Same chart (0.34.1) and same shape as the homelab — production mode, file storage, standalone, no HA, injector off — with one substantial difference: this Vault unseals itself. The homelab unseals with 3 of 5 Shamir keys after every restart, which was fine on an always-on VM. These nodes are spot and can be reclaimed at any hour, and a sealed Vault means every secret in the cluster is unavailable until someone notices. The trade is named rather than buried: unsealing now depends on GCP IAM rather than on people holding key shares. The seal stanza's values come from terraform output vault_seal, so Terraform and this file cannot disagree about which key is used, and no credential appears in either: the pod authenticates to KMS as its Workload Identity. That binding names exactly vault/vault, so serviceAccount.name is pinned and the GSA annotation set — miss either and Vault starts, fails to reach KMS, and stays sealed with an error that never mentions Workload Identity. Verified against the live project: the rendered seal block matches the existing key ring and key, which grant encrypt/decrypt to that service account and nothing else. Storage is 10Gi on standard-rwo. The homelab's 5Gi exists only because local-path cannot expand a bound volume; this class can. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
devops-infra-helm-charts
This branch (main) is part of the restructuring process for the gcp-devops-admin repository, aimed at organizing helmcharts of all infrastructure tools and their corresponding value files. The purpose of this repository is to centralize and manage these resources efficiently.
Directory Structure
helm-templates
This directory is intended for caching or forking helm charts locally. If there's a need to modify or customize any helm chart, it can be done here. Otherwise, the charts will be used directly from the provider.
helm-overrides
The helm-overrides folder stores custom values files for helm charts. These files can be used to override the default values provided by the helm charts, whether they are forked or used directly from the provider.
cluster_name
Each tool within the repository may have different values based on the specific clusters. This directory is used to manage configurations and values tailored to different clusters.
manifests
The manifests directory contains manifest files that need to be applied only once. Examples include service-to-service configurations, storage classes, and any other manifest-related files necessary for the operation of the infrastructure tools.
Additional Notes
Please ensure that all changes made to this branch align with the restructuring objectives and follow the best practices for managing helm charts and infrastructure-related configurations.
For any questions or concerns, please reach out to the designated repository maintainers.