refactor: derive the kubeconfig mesh endpoint in terraform (#103)

Signed-off-by: Devin Buhl <devin@buhl.casa>
This commit is contained in:
Devin Buhl
2026-07-16 09:31:15 -04:00
committed by GitHub
parent d39642be3a
commit 5ea3585222
2 changed files with 11 additions and 6 deletions
+3 -5
View File
@@ -73,12 +73,10 @@ dir = "{{cwd}}"
run = """
: "${ENVIRONMENT:?set ENVIRONMENT=staging (or production) first}"
mkdir -p {{config_root}}/.private/${ENVIRONMENT}
mise run tg run --working-dir deployment/modules/talos/cluster output -- -raw kubeconfig > {{config_root}}/.private/${ENVIRONMENT}/kubeconfig
# HA endpoint fronted by the mesh gateway (Envoy TLS-passthrough -> apiservers), so kubectl
# is no longer pinned to one CP. Break-glass for bootstrap/DR before the gateway is up:
# The kubeconfig output already points at the HA mesh endpoint (kube.<zone>, rewritten in
# talos/cluster outputs.tf). Break-glass for bootstrap/DR before the gateway is up:
# kubectl --server=https://<cp-private-ip>:6443 (each CP private IP is an apiserver cert SAN).
if [ "${ENVIRONMENT}" = "production" ]; then MESH_HOST="kube.o11y.futo.network"; else MESH_HOST="kube.${ENVIRONMENT}.o11y.futo.network"; fi
sd 'server: https://10[.]150[.][0-9]+[.]5:6443' "server: https://${MESH_HOST}:6443" {{config_root}}/.private/${ENVIRONMENT}/kubeconfig
mise run tg run --working-dir deployment/modules/talos/cluster output -- -raw kubeconfig > {{config_root}}/.private/${ENVIRONMENT}/kubeconfig
chmod 600 {{config_root}}/.private/${ENVIRONMENT}/kubeconfig
"""
description = "Fetch kubeconfig for $ENVIRONMENT into .private/<env>/ (server = HA mesh endpoint kube.<zone>)"
+8 -1
View File
@@ -16,7 +16,14 @@ output "talos_client_configuration" {
value = data.talos_client_configuration.this.talos_config
}
# Server rewritten from the (in-cluster-only) VIP to the HA mesh endpoint, so the zone
# special-case lives only in netbird/cluster's mesh_dns_zone. Break-glass for bootstrap/DR
# before the gateway exists: kubectl --server=https://<cp-private-ip>:6443 (all cert SANs).
output "kubeconfig" {
sensitive = true
value = talos_cluster_kubeconfig.this.kubeconfig_raw
value = replace(
talos_cluster_kubeconfig.this.kubeconfig_raw,
"server: ${local.cluster_endpoint}",
"server: https://kube.${var.mesh_dns_zone}:6443",
)
}