Files
plex-deployment/create-ci-kubeconfig.sh
feedc0de 35ae5557b9
Validate and deploy Plex / Validate manifests and scripts (push) Successful in 12s
Validate and deploy Plex / Deploy to Kubernetes (push) Successful in 18s
Initial commit with the existing deployment files
2026-10-09 09:09:31 +02:00

49 lines
1.8 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
project_dir=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)
namespace=plex
service_account=plex-deployer
secret=plex-deployer-token
if [[ "$(kubectl config current-context)" != kubernetes-admin@kubernetes ]]; then
echo 'Run this only with the kubernetes-admin@kubernetes homelab context.' >&2
exit 1
fi
kubectl apply --filename "${project_dir}/namespace.yaml" >&2
kubectl apply --filename "${project_dir}/ci-deployer.yaml" >&2
for attempt in {1..30}; do
if kubectl --namespace "${namespace}" get secret "${secret}" \
--output=jsonpath='{.data.token}' 2>/dev/null | grep -q .; then
break
fi
if [[ "${attempt}" == 30 ]]; then
echo 'Timed out waiting for the service-account token.' >&2
exit 1
fi
sleep 1
done
workdir=$(mktemp --directory)
trap 'rm -rf "${workdir}"' EXIT
server=$(kubectl config view --minify --output=jsonpath='{.clusters[0].cluster.server}')
kubectl --namespace "${namespace}" get secret "${secret}" \
--output=jsonpath='{.data.ca\.crt}' | base64 --decode > "${workdir}/ca.crt"
token=$(kubectl --namespace "${namespace}" get secret "${secret}" \
--output=jsonpath='{.data.token}' | base64 --decode)
export KUBECONFIG="${workdir}/config"
kubectl config set-cluster cluster --server="${server}" \
--certificate-authority="${workdir}/ca.crt" --embed-certs=true >/dev/null
kubectl config set-credentials "${service_account}" --token="${token}" >/dev/null
kubectl config set-context plex --cluster=cluster --user="${service_account}" \
--namespace="${namespace}" >/dev/null
kubectl config use-context plex >/dev/null
echo 'Store this single line as the Gitea Actions secret KUBE_CONFIG_BASE64.' >&2
echo 'Treat it as a password; do not commit it.' >&2
base64 --wrap=0 "${KUBECONFIG}"
printf '\n'