Compare commits
17 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 216b1d72ac | |||
| 7581578df1 | |||
| 6515e7f637 | |||
| 90d512fadf | |||
| 757ae5b240 | |||
| 02f877540c | |||
| 148dac8ca2 | |||
| 53e5846c18 | |||
| 9fed5decc8 | |||
| 20077f1029 | |||
| 426a399f31 | |||
| 5341253573 | |||
| d48125d699 | |||
| abf6bfae88 | |||
| 4190785389 | |||
| 812a9a2f2b | |||
| f37749523d |
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ns1.yaml
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: acme-ns1-a
|
||||||
|
namespace: bind-external
|
||||||
|
spec:
|
||||||
|
zoneRef: acme-unkin-net
|
||||||
|
name: ns1
|
||||||
|
type: A
|
||||||
|
ttl: 3600
|
||||||
|
values:
|
||||||
|
# Public address of this cluster's external BIND, same target as
|
||||||
|
# acme-ns1.unkin.net. Resolvers that cached the seeded ns1.acme.unkin.net
|
||||||
|
# NS name must still reach the zone.
|
||||||
|
- 103.216.191.185
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
# Authoritative delegation records for acme.unkin.net. Without these the zone
|
||||||
|
# only holds the operator's seed apex (NS ns1.acme.unkin.net glued to the
|
||||||
|
# primary pod IP), which is unroutable off-cluster and goes stale on
|
||||||
|
# reschedule. DNSRecords must live in the same namespace as their BindZone.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ns
|
||||||
|
- a
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: acme-apex-ns
|
||||||
|
namespace: bind-external
|
||||||
|
spec:
|
||||||
|
zoneRef: acme-unkin-net
|
||||||
|
# "@" is the zone apex.
|
||||||
|
name: "@"
|
||||||
|
type: NS
|
||||||
|
ttl: 3600
|
||||||
|
values:
|
||||||
|
# Matches the parent delegation in Google Cloud DNS. Out of zone, so the
|
||||||
|
# child needs no glue of its own.
|
||||||
|
- acme-ns1.unkin.net.
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- apex.yaml
|
||||||
@@ -7,4 +7,5 @@ resources:
|
|||||||
- cluster.yaml
|
- cluster.yaml
|
||||||
- tsigkey.yaml
|
- tsigkey.yaml
|
||||||
- zones.yaml
|
- zones.yaml
|
||||||
|
- acme-unkin-net
|
||||||
- agent-dns-rolebinding.yaml
|
- agent-dns-rolebinding.yaml
|
||||||
|
|||||||
@@ -17,3 +17,14 @@ spec:
|
|||||||
updateKeyRef: certmanager
|
updateKeyRef: certmanager
|
||||||
allowTransfer:
|
allowTransfer:
|
||||||
- key certmanager
|
- key certmanager
|
||||||
|
# Published apex NS. acme-ns1 is what the parent delegates to and glues; ns1 is
|
||||||
|
# in-zone, so its address is declared below or a reseed would glue it to the
|
||||||
|
# primary pod IP.
|
||||||
|
nameservers:
|
||||||
|
- acme-ns1.unkin.net.
|
||||||
|
- ns1.acme.unkin.net.
|
||||||
|
records:
|
||||||
|
- name: ns1
|
||||||
|
type: A
|
||||||
|
ttl: 3600
|
||||||
|
values: ["103.216.191.185"]
|
||||||
|
|||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: dashboard-ceph-cname
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: ceph-unkin-net
|
||||||
|
name: dashboard
|
||||||
|
type: CNAME
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# Ceph mgr dashboard, reached via lb1. Lets in-cluster clients (the
|
||||||
|
# cephrgw-operator) resolve dashboard.ceph.unkin.net.
|
||||||
|
- lb1.unkin.net.
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- dashboard.yaml
|
||||||
|
- s3.yaml
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: s3-ceph-cname
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: ceph-unkin-net
|
||||||
|
name: s3
|
||||||
|
type: CNAME
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# radosgw S3 endpoint. Points at the Consul service for now; the real
|
||||||
|
# target will be changed later.
|
||||||
|
- radosgw.service.consul.
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- cname
|
||||||
@@ -2,9 +2,14 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
|
|
||||||
|
# Individually-managed authoritative records live under <zone>/<type>/<record>.yaml.
|
||||||
|
# DNSRecords must live in the same namespace as their BindZone (the operator
|
||||||
|
# resolves zoneRef/clusterRef/updateKeyRef within the record's namespace), so
|
||||||
|
# these sit alongside the zone in bind-internal, not in the app namespace.
|
||||||
resources:
|
resources:
|
||||||
- cluster.yaml
|
- cluster.yaml
|
||||||
- tsigkey.yaml
|
- tsigkey.yaml
|
||||||
- zones.yaml
|
- zones.yaml
|
||||||
- records.yaml
|
- unkin-net
|
||||||
|
- ceph-unkin-net
|
||||||
- acls.yaml
|
- acls.yaml
|
||||||
|
|||||||
@@ -1,164 +0,0 @@
|
|||||||
# Individually-managed authoritative records for the unkin.net zone.
|
|
||||||
# DNSRecords must live in the same namespace as their BindZone (the operator
|
|
||||||
# resolves zoneRef/clusterRef/updateKeyRef within the record's namespace), so
|
|
||||||
# these sit alongside the zone in bind-internal, not in the app namespace.
|
|
||||||
---
|
|
||||||
apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
kind: DNSRecord
|
|
||||||
metadata:
|
|
||||||
# "internal" in the name distinguishes this from the external DNS that
|
|
||||||
# Authentik will manage its own records from later.
|
|
||||||
name: identity-dns-internal
|
|
||||||
namespace: bind-internal
|
|
||||||
spec:
|
|
||||||
zoneRef: unkin-net
|
|
||||||
name: identity
|
|
||||||
type: A
|
|
||||||
ttl: 600
|
|
||||||
values:
|
|
||||||
# traefik-EXTERNAL (DMZ) gateway VIP; the authentik Gateway serves the
|
|
||||||
# identity.unkin.net hostname there.
|
|
||||||
- 198.18.199.0
|
|
||||||
---
|
|
||||||
# PRODUCTION CUTOVER RECORD — intentionally commented out.
|
|
||||||
# git.unkin.net currently resolves to the LIVE VM forge (HAProxy VRRP VIP
|
|
||||||
# 198.18.19.17), which holds every repo the estate depends on. Uncommenting this
|
|
||||||
# repoints the whole org's git.unkin.net at the new k8s Gitea gateway VIP, so it
|
|
||||||
# is the FINAL step of the forge migration — gated on the data migration (gitea
|
|
||||||
# dump/restore + SECRET_KEY copy) in argocd-apps docs/gitea-migration.md.
|
|
||||||
# NOTE: the live git.unkin.net answer is served by the puppet DNS master today
|
|
||||||
# (profiles::dns::master, records from PuppetDB); this k8s apex zone holds only
|
|
||||||
# SOA+NS + a few DNSRecords so far. Confirm the k8s bind cluster is the live
|
|
||||||
# authority for unkin.net (or update the puppet record instead) before relying
|
|
||||||
# on this CR at cutover.
|
|
||||||
# ---
|
|
||||||
# apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
# kind: DNSRecord
|
|
||||||
# metadata:
|
|
||||||
# name: git-dns-internal
|
|
||||||
# namespace: bind-internal
|
|
||||||
# spec:
|
|
||||||
# zoneRef: unkin-net
|
|
||||||
# name: git
|
|
||||||
# type: A
|
|
||||||
# ttl: 600
|
|
||||||
# values:
|
|
||||||
# # traefik-internal gateway VIP; the gitea Gateway serves git.unkin.net there.
|
|
||||||
# - 198.18.200.4
|
|
||||||
---
|
|
||||||
apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
kind: DNSRecord
|
|
||||||
metadata:
|
|
||||||
name: s3-ceph-cname
|
|
||||||
namespace: bind-internal
|
|
||||||
spec:
|
|
||||||
zoneRef: ceph-unkin-net
|
|
||||||
name: s3
|
|
||||||
type: CNAME
|
|
||||||
ttl: 600
|
|
||||||
values:
|
|
||||||
# radosgw S3 endpoint. Points at the Consul service for now; the real
|
|
||||||
# target will be changed later.
|
|
||||||
- radosgw.service.consul.
