Skip to content

Commit 9c8e557

Browse files
wip
1 parent 21e94c7 commit 9c8e557

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

tls/create_certs.py

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -198,14 +198,17 @@ async def create_principal(
198198
sp.check_call(['kubectl', 'apply', '-f', k8s_secret.name])
199199

200200
if store_in_cloud_secret_manager:
201-
if os.getenv('CLOUD') == 'gcp':
201+
cloud = os.getenv('CLOUD')
202+
if cloud == 'gcp':
202203
client = GoogleSecretManagerClient(os.environ['HAIL_PROJECT'])
203204
expiration_seconds = None if namespace == 'default' else 60 * 60 * 24 * 7
204205
secret_id = f'ssl-config-{principal}-{namespace}'
205206
await client.create_secret_if_not_exists(secret_id, expiration_seconds)
206207
secret_data = {f: base64.b64encode(Path(f).read_bytes()).decode() for f in secret_files}
207208
await client.create_secret_version(secret_id, orjson.dumps(secret_data))
208209
print(f'Created {secret_id} in GCP secret manager')
210+
else:
211+
assert cloud == 'azure'
209212

210213

211214
async def main():

0 commit comments

Comments
 (0)