diff --git a/apps/base/pdbmux/configmap.yaml b/apps/base/pdbmux/configmap.yaml new file mode 100644 index 0000000..1238425 --- /dev/null +++ b/apps/base/pdbmux/configmap.yaml @@ -0,0 +1,19 @@ +--- +apiVersion: v1 +kind: ConfigMap +metadata: + name: pdbmux-env + namespace: pdbmux +data: + PDBMUX_LISTEN: ":8080" + # Two PuppetDB backends merged during the VM -> k8s migration: + # old = legacy Consul-registered puppetdbapi (reachable from pods via the + # Consul DNS the puppet workloads already use) + # new = the in-cluster k8s PuppetDB (plain HTTP on 8080; in-cluster address + # is preferred over the external gateway to avoid a hairpin). + PDBMUX_BACKENDS: "old=http://puppetdbapi.service.consul:8080,new=http://puppetdb.puppet.svc.cluster.local:8080" + # "new" (the k8s PuppetDB) is the primary for non-merged pass-through and the + # preferred backend for ties / static-merge fallback. + PDBMUX_PRIMARY: "new" + PDBMUX_PREFER: "new" + PDBMUX_MERGE: "freshness" diff --git a/apps/base/pdbmux/deployment.yaml b/apps/base/pdbmux/deployment.yaml new file mode 100644 index 0000000..d51b947 --- /dev/null +++ b/apps/base/pdbmux/deployment.yaml @@ -0,0 +1,63 @@ +--- +apiVersion: apps/v1 +kind: Deployment +metadata: + name: pdbmux + namespace: pdbmux + annotations: + reloader.stakater.com/auto: "true" +spec: + replicas: 2 + selector: + matchLabels: + app: pdbmux + strategy: + rollingUpdate: + maxUnavailable: 1 + type: RollingUpdate + template: + metadata: + labels: + app: pdbmux + spec: + automountServiceAccountToken: false + containers: + - name: pdbmux + # Image is published by the pdbmux repo's .woodpecker/docker.yaml on + # a v* tag. It only exists after that tag is cut (see PR merge gates). + image: git.unkin.net/unkin/pdbmux:v0.1.0 + imagePullPolicy: IfNotPresent + ports: + - containerPort: 8080 + name: http + protocol: TCP + envFrom: + # PDBMUX_LISTEN / PDBMUX_BACKENDS / PDBMUX_PRIMARY / PDBMUX_PREFER / + # PDBMUX_MERGE + - configMapRef: + name: pdbmux-env + optional: false + livenessProbe: + httpGet: + path: /healthz + port: http + initialDelaySeconds: 15 + periodSeconds: 30 + timeoutSeconds: 5 + failureThreshold: 3 + readinessProbe: + httpGet: + path: /healthz + port: http + initialDelaySeconds: 5 + periodSeconds: 5 + timeoutSeconds: 5 + failureThreshold: 3 + resources: + requests: + cpu: 50m + memory: 64Mi + limits: + cpu: 500m + memory: 256Mi + restartPolicy: Always diff --git a/apps/base/pdbmux/gateway.yaml b/apps/base/pdbmux/gateway.yaml new file mode 100644 index 0000000..100d2d9 --- /dev/null +++ b/apps/base/pdbmux/gateway.yaml @@ -0,0 +1,37 @@ +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: Gateway +metadata: + labels: + traefik.io/instance: internal + annotations: + cert-manager.io/cluster-issuer: vault-issuer + cert-manager.io/common-name: pdbmux.k8s.syd1.au.unkin.net + cert-manager.io/private-key-size: "4096" + external-dns.alpha.kubernetes.io/hostname: pdbmux.k8s.syd1.au.unkin.net + external-dns.alpha.kubernetes.io/target: 198.18.200.4 + name: pdbmux + namespace: pdbmux +spec: + gatewayClassName: traefik-internal + listeners: + - allowedRoutes: + namespaces: + from: Same + hostname: pdbmux.k8s.syd1.au.unkin.net + name: http + port: 80 + protocol: HTTP + - allowedRoutes: + namespaces: + from: Same + hostname: pdbmux.k8s.syd1.au.unkin.net + name: https + port: 443 + protocol: HTTPS + tls: + certificateRefs: + - group: "" + kind: Secret + name: pdbmux-tls + mode: Terminate diff --git a/apps/base/pdbmux/httproute.yaml b/apps/base/pdbmux/httproute.yaml new file mode 100644 index 0000000..a6fac82 --- /dev/null +++ b/apps/base/pdbmux/httproute.yaml @@ -0,0 +1,49 @@ +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: pdbmux-http-redirect + namespace: pdbmux +spec: + hostnames: + - pdbmux.k8s.syd1.au.unkin.net + parentRefs: + - group: gateway.networking.k8s.io + kind: Gateway + name: pdbmux + sectionName: http + rules: + - filters: + - type: RequestRedirect + requestRedirect: + scheme: https + statusCode: 301 + matches: + - path: + type: PathPrefix + value: / +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: pdbmux + namespace: pdbmux +spec: + hostnames: + - pdbmux.k8s.syd1.au.unkin.net + parentRefs: + - group: gateway.networking.k8s.io + kind: Gateway + name: pdbmux + sectionName: https + rules: + - backendRefs: + - group: "" + kind: Service + name: pdbmux + port: 80 + weight: 1 + matches: + - path: + type: PathPrefix + value: / diff --git a/apps/base/pdbmux/kustomization.yaml b/apps/base/pdbmux/kustomization.yaml new file mode 100644 index 0000000..372a7e3 --- /dev/null +++ b/apps/base/pdbmux/kustomization.yaml @@ -0,0 +1,11 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - namespace.yaml + - configmap.yaml + - deployment.yaml + - service.yaml + - gateway.yaml + - httproute.yaml diff --git a/apps/base/pdbmux/namespace.yaml b/apps/base/pdbmux/namespace.yaml new file mode 100644 index 0000000..12d2180 --- /dev/null +++ b/apps/base/pdbmux/namespace.yaml @@ -0,0 +1,5 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: pdbmux diff --git a/apps/base/pdbmux/service.yaml b/apps/base/pdbmux/service.yaml new file mode 100644 index 0000000..6b21ef2 --- /dev/null +++ b/apps/base/pdbmux/service.yaml @@ -0,0 +1,17 @@ +--- +apiVersion: v1 +kind: Service +metadata: + name: pdbmux + namespace: pdbmux +spec: + internalTrafficPolicy: Cluster + ports: + - name: http + port: 80 + protocol: TCP + targetPort: http + selector: + app: pdbmux + sessionAffinity: None + type: ClusterIP diff --git a/apps/overlays/au-syd1/pdbmux/kustomization.yaml b/apps/overlays/au-syd1/pdbmux/kustomization.yaml new file mode 100644 index 0000000..a9520c4 --- /dev/null +++ b/apps/overlays/au-syd1/pdbmux/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: + - ../../../base/pdbmux diff --git a/argocd/applicationsets/platform.yaml b/argocd/applicationsets/platform.yaml index 71b298d..28174aa 100644 --- a/argocd/applicationsets/platform.yaml +++ b/argocd/applicationsets/platform.yaml @@ -29,6 +29,7 @@ spec: - path: apps/overlays/*/jfrog - path: apps/overlays/*/kanidm - path: apps/overlays/*/node-feature-discovery + - path: apps/overlays/*/pdbmux - path: apps/overlays/*/priority-classes - path: apps/overlays/*/puppet - path: apps/overlays/*/purelb diff --git a/argocd/projects/platform.yaml b/argocd/projects/platform.yaml index db8f7df..ac32f91 100644 --- a/argocd/projects/platform.yaml +++ b/argocd/projects/platform.yaml @@ -39,6 +39,8 @@ spec: server: https://kubernetes.default.svc - namespace: 'node-feature-discovery' server: https://kubernetes.default.svc + - namespace: 'pdbmux' + server: https://kubernetes.default.svc - namespace: 'priority-classes' server: https://kubernetes.default.svc - namespace: 'purelb'