From df59803de02311856b4142a04fdde73759134b79 Mon Sep 17 00:00:00 2001 From: haburger Date: Wed, 4 Sep 2024 11:27:32 +0000 Subject: [PATCH] new configuration version --- ...-ob-fido-uaf-d990accd4fedae1acbc7109d.yaml | 5 +++- ...ession-store-e891ec2f4f924135261d22ce.yaml | 26 +++++++++++++++++++ .../opt/nevisfido/default/conf/nevisfido.yml | 10 +++---- 3 files changed, 35 insertions(+), 6 deletions(-) create mode 100644 DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/etc/nevis/k8s-work-mariadb-session-store-e891ec2f4f924135261d22ce.yaml diff --git a/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/etc/nevis/k8s-ob-fido-uaf-d990accd4fedae1acbc7109d.yaml b/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/etc/nevis/k8s-ob-fido-uaf-d990accd4fedae1acbc7109d.yaml index bac38b0..c63d2c1 100644 --- a/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/etc/nevis/k8s-ob-fido-uaf-d990accd4fedae1acbc7109d.yaml +++ b/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/etc/nevis/k8s-ob-fido-uaf-d990accd4fedae1acbc7109d.yaml @@ -46,9 +46,12 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-77573d3e5e2cb681902d14be670c30fa4846cda4" + tag: "r-62ba771c7d6f685abc4f0f645fa618b05f78774f" dir: "DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf" credentials: "git-credentials" + database: + name: "ob-fido-uaf" + requiredVersion: "8.2405.0" keystores: - "ob-fido-uaf-default-server-identity" truststores: diff --git a/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/etc/nevis/k8s-work-mariadb-session-store-e891ec2f4f924135261d22ce.yaml b/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/etc/nevis/k8s-work-mariadb-session-store-e891ec2f4f924135261d22ce.yaml new file mode 100644 index 0000000..b8d0b1a --- /dev/null +++ b/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/etc/nevis/k8s-work-mariadb-session-store-e891ec2f4f924135261d22ce.yaml @@ -0,0 +1,26 @@ +apiVersion: "operator.nevis-security.ch/v1" +kind: "NevisDatabase" +metadata: + name: "ob-fido-uaf" + namespace: "adn-agov-nevisidm-ob-01-uat" + labels: + deploymentTarget: "ob-fido-uaf" + annotations: + projectKey: "DEFAULT-ADN-AGOV-WORK-OB-PROJECT" + patternId: "e891ec2f4f924135261d22ce" +spec: + type: "NevisFIDO" + databaseType: "MariaDB" + version: "8.2405.0" + url: "mariadb-session-store-service.adn-agov-nevisidm-ob-01-uat" + port: 3306 + database: "nevisfido_uaf" + bootstrap: true + migrate: true + rootCredentials: + name: "root-mariadb-session-store" + namespace: "adn-agov-nevisidm-ob-01-uat" + podSecurity: + policy: "baseline" + automountServiceAccountToken: false + timeZone: "Europe/Zurich" diff --git a/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/var/opt/nevisfido/default/conf/nevisfido.yml b/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/var/opt/nevisfido/default/conf/nevisfido.yml index 09a410f..6bb95f2 100644 --- a/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/var/opt/nevisfido/default/conf/nevisfido.yml +++ b/DEFAULT-ADN-AGOV-WORK-OB-PROJECT/DEFAULT-DEFAULT-ADN-AGOV-OB-INV/ob-fido-uaf/var/opt/nevisfido/default/conf/nevisfido.yml @@ -31,11 +31,11 @@ credential-repository: user-attribute: extId session-repository: - type: in-memory - jdbc-url: - max-connection-lifetime: - user: - password: + type: sql + jdbc-url: jdbc:mariadb://mariadb-session-store-service.adn-agov-nevisidm-ob-01-uat:3306/nevisfido_uaf?sslMode=disable&autocommit=true + max-connection-lifetime: 10m + user: ${exec:/var/opt/nevisfido/default/conf/credentials/dbUser} + password: ${exec:/var/opt/nevisfido/default/conf/credentials/dbPassword} schema-user: schema-user-password: automatic-db-schema-setup: false