From 618b1e8d11acd9537baa837d49c04458a1213ec4 Mon Sep 17 00:00:00 2001 From: chemavx Date: Tue, 14 Apr 2026 19:09:41 +0000 Subject: [PATCH] fix: remove sensitive data from secret manifest, prevent ArgoCD from overwriting encryption key --- n8n/secret-n8n-secret.yaml | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/n8n/secret-n8n-secret.yaml b/n8n/secret-n8n-secret.yaml index 408c286..4a7feaa 100644 --- a/n8n/secret-n8n-secret.yaml +++ b/n8n/secret-n8n-secret.yaml @@ -1,13 +1,12 @@ apiVersion: v1 -data: - encryption-key: REDACTED kind: Secret metadata: - annotations: - kubectl.kubernetes.io/last-applied-configuration: '{"apiVersion":"v1","kind":"Secret","metadata":{"annotations":{},"name":"n8n-secret","namespace":"n8n"},"stringData":{"encryption-key":"Oc6e4mfCNU69FhJBU2blco3rz1doRyYl"},"type":"Opaque"} - - ' name: n8n-secret namespace: n8n + annotations: + argocd.argoproj.io/sync-options: "Prune=false" + # data managed manually — do NOT store the real value here + # create/update with: kubectl create secret generic n8n-secret \ + # --from-literal=encryption-key='' \ + # -n n8n --dry-run=client -o yaml | kubectl apply -f - type: Opaque -