Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
apiVersion: v1
name: pgdog
version: v0.81
version: v0.82
appVersion: "v0.1.58"
73 changes: 46 additions & 27 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -215,11 +215,56 @@ externalSecrets:
secretName: "my-secret" # Name of Secret you created
```

### Secrets

The chart can inject values from existing Kubernetes Secrets into the PgDog
container's environment:

| Setting | Environment variable | Default Secret key |
| -------------------------- | ------------------------ | ------------------ |
| `control.endpointSecret` | `PGDOG_CONTROL_ENDPOINT` | `endpoint` |
| `control.tokenSecret` | `PGDOG_CONTROL_TOKEN` | `token` |
| `otel.datadogApiKeySecret` | `DD_API_KEY` | `dd-api-key` |

#### Example

Create a `Secret` in the same namespace as PgDog:

```yaml
apiVersion: v1
kind: Secret
metadata:
name: pgdog-control
type: Opaque
stringData:
endpoint: "https://control.example.com"
token: "replace-with-your-control-token"
dd-api-key: "replace-with-your-datadog-api-key"
```

Reference it in your Helm values:

```yaml
control:
enabled: true
endpointSecret:
name: pgdog-control
key: endpoint
tokenSecret:
name: pgdog-control
key: token
otel:
endpoint: "https://otlp.example.com/v1/metrics" # Your OTLP endpoint.
datadogApiKeySecret:
name: pgdog-control
key: dd-api-key
```

### Referencing Existing Secrets

If you manage Kubernetes Secrets yourself (via `kubectl`, sealed-secrets,
SOPS, etc.), point the chart at them directly instead of putting secret
values in `values.yaml`. This works without the ExternalSecrets operator.
values in `values.yaml`. This works without the `ExternalSecrets` operator.

#### users.toml from an existing Secret

Expand Down Expand Up @@ -280,32 +325,6 @@ not mounted when `configSecret.name` is set. A Secret-provided pgdog.toml
controls its own plugin config paths, so mount plugin files elsewhere via
`extraVolumes`/`extraVolumeMounts`.

#### Datadog API key from an existing Secret

PgDog reads the Datadog API key from the `DD_API_KEY` environment variable.
Reference an existing Secret and the chart injects it as `DD_API_KEY`, so the
key is never written into `pgdog.toml` (or the ConfigMap):

```yaml
otel:
endpoint: https://otlp.example.com/v1/metrics # your OTLP endpoint
datadogApiKeySecret:
name: my-datadog # existing Secret in the same namespace
key: dd-api-key # key holding the API key (default: dd-api-key)
```

Create the Secret, for example:

```bash
kubectl create secret generic my-datadog \
--from-literal=dd-api-key=<your-datadog-api-key>
```

This is mutually exclusive with the inline `otel.datadogApiKey`, which writes
the key into the ConfigMap as plaintext and should be avoided.

If both are set, the inline value takes precedence.

### ServiceAccount & RBAC

RBAC with minimal permissions is enabled by default:
Expand Down
4 changes: 2 additions & 2 deletions templates/config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -552,10 +552,10 @@ data:
{{- with .Values.control }}
{{- if .enabled }}
[control]
{{- if hasKey . "endpoint" }}
{{- if .endpoint }}
endpoint = {{ .endpoint | quote }}
{{- end }}
{{- if hasKey . "token" }}
{{- if .token }}
token = {{ .token | quote }}
{{- end }}
{{- if hasKey . "metricsInterval" }}
Expand Down
22 changes: 22 additions & 0 deletions templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,28 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.name
{{- with .Values.control }}
{{- if .enabled }}
{{- with .endpointSecret }}
{{- if .name }}
- name: PGDOG_CONTROL_ENDPOINT
valueFrom:
secretKeyRef:
name: {{ .name | quote }}
key: {{ .key | default "endpoint" | quote }}
{{- end }}
{{- end }}
{{- with .tokenSecret }}
{{- if .name }}
- name: PGDOG_CONTROL_TOKEN
valueFrom:
secretKeyRef:
name: {{ .name | quote }}
key: {{ .key | default "token" | quote }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
{{- with .Values.otel }}
{{- with .datadogApiKeySecret }}
{{- if .name }}
Expand Down
13 changes: 13 additions & 0 deletions test/values-control-secrets.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Test Secret references for control plane environment variables (PgDog EE).
control:
enabled: true
# Inline values keep configcheck independent of Kubernetes Secrets and test
# precedence when both inline settings and Secret references are configured.
endpoint: "https://control.example.com"
token: "test-token"
endpointSecret:
name: pgdog-control-endpoint
# Uses the default key: endpoint.
tokenSecret:
name: pgdog-control-token
key: auth-token
13 changes: 11 additions & 2 deletions values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -576,10 +576,19 @@ queryStats:
control:
# enabled controls whether to include [control] section in pgdog.toml
enabled: false
# endpoint is the control plane URL
# endpoint is the control plane URL. Leave empty to use PGDOG_CONTROL_ENDPOINT.
endpoint: ""
# token is the authentication token for the control plane
# token is the authentication token. Leave empty to use PGDOG_CONTROL_TOKEN.
token: ""
# Inject the endpoint/token from existing Secrets in the same namespace.
# Inline endpoint/token values take precedence. Requires a PgDog EE version
# that supports PGDOG_CONTROL_ENDPOINT and PGDOG_CONTROL_TOKEN.
endpointSecret:
name: ""
key: endpoint
tokenSecret:
name: ""
key: token
# metricsInterval defines how often to push metrics (in milliseconds)
metricsInterval: 1000
# statsInterval defines how often to push stats (in milliseconds)
Expand Down
Loading