# TEMPLATE — fill in real values before applying, or create the secret # imperatively instead and never commit credentials: # # kubectl -n exploredns-receiver create secret generic exploredns-receiver \ # --from-literal=RECEIVER_ADMIN_USER=admin \ # --from-literal=RECEIVER_ADMIN_PASSWORD='change-me' \ # --from-literal=RECEIVER_INGEST_TOKEN='change-me-too' # # The deployment loads every key here as an environment variable (envFrom). apiVersion: v1 kind: Secret metadata: name: exploredns-receiver namespace: exploredns-receiver type: Opaque stringData: RECEIVER_ADMIN_USER: admin RECEIVER_ADMIN_PASSWORD: change-me # Bearer token the main app must send on POST /webhook. Must match the # sender's EXPLOREDNS_WEBHOOK_TOKEN. Leave unset to accept unauthenticated # posts (not recommended for an internet-facing receiver). RECEIVER_INGEST_TOKEN: change-me-too # Uncomment to store events in an external MySQL instead of the SQLite # file on the PVC (go-sql-driver DSN). # RECEIVER_MYSQL_DSN: "user:pass@tcp(mysql.example.com:3306)/exploredns"