Antoine Lecompte
254b7a4b49
feat(k8s): cluster naming ( #243 )
...
* chore(netbird): move to kebab naming
Render NetBird object names (groups, setup keys, policies, networks,
network-resources) as lowercase-kebab instead of UPPER_SNAKE, e.g.
YUCCA_PROD_HTZ_FSN1_MGMT → yucca-prod-htz-fsn1-mgmt. The 1Password setup-key
item titles stay UPPER_SNAKE (decoupled) so CI/ansible/talos op:// consumers
keep resolving.
Pin the futo-org/netbird provider to 1.0.2, which fixes the group
resources TF→API decode so a resource-tag group (htz-fsn1 `resources`) can be
renamed in place — no name pin needed.
* update locks
* chore(naming): naming names
2026-06-30 13:16:50 -04:00
Antoine Lecompte
75b7808993
chore(netbird): move to kebab naming ( #242 )
...
* chore(netbird): move to kebab naming
Render NetBird object names (groups, setup keys, policies, networks,
network-resources) as lowercase-kebab instead of UPPER_SNAKE, e.g.
YUCCA_PROD_HTZ_FSN1_MGMT → yucca-prod-htz-fsn1-mgmt. The 1Password setup-key
item titles stay UPPER_SNAKE (decoupled) so CI/ansible/talos op:// consumers
keep resolving.
Pin the futo-org/netbird provider to 1.0.2, which fixes the group
resources TF→API decode so a resource-tag group (htz-fsn1 `resources`) can be
renamed in place — no name pin needed.
* update locks
2026-06-30 16:20:10 +00:00
Antoine Lecompte
baae250f76
feat(fabric): management plane on a per cluster basis ( #240 )
2026-06-30 15:22:38 +00:00
Antoine Lecompte
e00ea72a21
fix(kube): move to local volumes ( #241 )
2026-06-30 11:22:14 -04:00
Antoine Lecompte
012db81704
fix(netbird): policies ( #239 )
2026-06-30 10:31:31 -04:00
Antoine Lecompte
2ec0e668ad
chore(netbird): switch provider ( #238 )
...
* chore(netbird): change provider, normalize
* commit
2026-06-30 10:09:42 -04:00
Antoine Lecompte
0c1b7f765c
chore(fabric): switch over the fabric from the generated provider to … ( #231 )
...
* chore(fabric): switch over the fabric from the generated provider to a community provider
* cleanup
2026-06-29 16:03:50 -04:00
Antoine Lecompte
f75cc90cf9
feat(prod): add mgmt-1 to terraform ownership (bye tailscale) ( #230 )
2026-06-29 14:10:28 -04:00
Antoine Lecompte
ceba1f0eef
fix(fabric): unhinged fix to duplicate config blocks because this is entirely spaget ( #229 )
2026-06-29 18:02:15 +00:00
Antoine Lecompte
f78ba50ebc
fix(fabric): fix fabric deployment ( #228 )
2026-06-29 13:35:19 -04:00
Antoine Lecompte
745bf5970e
feat(claude): first CLAUDE.md ( #226 )
2026-06-29 17:34:29 +00:00
Antoine Lecompte
b723285626
fix(workflow): gate ansible workflows ( #227 )
2026-06-29 13:34:14 -04:00
Antoine Lecompte
4cf9ac0a83
fix(ci): apply prettier formatting ( #225 )
2026-06-29 17:11:41 +00:00
Antoine Lecompte
aeee19e336
feat(bgp): stand up bgp ( #224 )
...
* feat(bgp): stand up bgp
* eergh
* firewall
* fix
2026-06-29 14:50:43 +00:00
Antoine Lecompte
48c6220894
fix(workflow): missing working directory ( #223 )
2026-06-29 13:04:36 +00:00
Antoine Lecompte
c6985d902c
feat(all): introduce partition/region/ceph-cluster model across the stack ( #222 )
...
* feat: introduce partition/region/ceph-cluster model across the stack
Formalize partition -> region -> {one k8s cluster, many ceph clusters} and
thread it through every layer plus a new yuctl ops CLI.
- tf: deployment/<partition>/<region>/<stack> layout; terragrunt path-parse +
state key yucca/<partition>/<region>/<stack>; per-region region.hcl (role,
site_id, datacenter, provider_code, domain); env->partition / site->region
renames (NetBird object names byte-identical); standardized per-stack
`discovery` output contract (secrets as op:// refs).
- k8s: clusters/<partition>/<region>/ (staging/austin, prod/htz-fsn1, dev/local);
role-based kustomize components (primary/secondary); hybrid cluster-settings
(TF-rendered identity + human fragment); dev-mirror folded into dev/local;
charts regrouped into charts/{apps,platform,lib,dev}.
