mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
feat(prod): continue prod (#288)
This commit is contained in:
@@ -9,8 +9,11 @@
|
||||
(dict "name" "POSTGRES_PASSWORD" "valueFrom" (dict "secretKeyRef" (dict "name" (printf "%s-app" .Values.postgresClusterName) "key" "password")))
|
||||
)) }}
|
||||
{{- /* extraEnvFrom comes after the chart secret: for duplicate keys Kubernetes
|
||||
takes the LAST envFrom source, so these act as overrides. */}}
|
||||
takes the LAST envFrom source, so these act as overrides. optional: everything
|
||||
the worker needs is explicit env above — deployments that null secretData
|
||||
(staging/prod) provide no Secret at all, and Optional=false would wedge the
|
||||
pod in CreateContainerConfigError. */}}
|
||||
{{- $_ := set .Values "envFrom" (concat
|
||||
(list (dict "secretRef" (dict "name" (include "yucca-common.fullname" .))))
|
||||
(list (dict "secretRef" (dict "name" (include "yucca-common.fullname" .) "optional" true)))
|
||||
(.Values.extraEnvFrom | default (list))) }}
|
||||
{{- include "yucca-common.deployment" . }}
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
---
|
||||
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/cert-manager.io/certificate_v1.json
|
||||
# Wildcard + apex for the staging domain — covers web (apex), api., gw. (and
|
||||
# admin. when it's exposed). cert-manager writes staging-backups-tls into this
|
||||
# namespace (envoy-system) for the Gateway to terminate with.
|
||||
# Wildcard + apex for the cluster's APP_DOMAIN — covers web (apex), api., gw.
|
||||
# (and admin. when it's exposed). cert-manager writes app-domain-tls into this
|
||||
# namespace (envoy-system) for the Gateway(s) to terminate with.
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: staging-backups
|
||||
name: app-domain
|
||||
spec:
|
||||
dnsNames:
|
||||
- "${APP_DOMAIN}"
|
||||
@@ -19,4 +19,4 @@ spec:
|
||||
issuerRef:
|
||||
kind: ClusterIssuer
|
||||
name: letsencrypt-production
|
||||
secretName: staging-backups-tls
|
||||
secretName: app-domain-tls
|
||||
|
||||
@@ -22,7 +22,7 @@ spec:
|
||||
mode: Terminate
|
||||
certificateRefs:
|
||||
- kind: Secret
|
||||
name: staging-backups-tls
|
||||
name: app-domain-tls
|
||||
- name: http
|
||||
protocol: HTTP
|
||||
port: 80
|
||||
|
||||
@@ -69,7 +69,8 @@ data:
|
||||
Corefile: ".:53 {\n errors\n health {\n lameduck 5s\n }\n ready\n\
|
||||
\ log . {\n class error\n }\n prometheus :9153\n\n kubernetes\
|
||||
\ cluster.local in-addr.arpa ip6.arpa {\n pods insecure\n fallthrough\
|
||||
\ in-addr.arpa ip6.arpa\n ttl 30\n }\n forward . /etc/resolv.conf\
|
||||
\ in-addr.arpa ip6.arpa\n ttl 30\n }\n hosts {\n 10.69.0.10\
|
||||
\ vmauth.o11y.futo.network\n fallthrough\n }\n forward . /etc/resolv.conf\
|
||||
\ {\n max_concurrent 1000\n }\n cache 30 {\n disable success\
|
||||
\ cluster.local\n disable denial cluster.local\n }\n loop\n reload\n\
|
||||
\ loadbalance\n}\n"
|
||||
|
||||
@@ -27,4 +27,4 @@ spec:
|
||||
mode: Terminate
|
||||
certificateRefs:
|
||||
- kind: Secret
|
||||
name: staging-backups-tls
|
||||
name: app-domain-tls
|
||||
|
||||
@@ -142,8 +142,10 @@ spec:
|
||||
- { name: config, mountPath: /config }
|
||||
- { name: buffer, mountPath: /buffer }
|
||||
resources:
|
||||
requests: { cpu: 50m, memory: 128Mi }
|
||||
limits: { memory: 512Mi }
|
||||
requests: { cpu: 50m, memory: 256Mi }
|
||||
# 512Mi OOM-looped every ~8min once the 12 k8s + 5 static targets
|
||||
# were all scraping (269 restarts over 6 days).
|
||||
limits: { memory: 4Gi }
|
||||
volumes:
|
||||
- name: config
|
||||
configMap: { name: vmagent-config }
|
||||
|
||||
@@ -0,0 +1,48 @@
|
||||
---
|
||||
# prod@htz-fsn1 observability overlay — the shared components/infra/observability
|
||||
# slice, with the remote-write egress repointed at o11y's MESH vmauth
|
||||
# (vmauth.o11y.futo.network → 10.69.0.10 over NetBird, unauthenticated: the
|
||||
# NetBird ACL `yucca-prod-htz-fsn1-talos → o11y-production-k8s-gateway:443` is
|
||||
# the only gate; the mesh-unauth vmauth 401s requests that DO carry a bearer,
|
||||
# so the token wiring must go, not just be ignored). Staging keeps the authed
|
||||
# public futostatus path. Pods resolve the mesh name via the coredns hosts
|
||||
# entry (../coredns.yaml) — the NetBird DNS zone is not distributed to nodes.
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../../../components/infra/observability
|
||||
patches:
|
||||
# vmagent: mesh URL, no bearer.
|
||||
- target:
|
||||
group: kustomize.toolkit.fluxcd.io
|
||||
kind: Kustomization
|
||||
name: vmagent
|
||||
patch: |-
|
||||
- op: add
|
||||
path: /spec/patches
|
||||
value:
|
||||
- target:
|
||||
kind: HelmRelease
|
||||
name: vmagent
|
||||
patch: |-
|
||||
- op: replace
|
||||
path: /spec/values/vmagent/spec/remoteWrite/0/url
|
||||
value: https://vmauth.o11y.futo.network/insert/0/prometheus/api/v1/write
|
||||
- op: remove
|
||||
path: /spec/values/vmagent/spec/remoteWrite/0/bearerTokenSecret
|
||||
# logs collector: URL comes from VLOGS_REMOTE_URL (cluster-settings); only the
|
||||
# bearer must go.
|
||||
- target:
|
||||
group: kustomize.toolkit.fluxcd.io
|
||||
kind: Kustomization
|
||||
name: victoria-logs-collector
|
||||
patch: |-
|
||||
- op: add
|
||||
path: /spec/patches
|
||||
value:
|
||||
- target:
|
||||
kind: HelmRelease
|
||||
name: victoria-logs-collector
|
||||
patch: |-
|
||||
- op: remove
|
||||
path: /spec/values/extraArgs/remoteWrite.bearerTokenFile
|
||||
@@ -1,9 +1,8 @@
|
||||
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/kustomize.toolkit.fluxcd.io/kustomization_v1.json
|
||||
---
|
||||
# Observability agents (vmagent + victoria-logs-collector) — the shared
|
||||
# components/infra/observability slice (namespace, netpols, the two nested
|
||||
# Kustomizations), reused as a plain kustomize path. The vmagent-remote-write
|
||||
# Secret is TF-provisioned (talos stack secrets.tf).
|
||||
# components/infra/observability slice via the prod overlay (../observability),
|
||||
# which repoints remote-write at o11y's mesh vmauth over NetBird, unauth.
|
||||
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
||||
kind: Kustomization
|
||||
metadata:
|
||||
@@ -13,10 +12,32 @@ spec:
|
||||
interval: 1h
|
||||
retryInterval: 2m
|
||||
timeout: 10m
|
||||
path: ./kubernetes/components/infra/observability
|
||||
path: ./kubernetes/apps/prod/htz-fsn1/observability
|
||||
prune: true
|
||||
wait: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
namespace: flux-system
|
||||
# The nested vmagent/victoria-logs-collector Kustomizations are applied by
|
||||
# THIS Kustomization, not cluster-apps, so its substituteFrom patch doesn't
|
||||
# reach them — re-apply it here or their ${vars} ship unsubstituted (the
|
||||
# 17h victoria-logs-collector crash loop on father).
|
||||
patches:
|
||||
- target:
|
||||
group: kustomize.toolkit.fluxcd.io
|
||||
kind: Kustomization
|
||||
patch: |-
|
||||
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
||||
kind: Kustomization
|
||||
metadata:
|
||||
name: _
|
||||
spec:
|
||||
postBuild:
|
||||
substituteFrom:
|
||||
- kind: ConfigMap
|
||||
name: cluster-settings-generated
|
||||
- kind: ConfigMap
|
||||
name: cluster-settings
|
||||
- kind: ConfigMap
|
||||
name: image-versions
|
||||
|
||||
@@ -26,6 +26,7 @@ data:
|
||||
S3_ENDPOINT: https://s3.prod.fsn1.htz.futo.cloud
|
||||
S3_HOST: s3.prod.fsn1.htz.futo.cloud
|
||||
|
||||
# Observability egress (apps -> agents -> o11y prod vmauth).
|
||||
# Observability egress (apps -> agents -> o11y's MESH vmauth over NetBird,
|
||||
# unauthenticated; see apps/prod/htz-fsn1/observability).
|
||||
VMAGENT_OTLP: vmagent-yucca.observability.svc:8429
|
||||
VLOGS_REMOTE_URL: https://vmauth.prod.futostatus.com/insert/native
|
||||
VLOGS_REMOTE_URL: https://vmauth.o11y.futo.network/insert/native
|
||||
|
||||
@@ -106,6 +106,22 @@ policies = {
|
||||
}]
|
||||
}
|
||||
|
||||
# Talos nodes → o11y's prod mesh gateway (external group, resolved in
|
||||
# netbird.tf): vmagent + victoria-logs-collector remote-write to the
|
||||
# UNAUTHENTICATED mesh vmauth (vmauth.o11y.futo.network:443) — this ACL is
|
||||
# the only gate. Mirrors o11y's own bootstrap-egress precedent.
|
||||
talos-to-o11y-gateway = {
|
||||
description = "Talos nodes → o11y prod mesh gateway (unauth vmauth remote-write)."
|
||||
rules = [{
|
||||
name = "talos-to-o11y-gateway"
|
||||
protocol = "tcp"
|
||||
bidirectional = false
|
||||
sources = ["talos"]
|
||||
destinations = ["o11y_k8s_gateway"]
|
||||
ports = ["443"]
|
||||
}]
|
||||
}
|
||||
|
||||
# Talos nodes reach the routed site subnets (esp. the kube fabric net 10.40.10/24)
|
||||
# via the mgmt route peers — this is how the cloud CPs' apiserver reaches the
|
||||
# bare-metal worker kubelets.
|
||||
|
||||
@@ -75,6 +75,14 @@ locals {
|
||||
}
|
||||
}
|
||||
|
||||
# o11y's prod mesh gateway group (owned by the yucca-o11y repo's netbird TF) —
|
||||
# destination of the talos-to-o11y-gateway policy (netbird.auto.tfvars): the
|
||||
# observability agents remote-write to the mesh vmauth
|
||||
# (vmauth.o11y.futo.network → the gateway VIP behind o11y's routing peers).
|
||||
data "netbird_group" "o11y_k8s_gateway" {
|
||||
name = "o11y-production-k8s-gateway"
|
||||
}
|
||||
|
||||
module "netbird" {
|
||||
source = "../../../../shared/modules/netbird-env"
|
||||
|
||||
@@ -82,10 +90,11 @@ module "netbird" {
|
||||
name_prefix = "yucca_${var.partition}_${var.region}" # yucca_prod_htz_fsn1 (slug normalized in the module)
|
||||
vault = "yucca_tf_${var.partition}" # yucca_tf_prod
|
||||
|
||||
groups = var.groups
|
||||
setup_keys = var.setup_keys
|
||||
policies = var.policies
|
||||
networks = local.netbird_networks
|
||||
groups = var.groups
|
||||
external_groups = { o11y_k8s_gateway = data.netbird_group.o11y_k8s_gateway.id }
|
||||
setup_keys = var.setup_keys
|
||||
policies = var.policies
|
||||
networks = local.netbird_networks
|
||||
}
|
||||
|
||||
output "group_ids" {
|
||||
|
||||
Reference in New Issue
Block a user