Compare commits

..

7 Commits

Author SHA1 Message Date
unkin-agent 1d9b7ec924 Add mail namespace with Stalwart backing stores (#538)
Stalwart needs a Postgres metadata store and an S3 blob store before it can be deployed into the new `mail` namespace.

- add CNPG Cluster `stalwart-db` (db/owner `stalwart`, CNPG-minted `stalwart-db-app` creds) with barman backups to a dedicated `cnpg-mail` bucket and a nightly ScheduledBackup
- add cephrgw Bucket `stalwart-blobs` with an owner user writing RW keys to `stalwart-blobs-s3`
- add the au-syd1 overlay, platform ApplicationSet path and project destination

Reviewed-on: #538
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-12 00:25:41 +11:00
unkin-agent fc7d69644c Add terraform-binarylane woodpecker service account (#537)
The new terraform-binarylane repo needs a Woodpecker ServiceAccount for its CI pipelines to authenticate to Vault.

- add serviceaccount_terraform_binarylane.yaml in the woodpecker namespace
- add it to the woodpecker base kustomization

Reviewed-on: #537
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-12 00:22:04 +11:00
unkin-agent 045c7ff009 Bump pdbmux to v0.5.0 (#536)
v0.5.0 answers AST name queries for pdbmux_source and reports the backend host as its value.

- bump pdbmux image to v0.5.0

Reviewed-on: #536
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-10 14:39:01 +11:00
unkin-agent 69f2a2a6ec add artifactapi image-keeper daemonset (#535)
artifactapi pulls its own images from itself, so a cold boot with every api pod down cannot pull them. Kubelet GC never removes images referenced by pods on the node, so a pod on every node holding the pinned tags keeps them local.

- add image-keeper DaemonSet referencing the api and ui images as no-op init containers
- run a static busybox as `true` inside the distroless api image
- tolerate all taints, run at low priority with tiny non-root resources

Reviewed-on: #535
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-10 01:06:10 +11:00
unkin-agent f89927b1f4 bump artifactapi to v3.13.1 (#534)
v3.13.1 adds rpm virtual repos, the cargo remote type and GitHub scan retry; its images now publish to docker-internal instead of the Gitea registry.

- pin api and ui to docker-internal/artifactapi{,-ui}:v3.13.1

Reviewed-on: #534
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-09 23:25:52 +11:00
unkin-agent 7960ee03f9 pin artifactapi back to v3.12.0 (#532)
The v3.13.0 images were never published (registry push failed), so the current pin cannot be pulled.

- pin api and ui images back to v3.12.0

Reviewed-on: #532
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-09 22:52:29 +11:00
unkin-agent 393100430b Bump artifactapi to v3.13.0 (#529)
Bump artifactapi API and UI images from v3.12.0 to v3.13.0.

- Update git.unkin.net/unkin/artifactapi to v3.13.0
- Update git.unkin.net/unkin/artifactapi-ui to v3.13.0

