mirror of
https://github.com/outbackdingo/homelab-v.git
synced 2026-08-25 14:53:19 +00:00
fix(gateway): remove separate tls-passthrough gateway
It appears to work without a separate Gateway now. Should investigate if https://github.com/cilium/cilium/issues/32371 can be closed Signed-off-by: Vegard Hagen <[email protected]>
This commit is contained in:
+4
-8
@@ -1,15 +1,11 @@
|
|||||||
apiVersion: gateway.networking.k8s.io/v1alpha2
|
apiVersion: gateway.networking.k8s.io/v1alpha2
|
||||||
kind: TLSRoute
|
kind: TLSRoute
|
||||||
metadata:
|
metadata:
|
||||||
name: proxmox-tls
|
name: proxmox
|
||||||
namespace: proxmox
|
namespace: proxmox
|
||||||
spec:
|
spec:
|
||||||
parentRefs:
|
parentRefs:
|
||||||
- name: tls-passthrough
|
- { name: internal, namespace: gateway }
|
||||||
namespace: gateway
|
hostnames: [ proxmox.stonegarden.dev ]
|
||||||
hostnames:
|
|
||||||
- "proxmox.stonegarden.dev"
|
|
||||||
rules:
|
rules:
|
||||||
- backendRefs:
|
- backendRefs: [ { name: proxmox, port: 443 } ]
|
||||||
- name: proxmox
|
|
||||||
port: 443
|
|
||||||
|
|||||||
+3
-7
@@ -5,11 +5,7 @@ metadata:
|
|||||||
namespace: truenas
|
namespace: truenas
|
||||||
spec:
|
spec:
|
||||||
parentRefs:
|
parentRefs:
|
||||||
- name: tls-passthrough
|
- { name: internal, namespace: gateway }
|
||||||
namespace: gateway
|
hostnames: [ truenas.stonegarden.dev ]
|
||||||
hostnames:
|
|
||||||
- "truenas.stonegarden.dev"
|
|
||||||
rules:
|
rules:
|
||||||
- backendRefs:
|
- backendRefs: [ { name: truenas, port: 443 } ]
|
||||||
- name: truenas
|
|
||||||
port: 443
|
|
||||||
|
|||||||
@@ -1,26 +0,0 @@
|
|||||||
apiVersion: gateway.networking.k8s.io/v1
|
|
||||||
kind: HTTPRoute
|
|
||||||
metadata:
|
|
||||||
name: argocd
|
|
||||||
namespace: argocd
|
|
||||||
spec:
|
|
||||||
parentRefs:
|
|
||||||
- name: internal
|
|
||||||
namespace: gateway
|
|
||||||
hostnames:
|
|
||||||
- "argocd.stonegarden.dev"
|
|
||||||
rules:
|
|
||||||
- matches:
|
|
||||||
- path:
|
|
||||||
type: PathPrefix
|
|
||||||
value: /
|
|
||||||
backendRefs:
|
|
||||||
- name: argocd-server
|
|
||||||
port: 80
|
|
||||||
# - matches:
|
|
||||||
# - headers:
|
|
||||||
# - name: Content-Type
|
|
||||||
# value: application/grpc
|
|
||||||
# backendRefs:
|
|
||||||
# - name: argocd-server
|
|
||||||
# port: 80
|
|
||||||
@@ -5,11 +5,7 @@ metadata:
|
|||||||
namespace: argocd
|
namespace: argocd
|
||||||
spec:
|
spec:
|
||||||
parentRefs:
|
parentRefs:
|
||||||
- name: internal
|
- { name: internal, namespace: gateway }
|
||||||
namespace: gateway
|
hostnames: [ argocd.stonegarden.dev ]
|
||||||
hostnames:
|
|
||||||
- "argocd.stonegarden.dev"
|
|
||||||
rules:
|
rules:
|
||||||
- backendRefs:
|
- backendRefs: [ { name: argocd-server, port: 443 } ]
|
||||||
- name: argocd-server
|
|
||||||
port: 443
|
|
||||||
|
|||||||
@@ -1,29 +0,0 @@
|
|||||||
apiVersion: gateway.networking.k8s.io/v1
|
|
||||||
kind: Gateway
|
|
||||||
metadata:
|
|
||||||
name: tls-passthrough
|
|
||||||
namespace: gateway
|
|
||||||
spec:
|
|
||||||
