consul: remove standalone k8s consul (#530)

The standalone k8s Consul runs its own raft under DC `au-syd1`, the same DC name as the VM cluster that k8s servers are about to join. Its leftover state risks a split brain, so it goes before the replacement lands.

- remove `apps/overlays/au-syd1/consul`, dropping `platform-consul` from the platform ApplicationSet and cascading deletion of the `consul` namespace and PVCs
- keep `apps/base/consul` for reuse by the replacement

Reviewed-on: #530
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #530.
This commit is contained in:
2026-10-09 22:46:40 +11:00
committed by BenVincent
parent 87880ac8ef
commit 5024945c74
2 changed files with 0 additions and 93 deletions
@@ -1,16 +0,0 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../../../base/consul
helmCharts:
- name: consul
repo: https://artifactapi.k8s.syd1.au.unkin.net/api/v1/virtual/helm
version: "1.9.7"
releaseName: consul
namespace: consul
valuesFile: values.yaml
apiVersions:
- policy/v1/PodDisruptionBudget
-77
View File
@@ -1,77 +0,0 @@
global:
name: consul
datacenter: au-syd1
domain: consul
acls:
# Enable chart-managed ACL tokens/policies for Consul system components.
manageSystemACLs: true
# Source the bootstrap/management token from a pre-existing Kubernetes secret
# instead of letting the chart generate one. The secret is synced from Vault
# via VSO (see ../../../base/consul/vaultauth.yaml and vaultstaticsecret.yaml).
# When this secret is populated the server-acl-init job SKIPS bootstrapping and
# uses the supplied token as the management token, so the k8s cluster bootstraps
# with the SAME initial_management token as the authoritative VM cluster.
bootstrapToken:
secretName: consul-bootstrap-acl-token
secretKey: token
server:
image: hashicorp/consul:1.22.7
replicas: 5
bootstrapExpect: 5
storage: 10Gi
storageClass: cephrbd-fast-delete
connect: true
disruptionBudget:
maxUnavailable: 1
extraConfig: |
{
"acl": {
"enabled": true,
"default_policy": "deny",
"down_policy": "extend-cache",
"enable_token_persistence": true
},
"disable_remote_exec": true,
"disable_update_check": true,
"performance": {
"raft_multiplier": 10
},
"ports": {
"dns": 8600,
"grpc": 8502,
"http": 8500,
"https": -1
},
"primary_datacenter": "au-syd1"
}
resources:
requests:
memory: 256Mi
cpu: 100m
limits:
memory: 2Gi
cpu: "1"
client:
enabled: false
ui:
enabled: true
service:
type: ClusterIP
connectInject:
enabled: false
dns:
enabled: true
type: LoadBalancer
annotations: |
purelb.io/service-group: "common"
purelb.io/addresses: 198.18.200.5