Reviewed-on: #529
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-09 22:48:05 +11:00
23 changed files with 340 additions and 394 deletions
+1 -1
View File
@@ -36,7 +36,7 @@ spec:
mountPath: /combined-certs mountPath: /combined-certs
containers: containers:
- name: api - name: api
image: git.unkin.net/unkin/artifactapi:v3.12.0 image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi:v3.13.1
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
ports: ports:
- containerPort: 8000 - containerPort: 8000
+105
View File
@@ -0,0 +1,105 @@
---
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: image-keeper
namespace: artifactapi
spec:
selector:
matchLabels:
app: image-keeper
updateStrategy:
rollingUpdate:
maxUnavailable: 25%
type: RollingUpdate
template:
metadata:
labels:
app: image-keeper
spec:
automountServiceAccountToken: false
priorityClassName: low
tolerations:
- operator: Exists
securityContext:
runAsNonRoot: true
runAsUser: 65532
runAsGroup: 65532
seccompProfile:
type: RuntimeDefault
initContainers:
# artifactapi is distroless with no exit-0 flag, so run a static busybox as `true`
- name: copy-true
image: busybox:1.37.0-musl
imagePullPolicy: IfNotPresent
command: ["cp", "/bin/busybox", "/keeper/true"]
volumeMounts:
- name: keeper
mountPath: /keeper
resources:
limits:
cpu: 10m
memory: 16Mi
requests:
cpu: 1m
memory: 4Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
- name: api
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi:v3.13.1
imagePullPolicy: IfNotPresent
command: ["/keeper/true"]
volumeMounts:
- name: keeper
mountPath: /keeper
readOnly: true
resources:
limits:
cpu: 10m
memory: 16Mi
requests:
cpu: 1m
memory: 4Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
- name: ui
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi-ui:v3.13.1
imagePullPolicy: IfNotPresent
command: ["true"]
resources:
limits:
cpu: 10m
memory: 16Mi
requests:
cpu: 1m
memory: 4Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
containers:
- name: pause
image: rancher/mirrored-pause:3.6
imagePullPolicy: IfNotPresent
resources:
limits:
cpu: 10m
memory: 16Mi
requests:
cpu: 1m
memory: 4Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
volumes:
- name: keeper
emptyDir: {}
+1
View File
@@ -11,6 +11,7 @@ resources:
- cnpg_pooler.yaml - cnpg_pooler.yaml
- gateway.yaml - gateway.yaml
- httproute.yaml - httproute.yaml
- image-keeper.yaml
- namespace.yaml - namespace.yaml
- oauth2-proxy-configmap.yaml - oauth2-proxy-configmap.yaml
- oauth2-proxy-deployment.yaml - oauth2-proxy-deployment.yaml
+1 -1
View File
@@ -22,7 +22,7 @@ spec:
automountServiceAccountToken: true automountServiceAccountToken: true
containers: containers:
- name: ui - name: ui
image: git.unkin.net/unkin/artifactapi-ui:v3.12.0 image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi-ui:v3.13.1
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
ports: ports:
- containerPort: 80 - containerPort: 80
+5 -8
View File
@@ -1,12 +1,7 @@
# consul (k8s) # consul (k8s)
Consul servers (plain StatefulSet, overlay `apps/overlays/au-syd1/consul`) that Consul server cluster (DC `au-syd1`), deployed via the HashiCorp helm chart with
join the VM datacenter `au-syd1` as extra raft voters. Pod `consul-server-N` ACLs enabled (`default_policy: deny`, parity with the VM cluster).
advertises its own purelb LB IP `198.18.200.(11+N)`; `consul-dns` serves DNS on
`198.18.200.5:53`. VSO renders the agent/default ACL tokens from
`kv/kubernetes/namespace/consul/default/server-acl` into `consul-server-acl`
(`acl-tokens.json`, hot-reloaded via `auto_reload_config`). Port 8501 serves
the `consul-server-tls` certificate.
## API access (ACL auth) ## API access (ACL auth)
@@ -15,7 +10,9 @@ The HTTP API and UI are served on port 8500 behind the gateway at
With ACLs enabled, requests beyond the anonymous policy require a token: With ACLs enabled, requests beyond the anonymous policy require a token:
```bash ```bash
# management token (the VM cluster's initial_management token): # management (bootstrap) token — seeded from Vault, synced by VSO into the
# consul-bootstrap-acl-token secret; same value as the VM cluster's
# initial_management token:
CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token) CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token)
curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader
+5 -2
View File
@@ -1,6 +1,9 @@
--- ---
# ClusterIP service targeting the consul server pods' HTTP API and UI (8500), # ClusterIP service targeting the consul server pods' HTTP API (8500).
# the Gateway's backend. # The HashiCorp chart only ships consul-ui (also 8500 via the server pods)
# and the headless consul-server; this named service gives the Gateway a
# stable API backend. Consul serves both the HTTP API and the UI (at /ui/)
# on this same port, so routing the API hostname here preserves the UI too.
apiVersion: v1 apiVersion: v1
kind: Service kind: Service
metadata: metadata:
+3 -11
View File
@@ -2,24 +2,16 @@
apiVersion: secrets.hashicorp.com/v1beta1 apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret kind: VaultStaticSecret
metadata: metadata:
name: server-acl name: bootstrap-acl-token
namespace: consul namespace: consul
spec: spec:
destination: destination:
create: true create: true
name: consul-server-acl name: consul-bootstrap-acl-token
overwrite: true overwrite: true
transformation:
excludeRaw: true
excludes:
- .*
templates:
acl-tokens.json:
text: >-
{"acl":{"tokens":{"agent":{{ get .Secrets "agent_token" | toJson }},"default":{{ get .Secrets "default_token" | toJson }}}}}
hmacSecretData: true hmacSecretData: true
mount: kv mount: kv
path: kubernetes/namespace/consul/default/server-acl path: kubernetes/namespace/consul/default/bootstrap-acl-token
refreshAfter: 5m refreshAfter: 5m
type: kv-v2 type: kv-v2
vaultAuthRef: default vaultAuthRef: default
+40
View File
@@ -0,0 +1,40 @@
---
apiVersion: ceph.unkin.net/v1alpha1
kind: ObjectStoreUser
metadata:
name: cnpg-mail-backup
namespace: mail
spec:
displayName: "CNPG backup owner (mail)"
uid: cnpg-mail-backup
maxBuckets: 5
secretName: cnpg-mail-backup-s3
retainOnDelete: true
---
apiVersion: ceph.unkin.net/v1alpha1
kind: Bucket
metadata:
name: cnpg-mail
namespace: mail
spec:
placementTarget: ec
bucketName: cnpg-mail
ownerRef: cnpg-mail-backup
versioning: false
tags:
app: mail
purpose: cnpg-backup
retainOnDelete: true
---
apiVersion: postgresql.cnpg.io/v1
kind: ScheduledBackup
metadata:
name: cnpg-mail-nightly
namespace: mail
spec:
schedule: "0 20 4 * * *"
immediate: false
backupOwnerReference: self
method: barmanObjectStore
cluster:
name: stalwart-db
+118
View File
@@ -0,0 +1,118 @@
---
# Stalwart metadata store. No bootstrap secret: CNPG mints stalwart-db-app
# (username/password/dbname/uri) for Stalwart to consume.
apiVersion: postgresql.cnpg.io/v1
kind: Cluster
metadata:
name: stalwart-db
namespace: mail
spec:
affinity:
podAntiAffinityType: preferred
backup:
retentionPolicy: 30d
barmanObjectStore:
destinationPath: s3://cnpg-mail
endpointURL: https://s3.ceph.unkin.net
endpointCA:
name: vault-ca-cert
key: ca.crt
s3Credentials:
accessKeyId:
name: cnpg-mail-backup-s3
key: AWS_ACCESS_KEY_ID
secretAccessKey:
name: cnpg-mail-backup-s3
key: AWS_SECRET_ACCESS_KEY
serverName: stalwart-db
data:
compression: bzip2
jobs: 2
wal:
compression: zstd
maxParallel: 2
bootstrap:
initdb:
database: stalwart
encoding: UTF8
localeCType: C
localeCollate: C
owner: stalwart
enablePDB: true
enableSuperuserAccess: false
failoverDelay: 0
imageName: ghcr.io/cloudnative-pg/postgresql:18.1-system-trixie
instances: 3
logLevel: info
maxSyncReplicas: 0
minSyncReplicas: 0
monitoring:
customQueriesConfigMap:
- key: queries
name: cnpg-default-monitoring
disableDefaultQueries: false
enablePodMonitor: false
postgresql:
parameters:
archive_mode: "on"
archive_timeout: 5min
dynamic_shared_memory_type: posix
effective_cache_size: 256MB
full_page_writes: "on"
hot_standby_feedback: "on"
log_destination: csvlog
log_directory: /controller/log
log_filename: postgres
log_rotation_age: "0"
log_rotation_size: "0"
log_truncate_on_rotation: "false"
logging_collector: "on"
max_connections: "200"
max_parallel_workers: "16"
max_replication_slots: "16"
max_worker_processes: "16"
pg_stat_statements.max: "10000"
pg_stat_statements.track: top
shared_buffers: 128MB
shared_memory_type: mmap
ssl_max_protocol_version: TLSv1.3
ssl_min_protocol_version: TLSv1.3
wal_keep_size: 256MB
wal_level: logical
wal_log_hints: "on"
wal_receiver_timeout: 5s
wal_sender_timeout: 5s
shared_preload_libraries:
- pg_stat_statements
syncReplicaElectionConstraint:
enabled: false
primaryUpdateMethod: restart
primaryUpdateStrategy: unsupervised
probes:
liveness:
isolationCheck:
connectionTimeout: 1000
enabled: true
requestTimeout: 1000
replicationSlots:
highAvailability:
enabled: true
slotPrefix: _cnpg_
synchronizeReplicas:
enabled: true
updateInterval: 30
resources:
limits:
cpu: "1"
memory: 1Gi
requests:
cpu: 50m
memory: 512Mi
smartShutdownTimeout: 180
startDelay: 3600
stopDelay: 1800
storage:
resizeInUseVolumes: true
size: 10Gi
storageClass: cephrbd-fast-delete
switchoverDelay: 3600
+9
View File
@@ -0,0 +1,9 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- cnpg_backup.yaml
- cnpg_cluster.yaml
- namespace.yaml
- stalwart-blobs-bucket.yaml
+5
View File
@@ -0,0 +1,5 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: mail
+30
View File
@@ -0,0 +1,30 @@
---
# Stalwart S3 blob store. The owner user has read-write on its own bucket; the
# operator mints AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / S3_ENDPOINT into
# stalwart-blobs-s3.
apiVersion: ceph.unkin.net/v1alpha1
kind: ObjectStoreUser
metadata:
name: stalwart-blobs
namespace: mail
spec:
displayName: "Stalwart blob store owner"
uid: mail-stalwart-blobs
maxBuckets: 5
secretName: stalwart-blobs-s3
retainOnDelete: true
---
apiVersion: ceph.unkin.net/v1alpha1
kind: Bucket
metadata:
name: stalwart-blobs
namespace: mail
spec:
placementTarget: ec
bucketName: stalwart-blobs
ownerRef: stalwart-blobs
versioning: false
tags:
app: stalwart
purpose: blob-store
retainOnDelete: true
+1 -1
View File
@@ -25,7 +25,7 @@ spec:
- name: pdbmux - name: pdbmux
# Image is published by the pdbmux repo's .woodpecker/docker.yaml on # Image is published by the pdbmux repo's .woodpecker/docker.yaml on
# a v* tag. It only exists after that tag is cut (see PR merge gates). # a v* tag. It only exists after that tag is cut (see PR merge gates).
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.4.0 image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.5.0
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
ports: ports:
- containerPort: 8080 - containerPort: 8080
+1
View File
@@ -20,6 +20,7 @@ resources:
- serviceaccount_repospawner_ci.yaml - serviceaccount_repospawner_ci.yaml
- serviceaccount_terraform_artifactapi.yaml - serviceaccount_terraform_artifactapi.yaml
- serviceaccount_terraform_authentik.yaml - serviceaccount_terraform_authentik.yaml
- serviceaccount_terraform_binarylane.yaml
- serviceaccount_terraform_enc.yaml - serviceaccount_terraform_enc.yaml
- serviceaccount_terraform_git.yaml - serviceaccount_terraform_git.yaml
- serviceaccount_terraform_netbox.yaml - serviceaccount_terraform_netbox.yaml
@@ -0,0 +1,6 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: terraform-binarylane
namespace: woodpecker
@@ -1,21 +0,0 @@
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: consul-server-tls
namespace: consul
spec:
secretName: consul-server-tls
issuerRef:
kind: ClusterIssuer
name: vault-issuer
commonName: consul.k8s.syd1.au.unkin.net
dnsNames:
- consul.service.consul
- consul.service.au-syd1.consul
- consul
- consul.k8s.syd1.au.unkin.net
- server.au-syd1.consul
privateKey:
algorithm: RSA
size: 4096
@@ -1,16 +0,0 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: consul
resources:
- ../../../base/consul
- statefulset.yaml
- services.yaml
- certificate.yaml
configMapGenerator:
- name: consul-server-config
files:
- server.json
-51
View File
@@ -1,51 +0,0 @@
{
"acl": {
"default_policy": "deny",
"down_policy": "extend-cache",
"enable_token_persistence": true,
"enabled": true
},
"auto_reload_config": true,
"bind_addr": "0.0.0.0",
"client_addr": "0.0.0.0",
"connect": {
"enabled": true
},
"datacenter": "au-syd1",
"disable_remote_exec": true,
"disable_update_check": true,
"leave_on_terminate": false,
