Skip to content

Fix Grafana telemetry credential delivery - #34

Merged
syscod3 merged 1 commit into
mainfrom
fix/grafana-bitwarden-secrets
Aug 11, 2026
Merged

Fix Grafana telemetry credential delivery#34
syscod3 merged 1 commit into
mainfrom
fix/grafana-bitwarden-secrets

Conversation

@syscod3

@syscod3 syscod3 commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Summary

Moves unraid-lab Grafana Cloud ingestion credentials into Bitwarden Secrets Manager and lets Argo CD reconcile the monitoring/grafana-cloud Secret.

Bootstraps only the Bitwarden machine-account token through Omni and removes the legacy direct Grafana credential injector.

Validation

  • bash omni/scripts/inject-bitwarden-auth-token.sh
  • kubectl kustomize clusters/unraid-lab/apps/grafana-cloud-secrets/manifests
  • Pre-commit: yamllint and gitleaks

Deployment

Run omni/scripts/inject-bitwarden-auth-token.sh --apply from an Omni-authenticated host after merge. Argo CD then creates the mapped credential Secret and Alloy should recover.

@syscod3
syscod3 merged commit 38f54a2 into main Aug 11, 2026
5 checks passed
@syscod3
syscod3 deleted the fix/grafana-bitwarden-secrets branch August 11, 2026 20:25
syscod3 added a commit that referenced this pull request Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant