Devin Buhl
33682e78cc
chore(renovate): match every o11y-manifests bundle in the no-pinDigest rule ( #293 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-09-11 09:09:34 -04:00
Devin Buhl
111d4c5b16
chore(renovate): track harbor o11y-manifests at registry.futo.org ( #292 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-09-11 09:06:11 -04:00
Devin Buhl
4a0b6f0cbe
feat(fip-o11y): consume the futo-internal-platform o11y bundle ( #290 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-09-09 11:53:02 -04:00
Devin Buhl
7697738da4
chore(renovate): skip harbor o11y-manifests digest pinning, automerge flate ( #289 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-09-09 07:46:58 -04:00
Devin Buhl
b239efb936
feat(grafana): default staging oauth logins to the editor role ( #273 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-09-09 07:37:34 -04:00
Devin Buhl
ec1a462f7a
chore(mise): lock only linux and macos on arm64/amd64 ( #271 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-09-02 10:11:59 -04:00
Devin Buhl
a3ca499b11
ci(deploy): swap the devtools use-mise wrapper for the official mise-action ( #270 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-09-02 09:56:56 -04:00
Devin Buhl
76e4e69f0d
feat(deployment): guard servers from destroy and stage production talos reboots ( #269 )
...
* feat(deployment): guard servers from destroy and stage production talos reboots
Add prevent_destroy to the OVH control-plane instances, the bare-metal
workers, and the Talos machine secrets so a plan that would replace or
delete one fails instead of applying.
Add a talos apply_mode variable. Production applies with
staged_if_needing_reboot: a machine-config change that needs a reboot is
written to the node but stays inactive until an operator reboots it, one
node at a time. Staging keeps auto so the reboot path is exercised there
first. The provider has no try-style auto-revert mode, and the per-node
applies are unordered, so this is the only lever that stops a bad config
from rebooting every control plane at once.
Document both behaviours in the bootstrap guide.
Signed-off-by: Devin Buhl <devin@buhl.casa >
* chore(rootly): refresh provider lock hashes
Signed-off-by: Devin Buhl <devin@buhl.casa >
---------
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-09-02 09:08:17 -04:00
Devin Buhl
75f9cb25a4
fix(victoria-logs): allow partial query responses during vlstorage outages ( #262 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-28 11:04:07 -04:00
Devin Buhl
63d12190a0
feat(deployment): publish vmauth gateway URLs to shared 1Password vaults ( #263 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-28 11:03:57 -04:00
Devin Buhl
143dd6ce42
feat(base): deploy VictoriaMetrics and VictoriaLogs MCP servers ( #264 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-28 11:03:49 -04:00
Devin Buhl
daaed94095
chore: latest flate versions should have fixed the ks root issue ( #256 )
2026-08-27 09:10:43 -04:00
Devin Buhl
f786c15d0e
feat(victoria-metrics): bound vmselect query concurrency and memory envelope ( #237 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-20 11:23:30 -04:00
Devin Buhl
2a80683728
feat(o11y): OOM alert and gatus-sidecar for httproute monitoring ( #236 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-19 11:38:40 -04:00
Devin Buhl
ec0f3c1ebe
feat(victoria-metrics): per-env memory tuning and longer query deadline ( #235 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-19 09:55:39 -04:00
Devin Buhl
d77ff2421b
feat(victoria-metrics): raise vmselect maxSamplesPerQuery to 1e12 ( #234 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-18 11:18:19 -04:00
Devin Buhl
ae9c02e57d
feat(talos): upgrade to v1.13.8 and kubernetes 1.36.2 ( #214 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-17 12:25:59 -04:00
Devin Buhl
1927887181
fix: trust NetBird peer sources on apid/kube-apiserver to cure the elected-router hairpin ( #198 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-13 10:33:03 -04:00
Devin Buhl
ea4da634ec
fix(o11y): bump vm-k8s-stack to 0.90.2 so rule scoping parses again ( #208 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-12 12:26:07 -04:00
Devin Buhl
1dd5d6b437
chore(o11y): o11y region label becomes global; document airport-code convention ( #197 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-07 08:33:54 -04:00
Devin Buhl
73c565f11b
feat(o11y): scope Grafana's default datasource to this cluster ( #196 )
...
Final step of the folder isolation work: the chart's datasources are
replaced by hand-written ones, and the default VictoriaMetrics datasource
(same uid, so dashboards and alerts resolve unchanged) now routes through
vmauth-self-select, which forces extra_label=cluster onto every request.
Anything that does not explicitly pick the VictoriaMetrics Fleet
datasource only sees this cluster's own series, including template
variable and metadata queries.
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-06 20:18:45 -04:00
Devin Buhl
f71208bb6a
feat(o11y): self-select vmauth proxy and Fleet datasource ( #195 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-06 11:50:07 -04:00
Devin Buhl
d168175360
fix(o11y): enable gateway_support so the operator gets HTTPRoute RBAC ( #194 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-06 10:10:34 -04:00
Devin Buhl
a9bd98112d
fix(o11y): scope vmalert rule evaluation via datasource extra_label ( #193 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-06 09:18:50 -04:00
Devin Buhl
a5a99af044
feat(o11y): five-label telemetry identity and correct cluster attribution ( #175 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-06 08:14:00 -04:00
Devin Buhl
0906adf4c0
feat(rootly): public status pages on futostatus.com ( #169 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-08-05 09:34:04 -04:00
Devin Buhl
c76cef0861
feat(deployment): source rootly api token from 1Password ( #157 )
...
ROOTLY_API_TOKEN now exists in shared_tf, so op run can resolve it like
the other module credentials; the exported-env-var interim is over and
CI plans of the rootly module get a real token.
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-30 15:23:22 -04:00
Devin Buhl
34a5f6eabd
feat(rootly): use dedicated ROOTLY_DISCORD_WEBHOOK for alert workflows ( #156 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-30 13:07:21 -04:00
Devin Buhl
2a9b50ac92
fix(envoy): structured access logs with _msg, errors-only on mesh gateway ( #155 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-30 11:34:49 -04:00
Devin Buhl
9cca6c8152
feat(rootly): tighten heartbeat cadence to 2m pings / 5m expiry ( #154 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-30 10:12:32 -04:00
Devin Buhl
b492894d44
feat: add initial rootly integration ( #152 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-29 12:48:28 -04:00
Devin Buhl
f62fc2f3bf
feat(grafana): replace heartbeat with core infrastructure and delivery alerts ( #151 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-28 11:30:04 -04:00
Devin Buhl
d02805ce67
refactor(mise): monorepo tasks for the deployment tree ( #148 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-27 11:27:16 -04:00
Devin Buhl
d20079b97b
refactor(flux): dedup per-env Kustomizations into base ks.yaml+app layout ( #147 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-24 12:49:03 -04:00
Devin Buhl
f027e07c9c
fix(grafana): consolidate the Discord alert into a single embed ( #146 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-24 06:49:01 -04:00
Devin Buhl
ec188a653b
feat(grafana): clean up Discord notifications and route by grafana_folder ( #141 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-24 06:24:47 -04:00
Devin Buhl
d8511212d7
feat: grafana dashboards + alerting overhaul (discord, oci bundle, folders, cnpg, o11y alerts) ( #140 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-23 20:37:46 -04:00
Devin Buhl
214da1b903
ci: wire up the terraform plan workflow ( #125 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-23 20:31:33 -04:00
Devin Buhl
17b89441a1
feat: o11y perf tuning, grafana HA alerting, and envoy observability ( #130 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-22 13:49:00 -04:00
Devin Buhl
b87b929bb6
feat: o11y stack tuning, yucca dashboard folder, and docs ( #128 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-22 11:59:42 -04:00
Devin Buhl
7fbc18a6c3
feat: browsable VM/VL mesh UIs and yucca grafana dashboards ( #127 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-22 11:16:01 -04:00
Devin Buhl
f133aefc8b
chore: fix production renovate gaps (pinDigest phantom + netbird image pin) ( #124 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-20 09:21:47 -04:00
Devin Buhl
428513655e
chore: unblock and gate renovate env PR flow ( #109 )
...
* chore: unblock and gate renovate env PR flow
prHourlyLimit 0 so the weekly window actually drains the queue - the
default of 2/hour meant production-prefixed branches never reached the
front, so no production PR was ever created. Production updates now
require a Dependency Dashboard checkbox (dependencyDashboardApproval),
giving the intended promotion flow: base/staging merges and soaks first,
production is a deliberate click. Also disables netbox provider majors,
which track NetBox server versions.
