Skip to content

Secret Management ​

Auto-Generation ​

By default, the operator generates cryptographic secrets for values not explicitly provided:

yaml
spec:
  secrets:
    autoGenerate:
      enabled: true      # default: true

Auto-generated values are stored in a Secret named <instance>-generated-secrets:

KeyPurpose
nextauth-secretNextAuth session encryption
saltEncryption salt
clickhouse-usernameManaged ClickHouse username
clickhouse-passwordManaged ClickHouse password
redis-passwordManaged Redis password
database-urlManaged PostgreSQL connection string

To provide your own values instead, set secretRef on the relevant spec fields. The operator skips auto-generation for any field with an explicit reference.

Secret Rotation ​

The operator watches all Secrets referenced in the spec. When a Secret changes, it computes a hash annotation on the affected Deployment to trigger a rolling restart:

yaml
spec:
  secrets:
    rotation:
      enabled: true     # default: true

Built-in mappings determine which components restart:

Secret TypeRestarts
NextAuth / Salt / OIDCWeb
RedisWeb + Worker
ClickHouseWeb + Worker
DatabaseWeb + Worker
Blob StorageWorker

Custom Mappings ​

Add custom secret-to-component mappings:

yaml
spec:
  secrets:
    rotation:
      enabled: true
      customMappings:
        - secretName: custom-api-key
          restartComponents:
            - web
            - worker

How It Works ​

  1. The Secret Controller watches all Secrets referenced by the LangfuseInstance spec
  2. On change, it computes a SHA-256 hash of the relevant Secret data
  3. The hash is stored as an annotation on the affected Deployment's pod template:
    langfuse.palena.ai/secret-hash: <sha256>
  4. Kubernetes detects the annotation change and triggers a rolling update

Released under the Apache 2.0 License.