# dataplane-catalog Layer 2 (Gateway infrastructure) for the **catalog** bounded context (domain team: catalog) — one Control Plane per environment, referenced by ID (created by `../konnect-platform`, never recreated here). **This repo does NOT hold `KonnectAPIAuthConfiguration`/`GatewayConfiguration`/ `Gateway`/`Certificate` YAML directly.** The actual resource template (one copy, covering every domain/environment) lives in `../k8s-platform/dataplane-template/`, `${VAR}`-parameterized. This repo only holds what's specific to one `//` — two files: - `kustomization.yaml` — a Flux `Kustomization` CR (not a plain Kustomize build file, despite the name) that builds `../k8s-platform/dataplane-template/` from the `k8s-platform` `GitRepository` source. Domain-specific non-sensitive values (`NAME`, `NAMESPACE`, `CONTROL_PLANE_ID`, `HOSTNAME`, `TLS_ISSUER_NAME`) are inline under `spec.postBuild.substitute` — no separate ConfigMap to forget to re-apply after an edit (bit us twice before this got simplified). Cluster-wide defaults (`KONNECT_SERVER_URL`, `GATEWAY_IMAGE`, `REPLICAS`, `TLS_ISSUER_KIND`) come from `dataplane-template-defaults`, a ConfigMap shared by every domain, via `substituteFrom`. - `externalsecret.yaml` — an `ExternalSecret` (External Secrets Operator) that pulls the Konnect PAT from Vault (`secrets/kong-v2/catalog/dev/konnect-pat` at `https://vault.sttlab.eu`, via the shared `ClusterSecretStore vault-kong-v2`) and materializes it directly as `catalog-dev-konnect-auth` in the `catalog` namespace. **Not part of the substitute/substituteFrom flow above** — Flux's substitution would have required the real PAT to sit in a Secret in `flux-system` (shared, broadly-readable namespace) before landing here, which was rejected. Rotation is now just "update the value in Vault" — `ExternalSecret`'s `refreshInterval` (1h) picks it up automatically, nothing to touch in the cluster or in git. Content here is generated and PR'd automatically when the matching Control Plane is created via the self-service flow in `../konnect-platform` — never hand-edited directly. **Deployed and validated on the local cluster (2026-08-19)**: full chain working end-to-end — `KonnectAPIAuthConfiguration` `Valid: True`, `Gateway` `Programmed: True`, a real `DataPlane` pod running, TLS cert issued by the `sttlab-local-ca` ClusterIssuer, Konnect PAT synced live from Vault via ESO.