From 54c410f59c3e502bafbe522018256c23ddeff79a Mon Sep 17 00:00:00 2001 From: Antoine Lecompte <38678863+nutgood@users.noreply.github.com> Date: Sat, 27 Jun 2026 08:01:58 -0400 Subject: [PATCH] fix(netbird): comment in the things (#221) * fix(netbird): comment in the things * remove netbird namespace --- kubernetes/apps/staging/network/namespace.yaml | 12 ++++-------- tf/.env | 7 +++---- 2 files changed, 7 insertions(+), 12 deletions(-) diff --git a/kubernetes/apps/staging/network/namespace.yaml b/kubernetes/apps/staging/network/namespace.yaml index 5f9e2746..744fd437 100644 --- a/kubernetes/apps/staging/network/namespace.yaml +++ b/kubernetes/apps/staging/network/namespace.yaml @@ -8,11 +8,7 @@ apiVersion: v1 kind: Namespace metadata: name: envoy-system ---- -# Also created by the staging/talos TF stack (it bootstraps the -# netbird-mgmt-api-key Secret here before Flux reconciles). A bare Namespace is -# safe under dual ownership — server-side apply ensures-exists either way. -apiVersion: v1 -kind: Namespace -metadata: - name: netbird +# NB: the `netbird` namespace is NOT declared here — it's created by the +# staging/talos TF stack (secrets.tf), which bootstraps the netbird-mgmt-api-key +# Secret into it before Flux reconciles. Declaring it here too would race TF for +# ownership and 409 on apply, so TF is the sole creator. diff --git a/tf/.env b/tf/.env index 44881606..2db0577e 100644 --- a/tf/.env +++ b/tf/.env @@ -67,10 +67,9 @@ export TF_VAR_cloudflare_api_token="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/p # item already exists (group `talos` was applied previously), so this is live. export TF_VAR_netbird_talos_setup_key="op://yucca_tf_staging/NETBIRD_YUCCA_STAGING_TALOS_SETUP_KEY/password" # • k8s_operator API token → in-cluster operator's netbird-mgmt-api-key (Part B). -# COMMENTED until the first `tf:apply` of deployment/staging/netbird mints the -# NETBIRD_YUCCA_STAGING_K8S_OPERATOR_API_TOKEN item; uncomment afterward so the -# talos stack can bootstrap the secret. (var default is "" → plans stay clean.) -# export TF_VAR_netbird_operator_api_token="op://yucca_tf_staging/NETBIRD_YUCCA_STAGING_K8S_OPERATOR_API_TOKEN/password" +# Live now that deployment/staging/netbird has minted the +# NETBIRD_YUCCA_STAGING_K8S_OPERATOR_API_TOKEN item. +export TF_VAR_netbird_operator_api_token="op://yucca_tf_staging/NETBIRD_YUCCA_STAGING_K8S_OPERATOR_API_TOKEN/password" # The `yucca_tf_staging` refs above are readable only by the staging SA. CI # injects it as OP_SERVICE_ACCOUNT_TOKEN from the repo secret