feat(coturn): add automated TURN shared-secret rotation CronJob
Closes issue #38's automation half (architecture fix + first rotation already landed in earlier commits this session). Monthly CronJob (rohana.axion1337.de/sorb/axion-secret-rotation:v1 - alpine + git/sops/ jq/age) that: - generates a new secret - re-encrypts coturn-secret.yaml and synapse-turn-secret.yaml using the scoped rotation-only age key (added as an additional recipient in an earlier commit) - never touches the repo's master sops-age key - bumps the turn-secret-checksum (HelmRelease annotation) and rotated-at (coturn Deployment annotation) so merging actually restarts both consumers, reusing the existing checksum-annotation pattern already in this repo rather than inventing a new mechanism - opens a Pull Request rather than pushing straight to main - a human reviews and merges, keeping a checkpoint before production picks up new credentials while still automating the tedious coordination work Needs a Gitea PAT (repo write scope) filled into turn-secret-rotation-secret.yaml's gitea-token key before first use. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
be95bd921c
commit
ac7e65100d
@@ -39,4 +39,7 @@ resources:
|
||||
- networkpolicy.yaml
|
||||
# Backup zur Hetzner Storage Box (Issues #6 + #15)
|
||||
- synapse-backup-secret.yaml
|
||||
- synapse-backup.yaml
|
||||
- synapse-backup.yaml
|
||||
# Automatisierte TURN-Secret-Rotation (Issue #38)
|
||||
- turn-secret-rotation-secret.yaml
|
||||
- turn-secret-rotation.yaml
|
||||
Reference in New Issue
Block a user