Refactor the vault/secrets

This commit is contained in:
Tobias Reisinger 2026-02-06 21:41:42 +01:00
parent 11c339ce92
commit 28f2e9a33a
Signed by: serguzim
GPG key ID: 13AD60C237A28DFE
32 changed files with 144 additions and 83 deletions

View file

@ -1,4 +1,8 @@
---
synapse_macaroon_secret_key: "{{ undef() }}"
synapse_form_secret: "{{ undef() }}"
synapse_signing_key: "{{ undef() }}"
synapse_svc:
domain: "{{ all_services | service_get_domain(role_name) }}"
docker_host: synapse-admin
@ -66,8 +70,8 @@ synapse_yml:
enable_metrics: true
report_stats: true
macaroon_secret_key: "{{ vault_synapse.macaroon_secret_key }}"
form_secret: "{{ vault_synapse.form_secret }}"
macaroon_secret_key: "{{ synapse_macaroon_secret_key | mandatory }}"
form_secret: "{{ synapse_form_secret | mandatory }}"
signing_key_path: "{{ (svc.config_path, 'msrg.cc.signing.key') | path_join }}"
trusted_key_servers: