Skip to content

chore(deploy): reseal dev database-connection secret after doadmin password rotation - #91

Merged
mahdi2ba merged 1 commit into
mainfrom
chore/dev-db-connection-secret
Oct 4, 2026
Merged

mahdi2ba merged 1 commit into
mainfrom
chore/dev-db-connection-secret

Conversation

@mahdi2ba

@mahdi2ba mahdi2ba commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

The dev Postgres password for user doadmin changed . The dev SealedSecret database-connection still holds the old password, so this service cannot connect to the database since then.

This PR replaces deployment/overlays/development/database-connection-sealed-secret.yaml with the same connection string re-sealed with the current password. No other change. Prod and test are not touched.

Impact (dev only): keycloak-treetracker-admin-api and treetracker-admin-api return 500 on every DB request (admin-client #1242, admin-api Greenstand/treetracker-admin-api#676).

After merge: ArgoCD syncs the SealedSecret, then the pods must be restarted (delete pods) because the env var is read at start.

Verified: the new password was tested with psql against the dev DB.

@mahdi2ba
mahdi2ba requested a review from dadiorchen October 4, 2026 20:40
@mahdi2ba

mahdi2ba commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

The failed check is not related to this PR. The job dies at actions/checkout@v2 before any test runs: GitHub now forces checkout to Node.js 24, and this workflow runs inside the node:10.18-jessie container, which cannot run it.

This PR only replaces a sealed secret YAML under deployment/, no code. I suggest a separate PR later to update the workflow (newer container image, checkout@v4, setup-node@v4).

@mahdi2ba
mahdi2ba merged commit e6dddbd into main Oct 4, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants