From bc2d40ebfbc1c2849cec5cad1acbc8763b8de78b Mon Sep 17 00:00:00 2001 From: Rich Braun Date: Sun, 27 Sep 2026 11:25:34 -0700 Subject: [PATCH 1/2] SYS-685 disable gateway access logs, fix headscale for gateway --- README.md | 1 - ansible/roles/network/defaults/main.yml | 1 + k8s/README.md | 23 +++++++++++-------- k8s/helm/apache/Chart.yaml | 2 +- k8s/helm/apache/values.yaml | 6 +++++ k8s/helm/headscale/Chart.yaml | 4 ++-- .../headscale/templates/gateway-backend.yaml | 11 +++++++++ k8s/helm/infra/Chart.yaml | 2 +- k8s/helm/infra/templates/gateway.yaml | 5 ++++ k8s/helm/infra/values.yaml | 1 + k8s/helm/restic/Chart.yaml | 4 ++-- k8s/helm/restic/values.yaml | 2 +- k8s/install/namespace-user.yaml | 2 ++ 13 files changed, 47 insertions(+), 17 deletions(-) create mode 100644 k8s/helm/headscale/templates/gateway-backend.yaml diff --git a/README.md b/README.md index c3d4a159..6f5cab07 100644 --- a/README.md +++ b/README.md @@ -32,7 +32,6 @@ The cluster-deployment tools here include helm charts and ansible playbooks to s * Helm4 * Mozilla [sops](https://github.com/mozilla/sops/blob/master/README.rst) with encryption (to keep credentials in local git repo) * Encryption for internal etcd -* MFA using [Authelia](https://github.com/clems4ever/authelia) and Google Authenticator * Calico or flannel networking * Envoy API gateway * Local-volume sync diff --git a/ansible/roles/network/defaults/main.yml b/ansible/roles/network/defaults/main.yml index 2d8f3c82..5be2d4e1 100644 --- a/ansible/roles/network/defaults/main.yml +++ b/ansible/roles/network/defaults/main.yml @@ -75,6 +75,7 @@ ubuntu_packages: - dnsutils - net-tools - psmisc + - socat vrrp: VI_1: diff --git a/k8s/README.md b/k8s/README.md index c427ba93..e2cee4f1 100644 --- a/k8s/README.md +++ b/k8s/README.md @@ -145,8 +145,6 @@ configuration. Set up a local admin repo to define helm overrides and environment variables, git-cloned under the path ~/docker/k8s/admin. Within the admin repo, create a subdirectory `services` with a file `values.yaml` containing any site-specific overrides, such as: ``` -authelia - fqdn: authtotp.mydomain.com domain: mydomain.com serviceAccount: name: instantlinux-privileged @@ -230,17 +228,24 @@ Look in the k8s/install subdirectory for resources in namespace-user.yaml for ex To configure k8s resources, first define a helm override file `infra.yaml` with content like these (define names to suit your environment): ``` -authelia: - namespace: instantlinux certManager: email: admin@ci.net - solvers: - dns01: - enabled: true - groupName: acme.ci.net -gateway: + internalCA: + commonName: MyCompany k8s root + subject: + organizations: [ MyCompany.com ] +gateways: +- name: gateway-1 + class: envoy-internal + config: envoy-config-internal nodeport_http: 30180 nodeport_https: 30543 +- name: gateway-2 + allowNamespaces: [ mynamespace ] + class: envoy-external + config: envoy-config-external + nodeport_http: 30080 + nodeport_https: 30443 ``` You'll need an account at letsencrypt, and a dns-apikey secret (with user and key) stored in cert-manager namespace. Invoke the following in this directory ([k8s](https://github.com/instantlinux/docker-tools/tree/main/k8s)): ``` diff --git a/k8s/helm/apache/Chart.yaml b/k8s/helm/apache/Chart.yaml index 89bd0c8a..7f4fa991 100644 --- a/k8s/helm/apache/Chart.yaml +++ b/k8s/helm/apache/Chart.yaml @@ -6,7 +6,7 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/apache/httpd type: application -version: 0.1.1 +version: 0.1.2 appVersion: "2.4.68" dependencies: - name: chartlib diff --git a/k8s/helm/apache/values.yaml b/k8s/helm/apache/values.yaml index 5c59353b..b004c89e 100644 --- a/k8s/helm/apache/values.yaml +++ b/k8s/helm/apache/values.yaml @@ -15,6 +15,12 @@ deployment: exec httpd-foreground containerPorts: - containerPort: 80 + resources: + limits: + memory: 512Mi + requests: + cpu: 50m + memory: 64Mi volumeMounts: - mountPath: /usr/local/apache2/conf/custom.conf name: config diff --git a/k8s/helm/headscale/Chart.yaml b/k8s/helm/headscale/Chart.yaml index d6c2f66a..8d412b39 100644 --- a/k8s/helm/headscale/Chart.yaml +++ b/k8s/helm/headscale/Chart.yaml @@ -6,8 +6,8 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/juanfont/headscale type: application -version: 0.1.2 -appVersion: "0.29.3" +version: 0.29.3 +appVersion: 0.29.3 dependencies: - name: chartlib version: 0.1.11 diff --git a/k8s/helm/headscale/templates/gateway-backend.yaml b/k8s/helm/headscale/templates/gateway-backend.yaml new file mode 100644 index 00000000..4b5328ab --- /dev/null +++ b/k8s/helm/headscale/templates/gateway-backend.yaml @@ -0,0 +1,11 @@ +apiVersion: gateway.envoyproxy.io/v1alpha1 +kind: BackendTrafficPolicy +metadata: + name: {{ include "local.fullname" . }}-tailscale +spec: + targetRefs: + - group: gateway.networking.k8s.io + kind: HTTPRoute + name: {{ include "local.fullname" . }} + httpUpgrade: + - type: tailscale-control-protocol diff --git a/k8s/helm/infra/Chart.yaml b/k8s/helm/infra/Chart.yaml index 025e2be2..464a4b84 100644 --- a/k8s/helm/infra/Chart.yaml +++ b/k8s/helm/infra/Chart.yaml @@ -5,7 +5,7 @@ home: https://github.com/instantlinux/docker-tools sources: - https://github.com/instantlinux/docker-tools type: application -version: 0.1.2 +version: 0.1.3 appVersion: "0.1.0" dependencies: - name: chartlib diff --git a/k8s/helm/infra/templates/gateway.yaml b/k8s/helm/infra/templates/gateway.yaml index 4d201e75..9606d3b0 100644 --- a/k8s/helm/infra/templates/gateway.yaml +++ b/k8s/helm/infra/templates/gateway.yaml @@ -41,6 +41,11 @@ spec: port: 443 protocol: TCP nodePort: {{ .nodeport_https }} + {{- if or (not (hasKey $gateway "accessLog")) (not $gateway.accessLog) }} + telemetry: + accessLog: + disable: true + {{- end }} --- apiVersion: gateway.networking.k8s.io/v1 kind: Gateway diff --git a/k8s/helm/infra/values.yaml b/k8s/helm/infra/values.yaml index 81936838..068f71cf 100644 --- a/k8s/helm/infra/values.yaml +++ b/k8s/helm/infra/values.yaml @@ -31,6 +31,7 @@ gateways: # gateway resources will launch in the namespace defined at top; to # allow listenersets from other namespaces, list them here # allowNamespaces: [ myapp ] + accessLog: false class: envoy-internal config: envoy-config-internal crdNamespace: envoy-gateway-system diff --git a/k8s/helm/restic/Chart.yaml b/k8s/helm/restic/Chart.yaml index ed703f0d..fbf5bf8e 100644 --- a/k8s/helm/restic/Chart.yaml +++ b/k8s/helm/restic/Chart.yaml @@ -6,10 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/restic/restic type: application -version: 0.1.27 +version: 0.1.28 # Remember to update restic== in values.yaml as releases are published; # the values.yaml file is not able to reference .Chart.appVersion -appVersion: "0.18.1-r7" +appVersion: "0.18.1-r8" dependencies: - name: chartlib version: 0.1.11 diff --git a/k8s/helm/restic/values.yaml b/k8s/helm/restic/values.yaml index 93656397..d794b83e 100644 --- a/k8s/helm/restic/values.yaml +++ b/k8s/helm/restic/values.yaml @@ -17,7 +17,7 @@ deployment: mkdir -p /var/log/week && tail -f -n 0 /var/log/restic.log env: # Edit the version in Chart.yaml to keep consistent - app_version: 0.18.1-r7 + app_version: 0.18.1-r8 env: /etc/profile tz: UTC nodeSelector: diff --git a/k8s/install/namespace-user.yaml b/k8s/install/namespace-user.yaml index 7409ce97..8498e059 100644 --- a/k8s/install/namespace-user.yaml +++ b/k8s/install/namespace-user.yaml @@ -75,6 +75,8 @@ rules: verbs: ["*"] - apiGroups: [gateway.envoyproxy.io] resources: + - backendtrafficpolicies + - clienttrafficpolicies - securitypolicies verbs: ["*"] - apiGroups: [gateway.networking.k8s.io] From 2758d8ea9d2c172a7108b75865a90846a34945c8 Mon Sep 17 00:00:00 2001 From: Rich Braun Date: Sun, 27 Sep 2026 11:46:34 -0700 Subject: [PATCH 2/2] SYS-685 wip --- k8s/helm/restic/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/k8s/helm/restic/Chart.yaml b/k8s/helm/restic/Chart.yaml index fbf5bf8e..f48d9529 100644 --- a/k8s/helm/restic/Chart.yaml +++ b/k8s/helm/restic/Chart.yaml @@ -6,7 +6,7 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/restic/restic type: application -version: 0.1.28 +version: 0.18.1-8 # Remember to update restic== in values.yaml as releases are published; # the values.yaml file is not able to reference .Chart.appVersion appVersion: "0.18.1-r8"