first commit
This commit is contained in:
@@ -5,28 +5,37 @@ Layer 2 (Gateway infrastructure) for the **catalog** bounded context
|
|||||||
ID (created by `../konnect-platform`, never recreated here).
|
ID (created by `../konnect-platform`, never recreated here).
|
||||||
|
|
||||||
**This repo does NOT hold `KonnectAPIAuthConfiguration`/`GatewayConfiguration`/
|
**This repo does NOT hold `KonnectAPIAuthConfiguration`/`GatewayConfiguration`/
|
||||||
`Gateway` YAML directly.** The actual resource template (one copy, covering
|
`Gateway`/`Certificate` YAML directly.** The actual resource template (one
|
||||||
every domain/environment) lives in `../k8s-platform/dataplane-template/`,
|
copy, covering every domain/environment) lives in
|
||||||
`${VAR}`-parameterized. This repo only holds the values for one
|
`../k8s-platform/dataplane-template/`, `${VAR}`-parameterized. This repo
|
||||||
`<env>/<gateway-type>/` — the Helm-`values.yaml` equivalent:
|
only holds what's specific to one `<env>/<gateway-type>/` — two files:
|
||||||
|
|
||||||
- `configmap.yaml` — non-sensitive values (domain, env, namespace, Control
|
|
||||||
Plane ID, image, hostname...).
|
|
||||||
- `secret.yaml` — the Konnect PAT. **Gitignored, never committed** — copy
|
|
||||||
`secret.yaml.example` to `secret.yaml` and fill in the real token locally.
|
|
||||||
- `kustomization.yaml` — a Flux `Kustomization` CR (not a plain Kustomize
|
- `kustomization.yaml` — a Flux `Kustomization` CR (not a plain Kustomize
|
||||||
build file, despite the name) that builds `../k8s-platform/dataplane-template/`
|
build file, despite the name) that builds `../k8s-platform/dataplane-template/`
|
||||||
from a `GitRepository` source and substitutes values from the ConfigMap
|
from the `k8s-platform` `GitRepository` source. Domain-specific
|
||||||
and Secret above (`postBuild.substituteFrom`).
|
non-sensitive values (`NAME`, `NAMESPACE`, `CONTROL_PLANE_ID`, `HOSTNAME`,
|
||||||
|
`TLS_ISSUER_NAME`) are inline under `spec.postBuild.substitute` — no
|
||||||
|
separate ConfigMap to forget to re-apply after an edit (bit us twice
|
||||||
|
before this got simplified). Cluster-wide defaults (`KONNECT_SERVER_URL`,
|
||||||
|
`GATEWAY_IMAGE`, `REPLICAS`, `TLS_ISSUER_KIND`) come from
|
||||||
|
`dataplane-template-defaults`, a ConfigMap shared by every domain, via
|
||||||
|
`substituteFrom`.
|
||||||
|
- `externalsecret.yaml` — an `ExternalSecret` (External Secrets Operator)
|
||||||
|
that pulls the Konnect PAT from Vault (`secrets/kong-v2/catalog/dev/konnect-pat`
|
||||||
|
at `https://vault.sttlab.eu`, via the shared `ClusterSecretStore
|
||||||
|
vault-kong-v2`) and materializes it directly as `catalog-dev-konnect-auth`
|
||||||
|
in the `catalog` namespace. **Not part of the substitute/substituteFrom
|
||||||
|
flow above** — Flux's substitution would have required the real PAT to
|
||||||
|
sit in a Secret in `flux-system` (shared, broadly-readable namespace)
|
||||||
|
before landing here, which was rejected. Rotation is now just "update the
|
||||||
|
value in Vault" — `ExternalSecret`'s `refreshInterval` (1h) picks it up
|
||||||
|
automatically, nothing to touch in the cluster or in git.
|
||||||
|
|
||||||
Content (the ConfigMap/Secret pair) is generated and PR'd automatically
|
Content here is generated and PR'd automatically when the matching Control
|
||||||
when the matching Control Plane is created via the self-service flow in
|
Plane is created via the self-service flow in `../konnect-platform` — never
|
||||||
`../konnect-platform` — never hand-edited directly.
|
hand-edited directly.
|
||||||
|
|
||||||
**Not yet applied/validated**: `kustomization.yaml`'s `sourceRef` points at
|
**Deployed and validated on the local cluster (2026-08-19)**: full chain
|
||||||
a `GitRepository` named `k8s-platform` that doesn't exist yet — this repo
|
working end-to-end — `KonnectAPIAuthConfiguration` `Valid: True`, `Gateway`
|
||||||
has no git remote (see `../STATUS.md`), so `source-controller` has nothing
|
`Programmed: True`, a real `DataPlane` pod running, TLS cert issued by the
|
||||||
to clone. `configmap.yaml` and `secret.yaml` have been applied directly
|
`sttlab-local-ca` ClusterIssuer, Konnect PAT synced live from Vault via ESO.
|
||||||
(`kubectl apply -f`) to validate they're well-formed, but the actual
|
|
||||||
generate-a-Gateway-from-the-template flow hasn't been exercised end-to-end
|
|
||||||
yet — that requires the `GitRepository` to exist first.
|
|
||||||
|
|||||||
Reference in New Issue
Block a user