|
|
@@ -4164,7 +4164,7 @@
|
|
|
<span class="nt">metadata</span><span class="p">:</span>
|
|
|
<span class="w"> </span><span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">github-auth-token</span>
|
|
|
<span class="nt">spec</span><span class="p">:</span>
|
|
|
-<span class="w"> </span><span class="nt">refreshInterval</span><span class="p">:</span><span class="w"> </span><span class="s">"30m"</span>
|
|
|
+<span class="w"> </span><span class="nt">refreshInterval</span><span class="p">:</span><span class="w"> </span><span class="s">"30m"</span><span class="w"> </span><span class="c1"># Be sure to set this value lower than 60m since that is the expiration time from github</span>
|
|
|
<span class="w"> </span><span class="nt">target</span><span class="p">:</span>
|
|
|
<span class="w"> </span><span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">github-auth-token</span><span class="w"> </span><span class="c1"># Name for the secret to be created on the cluster</span>
|
|
|
<span class="w"> </span><span class="nt">dataFrom</span><span class="p">:</span>
|
|
|
@@ -4185,7 +4185,7 @@
|
|
|
<span class="w"> </span><span class="nt">apiVersion</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">generators.external-secrets.io/v1alpha1</span>
|
|
|
<span class="w"> </span><span class="nt">kind</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">GithubAccessToken</span>
|
|
|
<span class="w"> </span><span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l l-Scalar l-Scalar-Plain">github-auth-token</span>
|
|
|
-<span class="w"> </span><span class="nt">refreshInterval</span><span class="p">:</span><span class="w"> </span><span class="s">"15m"</span>
|
|
|
+<span class="w"> </span><span class="nt">refreshInterval</span><span class="p">:</span><span class="w"> </span><span class="s">"15m"</span><span class="w"> </span><span class="c1"># Be sure to set this value lower than 60m since that is the expiration time from github</span>
|
|
|
<span class="w"> </span><span class="nt">target</span><span class="p">:</span>
|
|
|
<span class="w"> </span><span class="nt">template</span><span class="p">:</span>
|
|
|
<span class="w"> </span><span class="nt">metadata</span><span class="p">:</span>
|
|
|
@@ -4202,6 +4202,7 @@
|
|
|
<ul>
|
|
|
<li>Ensure that all sensitive data such as private keys and IDs are securely handled and stored.</li>
|
|
|
<li>Adjust the permissions and configurations according to your specific requirements and security policies.</li>
|
|
|
+<li>Github tokens expire after 60 minutes by default and this is non-configurable, make sure you choose a refreshInterval that is below this number.</li>
|
|
|
</ul>
|
|
|
|
|
|
|