Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,6 @@ The cluster-deployment tools here include helm charts and ansible playbooks to s
* Helm4
* Mozilla [sops](https://github.com/mozilla/sops/blob/master/README.rst) with encryption (to keep credentials in local git repo)
* Encryption for internal etcd
* MFA using [Authelia](https://github.com/clems4ever/authelia) and Google Authenticator
* Calico or flannel networking
* Envoy API gateway
* Local-volume sync
Expand Down
1 change: 1 addition & 0 deletions ansible/roles/network/defaults/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,7 @@ ubuntu_packages:
- dnsutils
- net-tools
- psmisc
- socat

vrrp:
VI_1:
Expand Down
23 changes: 14 additions & 9 deletions k8s/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,8 +145,6 @@ configuration.

Set up a local admin repo to define helm overrides and environment variables, git-cloned under the path ~/docker/k8s/admin. Within the admin repo, create a subdirectory `services` with a file `values.yaml` containing any site-specific overrides, such as:
```
authelia
fqdn: authtotp.mydomain.com
domain: mydomain.com
serviceAccount:
name: instantlinux-privileged
Expand Down Expand Up @@ -230,17 +228,24 @@ Look in the k8s/install subdirectory for resources in namespace-user.yaml for ex

To configure k8s resources, first define a helm override file `infra.yaml` with content like these (define names to suit your environment):
```
authelia:
namespace: instantlinux
certManager:
email: admin@ci.net
solvers:
dns01:
enabled: true
groupName: acme.ci.net
gateway:
internalCA:
commonName: MyCompany k8s root
subject:
organizations: [ MyCompany.com ]
gateways:
- name: gateway-1
class: envoy-internal
config: envoy-config-internal
nodeport_http: 30180
nodeport_https: 30543
- name: gateway-2
allowNamespaces: [ mynamespace ]
class: envoy-external
config: envoy-config-external
nodeport_http: 30080
nodeport_https: 30443
```
You'll need an account at letsencrypt, and a dns-apikey secret (with user and key) stored in cert-manager namespace. Invoke the following in this directory ([k8s](https://github.com/instantlinux/docker-tools/tree/main/k8s)):
```
Expand Down
2 changes: 1 addition & 1 deletion k8s/helm/apache/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ sources:
- https://github.com/instantlinux/docker-tools
- https://github.com/apache/httpd
type: application
version: 0.1.1
version: 0.1.2
appVersion: "2.4.68"
dependencies:
- name: chartlib
Expand Down
6 changes: 6 additions & 0 deletions k8s/helm/apache/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,12 @@ deployment:
exec httpd-foreground
containerPorts:
- containerPort: 80
resources:
limits:
memory: 512Mi
requests:
cpu: 50m
memory: 64Mi
volumeMounts:
- mountPath: /usr/local/apache2/conf/custom.conf
name: config
Expand Down
4 changes: 2 additions & 2 deletions k8s/helm/headscale/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@ sources:
- https://github.com/instantlinux/docker-tools
- https://github.com/juanfont/headscale
type: application
version: 0.1.2
appVersion: "0.29.3"
version: 0.29.3
appVersion: 0.29.3
dependencies:
- name: chartlib
version: 0.1.11
Expand Down
11 changes: 11 additions & 0 deletions k8s/helm/headscale/templates/gateway-backend.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: BackendTrafficPolicy
metadata:
name: {{ include "local.fullname" . }}-tailscale
spec:
targetRefs:
- group: gateway.networking.k8s.io
kind: HTTPRoute
name: {{ include "local.fullname" . }}
httpUpgrade:
- type: tailscale-control-protocol
2 changes: 1 addition & 1 deletion k8s/helm/infra/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ home: https://github.com/instantlinux/docker-tools
sources:
- https://github.com/instantlinux/docker-tools
type: application
version: 0.1.2
version: 0.1.3
appVersion: "0.1.0"
dependencies:
- name: chartlib
Expand Down
5 changes: 5 additions & 0 deletions k8s/helm/infra/templates/gateway.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,11 @@ spec:
port: 443
protocol: TCP
nodePort: {{ .nodeport_https }}
{{- if or (not (hasKey $gateway "accessLog")) (not $gateway.accessLog) }}
telemetry:
accessLog:
disable: true
{{- end }}
---
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
Expand Down
1 change: 1 addition & 0 deletions k8s/helm/infra/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ gateways:
# gateway resources will launch in the namespace defined at top; to
# allow listenersets from other namespaces, list them here
# allowNamespaces: [ myapp ]
accessLog: false
class: envoy-internal
config: envoy-config-internal
crdNamespace: envoy-gateway-system
Expand Down
4 changes: 2 additions & 2 deletions k8s/helm/restic/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,10 @@ sources:
- https://github.com/instantlinux/docker-tools
- https://github.com/restic/restic
type: application
version: 0.1.27
version: 0.18.1-8
# Remember to update restic==<ver> in values.yaml as releases are published;
# the values.yaml file is not able to reference .Chart.appVersion
appVersion: "0.18.1-r7"
appVersion: "0.18.1-r8"
dependencies:
- name: chartlib
version: 0.1.11
Expand Down
2 changes: 1 addition & 1 deletion k8s/helm/restic/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ deployment:
mkdir -p /var/log/week && tail -f -n 0 /var/log/restic.log
env:
# Edit the version in Chart.yaml to keep consistent
app_version: 0.18.1-r7
app_version: 0.18.1-r8
env: /etc/profile
tz: UTC
nodeSelector:
Expand Down
2 changes: 2 additions & 0 deletions k8s/install/namespace-user.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,8 @@ rules:
verbs: ["*"]
- apiGroups: [gateway.envoyproxy.io]
resources:
- backendtrafficpolicies
- clienttrafficpolicies
- securitypolicies
verbs: ["*"]
- apiGroups: [gateway.networking.k8s.io]
Expand Down
Loading