|
|
||||||
---
|
|
||||||
apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
kind: DNSRecord
|
|
||||||
metadata:
|
|
||||||
name: dashboard-ceph-cname
|
|
||||||
namespace: bind-internal
|
|
||||||
spec:
|
|
||||||
zoneRef: ceph-unkin-net
|
|
||||||
name: dashboard
|
|
||||||
type: CNAME
|
|
||||||
ttl: 600
|
|
||||||
values:
|
|
||||||
# Ceph mgr dashboard, reached via lb1. Lets in-cluster clients (the
|
|
||||||
# cephrgw-operator) resolve dashboard.ceph.unkin.net.
|
|
||||||
- lb1.unkin.net.
|
|
||||||
---
|
|
||||||
apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
kind: DNSRecord
|
|
||||||
metadata:
|
|
||||||
name: lb1-unkin-net
|
|
||||||
namespace: bind-internal
|
|
||||||
spec:
|
|
||||||
zoneRef: unkin-net
|
|
||||||
name: lb1
|
|
||||||
type: A
|
|
||||||
ttl: 600
|
|
||||||
values:
|
|
||||||
- 103.216.191.185
|
|
||||||
---
|
|
||||||
apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
kind: DNSRecord
|
|
||||||
metadata:
|
|
||||||
name: ghp-dns-internal
|
|
||||||
namespace: bind-internal
|
|
||||||
spec:
|
|
||||||
zoneRef: unkin-net
|
|
||||||
name: ghp
|
|
||||||
type: A
|
|
||||||
ttl: 600
|
|
||||||
values:
|
|
||||||
# traefik-internal gateway VIP; the ghp Gateway serves ghp.unkin.net there.
|
|
||||||
- 198.18.200.4
|
|
||||||
---
|
|
||||||
apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
kind: DNSRecord
|
|
||||||
metadata:
|
|
||||||
name: arrstack-dns-internal
|
|
||||||
namespace: bind-internal
|
|
||||||
spec:
|
|
||||||
zoneRef: unkin-net
|
|
||||||
name: arrstack
|
|
||||||
type: A
|
|
||||||
ttl: 600
|
|
||||||
values:
|
|
||||||
# traefik-EXTERNAL (DMZ) gateway VIP; the arrproxy Gateway serves the
|
|
||||||
# arrstack.unkin.net front door (oauth2-proxy) there.
|
|
||||||
- 198.18.199.0
|
|
||||||
---
|
|
||||||
apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
kind: DNSRecord
|
|
||||||
metadata:
|
|
||||||
name: logviewer-dns-internal
|
|
||||||
namespace: bind-internal
|
|
||||||
spec:
|
|
||||||
zoneRef: unkin-net
|
|
||||||
name: logviewer
|
|
||||||
type: A
|
|
||||||
ttl: 600
|
|
||||||
values:
|
|
||||||
# traefik-internal gateway VIP; the logviewer Gateway serves
|
|
||||||
# logviewer.unkin.net there.
|
|
||||||
- 198.18.200.4
|
|
||||||
---
|
|
||||||
apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
kind: DNSRecord
|
|
||||||
metadata:
|
|
||||||
name: cheeztv-dns-internal
|
|
||||||
namespace: bind-internal
|
|
||||||
spec:
|
|
||||||
zoneRef: unkin-net
|
|
||||||
name: cheeztv
|
|
||||||
type: A
|
|
||||||
ttl: 600
|
|
||||||
values:
|
|
||||||
# traefik-internal gateway VIP; the cheeztv Gateway serves cheeztv.unkin.net
|
|
||||||
# there.
|
|
||||||
- 198.18.200.4
|
|
||||||
---
|
|
||||||
apiVersion: bind.unkin.net/v1alpha1
|
|
||||||
kind: DNSRecord
|
|
||||||
metadata:
|
|
||||||
name: watchstate-dns-internal
|
|
||||||
namespace: bind-internal
|
|
||||||
spec:
|
|
||||||
zoneRef: unkin-net
|
|
||||||
name: watchstate
|
|
||||||
type: A
|
|
||||||
ttl: 600
|
|
||||||
values:
|
|
||||||
# traefik-EXTERNAL (DMZ) gateway VIP; the watchstate-external Gateway serves
|
|
||||||
# the watchstate.unkin.net front door (oauth2-proxy) there.
|
|
||||||
- 198.18.199.0
|
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: arrstack-dns-internal
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: unkin-net
|
||||||
|
name: arrstack
|
||||||
|
type: A
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# traefik-EXTERNAL (DMZ) gateway VIP; the arrproxy Gateway serves the
|
||||||
|
# arrstack.unkin.net front door (oauth2-proxy) there.
|
||||||
|
- 198.18.199.0
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: cheeztv-dns-internal
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: unkin-net
|
||||||
|
name: cheeztv
|
||||||
|
type: A
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# traefik-internal gateway VIP; the cheeztv Gateway serves cheeztv.unkin.net
|
||||||
|
# there.
|
||||||
|
- 198.18.200.4
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: ghp-dns-internal
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: unkin-net
|
||||||
|
name: ghp
|
||||||
|
type: A
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# traefik-internal gateway VIP; the ghp Gateway serves ghp.unkin.net there.
|
||||||
|
- 198.18.200.4
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
---
|
||||||
|
# PRODUCTION CUTOVER RECORD — intentionally commented out.
|
||||||
|
# git.unkin.net currently resolves to the LIVE VM forge (HAProxy VRRP VIP
|
||||||
|
# 198.18.19.17), which holds every repo the estate depends on. Uncommenting this
|
||||||
|
# repoints the whole org's git.unkin.net at the new k8s Gitea gateway VIP, so it
|
||||||
|
# is the FINAL step of the forge migration — gated on the data migration (gitea
|
||||||
|
# dump/restore + SECRET_KEY copy) in argocd-apps docs/gitea-migration.md.
|
||||||
|
# NOTE: the live git.unkin.net answer is served by the puppet DNS master today
|
||||||
|
# (profiles::dns::master, records from PuppetDB); this k8s apex zone holds only
|
||||||
|
# SOA+NS + a few DNSRecords so far. Confirm the k8s bind cluster is the live
|
||||||
|
# authority for unkin.net (or update the puppet record instead) before relying
|
||||||
|
# on this CR at cutover.
|
||||||
|
# Uncomment this record AND its entry in kustomization.yaml to activate it.
|
||||||
|
# ---
|
||||||
|
# apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
# kind: DNSRecord
|
||||||
|
# metadata:
|
||||||
|
# name: git-dns-internal
|
||||||
|
# namespace: bind-internal
|
||||||
|
# spec:
|
||||||
|
# zoneRef: unkin-net
|
||||||
|
# name: git
|
||||||
|
# type: A
|
||||||
|
# ttl: 600
|
||||||
|
# values:
|
||||||
|
# # traefik-internal gateway VIP; the gitea Gateway serves git.unkin.net there.
|
||||||
|
# - 198.18.200.4
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
# "internal" in the name distinguishes this from the external DNS that
|
||||||
|
# Authentik will manage its own records from later.
|
||||||
|
name: identity-dns-internal
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: unkin-net
|
||||||
|
name: identity
|
||||||
|
type: A
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# traefik-EXTERNAL (DMZ) gateway VIP; the authentik Gateway serves the
