4434265cf65e3c4dc928e2b9117d2328d1002f10
The clouddns approach is dropped in favour of self-delegating the ACME challenge to our own BIND: a one-time CNAME sends _acme-challenge.unkin.net into acme.unkin.net (served by bind-external), and cert-manager solves DNS-01 via RFC2136+TSIG against it. No GCP service account or Vault KV secret needed. - Replace the dns01 clouddns solver in both ClusterIssuers with rfc2136 (nameserver 198.18.199.53:53, key certmanager, HMACSHA256, secret certmanager-tsig reflected into the cert-manager namespace). - Remove the now-unneeded VaultAuth, VaultStaticSecret and clouddns ServiceAccount. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
argocd-apps docs
Operational notes for the manifests in this repo.
| Doc | What it covers |
|---|---|
| cnpg-backups.md | How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured. |
| cnpg-restore.md | Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas. |
| authentik-rancher-sso.md | Manual runtime step to point Rancher's OIDC auth at the canonical identity.unkin.net issuer and trust the internal CA. |
| gitea-migration.md | Staged cutover of the git.unkin.net forge from the Puppet VM to the gitea namespace. |
Description
Languages
Shell
88.8%
Makefile
11.2%