Signed-off-by: Devin Buhl <devin@buhl.casa >
* Apply suggestion from @onedr0p
* Apply suggestions from code review
Co-authored-by: Devin Buhl <onedr0p@users.noreply.github.com >
* Apply suggestions from code review
Co-authored-by: Devin Buhl <onedr0p@users.noreply.github.com >
---------
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-17 11:21:21 -04:00
Devin Buhl
7c237b79d7
chore: bring all deps up-to-date ( #108 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-17 11:13:16 -04:00
Devin Buhl
6cbb439098
docs: describe the netbird mesh topology and refresh stale sections ( #107 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-17 10:08:20 -04:00
Devin Buhl
e36185430c
fix: carry OCI chart digests in the production patches ( #106 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-17 07:42:03 -04:00
Devin Buhl
b9eb3cf26c
refactor: futo-org netbird provider + rfc1123 object names ( #105 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-16 11:42:11 -04:00
Devin Buhl
d2eb0b8ac0
refactor: make tf outputs the single source of operational facts ( #104 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-16 11:17:33 -04:00
Devin Buhl
5ea3585222
refactor: derive the kubeconfig mesh endpoint in terraform ( #103 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-16 09:31:15 -04:00
Devin Buhl
d39642be3a
feat: HA kube-apiserver access over the mesh (TLS passthrough) ( #101 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-16 08:23:55 -04:00
Devin Buhl
81f3d68750
refactor: retire the in-cluster 1Password Connect ( #100 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-14 09:41:06 -04:00
Devin Buhl
35f06f901e
feat: point ExternalSecrets at bootstrap-hosted 1Password Connect ( #99 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-14 09:18:26 -04:00
Devin Buhl
7d5446b43b
feat: add addressing to netbox ( #98 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-14 08:28:29 -04:00
Devin Buhl
8f332813d4
feat: mesh egress to bootstrap 1Password Connect + cluster mesh DNS ( #91 )
2026-07-10 11:44:30 -04:00
Devin Buhl
418e355554
fix: mesh-gateway svccidr was not rolled out correctly ( #90 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-08 11:36:51 -04:00
Devin Buhl
8263dd57c1
feat: deploy netbird mesh-gateway ( #89 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-08 10:28:09 -04:00
Devin Buhl
9a1a41bded
fix: move vmuser auth to shared OP vault ( #86 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-02 06:47:26 -04:00
Devin Buhl
f409d321b7
feat: migrate tailscale to netbird ( #84 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-07-01 06:31:59 -04:00
Devin Buhl
59456618d9
fix(grafana): auth basic needed for operator provisioning ( #76 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-26 10:49:32 -04:00
Devin Buhl
b3219a0238
feat: add vmlogs grafanadatasource ( #75 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-26 10:37:44 -04:00
Devin Buhl
1fe8e6439c
feat: grafana idm for zitadel ( #74 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-26 10:13:30 -04:00
Devin Buhl
ab3b629f93
fix: add cluster label to logs and flate workflow ( #72 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-25 09:11:21 -04:00
Devin Buhl
ad3d5ed968
chore: split up renny PRs based on env ( #71 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-25 08:26:55 -04:00
Devin Buhl
a55ee92680
chore: enhance renovate with additional manager configurations ( #60 )
2026-06-25 07:56:26 -04:00
Devin Buhl
8ee481b2e7
feat: add victoria-logs cluster and collector ( #54 )
...
* feat: add victoria-logs cluster and collector
Signed-off-by: Devin Buhl <devin@buhl.casa >
* fix: enable gateway api for vm
Signed-off-by: Devin Buhl <devin@buhl.casa >
---------
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-24 10:55:56 -04:00
Devin Buhl
b687efafb4
fix: use wildcard A records ( #45 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-22 09:07:27 -04:00
Devin Buhl
e618a2f782
feat(echo): deploy via the home-operations/echo Helm chart ( #44 )
...
* feat(echo): deploy via the home-operations/echo Helm chart
Replace the bjw-s app-template deployment of ghcr.io/mendhak/http-https-echo
with the dedicated home-operations/echo OCI chart
(oci://ghcr.io/home-operations/charts/echo, 0.1.2).
- OCIRepository now points at the echo chart; HelmRelease uses the chart's
native values (replicaCount, config, httpRoute, monitoring) instead of the
app-template schema.
- Drop the no-op install/upgrade crds: CreateReplace (echo ships no CRDs),
matching the cloudnative-pg / descheduler HelmRelease convention.
- Spread replicas across nodes with topologySpreadConstraints using
ScheduleAnyway, so the chart's default RollingUpdate (it exposes no strategy
field) is never blocked from surging a replacement pod.
- Keep the echo.${APP_DOMAIN}/${ALT_DOMAIN} HTTPRoute to the envoy gateway,
the ServiceMonitor, 3 replicas, the prometheus-operator-crds dependsOn, and
the renovate-pinned tag in the production overlay.
* Reformat resources section in helmrelease.yaml
2026-06-22 09:07:06 -04:00
Devin Buhl
9918c49098
fix: use TS oauth and update production bootstrap ( #43 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-19 09:39:09 -04:00
Devin Buhl
ac897a1010
feat: deploy production kubernetes overlays ( #36 )
...
* feat: deploy production kubernetes
Signed-off-by: Devin Buhl <devin@buhl.casa >
* fix: bad comment is bad
Signed-off-by: Devin Buhl <devin@buhl.casa >
---------
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-08 13:32:34 -04:00
Devin Buhl
3ffb45af4b
docs: add cluster access to bootstrap docs ( #33 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-08 13:01:28 -04:00
Devin Buhl
8506346eda
fix: change flux ref back to main ( #32 )
2026-06-02 10:14:35 -04:00
Devin Buhl
8a276fa37b
refactor!: it's a whole new infra ( #28 )
...
Signed-off-by: Devin Buhl <devin@buhl.casa >
2026-06-02 10:10:32 -04:00
Devin Buhl
e930ba90da
fix: switch GitRepository ref back to main branch ( #16 )
2026-04-06 11:30:39 -04:00
Devin Buhl
7f0642f97c
refactor: add support for multi-env cluster with flux ( #12 )
2026-04-06 09:38:17 -04:00