@@ -1,7 +1,26 @@
|
|||||||
# cloudflared
|
# cloudflared
|
||||||
|
|
||||||
Kubernetes deployment source-of-truth repository for `cloudflared`.
|
GitOps source for the Cloudflare Tunnel connector in the `networking` namespace.
|
||||||
|
|
||||||
This repo manages the Cloudflare tunnel deployment in `networking` through an
|
## Current deployment
|
||||||
Argo CD `ApplicationSet`, using a SOPS-encrypted tunnel token and a simple
|
|
||||||
kustomize overlay.
|
- Bootstrap: `enabled: true`, applied from `main`
|
||||||
|
- Argo application: `cloudflared-production`
|
||||||
|
- Target namespace: `networking`
|
||||||
|
- Render path: `manifest/overlays/production`
|
||||||
|
- Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/cloudflared.git`
|
||||||
|
- Config management plugin: `ksops`
|
||||||
|
|
||||||
|
## Runtime
|
||||||
|
|
||||||
|
The base deploys three `cloudflare/cloudflared:latest` replicas with rolling
|
||||||
|
updates, topology spread, readiness/liveness checks on port `2000`, and
|
||||||
|
`cloudflared tunnel --no-autoupdate --metrics 0.0.0.0:2000 run`.
|
||||||
|
|
||||||
|
## Secrets
|
||||||
|
|
||||||
|
The tunnel token is read from `Secret/cloudflared-secrets`, key `tunnel_token`.
|
||||||
|
`manifest/overlays/production/sealed-secret.yaml` exists in the repo but is not
|
||||||
|
currently referenced by the production kustomization. Confirm whether the secret
|
||||||
|
is managed out-of-band or should be added to the overlay before relying on a new
|
||||||
|
sync to create it.
|
||||||
|
|||||||
Reference in New Issue
Block a user