mirror of
https://github.com/immich-app/yucca-o11y.git
synced 2026-09-30 13:23:23 +08:00
refactor(flux): dedup per-env Kustomizations into base ks.yaml+app layout (#147)
Signed-off-by: Devin Buhl <devin@buhl.casa>
This commit is contained in:
@@ -27,8 +27,9 @@ deployment/modules/
|
||||
|
||||
kubernetes/
|
||||
├── apps/
|
||||
│ ├── base/ # chart sources + reusable manifests
|
||||
│ └── <env>/ # env overlay: Flux Kustomizations (version pins + dependsOn)
|
||||
│ ├── base/<app>/ # ks.yaml (the app's Flux Kustomization) + app/ (chart source + manifests)
|
||||
│ └── <env>/<ns>/ # namespace overlay: which base apps run; deltas from base as patches/<app>.yaml
|
||||
├── components/ # shared kustomize Components (targetNamespace replacement)
|
||||
└── clusters/
|
||||
└── <env>/
|
||||
├── apps.yaml # cluster-apps entry point (the Flux Instance points here)
|
||||
|
||||
@@ -63,13 +63,19 @@ Kubernetes with flannel CNI and kube-proxy in nftables mode. **Multus** runs as
|
||||
|
||||
Everything above the OS is managed by Flux v2. Manifests are organized as reusable bases plus per-environment overlays:
|
||||
|
||||
* **`kubernetes/apps/base/`** holds the chart sources and reusable manifests.
|
||||
* **`kubernetes/apps/<env>/`** holds the per-app Flux Kustomizations — each pins its chart version and declares its `dependsOn` ordering.
|
||||
* **`kubernetes/apps/base/<app>/`** is the app's single home: `ks.yaml` is its Flux Kustomization (`dependsOn` ordering, health checks) and `app/` is what that Kustomization deploys (chart source + manifests). Both environments reconcile the same definition.
|
||||
* **`kubernetes/apps/<env>/<ns>/`** is the per-namespace overlay: a kustomization listing which base apps run there, plus the Namespace itself. Anything an environment needs to differ from `base/` is one patch file per app under the overlay's `patches/` — today that's production's version pins.
|
||||
* **`kubernetes/components/`** holds shared kustomize Components — today just **`replacements/`**, included by every overlay. It copies the overlay Namespace's name into each Flux Kustomization's `spec.targetNamespace`, so an app deploys into whichever namespace lists it and `base/` stays namespace-agnostic. The corollary: an app belongs in the folder of the namespace its resources live in — `mesh-gateway-api` sits under `default/` because its TLSRoute must share a namespace with the `default/kubernetes` Service it fronts. The overlay's namespace is forced onto every namespaced resource (explicit values are overridden), so an app that genuinely needs resources in a foreign namespace would need a `reject` entry in the component.
|
||||
|
||||
* **`kubernetes/clusters/<env>/apps.yaml`** is the `cluster-apps` entry point the Flux Instance points at.
|
||||
|
||||
### Version pinning
|
||||
Cluster-wide HelmRelease lifecycle defaults (`crds: CreateReplace` on install and upgrade, `cleanupOnFail`, `RemediateOnFailure` with retries) are defined once in `kubernetes/clusters/<env>/apps.yaml`: `cluster-apps` **appends** them (a JSON6902 `add /spec/patches/-`) to every child Kustomization, which applies them to every HelmRelease it renders — individual releases declare only what deviates. Appending, rather than strategic-merging, is what lets the per-app override patches, which ride the same list, coexist: a strategic-merge there would replace the list and silently erase every override. Every base `ks.yaml` seeds `patches: []` so the append always has a list to land on; a new app that omits it fails the environment build loudly.
|
||||
|
||||
Chart (and the CloudNativePG Postgres image) versions are pinned per environment in the overlay Kustomization patches, so a version can be promoted in staging and soaked before production moves. Staging rides `base/` directly; production pins via patches. OCI chart refs pin a **tag and its digest** — Flux gives the digest precedence, so the production patches must carry both or a base digest would silently override the env pin; a renovate custom manager keeps each tag+digest pair in lockstep, and the built-in flux manager maintains the pairs in `base/`. Component versions are not documented here because they change continuously — the manifests are the source of truth.
|
||||
### Environment overrides
|
||||
|
||||
An overlay changes an app by dropping one patch file per app in its `patches/` folder and listing it in the overlay's `patches:` section — so the overlay reads as "these apps, these deltas". Each file patches the app's Flux Kustomization to inject a `spec.patches` override onto whatever resource must differ from `base/`; it has to ride the Kustomization because the app's resources are rendered by Flux from `base/`, never by the overlay build.
|
||||
|
||||
Today the only overrides are version pins. Chart (and the CloudNativePG Postgres image) versions are pinned in production, so a version can be promoted in staging — which rides `base/` directly and floats with it — and soaked before production moves. OCI chart refs pin a **tag and its digest** — Flux gives the digest precedence, so the production patches must carry both or a base digest would silently override the env pin; a renovate custom manager keeps each tag+digest pair in lockstep, and the built-in flux manager maintains the pairs in `base/`. Component versions are not documented here because they change continuously — the manifests are the source of truth.
|
||||
|
||||
### Configuration substitution
|
||||
|
||||
|
||||
@@ -130,9 +130,9 @@ Logs ride the identical `vmauth` hostnames (VictoriaLogs sits behind the same ga
|
||||
|
||||
## What backs this centrally
|
||||
|
||||
For maintainers, the ingestion config lives in `kubernetes/apps/base/victoria-metrics-users/`:
|
||||
For maintainers, the ingestion config lives in `kubernetes/apps/base/victoria-metrics-users/app/`:
|
||||
|
||||
* `vmuser-remote-clusters.yaml` - the `VMUser` behind the public gateway. It holds the shared token (via ExternalSecret) and the allowed path set: metrics and logs insert **and** select (remote clusters can read back, not only write).
|
||||
* `vmauth-mesh-unauth.yaml` - the unauthenticated `mesh-unauth` `VMAuth` on the mesh gateway, with the same path set exposed through `unauthorizedUserAccessSpec`.
|
||||
|
||||
The public gateway itself is the `vmauth` defined in the VictoriaMetrics release (`kubernetes/apps/base/victoria-metrics/helmrelease.yaml`), reached at `vmauth.<CLUSTER_APP_DOMAIN>`.
|
||||
The public gateway itself is the `vmauth` defined in the VictoriaMetrics release (`kubernetes/apps/base/victoria-metrics/app/helmrelease.yaml`), reached at `vmauth.<CLUSTER_APP_DOMAIN>`.
|
||||
|
||||
@@ -57,10 +57,10 @@ The bundle's CRs carry sane defaults (`instanceSelector: {dashboards: grafana}`,
|
||||
|
||||
## Model B: authored in this repo (o11y's own)
|
||||
|
||||
For this cluster's own dashboards and alerts, they live under `kubernetes/apps/base/grafana/` and deploy with the grafana Flux Kustomization:
|
||||
For this cluster's own dashboards and alerts, they live under `kubernetes/apps/base/grafana/app/` and deploy with the grafana Flux Kustomization:
|
||||
|
||||
- **Dashboards** - `base/grafana/dashboards/*.yaml`, one `GrafanaDashboard` per file, `folderRef: o11y`. Source the JSON however fits: `spec.url` to a raw/grafana.com dashboard (the envoy and cnpg dashboards), `spec.gzipJson`, etc. Map dashboard `__inputs` (e.g. `DS_PROMETHEUS`) to `datasourceName: VictoriaMetrics`.
|
||||
- **Alerts** - `base/grafana/alerts-*.yaml`, a `GrafanaAlertRuleGroup` with `folderRef: o11y`.
|
||||
- **Dashboards** - `base/grafana/app/dashboards/*.yaml`, one `GrafanaDashboard` per file, `folderRef: o11y`. Source the JSON however fits: `spec.url` to a raw/grafana.com dashboard (the envoy and cnpg dashboards), `spec.gzipJson`, etc. Map dashboard `__inputs` (e.g. `DS_PROMETHEUS`) to `datasourceName: VictoriaMetrics`.
|
||||
- **Alerts** - `base/grafana/app/alerts-*.yaml`, a `GrafanaAlertRuleGroup` with `folderRef: o11y`.
|
||||
|
||||
## Alerting
|
||||
|
||||
@@ -80,7 +80,7 @@ route:
|
||||
|
||||
So **routing follows the folder automatically** - no per-rule label to set or keep in sync. (Existing rules still carry a `project` label; it is now legacy and unused for routing.) Notifications additionally group by `cluster` (alongside `grafana_folder` and `alertname`), so the same rule firing in two clusters arrives as two grouped notifications rather than one blended message.
|
||||
|
||||
**Alert rule anatomy.** A `GrafanaAlertRuleGroup` (`folderRef: <project>`, an `interval`) with `rules[]`; each rule is a query stage on the `VictoriaMetrics` datasource (uid `VictoriaMetrics`) feeding a `__expr__` threshold stage, plus `labels` (at least `severity`) and `annotations`. See `base/grafana/alerts-o11y.yaml` for the pattern (a heartbeat plus target-down and ingestion-stalled rules). Rules that span clusters aggregate `by (cluster)` so each cluster raises its own instance and carries its `cluster` label into notification grouping; store-local rules (the heartbeat, ingestion-stalled) don't.
|
||||
**Alert rule anatomy.** A `GrafanaAlertRuleGroup` (`folderRef: <project>`, an `interval`) with `rules[]`; each rule is a query stage on the `VictoriaMetrics` datasource (uid `VictoriaMetrics`) feeding a `__expr__` threshold stage, plus `labels` (at least `severity`) and `annotations`. See `base/grafana/app/alerts-o11y.yaml` for the pattern (a heartbeat plus target-down and ingestion-stalled rules). Rules that span clusters aggregate `by (cluster)` so each cluster raises its own instance and carries its `cluster` label into notification grouping; store-local rules (the heartbeat, ingestion-stalled) don't.
|
||||
|
||||
## If you ship metrics to this cluster and want dashboards/alerts
|
||||
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./externalsecret.yaml
|
||||
- ./clusterissuer.yaml
|
||||
+2
-2
@@ -10,10 +10,10 @@ spec:
|
||||
- name: cert-manager
|
||||
- name: cluster-secret-store
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/cert-manager-issuers
|
||||
path: ./kubernetes/apps/base/cert-manager-issuers/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: cert-manager
|
||||
@@ -2,5 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./externalsecret.yaml
|
||||
- ./clusterissuer.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
-12
@@ -8,19 +8,7 @@ spec:
|
||||
chartRef:
|
||||
kind: OCIRepository
|
||||
name: cert-manager-webhook-ovh
|
||||
install:
|
||||
crds: CreateReplace
|
||||
interval: 1h
|
||||
rollback:
|
||||
cleanupOnFail: true
|
||||
upgrade:
|
||||
cleanupOnFail: true
|
||||
crds: CreateReplace
|
||||
strategy:
|
||||
name: RemediateOnFailure
|
||||
remediation:
|
||||
remediateLastFailure: true
|
||||
retries: 2
|
||||
values:
|
||||
groupName: acme.futostatus.com
|
||||
issuers:
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
+2
-2
@@ -14,10 +14,10 @@ spec:
|
||||
name: cert-manager-webhook-ovh
|
||||
namespace: cert-manager
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/cert-manager-webhook-ovh
|
||||
path: ./kubernetes/apps/base/cert-manager-webhook-ovh/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: cert-manager
|
||||
@@ -2,5 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
-12
@@ -8,19 +8,7 @@ spec:
|
||||
chartRef:
|
||||
kind: OCIRepository
|
||||
name: cert-manager
|
||||
install:
|
||||
crds: CreateReplace
|
||||
interval: 1h
|
||||
rollback:
|
||||
cleanupOnFail: true
|
||||
upgrade:
|
||||
cleanupOnFail: true
|
||||
crds: CreateReplace
|
||||
strategy:
|
||||
name: RemediateOnFailure
|
||||
remediation:
|
||||
remediateLastFailure: true
|
||||
retries: 2
|
||||
values:
|
||||
crds:
|
||||
enabled: true
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
+2
-2
@@ -14,10 +14,10 @@ spec:
|
||||
name: cert-manager
|
||||
namespace: cert-manager
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/cert-manager
|
||||
path: ./kubernetes/apps/base/cert-manager/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: cert-manager
|
||||
@@ -2,5 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
-9
@@ -9,15 +9,6 @@ spec:
|
||||
kind: OCIRepository
|
||||
name: cloudnative-pg
|
||||
interval: 1h
|
||||
rollback:
|
||||
cleanupOnFail: true
|
||||
upgrade:
|
||||
cleanupOnFail: true
|
||||
strategy:
|
||||
name: RemediateOnFailure
|
||||
remediation:
|
||||
remediateLastFailure: true
|
||||
retries: 2
|
||||
values:
|
||||
crds:
|
||||
create: true
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
+2
-2
@@ -12,10 +12,10 @@ spec:
|
||||
name: cloudnative-pg
|
||||
namespace: cnpg-system
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/cloudnative-pg
|
||||
path: ./kubernetes/apps/base/cloudnative-pg/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: cnpg-system
|
||||
@@ -2,5 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./clustersecretstore.yaml
|
||||
+2
-2
@@ -10,11 +10,11 @@ spec:
|
||||
- name: external-secrets
|
||||
- name: netbird-router
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/cluster-secret-store
|
||||
path: ./kubernetes/apps/base/cluster-secret-store/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: external-secrets
|
||||
wait: true
|
||||
@@ -2,4 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./clustersecretstore.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
-9
@@ -9,15 +9,6 @@ spec:
|
||||
kind: OCIRepository
|
||||
name: descheduler
|
||||
interval: 1h
|
||||
rollback:
|
||||
cleanupOnFail: true
|
||||
upgrade:
|
||||
cleanupOnFail: true
|
||||
strategy:
|
||||
name: RemediateOnFailure
|
||||
remediation:
|
||||
remediateLastFailure: true
|
||||
retries: 2
|
||||
values:
|
||||
kind: Deployment
|
||||
deschedulerPolicyAPIVersion: descheduler/v1alpha2
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
+2
-2
@@ -14,10 +14,10 @@ spec:
|
||||
name: descheduler
|
||||
namespace: kube-system
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/descheduler
|
||||
path: ./kubernetes/apps/base/descheduler/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: kube-system
|
||||
@@ -2,5 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
-9
@@ -9,15 +9,6 @@ spec:
|
||||
kind: OCIRepository
|
||||
name: echo
|
||||
interval: 1h
|
||||
rollback:
|
||||
cleanupOnFail: true
|
||||
upgrade:
|
||||
cleanupOnFail: true
|
||||
strategy:
|
||||
name: RemediateOnFailure
|
||||
remediation:
|
||||
remediateLastFailure: true
|
||||
retries: 2
|
||||
values:
|
||||
replicaCount: 3
|
||||
config:
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
@@ -15,10 +15,10 @@ spec:
|
||||
name: echo
|
||||
namespace: default
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/echo
|
||||
path: ./kubernetes/apps/base/echo/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: default
|
||||
@@ -2,5 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
-12
@@ -8,19 +8,7 @@ spec:
|
||||
chartRef:
|
||||
kind: OCIRepository
|
||||
name: envoy-gateway
|
||||
install:
|
||||
crds: CreateReplace
|
||||
interval: 1h
|
||||
rollback:
|
||||
cleanupOnFail: true
|
||||
upgrade:
|
||||
cleanupOnFail: true
|
||||
crds: CreateReplace
|
||||
strategy:
|
||||
name: RemediateOnFailure
|
||||
remediation:
|
||||
remediateLastFailure: true
|
||||
retries: 2
|
||||
values:
|
||||
global:
|
||||
imageRegistry: mirror.gcr.io
|
||||
@@ -0,0 +1,8 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./certificate.yaml
|
||||
- ./helmrelease.yaml
|
||||
- ./o11y.yaml
|
||||
- ./ocirepository.yaml
|
||||
+2
-2
@@ -14,10 +14,10 @@ spec:
|
||||
name: envoy-gateway
|
||||
namespace: envoy-system
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/envoy-gateway
|
||||
path: ./kubernetes/apps/base/envoy-gateway/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: envoy-system
|
||||
@@ -2,7 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./certificate.yaml
|
||||
- ./helmrelease.yaml
|
||||
- ./o11y.yaml
|
||||
- ./ocirepository.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./backendtrafficpolicy.yaml
|
||||
- ./clienttrafficpolicy.yaml
|
||||
- ./envoyproxy.yaml
|
||||
- ./gateway.yaml
|
||||
- ./gatewayclass.yaml
|
||||
+2
-2
@@ -9,11 +9,11 @@ spec:
|
||||
dependsOn:
|
||||
- name: envoy-gateway
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/envoy-proxy
|
||||
path: ./kubernetes/apps/base/envoy-proxy/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: envoy-system
|
||||
wait: true
|
||||
@@ -2,8 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./backendtrafficpolicy.yaml
|
||||
- ./clienttrafficpolicy.yaml
|
||||
- ./envoyproxy.yaml
|
||||
- ./gateway.yaml
|
||||
- ./gatewayclass.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
-12
@@ -8,19 +8,7 @@ spec:
|
||||
chartRef:
|
||||
kind: OCIRepository
|
||||
name: external-secrets
|
||||
install:
|
||||
crds: CreateReplace
|
||||
interval: 1h
|
||||
rollback:
|
||||
cleanupOnFail: true
|
||||
upgrade:
|
||||
cleanupOnFail: true
|
||||
crds: CreateReplace
|
||||
strategy:
|
||||
name: RemediateOnFailure
|
||||
remediation:
|
||||
remediateLastFailure: true
|
||||
retries: 2
|
||||
values:
|
||||
# Resolve DNS via the CoreDNS futo.network zone
|
||||
podAnnotations:
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
+2
-2
@@ -16,10 +16,10 @@ spec:
|
||||
name: external-secrets
|
||||
namespace: external-secrets
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/external-secrets
|
||||
path: ./kubernetes/apps/base/external-secrets/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: external-secrets
|
||||
@@ -2,5 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
-12
@@ -8,19 +8,7 @@ spec:
|
||||
chartRef:
|
||||
kind: OCIRepository
|
||||
name: grafana-operator
|
||||
install:
|
||||
crds: CreateReplace
|
||||
interval: 1h
|
||||
rollback:
|
||||
cleanupOnFail: true
|
||||
upgrade:
|
||||
cleanupOnFail: true
|
||||
crds: CreateReplace
|
||||
strategy:
|
||||
name: RemediateOnFailure
|
||||
remediation:
|
||||
remediateLastFailure: true
|
||||
retries: 2
|
||||
values:
|
||||
dashboard:
|
||||
enabled: false
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
+2
-2
@@ -14,10 +14,10 @@ spec:
|
||||
name: grafana-operator
|
||||
namespace: o11y
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/grafana-operator
|
||||
path: ./kubernetes/apps/base/grafana-operator/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: o11y
|
||||
@@ -2,5 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./externalsecret.yaml
|
||||
- ./cluster.yaml
|
||||
+2
-2
@@ -16,10 +16,10 @@ spec:
|
||||
name: grafana-postgres
