docs(traefik): update secrets reference for manifest-driven Pattern C migration
This commit is contained in:
@@ -1,5 +1,8 @@
|
|||||||
# traefik Stack — Secrets Reference
|
# traefik Stack — Secrets Reference
|
||||||
# Source: traefik.env
|
# Source: traefik.env.template (rendered by deploy/provision-stack.py per
|
||||||
|
# secrets/secrets-map.yaml — see secrets-map.yaml header for how
|
||||||
|
# this works). traefik/traefik.env is rendered fresh on every
|
||||||
|
# provisioning run and is NEVER committed to git.
|
||||||
#
|
#
|
||||||
# Add SECRET values to Woodpecker at:
|
# Add SECRET values to Woodpecker at:
|
||||||
# https://woodpecker.bryanmail.net
|
# https://woodpecker.bryanmail.net
|
||||||
@@ -8,27 +11,44 @@
|
|||||||
# ⚠️ HIGH RISK: Traefik is the entry point for all homelab services.
|
# ⚠️ HIGH RISK: Traefik is the entry point for all homelab services.
|
||||||
# If this stack fails, nothing is reachable from outside.
|
# If this stack fails, nothing is reachable from outside.
|
||||||
# Migrate carefully. The Keepalived VIP (192.168.4.30) depends on this stack.
|
# Migrate carefully. The Keepalived VIP (192.168.4.30) depends on this stack.
|
||||||
|
#
|
||||||
|
# ⚠️ 2026-09-12 INCIDENT: traefik.env was previously committed to git with a
|
||||||
|
# literal "***REDACTED***" placeholder as KEEPALIVED_PASSWORD. Every
|
||||||
|
# git-guard resync/checkout restored that broken value onto disk,
|
||||||
|
# diverging from keepalived-backup's stale-but-correct in-memory value
|
||||||
|
# and causing continuous VRRP auth failures + VIP instability. This was
|
||||||
|
# the trigger for migrating this stack to Pattern C. If you ever see
|
||||||
|
# KEEPALIVED_PASSWORD as a literal placeholder-looking string on disk
|
||||||
|
# again, do NOT hand-edit it — check `git log traefik/` for a stray
|
||||||
|
# commit and fix the template in Gitea instead.
|
||||||
|
|
||||||
# ── SECRETS (add to Woodpecker) ───────────────────────────────────────────────
|
# ── SECRETS (add to Woodpecker) ─────────────────────────────────────────
|
||||||
|
|
||||||
# Woodpecker secret name: traefik_keepalived_password
|
# Woodpecker secret name: traefik_keepalived_password
|
||||||
# Used for: Keepalived VRRP authentication password
|
# Used for: Keepalived VRRP authentication password
|
||||||
# Must match across all 3 nodes (docker-1, docker-2, docker-3)
|
# Must match across all 3 nodes (docker-1, docker-2, docker-3)
|
||||||
# Env var in .env: KEEPALIVED_PASSWORD
|
# NOTE: classic VRRP simple-auth is silently
|
||||||
|
# truncated to 8 chars by keepalived itself — keep
|
||||||
|
# the value <= 8 characters, or be aware only the
|
||||||
|
# first 8 are actually significant on the wire.
|
||||||
|
# Env var in .env.template: KEEPALIVED_PASSWORD (via TRAEFIK_KEEPALIVED_PASSWORD)
|
||||||
traefik_keepalived_password=
|
traefik_keepalived_password=
|
||||||
|
|
||||||
# ── NON-SECRETS (safe in compose file or .env) ────────────────────────────────
|
# ── NON-SECRETS (safe in compose file or .env.template) ─────────────────
|
||||||
|
|
||||||
# KEEPALIVED_UNICAST_PEERS Python2BASH list of peer IPs
|
# KEEPALIVED_VIRTUAL_IPS Python2BASH list of VIP addresses (192.168.4.30) — literal in template
|
||||||
# KEEPALIVED_VIRTUAL_IPS Python2BASH list of VIP addresses (192.168.4.30)
|
|
||||||
# ACME_EMAIL Let's Encrypt certificate email
|
# ACME_EMAIL Let's Encrypt certificate email
|
||||||
# TRUSTED_IPS Trusted proxy CIDR ranges
|
# TRUSTED_IPS Trusted proxy CIDR ranges
|
||||||
# TRAEFIK_HOST Traefik dashboard hostname
|
# TRAEFIK_HOST Traefik dashboard hostname
|
||||||
# SPEEDTEST_HOST Speedtest Traefik hostname
|
# SPEEDTEST_HOST Speedtest Traefik hostname
|
||||||
# WHOAMI_HOST Whoami Traefik hostname
|
# WHOAMI_HOST Whoami Traefik hostname
|
||||||
|
|
||||||
# ── Woodpecker provision-secrets case entry ───────────────────────────────────
|
# ── Provisioning (manifest-driven, deploy/provision-stack.py) ───────────
|
||||||
#
|
#
|
||||||
# traefik)
|
# This stack is migrated — provisioning happens automatically via:
|
||||||
# create_or_update_secret "traefik_keepalived_password" "$TRAEFIK_KEEPALIVED_PASSWORD"
|
# secrets/secrets-map.yaml (traefik: entry)
|
||||||
# ;;
|
# traefik/traefik.env.template (authoritative key list)
|
||||||
|
# deploy/provision-stack.py (renders + ships traefik/traefik.env)
|
||||||
|
#
|
||||||
|
# The .woodpecker/deploy.yml provision-secrets step calls this with a
|
||||||
|
# single line: `python3 deploy/provision-stack.py traefik`
|
||||||
|
|||||||
Reference in New Issue
Block a user