Consolidate bootstrapping steps, add cert-manager
This commit is contained in:
parent
3b85d6e85b
commit
ec5b2ab5f1
7 changed files with 127 additions and 17 deletions
6
Makefile
6
Makefile
|
|
@ -1,4 +1,4 @@
|
|||
.PHONY: init plan apply destroy kubeconfig talosconfig argocd-password bootstrap decrypt
|
||||
.PHONY: init plan apply destroy kubeconfig talosconfig argocd-password bootstrap decrypt post-apply
|
||||
|
||||
SECRET=dumpnet/cluster
|
||||
TF_DIR=terraform
|
||||
|
|
@ -56,3 +56,7 @@ decrypt:
|
|||
fi; \
|
||||
done
|
||||
@echo "Decrypted files are in /tmp/ - they will not persist after reboot"
|
||||
|
||||
# Run all post-apply steps (run once after fresh cluster creation)
|
||||
post-apply:
|
||||
scripts/post-apply.sh
|
||||
|
|
|
|||
28
README.md
28
README.md
|
|
@ -70,30 +70,25 @@ This will:
|
|||
- Create Route53 DNS records pointing to the EIP
|
||||
- Store all credentials in AWS Secrets Manager (`dumpnet/cluster`)
|
||||
|
||||
### 4. Configure local access
|
||||
### 4. Post-apply bootstrap (one-time)
|
||||
|
||||
```bash
|
||||
make kubeconfig # merges kubeconfig into ~/.kube/config
|
||||
make talosconfig # merges talosconfig into ~/.talos/config
|
||||
make post-apply
|
||||
```
|
||||
|
||||
These pull from Secrets Manager and are safe to run repeatedly.
|
||||
This script:
|
||||
- Fetches kubeconfig and talosconfig from Secrets Manager
|
||||
- Waits for the node to be ready
|
||||
- Imports the ingress-nginx namespace into Terraform state
|
||||
- Applies the ArgoCD App of Apps
|
||||
|
||||
### 5. Bootstrap ArgoCD App of Apps
|
||||
|
||||
```bash
|
||||
make bootstrap
|
||||
```
|
||||
|
||||
One-time step that hands control of all apps to ArgoCD. After this, everything in `manifests/` is managed automatically.
|
||||
|
||||
### 6. Get ArgoCD password
|
||||
### 5. Get ArgoCD password
|
||||
|
||||
```bash
|
||||
make argocd-password
|
||||
```
|
||||
|
||||
Then log in at https://argocd.dumpnet.chat
|
||||
Then log in at https://argocd.dumpnet.chat — ArgoCD will finish deploying ingress-nginx and metrics-server automatically.
|
||||
|
||||
## Day-to-Day
|
||||
|
||||
|
|
@ -109,7 +104,8 @@ Then log in at https://argocd.dumpnet.chat
|
|||
| `make apply` | Create/update cluster infrastructure |
|
||||
| `make plan` | Preview infrastructure changes |
|
||||
| `make destroy` | Tear down everything |
|
||||
| `make bootstrap` | Apply App of Apps (one-time) |
|
||||
| `make post-apply` | One-time bootstrap after fresh cluster creation |
|
||||
| `make bootstrap` | Apply App of Apps only |
|
||||
| `make kubeconfig` | Pull kubeconfig from Secrets Manager |
|
||||
| `make talosconfig` | Pull talosconfig from Secrets Manager |
|
||||
| `make argocd-password` | Print ArgoCD admin password |
|
||||
|
|
@ -120,6 +116,8 @@ Then log in at https://argocd.dumpnet.chat
|
|||
```
|
||||
dumpnet-argo/
|
||||
├── Makefile # top-level commands
|
||||
├── scripts/
|
||||
│ └── post-apply.sh # one-time bootstrap after fresh cluster
|
||||
├── apps/
|
||||
│ └── apps.yaml # ArgoCD App of Apps root
|
||||
├── manifests/ # ArgoCD Application manifests
|
||||
|
|
|
|||
|
|
@ -6,6 +6,8 @@ server:
|
|||
enabled: true
|
||||
ingressClassName: nginx
|
||||
hostname: argocd.dumpnet.chat
|
||||
tls: false
|
||||
tls: true
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||
extraArgs:
|
||||
- --insecure
|
||||
|
|
|
|||
29
charts/cert-manager/cluster-issuers.yaml
Normal file
29
charts/cert-manager/cluster-issuers.yaml
Normal file
|
|
@ -0,0 +1,29 @@
|
|||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: letsencrypt-prod
|
||||
spec:
|
||||
acme:
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
email: dumpnetcerts@keane.sh
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-prod
|
||||
solvers:
|
||||
- http01:
|
||||
ingress:
|
||||
ingressClassName: nginx
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: letsencrypt-staging
|
||||
spec:
|
||||
acme:
|
||||
server: https://acme-staging-v02.api.letsencrypt.org/directory
|
||||
email: dumpnetcerts@keane.sh
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-staging
|
||||
solvers:
|
||||
- http01:
|
||||
ingress:
|
||||
ingressClassName: nginx
|
||||
2
charts/cert-manager/values.yaml
Normal file
2
charts/cert-manager/values.yaml
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
crds:
|
||||
enabled: true
|
||||
49
manifests/cert-manager.yaml
Normal file
49
manifests/cert-manager.yaml
Normal file
|
|
@ -0,0 +1,49 @@
|
|||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: cert-manager
|
||||
namespace: argocd
|
||||
spec:
|
||||
project: default
|
||||
sources:
|
||||
- repoURL: https://forge.keane.sh/ian/dumpnet-argo.git
|
||||
targetRevision: HEAD
|
||||
ref: values
|
||||
- repoURL: https://charts.jetstack.io
|
||||
chart: cert-manager
|
||||
targetRevision: "*"
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/charts/cert-manager/values.yaml
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: cert-manager
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
---
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: cert-manager-issuers
|
||||
namespace: argocd
|
||||
spec:
|
||||
project: default
|
||||
source:
|
||||
repoURL: https://forge.keane.sh/ian/dumpnet-argo.git
|
||||
targetRevision: HEAD
|
||||
path: charts/cert-manager
|
||||
directory:
|
||||
include: "cluster-issuers.yaml"
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: cert-manager
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
26
scripts/post-apply.sh
Executable file
26
scripts/post-apply.sh
Executable file
|
|
@ -0,0 +1,26 @@
|
|||
#!/bin/sh
|
||||
# Post-apply bootstrap script
|
||||
# Run this once after 'make apply' completes on a fresh cluster
|
||||
|
||||
set -e
|
||||
|
||||
echo "==> Fetching kubeconfig..."
|
||||
make kubeconfig
|
||||
|
||||
echo "==> Fetching talosconfig..."
|
||||
make talosconfig
|
||||
|
||||
echo "==> Waiting for cluster to be ready..."
|
||||
kubectl wait --for=condition=Ready node --all --timeout=120s
|
||||
|
||||
echo "==> Importing ingress-nginx namespace into Terraform state (if needed)..."
|
||||
cd terraform
|
||||
terraform import kubernetes_namespace.ingress_nginx ingress-nginx 2>/dev/null || echo "Already in state, skipping"
|
||||
cd ..
|
||||
|
||||
echo "==> Bootstrapping ArgoCD App of Apps..."
|
||||
make bootstrap
|
||||
|
||||
echo ""
|
||||
echo "Done! ArgoCD should be available at https://argocd.dumpnet.chat shortly."
|
||||
echo "Get your password with: make argocd-password"
|
||||
Loading…
Add table
Add a link
Reference in a new issue