diff --git a/Chart.yaml b/Chart.yaml index ab97e6d..4669597 100644 --- a/Chart.yaml +++ b/Chart.yaml @@ -1,4 +1,4 @@ apiVersion: v1 name: pgdog -version: v0.81 +version: v0.82 appVersion: "v0.1.58" diff --git a/README.md b/README.md index ae6d200..26a306f 100644 --- a/README.md +++ b/README.md @@ -215,11 +215,56 @@ externalSecrets: secretName: "my-secret" # Name of Secret you created ``` +### Secrets + +The chart can inject values from existing Kubernetes Secrets into the PgDog +container's environment: + +| Setting | Environment variable | Default Secret key | +| -------------------------- | ------------------------ | ------------------ | +| `control.endpointSecret` | `PGDOG_CONTROL_ENDPOINT` | `endpoint` | +| `control.tokenSecret` | `PGDOG_CONTROL_TOKEN` | `token` | +| `otel.datadogApiKeySecret` | `DD_API_KEY` | `dd-api-key` | + +#### Example + +Create a `Secret` in the same namespace as PgDog: + +```yaml +apiVersion: v1 +kind: Secret +metadata: + name: pgdog-control +type: Opaque +stringData: + endpoint: "https://control.example.com" + token: "replace-with-your-control-token" + dd-api-key: "replace-with-your-datadog-api-key" +``` + +Reference it in your Helm values: + +```yaml +control: + enabled: true + endpointSecret: + name: pgdog-control + key: endpoint + tokenSecret: + name: pgdog-control + key: token +otel: + endpoint: "https://otlp.example.com/v1/metrics" # Your OTLP endpoint. + datadogApiKeySecret: + name: pgdog-control + key: dd-api-key +``` + ### Referencing Existing Secrets If you manage Kubernetes Secrets yourself (via `kubectl`, sealed-secrets, SOPS, etc.), point the chart at them directly instead of putting secret -values in `values.yaml`. This works without the ExternalSecrets operator. +values in `values.yaml`. This works without the `ExternalSecrets` operator. #### users.toml from an existing Secret @@ -280,32 +325,6 @@ not mounted when `configSecret.name` is set. A Secret-provided pgdog.toml controls its own plugin config paths, so mount plugin files elsewhere via `extraVolumes`/`extraVolumeMounts`. -#### Datadog API key from an existing Secret - -PgDog reads the Datadog API key from the `DD_API_KEY` environment variable. -Reference an existing Secret and the chart injects it as `DD_API_KEY`, so the -key is never written into `pgdog.toml` (or the ConfigMap): - -```yaml -otel: - endpoint: https://otlp.example.com/v1/metrics # your OTLP endpoint - datadogApiKeySecret: - name: my-datadog # existing Secret in the same namespace - key: dd-api-key # key holding the API key (default: dd-api-key) -``` - -Create the Secret, for example: - -```bash -kubectl create secret generic my-datadog \ - --from-literal=dd-api-key= -``` - -This is mutually exclusive with the inline `otel.datadogApiKey`, which writes -the key into the ConfigMap as plaintext and should be avoided. - -If both are set, the inline value takes precedence. - ### ServiceAccount & RBAC RBAC with minimal permissions is enabled by default: diff --git a/templates/config.yaml b/templates/config.yaml index 0e6791f..67af5bf 100644 --- a/templates/config.yaml +++ b/templates/config.yaml @@ -552,10 +552,10 @@ data: {{- with .Values.control }} {{- if .enabled }} [control] - {{- if hasKey . "endpoint" }} + {{- if .endpoint }} endpoint = {{ .endpoint | quote }} {{- end }} - {{- if hasKey . "token" }} + {{- if .token }} token = {{ .token | quote }} {{- end }} {{- if hasKey . "metricsInterval" }} diff --git a/templates/deployment.yaml b/templates/deployment.yaml index c0294bf..b43517b 100644 --- a/templates/deployment.yaml +++ b/templates/deployment.yaml @@ -106,6 +106,28 @@ spec: valueFrom: fieldRef: fieldPath: metadata.name + {{- with .Values.control }} + {{- if .enabled }} + {{- with .endpointSecret }} + {{- if .name }} + - name: PGDOG_CONTROL_ENDPOINT + valueFrom: + secretKeyRef: + name: {{ .name | quote }} + key: {{ .key | default "endpoint" | quote }} + {{- end }} + {{- end }} + {{- with .tokenSecret }} + {{- if .name }} + - name: PGDOG_CONTROL_TOKEN + valueFrom: + secretKeyRef: + name: {{ .name | quote }} + key: {{ .key | default "token" | quote }} + {{- end }} + {{- end }} + {{- end }} + {{- end }} {{- with .Values.otel }} {{- with .datadogApiKeySecret }} {{- if .name }} diff --git a/test/values-control-secrets.yaml b/test/values-control-secrets.yaml new file mode 100644 index 0000000..a3221fe --- /dev/null +++ b/test/values-control-secrets.yaml @@ -0,0 +1,13 @@ +# Test Secret references for control plane environment variables (PgDog EE). +control: + enabled: true + # Inline values keep configcheck independent of Kubernetes Secrets and test + # precedence when both inline settings and Secret references are configured. + endpoint: "https://control.example.com" + token: "test-token" + endpointSecret: + name: pgdog-control-endpoint + # Uses the default key: endpoint. + tokenSecret: + name: pgdog-control-token + key: auth-token diff --git a/values.yaml b/values.yaml index 312ddb5..0e803cd 100644 --- a/values.yaml +++ b/values.yaml @@ -576,10 +576,19 @@ queryStats: control: # enabled controls whether to include [control] section in pgdog.toml enabled: false - # endpoint is the control plane URL + # endpoint is the control plane URL. Leave empty to use PGDOG_CONTROL_ENDPOINT. endpoint: "" - # token is the authentication token for the control plane + # token is the authentication token. Leave empty to use PGDOG_CONTROL_TOKEN. token: "" + # Inject the endpoint/token from existing Secrets in the same namespace. + # Inline endpoint/token values take precedence. Requires a PgDog EE version + # that supports PGDOG_CONTROL_ENDPOINT and PGDOG_CONTROL_TOKEN. + endpointSecret: + name: "" + key: endpoint + tokenSecret: + name: "" + key: token # metricsInterval defines how often to push metrics (in milliseconds) metricsInterval: 1000 # statsInterval defines how often to push stats (in milliseconds)