/grafana/secrets.yaml", extract="['KEYCLOAK_SECRET']") }}
scopes = openid email profile offline_access roles
email_attribute_path = email
login_attribute_path = username