First commit
This commit is contained in:
@@ -1,9 +1,68 @@
|
||||
# k8s-platform
|
||||
|
||||
Platform-team owned, cluster-scoped only: Kong Gateway Operator install
|
||||
(Helm chart or OLM Subscription on OpenShift). Rare changes, cautious sync
|
||||
(not aggressive auto-sync).
|
||||
Platform-team owned, cluster-scoped only. Rare changes, cautious sync (not
|
||||
aggressive auto-sync).
|
||||
|
||||
Per-domain gateway infrastructure (DataPlane/KonnectExtension) does NOT
|
||||
live here — see the dedicated `dataplane-<domain>` repos, to avoid write
|
||||
contention across domains.
|
||||
Per-domain gateway infrastructure (`Gateway`, `GatewayConfiguration`,
|
||||
`KonnectAPIAuthConfiguration`) does NOT live here — see the dedicated
|
||||
`dataplane-<domain>` repos, to avoid write contention across domains.
|
||||
|
||||
## flux/
|
||||
|
||||
The Flux Operator (`flux-system` namespace) that everything else in this
|
||||
GitOps setup depends on. Installed 2026-08-19 on the local cluster.
|
||||
|
||||
The operator itself is installed manually via Helm — bootstrap problem,
|
||||
Flux can't deploy the thing that deploys it:
|
||||
|
||||
```bash
|
||||
helm install flux-operator oci://ghcr.io/controlplaneio-fluxcd/charts/flux-operator \
|
||||
--namespace flux-system --create-namespace
|
||||
```
|
||||
|
||||
`flux/fluxinstance.yaml` configures the actual Flux controllers
|
||||
(source-controller, kustomize-controller, helm-controller,
|
||||
notification-controller) — tracked in git, applied via
|
||||
`kubectl apply -k flux/`.
|
||||
|
||||
`flux/gitrepository.yaml` is what lets Flux clone this (`k8s-platform`)
|
||||
repo so other repos' `Kustomization`s can reference paths inside it (e.g.
|
||||
`dataplane-template/`). `url` is a `PLACEHOLDER` — this repo has no git
|
||||
remote yet. Once it does, apply it manually once
|
||||
(`kubectl apply -f flux/gitrepository.yaml`) — same bootstrap-chicken-egg
|
||||
reasoning as the operator install above.
|
||||
|
||||
## kong-platform/
|
||||
|
||||
Cluster-wide Kong foundations:
|
||||
- `gatewayclass.yaml` — `GatewayClass` `kong-v2` (deliberately not named
|
||||
`kong`, to avoid touching the pre-existing `kong` GatewayClass that backs
|
||||
the unrelated `tasks`/`jira`/`openrouter` Gateway on this cluster).
|
||||
- `operator/` — `HelmRepository` + `HelmRelease` for the Kong Gateway
|
||||
Operator itself, matching the release already installed manually on this
|
||||
cluster (`helm list -n kong`: chart `kong-operator-1.3.1`, `env.ENABLE_CONTROLLER_KONNECT: true`).
|
||||
`helm-controller` can adopt an existing release under the same
|
||||
`releaseName`/`targetNamespace` rather than reinstalling.
|
||||
|
||||
## dataplane-template/
|
||||
|
||||
The shared `KonnectAPIAuthConfiguration` + `GatewayConfiguration` + `Gateway`
|
||||
+ `Secret` template (one copy, `${VAR}`-parameterized) that every domain's
|
||||
Flux `Kustomization` builds via `postBuild.substitute` — see
|
||||
`dataplane-catalog/README.md` for the full mechanism and the values/secret
|
||||
side of it.
|
||||
|
||||
## Applying today (no git remote yet)
|
||||
|
||||
Nothing here reconciles from git automatically yet — `flux/gitrepository.yaml`
|
||||
has no real URL. Apply directly:
|
||||
|
||||
```bash
|
||||
kubectl apply -k flux/ # fluxinstance.yaml + gitrepository.yaml (the
|
||||
# latter will just sit inert, PLACEHOLDER url)
|
||||
kubectl apply -f kong-platform/gatewayclass.yaml
|
||||
```
|
||||
|
||||
`dataplane-template/` is never applied on its own — it only makes sense
|
||||
built + substituted by a domain's `flux-kustomization.yaml`, which itself
|
||||
can't reconcile yet (needs the real `GitRepository`, see above).
|
||||
|
||||
Reference in New Issue
Block a user