Give vlogs its own namespace (#507)

The Vault KV layout is kubernetes/namespace/<ns>/<sa>/<secret>, so vlogs and logviewer both running as SA default in the shared logging namespace would collide on one oauth-credentials entry. Splitting vlogs out resolves it without widening any Vault policy.

- Move apps/base/logging/vlogs to apps/base/vlogs, namespace vlogs
- Add namespace.yaml and a vlogs-scoped VaultAuth (role default)
- Point the VaultStaticSecret at kubernetes/namespace/vlogs/default/oauth-credentials
- Add the au-syd1 overlay, platform ApplicationSet path and project destination
- Move the wildcard-unkin-net-tls reflection from logging to vlogs; vlogs was its only consumer there

Secret is already seeded at the new Vault path.

Reviewed-on: #507
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #507.
This commit is contained in:
2026-09-28 22:55:28 +10:00
committed by BenVincent
parent c979579c50
commit e6e882abfc
14 changed files with 44 additions and 11 deletions
@@ -14,9 +14,9 @@ spec:
secretTemplate: secretTemplate:
annotations: annotations:
reflector.v1.k8s.emberstack.com/reflection-allowed: "true" reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,logging" reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,vlogs"
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true" reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,logging" reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,vlogs"
privateKey: privateKey:
size: 4096 size: 4096
dnsNames: dnsNames:
-1
View File
@@ -9,4 +9,3 @@ resources:
- vlagent.yaml - vlagent.yaml
- gateway.yaml - gateway.yaml
- httproute.yaml - httproute.yaml
- vlogs
@@ -12,7 +12,7 @@ metadata:
labels: labels:
traefik.io/instance: external traefik.io/instance: external
name: vlogs-external name: vlogs-external
namespace: logging namespace: vlogs
spec: spec:
gatewayClassName: traefik-external gatewayClassName: traefik-external
listeners: listeners:
@@ -3,7 +3,7 @@ apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute kind: HTTPRoute
metadata: metadata:
name: vlogs-http-redirect name: vlogs-http-redirect
namespace: logging namespace: vlogs
spec: spec:
hostnames: hostnames:
- vlogs.unkin.net - vlogs.unkin.net
@@ -27,7 +27,7 @@ apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute kind: HTTPRoute
metadata: metadata:
name: vlogs name: vlogs
namespace: logging namespace: vlogs
spec: spec:
hostnames: hostnames:
- vlogs.unkin.net - vlogs.unkin.net
@@ -3,6 +3,8 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- namespace.yaml
- vaultauth.yaml
- vaultstaticsecret.yaml - vaultstaticsecret.yaml
- oauth2-proxy-configmap.yaml - oauth2-proxy-configmap.yaml
- oauth2-proxy-deployment.yaml - oauth2-proxy-deployment.yaml
+5
View File
@@ -0,0 +1,5 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: vlogs
@@ -3,7 +3,7 @@ apiVersion: v1
kind: ConfigMap kind: ConfigMap
metadata: metadata:
name: vlogs-oauth2-env name: vlogs-oauth2-env
namespace: logging namespace: vlogs
data: data:
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180" OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
OAUTH2_PROXY_PROVIDER: "oidc" OAUTH2_PROXY_PROVIDER: "oidc"
@@ -3,7 +3,7 @@ apiVersion: apps/v1
kind: Deployment kind: Deployment
metadata: metadata:
name: vlogs-oauth2 name: vlogs-oauth2
namespace: logging namespace: vlogs
annotations: annotations:
configmap.reloader.stakater.com/auto: "true" configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "vlogs-oauth-credentials,vault-ca-cert" secret.reloader.stakater.com/reload: "vlogs-oauth-credentials,vault-ca-cert"
@@ -5,7 +5,7 @@ apiVersion: v1
kind: Service kind: Service
metadata: metadata:
name: vlogs-oauth2 name: vlogs-oauth2
namespace: logging namespace: vlogs
spec: spec:
internalTrafficPolicy: Cluster internalTrafficPolicy: Cluster
ports: ports:
+18
View File
@@ -0,0 +1,18 @@
---
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultAuth
metadata:
name: default
namespace: vlogs
spec:
allowedNamespaces:
- vlogs
kubernetes:
audiences:
- vault
role: default
serviceAccount: default
tokenExpirationSeconds: 600
method: kubernetes
mount: k8s/au/syd1
vaultConnectionRef: vso-system/default
@@ -3,7 +3,7 @@ apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret kind: VaultStaticSecret
metadata: metadata:
name: vlogs-oauth-credentials name: vlogs-oauth-credentials
namespace: logging namespace: vlogs
spec: spec:
destination: destination:
create: true create: true
@@ -11,7 +11,7 @@ spec:
overwrite: true overwrite: true
hmacSecretData: true hmacSecretData: true
mount: kv mount: kv
path: kubernetes/namespace/logging/default/vlogs-oauth-credentials path: kubernetes/namespace/vlogs/default/oauth-credentials
refreshAfter: 5m refreshAfter: 5m
type: kv-v2 type: kv-v2
vaultAuthRef: default vaultAuthRef: default
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../../../base/vlogs
+1
View File
@@ -49,6 +49,7 @@ spec:
- path: apps/overlays/*/vm-system - path: apps/overlays/*/vm-system
- path: apps/overlays/*/vpa-system - path: apps/overlays/*/vpa-system
- path: apps/overlays/*/vault - path: apps/overlays/*/vault
- path: apps/overlays/*/vlogs
- path: apps/overlays/*/vso-system - path: apps/overlays/*/vso-system
- path: apps/overlays/*/woodpecker - path: apps/overlays/*/woodpecker
template: template:
+2
View File
@@ -67,6 +67,8 @@ spec:
server: https://kubernetes.default.svc server: https://kubernetes.default.svc
- namespace: 'vault' - namespace: 'vault'
server: https://kubernetes.default.svc server: https://kubernetes.default.svc
- namespace: 'vlogs'
server: https://kubernetes.default.svc
- namespace: 'woodpecker' - namespace: 'woodpecker'
server: https://kubernetes.default.svc server: https://kubernetes.default.svc
clusterResourceWhitelist: clusterResourceWhitelist: