fix(admin): wire-in the admin-api like prod (#559)

This commit is contained in:
Antoine Lecompte
2026-08-26 12:20:09 +00:00
committed by GitHub
parent e61dabe7e3
commit eb89c13118
18 changed files with 216 additions and 22 deletions
+5 -2
View File
@@ -65,8 +65,11 @@ export TF_VAR_sietch_db_backup_access_key="op://yucca_tf_staging/SIETCH_CEPH_S3_
export TF_VAR_sietch_db_backup_secret_key="op://yucca_tf_staging/SIETCH_CEPH_S3_SVC_YUCCA_DB_BACKUP_SECRET_KEY/password"
export TF_VAR_sietch_rgw_tls_cert="op://yucca_tf_staging/SIETCH_CEPH_RGW_TLS_CERT/password"
# Cloudflare API token for cert-manager DNS-01 (same item, TF_VAR form).
export TF_VAR_cloudflare_api_token="op://yucca_tf_staging/CLOUDFLARE_API_TOKEN/password"
# Cloudflare API token for cert-manager DNS-01. The shared bootstrap token, not
# the futo.cloud-scoped staging one: the admin cert (admin.luke.….yucca.futo.
# network, apps/staging/austin/admin) needs DNS:Edit on futo.network — same
# item prod's cert-manager uses.
export TF_VAR_cloudflare_api_token="op://shared_tf/FUTO_BOOTSTRAP_CLOUDFLARE_API_TOKEN/password"
# NetBird, minted by deployment/staging/netbird into yucca_tf_staging.
# NB: `op run` resolves EVERY ref in this file up front for ANY stack, so a ref
@@ -119,3 +119,17 @@ output "kube_api_fqdn" {
description = "father API endpoint FQDN — NetBird peers resolve it (round-robin) to the CPs."
value = local.father_kube_api_fqdn
}
# luke (staging@austin) admin-api — the ONLY non-father record, living here
# because the account-wide zone does (see the NB above; move it out together
# with the zone). Points at luke's internal admin gateway VIP, L2-announced on
# the Austin LAN and reachable over the staging 10.10.10.0/24 NetBird route —
# never the public NAT. VIP pinned in kubernetes/apps/staging/austin/admin/
# (lbipam annotation) and allocated from cilium-lb.yaml; keep the three in sync.
resource "netbird_dns_record" "luke_admin" {
zone_id = netbird_dns_zone.yucca_internal.id
name = "admin.luke.aus.int.yucca.futo.network"
type = "A"
content = "10.10.10.17"
ttl = 300
}
@@ -34,8 +34,10 @@ output "discovery" {
domain = var.domain
}
kubernetes = {
cluster_name = var.cluster.name
api_endpoint = local.cluster_endpoint # https://<api_dns_name>:6443 (VIP)
cluster_name = var.cluster.name
api_endpoint = local.cluster_endpoint # https://<api_dns_name>:6443 (VIP)
# NetBird-only netops record (netbird/dns.tf) = YUCCA_ADMIN_HOST.
admin_api_host = "admin.${trimprefix(local.api_dns_name, "kube.")}"
api_vip = local.api_vip # Talos-elected VIP on kube-cp (the api_dns_name A record)
operator_endpoint = local.operator_endpoint # direct bootstrap-CP apiserver
cp_node_ips = local.cp_ips # kube-cp IPs; operators/yuctl reach via NetBird
@@ -31,8 +31,12 @@ output "discovery" {
domain = var.domain
}
kubernetes = {
cluster_name = local.only_cluster_key
api_endpoint = local.k8s.cluster_endpoint
cluster_name = local.only_cluster_key
api_endpoint = local.k8s.cluster_endpoint
# NetBird-only: the record lives in the prod/htz-fsn1/netbird stack (the
# account-wide yucca.futo.network zone is there), the internal admin VIP +
# gateway in kubernetes/apps/staging/austin/admin. = YUCCA_ADMIN_HOST.
admin_api_host = "admin.${local.only_cluster_key}.${var.region_code}.${var.provider_code}.yucca.futo.network"
operator_endpoint = local.k8s.operator_endpoint
cp_node_ips = local.k8s.cp_node_ips
kubeconfig_ref = "op://${local._disc_vault}/${local._kubeconfig_title}/password"
@@ -143,9 +143,10 @@ variable "sietch_rgw_tls_cert" {
}
# Cloudflare API token for the cert-manager DNS-01 ClusterIssuer (futo.cloud
# zone). Same 1P item the dns stack uses. Injected via TF_VAR from 1P.
# for the app domain + futo.network for the admin cert — the shared bootstrap
# token, see tf/.env). Injected via TF_VAR from 1P.
variable "cloudflare_api_token" {
description = "Cloudflare API token (Zone:Read + DNS:Edit on futo.cloud) for cert-manager DNS-01. Injected via TF_VAR from 1P."
description = "Cloudflare API token (Zone:Read + DNS:Edit on futo.cloud and futo.network) for cert-manager DNS-01. Injected via TF_VAR from 1P."
type = string
sensitive = true
default = ""