"performance": {
"raft_multiplier": 10
},
"ports": {
"dns": 8600,
"grpc": 8502,
"http": 8500,
"https": 8501
},
"primary_datacenter": "au-syd1",
"retry_join": [
"198.18.200.11",
"198.18.200.12",
"198.18.200.13",
"198.18.200.14",
"198.18.200.15",
"ausyd1nxvm2005.main.unkin.net",
"ausyd1nxvm2006.main.unkin.net",
"ausyd1nxvm2007.main.unkin.net",
"ausyd1nxvm2008.main.unkin.net",
"ausyd1nxvm2009.main.unkin.net"
],
"server": true,
"tls": {
"https": {
"cert_file": "/consul/tls/tls.crt",
"key_file": "/consul/tls/tls.key",
"verify_incoming": false
}
},
"ui_config": {
"enabled": true
}
}
-151
View File
@@ -1,151 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: consul-server
namespace: consul
spec:
clusterIP: None
publishNotReadyAddresses: true
selector:
app: consul
component: server
release: consul
ports:
- {name: server, port: 8300, protocol: TCP}
- {name: serflan-tcp, port: 8301, protocol: TCP}
- {name: serflan-udp, port: 8301, protocol: UDP}
---
apiVersion: v1
kind: Service
metadata:
name: consul-dns
namespace: consul
annotations:
purelb.io/service-group: common
purelb.io/addresses: 198.18.200.5
spec:
type: LoadBalancer
externalTrafficPolicy: Local
selector:
app: consul
component: server
release: consul
ports:
- {name: dns-udp, port: 53, protocol: UDP, targetPort: 8600}
- {name: dns-tcp, port: 53, protocol: TCP, targetPort: 8600}
---
apiVersion: v1
kind: Service
metadata:
name: consul-server-0-lb
namespace: consul
annotations:
purelb.io/service-group: common
purelb.io/addresses: 198.18.200.11
spec:
type: LoadBalancer
externalTrafficPolicy: Local
publishNotReadyAddresses: true
selector:
statefulset.kubernetes.io/pod-name: consul-server-0
ports:
- {name: server, port: 8300, protocol: TCP}
- {name: serflan-tcp, port: 8301, protocol: TCP}
- {name: serflan-udp, port: 8301, protocol: UDP}
- {name: serfwan-tcp, port: 8302, protocol: TCP}
- {name: serfwan-udp, port: 8302, protocol: UDP}
- {name: http, port: 8500, protocol: TCP}
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
---
apiVersion: v1
kind: Service
metadata:
name: consul-server-1-lb
namespace: consul
annotations:
purelb.io/service-group: common
purelb.io/addresses: 198.18.200.12
spec:
type: LoadBalancer
externalTrafficPolicy: Local
publishNotReadyAddresses: true
selector:
statefulset.kubernetes.io/pod-name: consul-server-1
ports:
- {name: server, port: 8300, protocol: TCP}
- {name: serflan-tcp, port: 8301, protocol: TCP}
- {name: serflan-udp, port: 8301, protocol: UDP}
- {name: serfwan-tcp, port: 8302, protocol: TCP}
- {name: serfwan-udp, port: 8302, protocol: UDP}
- {name: http, port: 8500, protocol: TCP}
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
---
apiVersion: v1
kind: Service
metadata:
name: consul-server-2-lb
namespace: consul
annotations:
purelb.io/service-group: common
purelb.io/addresses: 198.18.200.13
spec:
type: LoadBalancer
externalTrafficPolicy: Local
publishNotReadyAddresses: true
selector:
statefulset.kubernetes.io/pod-name: consul-server-2
ports:
- {name: server, port: 8300, protocol: TCP}
- {name: serflan-tcp, port: 8301, protocol: TCP}
- {name: serflan-udp, port: 8301, protocol: UDP}
- {name: serfwan-tcp, port: 8302, protocol: TCP}
- {name: serfwan-udp, port: 8302, protocol: UDP}
- {name: http, port: 8500, protocol: TCP}
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
---
apiVersion: v1
kind: Service
metadata:
name: consul-server-3-lb
namespace: consul
annotations:
purelb.io/service-group: common
purelb.io/addresses: 198.18.200.14
spec:
type: LoadBalancer
externalTrafficPolicy: Local
publishNotReadyAddresses: true
selector:
statefulset.kubernetes.io/pod-name: consul-server-3
ports:
- {name: server, port: 8300, protocol: TCP}
- {name: serflan-tcp, port: 8301, protocol: TCP}
- {name: serflan-udp, port: 8301, protocol: UDP}
- {name: serfwan-tcp, port: 8302, protocol: TCP}
- {name: serfwan-udp, port: 8302, protocol: UDP}
- {name: http, port: 8500, protocol: TCP}
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
---
apiVersion: v1
kind: Service
metadata:
name: consul-server-4-lb
namespace: consul
annotations:
purelb.io/service-group: common
