Ben Vincent 779e448686
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
Add Let's Encrypt DNS-01 clouddns ClusterIssuers
unkin.net public DNS is delegated to Google Cloud DNS, so publicly-trusted
wildcard certs need an ACME issuer using cert-manager's clouddns DNS-01
solver. The existing vault-issuer (internal PKI) is unchanged.

- Add ClusterIssuers letsencrypt (prod) and letsencrypt-staging, both using
  a dns01 clouddns solver with a GCP service-account key.
- Sync that key from Vault KV into Secret cert-manager-clouddns via a
  VaultStaticSecret + VaultAuth (role cert_manager_clouddns) and a dedicated
  cert-manager-clouddns service account.
- Wire the new files into the base kustomization.
- Whitelist cert-manager.io ClusterIssuer in the platform AppProject.

The clouddns project and the KV secret value are set out-of-band.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-02 17:07:18 +10:00
2026-03-01 16:34:01 +11:00

argocd-apps docs

Operational notes for the manifests in this repo.

Doc What it covers
cnpg-backups.md How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured.
cnpg-restore.md Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas.
authentik-rancher-sso.md Manual runtime step to point Rancher's OIDC auth at the canonical identity.unkin.net issuer and trust the internal CA.
gitea-migration.md Staged cutover of the git.unkin.net forge from the Puppet VM to the gitea namespace.
S
Description
GitOps for ArgoCD
Readme 4.8 MiB
Languages
Shell 88.8%
Makefile 11.2%