Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
892f5d03b8 | ||
|
|
a5b226b74c | ||
|
|
f82eba2f2e | ||
|
|
722426b5c8 | ||
|
|
6013157a6b | ||
|
|
014244246b | ||
|
|
808af0910c | ||
|
|
721bcdb2d2 | ||
|
|
1a0d542927 | ||
|
|
b87a779018 | ||
|
|
091ddf8203 | ||
|
|
d9ad49cdc6 | ||
|
|
e880713644 | ||
|
|
f712a4be21 | ||
|
|
128727d3a6 | ||
|
|
107d94bcdc |
@@ -1,7 +0,0 @@
|
||||
# Replace the age recipient below with the public key used by ArgoCD / ksops
|
||||
# in the target environment before storing real secrets in this repository.
|
||||
creation_rules:
|
||||
- path_regex: manifest/(overlays|components)/.*/.*\.enc\.yaml$
|
||||
age: age1s0gzgh8c00tgnkgxrqyz2nu0k56xvc9ev3jdenkmu90egux9xfmsxvvj43
|
||||
- path_regex: manifest/(overlays|components)/.*/secret\.secret\.yaml$
|
||||
age: age1s0gzgh8c00tgnkgxrqyz2nu0k56xvc9ev3jdenkmu90egux9xfmsxvvj43
|
||||
@@ -0,0 +1,31 @@
|
||||
# Changelog
|
||||
|
||||
All notable changes to the **cloudflared** deployment are documented here.
|
||||
|
||||
cloudflared runs the [Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/) connector in the `networking` namespace, giving Cloudflare an outbound-only path into the cluster (no inbound ports opened). This repo owns raw Kubernetes manifests (a Deployment) under `manifest/base` plus a production overlay; Argo CD renders `manifest/overlays/production`.
|
||||
|
||||
Entries describe what actually changed in the running deployment. Dates are commit dates; newest first.
|
||||
|
||||
---
|
||||
|
||||
## 2026-08-12 — Scale down to 2 replicas
|
||||
|
||||
- **`2 replicas`:** Deployment replicas 3 → 2. Keeps HA (survives a node loss) at lower footprint.
|
||||
|
||||
## 2026-06-05 → 2026-06-06 — Glance dashboard tile
|
||||
|
||||
- **`glances` / `icon`:** added Glance annotations (`glance/id`, description, icon `di:cloudflared`, and a `glance/url` linking to the Cloudflare Zero Trust connectors page), grouped under `glance/parent: cloudflared`.
|
||||
|
||||
## 2026-06-01 — Pin the image + auto-sync toggle
|
||||
|
||||
- **`pin version`:** pinned the image from `cloudflare/cloudflared:latest` (`imagePullPolicy: Always`) to **`2026.5.2`** (`IfNotPresent`). Removes the risk of an unattended `latest` pull silently changing the running connector version.
|
||||
- **`auto update toggle`:** dropped the `ksops` config-management plugin from the ApplicationSet (secret no longer rendered via ksops) and kept the `ignoreApplicationDifferences` on `/spec/syncPolicy` so auto-sync can be toggled in the Argo CD UI without showing drift.
|
||||
|
||||
## 2026-04-19 → 2026-05-11 — Initial rollout and secret-management churn
|
||||
|
||||
- **`Initial cloudflared gitops app`:** ApplicationSet `cloudflared` (namespace `networking`), rendering a Deployment of **3 replicas** of `cloudflare/cloudflared:latest`, running `tunnel --no-autoupdate --metrics 0.0.0.0:2000 run`, with readiness/liveness on `/ready:2000`, topology spread across hosts, and rolling updates (`maxSurge: 0`, `maxUnavailable: 1`). Tunnel token read from `Secret/cloudflared-secrets` key `tunnel_token`. Originally used a **SOPS/ksops** secret generator.
|
||||
- **`Enable bootstrap on main`:** flipped `bootstrap/config.yaml` to `enabled: true` so Argo CD picks it up.
|
||||
- **Secret management migration:** `Migrate secret to Sealed Secrets` (ksops generator → `sealed-secret.yaml`), then `remove secret from manifest` (commented the sealed-secret out — the tunnel token is now managed **out-of-band**, not created by the sync). *Operational caveat:* a fresh sync will not recreate `cloudflared-secrets`; it must exist in the cluster already.
|
||||
- **Replica churn:** `shutdown` (3 → 1) then `return to 3 replicas` — briefly scaled to a single pod, then back to 3.
|
||||
- **`enable toggle of autosync`:** added `ignoreApplicationDifferences` on `/spec/syncPolicy` and set `selfHeal: false` / `enabled: false` so sync can be paused from the UI.
|
||||
- **README + badge:** added then removed a CI badge; rewrote the README to document the running deployment.
|
||||
@@ -1,7 +1,26 @@
|
||||
# cloudflared
|
||||
|
||||
Kubernetes deployment source-of-truth repository for `cloudflared`.
|
||||
GitOps source for the Cloudflare Tunnel connector in the `networking` namespace.
|
||||
|
||||
This repo manages the Cloudflare tunnel deployment in `networking` through an
|
||||
Argo CD `ApplicationSet`, using a SOPS-encrypted tunnel token and a simple
|
||||
kustomize overlay.
|
||||
## Current deployment
|
||||
|
||||
- Bootstrap: `enabled: true`, applied from `main`
|
||||
- Argo application: `cloudflared-production`
|
||||
- Target namespace: `networking`
|
||||
- Render path: `manifest/overlays/production`
|
||||
- Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/cloudflared.git`
|
||||
- Config management plugin: `ksops`
|
||||
|
||||
## Runtime
|
||||
|
||||
The base deploys three `cloudflare/cloudflared:latest` replicas with rolling
|
||||
updates, topology spread, readiness/liveness checks on port `2000`, and
|
||||
`cloudflared tunnel --no-autoupdate --metrics 0.0.0.0:2000 run`.
|
||||
|
||||
## Secrets
|
||||
|
||||
The tunnel token is read from `Secret/cloudflared-secrets`, key `tunnel_token`.
|
||||
`manifest/overlays/production/sealed-secret.yaml` exists in the repo but is not
|
||||
currently referenced by the production kustomization. Confirm whether the secret
|
||||
is managed out-of-band or should be added to the overlay before relying on a new
|
||||
sync to create it.
|
||||
|
||||
@@ -4,9 +4,15 @@ metadata:
|
||||
name: cloudflared
|
||||
namespace: argocd
|
||||
spec:
|
||||
ignoreApplicationDifferences:
|
||||
- jsonPointers:
|
||||
- /spec/syncPolicy
|
||||
goTemplate: true
|
||||
goTemplateOptions:
|
||||
- missingkey=error
|
||||
ignoreApplicationDifferences:
|
||||
- jsonPointers:
|
||||
- /spec/syncPolicy
|
||||
generators:
|
||||
- list:
|
||||
elements:
|
||||
@@ -25,15 +31,14 @@ spec:
|
||||
