Signal Forge ADR-007: secretKeyRef for all credentials (no plaintext env vars)
Status: Accepted
Decision: All database passwords, RabbitMQ credentials, and API keys are stored in Kubernetes
Secrets and referenced via secretKeyRef in Deployment env vars. No plaintext credentials in
manifests. See
ADR-006 for what
happens when a referenced secret is absent.
Rationale:
- Kubernetes manifests are typically committed to version control. Plaintext passwords in
deployment.yamlwould be exposed to anyone with repo read access and in all git history. secretKeyRefkeeps credential values in the cluster only. Manifests are safe to commit.optional: trueis used on Grafana Cloud secrets only (opt-in feature). All datastore secrets are required (nooptional).
Alternative considered: ConfigMap with base64 values — rejected because ConfigMaps are not access-controlled by default and are not treated as sensitive by cluster operators.