# cloudflared GitOps source for the Cloudflare Tunnel connector in the `networking` namespace. ## Current deployment - Bootstrap: `enabled: true`, applied from `main` - Argo application: `cloudflared-production` - Target namespace: `networking` - Render path: `manifest/overlays/production` - Repo URL used by Argo CD: `http://gitea-ha-http.apps:3000/olb42/cloudflared.git` - Config management plugin: `ksops` ## Runtime The base deploys three `cloudflare/cloudflared:latest` replicas with rolling updates, topology spread, readiness/liveness checks on port `2000`, and `cloudflared tunnel --no-autoupdate --metrics 0.0.0.0:2000 run`. ## Secrets The tunnel token is read from `Secret/cloudflared-secrets`, key `tunnel_token`. `manifest/overlays/production/sealed-secret.yaml` exists in the repo but is not currently referenced by the production kustomization. Confirm whether the secret is managed out-of-band or should be added to the overlay before relying on a new sync to create it.