Tom Alexander
26b885c557
Add harbor secrets.
2026-05-02 15:54:31 -04:00
Tom Alexander
5e0ac767a6
Switch to the experimental gateway CRDs for TCPRoute support.
2026-05-02 15:54:31 -04:00
Tom Alexander
db56093582
Add oauth2 proxy secrets.
2026-05-02 15:54:30 -04:00
Tom Alexander
4bcb9d5f47
Add dex secrets.
2026-05-02 15:54:30 -04:00
Tom Alexander
145ff42a1f
Enable the firewall.
2026-05-02 15:54:30 -04:00
Tom Alexander
44ddc84237
Add gitea secrets.
2026-05-02 15:54:30 -04:00
Tom Alexander
eaf0c16c17
Add generation for in-repo secrets.
2026-05-02 15:54:30 -04:00
Tom Alexander
4abd80ac98
Enforce cilium network policies.
2026-05-02 15:54:30 -04:00
Tom Alexander
bd4e26dde5
Downgrade to gateway 1.4.1.
...
1.5 came out recently, so no gateway providers support it.
2026-05-02 15:54:30 -04:00
Tom Alexander
458b4afc9e
Update packages in kubernetes/keys.
2026-05-02 15:54:29 -04:00
Tom Alexander
10fe4329e6
Fix proxy auth tls
2026-05-02 15:54:29 -04:00
Tom Alexander
fd1ea9e890
Generate certificates for the aggregation layer.
2026-05-02 15:54:29 -04:00
Tom Alexander
d3e6cd08a5
Temporarily disable the firewall for debugging.
2026-05-02 15:54:29 -04:00
Tom Alexander
c888055876
Enable gateway support.
2026-05-02 15:54:28 -04:00
Tom Alexander
650f8d41a6
Enable hubble.
2026-05-02 15:54:28 -04:00
Tom Alexander
346d15a1fe
Temporarily drop flux interval to 1 minute during early development.
...
This is to reduce waiting time.
2026-05-02 15:54:28 -04:00
Tom Alexander
1133b5cbf2
Install deferred manifests.
2026-05-02 15:54:28 -04:00
Tom Alexander
0e959cb78f
Enable the firewall.
...
Now that we have networking working, I can enable the firewall and confirm nothing breaks.
2026-05-02 15:54:28 -04:00
Tom Alexander
758f21d454
Fix CoreDNS IPv4 connectivity.
2026-05-02 15:54:28 -04:00
Tom Alexander
a9baed129b
Increase timeout for coredns cache.
2026-05-02 15:54:27 -04:00
Tom Alexander
23cba83b96
More changes to try to fix coredns.
2026-05-02 15:54:27 -04:00
Tom Alexander
8ab03789fa
Move the kubelet yaml config into nix.
2026-05-02 15:54:27 -04:00
Tom Alexander
7c33c06ce0
Implement a generic helm templater package.
2026-05-02 15:54:27 -04:00
Tom Alexander
cdb332e7fd
Switch to generating the coredns manifests via nix.
2026-05-02 15:54:27 -04:00
Tom Alexander
6546edd82f
Use CoreDNS for in-cluster DNS requests and caching.
2026-05-02 15:54:27 -04:00
Tom Alexander
5c445da492
Enable native routing.
2026-05-02 15:54:27 -04:00
Tom Alexander
58a2061c08
Build the cilium manifest automatically in nix.
2026-05-02 15:54:26 -04:00
Tom Alexander
b504dc4d66
Allow pods to directly speak to the public internet on their own public IPv6 addresses.
2026-05-02 15:54:26 -04:00
Tom Alexander
d1c7a0bfca
Enable ipv4 and tunnel routing.
2026-05-02 15:54:26 -04:00
Tom Alexander
0b291d7648
Switch to kubernetes ipam mode.
2026-05-02 15:54:26 -04:00
Tom Alexander
8ae16e4bdf
Fix service cluster ip range.
...
Kubernetes only allows a /112 for service ip range.
2026-05-02 15:54:26 -04:00
Tom Alexander
cfb92eb156
Fix trailing line break in kubernetes encryption config.
2026-05-02 15:54:26 -04:00
Tom Alexander
2e2e64715a
Move the yaml functions to their own file.
2026-05-02 15:54:25 -04:00
Tom Alexander
8ff58c3c95
Introduce functions to generate yaml.
...
The toYAML function is just an alias to toJSON which is technically fine since YAML is a superset of JSON, but these new functions will generate actual YAML.
2026-05-02 15:54:25 -04:00
Tom Alexander
030f1c8504
Add missing cidr declarations.
2026-05-02 15:54:25 -04:00
Tom Alexander
1effb2830f
Fix DNS resolution.
2026-05-02 15:54:25 -04:00
Tom Alexander
641adf9dd3
Apply the git repo to the cluster.
2026-05-02 15:54:25 -04:00
Tom Alexander
2997fd43ea
Trust flux's ssh key in the yaml git repo.
2026-05-02 15:54:25 -04:00
Tom Alexander
063fcdbbab
Generic secrets for ssh keys.
2026-05-02 15:54:25 -04:00
Tom Alexander
71d9f5672a
Generic secrets for pgp keys.
2026-05-02 15:54:24 -04:00
Tom Alexander
7e3fa38af6
Generate kubernetes secrets for ssh keys.
2026-05-02 15:54:24 -04:00
Tom Alexander
3e13a3649a
Install CoreDNS.
2026-05-02 15:54:24 -04:00
Tom Alexander
651a97d126
Generate pgp keys for sops.
2026-05-02 15:54:24 -04:00
Tom Alexander
cd313e673b
Generate ssh keys for flux bootstrap.
2026-05-02 15:54:24 -04:00
Tom Alexander
cdac1cd091
Move the cluster bootstrap into the keys flake.
...
Bootstrapping the cluster needs access to secrets, so I am moving it into the keys flake.
2026-05-02 15:54:24 -04:00
Tom Alexander
3ccda1d4e5
Add kube-proxy.
2026-05-02 15:54:22 -04:00
Tom Alexander
27f4a78221
Add kubelet.
2026-05-02 15:54:22 -04:00
Tom Alexander
5c58e30709
Add kube-scheduler.
2026-05-02 15:54:22 -04:00
Tom Alexander
efa1e3247a
Add kube-controller-manager.
2026-05-02 15:54:22 -04:00
Tom Alexander
3e14efcceb
Fix launching kube-apiserver.
2026-05-02 15:54:21 -04:00