refactor(flux): dedup per-env Kustomizations into base ks.yaml+app layout (#147)

Signed-off-by: Devin Buhl <devin@buhl.casa>
This commit is contained in:
Devin Buhl
2026-07-24 12:49:03 -04:00
committed by GitHub
parent f027e07c9c
commit d20079b97b
211 changed files with 506 additions and 860 deletions
+3 -2
View File
@@ -27,8 +27,9 @@ deployment/modules/
kubernetes/
├── apps/
│ ├── base/ # chart sources + reusable manifests
│ └── <env>/ # env overlay: Flux Kustomizations (version pins + dependsOn)
│ ├── base/<app>/ # ks.yaml (the app's Flux Kustomization) + app/ (chart source + manifests)
│ └── <env>/<ns>/ # namespace overlay: which base apps run; deltas from base as patches/<app>.yaml
├── components/ # shared kustomize Components (targetNamespace replacement)
└── clusters/
└── <env>/
├── apps.yaml # cluster-apps entry point (the Flux Instance points here)
+10 -4
View File
@@ -63,13 +63,19 @@ Kubernetes with flannel CNI and kube-proxy in nftables mode. **Multus** runs as
Everything above the OS is managed by Flux v2. Manifests are organized as reusable bases plus per-environment overlays:
* **`kubernetes/apps/base/`** holds the chart sources and reusable manifests.
* **`kubernetes/apps/<env>/`** holds the per-app Flux Kustomizations — each pins its chart version and declares its `dependsOn` ordering.
* **`kubernetes/apps/base/<app>/`** is the app's single home: `ks.yaml` is its Flux Kustomization (`dependsOn` ordering, health checks) and `app/` is what that Kustomization deploys (chart source + manifests). Both environments reconcile the same definition.
* **`kubernetes/apps/<env>/<ns>/`** is the per-namespace overlay: a kustomization listing which base apps run there, plus the Namespace itself. Anything an environment needs to differ from `base/` is one patch file per app under the overlay's `patches/` — today that's production's version pins.
* **`kubernetes/components/`** holds shared kustomize Components — today just **`replacements/`**, included by every overlay. It copies the overlay Namespace's name into each Flux Kustomization's `spec.targetNamespace`, so an app deploys into whichever namespace lists it and `base/` stays namespace-agnostic. The corollary: an app belongs in the folder of the namespace its resources live in — `mesh-gateway-api` sits under `default/` because its TLSRoute must share a namespace with the `default/kubernetes` Service it fronts. The overlay's namespace is forced onto every namespaced resource (explicit values are overridden), so an app that genuinely needs resources in a foreign namespace would need a `reject` entry in the component.
* **`kubernetes/clusters/<env>/apps.yaml`** is the `cluster-apps` entry point the Flux Instance points at.
### Version pinning
Cluster-wide HelmRelease lifecycle defaults (`crds: CreateReplace` on install and upgrade, `cleanupOnFail`, `RemediateOnFailure` with retries) are defined once in `kubernetes/clusters/<env>/apps.yaml`: `cluster-apps` **appends** them (a JSON6902 `add /spec/patches/-`) to every child Kustomization, which applies them to every HelmRelease it renders — individual releases declare only what deviates. Appending, rather than strategic-merging, is what lets the per-app override patches, which ride the same list, coexist: a strategic-merge there would replace the list and silently erase every override. Every base `ks.yaml` seeds `patches: []` so the append always has a list to land on; a new app that omits it fails the environment build loudly.
Chart (and the CloudNativePG Postgres image) versions are pinned per environment in the overlay Kustomization patches, so a version can be promoted in staging and soaked before production moves. Staging rides `base/` directly; production pins via patches. OCI chart refs pin a **tag and its digest** — Flux gives the digest precedence, so the production patches must carry both or a base digest would silently override the env pin; a renovate custom manager keeps each tag+digest pair in lockstep, and the built-in flux manager maintains the pairs in `base/`. Component versions are not documented here because they change continuously — the manifests are the source of truth.
### Environment overrides
An overlay changes an app by dropping one patch file per app in its `patches/` folder and listing it in the overlay's `patches:` section — so the overlay reads as "these apps, these deltas". Each file patches the app's Flux Kustomization to inject a `spec.patches` override onto whatever resource must differ from `base/`; it has to ride the Kustomization because the app's resources are rendered by Flux from `base/`, never by the overlay build.
Today the only overrides are version pins. Chart (and the CloudNativePG Postgres image) versions are pinned in production, so a version can be promoted in staging — which rides `base/` directly and floats with it — and soaked before production moves. OCI chart refs pin a **tag and its digest** — Flux gives the digest precedence, so the production patches must carry both or a base digest would silently override the env pin; a renovate custom manager keeps each tag+digest pair in lockstep, and the built-in flux manager maintains the pairs in `base/`. Component versions are not documented here because they change continuously — the manifests are the source of truth.
### Configuration substitution
+2 -2
View File
@@ -130,9 +130,9 @@ Logs ride the identical `vmauth` hostnames (VictoriaLogs sits behind the same ga
## What backs this centrally
For maintainers, the ingestion config lives in `kubernetes/apps/base/victoria-metrics-users/`:
For maintainers, the ingestion config lives in `kubernetes/apps/base/victoria-metrics-users/app/`:
* `vmuser-remote-clusters.yaml` - the `VMUser` behind the public gateway. It holds the shared token (via ExternalSecret) and the allowed path set: metrics and logs insert **and** select (remote clusters can read back, not only write).
* `vmauth-mesh-unauth.yaml` - the unauthenticated `mesh-unauth` `VMAuth` on the mesh gateway, with the same path set exposed through `unauthorizedUserAccessSpec`.
The public gateway itself is the `vmauth` defined in the VictoriaMetrics release (`kubernetes/apps/base/victoria-metrics/helmrelease.yaml`), reached at `vmauth.<CLUSTER_APP_DOMAIN>`.
The public gateway itself is the `vmauth` defined in the VictoriaMetrics release (`kubernetes/apps/base/victoria-metrics/app/helmrelease.yaml`), reached at `vmauth.<CLUSTER_APP_DOMAIN>`.
+4 -4
View File
@@ -57,10 +57,10 @@ The bundle's CRs carry sane defaults (`instanceSelector: {dashboards: grafana}`,
## Model B: authored in this repo (o11y's own)
For this cluster's own dashboards and alerts, they live under `kubernetes/apps/base/grafana/` and deploy with the grafana Flux Kustomization:
For this cluster's own dashboards and alerts, they live under `kubernetes/apps/base/grafana/app/` and deploy with the grafana Flux Kustomization:
- **Dashboards** - `base/grafana/dashboards/*.yaml`, one `GrafanaDashboard` per file, `folderRef: o11y`. Source the JSON however fits: `spec.url` to a raw/grafana.com dashboard (the envoy and cnpg dashboards), `spec.gzipJson`, etc. Map dashboard `__inputs` (e.g. `DS_PROMETHEUS`) to `datasourceName: VictoriaMetrics`.
- **Alerts** - `base/grafana/alerts-*.yaml`, a `GrafanaAlertRuleGroup` with `folderRef: o11y`.
- **Dashboards** - `base/grafana/app/dashboards/*.yaml`, one `GrafanaDashboard` per file, `folderRef: o11y`. Source the JSON however fits: `spec.url` to a raw/grafana.com dashboard (the envoy and cnpg dashboards), `spec.gzipJson`, etc. Map dashboard `__inputs` (e.g. `DS_PROMETHEUS`) to `datasourceName: VictoriaMetrics`.
- **Alerts** - `base/grafana/app/alerts-*.yaml`, a `GrafanaAlertRuleGroup` with `folderRef: o11y`.
## Alerting
@@ -80,7 +80,7 @@ route:
So **routing follows the folder automatically** - no per-rule label to set or keep in sync. (Existing rules still carry a `project` label; it is now legacy and unused for routing.) Notifications additionally group by `cluster` (alongside `grafana_folder` and `alertname`), so the same rule firing in two clusters arrives as two grouped notifications rather than one blended message.
**Alert rule anatomy.** A `GrafanaAlertRuleGroup` (`folderRef: <project>`, an `interval`) with `rules[]`; each rule is a query stage on the `VictoriaMetrics` datasource (uid `VictoriaMetrics`) feeding a `__expr__` threshold stage, plus `labels` (at least `severity`) and `annotations`. See `base/grafana/alerts-o11y.yaml` for the pattern (a heartbeat plus target-down and ingestion-stalled rules). Rules that span clusters aggregate `by (cluster)` so each cluster raises its own instance and carries its `cluster` label into notification grouping; store-local rules (the heartbeat, ingestion-stalled) don't.
**Alert rule anatomy.** A `GrafanaAlertRuleGroup` (`folderRef: <project>`, an `interval`) with `rules[]`; each rule is a query stage on the `VictoriaMetrics` datasource (uid `VictoriaMetrics`) feeding a `__expr__` threshold stage, plus `labels` (at least `severity`) and `annotations`. See `base/grafana/app/alerts-o11y.yaml` for the pattern (a heartbeat plus target-down and ingestion-stalled rules). Rules that span clusters aggregate `by (cluster)` so each cluster raises its own instance and carries its `cluster` label into notification grouping; store-local rules (the heartbeat, ingestion-stalled) don't.
## If you ship metrics to this cluster and want dashboards/alerts
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./externalsecret.yaml
- ./clusterissuer.yaml
@@ -10,10 +10,10 @@ spec:
- name: cert-manager
- name: cluster-secret-store
interval: 1h
path: ./kubernetes/apps/base/cert-manager-issuers
path: ./kubernetes/apps/base/cert-manager-issuers/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: cert-manager
@@ -2,5 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./externalsecret.yaml
- ./clusterissuer.yaml
- ./ks.yaml
@@ -8,19 +8,7 @@ spec:
chartRef:
kind: OCIRepository
name: cert-manager-webhook-ovh
install:
crds: CreateReplace
interval: 1h
rollback:
cleanupOnFail: true
upgrade:
cleanupOnFail: true
crds: CreateReplace
strategy:
name: RemediateOnFailure
remediation:
remediateLastFailure: true
retries: 2
values:
groupName: acme.futostatus.com
issuers:
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
@@ -14,10 +14,10 @@ spec:
name: cert-manager-webhook-ovh
namespace: cert-manager
interval: 1h
path: ./kubernetes/apps/base/cert-manager-webhook-ovh
path: ./kubernetes/apps/base/cert-manager-webhook-ovh/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: cert-manager
@@ -2,5 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
- ./ks.yaml
@@ -8,19 +8,7 @@ spec:
chartRef:
kind: OCIRepository
name: cert-manager
install:
crds: CreateReplace
interval: 1h
rollback:
cleanupOnFail: true
upgrade:
cleanupOnFail: true
crds: CreateReplace
strategy:
name: RemediateOnFailure
remediation:
remediateLastFailure: true
retries: 2
values:
crds:
enabled: true
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
@@ -14,10 +14,10 @@ spec:
name: cert-manager
namespace: cert-manager
interval: 1h
path: ./kubernetes/apps/base/cert-manager
path: ./kubernetes/apps/base/cert-manager/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: cert-manager
@@ -2,5 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
- ./ks.yaml
@@ -9,15 +9,6 @@ spec:
kind: OCIRepository
name: cloudnative-pg
interval: 1h
rollback:
cleanupOnFail: true
upgrade:
cleanupOnFail: true
strategy:
name: RemediateOnFailure
remediation:
remediateLastFailure: true
retries: 2
values:
crds:
create: true
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
@@ -12,10 +12,10 @@ spec:
name: cloudnative-pg
namespace: cnpg-system
interval: 1h
path: ./kubernetes/apps/base/cloudnative-pg
path: ./kubernetes/apps/base/cloudnative-pg/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: cnpg-system
@@ -2,5 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
- ./ks.yaml
@@ -0,0 +1,5 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./clustersecretstore.yaml
