skillhub/deploy/k8s/base/secret.yaml.example
XiaoSeS 75c7f9a880 feat(deploy): wire DingTalk credentials into the release surfaces
Adds the DingTalk credentials to every path that actually delivers
configuration: compose.release.yml (which has no env_file, so variables must
be listed explicitly), the Helm secret template and values, the k8s
deployment and its secret example. validate-release-config.sh gains DingTalk
in its provider loop, so a half-configured pair is rejected the same way.

Documents the three-stage strategy contract in the authentication design: a
table mapping each deviation -- authorize parameters, token exchange,
userinfo loading -- to its interface and current implementations, plus the
rule that a provider must never make account decisions itself.

Deployment notes and both FAQs now cover DingTalk, including the shared trap
with Feishu: their emails are admin-recorded and never confirmed, so
emailVerified is always false and an EMAIL_DOMAIN access policy would reject
every login through either provider.

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-21 15:15:41 +08:00

45 lines
1.5 KiB
Text
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# SkillHub Secret 配置
# 复制此文件为 secret.yaml 并修改值
# cp secret.yaml.example secret.yaml
apiVersion: v1
kind: Secret
metadata:
name: skillhub-secret
type: Opaque
stringData:
# PostgreSQL 连接配置
# 使用外部数据库:修改主机地址和端口
# 使用内置数据库(overlays/with-infra):保持 postgres:5432
spring-datasource-url: jdbc:postgresql://postgres:5432/skillhub
spring-datasource-username: skillhub
spring-datasource-password: change-me
# Redis 数据节点密码(单机、Sentinel 与 Cluster 共用;无密码时留空)
redis-password: ""
# Redis Sentinel 独立密码;与数据节点相同时也可填写同一个值
redis-sentinel-password: ""
# Bootstrap 管理员密码(敏感)
bootstrap-admin-password: ChangeMe!2026
# GitHub OAuth(可选,用于 GitHub 登录)
oauth2-github-client-id: ""
oauth2-github-client-secret: ""
# 飞书 OAuth(可选,用于飞书登录;留空则登录页不展示该入口)
oauth2-feishu-client-id: ""
oauth2-feishu-client-secret: ""
# 钉钉 OAuth(可选,用于钉钉登录;留空则登录页不展示该入口)
oauth2-dingtalk-client-id: ""
oauth2-dingtalk-client-secret: ""
# LLM 配置(可选,用于技能扫描)
skill-scanner-llm-api-key: ""
skill-scanner-llm-base-url: ""
skill-scanner-llm-model: ""
# S3 存储配置(可选,使用 S3/OSS 时配置)
skillhub-storage-s3-access-key: ""
skillhub-storage-s3-secret-key: ""