- talos/: generated base config (gitignored) + patches for control-plane scheduling, unprivileged ports and the ingress firewall - kubernetes/: sish base and cirrus-dev overlay, applied with kubectl - READMEs incl. production rollout plan Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
24 lines
901 B
YAML
24 lines
901 B
YAML
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
namespace: sish
|
|
resources:
|
|
- ../base/sish
|
|
configMapGenerator:
|
|
- name: sish-env
|
|
literals:
|
|
# .test is a reserved TLD: fine for dev, replace with real domains on the edge.
|
|
- SISH_DOMAIN=tunnel.cirrus.test
|
|
# Parents a connector may bind under (exact match on everything after the first label).
|
|
# "sto" allows cirrus.sto itself (and any <name>.sto); "cirrus.sto" allows <name>.cirrus.sto
|
|
- SISH_BIND_HOSTS=cirrus.test,apps.cirrus.test,sto,cirrus.sto
|
|
- name: sish-pubkeys
|
|
files:
|
|
- pubkeys/connector-dev.pub
|
|
- pubkeys/connector-hello.pub
|
|
secretGenerator:
|
|
# Edge SSH host key (connectors pin its public half). Kept only locally in
|
|
# .secrets/ (gitignored), so back it up outside this folder.
|
|
- name: sish-hostkey
|
|
files:
|
|
- ssh_host_ed25519_key=.secrets/ssh_host_ed25519_key
|