|
||||
namespace: o11y
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/grafana-postgres
|
||||
path: ./kubernetes/apps/base/grafana-postgres/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: o11y
|
||||
@@ -2,5 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./externalsecret.yaml
|
||||
- ./cluster.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./externalsecret.yaml
|
||||
- ./grafana.yaml
|
||||
- ./datasource.yaml
|
||||
- ./contactpoint-discord.yaml
|
||||
- ./notificationpolicy.yaml
|
||||
- ./alerts-o11y.yaml
|
||||
- ./dashboards
|
||||
@@ -12,10 +12,10 @@ spec:
|
||||
- name: external-secrets
|
||||
- name: grafana-postgres
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/grafana
|
||||
path: ./kubernetes/apps/base/grafana/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: o11y
|
||||
@@ -2,10 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./externalsecret.yaml
|
||||
- ./grafana.yaml
|
||||
- ./datasource.yaml
|
||||
- ./contactpoint-discord.yaml
|
||||
- ./notificationpolicy.yaml
|
||||
- ./alerts-o11y.yaml
|
||||
- ./dashboards
|
||||
- ./ks.yaml
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./tlsroute.yaml
|
||||
-1
@@ -7,7 +7,6 @@ apiVersion: gateway.networking.k8s.io/v1alpha2
|
||||
kind: TLSRoute
|
||||
metadata:
|
||||
name: kube-apiserver
|
||||
namespace: default
|
||||
spec:
|
||||
parentRefs:
|
||||
- name: mesh
|
||||
+2
-1
@@ -9,7 +9,8 @@ spec:
|
||||
dependsOn:
|
||||
- name: mesh-gateway
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/mesh-gateway-api
|
||||
path: ./kubernetes/apps/base/mesh-gateway-api/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
@@ -2,4 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./tlsroute.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
# yaml-language-server: $schema=https://json.schemastore.org/kustomization
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./servicecidr.yaml
|
||||
+2
-1
@@ -7,7 +7,8 @@ metadata:
|
||||
namespace: flux-system
|
||||
spec:
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/mesh-gateway-network
|
||||
path: ./kubernetes/apps/base/mesh-gateway-network/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
@@ -1,6 +1,5 @@
|
||||
---
|
||||
# yaml-language-server: $schema=https://json.schemastore.org/kustomization
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./servicecidr.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./gatewayclass.yaml
|
||||
- ./envoyproxy.yaml
|
||||
- ./gateway.yaml
|
||||
- ./service.yaml
|
||||
- ./certificate.yaml
|
||||
+2
-2
@@ -11,11 +11,11 @@ spec:
|
||||
- name: cert-manager-issuers
|
||||
- name: mesh-gateway-network
|
||||
interval: 1h
|
||||
path: ./kubernetes/apps/base/mesh-gateway
|
||||
path: ./kubernetes/apps/base/mesh-gateway/app
|
||||
patches: []
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
targetNamespace: envoy-system
|
||||
wait: true
|
||||
@@ -2,8 +2,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./gatewayclass.yaml
|
||||
- ./envoyproxy.yaml
|
||||
- ./gateway.yaml
|
||||
- ./service.yaml
|
||||
- ./certificate.yaml
|
||||
- ./ks.yaml
|
||||
|
||||
-9
@@ -9,15 +9,6 @@ spec:
|
||||
kind: OCIRepository
|
||||
name: metrics-server
|
||||
interval: 1h
|
||||
rollback:
|
||||
cleanupOnFail: true
|
||||
upgrade:
|
||||
cleanupOnFail: true
|
||||
strategy:
|
||||
name: RemediateOnFailure
|
||||
remediation:
|
||||
remediateLastFailure: true
|
||||
retries: 2
|
||||
values:
|
||||
args:
|
||||
- --kubelet-insecure-tls
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./helmrelease.yaml
|
||||
- ./ocirepository.yaml
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user