References to helm-overrides/k8s-admin-prd-ase1 now either name the homelab repo that still has that folder, or point at the GKE equivalent under gke-toolshed-prd-usc1. Comments only; no rendered values change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Fn2kUxyYNY4ApytbLiGWeY
71 lines
3.0 KiB
YAML
71 lines
3.0 KiB
YAML
contour:
|
|
# GKE counterpart of the homelab's contour override (k8s-admin-prd-ase1,
|
|
# in the homelab devops-infra-helm-charts repo). Same official projectcontour chart (0.7.0, see helm-templates/contour), but
|
|
# exposed the opposite way.
|
|
#
|
|
# The homelab binds Envoy to node ports 80/443 with hostPort, because
|
|
# VMware bridging over Wi-Fi never made a LoadBalancer IP reachable
|
|
# (claude.md issue #6). None of that applies here: this is a real cloud
|
|
# load balancer on the reserved address, and it is the ONE inbound path
|
|
# into the cluster now that the nodes have no public IPs of their own.
|
|
|
|
contour:
|
|
replicaCount: 1
|
|
# Ingress objects across this cluster say `ingressClassName: contour`,
|
|
# so the class must be created under exactly that name. The chart's
|
|
# default is an empty string, which derives a name from the release.
|
|
ingressClass:
|
|
name: contour
|
|
create: true
|
|
default: true
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 64Mi
|
|
limits:
|
|
memory: 192Mi
|
|
|
|
envoy:
|
|
# DaemonSet (the chart default): one Envoy per node, which pairs with
|
|
# externalTrafficPolicy: Local below — every node the load balancer can
|
|
# send to is running a proxy that can serve the request locally.
|
|
kind: daemonset
|
|
|
|
service:
|
|
type: LoadBalancer
|
|
|
|
# The reserved address from Terraform (module.network's
|
|
# google_compute_address). Every hostname in this deployment — the
|
|
# deployshed.com records, including the two wildcards — resolves here,
|
|
# so this pin is what makes DNS work at all: an unpinned Service takes
|
|
# a fresh ephemeral IP and every hostname points at nothing.
|
|
#
|
|
# More load-bearing now, not less, than when hostnames were
|
|
# <name>.35.238.248.203.nip.io. Those encoded the address, so a changed
|
|
# IP produced names that were merely wrong. Real DNS records point here
|
|
# until somebody edits them in Cloudflare, so a changed IP is an
|
|
# outage across every hostname at once.
|
|
#
|
|
# spec.loadBalancerIP is deprecated upstream (Kubernetes 1.24), and
|
|
# GKE's replacement is the annotation
|
|
# networking.gke.io/load-balancer-ip-addresses. That annotation is NOT
|
|
# a drop-in: it takes the address resource's NAME rather than the
|
|
# address, and on an external Service it also requires
|
|
# spec.loadBalancerClass: networking.gke.io/l4-regional-external,
|
|
# which changes which controller programs the load balancer. GKE still
|
|
# honours this field, so the deprecated-but-working one is the smaller
|
|
# change; revisit if a GKE upgrade ever stops honouring it.
|
|
loadBalancerIP: "35.238.248.203"
|
|
|
|
# Chart default, kept deliberately: preserves the real client IP
|
|
# instead of replacing it with a node's address. Valid here precisely
|
|
# because Envoy is a DaemonSet.
|
|
externalTrafficPolicy: Local
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 96Mi
|
|
limits:
|
|
memory: 256Mi
|