Ports the rest of the homelab's stack: external-secrets, harbor, jenkins, postgresql, redis, victoria-metrics-single, vmagent, node-exporter and grafana. All nine verified with helm template. Most are the homelab's values with storage moved from local-path to standard-rwo and hostnames rebuilt on the reserved ingress IP. vmagent and node-exporter are unchanged outright — everything in them is addressed by cluster DNS, namespace or container port, none of which differs here. Harbor is the substantial one. The homelab serves it over plain HTTP and makes containerd accept that by hand-editing hosts.toml on the node; GKE nodes are managed and replaced, so that edit cannot survive. Instead the node pool was told at creation to trust a private CA for exactly this hostname, and cert-manager now signs Harbor's certificate from that same CA via an ingress-shim annotation. certSource is "secret" rather than the chart's "auto", which would self-sign a certificate nothing trusts. externalURL moves to https to match, since Harbor hands that URL to docker clients and a mismatch surfaces as registry errors. Jenkins drops secondaryingress, which exists in the homelab only to serve its Tailscale hostname. Its plugin pins are carried over deliberately: each fixes a failure whose symptom points somewhere else, above all the kubernetes/kubernetes-client-api pairing, without which agents never come online and builds hang at "Still waiting to schedule task". Postgres and Redis keep the homelab's deliberately small memory settings. Those were chosen for an 8GB node under pressure, and while this cluster has room, a bigger cache buys nothing for a handful of small tools. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
43 lines
1.3 KiB
YAML
43 lines
1.3 KiB
YAML
external-secrets:
|
|
# Same as the homelab's, which carries nothing cluster-specific: the
|
|
# controller is configured entirely by the ClusterSecretStore and
|
|
# ExternalSecret objects in devops-infra-argo-config-gcp, not by values.
|
|
#
|
|
# This is the piece every credential in the cluster hangs off — Harbor,
|
|
# Jenkins, Grafana and the pipeline all read their secrets from Vault
|
|
# through it, so it comes up before any of them.
|
|
#
|
|
# Two things must exist in Vault before the first ExternalSecret can sync,
|
|
# and neither is declarative: the KV v2 engine at secret/, and the
|
|
# Kubernetes auth method with a role bound to this controller's service
|
|
# account. Until then ExternalSecrets stay in a retry loop rather than
|
|
# failing outright.
|
|
#
|
|
# installCRDs defaults to true — kept, as on a fresh cluster there are no
|
|
# existing SecretStore/ExternalSecret CRs whose schema it could clobber.
|
|
#
|
|
# All three components default to unbounded resources; trimmed here for
|
|
# the same reason as everything else in this repo.
|
|
resources:
|
|
requests:
|
|
cpu: 25m
|
|
memory: 32Mi
|
|
limits:
|
|
memory: 128Mi
|
|
|
|
webhook:
|
|
resources:
|
|
requests:
|
|
cpu: 25m
|
|
memory: 32Mi
|
|
limits:
|
|
memory: 64Mi
|
|
|
|
certController:
|
|
resources:
|
|
requests:
|
|
cpu: 25m
|
|
memory: 32Mi
|
|
limits:
|
|
memory: 64Mi
|