Merge pull request 'Toolshed redis and domain rbac' (#1) from toolshed-redis-and-domain-rbac into main
Reviewed-on: http://gitea.100.90.248.118.nip.io/mukul/devops-infra-argo-config/pulls/1
This commit is contained in:
@@ -85,3 +85,47 @@ roleRef:
|
|||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: toolshed-deployer
|
name: toolshed-deployer
|
||||||
|
---
|
||||||
|
# A custom domain's Ingress and TLS secret live in the gateway's own
|
||||||
|
# namespace (toolshed, same as above) — never an app's namespace. Scoped
|
||||||
|
# with a namespaced Role/RoleBinding rather than widening the ClusterRole
|
||||||
|
# above: Ingress management here only ever targets this one fixed
|
||||||
|
# namespace, unlike the per-app namespaces the ClusterRole necessarily
|
||||||
|
# spans. Added alongside toolshed's custom-domains feature — see
|
||||||
|
# internal/deploy.Client.EnsureDomainIngress/DomainCertReady/
|
||||||
|
# RemoveDomainIngress and this file's own header comment about keeping it
|
||||||
|
# and deploy/helm/toolshed/templates/rbac.yaml in sync.
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: toolshed-deployer-ingress
|
||||||
|
namespace: toolshed
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/part-of: toolshed
|
||||||
|
rules:
|
||||||
|
- apiGroups: ["networking.k8s.io"]
|
||||||
|
resources: ["ingresses"]
|
||||||
|
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
|
||||||
|
# Reads the TLS secret cert-manager's ingress-shim populates for a domain
|
||||||
|
# Ingress, and deletes it (and the Ingress above) when a domain is
|
||||||
|
# removed. Never create/update — cert-manager, not deployer, writes this
|
||||||
|
# secret.
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["secrets"]
|
||||||
|
verbs: ["get", "list", "watch", "delete"]
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: toolshed-deployer-ingress
|
||||||
|
namespace: toolshed
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/part-of: toolshed
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: toolshed-deployer
|
||||||
|
namespace: toolshed
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: toolshed-deployer-ingress
|
||||||
|
|||||||
@@ -0,0 +1,54 @@
|
|||||||
|
# Redis admin password, backing toolshed's managed cache add-on.
|
||||||
|
#
|
||||||
|
# Only one consumer, unlike the Postgres credential next door: the Redis
|
||||||
|
# server itself needs it to seed its ACL file on first boot. toolshed's api
|
||||||
|
# reads it from the *connection* an operator configures in the dashboard
|
||||||
|
# (encrypted in toolshed's own database via the secretbox keyring), not from
|
||||||
|
# a Kubernetes Secret — so there is deliberately no second ExternalSecret
|
||||||
|
# into the toolshed namespace here.
|
||||||
|
#
|
||||||
|
# Put the credential in Vault BEFORE syncing this. External Secrets cannot
|
||||||
|
# create a Secret for a path that does not exist, and the Redis pod's init
|
||||||
|
# container will sit in CreateContainerConfigError until it can:
|
||||||
|
#
|
||||||
|
# kubectl -n vault exec -i vault-0 -- sh -lc '
|
||||||
|
# vault login <root-token> >/dev/null &&
|
||||||
|
# vault kv put secret/toolshed/redis \
|
||||||
|
# password=<a long alphanumeric password>'
|
||||||
|
#
|
||||||
|
# Use an alphanumeric password. It is written into the ACL file as
|
||||||
|
# `user default on ><password> ...` by the init container, where a space or
|
||||||
|
# a quote would split the directive and produce a server that either fails
|
||||||
|
# to start or, worse, starts with different rules than intended.
|
||||||
|
#
|
||||||
|
# Remember that `kubectl exec` into Vault is unauthenticated by default —
|
||||||
|
# without the `vault login` the commands fail with a "preflight capability
|
||||||
|
# check" error that reads like a permissions bug rather than a missing
|
||||||
|
# login.
|
||||||
|
#
|
||||||
|
# Rotating this password later does NOT propagate to a running server: the
|
||||||
|
# init container only ever writes the ACL file when it is absent, precisely
|
||||||
|
# so it cannot delete the per-app users toolshed has provisioned into it.
|
||||||
|
# To rotate, update Vault and then, against the running server:
|
||||||
|
#
|
||||||
|
# ACL SETUSER default >newpassword
|
||||||
|
# ACL SAVE
|
||||||
|
---
|
||||||
|
apiVersion: external-secrets.io/v1
|
||||||
|
kind: ExternalSecret
|
||||||
|
metadata:
|
||||||
|
name: redis-credentials
|
||||||
|
namespace: redis
|
||||||
|
spec:
|
||||||
|
refreshInterval: 1h
|
||||||
|
secretStoreRef:
|
||||||
|
name: vault-backend
|
||||||
|
kind: ClusterSecretStore
|
||||||
|
target:
|
||||||
|
name: redis-credentials
|
||||||
|
creationPolicy: Owner
|
||||||
|
data:
|
||||||
|
- secretKey: password
|
||||||
|
remoteRef:
|
||||||
|
key: toolshed/redis
|
||||||
|
property: password
|
||||||
@@ -132,6 +132,27 @@ appSpec:
|
|||||||
namespace: postgres
|
namespace: postgres
|
||||||
chartDir: postgresql
|
chartDir: postgresql
|
||||||
valuesDir: postgresql
|
valuesDir: postgresql
|
||||||
|
- name: redis
|
||||||
|
# Backs toolshed's managed cache add-on — toolshed provisions a per-app
|
||||||
|
# ACL user, scoped to its own key prefix, on request. Own namespace for
|
||||||
|
# the same reason postgresql has one: addressed over cluster DNS like
|
||||||
|
# any other platform component, outliving whatever consumes it:
|
||||||
|
# redis.redis.svc.cluster.local:6379
|
||||||
|
#
|
||||||
|
# Hand-written chart, not Bitnami's, for the same reason as postgresql
|
||||||
|
# (infra issue #4) — Redis ships no official chart either.
|
||||||
|
#
|
||||||
|
# Authentication is defined by an ACL file with no requirepass, which
|
||||||
|
# is a security property rather than a preference: see the chart's own
|
||||||
|
# values.yaml, where getting it wrong leaves the server open to
|
||||||
|
# unauthenticated access after its first restart.
|
||||||
|
#
|
||||||
|
# Requires secretstores/toolshed-redis-credentials.yaml to have synced
|
||||||
|
# first — the init container cannot seed the ACL file without it.
|
||||||
|
nameOverride: redis
|
||||||
|
namespace: redis
|
||||||
|
chartDir: redis
|
||||||
|
valuesDir: redis
|
||||||
- name: victoria-metrics-single
|
- name: victoria-metrics-single
|
||||||
# Replaces the Prometheus server this entry briefly was (see git
|
# Replaces the Prometheus server this entry briefly was (see git
|
||||||
# history on this file) — same job, lower RAM/disk footprint for the
|
# history on this file) — same job, lower RAM/disk footprint for the
|
||||||
|
|||||||
Reference in New Issue
Block a user