Files
cloudflared/CHANGELOG.md
T
olb042andClaude Opus 4.8 892f5d03b8
Validate manifests / validate (push) Failing after 4s
docs: add CHANGELOG.md documenting deployment history
Generated from a per-commit review of the actual file changes, describing
the real operational impact of each change on the running deployment.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-09-09 16:59:09 +01:00

3.0 KiB

Changelog

All notable changes to the cloudflared deployment are documented here.

cloudflared runs the Cloudflare Tunnel connector in the networking namespace, giving Cloudflare an outbound-only path into the cluster (no inbound ports opened). This repo owns raw Kubernetes manifests (a Deployment) under manifest/base plus a production overlay; Argo CD renders manifest/overlays/production.

Entries describe what actually changed in the running deployment. Dates are commit dates; newest first.


2026-08-12 — Scale down to 2 replicas

  • 2 replicas: Deployment replicas 3 → 2. Keeps HA (survives a node loss) at lower footprint.

2026-06-05 → 2026-06-06 — Glance dashboard tile

  • glances / icon: added Glance annotations (glance/id, description, icon di:cloudflared, and a glance/url linking to the Cloudflare Zero Trust connectors page), grouped under glance/parent: cloudflared.

2026-06-01 — Pin the image + auto-sync toggle

  • pin version: pinned the image from cloudflare/cloudflared:latest (imagePullPolicy: Always) to 2026.5.2 (IfNotPresent). Removes the risk of an unattended latest pull silently changing the running connector version.
  • auto update toggle: dropped the ksops config-management plugin from the ApplicationSet (secret no longer rendered via ksops) and kept the ignoreApplicationDifferences on /spec/syncPolicy so auto-sync can be toggled in the Argo CD UI without showing drift.

2026-04-19 → 2026-05-11 — Initial rollout and secret-management churn

  • Initial cloudflared gitops app: ApplicationSet cloudflared (namespace networking), rendering a Deployment of 3 replicas of cloudflare/cloudflared:latest, running tunnel --no-autoupdate --metrics 0.0.0.0:2000 run, with readiness/liveness on /ready:2000, topology spread across hosts, and rolling updates (maxSurge: 0, maxUnavailable: 1). Tunnel token read from Secret/cloudflared-secrets key tunnel_token. Originally used a SOPS/ksops secret generator.
  • Enable bootstrap on main: flipped bootstrap/config.yaml to enabled: true so Argo CD picks it up.
  • Secret management migration: Migrate secret to Sealed Secrets (ksops generator → sealed-secret.yaml), then remove secret from manifest (commented the sealed-secret out — the tunnel token is now managed out-of-band, not created by the sync). Operational caveat: a fresh sync will not recreate cloudflared-secrets; it must exist in the cluster already.
  • Replica churn: shutdown (3 → 1) then return to 3 replicas — briefly scaled to a single pod, then back to 3.
  • enable toggle of autosync: added ignoreApplicationDifferences on /spec/syncPolicy and set selfHeal: false / enabled: false so sync can be paused from the UI.
  • README + badge: added then removed a CI badge; rewrote the README to document the running deployment.