Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

INT: improve K8s secret setting page #1004

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
94 changes: 33 additions & 61 deletions content/integrate/redis-data-integration/data-pipelines/deploy.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,72 +78,44 @@ The specific command lines for source secrets are as follows:

```bash
# Source username
dwdougherty marked this conversation as resolved.
Show resolved Hide resolved
kubectl create secret generic source-db \
--namespace=rdi \
--from-literal=SOURCE_DB_USERNAME=yourUsername

# Source password
kubectl create secret generic source-db \
--namespace=rdi \
--from-literal=SOURCE_DB_PASSWORD=yourPassword

# Source trust certificate (both commands are required)
kubectl create secret generic source-db-ssl --from-file=ca.crt=/path/to/myca.crt -n rdi

kubectl create secret generic source-db \
--namespace=rdi \
--from-literal=SOURCE_DB_CACERT=/etc/certificates/source_db/ca.crt

# Source public key (both commands are required)
kubectl create secret generic source-db-ssl --from-file=client.crt=/path/to/myclient.crt -n rdi

kubectl create secret generic source-db \
--namespace=rdi \
--from-literal=SOURCE_DB_CERT=/etc/certificates/source_db/client.crt


# Source private key (both commands are required)
kubectl create secret generic source-db-ssl --from-file=client.key=/path/to/myclient.key -n rdi

kubectl create secret generic source-db \
--namespace=rdi \
--from-literal=SOURCE_DB_KEY=/etc/certificates/source_db/client.key
kubectl create secret generic source-db --namespace=rdi \
--from-literal=SOURCE_DB_USERNAME=yourUsername \
--from-literal=SOURCE_DB_PASSWORD=yourPassword \
dwdougherty marked this conversation as resolved.
Show resolved Hide resolved
--save-config --dry-run=client -o yaml | kubectl apply -f -

# Source TLS
kubectl create secret generic source-db-ssl --namespace=rdi \
--from-file=ca.crt=/path/to/myca.crt \
--save-config --dry-run=client -o yaml | kubectl apply -f -

# Source mTLS
kubectl create secret generic source-db-ssl --namespace=rdi \
--from-file=ca.crt=/path/to/myca.crt \
--from-file=client.crt=/path/to/myclient.crt \
--from-file=client.key=/path/to/myclient.key \
--save-config --dry-run=client -o yaml | kubectl apply -f -
```

The corresponding command lines for target secrets are:

```bash
# Target username
kubectl create secret generic target-db \
--namespace=rdi \
--from-literal=TARGET_DB_USERNAME=yourUsername

# Target password
kubectl create secret generic target-db \
--namespace=rdi \
--from-literal=TARGET_DB_PASSWORD=yourPassword

# Target trust certificate (both commands are required)
kubectl create secret generic target-db-ssl --from-file=ca.crt=/path/to/myca.crt -n rdi

kubectl create secret generic target-db \
--namespace=rdi \
--from-literal=TARGET_DB_CACERT=/etc/certificates/target-db/ca.crt

# Target public key (both commands are required)
kubectl create secret generic target-db-ssl --from-file=client.crt=/path/to/myclient.crt -n rdi

kubectl create secret generic target-db \
--namespace=rdi \
--from-literal=SOURCE_DB_CERT=/etc/certificates/target_db/client.crt


# Target private key (both commands are required)
kubectl create secret generic target-db-ssl --from-file=client.key=/path/to/myclient.key -n rdi

kubectl create secret generic target-db \
--namespace=rdi \
--from-literal=SOURCE_DB_KEY=/etc/certificates/target_db/client.key
# Target credentials
kubectl create secret generic target-db --namespace=rdi \
--from-literal=TARGET_DB_USERNAME=yourUsername \
--from-literal=TARGET_DB_PASSWORD=yourPassword \
dwdougherty marked this conversation as resolved.
Show resolved Hide resolved
--save-config --dry-run=client -o yaml | kubectl apply -f -

# Target TLS
kubectl create secret generic target-db-ssl --namespace=rdi \
--from-file=ca.crt=/path/to/myca.crt \
--save-config --dry-run=client -o yaml | kubectl apply -f -

# Target mTLS
kubectl create secret generic target-db-ssl --namespace=rdi \
--from-file=ca.crt=/path/to/myca.crt \
--from-file=client.crt=/path/to/myclient.crt \
--from-file=client.key=/path/to/myclient.key \
--save-config --dry-run=client -o yaml | kubectl apply -f -
```

## Deploy a pipeline
Expand Down
Loading