Compare commits

..

1 Commits

Author SHA1 Message Date
unkin-agent 797e1bc7bc kea-operator: bump to v0.1.6
Stop the operator's reconcile hot-loop, which was hot-reloading Kea about 9 times a second and flooding the dhcp-system logs.
2026-10-06 00:05:34 +11:00
6 changed files with 99 additions and 6 deletions
@@ -1,10 +1,10 @@
# Conditional forward zones, from the puppet openforwarder view.
# Upstreams: unkin authoritative 198.18.200.6, consul 198.18.200.5 (k8s consul DNS LB),
# Upstreams: unkin authoritative 198.18.200.6, consul 198.18.19.14,
# k8s 198.18.200.8 (in-cluster bind-externaldns VIP).
# k8s -> in-cluster bind-externaldns 198.18.200.8 for both the forward zone
# k8s.syd1.au.unkin.net and the reverse zone 200.18.198.in-addr.arpa, which
# external-dns now publishes to (see the external-dns migration PRs).
# (Zones that forwarded to 10.10.16.x were dropped.)
# (Zones that forwarded to 10.10.16.x were dropped; consul left as-is.)
---
apiVersion: bind.unkin.net/v1alpha1
kind: BindZone
@@ -46,7 +46,7 @@ spec:
type: forward
catalog: false
forwarders:
- 198.18.200.5
- 198.18.19.14
---
apiVersion: bind.unkin.net/v1alpha1
kind: BindZone
+1 -1
View File
@@ -11,7 +11,7 @@ metadata:
argocd.argoproj.io/sync-wave: "1"
spec:
replicas: 1
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/kea-api:v0.1.7
image: git.unkin.net/unkin/kea-api:v0.1.3
tokenSecretName: kea-api-token
service:
type: ClusterIP
+1 -1
View File
@@ -11,7 +11,7 @@ metadata:
argocd.argoproj.io/sync-wave: "1"
spec:
replicas: 2
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/kea:v0.1.7
image: git.unkin.net/unkin/kea:v0.1.3
domainName: main.unkin.net
defaultLeaseTime: 1200
maxLeaseTime: 86400
+1 -1
View File
@@ -21,7 +21,7 @@ spec:
runAsNonRoot: true
containers:
- name: operator
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/kea-operator:v0.1.7
image: git.unkin.net/unkin/kea-operator:v0.1.6
args:
- --metrics-bind-address=:8080
- --health-probe-bind-address=:8081
@@ -0,0 +1,16 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../../../base/consul
helmCharts:
- name: consul
repo: https://helm.releases.hashicorp.com
version: "1.9.7"
releaseName: consul
namespace: consul
valuesFile: values.yaml
apiVersions:
- policy/v1/PodDisruptionBudget
+77
View File
@@ -0,0 +1,77 @@
global:
name: consul
datacenter: au-syd1
domain: consul
acls:
# Enable chart-managed ACL tokens/policies for Consul system components.
manageSystemACLs: true
# Source the bootstrap/management token from a pre-existing Kubernetes secret
# instead of letting the chart generate one. The secret is synced from Vault
# via VSO (see ../../../base/consul/vaultauth.yaml and vaultstaticsecret.yaml).
# When this secret is populated the server-acl-init job SKIPS bootstrapping and
# uses the supplied token as the management token, so the k8s cluster bootstraps
# with the SAME initial_management token as the authoritative VM cluster.
bootstrapToken:
secretName: consul-bootstrap-acl-token
secretKey: token
server:
image: hashicorp/consul:1.22.7
replicas: 5
bootstrapExpect: 5
storage: 10Gi
storageClass: cephrbd-fast-delete
connect: true
disruptionBudget:
maxUnavailable: 1
extraConfig: |
{
"acl": {
"enabled": true,
"default_policy": "deny",
"down_policy": "extend-cache",
"enable_token_persistence": true
},
"disable_remote_exec": true,
"disable_update_check": true,
"performance": {
"raft_multiplier": 10
},
"ports": {
"dns": 8600,
"grpc": 8502,
"http": 8500,
"https": -1
},
"primary_datacenter": "au-syd1"
}
resources:
requests:
memory: 256Mi
cpu: 100m
limits:
memory: 2Gi
cpu: "1"
client:
enabled: false
ui:
enabled: true
service:
type: ClusterIP
connectInject:
enabled: false
dns:
enabled: true
type: LoadBalancer
annotations: |
purelb.io/service-group: "common"
purelb.io/addresses: 198.18.200.5