|
||||||
|
# identity.unkin.net hostname there.
|
||||||
|
- 198.18.199.0
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- arrstack.yaml
|
||||||
|
- cheeztv.yaml
|
||||||
|
# PRODUCTION CUTOVER RECORD — see git.yaml. Uncomment together with the
|
||||||
|
# record itself.
|
||||||
|
# - git.yaml
|
||||||
|
- ghp.yaml
|
||||||
|
- identity.yaml
|
||||||
|
- lb1.yaml
|
||||||
|
- logviewer.yaml
|
||||||
|
- vlogs.yaml
|
||||||
|
- watchstate.yaml
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: lb1-unkin-net
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: unkin-net
|
||||||
|
name: lb1
|
||||||
|
type: A
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
- 103.216.191.185
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: logviewer-dns-internal
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: unkin-net
|
||||||
|
name: logviewer
|
||||||
|
type: A
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# traefik-internal gateway VIP; the logviewer Gateway serves
|
||||||
|
# logviewer.unkin.net there.
|
||||||
|
- 198.18.200.4
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: vlogs-dns-internal
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: unkin-net
|
||||||
|
name: vlogs
|
||||||
|
type: A
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# traefik-EXTERNAL (DMZ) gateway VIP; the vlogs-external Gateway serves the
|
||||||
|
# vlogs.unkin.net front door (oauth2-proxy) there.
|
||||||
|
- 198.18.199.0
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bind.unkin.net/v1alpha1
|
||||||
|
kind: DNSRecord
|
||||||
|
metadata:
|
||||||
|
name: watchstate-dns-internal
|
||||||
|
namespace: bind-internal
|
||||||
|
spec:
|
||||||
|
zoneRef: unkin-net
|
||||||
|
name: watchstate
|
||||||
|
type: A
|
||||||
|
ttl: 600
|
||||||
|
values:
|
||||||
|
# traefik-EXTERNAL (DMZ) gateway VIP; the watchstate-external Gateway serves
|
||||||
|
# the watchstate.unkin.net front door (oauth2-proxy) there.
|
||||||
|
- 198.18.199.0
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- a
|
||||||
@@ -21,7 +21,7 @@ spec:
|
|||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
containers:
|
containers:
|
||||||
- name: operator
|
- name: operator
|
||||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.2.7
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.3.0
|
||||||
args:
|
args:
|
||||||
- --metrics-bind-address=:8080
|
- --metrics-bind-address=:8080
|
||||||
- --health-probe-bind-address=:8081
|
- --health-probe-bind-address=:8081
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ resources:
|
|||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
# CRDs are pulled from the bind-operator repo at the matching tag rather than
|
# CRDs are pulled from the bind-operator repo at the matching tag rather than
|
||||||
# vendored here, so they never drift from the operator.
|
# vendored here, so they never drift from the operator.
|
||||||
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.7/config/crd/install.yaml
|
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.3.0/config/crd/install.yaml
|
||||||
- rbac.yaml
|
- rbac.yaml
|
||||||
- agent-dns-rbac.yaml
|
- agent-dns-rbac.yaml
|
||||||
- deployment.yaml
|
- deployment.yaml
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
---
|
||||||
|
# Let's Encrypt *.ceph.unkin.net wildcard for the haproxy edge (ceph dashboard).
|
||||||
|
# DNS-01 needs the delegated _acme-challenge.ceph.unkin.net CNAME in the public
|
||||||
|
# unkin.net zone.
|
||||||
|
# _acme-challenge.ceph.unkin.net. CNAME _acme-challenge.ceph.acme.unkin.net.
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: wildcard-ceph-unkin-net
|
||||||
|
namespace: cert-manager
|
||||||
|
spec:
|
||||||
|
secretName: wildcard-ceph-unkin-net-tls
|
||||||
|
secretTemplate:
|
||||||
|
annotations:
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "haproxy"
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "haproxy"
|
||||||
|
privateKey:
|
||||||
|
size: 4096
|
||||||
|
dnsNames:
|
||||||
|
- "*.ceph.unkin.net"
|
||||||
|
issuerRef:
|
||||||
|
name: letsencrypt
|
||||||
|
kind: ClusterIssuer
|
||||||
|
group: cert-manager.io
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
---
|
||||||
|
# Let's Encrypt *.main.unkin.net wildcard for the haproxy edge (pve, arr stack,
|
||||||
|
# jellyfin, stalwart webadmin/autoconfig). DNS-01 needs the delegated
|
||||||
|
# _acme-challenge.main.unkin.net CNAME in the public unkin.net zone.
|
||||||
|
# _acme-challenge.main.unkin.net. CNAME _acme-challenge.main.acme.unkin.net.
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: wildcard-main-unkin-net
|
||||||
|
namespace: cert-manager
|
||||||
|
spec:
|
||||||
|
secretName: wildcard-main-unkin-net-tls
|
||||||
|
secretTemplate:
|
||||||
|
annotations:
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "haproxy"
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "haproxy"
|
||||||
|
privateKey:
|
||||||
|
size: 4096
|
||||||
|
dnsNames:
|
||||||
|
- "*.main.unkin.net"
|
||||||
|
issuerRef:
|
||||||
|
name: letsencrypt
|
||||||
|
kind: ClusterIssuer
|
||||||
|
group: cert-manager.io
|
||||||
@@ -14,9 +14,9 @@ spec:
|
|||||||
secretTemplate:
|
secretTemplate:
|
||||||
annotations:
|
annotations:
|
||||||
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner"
|
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,logging"
|
||||||
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner"
|
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,logging"
|
||||||
privateKey:
|
privateKey:
|
||||||
size: 4096
|
size: 4096
|
||||||
dnsNames:
|
dnsNames:
|
||||||
|
|||||||
@@ -12,3 +12,5 @@ resources:
|
|||||||
- clusterissuer_letsencrypt.yaml
|
- clusterissuer_letsencrypt.yaml
|
||||||
- clusterissuer_letsencrypt-staging.yaml
|
- clusterissuer_letsencrypt-staging.yaml
|
||||||
- certificate_wildcard-unkin-net.yaml
|
- certificate_wildcard-unkin-net.yaml
|
||||||
|
- certificate_wildcard-main-unkin-net.yaml
|
||||||
|
- certificate_wildcard-ceph-unkin-net.yaml
|
||||||
|
|||||||
@@ -20,3 +20,22 @@ spec:
|
|||||||
jsonData:
|
jsonData:
|
||||||
timeInterval: "15s"
|
timeInterval: "15s"
|
||||||
httpMethod: "POST"
|
httpMethod: "POST"
|
||||||
|
---
|
||||||
|
apiVersion: grafana.integreatly.org/v1beta1
|
||||||
|
kind: GrafanaDatasource
|
||||||
|
metadata:
|
||||||
|
name: victorialogs
|
||||||
|
namespace: grafana
|
||||||
|
spec:
|
||||||
|
instanceSelector:
|
||||||
|
matchLabels:
|
||||||
|
dashboards: "grafana"
|
||||||
|
plugins:
|
||||||
|
- name: victoriametrics-logs-datasource
|
||||||
|
version: 0.32.0
|
||||||
|
datasource:
|
||||||
|
name: "VictoriaLogs"
|
||||||
|
type: "victoriametrics-logs-datasource"
|
||||||
|
uid: "victorialogs"
|
||||||
|
access: "proxy"
|
||||||
|
url: "http://vlselect-logs.logging.svc.cluster.local:9471"
|
||||||
|
|||||||
@@ -0,0 +1,274 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: haproxy-config
|
||||||
|
namespace: haproxy
|
||||||
|
data:
