mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
fix(admin): wire-in the admin-api like prod (#559)
This commit is contained in:
@@ -65,8 +65,11 @@ export TF_VAR_sietch_db_backup_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_
|
||||
export TF_VAR_sietch_db_backup_secret_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_DB_BACKUP_SECRET_KEY/password"
|
||||
export TF_VAR_sietch_rgw_tls_cert="op://yucca_tf_staging/SIETCH_CEPH_RGW_TLS_CERT/password"
|
||||
|
||||
# Cloudflare API token for cert-manager DNS-01 (same item, TF_VAR form).
|
||||
export TF_VAR_cloudflare_api_token="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"
|
||||
# Cloudflare API token for cert-manager DNS-01. The shared bootstrap token, not
|
||||
# the futo.cloud-scoped staging one: the admin cert (admin.luke.….yucca.futo.
|
||||
# network, apps/staging/austin/admin) needs DNS:Edit on futo.network — same
|
||||
# item prod's cert-manager uses.
|
||||
export TF_VAR_cloudflare_api_token="op://shared_tf/FUTO_BOOTSTRAP_CLOUDFLARE_API_TOKEN/password"
|
||||
|
||||
# NetBird, minted by deployment/staging/netbird into yucca_tf_staging.
|
||||
# NB: `op run` resolves EVERY ref in this file up front for ANY stack, so a ref
|
||||
|
||||
@@ -119,3 +119,17 @@ output "kube_api_fqdn" {
|
||||
description = "father API endpoint FQDN — NetBird peers resolve it (round-robin) to the CPs."
|
||||
value = local.father_kube_api_fqdn
|
||||
}
|
||||
|
||||
# luke (staging@austin) admin-api — the ONLY non-father record, living here
|
||||
# because the account-wide zone does (see the NB above; move it out together
|
||||
# with the zone). Points at luke's internal admin gateway VIP, L2-announced on
|
||||
# the Austin LAN and reachable over the staging 10.10.10.0/24 NetBird route —
|
||||
# never the public NAT. VIP pinned in kubernetes/apps/staging/austin/admin/
|
||||
# (lbipam annotation) and allocated from cilium-lb.yaml; keep the three in sync.
|
||||
resource "netbird_dns_record" "luke_admin" {
|
||||
zone_id = netbird_dns_zone.yucca_internal.id
|
||||
name = "admin.luke.aus.int.yucca.futo.network"
|
||||
type = "A"
|
||||
content = "10.10.10.17"
|
||||
ttl = 300
|
||||
}
|
||||
|
||||
@@ -34,8 +34,10 @@ output "discovery" {
|
||||
domain = var.domain
|
||||
}
|
||||
kubernetes = {
|
||||
cluster_name = var.cluster.name
|
||||
api_endpoint = local.cluster_endpoint # https://<api_dns_name>:6443 (VIP)
|
||||
cluster_name = var.cluster.name
|
||||
api_endpoint = local.cluster_endpoint # https://<api_dns_name>:6443 (VIP)
|
||||
# NetBird-only netops record (netbird/dns.tf) = YUCCA_ADMIN_HOST.
|
||||
admin_api_host = "admin.${trimprefix(local.api_dns_name, "kube.")}"
|
||||
api_vip = local.api_vip # Talos-elected VIP on kube-cp (the api_dns_name A record)
|
||||
operator_endpoint = local.operator_endpoint # direct bootstrap-CP apiserver
|
||||
cp_node_ips = local.cp_ips # kube-cp IPs; operators/yuctl reach via NetBird
|
||||
|
||||
@@ -31,8 +31,12 @@ output "discovery" {
|
||||
domain = var.domain
|
||||
}
|
||||
kubernetes = {
|
||||
cluster_name = local.only_cluster_key
|
||||
api_endpoint = local.k8s.cluster_endpoint
|
||||
cluster_name = local.only_cluster_key
|
||||
api_endpoint = local.k8s.cluster_endpoint
|
||||
# NetBird-only: the record lives in the prod/htz-fsn1/netbird stack (the
|
||||
# account-wide yucca.futo.network zone is there), the internal admin VIP +
|
||||
# gateway in kubernetes/apps/staging/austin/admin. = YUCCA_ADMIN_HOST.
|
||||
admin_api_host = "admin.${local.only_cluster_key}.${var.region_code}.${var.provider_code}.yucca.futo.network"
|
||||
operator_endpoint = local.k8s.operator_endpoint
|
||||
cp_node_ips = local.k8s.cp_node_ips
|
||||
kubeconfig_ref = "op://${local._disc_vault}/${local._kubeconfig_title}/password"
|
||||
|
||||
@@ -143,9 +143,10 @@ variable "sietch_rgw_tls_cert" {
|
||||
}
|
||||
|
||||
# Cloudflare API token for the cert-manager DNS-01 ClusterIssuer (futo.cloud
|
||||
# zone). Same 1P item the dns stack uses. Injected via TF_VAR from 1P.
|
||||
# for the app domain + futo.network for the admin cert — the shared bootstrap
|
||||
# token, see tf/.env). Injected via TF_VAR from 1P.
|
||||
variable "cloudflare_api_token" {
|
||||
description = "Cloudflare API token (Zone:Read + DNS:Edit on futo.cloud) for cert-manager DNS-01. Injected via TF_VAR from 1P."
|
||||
description = "Cloudflare API token (Zone:Read + DNS:Edit on futo.cloud and futo.network) for cert-manager DNS-01. Injected via TF_VAR from 1P."
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
|
||||
Reference in New Issue
Block a user