- ci: infra.yml partition/region discovery matrix; partition-keyed path filters;
<partition>-<region> environment gates; image-versions path moves.
- ansible: inventories under <partition>-<region>/<cluster>.
- yuctl: Go/cobra CLI reading the discovery contract from TF state.
- Retire the sietch-talos libvirt VM cluster (dev@local is the k3d cluster);
ceph inventory_dirname -> <partition>-<region>/<cluster>.
Verified: mise k8s:validate green (3 clusters); yuctl go build/vet; tofu
validate pre-merge (all 9 stacks). Live-staging state migration NOT run.
* fix typo
* commit
2026-06-29 08:40:29 -04:00
Antoine Lecompte
54c410f59c
fix(netbird): comment in the things ( #221 )
...
* fix(netbird): comment in the things
* remove netbird namespace
2026-06-27 12:01:58 +00:00
Antoine Lecompte
a6235d77ed
fix(netbird): comment out lines ( #220 )
...
* feat(netbird): k8s
* fix(netbird): comment out things temp
2026-06-26 19:48:41 +00:00
Antoine Lecompte
4033cc2d97
fix(netbird): add netbird network to trusted list ( #219 )
2026-06-26 19:42:45 +00:00
Antoine Lecompte
0ec09f022a
feat(netbird): k8s ( #218 )
2026-06-26 19:41:32 +00:00
Antoine Lecompte
e039026cbe
feat(netbird-ansible): better subnet routers ( #217 )
2026-06-26 19:27:28 +00:00
Antoine Lecompte
00421f33ec
fix(netbird): take explicit group-name overrides verbatim( #216 )
2026-06-26 19:02:30 +00:00
Antoine Lecompte
481c5e920a
feat(yucca): add full e2e mgmt provisioning maybe ( #182 )
...
* feat(yucca): add full e2e mgmt provisioning maybe
* moar !
* prefer tailscale over public ip if availbale
* ignore files
* fix
* more progress
2026-06-26 14:45:20 -04:00
Antoine Lecompte
847409819f
fix(netbird): restore the talos plan's NetBird connect (revert -refre… ( #215 )
...
fix(netbird): restore the talos plan's NetBird connect (revert -refresh=false)
#212 left the talos plan on `-refresh=false` with no overlay connect, but the
plan reads data.talos_cluster_health — a data source that dials the cluster over
the overlay and is NOT skipped by -refresh=false, so it hangs with no route to
the nodes. Restore the netbird-connect step on the plan job.
Documents the one-time out-of-band bootstrap: the CI setup key is minted by the
netbird apply, which is gated behind the plan that needs it, so seed it once via
TF_STACK_DIR=tf/deployment/staging/netbird mise run tf:apply.
2026-06-26 18:36:17 +00:00
Antoine Lecompte
948b15cf0b
fix(netbird): some issues ( #212 )
2026-06-26 18:16:41 +00:00
Antoine Lecompte
031974a32b
feat(netbird): wire this sweetie up ( #209 )
...
* feat(netbird): wire this sweetie up
* remove dev
* fix
* more features
2026-06-26 18:03:02 +00:00
Antoine Lecompte
05bb52e750
fix(ansible): add missing deps ( #204 )
2026-06-26 11:44:45 -04:00
Antoine Lecompte
1d4a0ebcc2
Feat/ansible change ( #203 )
...
* feat(ansible): change
* fix(ceph): install ansible-iac SSH key in OpenSSH format
The SIETCH_CEPH_ANSIBLE_IAC_SSH_KEY 1P item is an SSH_KEY whose private-key
field reads back as PKCS#8 by default. macOS ssh tolerates that for ed25519,
but Ubuntu's OpenSSH (CI runners) rejects it with 'Load key: invalid format',
so the infra.yml ceph deploy hit 'Permission denied (publickey)' and every
node was UNREACHABLE. Read the key with ?ssh-format=openssh so it lands as a
universally-accepted OPENSSH private key.
2026-06-26 15:35:11 +00:00
Antoine Lecompte
f49cf82079
feat(ansible): change ( #202 )
2026-06-26 15:20:56 +00:00
Antoine Lecompte
97b4514644
feat(ansible): make it go brrr in ci ( #200 )
2026-06-26 15:10:20 +00:00
Antoine Lecompte
5d97a0fd04
feat(staging): wire in metrics-worker ( #181 )
...
