# Two credentials, deliberately. The runtime role can read and write rows; the # migration role owns the schema. A service that can ALTER its own tables at # runtime turns any code defect into a schema defect. apiVersion: external-secrets.io/v1 kind: ClusterSecretStore metadata: name: openbao-canned-prompts-database labels: app.kubernetes.io/name: canned-prompts railiance-platform/component: external-secrets spec: conditions: - namespaces: - canned-prompts provider: vault: server: http://openbao.openbao.svc:8200 path: database version: v1 auth: tokenSecretRef: name: openbao-canned-prompts-eso-token namespace: external-secrets key: token --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: canned-prompts-postgres-runtime namespace: canned-prompts spec: refreshInterval: 5m secretStoreRef: kind: ClusterSecretStore name: openbao-canned-prompts-database target: name: canned-prompts-postgres-runtime creationPolicy: Owner deletionPolicy: Retain template: engineVersion: v2 data: url: >- postgresql+psycopg://{{ .username | urlquery }}:{{ .password | urlquery }}@platform-pg-2-rw.databases.svc.cluster.local:5432/canned_prompts?sslmode=require dataFrom: - extract: key: creds/canned-prompts-runtime --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: canned-prompts-postgres-migration namespace: canned-prompts spec: refreshInterval: 5m secretStoreRef: kind: ClusterSecretStore name: openbao-canned-prompts-database target: name: canned-prompts-postgres-migration creationPolicy: Owner deletionPolicy: Retain template: engineVersion: v2 data: url: >- postgresql+psycopg://{{ .username | urlquery }}:{{ .password | urlquery }}@platform-pg-2-rw.databases.svc.cluster.local:5432/canned_prompts?sslmode=require dataFrom: - extract: key: creds/canned-prompts-migration --- # The publish token. Absent, the service is read-only — which is the correct # posture until per-publisher identity exists (canned-prompts service/auth.py). apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: canned-prompts-publish-token namespace: canned-prompts spec: refreshInterval: 15m secretStoreRef: kind: ClusterSecretStore name: openbao-canned-prompts-database target: name: canned-prompts-publish-token creationPolicy: Owner deletionPolicy: Retain dataFrom: - extract: key: creds/canned-prompts-publish