Give vlogs its own namespace (#507)
The Vault KV layout is kubernetes/namespace/<ns>/<sa>/<secret>, so vlogs and logviewer both running as SA default in the shared logging namespace would collide on one oauth-credentials entry. Splitting vlogs out resolves it without widening any Vault policy. - Move apps/base/logging/vlogs to apps/base/vlogs, namespace vlogs - Add namespace.yaml and a vlogs-scoped VaultAuth (role default) - Point the VaultStaticSecret at kubernetes/namespace/vlogs/default/oauth-credentials - Add the au-syd1 overlay, platform ApplicationSet path and project destination - Move the wildcard-unkin-net-tls reflection from logging to vlogs; vlogs was its only consumer there Secret is already seeded at the new Vault path. Reviewed-on: #507 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #507.
This commit is contained in:
@@ -14,9 +14,9 @@ spec:
|
|||||||
secretTemplate:
|
secretTemplate:
|
||||||
annotations:
|
annotations:
|
||||||
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,logging"
|
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,vlogs"
|
||||||
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,logging"
|
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,vlogs"
|
||||||
privateKey:
|
privateKey:
|
||||||
size: 4096
|
size: 4096
|
||||||
dnsNames:
|
dnsNames:
|
||||||
|
|||||||
@@ -9,4 +9,3 @@ resources:
|
|||||||
- vlagent.yaml
|
- vlagent.yaml
|
||||||
- gateway.yaml
|
- gateway.yaml
|
||||||
- httproute.yaml
|
- httproute.yaml
|
||||||
- vlogs
|
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ metadata:
|
|||||||
labels:
|
labels:
|
||||||
traefik.io/instance: external
|
traefik.io/instance: external
|
||||||
name: vlogs-external
|
name: vlogs-external
|
||||||
namespace: logging
|
namespace: vlogs
|
||||||
spec:
|
spec:
|
||||||
gatewayClassName: traefik-external
|
gatewayClassName: traefik-external
|
||||||
listeners:
|
listeners:
|
||||||
@@ -3,7 +3,7 @@ apiVersion: gateway.networking.k8s.io/v1
|
|||||||
kind: HTTPRoute
|
kind: HTTPRoute
|
||||||
metadata:
|
metadata:
|
||||||
name: vlogs-http-redirect
|
name: vlogs-http-redirect
|
||||||
namespace: logging
|
namespace: vlogs
|
||||||
spec:
|
spec:
|
||||||
hostnames:
|
hostnames:
|
||||||
- vlogs.unkin.net
|
- vlogs.unkin.net
|
||||||
@@ -27,7 +27,7 @@ apiVersion: gateway.networking.k8s.io/v1
|
|||||||
kind: HTTPRoute
|
kind: HTTPRoute
|
||||||
metadata:
|
metadata:
|
||||||
name: vlogs
|
name: vlogs
|
||||||
namespace: logging
|
namespace: vlogs
|
||||||
spec:
|
spec:
|
||||||
hostnames:
|
hostnames:
|
||||||
- vlogs.unkin.net
|
- vlogs.unkin.net
|
||||||
@@ -3,6 +3,8 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
|
|
||||||
resources:
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- vaultauth.yaml
|
||||||
- vaultstaticsecret.yaml
|
- vaultstaticsecret.yaml
|
||||||
- oauth2-proxy-configmap.yaml
|
- oauth2-proxy-configmap.yaml
|
||||||
- oauth2-proxy-deployment.yaml
|
- oauth2-proxy-deployment.yaml
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: vlogs
|
||||||
+1
-1
@@ -3,7 +3,7 @@ apiVersion: v1
|
|||||||
kind: ConfigMap
|
kind: ConfigMap
|
||||||
metadata:
|
metadata:
|
||||||
name: vlogs-oauth2-env
|
name: vlogs-oauth2-env
|
||||||
namespace: logging
|
namespace: vlogs
|
||||||
data:
|
data:
|
||||||
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
