diff --git a/.sops.yaml b/.sops.yaml index 0f279e74..e686f2b0 100644 --- a/.sops.yaml +++ b/.sops.yaml @@ -1,6 +1,6 @@ # Auto-generated by `just sops-rekey` from keys/*.pub. -# Every recipient can decrypt every secret. To add or remove a -# machine, add or remove its .pub file and re-run `just sops-rekey`. +# User and host keys decrypt legacy secrets/*.yaml. Flux keys decrypt +# only k8s/flux/secrets/*.sops.yaml. keys: # === user keys (aly@) === - &user_aly_eterna age1g79dfm0p44q5yxzhwd9syg965lupdu3n5lgyltdannmul5v5v5aszzz3gs @@ -26,8 +26,37 @@ keys: - &host_slateport age1ephzrpgftmvq4cul9766q2r3mss38xu6un74ryfmw0729afysghsh0a3qg - &host_snowpoint age1stsuakfyj3gkee4sm328ky2crmymyuzwjjmxrpvnm754sdt2zvnshf68jx - &host_sootopolis age1s7ecrfntus8rvyprzhffjpqk2tmrc259knf9xqajlrqvewfp8d6svwp9pp + # === flux keys === + - &flux_k8s age1yq47x0cyf95jg372v84ttptgnppsrfmxshsua6p58ecmgzxc5c0s5stfth creation_rules: + - path_regex: ^k8s/flux/secrets/.*\.sops\.ya?ml$ + key_groups: + - age: + - *user_aly_eterna + - *user_aly_fallarbor + - *user_aly_fortree + - *user_aly_jubilife + - *user_aly_pacifidlog + - *user_aly_petalburg + - *user_aly_rustboro + - *user_aly_slateport + - *user_aly_snowpoint + - *user_aly_sootopolis + - *host_celestic + - *host_eterna + - *host_fallarbor + - *host_fortree + - *host_jubilife + - *host_pacifidlog + - *host_pastoria + - *host_petalburg + - *host_rustboro + - *host_slateport + - *host_snowpoint + - *host_sootopolis + - *flux_k8s + - path_regex: ^secrets/.*\.ya?ml$ key_groups: - age: diff --git a/k8s/flux/infra-crds/cert-manager.yaml b/k8s/flux/infra-crds/cert-manager.yaml new file mode 100644 index 00000000..3a52ab15 --- /dev/null +++ b/k8s/flux/infra-crds/cert-manager.yaml @@ -0,0 +1,23 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: cert-manager + namespace: flux-system +spec: + interval: 15m + releaseName: cert-manager + targetNamespace: cert-manager + install: + createNamespace: true + chart: + spec: + chart: cert-manager + interval: 15m + sourceRef: + kind: HelmRepository + name: jetstack + namespace: flux-system + version: v1.20.3 + values: + crds: + enabled: true diff --git a/k8s/flux/infra-crds/cnpg.yaml b/k8s/flux/infra-crds/cnpg.yaml new file mode 100644 index 00000000..8c2a330a --- /dev/null +++ b/k8s/flux/infra-crds/cnpg.yaml @@ -0,0 +1,20 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: cnpg + namespace: flux-system +spec: + interval: 15m + releaseName: cnpg + targetNamespace: cnpg-system + install: + createNamespace: true + chart: + spec: + chart: cloudnative-pg + interval: 15m + sourceRef: + kind: HelmRepository + name: cnpg + namespace: flux-system + version: 0.29.0 diff --git a/k8s/flux/infra-crds/kustomization.yaml b/k8s/flux/infra-crds/kustomization.yaml index 3bfb0195..155e1cdb 100644 --- a/k8s/flux/infra-crds/kustomization.yaml +++ b/k8s/flux/infra-crds/kustomization.yaml @@ -1,4 +1,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - placeholder.yaml + - cert-manager.yaml + - cnpg.yaml diff --git a/k8s/flux/infra-crds/placeholder.yaml b/k8s/flux/infra-crds/placeholder.yaml deleted file mode 100644 index bc24592f..00000000 --- a/k8s/flux/infra-crds/placeholder.yaml +++ /dev/null @@ -1,9 +0,0 @@ -apiVersion: v1 -kind: ConfigMap -metadata: - name: flux-layer-infra-crds-placeholder - namespace: flux-system - labels: - cute.haus/flux-layer-placeholder: "true" -data: - note: Remove this placeholder when infra-crds has real resources. diff --git a/k8s/helmfile.yaml b/k8s/helmfile.yaml index 196d35a0..08e832c2 100644 --- a/k8s/helmfile.yaml +++ b/k8s/helmfile.yaml @@ -124,21 +124,6 @@ releases: ingress: enabled: false - - name: cnpg - namespace: cnpg-system - createNamespace: true - chart: cnpg/cloudnative-pg - version: 0.29.0 - - - name: cert-manager - namespace: cert-manager - createNamespace: true - chart: jetstack/cert-manager - version: v1.20.3 - values: - - crds: - enabled: true - - name: cert-manager-issuers namespace: cert-manager chart: ./charts/cert-manager-issuers diff --git a/keys/flux_k8s.pub b/keys/flux_k8s.pub new file mode 100644 index 00000000..fe372123 --- /dev/null +++ b/keys/flux_k8s.pub @@ -0,0 +1 @@ +age1yq47x0cyf95jg372v84ttptgnppsrfmxshsua6p58ecmgzxc5c0s5stfth