purelb.io/addresses: 198.18.200.15
spec:
type: LoadBalancer
externalTrafficPolicy: Local
publishNotReadyAddresses: true
selector:
statefulset.kubernetes.io/pod-name: consul-server-4
ports:
- {name: server, port: 8300, protocol: TCP}
- {name: serflan-tcp, port: 8301, protocol: TCP}
- {name: serflan-udp, port: 8301, protocol: UDP}
- {name: serfwan-tcp, port: 8302, protocol: TCP}
- {name: serfwan-udp, port: 8302, protocol: UDP}
- {name: http, port: 8500, protocol: TCP}
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
@@ -1,131 +0,0 @@
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: consul-server
namespace: consul
labels:
app: consul
component: server
release: consul
spec:
serviceName: consul-server
replicas: 1
minReadySeconds: 30
podManagementPolicy: OrderedReady
selector:
matchLabels:
app: consul
component: server
release: consul
template:
metadata:
labels:
app: consul
component: server
release: consul
spec:
terminationGracePeriodSeconds: 30
securityContext:
runAsUser: 100
runAsGroup: 1000
runAsNonRoot: true
fsGroup: 1000
affinity:
podAntiAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- labelSelector:
matchLabels:
app: consul
component: server
topologyKey: kubernetes.io/hostname
containers:
- name: consul
image: hashicorp/consul:1.22.7
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: [ALL]
command:
- /bin/sh
- -ec
# ponytail: contiguous .11-.15 block
- >-
exec consul agent
-config-dir=/consul/config
-config-dir=/consul/acl
-data-dir=/consul/data
-node="${HOSTNAME}"
-advertise="198.18.200.$((11 + ${HOSTNAME##*-}))"
ports:
- {name: server, containerPort: 8300, protocol: TCP}
- {name: serflan-tcp, containerPort: 8301, protocol: TCP}
- {name: serflan-udp, containerPort: 8301, protocol: UDP}
- {name: serfwan-tcp, containerPort: 8302, protocol: TCP}
- {name: serfwan-udp, containerPort: 8302, protocol: UDP}
- {name: http, containerPort: 8500, protocol: TCP}
- {name: https, containerPort: 8501, protocol: TCP}
- {name: grpc, containerPort: 8502, protocol: TCP}
- {name: dns-tcp, containerPort: 8600, protocol: TCP}
- {name: dns-udp, containerPort: 8600, protocol: UDP}
readinessProbe:
exec:
command:
- /bin/sh
- -c
- wget -qO- http://127.0.0.1:8500/v1/status/leader | grep -q ':8300'
initialDelaySeconds: 5
periodSeconds: 10
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: "1"
memory: 2Gi
volumeMounts:
- name: data
mountPath: /consul/data
- name: config
mountPath: /consul/config
readOnly: true
- name: acl
mountPath: /consul/acl
readOnly: true
- name: tls
mountPath: /consul/tls
readOnly: true
volumes:
- name: config
configMap:
name: consul-server-config
- name: acl
secret:
secretName: consul-server-acl
defaultMode: 0440
- name: tls
secret:
secretName: consul-server-tls
volumeClaimTemplates:
- metadata:
name: data
spec:
accessModes:
- ReadWriteOnce
storageClassName: cephrbd-fast-retain
resources:
requests:
storage: 10Gi
---
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: consul-server
namespace: consul
spec:
maxUnavailable: 1
selector:
matchLabels:
app: consul
component: server
release: consul
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../../../base/mail
+1
View File
@@ -34,6 +34,7 @@ spec:
- path: apps/overlays/*/jfrog - path: apps/overlays/*/jfrog
- path: apps/overlays/*/k8up-system - path: apps/overlays/*/k8up-system
- path: apps/overlays/*/kanidm - path: apps/overlays/*/kanidm
- path: apps/overlays/*/mail
- path: apps/overlays/*/netbox - path: apps/overlays/*/netbox
- path: apps/overlays/*/node-feature-discovery - path: apps/overlays/*/node-feature-discovery
- path: apps/overlays/*/pdbmux - path: apps/overlays/*/pdbmux
+2
View File
@@ -49,6 +49,8 @@ spec:
server: https://kubernetes.default.svc server: https://kubernetes.default.svc
- namespace: 'kanidm' - namespace: 'kanidm'
server: https://kubernetes.default.svc server: https://kubernetes.default.svc
- namespace: 'mail'
server: https://kubernetes.default.svc
- namespace: 'netbox' - namespace: 'netbox'
server: https://kubernetes.default.svc server: https://kubernetes.default.svc
- namespace: 'node-feature-discovery' - namespace: 'node-feature-discovery'