Add new infra architecture
This commit is contained in:
37
infrastructure/platform/mail/mailu/mailu-secrets.yaml
Normal file
37
infrastructure/platform/mail/mailu/mailu-secrets.yaml
Normal file
@@ -0,0 +1,37 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: mailu-secrets
|
||||
namespace: bakery-ia
|
||||
labels:
|
||||
app: mailu
|
||||
component: secrets
|
||||
type: Opaque
|
||||
data:
|
||||
# Admin credentials (base64 encoded)
|
||||
# IMPORTANT: Replace with real credentials before production deployment
|
||||
# Generate with: openssl rand -base64 24 | tr -d '\n' | base64
|
||||
ADMIN_PASSWORD: "VzJYS2tSdUxpT25ZS2RCWVFTQXJvbjFpeWtFU1M1b2I=" # W2XKkRuLiOnYKdBYQSAron1iykESS5ob
|
||||
|
||||
# Mailu secret key for internal encryption
|
||||
# Generate with: openssl rand -base64 32
|
||||
SECRET_KEY: "Y2I2MWI5MzRkNDcwMjlhNjQxMTdjMGU0MTEwYzkzZjY2YmJjZjVlYWExNWM4NGM0MjcyN2ZhZDc4Zjc=" # cb61b934d47029a64117c0e4110c93f66bbcf5eaa15c84c42727fad78f7
|
||||
|
||||
# External SMTP relay credentials (Mailgun)
|
||||
# For Mailgun: use postmaster@domain as username
|
||||
RELAY_USER: "cG9zdG1hc3RlckBiYWtld2lzZS5haQ==" # postmaster@bakewise.ai
|
||||
RELAY_PASSWORD: "bWFpbGd1bi1hcGkta2V5LXJlcGxhY2UtaW4tcHJvZHVjdGlvbg==" # mailgun-api-key-replace-in-production
|
||||
|
||||
# Database credentials
|
||||
DB_PASSWORD: "RThLejQ3WW1WekRsSEdzMU05d0FiSnp4Y0tuR09OQ1Q=" # E8Kz47YmVzDlHGs1M9wAbJzxcKnGONCT
|
||||
|
||||
# Dovecot admin password (moved from ConfigMap for security)
|
||||
DOVEADM_PASSWORD: "WnZhMzNoaVBJc2ZtV3RxUlBWV29taTRYZ2xLTlZPcHY=" # Zva33hiPIsfmWtqRPVWomi4XglKNVOpv
|
||||
|
||||
# Redis password - same as shared cluster Redis (redis-secrets)
|
||||
# Mailu uses database 15 for isolation from other services
|
||||
# REDIS_PW is required by Mailu for Redis authentication
|
||||
REDIS_PASSWORD: "SjNsa2x4cHU5QzlPTElLdkJteFVIT2h0czFnc0lvM0E=" # J3lklxpu9C9OLIKvBmxUHOhts1gsIo3A
|
||||
REDIS_PW: "SjNsa2x4cHU5QzlPTElLdkJteFVIT2h0czFnc0lvM0E=" # J3lklxpu9C9OLIKvBmxUHOhts1gsIo3A
|
||||
# Redis URL for Mailu - using plain TCP port 6380 for internal cluster communication
|
||||
REDIS_URL: "cmVkaXM6Ly86SjNsa2x4cHU5QzlPTElLdkJteFVIT2h0czFnc0lvM0FAcmVkaXMtc2VydmljZS5iYWtlcnktaWEuc3ZjLmNsdXN0ZXIubG9jYWw6NjM4MC8xNQ==" # redis://:J3lklxpu9C9OLIKvBmxUHOhts1gsIo3A@redis-service.bakery-ia.svc.cluster.local:6380/15
|
||||
Reference in New Issue
Block a user