Template defaults
This commit is contained in:
@@ -1,2 +1,5 @@
|
|||||||
.DS_Store
|
.DS_Store
|
||||||
*.swp
|
*.swp
|
||||||
|
|
||||||
|
# Real SSH key material — never committed. Commit gitrepository-secret.yaml.example instead.
|
||||||
|
**/gitrepository-secret.yaml
|
||||||
|
|||||||
@@ -0,0 +1,16 @@
|
|||||||
|
# Not a self-signed cert hand-copied into a Secret like
|
||||||
|
# ~/dev/kong/kube/gateway/apigw/secret.yaml does — issuer is per-domain/env
|
||||||
|
# config (e.g. sttlab-local-ca ClusterIssuer for local, a real ACME issuer
|
||||||
|
# for prod), not hardcoded here.
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: ${NAME}
|
||||||
|
namespace: ${NAMESPACE}
|
||||||
|
spec:
|
||||||
|
secretName: ${NAME}-tls
|
||||||
|
dnsNames:
|
||||||
|
- ${HOSTNAME}
|
||||||
|
issuerRef:
|
||||||
|
kind: ${TLS_ISSUER_KIND}
|
||||||
|
name: ${TLS_ISSUER_NAME}
|
||||||
@@ -21,4 +21,4 @@ spec:
|
|||||||
tls:
|
tls:
|
||||||
certificateRefs:
|
certificateRefs:
|
||||||
- kind: Secret
|
- kind: Secret
|
||||||
name: ${TLS_SECRET_NAME}
|
name: ${NAME}-tls
|
||||||
|
|||||||
@@ -6,5 +6,5 @@ metadata:
|
|||||||
spec:
|
spec:
|
||||||
type: secretRef
|
type: secretRef
|
||||||
secretRef:
|
secretRef:
|
||||||
name: ${KONNECT_AUTH_SECRET_NAME}
|
name: ${NAME}-konnect-auth
|
||||||
serverURL: ${KONNECT_SERVER_URL}
|
serverURL: ${KONNECT_SERVER_URL}
|
||||||
|
|||||||
@@ -5,3 +5,4 @@ resources:
|
|||||||
- gatewayconfiguration.yaml
|
- gatewayconfiguration.yaml
|
||||||
- gateway.yaml
|
- gateway.yaml
|
||||||
- secret.yaml
|
- secret.yaml
|
||||||
|
- certificate.yaml
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Secret
|
kind: Secret
|
||||||
metadata:
|
metadata:
|
||||||
name: ${KONNECT_AUTH_SECRET_NAME}
|
name: ${NAME}-konnect-auth
|
||||||
namespace: ${NAMESPACE}
|
namespace: ${NAMESPACE}
|
||||||
labels:
|
labels:
|
||||||
konghq.com/credential: konnect
|
konghq.com/credential: konnect
|
||||||
|
|||||||
@@ -0,0 +1,25 @@
|
|||||||
|
# Shape of the k8s-platform-git-auth Secret that gitrepository.yaml's
|
||||||
|
# secretRef points at — created directly via `kubectl create secret`
|
||||||
|
# (never written to a real file, real key material never committed):
|
||||||
|
#
|
||||||
|
# kubectl create secret generic k8s-platform-git-auth \
|
||||||
|
# -n flux-system \
|
||||||
|
# --from-file=identity=$HOME/.ssh/id_rsa \
|
||||||
|
# --from-file=identity.pub=$HOME/.ssh/id_rsa.pub \
|
||||||
|
# --from-file=known_hosts=<(ssh-keyscan -p 2222 gitea.sttlab.eu)
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: k8s-platform-git-auth
|
||||||
|
namespace: flux-system
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
identity: |
|
||||||
|
-----BEGIN OPENSSH PRIVATE KEY-----
|
||||||
|
PLACEHOLDER
|
||||||
|
-----END OPENSSH PRIVATE KEY-----
|
||||||
|
identity.pub: ssh-rsa PLACEHOLDER
|
||||||
|
known_hosts: |
|
||||||
|
[gitea.sttlab.eu]:2222 ssh-ed25519 PLACEHOLDER
|
||||||
|
[gitea.sttlab.eu]:2222 ssh-rsa PLACEHOLDER
|
||||||
|
[gitea.sttlab.eu]:2222 ecdsa-sha2-nistp256 PLACEHOLDER
|
||||||
+11
-8
@@ -1,9 +1,5 @@
|
|||||||
# Not applied yet: url is a PLACEHOLDER, this repo has no git remote (see
|
|
||||||
# ../../STATUS.md). Once it does, this object is what makes source-controller
|
|
||||||
# actually clone it — nothing else does.
|
|
||||||
#
|
|
||||||
# Bootstrap step, same category as installing the Flux Operator itself
|
# Bootstrap step, same category as installing the Flux Operator itself
|
||||||
# (see ../README.md): this file must be applied manually once
|
# (see ../README.md): this file was applied manually once
|
||||||
# (`kubectl apply -f gitrepository.yaml`), because nothing can apply it
|
# (`kubectl apply -f gitrepository.yaml`), because nothing can apply it
|
||||||
# automatically before it exists — Flux can't fetch the object that tells it
|
# automatically before it exists — Flux can't fetch the object that tells it
|
||||||
# where to fetch from. After that one-time apply, since this file lives
|
# where to fetch from. After that one-time apply, since this file lives
|
||||||
@@ -12,9 +8,14 @@
|
|||||||
# would keep it (and everything else here) self-managing going forward —
|
# would keep it (and everything else here) self-managing going forward —
|
||||||
# not scaffolded yet, out of scope for this file.
|
# not scaffolded yet, out of scope for this file.
|
||||||
#
|
#
|
||||||
|
# secretRef -> k8s-platform-git-auth: SSH identity/known_hosts, created
|
||||||
|
# directly via `kubectl create secret` (never written to a file), backed by
|
||||||
|
# ~/.ssh/id_rsa (fingerprint SHA256:+BneVyWyJgOlDvISQ597e9YTXmd3GPpN9XHcItgQGKk,
|
||||||
|
# already an authorized key on this Gitea account).
|
||||||
|
#
|
||||||
# Any other repo's Kustomization (e.g. dataplane-catalog's
|
# Any other repo's Kustomization (e.g. dataplane-catalog's
|
||||||
# flux-kustomization.yaml) can reference this SAME GitRepository by name —
|
# kustomization.yaml) can reference this SAME GitRepository by name — one
|
||||||
# one GitRepository per source repo, not per consumer.
|
# GitRepository per source repo, not per consumer.
|
||||||
apiVersion: source.toolkit.fluxcd.io/v1
|
apiVersion: source.toolkit.fluxcd.io/v1
|
||||||
kind: GitRepository
|
kind: GitRepository
|
||||||
metadata:
|
metadata:
|
||||||
@@ -22,6 +23,8 @@ metadata:
|
|||||||
namespace: flux-system
|
namespace: flux-system
|
||||||
spec:
|
spec:
|
||||||
interval: 5m
|
interval: 5m
|
||||||
url: PLACEHOLDER # e.g. https://github.com/<org>/k8s-platform
|
url: ssh://git@gitea.sttlab.eu:2222/stt/kong-k8s-platform.git
|
||||||
|
secretRef:
|
||||||
|
name: k8s-platform-git-auth
|
||||||
ref:
|
ref:
|
||||||
branch: main
|
branch: main
|
||||||
|
|||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# Cluster-wide defaults for the dataplane-template ${VAR}s. NOT part of
|
||||||
|
# dataplane-template/ itself (that folder is what gets built+applied once
|
||||||
|
# per domain into its own namespace — this ConfigMap is applied once,
|
||||||
|
# cluster-wide, in flux-system). Each domain's Kustomization lists this
|
||||||
|
# FIRST in postBuild.substituteFrom, then its own ConfigMap/Secret after —
|
||||||
|
# Flux applies "last wins" precedence across substituteFrom entries, so a
|
||||||
|
# domain can still override any of these if it ever needs to.
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: dataplane-template-defaults
|
||||||
|
namespace: flux-system
|
||||||
|
data:
|
||||||
|
KONNECT_SERVER_URL: eu.api.konghq.com
|
||||||
|
GATEWAY_IMAGE: kong/kong-gateway:3.15
|
||||||
|
REPLICAS: "1"
|
||||||
|
TLS_ISSUER_KIND: ClusterIssuer
|
||||||
@@ -2,3 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
- gatewayclass.yaml
|
- gatewayclass.yaml
|
||||||
|
- dataplane-template-defaults.yaml
|
||||||
|
|||||||
Reference in New Issue
Block a user