Harbor, Gitea, Argo CD, Jenkins, Vault, Grafana and vmui now answer on their deployshed.com names alone. Each was already serving both while the move was proved out; this removes the nip.io half. The dual-hostname workarounds go with it. Jenkins' secondaryingress existed only because its chart's primary ingress takes one hostName and a certificate could not span both names — the real domain moves onto the primary with jenkins-tls, which it already holds. Argo CD gets extraTls rather than ingress.tls, because the boolean hardcodes secretName argocd-server-tls and would request a second certificate for a name that already has a valid one in argocd-deployshed-tls. Harbor also changes in two ways beyond the hostname: - externalURL moves to https://harbor.infra.deployshed.com. Harbor hands this to docker clients in its own API responses and builds the push commands shown in its UI from it, so a stale value is what makes a correctly-configured registry still advertise the old address. - updateStrategy is now Recreate. Its jobservice and registry volumes are standard-rwo (ReadWriteOnce), and a RollingUpdate starts the new pod before the old one releases the disk, so the replacement hangs forever on Multi-Attach. The cluster was sitting in exactly that state, old pods serving while new ones stayed in ContainerCreating. The chart's own comment on this value recommends Recreate when RWM is unavailable. The cost is a brief outage during upgrades, which beats a rollout that cannot complete. The private registry CA is not removed yet. Apps deployed before this move recorded nip.io image references that only change when each is rebuilt, so the old hostname stays served by a standalone Ingress until then. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
71 lines
2.9 KiB
YAML
71 lines
2.9 KiB
YAML
contour:
|
|
# GKE counterpart of helm-overrides/k8s-admin-prd-ase1/contour. Same
|
|
# official projectcontour chart (0.7.0, see helm-templates/contour), but
|
|
# exposed the opposite way.
|
|
#
|
|
# The homelab binds Envoy to node ports 80/443 with hostPort, because
|
|
# VMware bridging over Wi-Fi never made a LoadBalancer IP reachable
|
|
# (claude.md issue #6). None of that applies here: this is a real cloud
|
|
# load balancer on the reserved address, and it is the ONE inbound path
|
|
# into the cluster now that the nodes have no public IPs of their own.
|
|
|
|
contour:
|
|
replicaCount: 1
|
|
# Ingress objects across this cluster say `ingressClassName: contour`,
|
|
# so the class must be created under exactly that name. The chart's
|
|
# default is an empty string, which derives a name from the release.
|
|
ingressClass:
|
|
name: contour
|
|
create: true
|
|
default: true
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 64Mi
|
|
limits:
|
|
memory: 192Mi
|
|
|
|
envoy:
|
|
# DaemonSet (the chart default): one Envoy per node, which pairs with
|
|
# externalTrafficPolicy: Local below — every node the load balancer can
|
|
# send to is running a proxy that can serve the request locally.
|
|
kind: daemonset
|
|
|
|
service:
|
|
type: LoadBalancer
|
|
|
|
# The reserved address from Terraform (module.network's
|
|
# google_compute_address). Every hostname in this deployment — the
|
|
# deployshed.com records, including the two wildcards — resolves here,
|
|
# so this pin is what makes DNS work at all: an unpinned Service takes
|
|
# a fresh ephemeral IP and every hostname points at nothing.
|
|
#
|
|
# More load-bearing now, not less, than when hostnames were
|
|
# <name>.35.238.248.203.nip.io. Those encoded the address, so a changed
|
|
# IP produced names that were merely wrong. Real DNS records point here
|
|
# until somebody edits them in Cloudflare, so a changed IP is an
|
|
# outage across every hostname at once.
|
|
#
|
|
# spec.loadBalancerIP is deprecated upstream (Kubernetes 1.24), and
|
|
# GKE's replacement is the annotation
|
|
# networking.gke.io/load-balancer-ip-addresses. That annotation is NOT
|
|
# a drop-in: it takes the address resource's NAME rather than the
|
|
# address, and on an external Service it also requires
|
|
# spec.loadBalancerClass: networking.gke.io/l4-regional-external,
|
|
# which changes which controller programs the load balancer. GKE still
|
|
# honours this field, so the deprecated-but-working one is the smaller
|
|
# change; revisit if a GKE upgrade ever stops honouring it.
|
|
loadBalancerIP: "35.238.248.203"
|
|
|
|
# Chart default, kept deliberately: preserves the real client IP
|
|
# instead of replacing it with a node's address. Valid here precisely
|
|
# because Envoy is a DaemonSet.
|
|
externalTrafficPolicy: Local
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 96Mi
|
|
limits:
|
|
memory: 256Mi
|