workspace secrets optional, readme updated

signed Tested deployments with/without workspace credentials. Marked workspace secrets as optional. Updated readme to encourage users to specify a secret name as has recently been done with the scimsession file.

Co-Authored-By: Adam Pike <adam.pike@1password.com>
This commit is contained in:
Scott Lougheed
2022-09-15 12:13:03 -07:00
parent 7c9af927fa
commit 56ca993a1d
3 changed files with 6 additions and 5 deletions

View File

@@ -58,13 +58,13 @@ This section is only relevant to those enrolled in our Google Workspace provisio
First, youll need to edit the file located at `scim-examples/beta/workspace-settings.json`, and fill in the values according to those presented in our Google Workspace documentation.
```bash
kubectl create secret generic workspace-settings --from-file=/path/to/workspace-settings.json
kubectl create secret generic workspace-settings --from-file=workspace-settings=/path/to/workspace-settings.json
```
Then, you will need to provide the Google Service Account key file, also generated according to our documentation. Substitute `<keyfile>` with the filename generated by Google for your Google Service Account.
```bash
kubectl create secret generic workspace-credentials --from-file=/path/to/<keyfile>.json
kubectl create secret generic workspace-credentials --from-file=workspace-credentials=/path/to/<keyfile>.json
```
## Deploy to the Kubernetes cluster

View File

@@ -15,5 +15,5 @@ data:
# default: "1pw@[OP_LETSENCRYPT_DOMAIN]"
#OP_LETSENCRYPT_EMAIL: "1pw@example.com"
# (Workspace Beta) these settings are specific to those participating in the Google Workspace provisioning beta
OP_WORKSPACE_CREDENTIALS: "/secret/workspace-credentials.json"
OP_WORKSPACE_SETTINGS: "/secret/workspace-settings.json"
OP_WORKSPACE_CREDENTIALS: "/secret/workspace-credentials"
OP_WORKSPACE_SETTINGS: "/secret/workspace-settings"

View File

@@ -36,7 +36,6 @@ spec:
envFrom:
- configMapRef:
name: op-scim-configmap
# TODO: make workspace secrets optional, test deployment with/without workspace secrets
volumes:
- name: secrets
projected:
@@ -45,5 +44,7 @@ spec:
name: scimsession
- secret:
name: workspace-credentials
optional: true
- secret:
name: workspace-settings
optional: true