e6e882abfc
The Vault KV layout is kubernetes/namespace/<ns>/<sa>/<secret>, so vlogs and logviewer both running as SA default in the shared logging namespace would collide on one oauth-credentials entry. Splitting vlogs out resolves it without widening any Vault policy. - Move apps/base/logging/vlogs to apps/base/vlogs, namespace vlogs - Add namespace.yaml and a vlogs-scoped VaultAuth (role default) - Point the VaultStaticSecret at kubernetes/namespace/vlogs/default/oauth-credentials - Add the au-syd1 overlay, platform ApplicationSet path and project destination - Move the wildcard-unkin-net-tls reflection from logging to vlogs; vlogs was its only consumer there Secret is already seeded at the new Vault path. Reviewed-on: #507 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
20 lines
400 B
YAML
20 lines
400 B
YAML
---
|
|
# Front-door entry Service: the HTTPRoute for vlogs.unkin.net targets this, so
|
|
# all traffic enters via oauth2-proxy.
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: vlogs-oauth2
|
|
namespace: vlogs
|
|
spec:
|
|
internalTrafficPolicy: Cluster
|
|
ports:
|
|
- name: http
|
|
port: 80
|
|
protocol: TCP
|
|
targetPort: http
|
|
selector:
|
|
app: vlogs-oauth2
|
|
sessionAffinity: None
|
|
type: ClusterIP
|