Skip to content

feat: load cookie_secret from external-secrets - #19

Open
siryur wants to merge 2 commits into
pgdogdev:mainfrom
siryur:feat/cookie-secret-external-secrets
Open

feat: load cookie_secret from external-secrets#19
siryur wants to merge 2 commits into
pgdogdev:mainfrom
siryur:feat/cookie-secret-external-secrets

Conversation

@siryur

@siryur siryur commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

cookie_secret previously had two sources: an inline value in control.config.auth, or a random key the chart generates and reuses via a lookup call. Neither let users manage the value through the external-secrets operator, which pgdogdev/helm already supports for its own secrets via templates/externalsecret.yaml.

Add control.externalSecrets, mirroring that chart's block, plus a templates/externalsecret.yaml that renders an ExternalSecret when enabled. Its target Secret name is shared with the chart's existing lookup-based cookie_secret resolution (in secrets.yaml and configmap.yaml), so a synced cookie_secret key flows into control.toml exactly like the auto-generated case does, and the chart skips generating its own random secret to avoid ownership conflicts with the ExternalSecret.

Fix #18

siryur added 2 commits August 18, 2026 14:03
cookie_secret previously had two sources: an inline value in
control.config.auth, or a random key the chart generates and reuses
via a lookup call. Neither let users manage the value through the
external-secrets operator, which pgdogdev/helm already supports for
its own secrets via templates/externalsecret.yaml.

Add control.externalSecrets, mirroring that chart's block, plus a
templates/externalsecret.yaml that renders an ExternalSecret when
enabled. Its target Secret name is shared with the chart's existing
lookup-based cookie_secret resolution (in secrets.yaml and
configmap.yaml), so a synced cookie_secret key flows into
control.toml exactly like the auto-generated case does, and the
chart skips generating its own random secret to avoid ownership
conflicts with the ExternalSecret.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add support for loading cookie_secret from external-secrets

1 participant