# The shape only. Do not commit real values: point your secret store at this name instead, # or create it once by hand: # # kubectl -n impuestos create secret generic impuestos-secrets \ # --from-literal=DATABASE_URL='postgres://user:pass@host:5432/impuestos' \ # --from-literal=BETTER_AUTH_SECRET="$(openssl rand -base64 32)" \ # --from-literal=S3_ACCESS_KEY_ID=... --from-literal=S3_SECRET_ACCESS_KEY=... # # Optional keys may be left out entirely. The API degrades honestly without them: no # ANTHROPIC_API_KEY sends a scan with no QR to the manual form, no SMTP_HOST logs # verification codes to stdout, and no VAPID keys hides push everywhere in the UI. apiVersion: v1 kind: Secret metadata: name: impuestos-secrets namespace: impuestos type: Opaque stringData: DATABASE_URL: 'postgres://impuestos:change-me@postgres:5432/impuestos' BETTER_AUTH_SECRET: 'change-me-at-least-32-characters-long' S3_ACCESS_KEY_ID: 'change-me' S3_SECRET_ACCESS_KEY: 'change-me' ANTHROPIC_API_KEY: '' PUSH_VAPID_PUBLIC_KEY: '' PUSH_VAPID_PRIVATE_KEY: '' SMTP_HOST: '' SMTP_USER: '' SMTP_PASS: '' TELEGRAM_BOT_TOKEN: ''