|
||||||
|
certificate.list: |
|
||||||
|
# First entry is the default cert for non-matching SNI.
|
||||||
|
/etc/haproxy/certs/unkin-net/tls.crt
|
||||||
|
/etc/haproxy/certs/main-unkin-net/tls.crt
|
||||||
|
/etc/haproxy/certs/ceph-unkin-net/tls.crt
|
||||||
|
|
||||||
|
fe_https.map: |
|
||||||
|
sonarr.main.unkin.net be_sonarr
|
||||||
|
radarr.main.unkin.net be_radarr
|
||||||
|
lidarr.main.unkin.net be_lidarr
|
||||||
|
readarr.main.unkin.net be_readarr
|
||||||
|
prowlarr.main.unkin.net be_prowlarr
|
||||||
|
nzbget.main.unkin.net be_nzbget
|
||||||
|
jellyfin.main.unkin.net be_jellyfin
|
||||||
|
fafflix.unkin.net be_jellyfin
|
||||||
|
git.unkin.net be_gitea
|
||||||
|
grafana.unkin.net be_grafana
|
||||||
|
dashboard.ceph.unkin.net be_ceph_dashboard
|
||||||
|
auth.unkin.net be_k8s_kanidm
|
||||||
|
|
||||||
|
haproxy.cfg: |
|
||||||
|
global
|
||||||
|
log stdout format raw local0
|
||||||
|
log stdout format raw local1 notice
|
||||||
|
maxconn 4000
|
||||||
|
hard-stop-after 2m
|
||||||
|
ssl-default-bind-ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH
|
||||||
|
ssl-default-bind-options ssl-min-ver TLSv1.2 ssl-max-ver TLSv1.3
|
||||||
|
ssl-default-server-ciphers kEECDH+aRSA+AES:kRSA+AES:+AES256:RC4-SHA:!kEDH:!LOW:!EXP:!MD5:!aNULL:!eNULL
|
||||||
|
ssl-default-server-options no-sslv3
|
||||||
|
stats timeout 30s
|
||||||
|
stats socket /var/lib/haproxy/stats
|
||||||
|
stats socket /var/lib/haproxy/admin.sock mode 660 level admin
|
||||||
|
tune.ssl.default-dh-param 2048
|
||||||
|
|
||||||
|
defaults
|
||||||
|
log global
|
||||||
|
maxconn 5000
|
||||||
|
mode http
|
||||||
|
option httplog
|
||||||
|
option dontlognull
|
||||||
|
option http-server-close
|
||||||
|
option forwardfor except 127.0.0.0/8
|
||||||
|
option redispatch
|
||||||
|
retries 3
|
||||||
|
stats enable
|
||||||
|
timeout http-request 10s
|
||||||
|
timeout queue 1m
|
||||||
|
timeout connect 10s
|
||||||
|
timeout client 5m
|
||||||
|
timeout server 5m
|
||||||
|
timeout http-keep-alive 10s
|
||||||
|
timeout check 10s
|
||||||
|
|
||||||
|
frontend fe_https
|
||||||
|
bind 0.0.0.0:443 ssl crt-list /usr/local/etc/haproxy/certificate.list ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH force-tlsv12
|
||||||
|
mode http
|
||||||
|
description Global HTTPS Frontend
|
||||||
|
http-request set-header X-Forwarded-Proto https
|
||||||
|
http-request set-header X-Real-IP %[src]
|
||||||
|
http-response set-header X-Content-Type-Options nosniff
|
||||||
|
http-response set-header X-XSS-Protection 1;mode=block
|
||||||
|
use_backend %[req.hdr(host),lower,map(/usr/local/etc/haproxy/fe_https.map,be_default)]
|
||||||
|
|
||||||
|
frontend fe_metrics
|
||||||
|
bind 0.0.0.0:8405
|
||||||
|
mode http
|
||||||
|
description Metrics Frontend
|
||||||
|
http-request set-header X-Forwarded-Proto https
|
||||||
|
http-request set-header X-Real-IP %[src]
|
||||||
|
http-request use-service prometheus-exporter if { path /metrics }
|
||||||
|
|
||||||
|
backend be_ceph_dashboard
|
||||||
|
description Backend for Ceph Dashboard from Mgr instances
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-check expect status 200
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 9443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
stick-table type ip size 200k expire 30m
|
||||||
|
server prodnxsr0009 198.18.23.9:9443 check cookie prodnxsr0009 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
server prodnxsr0010 198.18.23.10:9443 check cookie prodnxsr0010 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
server prodnxsr0011 198.18.23.11:9443 check cookie prodnxsr0011 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
server prodnxsr0012 198.18.23.12:9443 check cookie prodnxsr0012 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
server prodnxsr0013 198.18.23.13:9443 check cookie prodnxsr0013 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
backend be_default
|
||||||
|
description Backend for unmatched HTTP traffic
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
option httpchk GET /
|
||||||
|
option forwardfor
|
||||||
|
|
||||||
|
backend be_gitea
|
||||||
|
description Backend for gitea cluster
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
stick on src
|
||||||
|
stick-table type ip size 200k expire 30m
|
||||||
|
server ausyd1nxvm2080 198.18.26.18:443 check cookie ausyd1nxvm2080 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
server ausyd1nxvm2081 198.18.27.117:443 check cookie ausyd1nxvm2081 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
server ausyd1nxvm2082 198.18.28.71:443 check cookie ausyd1nxvm2082 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
backend be_grafana
|
||||||
|
description Backend for grafana nodes
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
stick on src
|
||||||
|
stick-table type ip size 200k expire 30m
|
||||||
|
server ausyd1nxvm2015 198.18.27.2:443 check cookie ausyd1nxvm2015 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
server ausyd1nxvm2016 198.18.28.189:443 check cookie ausyd1nxvm2016 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
backend be_jellyfin
|
||||||
|
description Backend for au-syd1 jellyfin
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
server ausyd1nxvm2051 198.18.25.164:443 check cookie ausyd1nxvm2051 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
backend be_k8s_kanidm
|
||||||
|
description Backend for Kanidm (auth.unkin.net via Kubernetes internal Traefik)
|
||||||
|
balance roundrobin
|
||||||
|
http-reuse always
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
option httpchk
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
http-check connect ssl sni auth.unkin.net
|
||||||
|
http-check send meth GET uri /status ver HTTP/1.1 hdr Host auth.unkin.net
|
||||||
|
http-check expect status 200
|
||||||
|
server k8s-traefik-internal 198.18.200.4:443 ssl verify none check inter 2s rise 3 fall 2 sni str(auth.unkin.net)
|
||||||
|
|
||||||
|
backend be_lidarr
|
||||||
|
description Backend for au-syd1 lidarr
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /consul/health
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
server ausyd1nxvm2048 198.18.28.165:443 check cookie ausyd1nxvm2048 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
backend be_nzbget
|
||||||
|
description Backend for au-syd1 nzbget
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /consul/health
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
server ausyd1nxvm2045 198.18.25.44:443 check cookie ausyd1nxvm2045 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
backend be_prowlarr
|
||||||
|
description Backend for au-syd1 prowlarr
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /consul/health
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
server ausyd1nxvm2050 198.18.25.66:443 check cookie ausyd1nxvm2050 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
backend be_radarr
|
||||||
|
description Backend for au-syd1 radarr
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /consul/health
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
server ausyd1nxvm2047 198.18.27.131:443 check cookie ausyd1nxvm2047 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
backend be_readarr
|
||||||
|
description Backend for au-syd1 readarr
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /consul/health
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
server ausyd1nxvm2049 198.18.29.32:443 check cookie ausyd1nxvm2049 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
backend be_sonarr
|
||||||
|
description Backend for au-syd1 sonarr
|
||||||
|
balance roundrobin
|
||||||
|
cookie SRVNAME insert indirect nocache
|
||||||
|
http-request set-header X-Forwarded-Port %[dst_port]
|
||||||
|
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||||
|
http-reuse always
|
||||||
|
option httpchk GET /consul/health
|
||||||
|
option forwardfor
|
||||||
|
option http-keep-alive
|
||||||
|
option prefer-last-server
|
||||||
|
redirect scheme https if !{ ssl_fc }
|
||||||
|
server ausyd1nxvm2046 198.18.26.161:443 check cookie ausyd1nxvm2046 fall 2 inter 2s rise 3 ssl verify none