* feat(staging): wire in metrics-worker
* fix(metrics-worker): urls
* secrets
2026-06-26 14:35:37 +00:00
Antoine Lecompte
fa1683c9c6
fix(michael): remove duplicate s3 env vars ( #194 )
2026-06-26 14:06:26 +00:00
Antoine Lecompte
deed0ba505
fix(yucca-api): good secret name ( #198 )
2026-06-26 14:02:42 +00:00
Antoine Lecompte
ec750767a3
fix: device code flow maybe ( #158 )
2026-06-26 13:58:11 +00:00
Antoine Lecompte
9f7b94b5fb
Fix/vault vmauth ( #197 )
...
fix(yucca): correct vault for vmwauth
2026-06-26 13:53:41 +00:00
Antoine Lecompte
82f8f44a97
feat(k8s): wire in flux notifications-controller for commit statuses ( #195 )
2026-06-26 09:47:05 -04:00
Antoine Lecompte
065ff3d308
feat(michael): make michael also do load balancing since he's not too… ( #179 )
...
* feat(michael): make michael also do load balancing since he's not too busy
* add load balancing locally plus expose knobs
2026-06-25 18:02:51 +00:00
Antoine Lecompte
9b39abfd6a
fix(fabic): a lot of custom stuff there ( #180 )
...
* fix: fabric stuff
* fix: fabric stuff 2 - electric boogaloo
* fix: fabric stuff 2 - electric boogaloo 2
* fix(fabric): fix stuff 3 electic boogaloo (big)
2026-06-25 18:01:47 +00:00
Antoine Lecompte
bc8136def5
feat(staging): normalize logs ( #164 )
2026-06-25 17:55:33 +00:00
Antoine Lecompte
b5a0b97bcb
Fix/fabric stuff 2 ( #176 )
...
* fix: fabric stuff
* fix: fabric stuff 2 - electric boogaloo
* fix: fabric stuff 2 - electric boogaloo 2
2026-06-25 17:19:17 +00:00
Antoine Lecompte
6d4056dffd
fix: fabric stuff ( #173 )
2026-06-25 16:17:39 +00:00
Antoine Lecompte
a6802df749
feat: more fabric things!! ( #171 )
2026-06-25 15:54:20 +00:00
Antoine Lecompte
80d15f23af
feat: fabric terraform ( #170 )
2026-06-25 11:23:59 -04:00
Antoine Lecompte
03e2802c06
fix(staging): correct vmauth url ( #153 )
2026-06-24 10:21:38 -04:00
Antoine Lecompte
1736b7cd3a
fix(staging): set web port ( #152 )
2026-06-24 14:08:17 +00:00
Antoine Lecompte
8f8be89592
fix(staging): oidc unfun ( #151 )
2026-06-24 14:01:28 +00:00
Antoine Lecompte
b03327f7c7
fix(staging): missing quotes ( #150 )
2026-06-24 13:48:09 +00:00
Antoine Lecompte
a92d39f4ec
fix(staging): something ( #149 )
2026-06-24 09:41:40 -04:00
Antoine Lecompte
7d5af4559f
feat(staging): wire in oidc ( #148 )
2026-06-24 09:22:29 -04:00
Antoine Lecompte
df65da6f92
fix(staging): a lot ( #147 )
2026-06-24 13:10:57 +00:00
Antoine Lecompte
ff995bc59c
fix(staging): typo ( #146 )
2026-06-24 12:43:06 +00:00
Antoine Lecompte
fad10fdae9
feat(ci): add kubeconfig / talosconfig to op ( #145 )
2026-06-24 12:35:40 +00:00
Antoine Lecompte
02dab5bcc3
fix(ci): fix secret not having write access ( #144 )
2026-06-24 08:22:32 -04:00
Antoine Lecompte
a4e15123be
fix(ci): op wrong secret field ( #143 )
...
* fix(ci): op wrong secret field
2026-06-24 07:54:39 -04:00
Antoine Lecompte
a6eeb8bb67
fix(ci): adjust secret name ( #142 )
2026-06-24 07:43:23 -04:00
Antoine Lecompte
f700b18cd6
feat: staging ( #135 )
...
* feat: staging
* more stuff
* pin actions
* adjust
* adjust
2026-06-23 18:21:12 +00:00
Antoine Lecompte
070e22a7bb
feat: local k8s ( #85 )
...
* impl. local kube
* add support for op injected oidc secrets
* ci: set least-privilege workflow token permissions
2026-06-12 13:17:37 +00:00
Antoine Lecompte
4665f5cdd1
feat: replace restic-api with michael ( #57 )
2026-04-09 16:47:37 +01:00