repoURL: http://gitea-ha-http.apps:3000/olb42/cloudflared.git
|
||||
targetRevision: main
|
||||
path: '{{ .path }}'
|
||||
plugin:
|
||||
name: ksops
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: '{{ .namespace }}'
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
selfHeal: false
|
||||
enabled: false
|
||||
syncOptions:
|
||||
- CreateNamespace=false
|
||||
- ApplyOutOfSyncOnly=true
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
enabled: false
|
||||
enabled: true
|
||||
target_namespace: argocd
|
||||
apply_from_branch: main
|
||||
|
||||
@@ -5,8 +5,13 @@ metadata:
|
||||
namespace: networking
|
||||
labels:
|
||||
app: cloudflared
|
||||
annotations:
|
||||
glance/id: cloudflared
|
||||
glance/description: "Clourflare Tunnels"
|
||||
glance/icon: di:cloudflared
|
||||
glance/url: https://dash.cloudflare.com/d1ecdad4f5c739647b0c123f0c97f57e/one/networks/connectors
|
||||
spec:
|
||||
replicas: 3
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: cloudflared
|
||||
@@ -20,11 +25,12 @@ spec:
|
||||
labels:
|
||||
app: cloudflared
|
||||
app.kubernetes.io/name: cloudflared
|
||||
glance/parent: cloudflared
|
||||
spec:
|
||||
containers:
|
||||
- name: cloudflared
|
||||
image: cloudflare/cloudflared:latest
|
||||
imagePullPolicy: Always
|
||||
image: cloudflare/cloudflared:2026.5.2
|
||||
imagePullPolicy: IfNotPresent
|
||||
args:
|
||||
- tunnel
|
||||
- --no-autoupdate
|
||||
|
||||
@@ -5,6 +5,4 @@ namespace: networking
|
||||
|
||||
resources:
|
||||
- ../../base
|
||||
|
||||
generators:
|
||||
- secret-generator.yaml
|
||||
# - sealed-secret.yaml
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
---
|
||||
apiVersion: bitnami.com/v1alpha1
|
||||
kind: SealedSecret
|
||||
metadata:
|
||||
name: cloudflared-secrets
|
||||
namespace: networking
|
||||
spec:
|
||||
encryptedData:
|
||||
tunnel_token: AgACw5tgW4ijp9qJyAGykFfs2hW/PHp0naChLOJRpEZnHY6Zar6TYmlT6bYjXqkiVyzlNWjMMA7TtScpTGWPTe7+Lrt3aYYwvWfpVi1tNuPim4Bl2ymqgNZY4+HhuNkyD+P1at/8wuZnOhCJOIc4pw9BW5P5UdypZQCU4Xn65QHV0XjgL1Vscg8NQT3U+vVJYNzA+i6x3ttunuIF4O+W+lOmvk3ndR7C/GUju6rArNJyIZeT0EwQstVresMDxMP1ZWdRTytV9wKAh+0tJpBxHsbG4ZOcQl9NXilJJG+ruIqpIAz+KAb6ZL1S7E3NpIMRPmOMMBSbBPyNJWoB9LCRFR4FoFnnanncE+Y45/9RzTyWMy8sbKlmHWNGbiU75s2RLWW2e9LLQIHbhi3UFxb3u8MW7LER3ogRyOHktqz8mrYN5ndVrtDdqIl4iEspfXEKrCHnNIK0e8q060pongd7ArjxdtxLP741oFi8ImfVxdb9b7KTDaHxFKKS+OVexoPzcKHWMahi4383ZgvciehdR+W/a3UhZbtHFIr81/MP3DWI0r7iMKpN96Qavb7tQkVX1u88QcLFhiA85GeyBN5Tb+86B4moagn+qS5tKT+kOfZTmKKxM2qyVKNmh5Em8T/j8OxXC18iRvrvG3/PoJr1Iw/4bb+ekGtR8gyNWS22Sme695igvFIfrlIAGhxMXuuUXUhDCluOKpJnoo3/d2YI2wzSxW3H3kb7AZc+dt06EYd4dGJ5cyO08wub/h90DIp6VA4Ak9g64OfKyq3NEJ27pmUIsfeOsBX7opm9FKmnTNH8O9igVbELKIlkTvR5+hSW5bwrSPfG++eTiIaHG4sReIvC2Fn7aiw2mc+66M6CqmnziSug7mWzLJmSjFWhwI1y8mfw1GiT3jlv3e9Uy2qZlnxcbK0X4PR3vAmuGgs2sK2jAoJlejkJxr2q
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
sealedsecrets.bitnami.com/managed: "true"
|
||||
name: cloudflared-secrets
|
||||
namespace: networking
|
||||
type: Opaque
|
||||
@@ -1,10 +0,0 @@
|
||||
apiVersion: viaduct.ai/v1
|
||||
kind: ksops
|
||||
metadata:
|
||||
name: cloudflared-secret-generator
|
||||
annotations:
|
||||
config.kubernetes.io/function: |
|
||||
exec:
|
||||
path: ksops
|
||||
files:
|
||||
- ./secret.enc.yaml
|
||||
@@ -1,23 +0,0 @@
|
||||
apiVersion: ENC[AES256_GCM,data:XLg=,iv:e4bs1sbC0OsThQkSTutlJvxVt196+fBM4CrdEUmiV08=,tag:sE883HlgDXTimCmDF53ngQ==,type:str]
|
||||
kind: ENC[AES256_GCM,data:IbLbkzXn,iv:Pgec9rmS5dISb4r4o6ZpdZcVr+/LFdlsNN/57+pRsV4=,tag:+A/QpP4bxSCTahkQMs1XOg==,type:str]
|
||||
metadata:
|
||||
name: ENC[AES256_GCM,data:nCVkADeqfK/naglook1T1NBDGw==,iv:CmJETpKb8jva4+AjHPsEnFaCpZIkxvS5F2JQdxZHGX8=,tag:esZvv9CPBdx5WQvGqQKMOg==,type:str]
|
||||
namespace: ENC[AES256_GCM,data:WP1kOzlC7gAvSA==,iv:KRqRq2Vrii3DiwctvtRVMBr/dF/2WVbmMzHubRo9/CU=,tag:xA2WzI5TANfE6JqLyf4eEQ==,type:str]
|
||||
type: ENC[AES256_GCM,data:BzkXVeKq,iv:MDhXcSX42vHy3jzJqi1RLgQcALUaJY/svh4+0yOArpg=,tag:msRPAgzpLXLiJcc6yJWWmQ==,type:str]
|
||||
stringData:
|
||||
tunnel_token: ENC[AES256_GCM,data:iFHNtMOmF42bqa5QJrMeTPq05RAVHbSV1imJHQbuCnnRQEA31ywgo0zO9mmzaS7JfWG6CFVSgQpnZ5mLQR0dBAL3ymyeRMXCWg4DLCRpAQJIynB2CRb7nQY2tSC4bxdPY112hUIFPnivjW7w+aUcmauAlJG0SqVJQYIWz/htbkOA9SK+oIIcU+8aTmWNuh3IHoMXgq8q14/OQWp1wlkADTinXn4smc7HOWIsQ4eX1MMge3mtN6rwCw==,iv:Yz6u+Wa9p2rJ5U0hNa7hAH3wmmA+AbRYXCKurJDjatA=,tag:2cZvt5f2skLe3kf9ypPYJw==,type:str]
|
||||
sops:
|
||||
age:
|
||||
- recipient: age1s0gzgh8c00tgnkgxrqyz2nu0k56xvc9ev3jdenkmu90egux9xfmsxvvj43
|
||||
enc: |
|
||||
-----BEGIN AGE ENCRYPTED FILE-----
|
||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBNdU51OW9qWVJpQ3h1QjMr
|
||||
WmtLU2I4SjJMNG9jbDRoblZaNTlPV0lVZngwCkxNUmlEQlJ6Y0hyNW9KMTdSRmIv
|
||||
SnBMdkI3dm0vRzJ1YVVRSG0xYnN6VDQKLS0tIG04aFV4clFnUlRRTUgrSEZBQXlv
|
||||
MEIxQmV6SWp3MFhjOVRyVytXaFh6bDAKltn5GQY4OUkTn6dzY1V1dYdubzXtfWmW
|
||||
Z6IDAk0q/m1MJuFMz72M4nQzwFmgrD/MFMnb1utB9ZOBdSTU3F0aMw==
|
||||
-----END AGE ENCRYPTED FILE-----
|
||||
lastmodified: "2026-04-20T00:07:18Z"
|
||||
mac: ENC[AES256_GCM,data:aQX+mbLEDvKoHWdy6SqMuOhSg+NgZcrx2rC0rSeqjtXemvaL6zmZVO4DAVqFrNkNVwm6t37iy/0JAAdN3kY8EEdm/FVGrCctyuC4L7MLQyhQMaPuk5oKoX1/fKlq1iH8q0UZYO6tkE6hJJ/BdkpG4dwS9AWtPxW3l0hkZaEn6ag=,iv:P7c8eYDj4lDDAXjYpLhvvvKWxis/oA/vk9Q+lcuRkAo=,tag:m8zAyklSkziDz6Al5BwLEA==,type:str]
|
||||
unencrypted_suffix: _unencrypted
|
||||
version: 3.12.2
|
||||
Reference in New Issue
Block a user