-
Notifications
You must be signed in to change notification settings - Fork 6
Open
Description
In the pv.yaml files found below, there appears to be a mismatch in credentials.
helm/metadig-scheduler/pv.yaml
helm/metadig-worker/pv.yaml
Per @artntek's PR feedback:
the credentials in this
csi-cephfs-secretdon't appear to match those in the security repo (security/k8s/cephfs-subvols.gpg). Instead, it's listed as:subvolume: k8sdevsubvol user: (redacted) group: k8sdevsubvolgroup path: /volumes/k8sdevsubvolgroup/k8sdevsubvol/4b7cd044-4055-49c5-97b4-d1240d276856/ key: (matches this one)(note the different path, too)
The credentials for:
## PRODUCTION rootPath: /volumes/pdg-subvol-group/pdg-subvol/a5c90f20-f824-4ce9-b175-6685d7846520/repos ## DEV/TEST rootPath: /volumes/tdg-subvol-group/tdg-subvol/a5c90f20-f824-4ce9-b175-6685d7846520/repos...are already installed in secrets named:
csi-cephfs-prod-data-pdg-subvol(for prod), andcsi-cephfs-test-data-tdg-subvol(for dev)For consistency and to reduce confusion, it would be good to replace
name: csi-cephfs-secretwithname: csi-cephfs-prod-data-pdg-subvol(and ideally to deletecsi-cephfs-secret(if nothing else is using it).
Review, apply and test these changes.
- Note, access to dev k8s is required so that the updated name/namespace can be applied. This cannot be done via
dev-metadigk8s directly.
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
No status