Deploy cephrgw-operator to cephrgw-system #261

Merged
benvin merged 2 commits from benvin/add-cephrgw-operator into main 2026-07-18 14:32:12 +10:00
Owner

Why

The new cephrgw-operator provisions Ceph RGW (S3) buckets and access keys (RW/RO) from Kubernetes CRDs via the Ceph manager dashboard API. This deploys it as a platform app.

Changes

  • Add apps/base/cephrgw-system: namespace, ServiceAccount + ClusterRole/Binding (manage ceph.unkin.net CRDs, Secrets, leader-election leases), and the operator Deployment. CRDs are pulled from the operator repo at tag v0.1.0; the Deployment sources dashboard credentials from the cephrgw-credentials Secret via envFrom and carries the reloader annotation.
  • Add apps/overlays/au-syd1/cephrgw-system referencing the base.
  • Register apps/overlays/*/cephrgw-system in the platform ApplicationSet.

The platform AppProject already permits *-system namespaces and the Namespace/ClusterRole/CRD cluster resources, so no project change is needed.

Ordering / dependencies

  • Depends on the Gitea repo from terraform-git #34 and on the operator being pushed + tagged v0.1.0 (image git.unkin.net/unkin/cephrgw-operator:v0.1.0 and the raw CRD install.yaml at that tag). The kubeconform check will stay red until v0.1.0 exists, then go green.
  • The cephrgw-credentials Secret must be created out-of-band in cephrgw-system (see the operator's docs/ceph-setup.md); it is intentionally not managed in GitOps.
## Why The new `cephrgw-operator` provisions Ceph RGW (S3) buckets and access keys (RW/RO) from Kubernetes CRDs via the Ceph manager dashboard API. This deploys it as a platform app. ## Changes - Add `apps/base/cephrgw-system`: namespace, ServiceAccount + ClusterRole/Binding (manage `ceph.unkin.net` CRDs, Secrets, leader-election leases), and the operator Deployment. CRDs are pulled from the operator repo at tag `v0.1.0`; the Deployment sources dashboard credentials from the `cephrgw-credentials` Secret via `envFrom` and carries the reloader annotation. - Add `apps/overlays/au-syd1/cephrgw-system` referencing the base. - Register `apps/overlays/*/cephrgw-system` in the platform ApplicationSet. The platform AppProject already permits `*-system` namespaces and the Namespace/ClusterRole/CRD cluster resources, so no project change is needed. ## Ordering / dependencies - Depends on the Gitea repo from terraform-git #34 and on the operator being pushed + tagged **v0.1.0** (image `git.unkin.net/unkin/cephrgw-operator:v0.1.0` and the raw CRD `install.yaml` at that tag). The `kubeconform` check will stay red until v0.1.0 exists, then go green. - The `cephrgw-credentials` Secret must be created out-of-band in `cephrgw-system` (see the operator's `docs/ceph-setup.md`); it is intentionally **not** managed in GitOps.
unkinben added 1 commit 2026-07-18 00:11:22 +10:00
Deploy cephrgw-operator to cephrgw-system
ci/woodpecker/pr/kubeconform Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
e84f296f88
The cephrgw-operator provisions Ceph RGW (S3) buckets and access keys from
CRDs via the Ceph manager dashboard API. Deploy it as a platform app.

- Add apps/base/cephrgw-system: namespace, ServiceAccount + ClusterRole/
  Binding (manage ceph.unkin.net CRDs, Secrets, leases), and the operator
  Deployment. CRDs are pulled from the operator repo at tag v0.1.0; the
  Deployment sources dashboard credentials from the cephrgw-credentials
  Secret via envFrom and carries the reloader annotation.
- Add apps/overlays/au-syd1/cephrgw-system referencing the base.
- Register apps/overlays/*/cephrgw-system in the platform ApplicationSet.

The platform AppProject already permits *-system namespaces and the
Namespace/ClusterRole/CRD cluster resources, so no project change is needed.
Requires the cephrgw-credentials Secret to be created out-of-band (see the
operator's docs/ceph-setup.md); it is intentionally not managed in GitOps.
unkinben added 1 commit 2026-07-18 11:28:18 +10:00
ci: re-run checks now that cephrgw-operator v0.1.0 is tagged
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
5b577a3864
The kubeconform check first ran before the operator's v0.1.0 tag existed, so
the remote CRD install.yaml (referenced at raw/tag/v0.1.0) 404'd. The tag now
exists and the raw URL resolves; this empty commit re-triggers CI.
benvin merged commit 19f8055144 into main 2026-07-18 14:32:12 +10:00
benvin deleted branch benvin/add-cephrgw-operator 2026-07-18 14:32:12 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/argocd-apps#261