2 KiB
Bootstrap Secret Inputs
bootstrap uses the Flux age identity in ignored .age/ storage to encrypt
the configured Democratic CSI Secret directly into the generated cluster
repository. Its TrueNAS API key is never printed or committed in plaintext.
operational-secrets.sops.yaml is decrypted only in MaidnCLI memory after
OpenBao is initialized. It is not copied to the cluster repository. Its schema
is:
secrets:
cicd/forgejo:
username: encrypted-value
token: encrypted-value
cicd/forgejo-registry:
dockerconfigjson: encrypted-value
cicd/forgejo-webhook:
authorization: encrypted-value
platform/cloudflare:
api-token: encrypted-value
platform/cloudflare-tunnel:
token: encrypted-value
Keys are written to OpenBao KV v2 under secret/<path>. Additional paths are
allowed when they use lowercase path characters and scalar property names.
Set all democraticCsi settings in the bootstrap configuration or provide
them through the interactive wizard. The CLI writes those values only to
base/democratic-csi/secret.sops.yaml in the generated cluster repository.
For an existing configuration, run bootstrap --config <path> --prompt-democratic-csi to enter the settings with the API key masked.
For a new operational-secret input, run bootstrap --config <path> --prompt-operational-secrets. It derives Forgejo Git and registry credentials
from the configured Forgejo account, prompts for Cloudflare credentials with
input masked, and generates the webhook authorization value.
cicd/forgejo-webhook.authorization is required for delivery bootstrap. The
CLI supplies it as the Forgejo webhook Authorization header and Tekton compares
that header against the ExternalSecret-derived forgejo-webhook Secret.
Run bootstrap --config <path> --initialize-openbao-recovery to create and
save a separate recovery age identity for openbao-recovery.age. The Flux SOPS
age identity is installed in flux-system; it must not encrypt OpenBao
recovery material.