|
||||||
|
|
||||||
|
# The `peers au-syd1-prod` section is dropped: peer names must be static and a
|
||||||
|
# Deployment cannot provide them. Behind the external Traefik's TLS
|
||||||
|
# passthrough `src` is a Traefik pod, so X-Real-IP, forwardfor and the
|
||||||
|
# `stick on src` tables all key on that; the SRVNAME cookie carries real
|
||||||
|
# session persistence. Traefik cannot emit PROXY protocol to a TLSRoute
|
||||||
|
# backend, so there is nothing to bind `accept-proxy` to.
|
||||||
|
|
||||||
|
listen health
|
||||||
|
bind 0.0.0.0:8404
|
||||||
|
mode http
|
||||||
|
monitor-uri /healthz
|
||||||
|
|
||||||
|
listen stats
|
||||||
|
bind 127.0.0.1:9090
|
||||||
|
mode http
|
||||||
|
stats uri /
|
||||||
|
stats auth admin:admin
|
||||||
@@ -0,0 +1,148 @@
|
|||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: haproxy
|
||||||
|
namespace: haproxy
|
||||||
|
annotations:
|
||||||
|
reloader.stakater.com/auto: "true"
|
||||||
|
spec:
|
||||||
|
replicas: 3
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: haproxy
|
||||||
|
strategy:
|
||||||
|
type: RollingUpdate
|
||||||
|
rollingUpdate:
|
||||||
|
maxUnavailable: 1
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: haproxy
|
||||||
|
spec:
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
terminationGracePeriodSeconds: 150
|
||||||
|
affinity:
|
||||||
|
podAntiAffinity:
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app: haproxy
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
securityContext:
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 99
|
||||||
|
runAsGroup: 99
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
containers:
|
||||||
|
- name: haproxy
|
||||||
|
image: haproxy:3.2.24-alpine
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
command:
|
||||||
|
- haproxy
|
||||||
|
- -W
|
||||||
|
- -db
|
||||||
|
- -f
|
||||||
|
- /usr/local/etc/haproxy/haproxy.cfg
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
capabilities:
|
||||||
|
drop: [ALL]
|
||||||
|
# fe_https binds the privileged port 443 as uid 99, and the
|
||||||
|
# dst_port ACLs need the real port.
|
||||||
|
add: [NET_BIND_SERVICE]
|
||||||
|
ports:
|
||||||
|
- name: https
|
||||||
|
containerPort: 443
|
||||||
|
protocol: TCP
|
||||||
|
- name: health
|
||||||
|
containerPort: 8404
|
||||||
|
protocol: TCP
|
||||||
|
- name: metrics
|
||||||
|
containerPort: 8405
|
||||||
|
protocol: TCP
|
||||||
|
- name: stats
|
||||||
|
containerPort: 9090
|
||||||
|
protocol: TCP
|
||||||
|
lifecycle:
|
||||||
|
preStop:
|
||||||
|
exec:
|
||||||
|
# SIGUSR1 to the master soft-stops the workers; hard-stop-after
|
||||||
|
# caps the drain. Wait so kubelet holds SIGTERM until it is done.
|
||||||
|
command:
|
||||||
|
- /bin/sh
|
||||||
|
- -c
|
||||||
|
- kill -s USR1 1; while kill -0 1 2>/dev/null; do sleep 1; done
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /healthz
|
||||||
|
port: health
|
||||||
|
initialDelaySeconds: 15
|
||||||
|
periodSeconds: 30
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 3
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /healthz
|
||||||
|
port: health
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 5
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 3
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 200m
|
||||||
|
memory: 256Mi
|
||||||
|
limits:
|
||||||
|
cpu: 2
|
||||||
|
memory: 1Gi
|
||||||
|
volumeMounts:
|
||||||
|
- name: config
|
||||||
|
mountPath: /usr/local/etc/haproxy
|
||||||
|
readOnly: true
|
||||||
|
- name: cert-unkin-net
|
||||||
|
mountPath: /etc/haproxy/certs/unkin-net
|
||||||
|
readOnly: true
|
||||||
|
- name: cert-main-unkin-net
|
||||||
|
mountPath: /etc/haproxy/certs/main-unkin-net
|
||||||
|
readOnly: true
|
||||||
|
- name: cert-ceph-unkin-net
|
||||||
|
mountPath: /etc/haproxy/certs/ceph-unkin-net
|
||||||
|
readOnly: true
|
||||||
|
- name: run
|
||||||
|
mountPath: /var/lib/haproxy
|
||||||
|
volumes:
|
||||||
|
- name: config
|
||||||
|
configMap:
|
||||||
|
name: haproxy-config
|
||||||
|
# ssl-load-extra-files loads <crtfile>.key by default, so the key is
|
||||||
|
# projected next to the cert as tls.crt.key.
|
||||||
|
- name: cert-unkin-net
|
||||||
|
secret:
|
||||||
|
secretName: wildcard-unkin-net-tls
|
||||||
|
items:
|
||||||
|
- key: tls.crt
|
||||||
|
path: tls.crt
|
||||||
|
- key: tls.key
|
||||||
|
path: tls.crt.key
|
||||||
|
- name: cert-main-unkin-net
|
||||||
|
secret:
|
||||||
|
secretName: wildcard-main-unkin-net-tls
|
||||||
|
items:
|
||||||
|
- key: tls.crt
|
||||||
|
path: tls.crt
|
||||||
|
- key: tls.key
|
||||||
|
path: tls.crt.key
|
||||||
|
- name: cert-ceph-unkin-net
|
||||||
|
secret:
|
||||||
|
secretName: wildcard-ceph-unkin-net-tls
|
||||||
|
items:
|
||||||
|
- key: tls.crt
|
||||||
|
path: tls.crt
|
||||||
|
- key: tls.key
|
||||||
|
path: tls.crt.key
|
||||||
|
- name: run
|
||||||
|
emptyDir: {}
|
||||||
|
restartPolicy: Always
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
---
|
||||||
|
# External (DMZ) front for the haproxy edge on the traefik-external LB VIP
|
||||||
|
# 198.18.199.0. The :443 listener is TLS Passthrough: haproxy owns the three
|
||||||
|
# wildcard certs and terminates behind Traefik, so there are no certificateRefs
|
||||||
|
# here. Listener hostnames are deliberately unset and the routes carry the
|
||||||
|
# explicit hostname list instead; allowedRoutes Same keeps other namespaces off
|
||||||
|
# these listeners.
|
||||||
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
|
kind: Gateway
|
||||||
|
metadata:
|
||||||
|
name: haproxy
|
||||||
|
namespace: haproxy
|
||||||
|
labels:
|
||||||
|
traefik.io/instance: external
|
||||||
|
spec:
|
||||||
|
gatewayClassName: traefik-external
|
||||||
|
listeners:
|
||||||
|
- name: http
|
||||||
|
port: 80
|
||||||
|
protocol: HTTP
|
||||||
|
allowedRoutes:
|
||||||
|
namespaces:
|
||||||
|
from: Same
|
||||||
|
- name: https-passthrough
|
||||||
|
port: 443
|
||||||
|
protocol: TLS
|
||||||
|
tls:
|
||||||
|
mode: Passthrough
|
||||||
|
allowedRoutes:
|
||||||
|
namespaces:
|
||||||
|
from: Same
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
---
|
||||||
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
|
kind: HTTPRoute
|
||||||
|
metadata:
|
||||||
|
name: haproxy-http-redirect
|
||||||
|
namespace: haproxy
|
||||||
|
labels:
|
||||||
|
app: haproxy
|
||||||
|
spec:
|
||||||
|
hostnames:
|
||||||
|
- sonarr.main.unkin.net
|
||||||
|
- radarr.main.unkin.net
|
||||||
|
- lidarr.main.unkin.net
|
||||||
|
- readarr.main.unkin.net
|
||||||
|
- prowlarr.main.unkin.net
|
||||||
|
- nzbget.main.unkin.net
|
||||||
|
- jellyfin.main.unkin.net
|
||||||
|
- fafflix.unkin.net
|
||||||
|
- git.unkin.net
|
||||||
|
- grafana.unkin.net
|
||||||
|
- dashboard.ceph.unkin.net
|
||||||
|
- auth.unkin.net
|
||||||
|
parentRefs:
|
||||||
|
- group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: haproxy
|
||||||
|
sectionName: http
|
||||||
|
rules:
|
||||||
|
- filters:
|
||||||
|
- type: RequestRedirect
|
||||||
|
requestRedirect:
|
||||||
|
scheme: https
|
||||||
|
statusCode: 301
|
||||||
|
matches:
|
||||||
|
- path:
|
||||||
|
type: PathPrefix
|
||||||
|
value: /
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- configmap.yaml
|
||||||
|
- deployment.yaml
|
||||||
|
- service.yaml
|
||||||
|
- gateway.yaml
|
||||||
|
- tlsroute.yaml
|
||||||
|
- httproute.yaml
|
||||||
|
- pdb.yaml
|
||||||
|
- vpa.yaml
|
||||||
|
- vmpodscrape.yaml
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: haproxy
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
apiVersion: policy/v1
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
metadata:
|
||||||
|
name: haproxy
|
||||||
|
namespace: haproxy
|
||||||
|
spec:
|
||||||
|
maxUnavailable: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: haproxy
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: haproxy
|
||||||
|
namespace: haproxy
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
# Reached only by the external Traefik's TLS-passthrough TLSRoute, so the
|
||||||
|
# peer address here is a Traefik pod, not the client. sessionAffinity is
|
||||||
|
# deliberately absent: keyed on ClientIP it would pin whole Traefik pods,
|
||||||
|
# not clients. Backend persistence rests on the per-backend SRVNAME cookie.
|
||||||
|
selector:
|
||||||
|
app: haproxy
|
||||||
|
ports:
|
||||||
|
- name: https
|
||||||
|
port: 443
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: https
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
---
|
||||||
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
|
kind: TLSRoute
|
||||||
|
metadata:
|
||||||
|
name: haproxy
|
||||||
|
namespace: haproxy
|
||||||
|
labels:
|
||||||
|
app: haproxy
|
||||||
|
spec:
|
||||||
|
hostnames:
|
||||||
|
- sonarr.main.unkin.net
|
||||||
|
- radarr.main.unkin.net
|
||||||
|
- lidarr.main.unkin.net
|
||||||
|
- readarr.main.unkin.net
|
||||||
|
- prowlarr.main.unkin.net
|
||||||
|
- nzbget.main.unkin.net
|
||||||
|
- jellyfin.main.unkin.net
|
||||||
|
- fafflix.unkin.net
|
||||||
|
- git.unkin.net
|
||||||
|
- grafana.unkin.net
|
||||||
|
- dashboard.ceph.unkin.net
|
||||||
|
- auth.unkin.net
|
||||||
|
parentRefs:
|
||||||
|
- group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: haproxy
|
||||||
|
sectionName: https-passthrough
|
||||||
|
rules:
|
||||||
|
- backendRefs:
|
||||||
|
- group: ""
|
||||||
|
kind: Service
|
||||||
|
name: haproxy
|
||||||
|
port: 443
|
||||||
|
weight: 1
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
apiVersion: operator.victoriametrics.com/v1beta1
|
||||||
|
kind: VMPodScrape
|
||||||
|
metadata:
|
||||||
|
name: haproxy
|
||||||
|
namespace: haproxy
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: haproxy
|
||||||
|
podMetricsEndpoints:
|
||||||
|
- port: metrics
|
||||||
|
path: /metrics
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
apiVersion: autoscaling.k8s.io/v1
|
||||||
|
kind: VerticalPodAutoscaler
|
||||||
|
metadata:
|
||||||
|
name: haproxy-vpa
|
||||||
|
namespace: haproxy
|
||||||
|
spec:
|
||||||
|
targetRef:
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
name: haproxy
|
||||||
|
updatePolicy:
|
||||||
|
updateMode: "Off"
|
||||||
@@ -1,16 +1,13 @@
|
|||||||
---
|
---
|
||||||
# Log ingestion endpoint for puppet-managed VMs (and any non-k8s client).
|
# Log ingestion endpoint for puppet-managed VMs (and any non-k8s client):
|
||||||
# Reuses the internal Traefik gateway + cert-manager + external-dns pattern so
|
# fronts the VLCluster vlinsert service over TLS at a name VMs can resolve.
|
||||||
# VMs reach the Vector aggregator's HTTP source over TLS at a DNS name they can
|
|
||||||
# resolve. The puppet-side Vector rollout ships NDJSON to
|
|
||||||
# https://logs-ingest.k8s.syd1.au.unkin.net/ (a later task).
|
|
||||||
apiVersion: gateway.networking.k8s.io/v1
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
kind: Gateway
|
kind: Gateway
|
||||||
metadata:
|
metadata:
|
||||||
name: logs-ingest
|
name: logs-ingest
|
||||||
namespace: logging
|
namespace: logging
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: vector-aggregator
|
app.kubernetes.io/name: victorialogs
|
||||||
app.kubernetes.io/component: ingest
|
app.kubernetes.io/component: ingest
|
||||||
traefik.io/instance: internal
|
traefik.io/instance: internal
|
||||||
annotations:
|
annotations:
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ metadata:
|
|||||||
name: logs-ingest-http-redirect
|
name: logs-ingest-http-redirect
|
||||||
namespace: logging
|
namespace: logging
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: vector-aggregator
|
app.kubernetes.io/name: victorialogs
|
||||||
app.kubernetes.io/component: ingest
|
app.kubernetes.io/component: ingest
|
||||||
spec:
|
spec:
|
||||||
hostnames:
|
hostnames:
|
||||||
@@ -32,7 +32,7 @@ metadata:
|
|||||||
name: logs-ingest
|
name: logs-ingest
|
||||||
namespace: logging
|
namespace: logging
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: vector-aggregator
|
app.kubernetes.io/name: victorialogs
|
||||||
app.kubernetes.io/component: ingest
|
app.kubernetes.io/component: ingest
|
||||||
spec:
|
spec:
|
||||||
hostnames:
|
hostnames:
|
||||||
@@ -46,8 +46,8 @@ spec:
|
|||||||
- backendRefs:
|
- backendRefs:
|
||||||
- group: ""
|
- group: ""
|
||||||
kind: Service
|
kind: Service
|
||||||
name: vector-vm-ingest
|
name: vlinsert-logs
|
||||||
port: 8080
|
port: 9481
|
||||||
weight: 1
|
weight: 1
|
||||||
matches:
|
matches:
|
||||||
- path:
|
- path:
|
||||||
|
|||||||
@@ -10,12 +10,14 @@ resources:
|
|||||||
- job_clickhouse-schema.yaml
|
- job_clickhouse-schema.yaml
|
||||||
- nats-bootstrap-job.yaml
|
- nats-bootstrap-job.yaml
|
||||||
- cephrgw.yaml
|
- cephrgw.yaml
|
||||||
|
- vlcluster.yaml
|
||||||
- gateway.yaml
|
- gateway.yaml
|
||||||
- httproute.yaml
|
- httproute.yaml
|
||||||
- serviceaccount_logarchiver.yaml
|
- serviceaccount_logarchiver.yaml
|
||||||
- configmap_logarchiver.yaml
|
- configmap_logarchiver.yaml
|
||||||
- deployment_logarchiver.yaml
|
- deployment_logarchiver.yaml
|
||||||
- logviewer
|
- logviewer
|
||||||
|
- vlogs
|
||||||
|
|
||||||
# Vector pipelines are the single source of truth (also validated by
|
# Vector pipelines are the single source of truth (also validated by
|
||||||
# `vector test` in CI). Mounted into each tier via `existingConfigMaps`.
|
# `vector test` in CI). Mounted into each tier via `existingConfigMaps`.
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
---
|
||||||
|
apiVersion: operator.victoriametrics.com/v1
|
||||||
|
kind: VLCluster
|
||||||
|
metadata:
|
||||||
|
name: logs
|
||||||
|
namespace: logging
|
||||||
|
spec:
|
||||||
|
clusterVersion: v1.52.0
|
||||||
|
vlinsert:
|
||||||
|
replicaCount: 2
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 1Gi
|
||||||
|
limits:
|
||||||
|
cpu: "2"
|
||||||
|
memory: 4Gi
|
||||||
|
vlselect:
|
||||||
|
replicaCount: 2
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 1Gi
|
||||||
|
limits:
|
||||||
|
cpu: "2"
|
||||||
|
memory: 4Gi
|
||||||
|
vlstorage:
|
||||||
|
replicaCount: 3
|
||||||
|
retentionPeriod: 180d
|
||||||
|
# ~3 GiB/day measured; 220GiB/node cap keeps 180d time-based, not disk-bound
|
||||||
|
retentionMaxDiskSpaceUsageBytes: 220GiB
|
||||||
|
storage:
|
||||||
|
volumeClaimTemplate:
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
storageClassName: cephrbd-fast-delete
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 250Gi
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: "1"
|
||||||
|
memory: 2Gi
|
||||||
|
limits:
|
||||||
|
cpu: "4"
|
||||||
|
memory: 8Gi
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
---
|
||||||
|
# External (DMZ) front for the VictoriaLogs UI on vlogs.unkin.net via the
|
||||||
|
# external Traefik (LB VIP 198.18.199.0). TLS terminates with the real Let's
|
||||||
|
# Encrypt *.unkin.net wildcard (Certificate wildcard-unkin-net in cert-manager,
|
||||||
|
# reflected into this namespace as wildcard-unkin-net-tls by the emberstack
|
||||||
|
# reflector), so there is no cert-manager annotation here. The apex
|
||||||
|
# vlogs.unkin.net A record lives in the bind-operator unkin.net zone, NOT
|
||||||
|
# external-dns, so no external-dns annotation either. oauth2-proxy fronts it.
|
||||||
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
|
kind: Gateway
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
traefik.io/instance: external
|
||||||
|
name: vlogs-external
|
||||||
|
namespace: logging
|
||||||
|
spec:
|
||||||
|
gatewayClassName: traefik-external
|
||||||
|
listeners:
|
||||||
|
- allowedRoutes:
|
||||||
|
namespaces:
|
||||||
|
from: Same
|
||||||
|
hostname: vlogs.unkin.net
|
||||||
|
name: http
|
||||||
|
port: 80
|
||||||
|
protocol: HTTP
|
||||||
|
- allowedRoutes:
|
||||||
|
namespaces:
|
||||||
|
from: Same
|
||||||
|
hostname: vlogs.unkin.net
|
||||||
|
name: https
|
||||||
|
port: 443
|
||||||
|
protocol: HTTPS
|
||||||
|
tls:
|
||||||
|
certificateRefs:
|
||||||
|
- group: ""
|
||||||
|
kind: Secret
|
||||||
|
name: wildcard-unkin-net-tls
|
||||||
|
mode: Terminate
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
---
|
||||||
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
|
kind: HTTPRoute
|
||||||
|
metadata:
|
||||||
|
name: vlogs-http-redirect
|
||||||
|
namespace: logging
|
||||||
|
spec:
|
||||||
|
hostnames:
|
||||||
|
- vlogs.unkin.net
|
||||||
|
parentRefs:
|
||||||
|
- group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: vlogs-external
|
||||||
|
sectionName: http
|
||||||
|
rules:
|
||||||
|
- filters:
|
||||||
|
- type: RequestRedirect
|
||||||
|
requestRedirect:
|
||||||
|
scheme: https
|
||||||
|
statusCode: 301
|
||||||
|
matches:
|
||||||
|
- path:
|
||||||
|
type: PathPrefix
|
||||||
|
value: /
|
||||||
|
---
|
||||||
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
|
kind: HTTPRoute
|
||||||
|
metadata:
|
||||||
|
name: vlogs
|
||||||
|
namespace: logging
|
||||||
|
spec:
|
||||||
|
hostnames:
|
||||||
|
- vlogs.unkin.net
|
||||||
|
parentRefs:
|
||||||
|
- group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: vlogs-external
|
||||||
|
sectionName: https
|
||||||
|
rules:
|
||||||
|
- backendRefs:
|
||||||
|
- group: ""
|
||||||
|
kind: Service
|
||||||
|
name: vlogs-oauth2
|
||||||
|
port: 80
|
||||||
|
weight: 1
|
||||||
|
matches:
|
||||||
|
- path:
|
||||||
|
type: PathPrefix
|
||||||
|
value: /
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- vaultstaticsecret.yaml
|
||||||
|
- oauth2-proxy-configmap.yaml
|
||||||
|
- oauth2-proxy-deployment.yaml
|
||||||
|
- service.yaml
|
||||||
|
- gateway.yaml
|
||||||
|
- httproute.yaml
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: vlogs-oauth2-env
|
||||||
|
namespace: logging
|
||||||
|
data:
|
||||||
|
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
||||||
|
OAUTH2_PROXY_PROVIDER: "oidc"
|
||||||
|
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/vlogs/"
|
||||||
|
OAUTH2_PROXY_REDIRECT_URL: "https://vlogs.unkin.net/oauth2/callback"
|
||||||
|
OAUTH2_PROXY_UPSTREAMS: "http://vlselect-logs.logging.svc.cluster.local:9471/"
|
||||||
|
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
|
||||||
|
# Populate session.Groups from the Authentik ak_groups claim.
|
||||||
|
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
|
||||||
|
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-vlogs-admin"
|
||||||
|
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
|
||||||
|
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
|
||||||
|
# Authentik hardcodes email_verified=false in the id_token; authorization is
|
||||||
|
# enforced via ak_groups, so accepting the unverified email is safe.
|
||||||
|
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
|
||||||
|
OAUTH2_PROXY_COOKIE_SECURE: "true"
|
||||||
|
OAUTH2_PROXY_COOKIE_DOMAINS: "vlogs.unkin.net"
|
||||||
|
OAUTH2_PROXY_WHITELIST_DOMAINS: "vlogs.unkin.net"
|
||||||
|
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
||||||
|
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
|
||||||
|
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
||||||
|
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
||||||
@@ -0,0 +1,132 @@
|
|||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: vlogs-oauth2
|
||||||
|
namespace: logging
|
||||||
|
annotations:
|
||||||
|
configmap.reloader.stakater.com/auto: "true"
|
||||||
|
secret.reloader.stakater.com/reload: "vlogs-oauth-credentials,vault-ca-cert"
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: vlogs-oauth2
|
||||||
|
strategy:
|
||||||
|
rollingUpdate:
|
||||||
|
maxUnavailable: 1
|
||||||
|
type: RollingUpdate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: vlogs-oauth2
|
||||||
|
spec:
|
||||||
|
serviceAccountName: default
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
securityContext:
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 65532
|
||||||
|
runAsGroup: 65532
|
||||||
|
fsGroup: 65532
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
initContainers:
|
||||||
|
# identity.unkin.net serves a Vault-PKI cert; combine the system roots
|
||||||
|
# with the internal CA so oauth2-proxy's OIDC HTTP client trusts it.
|
||||||
|
- name: combine-certs
|
||||||
|
image: docker.io/library/alpine:3
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
|
||||||
|
volumeMounts:
|
||||||
|
- name: vault-ca-cert
|
||||||
|
mountPath: /custom-ca
|
||||||
|
readOnly: true
|
||||||
|
- name: combined-certs
|
||||||
|
mountPath: /combined-certs
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 32Mi
|
||||||
|
limits:
|
||||||
|
cpu: 200m
|
||||||
|
memory: 64Mi
|
||||||
|
containers:
|
||||||
|
- name: oauth2-proxy
|
||||||
|
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
ports:
|
||||||
|
- containerPort: 4180
|
||||||
|
name: http
|
||||||
|
protocol: TCP
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: vlogs-oauth2-env
|
||||||
|
optional: false
|
||||||
|
env:
|
||||||
|
- name: OAUTH2_PROXY_CLIENT_ID
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: vlogs-oauth-credentials
|
||||||
|
key: client_id
|
||||||
|
- name: OAUTH2_PROXY_CLIENT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: vlogs-oauth-credentials
|
||||||
|
key: client_secret
|
||||||
|
- name: OAUTH2_PROXY_COOKIE_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: vlogs-oauth-credentials
|
||||||
|
key: cookie_secret
|
||||||
|
volumeMounts:
|
||||||
|
- name: combined-certs
|
||||||
|
mountPath: /etc/ssl/combined
|
||||||
|
readOnly: true
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /ping
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 30
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 3
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /ready
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 3
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 64Mi
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 256Mi
|
||||||
|
volumes:
|
||||||
|
- name: vault-ca-cert
|
||||||
|
secret:
|
||||||
|
secretName: vault-ca-cert
|
||||||
|
items:
|
||||||
|
- key: ca.crt
|
||||||
|
path: ca.crt
|
||||||
|
- name: combined-certs
|
||||||
|
emptyDir: {}
|
||||||
|
restartPolicy: Always
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
# Front-door entry Service: the HTTPRoute for vlogs.unkin.net targets this, so
|
||||||
|
# all traffic enters via oauth2-proxy.
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: vlogs-oauth2
|
||||||
|
namespace: logging
|
||||||
|
spec:
|
||||||
|
internalTrafficPolicy: Cluster
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: 80
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: http
|
||||||
|
selector:
|
||||||
|
app: vlogs-oauth2
|
||||||
|
sessionAffinity: None
|
||||||
|
type: ClusterIP
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
apiVersion: secrets.hashicorp.com/v1beta1
|
||||||
|
kind: VaultStaticSecret
|
||||||
|
metadata:
|
||||||
|
name: vlogs-oauth-credentials
|
||||||
|
namespace: logging
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
create: true
|
||||||
|
name: vlogs-oauth-credentials
|
||||||
|
overwrite: true
|
||||||
|
hmacSecretData: true
|
||||||
|
mount: kv
|
||||||
|
path: kubernetes/namespace/logging/default/vlogs-oauth-credentials
|
||||||
|
refreshAfter: 5m
|
||||||
|
type: kv-v2
|
||||||
|
vaultAuthRef: default
|
||||||
@@ -11,11 +11,13 @@ metadata:
|
|||||||
namespace: puppet
|
namespace: puppet
|
||||||
spec:
|
spec:
|
||||||
schedule: "*/1 * * * *"
|
schedule: "*/1 * * * *"
|
||||||
|
startingDeadlineSeconds: 200
|
||||||
concurrencyPolicy: Forbid
|
concurrencyPolicy: Forbid
|
||||||
successfulJobsHistoryLimit: 3
|
successfulJobsHistoryLimit: 3
|
||||||
failedJobsHistoryLimit: 3
|
failedJobsHistoryLimit: 3
|
||||||
jobTemplate:
|
jobTemplate:
|
||||||
spec:
|
spec:
|
||||||
|
activeDeadlineSeconds: 300
|
||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
labels:
|
labels:
|
||||||
|
|||||||
@@ -0,0 +1,33 @@
|
|||||||
|
---
|
||||||
|
# Shared Go build cache (GOCACHEPROG) for CI and developer laptops. Lives in the
|
||||||
|
# woodpecker namespace because CI is the primary consumer and reads the Secret here.
|
||||||
|
apiVersion: ceph.unkin.net/v1alpha1
|
||||||
|
kind: ObjectStoreUser
|
||||||
|
metadata:
|
||||||
|
name: gocache
|
||||||
|
namespace: woodpecker
|
||||||
|
spec:
|
||||||
|
displayName: "Go build cache owner"
|
||||||
|
uid: gocache
|
||||||
|
maxBuckets: 1
|
||||||
|
secretName: gocache-s3
|
||||||
|
retainOnDelete: false
|
||||||
|
---
|
||||||
|
apiVersion: ceph.unkin.net/v1alpha1
|
||||||
|
kind: Bucket
|
||||||
|
metadata:
|
||||||
|
name: gocache
|
||||||
|
namespace: woodpecker
|
||||||
|
spec:
|
||||||
|
bucketName: gocache
|
||||||
|
ownerRef: gocache
|
||||||
|
versioning: false
|
||||||
|
# No placementTarget: default (replicated) placement, not the ec target the
|
||||||
|
# backup buckets use — a build cache is millions of small objects.
|
||||||
|
tags:
|
||||||
|
app: gocache
|
||||||
|
purpose: go-build-cache
|
||||||
|
retainOnDelete: false
|
||||||
|
# A cache bucket is never empty, and the operator refuses to delete a
|
||||||
|
# non-empty bucket without this, wedging the finalizer.
|
||||||
|
purgeOnDelete: true
|
||||||
@@ -7,6 +7,7 @@ resources:
|
|||||||
- cnpg_cluster.yaml
|
- cnpg_cluster.yaml
|
||||||
- cnpg_backup.yaml
|
- cnpg_backup.yaml
|
||||||
- cnpg_pooler.yaml
|
- cnpg_pooler.yaml
|
||||||
|
- gocache_bucket.yaml
|
||||||
- serviceaccount_arrproxy_ci.yaml
|
- serviceaccount_arrproxy_ci.yaml
|
||||||
- serviceaccount_autobackup_operator_ci.yaml
|
- serviceaccount_autobackup_operator_ci.yaml
|
||||||
- serviceaccount_ghp.yaml
|
- serviceaccount_ghp.yaml
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ../../../base/haproxy
|
||||||
@@ -10,7 +10,7 @@ resources:
|
|||||||
helmCharts:
|
helmCharts:
|
||||||
- name: victoria-metrics-operator
|
- name: victoria-metrics-operator
|
||||||
repo: https://victoriametrics.github.io/helm-charts/
|
repo: https://victoriametrics.github.io/helm-charts/
|
||||||
version: "0.57.1"
|
version: "0.67.3"
|
||||||
releaseName: victoria-metrics-operator
|
releaseName: victoria-metrics-operator
|
||||||
namespace: vm-system
|
namespace: vm-system
|
||||||
valuesFile: values.yaml
|
valuesFile: values.yaml
|
||||||
|
|||||||
@@ -29,6 +29,7 @@ spec:
|
|||||||
- path: apps/overlays/*/ghp
|
- path: apps/overlays/*/ghp
|
||||||
- path: apps/overlays/*/gitea
|
- path: apps/overlays/*/gitea
|
||||||
- path: apps/overlays/*/grafana-system
|
- path: apps/overlays/*/grafana-system
|
||||||
|
- path: apps/overlays/*/haproxy
|
||||||
- path: apps/overlays/*/inteldeviceplugins-system
|
- path: apps/overlays/*/inteldeviceplugins-system
|
||||||
- path: apps/overlays/*/jfrog
|
- path: apps/overlays/*/jfrog
|
||||||
- path: apps/overlays/*/k8up-system
|
- path: apps/overlays/*/k8up-system
|
||||||
|
|||||||
@@ -43,6 +43,8 @@ spec:
|
|||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: 'gitea'
|
- namespace: 'gitea'
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
|
- namespace: 'haproxy'
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
- namespace: 'jfrog'
|
- namespace: 'jfrog'
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: 'kanidm'
|
- namespace: 'kanidm'
|
||||||
|
|||||||
Reference in New Issue
Block a user