||||||
OAUTH2_PROXY_PROVIDER: "oidc"
|
OAUTH2_PROXY_PROVIDER: "oidc"
|
||||||
+1
-1
@@ -3,7 +3,7 @@ apiVersion: apps/v1
|
|||||||
kind: Deployment
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
name: vlogs-oauth2
|
name: vlogs-oauth2
|
||||||
namespace: logging
|
namespace: vlogs
|
||||||
annotations:
|
annotations:
|
||||||
configmap.reloader.stakater.com/auto: "true"
|
configmap.reloader.stakater.com/auto: "true"
|
||||||
secret.reloader.stakater.com/reload: "vlogs-oauth-credentials,vault-ca-cert"
|
secret.reloader.stakater.com/reload: "vlogs-oauth-credentials,vault-ca-cert"
|
||||||
@@ -5,7 +5,7 @@ apiVersion: v1
|
|||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
name: vlogs-oauth2
|
name: vlogs-oauth2
|
||||||
namespace: logging
|
namespace: vlogs
|
||||||
spec:
|
spec:
|
||||||
internalTrafficPolicy: Cluster
|
internalTrafficPolicy: Cluster
|
||||||
ports:
|
ports:
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
apiVersion: secrets.hashicorp.com/v1beta1
|
||||||
|
kind: VaultAuth
|
||||||
|
metadata:
|
||||||
|
name: default
|
||||||
|
namespace: vlogs
|
||||||
|
spec:
|
||||||
|
allowedNamespaces:
|
||||||
|
- vlogs
|
||||||
|
kubernetes:
|
||||||
|
audiences:
|
||||||
|
- vault
|
||||||
|
role: default
|
||||||
|
serviceAccount: default
|
||||||
|
tokenExpirationSeconds: 600
|
||||||
|
method: kubernetes
|
||||||
|
mount: k8s/au/syd1
|
||||||
|
vaultConnectionRef: vso-system/default
|
||||||
+2
-2
@@ -3,7 +3,7 @@ apiVersion: secrets.hashicorp.com/v1beta1
|
|||||||
kind: VaultStaticSecret
|
kind: VaultStaticSecret
|
||||||
metadata:
|
metadata:
|
||||||
name: vlogs-oauth-credentials
|
name: vlogs-oauth-credentials
|
||||||
namespace: logging
|
namespace: vlogs
|
||||||
spec:
|
spec:
|
||||||
destination:
|
destination:
|
||||||
create: true
|
create: true
|
||||||
@@ -11,7 +11,7 @@ spec:
|
|||||||
overwrite: true
|
overwrite: true
|
||||||
hmacSecretData: true
|
hmacSecretData: true
|
||||||
mount: kv
|
mount: kv
|
||||||
path: kubernetes/namespace/logging/default/vlogs-oauth-credentials
|
path: kubernetes/namespace/vlogs/default/oauth-credentials
|
||||||
refreshAfter: 5m
|
refreshAfter: 5m
|
||||||
type: kv-v2
|
type: kv-v2
|
||||||
vaultAuthRef: default
|
vaultAuthRef: default
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ../../../base/vlogs
|
||||||
@@ -49,6 +49,7 @@ spec:
|
|||||||
- path: apps/overlays/*/vm-system
|
- path: apps/overlays/*/vm-system
|
||||||
- path: apps/overlays/*/vpa-system
|
- path: apps/overlays/*/vpa-system
|
||||||
- path: apps/overlays/*/vault
|
- path: apps/overlays/*/vault
|
||||||
|
- path: apps/overlays/*/vlogs
|
||||||
- path: apps/overlays/*/vso-system
|
- path: apps/overlays/*/vso-system
|
||||||
- path: apps/overlays/*/woodpecker
|
- path: apps/overlays/*/woodpecker
|
||||||
template:
|
template:
|
||||||
|
|||||||
@@ -67,6 +67,8 @@ spec:
|
|||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: 'vault'
|
- namespace: 'vault'
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
|
- namespace: 'vlogs'
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
- namespace: 'woodpecker'
|
- namespace: 'woodpecker'
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
clusterResourceWhitelist:
|
clusterResourceWhitelist:
|
||||||
|
|||||||
Reference in New Issue
Block a user