Stéphane Tailland e8c1a48423 first commit
2026-08-19 18:56:29 +02:00
2026-08-19 18:55:06 +02:00
2026-08-19 18:55:06 +02:00
2026-08-19 18:56:29 +02:00

dataplane-catalog

Layer 2 (Gateway infrastructure) for the catalog bounded context (domain team: catalog) — one Control Plane per environment, referenced by ID (created by ../konnect-platform, never recreated here).

This repo does NOT hold KonnectAPIAuthConfiguration/GatewayConfiguration/ Gateway/Certificate YAML directly. The actual resource template (one copy, covering every domain/environment) lives in ../k8s-platform/dataplane-template/, ${VAR}-parameterized. This repo only holds what's specific to one <env>/<gateway-type>/ — two files:

  • kustomization.yaml — a Flux Kustomization CR (not a plain Kustomize build file, despite the name) that builds ../k8s-platform/dataplane-template/ from the k8s-platform GitRepository source. Domain-specific non-sensitive values (NAME, NAMESPACE, CONTROL_PLANE_ID, HOSTNAME, TLS_ISSUER_NAME) are inline under spec.postBuild.substitute — no separate ConfigMap to forget to re-apply after an edit (bit us twice before this got simplified). Cluster-wide defaults (KONNECT_SERVER_URL, GATEWAY_IMAGE, REPLICAS, TLS_ISSUER_KIND) come from dataplane-template-defaults, a ConfigMap shared by every domain, via substituteFrom.
  • externalsecret.yaml — an ExternalSecret (External Secrets Operator) that pulls the Konnect PAT from Vault (secrets/kong-v2/catalog/dev/konnect-pat at https://vault.sttlab.eu, via the shared ClusterSecretStore vault-kong-v2) and materializes it directly as catalog-dev-konnect-auth in the catalog namespace. Not part of the substitute/substituteFrom flow above — Flux's substitution would have required the real PAT to sit in a Secret in flux-system (shared, broadly-readable namespace) before landing here, which was rejected. Rotation is now just "update the value in Vault" — ExternalSecret's refreshInterval (1h) picks it up automatically, nothing to touch in the cluster or in git.

Content here is generated and PR'd automatically when the matching Control Plane is created via the self-service flow in ../konnect-platform — never hand-edited directly.

Deployed and validated on the local cluster (2026-08-19): full chain working end-to-end — KonnectAPIAuthConfiguration Valid: True, Gateway Programmed: True, a real DataPlane pod running, TLS cert issued by the sttlab-local-ca ClusterIssuer, Konnect PAT synced live from Vault via ESO.

S
Description
No description provided
Readme 32 KiB