@@ -10,11 +10,11 @@ spec:
- name: external-secrets
- name: netbird-router
interval: 1h
path: ./kubernetes/apps/base/cluster-secret-store
path: ./kubernetes/apps/base/cluster-secret-store/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: external-secrets
wait: true
@@ -2,4 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./clustersecretstore.yaml
- ./ks.yaml
@@ -9,15 +9,6 @@ spec:
kind: OCIRepository
name: descheduler
interval: 1h
rollback:
cleanupOnFail: true
upgrade:
cleanupOnFail: true
strategy:
name: RemediateOnFailure
remediation:
remediateLastFailure: true
retries: 2
values:
kind: Deployment
deschedulerPolicyAPIVersion: descheduler/v1alpha2
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
@@ -14,10 +14,10 @@ spec:
name: descheduler
namespace: kube-system
interval: 1h
path: ./kubernetes/apps/base/descheduler
path: ./kubernetes/apps/base/descheduler/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: kube-system
@@ -2,5 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
- ./ks.yaml
@@ -9,15 +9,6 @@ spec:
kind: OCIRepository
name: echo
interval: 1h
rollback:
cleanupOnFail: true
upgrade:
cleanupOnFail: true
strategy:
name: RemediateOnFailure
remediation:
remediateLastFailure: true
retries: 2
values:
replicaCount: 3
config:
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
@@ -15,10 +15,10 @@ spec:
name: echo
namespace: default
interval: 1h
path: ./kubernetes/apps/base/echo
path: ./kubernetes/apps/base/echo/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: default
+1 -2
View File
@@ -2,5 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
- ./ks.yaml
@@ -8,19 +8,7 @@ spec:
chartRef:
kind: OCIRepository
name: envoy-gateway
install:
crds: CreateReplace
interval: 1h
rollback:
cleanupOnFail: true
upgrade:
cleanupOnFail: true
crds: CreateReplace
strategy:
name: RemediateOnFailure
remediation:
remediateLastFailure: true
retries: 2
values:
global:
imageRegistry: mirror.gcr.io
@@ -0,0 +1,8 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./certificate.yaml
- ./helmrelease.yaml
- ./o11y.yaml
- ./ocirepository.yaml
@@ -14,10 +14,10 @@ spec:
name: envoy-gateway
namespace: envoy-system
interval: 1h
path: ./kubernetes/apps/base/envoy-gateway
path: ./kubernetes/apps/base/envoy-gateway/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: envoy-system
@@ -2,7 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./certificate.yaml
- ./helmrelease.yaml
- ./o11y.yaml
- ./ocirepository.yaml
- ./ks.yaml
@@ -0,0 +1,9 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./backendtrafficpolicy.yaml
- ./clienttrafficpolicy.yaml
- ./envoyproxy.yaml
- ./gateway.yaml
- ./gatewayclass.yaml
@@ -9,11 +9,11 @@ spec:
dependsOn:
- name: envoy-gateway
interval: 1h
path: ./kubernetes/apps/base/envoy-proxy
path: ./kubernetes/apps/base/envoy-proxy/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: envoy-system
wait: true
@@ -2,8 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./backendtrafficpolicy.yaml
- ./clienttrafficpolicy.yaml
- ./envoyproxy.yaml
- ./gateway.yaml
- ./gatewayclass.yaml
- ./ks.yaml
@@ -8,19 +8,7 @@ spec:
chartRef:
kind: OCIRepository
name: external-secrets
install:
crds: CreateReplace
interval: 1h
rollback:
cleanupOnFail: true
upgrade:
cleanupOnFail: true
crds: CreateReplace
strategy:
name: RemediateOnFailure
remediation:
remediateLastFailure: true
retries: 2
values:
# Resolve DNS via the CoreDNS futo.network zone
podAnnotations:
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
@@ -16,10 +16,10 @@ spec:
name: external-secrets
namespace: external-secrets
interval: 1h
path: ./kubernetes/apps/base/external-secrets
path: ./kubernetes/apps/base/external-secrets/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: external-secrets
@@ -2,5 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
- ./ks.yaml
@@ -8,19 +8,7 @@ spec:
chartRef:
kind: OCIRepository
name: grafana-operator
install:
