airshipctl/tools/gate
Alexey Odinokov e2c56108ee Nextgen secrets implementation with separation per cluster
1. Extending templater with kyaml functions and creating combined catalogue
to be able to request/update the existing resources.
This is based on 'everything is transformer' concept introduced in kustomize 4.x
That includes gathering all secrets into 1 variable catalogue and
special mechanism to regenerate/merge with manual secrets.

2. Implementing 'catalogue per cluster' approach for secrets.

3. Rearranging secrets so it's possible to use:
pgp (each person may have his own key), age, Hachicorp Vault and etc
and the list of people who can decrypt documents is set in a special file.
Since in some cases there should be a separate list of people who can decrypt
data - this list is set for each cluster (ephemeral and target) separatelly.

Closes: #586
Change-Id: I038f84dd138d5ad4a35f4862c61ff2124c2fd530
2021-09-03 20:46:15 +00:00
..
00_setup.sh Read site name from env instead of hardcoded value 2021-07-14 20:37:23 +00:00
10_build_gate.sh (fix) Add -E for sudo to pick user env 2020-10-27 14:27:27 +00:00
20_run_gate_runner.sh Nextgen secrets implementation with separation per cluster 2021-09-03 20:46:15 +00:00
99_collect_logs.sh Added tags to control execution of tasks 2021-01-22 19:42:39 +00:00
config_template.yaml Nextgen secrets implementation with separation per cluster 2021-09-03 20:46:15 +00:00