Files
argocd-apps/apps/base/dhcp-system/cr/keaapi.yaml
T
Ben Vincent 53090d1798
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
Deploy kea DHCP operator to dhcp-system
Replaces the isc-dhcpd PXE-boot VM with the kea-operator (v0.1.0) and an
HA kea pair, managed by ArgoCD. Deploys on a new, unused anycast IP; the
production cutover off the current dhcpd address is a separate later task.

- Add apps/base/dhcp-system: namespace, kea-operator RBAC + Deployment,
  VPA, and the kea.unkin.net CRDs pulled from the operator repo at v0.1.0.
- Add the CRs translating the legacy dhcpd config: KeaCluster (2 replicas,
  hot-standby HA, main.unkin.net, 1200/86400 leases, AU ntp pool), five
  KeaSubnets 198.18.13-17.0/24 (gateways .254 except .17->.1 per the puppet
  dhcp hieradata), Legacy/UEFI-64 PXE client classes, and the KeaAPI.
- Pin the DHCP LoadBalancer Service to the free common-pool IP 198.18.200.10
  via PureLB (not the current dhcpd anycast 198.18.19.18).
- Provision the KeaAPI bearer token via an operator-generated Secret.
- Commit generated kea.unkin.net JSON schemas for kubeconform.
- Register dhcp-system in the platform ApplicationSet and AppProject.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-02 21:43:11 +10:00

26 lines
638 B
YAML

---
# Terraform-friendly REST API for KeaSubnet/KeaClientClass CRUD. The bearer
# token Secret is generated by the operator when absent (no plain Secret is
# committed here); it can later be pre-seeded from Vault under the same name.
apiVersion: kea.unkin.net/v1alpha1
kind: KeaAPI
metadata:
name: kea-api
namespace: dhcp-system
annotations:
argocd.argoproj.io/sync-wave: "1"
spec:
replicas: 1
image: git.unkin.net/unkin/kea-api:v0.1.0
tokenSecretName: kea-api-token
service:
type: ClusterIP
port: 8080
resources:
requests:
cpu: 100m
memory: 64Mi
limits:
cpu: "1"
memory: 256Mi