From 5024945c74ff85700eb3024aa5e05c7fdc827866 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Fri, 9 Oct 2026 22:46:40 +1100 Subject: [PATCH] consul: remove standalone k8s consul (#530) The standalone k8s Consul runs its own raft under DC `au-syd1`, the same DC name as the VM cluster that k8s servers are about to join. Its leftover state risks a split brain, so it goes before the replacement lands. - remove `apps/overlays/au-syd1/consul`, dropping `platform-consul` from the platform ApplicationSet and cascading deletion of the `consul` namespace and PVCs - keep `apps/base/consul` for reuse by the replacement Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/530 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- .../au-syd1/consul/kustomization.yaml | 16 ---- apps/overlays/au-syd1/consul/values.yaml | 77 ------------------- 2 files changed, 93 deletions(-) delete mode 100644 apps/overlays/au-syd1/consul/kustomization.yaml delete mode 100644 apps/overlays/au-syd1/consul/values.yaml diff --git a/apps/overlays/au-syd1/consul/kustomization.yaml b/apps/overlays/au-syd1/consul/kustomization.yaml deleted file mode 100644 index c737f99..0000000 --- a/apps/overlays/au-syd1/consul/kustomization.yaml +++ /dev/null @@ -1,16 +0,0 @@ ---- -apiVersion: kustomize.config.k8s.io/v1beta1 -kind: Kustomization - -resources: - - ../../../base/consul - -helmCharts: - - name: consul - repo: https://artifactapi.k8s.syd1.au.unkin.net/api/v1/virtual/helm - version: "1.9.7" - releaseName: consul - namespace: consul - valuesFile: values.yaml - apiVersions: - - policy/v1/PodDisruptionBudget diff --git a/apps/overlays/au-syd1/consul/values.yaml b/apps/overlays/au-syd1/consul/values.yaml deleted file mode 100644 index cc9f434..0000000 --- a/apps/overlays/au-syd1/consul/values.yaml +++ /dev/null @@ -1,77 +0,0 @@ -global: - name: consul - datacenter: au-syd1 - domain: consul - - acls: - # Enable chart-managed ACL tokens/policies for Consul system components. - manageSystemACLs: true - # Source the bootstrap/management token from a pre-existing Kubernetes secret - # instead of letting the chart generate one. The secret is synced from Vault - # via VSO (see ../../../base/consul/vaultauth.yaml and vaultstaticsecret.yaml). - # When this secret is populated the server-acl-init job SKIPS bootstrapping and - # uses the supplied token as the management token, so the k8s cluster bootstraps - # with the SAME initial_management token as the authoritative VM cluster. - bootstrapToken: - secretName: consul-bootstrap-acl-token - secretKey: token - -server: - image: hashicorp/consul:1.22.7 - replicas: 5 - bootstrapExpect: 5 - storage: 10Gi - storageClass: cephrbd-fast-delete - - connect: true - - disruptionBudget: - maxUnavailable: 1 - - extraConfig: | - { - "acl": { - "enabled": true, - "default_policy": "deny", - "down_policy": "extend-cache", - "enable_token_persistence": true - }, - "disable_remote_exec": true, - "disable_update_check": true, - "performance": { - "raft_multiplier": 10 - }, - "ports": { - "dns": 8600, - "grpc": 8502, - "http": 8500, - "https": -1 - }, - "primary_datacenter": "au-syd1" - } - - resources: - requests: - memory: 256Mi - cpu: 100m - limits: - memory: 2Gi - cpu: "1" - -client: - enabled: false - -ui: - enabled: true - service: - type: ClusterIP - -connectInject: - enabled: false - -dns: - enabled: true - type: LoadBalancer - annotations: | - purelb.io/service-group: "common" - purelb.io/addresses: 198.18.200.5