Direct SSH access to the actual clusters (node1-3 "prod" HA, dev-k8s-1-3
"dev") revealed two things that made the previous design wrong:
1. Neither cluster has vncmail/vnc-ca namespaces or a bulwark ingress at
all - the "live sandbox" referenced in this repo's docs/manifests was
never actually applied anywhere. Both ingress.yaml's ingressClassName
(public) and cert-manager issuer (letsencrypt-prod) were also wrong:
both clusters run Traefik (class is literally named `traefik`), and
only dev-k8s has any ClusterIssuer at all (`letsencrypt-staging`).
node1-3 has zero ClusterIssuers configured.
2. dev-k8s already has ArgoCD installed, idle, zero Applications - more
idiomatic to use it than have GitLab Runner execute kubectl directly.
Pivots .gitlab-ci.yml: build+push image, then commit the tag into a small
per-overlay Component (overlays/{dev,prod}/image-tag/) that ArgoCD's
Application watches - CI never touches the cluster, only the registry and
this repo. dev's Application (vncmail-dev) is registered and applied
already (manual sync for now, until the one-time namespace secret
bootstrap is done - see VNCMAIL-SETUP.md). prod's Application is
scaffolded in deploy/argocd/ but deliberately not applied - it targets a
different cluster (node1-3) that isn't registered with ArgoCD yet, and
there's still no real prod hostname/Stalwart/ClusterIssuer.
Fixes base/ingress.yaml to the real ingressClassName: traefik (was the
nginx-style `public`, which doesn't exist on either cluster) and gives
each overlay its own cert-manager issuer patch instead of one hardcoded
value, since dev and prod need different (or, for prod, nonexistent)
issuers.
32 lines
1.1 KiB
YAML
32 lines
1.1 KiB
YAML
# PLACEHOLDER — the real production hostname has not been decided yet (see
|
|
# VNCMAIL-SETUP.md / the pipeline plan). vncmail.CHANGEME.invalid is
|
|
# deliberately unresolvable: applying this overlay as committed will not
|
|
# issue a cert or route traffic anywhere. Replace both occurrences below,
|
|
# and the matching TLS secretName, before Phase D (first real prod deploy).
|
|
#
|
|
# Targets node1-3 (the HA "prod" cluster). Deliberately does NOT override
|
|
# base's `cert-manager.io/cluster-issuer: CHANGEME` — node1-3 has ZERO
|
|
# ClusterIssuers configured today (confirmed via direct access). A human
|
|
# needs to create a real one there (ACME account, DNS-01 or HTTP-01 solver)
|
|
# before this can be anything but a placeholder.
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: Ingress
|
|
metadata:
|
|
name: vncmail-plus
|
|
spec:
|
|
tls:
|
|
- hosts:
|
|
- vncmail.CHANGEME.invalid
|
|
secretName: vncmail-plus-prod-tls
|
|
rules:
|
|
- host: vncmail.CHANGEME.invalid
|
|
http:
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: vncmail-plus
|
|
port:
|
|
number: 80
|