From 808af0910c820bc88b1c55f25e0d8bf01042d221 Mon Sep 17 00:00:00 2001 From: nick-gorse Date: Mon, 11 May 2026 11:25:48 +0100 Subject: [PATCH] update README.md --- README.md | 27 +++++++++++++++++++++++---- 1 file changed, 23 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index aa9b16c..9c07806 100644 --- a/README.md +++ b/README.md @@ -1,7 +1,26 @@ # cloudflared -Kubernetes deployment source-of-truth repository for `cloudflared`. +GitOps source for the Cloudflare Tunnel connector in the `networking` namespace. -This repo manages the Cloudflare tunnel deployment in `networking` through an -Argo CD `ApplicationSet`, using a SOPS-encrypted tunnel token and a simple -kustomize overlay. +## Current deployment + +- Bootstrap: `enabled: true`, applied from `main` +- Argo application: `cloudflared-production` +- Target namespace: `networking` +- Render path: `manifest/overlays/production` +- Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/cloudflared.git` +- Config management plugin: `ksops` + +## Runtime + +The base deploys three `cloudflare/cloudflared:latest` replicas with rolling +updates, topology spread, readiness/liveness checks on port `2000`, and +`cloudflared tunnel --no-autoupdate --metrics 0.0.0.0:2000 run`. + +## Secrets + +The tunnel token is read from `Secret/cloudflared-secrets`, key `tunnel_token`. +`manifest/overlays/production/sealed-secret.yaml` exists in the repo but is not +currently referenced by the production kustomization. Confirm whether the secret +is managed out-of-band or should be added to the overlay before relying on a new +sync to create it.