crds: CreateReplace
interval: 1h
rollback:
cleanupOnFail: true
upgrade:
cleanupOnFail: true
crds: CreateReplace
strategy:
name: RemediateOnFailure
remediation:
remediateLastFailure: true
retries: 2
values:
dashboard:
enabled: false
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
@@ -14,10 +14,10 @@ spec:
name: grafana-operator
namespace: o11y
interval: 1h
path: ./kubernetes/apps/base/grafana-operator
path: ./kubernetes/apps/base/grafana-operator/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: o11y
@@ -2,5 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml
- ./ks.yaml
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./externalsecret.yaml
- ./cluster.yaml
@@ -16,10 +16,10 @@ spec:
name: grafana-postgres
namespace: o11y
interval: 1h
path: ./kubernetes/apps/base/grafana-postgres
path: ./kubernetes/apps/base/grafana-postgres/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: o11y
@@ -2,5 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./externalsecret.yaml
- ./cluster.yaml
- ./ks.yaml
@@ -0,0 +1,11 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./externalsecret.yaml
- ./grafana.yaml
- ./datasource.yaml
- ./contactpoint-discord.yaml
- ./notificationpolicy.yaml
- ./alerts-o11y.yaml
- ./dashboards
@@ -12,10 +12,10 @@ spec:
- name: external-secrets
- name: grafana-postgres
interval: 1h
path: ./kubernetes/apps/base/grafana
path: ./kubernetes/apps/base/grafana/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: o11y
@@ -2,10 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./externalsecret.yaml
- ./grafana.yaml
- ./datasource.yaml
- ./contactpoint-discord.yaml
- ./notificationpolicy.yaml
- ./alerts-o11y.yaml
- ./dashboards
- ./ks.yaml
@@ -0,0 +1,5 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./tlsroute.yaml
@@ -7,7 +7,6 @@ apiVersion: gateway.networking.k8s.io/v1alpha2
kind: TLSRoute
metadata:
name: kube-apiserver
namespace: default
spec:
parentRefs:
- name: mesh
@@ -9,7 +9,8 @@ spec:
dependsOn:
- name: mesh-gateway
interval: 1h
path: ./kubernetes/apps/base/mesh-gateway-api
path: ./kubernetes/apps/base/mesh-gateway-api/app
patches: []
prune: true
sourceRef:
kind: GitRepository
@@ -2,4 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./tlsroute.yaml
- ./ks.yaml
@@ -0,0 +1,6 @@
---
# yaml-language-server: $schema=https://json.schemastore.org/kustomization
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./servicecidr.yaml
@@ -7,7 +7,8 @@ metadata:
namespace: flux-system
spec:
interval: 1h
path: ./kubernetes/apps/base/mesh-gateway-network
path: ./kubernetes/apps/base/mesh-gateway-network/app
patches: []
prune: true
sourceRef:
kind: GitRepository
@@ -1,6 +1,5 @@
---
# yaml-language-server: $schema=https://json.schemastore.org/kustomization
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./servicecidr.yaml
- ./ks.yaml
@@ -0,0 +1,9 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./gatewayclass.yaml
- ./envoyproxy.yaml
- ./gateway.yaml
- ./service.yaml
- ./certificate.yaml
@@ -11,11 +11,11 @@ spec:
- name: cert-manager-issuers
- name: mesh-gateway-network
interval: 1h
path: ./kubernetes/apps/base/mesh-gateway
path: ./kubernetes/apps/base/mesh-gateway/app
patches: []
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
targetNamespace: envoy-system
wait: true
@@ -2,8 +2,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./gatewayclass.yaml
- ./envoyproxy.yaml
- ./gateway.yaml
- ./service.yaml
- ./certificate.yaml
- ./ks.yaml
@@ -9,15 +9,6 @@ spec:
kind: OCIRepository
name: metrics-server
interval: 1h
rollback:
cleanupOnFail: true
upgrade:
cleanupOnFail: true
strategy:
name: RemediateOnFailure
remediation:
remediateLastFailure: true
retries: 2
values:
args:
- --kubelet-insecure-tls
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./helmrelease.yaml
- ./ocirepository.yaml

Some files were not shown because too many files have changed in this diff Show More