This message was deleted.
# kubernetes
s
This message was deleted.
1
h
Copy code
registry_credentials_encoded = base64.b64encode(
    f'{REGISTRY_USERNAME}:{REGISTRY_PASSWORD}'.encode(),
).decode()
image_pull_secret_ns_main = k8s.core.v1.Secret(
    resource_name=f'containerRegistryCredentials-{NAMESPACE_MAIN}',
    metadata=k8s.meta.v1.ObjectMetaArgs(
        name='regcred',
        namespace=NAMESPACES[NAMESPACE_MAIN].metadata.name,
    ),
    type='<http://kubernetes.io/dockerconfigjson|kubernetes.io/dockerconfigjson>',
    string_data={
        '.dockerconfigjson':
            '{"auths":{'
            f'"{CONTAINER_REGISTRY}":'
            '{"auth":'
            f'"{registry_credentials_encoded}"'
            '}}}',
    },
    opts=p.ResourceOptions(
        provider=k8s_provider,
        parent=NAMESPACES[NAMESPACE_MAIN]
        if NAMESPACE_MAIN in NAMESPACES else aks,
    ),
)

# Service account configuration for main namespaces
k8s.core.v1.ServiceAccount(
    resource_name=f'serviceAccount-{NAMESPACE_MAIN}',
    metadata=k8s.meta.v1.ObjectMetaArgs(
        namespace=NAMESPACES[NAMESPACE_MAIN].metadata.name,
    ),
    image_pull_secrets=[
        image_pull_secret_ns_main,
    ],
    opts=p.ResourceOptions(
        provider=k8s_provider,
        parent=NAMESPACES[NAMESPACE_MAIN]
        if NAMESPACE_MAIN in NAMESPACES else aks,
    ),
)
another issue is that the final secret at k8s has
{"auth":"X2pzb25fa2V5OjxwdWx1bWkub3V0cHV0Lk91dHB1dCBvYmplY3QgYXQgMHgxNTI0NzhjZDA+"}
which decodes to
_json_key:<pulumi.output.Output object at 0x152478cd0>
instead of
REGISTRY_PASSWORD
's value (obtained via
config.require_secret()
). what am i doing wrong?
1