Files
Mukul SharmaandClaude Opus 5 fb7db5aee6 Point comments at paths that still exist after the homelab overrides were removed
References to helm-overrides/k8s-admin-prd-ase1 now either name the
homelab repo that still has that folder, or point at the GKE equivalent
under gke-toolshed-prd-usc1. Comments only; no rendered values change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fn2kUxyYNY4ApytbLiGWeY
2026-09-17 18:02:01 +05:30

71 lines
3.0 KiB
YAML

contour:
# GKE counterpart of the homelab's contour override (k8s-admin-prd-ase1,
# in the homelab devops-infra-helm-charts repo). Same official projectcontour chart (0.7.0, see helm-templates/contour), but
# exposed the opposite way.
#
# The homelab binds Envoy to node ports 80/443 with hostPort, because
# VMware bridging over Wi-Fi never made a LoadBalancer IP reachable
# (claude.md issue #6). None of that applies here: this is a real cloud
# load balancer on the reserved address, and it is the ONE inbound path
# into the cluster now that the nodes have no public IPs of their own.
contour:
replicaCount: 1
# Ingress objects across this cluster say `ingressClassName: contour`,
# so the class must be created under exactly that name. The chart's
# default is an empty string, which derives a name from the release.
ingressClass:
name: contour
create: true
default: true
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
memory: 192Mi
envoy:
# DaemonSet (the chart default): one Envoy per node, which pairs with
# externalTrafficPolicy: Local below — every node the load balancer can
# send to is running a proxy that can serve the request locally.
kind: daemonset
service:
type: LoadBalancer
# The reserved address from Terraform (module.network's
# google_compute_address). Every hostname in this deployment — the
# deployshed.com records, including the two wildcards — resolves here,
# so this pin is what makes DNS work at all: an unpinned Service takes
# a fresh ephemeral IP and every hostname points at nothing.
#
# More load-bearing now, not less, than when hostnames were
# <name>.35.238.248.203.nip.io. Those encoded the address, so a changed
# IP produced names that were merely wrong. Real DNS records point here
# until somebody edits them in Cloudflare, so a changed IP is an
# outage across every hostname at once.
#
# spec.loadBalancerIP is deprecated upstream (Kubernetes 1.24), and
# GKE's replacement is the annotation
# networking.gke.io/load-balancer-ip-addresses. That annotation is NOT
# a drop-in: it takes the address resource's NAME rather than the
# address, and on an external Service it also requires
# spec.loadBalancerClass: networking.gke.io/l4-regional-external,
# which changes which controller programs the load balancer. GKE still
# honours this field, so the deprecated-but-working one is the smaller
# change; revisit if a GKE upgrade ever stops honouring it.
loadBalancerIP: "35.238.248.203"
# Chart default, kept deliberately: preserves the real client IP
# instead of replacing it with a node's address. Valid here precisely
# because Envoy is a DaemonSet.
externalTrafficPolicy: Local
resources:
requests:
cpu: 50m
memory: 96Mi
limits:
memory: 256Mi