mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
78 lines
2.8 KiB
YAML
78 lines
2.8 KiB
YAML
# Envoy Gateway on father — CHERRY-PICKED from components/infra/network (same
|
|
# caveat as cert-manager.yaml: REMOVE this file when components/infra is enabled,
|
|
# or the Kustomization names collide). Deploys the operator + the APP gateway
|
|
# (pre-staged for the yucca launch: VIP ${INGRESS_VIP}, cert for
|
|
# ${APP_DOMAIN}); the NETOPS gateway lives in netops/gateway.yaml.
|
|
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/kustomize.toolkit.fluxcd.io/kustomization_v1.json
|
|
---
|
|
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
|
kind: Kustomization
|
|
metadata:
|
|
name: envoy-gateway
|
|
namespace: flux-system
|
|
spec:
|
|
healthChecks:
|
|
- apiVersion: helm.toolkit.fluxcd.io/v2
|
|
kind: HelmRelease
|
|
name: envoy-gateway
|
|
namespace: envoy-system
|
|
interval: 1h
|
|
retryInterval: 2m
|
|
timeout: 10m
|
|
path: ./kubernetes/apps/base/envoy-gateway
|
|
prune: true
|
|
wait: true
|
|
sourceRef:
|
|
kind: GitRepository
|
|
name: ${MANIFEST_SOURCE:=flux-system}
|
|
namespace: flux-system
|
|
targetNamespace: envoy-system
|
|
|
|
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/kustomize.toolkit.fluxcd.io/kustomization_v1.json
|
|
---
|
|
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
|
kind: Kustomization
|
|
metadata:
|
|
name: envoy-proxy
|
|
namespace: flux-system
|
|
spec:
|
|
dependsOn:
|
|
- name: envoy-gateway
|
|
- name: cert-manager-issuer
|
|
interval: 1h
|
|
retryInterval: 2m
|
|
timeout: 10m
|
|
path: ./kubernetes/apps/base/envoy-proxy
|
|
prune: true
|
|
wait: true
|
|
sourceRef:
|
|
kind: GitRepository
|
|
name: ${MANIFEST_SOURCE:=flux-system}
|
|
namespace: flux-system
|
|
targetNamespace: envoy-system
|
|
# PROD-ONLY: the discovery pointer lives on ${META_HOST} = meta.futo.cloud,
|
|
# which is outside the *.${APP_DOMAIN} wildcard the base cert covers (staging's
|
|
# META_HOST is under its app domain, so staging needs none of this).
|
|
#
|
|
# Deliberately an extra SAN on the EXISTING cert rather than a second
|
|
# certificateRef on the gateway listener: Gateway API makes a listener whose
|
|
# certificateRef can't be resolved Programmed=False, so a new ref would take
|
|
# the whole https listener (web + api) down for as long as it takes
|
|
# cert-manager to issue — an outage designed into a routine merge. Editing
|
|
# dnsNames instead just triggers a reissue; the old Secret keeps serving
|
|
# throughout and the listener never changes.
|
|
#
|
|
# NB: kustomize applies this patch, THEN postBuild substitutes — which is why
|
|
# a ${VAR} in the patch value resolves. Coupling accepted: a meta.futo.cloud
|
|
# DNS-01 failure now blocks renewal of the app cert too, but both names sit in
|
|
# the same Cloudflare zone behind the same token, so they fail together anyway.
|
|
patches:
|
|
- target:
|
|
group: cert-manager.io
|
|
kind: Certificate
|
|
name: app-domain
|
|
patch: |-
|
|
- op: add
|
|
path: /spec/dnsNames/-
|
|
value: ${META_HOST}
|