Testing SS on amd host
This commit is contained in:
parent
b322446b0d
commit
c5e47bb142
@ -2,6 +2,7 @@ Repo for storing the home lab's K8s GitOps setup. WIP...
|
||||
|
||||
### WIP
|
||||
|
||||
- [ ] configure ingress for Grafana instances
|
||||
- [ ] update repo README
|
||||
- [ ] move all apps on old-reliable into Flux management
|
||||
- [ ] switch to branch based operation (merge feature branch into main for any changes)
|
||||
|
||||
@ -3,10 +3,10 @@ kind: Kustomization
|
||||
namespace: monitoring
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- kube-prometheus-stack.yaml
|
||||
- metrics-server.yaml
|
||||
- rbac.yaml
|
||||
- grafana-auth-secret.yaml
|
||||
- kube-prometheus-stack.yaml
|
||||
- metrics-server.yaml
|
||||
configMapGenerator:
|
||||
- name: flux-kube-state-metrics-config
|
||||
files:
|
||||
|
||||
5
components/security/controllers/base/.sops.yaml
Normal file
5
components/security/controllers/base/.sops.yaml
Normal file
@ -0,0 +1,5 @@
|
||||
creation_rules:
|
||||
- path_regex: sealed-secret-seed-tls.yaml$
|
||||
encrypted_regex: "^(data)$"
|
||||
age:
|
||||
- age1u0mt3kmhsr9tz2jaw8n0ztu7s9hnlffkd2acxf85cvk6tysj4gsqqulfdq
|
||||
8
components/security/controllers/base/kustomization.yaml
Normal file
8
components/security/controllers/base/kustomization.yaml
Normal file
@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
namespace: security
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- rbac.yaml
|
||||
- sealed-secret-seed-tls.yaml
|
||||
- sealed-secrets.yaml
|
||||
8
components/security/controllers/base/namespace.yaml
Normal file
8
components/security/controllers/base/namespace.yaml
Normal file
@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: security
|
||||
labels:
|
||||
app.kubernetes.io/component: security
|
||||
toolkit.fluxcd.io/tenant: platform-team
|
||||
pod-security.kubernetes.io/enforce: privileged
|
||||
0
components/security/controllers/base/rbac.yaml
Normal file
0
components/security/controllers/base/rbac.yaml
Normal file
File diff suppressed because one or more lines are too long
20
components/security/controllers/base/sealed-secrets.yaml
Normal file
20
components/security/controllers/base/sealed-secrets.yaml
Normal file
@ -0,0 +1,20 @@
|
||||
apiVersion: source.toolkit.fluxcd.io/v1
|
||||
kind: HelmRepository
|
||||
metadata:
|
||||
name: sealed-secrets
|
||||
spec:
|
||||
interval: 1h
|
||||
url: https://bitnami-labs.github.io/sealed-secrets
|
||||
---
|
||||
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||
kind: HelmRelease
|
||||
metadata:
|
||||
name: sealed-secrets
|
||||
spec:
|
||||
serviceAccountName: flux
|
||||
interval: 1h
|
||||
chartRef:
|
||||
kind: HelmChart
|
||||
name: sealed-secrets
|
||||
values:
|
||||
secretName: sealed-secrets-seed-key
|
||||
@ -0,0 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../base
|
||||
Loading…
Reference in New Issue
Block a user