Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| cdaab736b5 |
@@ -164,7 +164,7 @@ spec:
|
||||
readOnly: true
|
||||
containers:
|
||||
- name: cheeztv
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.3.3
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- name: http
|
||||
|
||||
@@ -164,7 +164,7 @@ spec:
|
||||
readOnly: true
|
||||
containers:
|
||||
- name: fafflix
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.3.3
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- name: http
|
||||
|
||||
@@ -105,17 +105,6 @@ spec:
|
||||
- mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh
|
||||
name: compiler-auth-conf-seed
|
||||
subPath: 10-auth-conf.sh
|
||||
- mountPath: /docker-custom-entrypoint.d/pre-default/20-vault-helpers.sh
|
||||
name: compiler-vault-helpers-seed
|
||||
subPath: 20-vault-helpers.sh
|
||||
- mountPath: /opt/certmanager/config.yaml
|
||||
name: certmanager-config
|
||||
subPath: certmanager.yaml
|
||||
readOnly: true
|
||||
- mountPath: /opt/sshsignhost/config.yaml
|
||||
name: sshsignhost-config
|
||||
subPath: sshsignhost.yaml
|
||||
readOnly: true
|
||||
initContainers:
|
||||
- name: copy-configmaps
|
||||
image: busybox:1.35
|
||||
@@ -213,38 +202,7 @@ spec:
|
||||
echo "$EXPECTED encapic" | sha256sum -c -
|
||||
install -m 0755 encapic /opt/bin/encapic
|
||||
|
||||
# Puppet shells out to these two from generate() during catalog
|
||||
# compilation: profiles::pki::vault runs certmanager and
|
||||
# profiles::ssh::sign runs sshsignhost.
|
||||
install_release() {
|
||||
name=$1
|
||||
version=$2
|
||||
asset="$name-linux-amd64"
|
||||
base="https://git.unkin.net/unkin/$name/releases/download/$version"
|
||||
curl -fsSL -o "$name" "$base/$asset"
|
||||
curl -fsSL -o "$name.checksums" "$base/checksums.txt"
|
||||
# checksums.txt covers every release asset; pick the line for the
|
||||
# one we downloaded and verify it under our local filename.
|
||||
expected=$(awk -v a="$asset" '$NF == a || $NF == "*"a {print $1}' "$name.checksums")
|
||||
if [ -z "$expected" ]; then
|
||||
echo "no checksum for $asset in $version checksums.txt" >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "$expected $name" | sha256sum -c -
|
||||
install -m 0755 "$name" "/opt/bin/$name"
|
||||
}
|
||||
|
||||
install_release certmanager v0.2.0
|
||||
install_release sshsignhost v0.1.0
|
||||
|
||||
echo "Shared binaries setup completed"
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 256Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 64Mi
|
||||
volumeMounts:
|
||||
- mountPath: /opt/bin/
|
||||
name: puppet-shared-bins
|
||||
@@ -289,15 +247,5 @@ spec:
|
||||
configMap:
|
||||
name: compiler-auth-conf-seed
|
||||
defaultMode: 0755
|
||||
- name: compiler-vault-helpers-seed
|
||||
configMap:
|
||||
name: compiler-vault-helpers-seed
|
||||
defaultMode: 0755
|
||||
- name: certmanager-config
|
||||
configMap:
|
||||
name: certmanager-config
|
||||
- name: sshsignhost-config
|
||||
configMap:
|
||||
name: sshsignhost-config
|
||||
strategy:
|
||||
type: RollingUpdate
|
||||
|
||||
@@ -64,21 +64,6 @@ configMapGenerator:
|
||||
- resources/compiler/10-auth-conf.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: compiler-vault-helpers-seed
|
||||
files:
|
||||
- resources/compiler/20-vault-helpers.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: certmanager-config
|
||||
files:
|
||||
- resources/compiler/certmanager.yaml
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: sshsignhost-config
|
||||
files:
|
||||
- resources/compiler/sshsignhost.yaml
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: additional-ruby-gems
|
||||
files:
|
||||
- resources/additional-ruby-gems.sh
|
||||
|
||||
@@ -1,29 +0,0 @@
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
|
||||
BIN_DIR=/opt/bin
|
||||
CA=/opt/vault-ca-cert.crt
|
||||
|
||||
if [ ! -s "$CA" ]; then
|
||||
echo "FATAL: $CA missing or empty; certmanager and sshsignhost cannot verify Vault" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# profiles::pki::vault and profiles::ssh::sign shell out to fixed /usr/local/bin
|
||||
# paths from generate(); the binaries ship on the shared PVC, and /usr/local/bin
|
||||
# lives in the image. Wrappers rather than symlinks because neither binary reads
|
||||
# a CA path from its config: SSL_CERT_FILE scopes the internal CA to these two
|
||||
# processes instead of the puppetserver JVM's own trust store.
|
||||
for bin in certmanager sshsignhost; do
|
||||
if [ ! -x "$BIN_DIR/$bin" ]; then
|
||||
echo "FATAL: $BIN_DIR/$bin missing; generate() would abort every catalog compile" >&2
|
||||
exit 1
|
||||
fi
|
||||
cat > "/usr/local/bin/$bin" <<WRAPPER
|
||||
#!/bin/sh
|
||||
SSL_CERT_FILE=$CA
|
||||
export SSL_CERT_FILE
|
||||
exec $BIN_DIR/$bin "\$@"
|
||||
WRAPPER
|
||||
chmod 0755 "/usr/local/bin/$bin"
|
||||
done
|
||||
@@ -1,12 +0,0 @@
|
||||
---
|
||||
vault:
|
||||
addr: https://vault.service.consul:8200
|
||||
auth_method: kubernetes
|
||||
k8s_mount: k8s/au/syd1
|
||||
k8s_role: puppet_certmanager
|
||||
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||
mount_point: pki_int
|
||||
role_name: servers_default
|
||||
output_path: /tmp/certmanager
|
||||
tls_skip_verify: false
|
||||
timeout: 30s
|
||||
@@ -1,11 +0,0 @@
|
||||
---
|
||||
vault:
|
||||
addr: https://vault.service.consul:8200
|
||||
auth_method: kubernetes
|
||||
k8s_mount: k8s/au/syd1
|
||||
k8s_role: puppet_sshsigner
|
||||
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||
mount_point: sshca
|
||||
role_name: signhost
|
||||
tls_skip_verify: false
|
||||
timeout: 30s
|
||||
Reference in New Issue
Block a user