Compare commits

...
12 Commits
Author SHA1 Message Date
olb042andClaude Opus 4.8 892f5d03b8 docs: add CHANGELOG.md documenting deployment history
Validate manifests / validate (push) Failing after 4s
Generated from a per-commit review of the actual file changes, describing
the real operational impact of each change on the running deployment.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-09-09 16:59:09 +01:00
olb042 a5b226b74c 2 replicas
Validate manifests / validate (push) Failing after 5s
2026-08-12 13:05:40 +01:00
olb042 f82eba2f2e icon
Validate manifests / validate (push) Failing after 4s
2026-06-06 02:43:43 +01:00
olb042 722426b5c8 glances
Validate manifests / validate (push) Failing after 4s
2026-06-05 22:57:51 +01:00
olb042 6013157a6b pin version
Validate manifests / validate (push) Failing after 4s
2026-06-01 10:01:52 +01:00
olb042 014244246b auto update toggle
Validate manifests / validate (push) Failing after 6s
2026-06-01 00:03:45 +01:00
olb042 808af0910c update README.md
Validate manifests / validate (push) Failing after 6s
2026-05-11 11:25:48 +01:00
olb042 721bcdb2d2 remove sops
Validate manifests / validate (push) Failing after 11s
2026-05-08 15:49:17 +01:00
olb042 1a0d542927 remove badge
Validate manifests / validate (push) Failing after 5s
2026-05-08 15:43:17 +01:00
olb042 b87a779018 return to 3 replicas
Validate manifests / validate (push) Failing after 3s
2026-04-27 11:02:43 +01:00
olb042 091ddf8203 remove secret from manifest
Validate manifests / validate (push) Failing after 4s
2026-04-27 11:01:41 +01:00
olb042 d9ad49cdc6 add badge link 2026-04-26 00:36:37 +01:00
6 changed files with 67 additions and 17 deletions
-7
View File
@@ -1,7 +0,0 @@
# Replace the age recipient below with the public key used by ArgoCD / ksops
# in the target environment before storing real secrets in this repository.
creation_rules:
- path_regex: manifest/(overlays|components)/.*/.*\.enc\.yaml$
age: age1s0gzgh8c00tgnkgxrqyz2nu0k56xvc9ev3jdenkmu90egux9xfmsxvvj43
- path_regex: manifest/(overlays|components)/.*/secret\.secret\.yaml$
age: age1s0gzgh8c00tgnkgxrqyz2nu0k56xvc9ev3jdenkmu90egux9xfmsxvvj43
+31
View File
@@ -0,0 +1,31 @@
# Changelog
All notable changes to the **cloudflared** deployment are documented here.
cloudflared runs the [Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/) connector in the `networking` namespace, giving Cloudflare an outbound-only path into the cluster (no inbound ports opened). This repo owns raw Kubernetes manifests (a Deployment) under `manifest/base` plus a production overlay; Argo CD renders `manifest/overlays/production`.
Entries describe what actually changed in the running deployment. Dates are commit dates; newest first.
---
## 2026-08-12 — Scale down to 2 replicas
- **`2 replicas`:** Deployment replicas 3 → 2. Keeps HA (survives a node loss) at lower footprint.
## 2026-06-05 → 2026-06-06 — Glance dashboard tile
- **`glances` / `icon`:** added Glance annotations (`glance/id`, description, icon `di:cloudflared`, and a `glance/url` linking to the Cloudflare Zero Trust connectors page), grouped under `glance/parent: cloudflared`.
## 2026-06-01 — Pin the image + auto-sync toggle
- **`pin version`:** pinned the image from `cloudflare/cloudflared:latest` (`imagePullPolicy: Always`) to **`2026.5.2`** (`IfNotPresent`). Removes the risk of an unattended `latest` pull silently changing the running connector version.
- **`auto update toggle`:** dropped the `ksops` config-management plugin from the ApplicationSet (secret no longer rendered via ksops) and kept the `ignoreApplicationDifferences` on `/spec/syncPolicy` so auto-sync can be toggled in the Argo CD UI without showing drift.
## 2026-04-19 → 2026-05-11 — Initial rollout and secret-management churn
- **`Initial cloudflared gitops app`:** ApplicationSet `cloudflared` (namespace `networking`), rendering a Deployment of **3 replicas** of `cloudflare/cloudflared:latest`, running `tunnel --no-autoupdate --metrics 0.0.0.0:2000 run`, with readiness/liveness on `/ready:2000`, topology spread across hosts, and rolling updates (`maxSurge: 0`, `maxUnavailable: 1`). Tunnel token read from `Secret/cloudflared-secrets` key `tunnel_token`. Originally used a **SOPS/ksops** secret generator.
- **`Enable bootstrap on main`:** flipped `bootstrap/config.yaml` to `enabled: true` so Argo CD picks it up.
- **Secret management migration:** `Migrate secret to Sealed Secrets` (ksops generator → `sealed-secret.yaml`), then `remove secret from manifest` (commented the sealed-secret out — the tunnel token is now managed **out-of-band**, not created by the sync). *Operational caveat:* a fresh sync will not recreate `cloudflared-secrets`; it must exist in the cluster already.
- **Replica churn:** `shutdown` (3 → 1) then `return to 3 replicas` — briefly scaled to a single pod, then back to 3.
- **`enable toggle of autosync`:** added `ignoreApplicationDifferences` on `/spec/syncPolicy` and set `selfHeal: false` / `enabled: false` so sync can be paused from the UI.
- **README + badge:** added then removed a CI badge; rewrote the README to document the running deployment.
+23 -4
View File
@@ -1,7 +1,26 @@
# cloudflared
Kubernetes deployment source-of-truth repository for `cloudflared`.
GitOps source for the Cloudflare Tunnel connector in the `networking` namespace.
This repo manages the Cloudflare tunnel deployment in `networking` through an
Argo CD `ApplicationSet`, using a SOPS-encrypted tunnel token and a simple
kustomize overlay.
## Current deployment
- Bootstrap: `enabled: true`, applied from `main`
- Argo application: `cloudflared-production`
- Target namespace: `networking`
- Render path: `manifest/overlays/production`
- Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/cloudflared.git`
- Config management plugin: `ksops`
## Runtime
The base deploys three `cloudflare/cloudflared:latest` replicas with rolling
updates, topology spread, readiness/liveness checks on port `2000`, and
`cloudflared tunnel --no-autoupdate --metrics 0.0.0.0:2000 run`.
## Secrets
The tunnel token is read from `Secret/cloudflared-secrets`, key `tunnel_token`.
`manifest/overlays/production/sealed-secret.yaml` exists in the repo but is not
currently referenced by the production kustomization. Confirm whether the secret
is managed out-of-band or should be added to the overlay before relying on a new
sync to create it.
+3 -2
View File
@@ -4,6 +4,9 @@ metadata:
name: cloudflared
namespace: argocd
spec:
ignoreApplicationDifferences:
- jsonPointers:
- /spec/syncPolicy
goTemplate: true
goTemplateOptions:
- missingkey=error
@@ -28,8 +31,6 @@ spec:
repoURL: http://gitea-ha-http.apps:3000/olb42/cloudflared.git
targetRevision: main
path: '{{ .path }}'
plugin:
name: ksops
destination:
server: https://kubernetes.default.svc
namespace: '{{ .namespace }}'
+9 -3
View File
@@ -5,8 +5,13 @@ metadata:
namespace: networking
labels:
app: cloudflared
annotations:
glance/id: cloudflared
glance/description: "Clourflare Tunnels"
glance/icon: di:cloudflared
glance/url: https://dash.cloudflare.com/d1ecdad4f5c739647b0c123f0c97f57e/one/networks/connectors
spec:
replicas: 1
replicas: 2
selector:
matchLabels:
app: cloudflared
@@ -20,11 +25,12 @@ spec:
labels:
app: cloudflared
app.kubernetes.io/name: cloudflared
glance/parent: cloudflared
spec:
containers:
- name: cloudflared
image: cloudflare/cloudflared:latest
imagePullPolicy: Always
image: cloudflare/cloudflared:2026.5.2
imagePullPolicy: IfNotPresent
args:
- tunnel
- --no-autoupdate
@@ -5,4 +5,4 @@ namespace: networking
resources:
- ../../base
- sealed-secret.yaml
# - sealed-secret.yaml