bolt.diy/k8s
Nirmal Arya db9a2c9292 feat: implement enterprise secrets management with AWS Secrets Manager
- Add ExternalSecret for auth secrets (SESSION_SECRET, GitHub OAuth) via AWS Secrets Manager
- Separate user-configurable provider API keys into dedicated K8s Secret
- Update deployment to use three-layer configuration model:
  * ConfigMap: non-sensitive public settings
  * ExternalSecret → Secret: infrastructure auth secrets from AWS
  * Secret: user-configurable provider API keys managed via UI
- Add comprehensive documentation for AWS Secrets Manager setup
- Include K8s deployment architecture guide with troubleshooting commands
- Enable secure, auditable, and rotatable secrets management for production

This follows enterprise security best practices with proper separation of concerns between infrastructure and user secrets.
2025-05-31 16:21:18 -04:00
..
argocd bolt diy to buildify. 2025-05-31 13:09:11 -04:00
backup feat: implement enterprise secrets management with AWS Secrets Manager 2025-05-31 16:21:18 -04:00
configmap.yaml bolt diy to buildify. 2025-05-31 13:09:11 -04:00
deployment.yaml feat: implement enterprise secrets management with AWS Secrets Manager 2025-05-31 16:21:18 -04:00
external-secret.yaml feat: implement enterprise secrets management with AWS Secrets Manager 2025-05-31 16:21:18 -04:00
ingress.yaml bolt diy to buildify. 2025-05-31 13:09:11 -04:00
irsa-serviceaccount.yaml bolt diy to buildify. 2025-05-31 13:09:11 -04:00
namespace.yaml bolt diy to buildify. 2025-05-31 13:09:11 -04:00
service.yaml bolt diy to buildify. 2025-05-31 13:09:11 -04:00