diff --git a/templates/_helpers.tpl b/templates/_helpers.tpl new file mode 100644 index 0000000..daca6d2 --- /dev/null +++ b/templates/_helpers.tpl @@ -0,0 +1,15 @@ +{{/* +Replicates the openbao-helm subchart's "openbao.fullname" naming logic so our +own templates (ClusterSecretStore, bootstrap Job) can address its Service +without hardcoding "-openbao", which is wrong whenever the release +name already contains "openbao" (Helm's standard fullname collapsing). +*/}} +{{- define "openbao-gitops.openbaoFullname" -}} +{{- if (index .Values "openbao" "fullnameOverride") -}} +{{- index .Values "openbao" "fullnameOverride" | trunc 63 | trimSuffix "-" -}} +{{- else if contains "openbao" .Release.Name -}} +{{- .Release.Name | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- printf "%s-openbao" .Release.Name | trunc 63 | trimSuffix "-" -}} +{{- end -}} +{{- end -}} diff --git a/templates/bootstrap-job.yaml b/templates/bootstrap-job.yaml index 89c01a7..887edc0 100644 --- a/templates/bootstrap-job.yaml +++ b/templates/bootstrap-job.yaml @@ -29,7 +29,7 @@ spec: image: {{ .Values.bootstrap.image }} env: - name: BAO_ADDR - value: "http://{{ .Release.Name }}-openbao:8200" + value: "http://{{ include "openbao-gitops.openbaoFullname" . }}:8200" - name: BAO_TOKEN valueFrom: secretKeyRef: diff --git a/templates/clustersecretstore.yaml b/templates/clustersecretstore.yaml index 14e6290..46d685d 100644 --- a/templates/clustersecretstore.yaml +++ b/templates/clustersecretstore.yaml @@ -8,7 +8,7 @@ metadata: spec: provider: vault: - server: "http://{{ .Release.Name }}-openbao.{{ .Release.Namespace }}.svc:8200" + server: "http://{{ include "openbao-gitops.openbaoFullname" . }}.{{ .Release.Namespace }}.svc:8200" path: {{ .Values.eso.kvMountPath }} version: v2 auth: