Give vlogs its own namespace #507
@@ -14,9 +14,9 @@ spec:
|
||||
secretTemplate:
|
||||
annotations:
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,logging"
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,vlogs"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,logging"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy,vlogs"
|
||||
privateKey:
|
||||
size: 4096
|
||||
dnsNames:
|
||||
|
||||
@@ -9,4 +9,3 @@ resources:
|
||||
- vlagent.yaml
|
||||
- gateway.yaml
|
||||
- httproute.yaml
|
||||
- vlogs
|
||||
|
||||
@@ -12,7 +12,7 @@ metadata:
|
||||
labels:
|
||||
traefik.io/instance: external
|
||||
name: vlogs-external
|
||||
namespace: logging
|
||||
namespace: vlogs
|
||||
spec:
|
||||
gatewayClassName: traefik-external
|
||||
listeners:
|
||||
@@ -3,7 +3,7 @@ apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: vlogs-http-redirect
|
||||
namespace: logging
|
||||
namespace: vlogs
|
||||
spec:
|
||||
hostnames:
|
||||
- vlogs.unkin.net
|
||||
@@ -27,7 +27,7 @@ apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: vlogs
|
||||
namespace: logging
|
||||
namespace: vlogs
|
||||
spec:
|
||||
hostnames:
|
||||
- vlogs.unkin.net
|
||||
@@ -3,6 +3,8 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- vaultauth.yaml
|
||||
- vaultstaticsecret.yaml
|
||||
- oauth2-proxy-configmap.yaml
|
||||
- oauth2-proxy-deployment.yaml
|
||||
@@ -0,0 +1,5 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: vlogs
|
||||
+1
-1
@@ -3,7 +3,7 @@ apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: vlogs-oauth2-env
|
||||
namespace: logging
|
||||
namespace: vlogs
|
||||
data:
|
||||
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
||||
OAUTH2_PROXY_PROVIDER: "oidc"
|
||||
+1
-1
@@ -3,7 +3,7 @@ apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: vlogs-oauth2
|
||||
namespace: logging
|
||||
namespace: vlogs
|
||||
annotations:
|
||||
configmap.reloader.stakater.com/auto: "true"
|
||||
secret.reloader.stakater.com/reload: "vlogs-oauth-credentials,vault-ca-cert"
|
||||
@@ -5,7 +5,7 @@ apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: vlogs-oauth2
|
||||
namespace: logging
|
||||
namespace: vlogs
|
||||
spec:
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
@@ -0,0 +1,18 @@
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultAuth
|
||||
metadata:
|
||||
name: default
|
||||
namespace: vlogs
|
||||
spec:
|
||||
allowedNamespaces:
|
||||
- vlogs
|
||||
kubernetes:
|
||||
audiences:
|
||||
- vault
|
||||
role: default
|
||||
serviceAccount: default
|
||||
tokenExpirationSeconds: 600
|
||||
method: kubernetes
|
||||
mount: k8s/au/syd1
|
||||
vaultConnectionRef: vso-system/default
|
||||
+2
-2
@@ -3,7 +3,7 @@ apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: vlogs-oauth-credentials
|
||||
namespace: logging
|
||||
namespace: vlogs
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
@@ -11,7 +11,7 @@ spec:
|
||||
overwrite: true
|
||||
hmacSecretData: true
|
||||
mount: kv
|
||||
path: kubernetes/namespace/logging/default/vlogs-oauth-credentials
|
||||
path: kubernetes/namespace/vlogs/default/oauth-credentials
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- ../../../base/vlogs
|
||||
@@ -49,6 +49,7 @@ spec:
|
||||
- path: apps/overlays/*/vm-system
|
||||
- path: apps/overlays/*/vpa-system
|
||||
- path: apps/overlays/*/vault
|
||||
- path: apps/overlays/*/vlogs
|
||||
- path: apps/overlays/*/vso-system
|
||||
- path: apps/overlays/*/woodpecker
|
||||
template:
|
||||
|
||||
@@ -67,6 +67,8 @@ spec:
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: 'vault'
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: 'vlogs'
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: 'woodpecker'
|
||||
server: https://kubernetes.default.svc
|
||||
clusterResourceWhitelist:
|
||||
|
||||
Reference in New Issue
Block a user