Validate manifests / validate (push) Failing after 4s
Generated from a per-commit review of the actual file changes, describing the real operational impact of each change on the running deployment. Co-Authored-By: Claude Opus 4.8 <[email protected]>
3.0 KiB
3.0 KiB
Changelog
All notable changes to the cloudflared deployment are documented here.
cloudflared runs the Cloudflare Tunnel connector in the networking namespace, giving Cloudflare an outbound-only path into the cluster (no inbound ports opened). This repo owns raw Kubernetes manifests (a Deployment) under manifest/base plus a production overlay; Argo CD renders manifest/overlays/production.
Entries describe what actually changed in the running deployment. Dates are commit dates; newest first.
2026-08-12 — Scale down to 2 replicas
2 replicas: Deployment replicas 3 → 2. Keeps HA (survives a node loss) at lower footprint.
2026-06-05 → 2026-06-06 — Glance dashboard tile
glances/icon: added Glance annotations (glance/id, description, icondi:cloudflared, and aglance/urllinking to the Cloudflare Zero Trust connectors page), grouped underglance/parent: cloudflared.
2026-06-01 — Pin the image + auto-sync toggle
pin version: pinned the image fromcloudflare/cloudflared:latest(imagePullPolicy: Always) to2026.5.2(IfNotPresent). Removes the risk of an unattendedlatestpull silently changing the running connector version.auto update toggle: dropped theksopsconfig-management plugin from the ApplicationSet (secret no longer rendered via ksops) and kept theignoreApplicationDifferenceson/spec/syncPolicyso auto-sync can be toggled in the Argo CD UI without showing drift.
2026-04-19 → 2026-05-11 — Initial rollout and secret-management churn
Initial cloudflared gitops app: ApplicationSetcloudflared(namespacenetworking), rendering a Deployment of 3 replicas ofcloudflare/cloudflared:latest, runningtunnel --no-autoupdate --metrics 0.0.0.0:2000 run, with readiness/liveness on/ready:2000, topology spread across hosts, and rolling updates (maxSurge: 0,maxUnavailable: 1). Tunnel token read fromSecret/cloudflared-secretskeytunnel_token. Originally used a SOPS/ksops secret generator.Enable bootstrap on main: flippedbootstrap/config.yamltoenabled: trueso Argo CD picks it up.- Secret management migration:
Migrate secret to Sealed Secrets(ksops generator →sealed-secret.yaml), thenremove secret from manifest(commented the sealed-secret out — the tunnel token is now managed out-of-band, not created by the sync). Operational caveat: a fresh sync will not recreatecloudflared-secrets; it must exist in the cluster already. - Replica churn:
shutdown(3 → 1) thenreturn to 3 replicas— briefly scaled to a single pod, then back to 3. enable toggle of autosync: addedignoreApplicationDifferenceson/spec/syncPolicyand setselfHeal: false/enabled: falseso sync can be paused from the UI.- README + badge: added then removed a CI badge; rewrote the README to document the running deployment.