diff --git a/kubernetes/docs/nixidy.md b/kubernetes/docs/nixidy.md index da25948..19805ed 100644 --- a/kubernetes/docs/nixidy.md +++ b/kubernetes/docs/nixidy.md @@ -1,6 +1,18 @@ # Nixidy Integration Proposal -Status: proposal. Nixidy is not part of the deployment pipeline yet. +Status: in progress. Phases 1-3 are complete: Cilium is applied through Nixidy via +`just up-nixidy`, while Rook/Ceph and verification remain Ansible-managed. + +Progress notes (keep each fact here only once): + +- Phase 0-2 done previously: cluster stabilized, pinned `nixidy` flake input added, + Cilium values ported to `nixidy/cilium.nix` and render-compared against Helm output. +- Phase 3 done 2026-08-21: full `just up-nixidy` lifecycle passed end-to-end + (deploy -> wait -> import -> `kubeconfig` -> `scripts/nixidy-apply.sh` -> + Ansible `site.yml --skip-tags cilium` including `verify.yml`). All 4 nodes Ready + with Nixidy-applied Cilium. +- The `up-nixidy` lifecycle still runs Ansible for CoreDNS patching, Rook/Ceph, and + verification (`--skip-tags cilium`); those move in phases 4-6. [Nixidy](https://nixidy.dev/) could replace the imperative Kubernetes application deployment currently handled by Ansible while leaving the NixOS, QEMU, and OpenTofu @@ -80,6 +92,12 @@ checks have been tested independently. ## Open Issues +- Nixidy's generated apply script feeds a bare `---` into `kubectl apply -f -` for + classes with no objects; Cilium 1.20 renders zero CRDs, so the crds step exits 1 + with "no objects passed to apply". Worked around by + `scripts/nixidy-apply.sh`, which rewrites the generated script's absolute kubectl + path to a shim that skips document-less streams (a PATH shim is not enough — the + script hardcodes store paths). Revisit if upstream gains empty-class handling. - Nixidy does not replace offline image importing; rendered image references still need digest pinning and fixed archive hashes. - Argo CD would need a reachable Git repository or a locally mirrored repository, so it