Compare commits
6 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ff2309cc9f | |||
| 7960ee03f9 | |||
| 393100430b | |||
| 5024945c74 | |||
| 87880ac8ef | |||
| 7ac84461ce |
@@ -1,10 +1,10 @@
|
||||
# Conditional forward zones, from the puppet openforwarder view.
|
||||
# Upstreams: unkin authoritative 198.18.200.6, consul 198.18.19.14,
|
||||
# Upstreams: unkin authoritative 198.18.200.6, consul 198.18.200.5 (k8s consul DNS LB),
|
||||
# k8s 198.18.200.8 (in-cluster bind-externaldns VIP).
|
||||
# k8s -> in-cluster bind-externaldns 198.18.200.8 for both the forward zone
|
||||
# k8s.syd1.au.unkin.net and the reverse zone 200.18.198.in-addr.arpa, which
|
||||
# external-dns now publishes to (see the external-dns migration PRs).
|
||||
# (Zones that forwarded to 10.10.16.x were dropped; consul left as-is.)
|
||||
# (Zones that forwarded to 10.10.16.x were dropped.)
|
||||
---
|
||||
apiVersion: bind.unkin.net/v1alpha1
|
||||
kind: BindZone
|
||||
@@ -46,7 +46,7 @@ spec:
|
||||
type: forward
|
||||
catalog: false
|
||||
forwarders:
|
||||
- 198.18.19.14
|
||||
- 198.18.200.5
|
||||
---
|
||||
apiVersion: bind.unkin.net/v1alpha1
|
||||
kind: BindZone
|
||||
|
||||
@@ -11,7 +11,7 @@ metadata:
|
||||
argocd.argoproj.io/sync-wave: "1"
|
||||
spec:
|
||||
replicas: 1
|
||||
image: git.unkin.net/unkin/kea-api:v0.1.3
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/kea-api:v0.1.7
|
||||
tokenSecretName: kea-api-token
|
||||
service:
|
||||
type: ClusterIP
|
||||
|
||||
@@ -11,7 +11,7 @@ metadata:
|
||||
argocd.argoproj.io/sync-wave: "1"
|
||||
spec:
|
||||
replicas: 2
|
||||
image: git.unkin.net/unkin/kea:v0.1.3
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/kea:v0.1.7
|
||||
domainName: main.unkin.net
|
||||
defaultLeaseTime: 1200
|
||||
maxLeaseTime: 86400
|
||||
|
||||
@@ -21,7 +21,7 @@ spec:
|
||||
runAsNonRoot: true
|
||||
containers:
|
||||
- name: operator
|
||||
image: git.unkin.net/unkin/kea-operator:v0.1.5
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/kea-operator:v0.1.7
|
||||
args:
|
||||
- --metrics-bind-address=:8080
|
||||
- --health-probe-bind-address=:8081
|
||||
|
||||
@@ -1,16 +0,0 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- ../../../base/consul
|
||||
|
||||
helmCharts:
|
||||
- name: consul
|
||||
repo: https://helm.releases.hashicorp.com
|
||||
version: "1.9.7"
|
||||
releaseName: consul
|
||||
namespace: consul
|
||||
valuesFile: values.yaml
|
||||
apiVersions:
|
||||
- policy/v1/PodDisruptionBudget
|
||||
@@ -1,77 +0,0 @@
|
||||
global:
|
||||
name: consul
|
||||
datacenter: au-syd1
|
||||
domain: consul
|
||||
|
||||
acls:
|
||||
# Enable chart-managed ACL tokens/policies for Consul system components.
|
||||
manageSystemACLs: true
|
||||
# Source the bootstrap/management token from a pre-existing Kubernetes secret
|
||||
# instead of letting the chart generate one. The secret is synced from Vault
|
||||
# via VSO (see ../../../base/consul/vaultauth.yaml and vaultstaticsecret.yaml).
|
||||
# When this secret is populated the server-acl-init job SKIPS bootstrapping and
|
||||
# uses the supplied token as the management token, so the k8s cluster bootstraps
|
||||
# with the SAME initial_management token as the authoritative VM cluster.
|
||||
bootstrapToken:
|
||||
secretName: consul-bootstrap-acl-token
|
||||
secretKey: token
|
||||
|
||||
server:
|
||||
image: hashicorp/consul:1.22.7
|
||||
replicas: 5
|
||||
bootstrapExpect: 5
|
||||
storage: 10Gi
|
||||
storageClass: cephrbd-fast-delete
|
||||
|
||||
connect: true
|
||||
|
||||
disruptionBudget:
|
||||
maxUnavailable: 1
|
||||
|
||||
extraConfig: |
|
||||
{
|
||||
"acl": {
|
||||
"enabled": true,
|
||||
"default_policy": "deny",
|
||||
"down_policy": "extend-cache",
|
||||
"enable_token_persistence": true
|
||||
},
|
||||
"disable_remote_exec": true,
|
||||
"disable_update_check": true,
|
||||
"performance": {
|
||||
"raft_multiplier": 10
|
||||
},
|
||||
"ports": {
|
||||
"dns": 8600,
|
||||
"grpc": 8502,
|
||||
"http": 8500,
|
||||
"https": -1
|
||||
},
|
||||
"primary_datacenter": "au-syd1"
|
||||
}
|
||||
|
||||
resources:
|
||||
requests:
|
||||
memory: 256Mi
|
||||
cpu: 100m
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: "1"
|
||||
|
||||
client:
|
||||
enabled: false
|
||||
|
||||
ui:
|
||||
enabled: true
|
||||
service:
|
||||
type: ClusterIP
|
||||
|
||||
connectInject:
|
||||
enabled: false
|
||||
|
||||
dns:
|
||||
enabled: true
|
||||
type: LoadBalancer
|
||||
annotations: |
|
||||
purelb.io/service-group: "common"
|
||||
purelb.io/addresses: 198.18.200.5
|
||||
Reference in New Issue
Block a user