Files
yucca/kubernetes/apps/prod/htz-fsn1/infra/envoy.yaml
T

78 lines
2.8 KiB
YAML

# Envoy Gateway on father — CHERRY-PICKED from components/infra/network (same
# caveat as cert-manager.yaml: REMOVE this file when components/infra is enabled,
# or the Kustomization names collide). Deploys the operator + the APP gateway
# (pre-staged for the yucca launch: VIP ${INGRESS_VIP}, cert for
# ${APP_DOMAIN}); the NETOPS gateway lives in netops/gateway.yaml.
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/kustomize.toolkit.fluxcd.io/kustomization_v1.json
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: envoy-gateway
namespace: flux-system
spec:
healthChecks:
- apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
name: envoy-gateway
namespace: envoy-system
interval: 1h
retryInterval: 2m
timeout: 10m
path: ./kubernetes/apps/base/envoy-gateway
prune: true
wait: true
sourceRef:
kind: GitRepository
name: ${MANIFEST_SOURCE:=flux-system}
namespace: flux-system
targetNamespace: envoy-system
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/kustomize.toolkit.fluxcd.io/kustomization_v1.json
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: envoy-proxy
namespace: flux-system
spec:
dependsOn:
- name: envoy-gateway
- name: cert-manager-issuer
interval: 1h
retryInterval: 2m
timeout: 10m
path: ./kubernetes/apps/base/envoy-proxy
prune: true
wait: true
sourceRef:
kind: GitRepository
name: ${MANIFEST_SOURCE:=flux-system}
namespace: flux-system
targetNamespace: envoy-system
# PROD-ONLY: the discovery pointer lives on ${META_HOST} = meta.futo.cloud,
# which is outside the *.${APP_DOMAIN} wildcard the base cert covers (staging's
# META_HOST is under its app domain, so staging needs none of this).
#
# Deliberately an extra SAN on the EXISTING cert rather than a second
# certificateRef on the gateway listener: Gateway API makes a listener whose
# certificateRef can't be resolved Programmed=False, so a new ref would take
# the whole https listener (web + api) down for as long as it takes
# cert-manager to issue — an outage designed into a routine merge. Editing
# dnsNames instead just triggers a reissue; the old Secret keeps serving
# throughout and the listener never changes.
#
# NB: kustomize applies this patch, THEN postBuild substitutes — which is why
# a ${VAR} in the patch value resolves. Coupling accepted: a meta.futo.cloud
# DNS-01 failure now blocks renewal of the app cert too, but both names sit in
# the same Cloudflare zone behind the same token, so they fail together anyway.
patches:
- target:
group: cert-manager.io
kind: Certificate
name: app-domain
patch: |-
- op: add
path: /spec/dnsNames/-
value: ${META_HOST}