# Clone from platform-provisioned Secrets that carry the connection parts
# as individual keys. The convention, remappable via keys:
#   DB            bare database name, or a password-free libpq URI
#   PW            the password; required in every layout
#   URL           internal hostname, host or host:port (default port 5432)
#   URL_EXTERNAL  externally reachable hostname, same shape
#   USER          the role to connect as
apiVersion: pgcopydb-operator.io/v1beta1
kind: Migration
metadata:
  name: clone-platform-secret
spec:
  source:
    # DB-as-URI variant on the default key names: DB holds
    # postgresql://svc@db.example.com:5432/app, supplying user, host, port,
    # and database name; PW still holds the password, URL/USER are not needed.
    secretRef:
      name: clouddb-app
  target:
    # Bare-name variant: DB is just the database name, so the host comes
    # from a URL key (endpoint: external picks URL_EXTERNAL) and the user
    # from USER. This Secret names its keys differently; keys remaps them.
    secretRef:
      name: platform-db
      endpoint: external
      keys:
        database: db
        password: pw
        urlExternal: host
        username: role
    sslMode: require
