From 892f5d03b85b47cb3639d07b8624f8a3d2af4270 Mon Sep 17 00:00:00 2001 From: nick-gorse Date: Wed, 9 Sep 2026 16:59:09 +0100 Subject: [PATCH] docs: add CHANGELOG.md documenting deployment history Generated from a per-commit review of the actual file changes, describing the real operational impact of each change on the running deployment. Co-Authored-By: Claude Opus 4.8 --- CHANGELOG.md | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 CHANGELOG.md diff --git a/CHANGELOG.md b/CHANGELOG.md new file mode 100644 index 0000000..3d2f1b5 --- /dev/null +++ b/CHANGELOG.md @@ -0,0 +1,31 @@ +# Changelog + +All notable changes to the **cloudflared** deployment are documented here. + +cloudflared runs the [Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/) connector in the `networking` namespace, giving Cloudflare an outbound-only path into the cluster (no inbound ports opened). This repo owns raw Kubernetes manifests (a Deployment) under `manifest/base` plus a production overlay; Argo CD renders `manifest/overlays/production`. + +Entries describe what actually changed in the running deployment. Dates are commit dates; newest first. + +--- + +## 2026-08-12 — Scale down to 2 replicas + +- **`2 replicas`:** Deployment replicas 3 → 2. Keeps HA (survives a node loss) at lower footprint. + +## 2026-06-05 → 2026-06-06 — Glance dashboard tile + +- **`glances` / `icon`:** added Glance annotations (`glance/id`, description, icon `di:cloudflared`, and a `glance/url` linking to the Cloudflare Zero Trust connectors page), grouped under `glance/parent: cloudflared`. + +## 2026-06-01 — Pin the image + auto-sync toggle + +- **`pin version`:** pinned the image from `cloudflare/cloudflared:latest` (`imagePullPolicy: Always`) to **`2026.5.2`** (`IfNotPresent`). Removes the risk of an unattended `latest` pull silently changing the running connector version. +- **`auto update toggle`:** dropped the `ksops` config-management plugin from the ApplicationSet (secret no longer rendered via ksops) and kept the `ignoreApplicationDifferences` on `/spec/syncPolicy` so auto-sync can be toggled in the Argo CD UI without showing drift. + +## 2026-04-19 → 2026-05-11 — Initial rollout and secret-management churn + +- **`Initial cloudflared gitops app`:** ApplicationSet `cloudflared` (namespace `networking`), rendering a Deployment of **3 replicas** of `cloudflare/cloudflared:latest`, running `tunnel --no-autoupdate --metrics 0.0.0.0:2000 run`, with readiness/liveness on `/ready:2000`, topology spread across hosts, and rolling updates (`maxSurge: 0`, `maxUnavailable: 1`). Tunnel token read from `Secret/cloudflared-secrets` key `tunnel_token`. Originally used a **SOPS/ksops** secret generator. +- **`Enable bootstrap on main`:** flipped `bootstrap/config.yaml` to `enabled: true` so Argo CD picks it up. +- **Secret management migration:** `Migrate secret to Sealed Secrets` (ksops generator → `sealed-secret.yaml`), then `remove secret from manifest` (commented the sealed-secret out — the tunnel token is now managed **out-of-band**, not created by the sync). *Operational caveat:* a fresh sync will not recreate `cloudflared-secrets`; it must exist in the cluster already. +- **Replica churn:** `shutdown` (3 → 1) then `return to 3 replicas` — briefly scaled to a single pod, then back to 3. +- **`enable toggle of autosync`:** added `ignoreApplicationDifferences` on `/spec/syncPolicy` and set `selfHeal: false` / `enabled: false` so sync can be paused from the UI. +- **README + badge:** added then removed a CI badge; rewrote the README to document the running deployment.