gatewayClassName: cilium
|
|
||||||
infrastructure:
|
|
||||||
annotations:
|
|
||||||
io.cilium/lb-ipam-ips: 192.168.1.221
|
|
||||||
listeners:
|
|
||||||
- protocol: TLS
|
|
||||||
port: 443
|
|
||||||
name: proxmox
|
|
||||||
hostname: "proxmox.stonegarden.dev"
|
|
||||||
tls:
|
|
||||||
mode: Passthrough
|
|
||||||
allowedRoutes:
|
|
||||||
namespaces:
|
|
||||||
from: All
|
|
||||||
- protocol: TLS
|
|
||||||
port: 443
|
|
||||||
name: truenas
|
|
||||||
hostname: "truenas.stonegarden.dev"
|
|
||||||
tls:
|
|
||||||
mode: Passthrough
|
|
||||||
allowedRoutes:
|
|
||||||
namespaces:
|
|
||||||
from: All
|
|
||||||
@@ -7,4 +7,3 @@ resources:
|
|||||||
- ns.yaml
|
- ns.yaml
|
||||||
- gw-external.yaml
|
- gw-external.yaml
|
||||||
- gw-internal.yaml
|
- gw-internal.yaml
|
||||||
- gw-tls-passthrough.yaml
|
|
||||||
|
|||||||
@@ -1,42 +0,0 @@
|
|||||||
## GCS Remote
|
|
||||||
|
|
||||||
1. Create a [Service Account](https://cloud.google.com/iam/docs/service-accounts-create) named tofu (after enabling the
|
|
||||||
IAM API if needed). Leave the permissions blank.
|
|
||||||
2. Create and download the [service account key](https://cloud.google.com/iam/docs/keys-create-delete#creating).
|
|
||||||
3. Create a GCS bucket for tofu state with public access prevention and versioning as necessary.
|
|
||||||
4. In the permissions tab of the bucket, give **Storage Object Admin** access to the service account.
|
|
||||||
5. Copy backend.tf.sample to backend.tf and make necessary changes.
|
|
||||||
|
|
||||||
```shell
|
|
||||||
cp remote_backend.tf.sample remote_backend.tf
|
|
||||||
```
|
|
||||||
|
|
||||||
### Encryption key
|
|
||||||
|
|
||||||
Generate the encryption key
|
|
||||||
|
|
||||||
```shell
|
|
||||||
python3 -c 'import os;import base64;print(base64.b64encode(os.urandom(32)).decode("utf-8"))'
|
|
||||||
```
|
|
||||||
|
|
||||||
`Without the encryption key, your state would not be recoverable. Store in a password manager, if not using any kms like bws.`
|
|
||||||
|
|
||||||
### Environment variables
|
|
||||||
|
|
||||||
```shell
|
|
||||||
export GOOGLE_APPLICATION_CREDENTIALS="<YOUR_DOWNLOADED_KEY_PATH>"
|
|
||||||
export GOOGLE_ENCRYPTION_KEY="<YOUR_GENERATED_ENCRYPTION_KEY>"
|
|
||||||
```
|
|
||||||
|
|
||||||
Run tofu init / plan / apply as usual.
|
|
||||||
|
|
||||||
### Bitwarden Secrets Manager
|
|
||||||
|
|
||||||
Store the downloaded key contents and generated encryption key into GOOGLE_CREDENTIALS and GOOGLE_ENCRYPTION_KEY
|
|
||||||
respectively in bws.
|
|
||||||
|
|
||||||
Run bws run -- tofu init / plan / apply as usual.
|
|
||||||
|
|
||||||
### Beta Notice
|
|
||||||
|
|
||||||
`Please treat this as beta and only use for air-gapped installations as of now. Will remove the beta tag after testing it in due course.`
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
terraform {
|
|
||||||
backend "gcs" {
|
|
||||||
bucket = "<YOUR_GCS_BUCKET>"
|
|
||||||
prefix = "prod/kubernetes"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user