@@ -1,7 +1,26 @@
|
||||
# cloudflared
|
||||
|
||||
Kubernetes deployment source-of-truth repository for `cloudflared`.
|
||||
GitOps source for the Cloudflare Tunnel connector in the `networking` namespace.
|
||||
|
||||
This repo manages the Cloudflare tunnel deployment in `networking` through an
|
||||
Argo CD `ApplicationSet`, using a SOPS-encrypted tunnel token and a simple
|
||||
kustomize overlay.
|
||||
## Current deployment
|
||||
|
||||
- Bootstrap: `enabled: true`, applied from `main`
|
||||
- Argo application: `cloudflared-production`
|
||||
- Target namespace: `networking`
|
||||
- Render path: `manifest/overlays/production`
|
||||
- Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/cloudflared.git`
|
||||
- Config management plugin: `ksops`
|
||||
|
||||
## Runtime
|
||||
|
||||
The base deploys three `cloudflare/cloudflared:latest` replicas with rolling
|
||||
updates, topology spread, readiness/liveness checks on port `2000`, and
|
||||
`cloudflared tunnel --no-autoupdate --metrics 0.0.0.0:2000 run`.
|
||||
|
||||
## Secrets
|
||||
|
||||
The tunnel token is read from `Secret/cloudflared-secrets`, key `tunnel_token`.
|
||||
`manifest/overlays/production/sealed-secret.yaml` exists in the repo but is not
|
||||
currently referenced by the production kustomization. Confirm whether the secret
|
||||
is managed out-of-band or should be added to the overlay before relying on a new
|
||||
sync to create it.
|
||||
|
||||
Reference in New Issue
Block a user