apiVersion: batch/v1 kind: Job metadata: name: istio-mesh-app-enrollment namespace: istio-system annotations: argocd.argoproj.io/hook: PostSync argocd.argoproj.io/hook-delete-policy: BeforeHookCreation argocd.argoproj.io/sync-wave: "1" spec: backoffLimit: 3 ttlSecondsAfterFinished: 300 template: spec: serviceAccountName: argocd-hook-sa restartPolicy: Never containers: - name: enroll image: alpine/k8s:1.32.13 command: - /bin/bash - -c - | set -euo pipefail echo "=== Enrolling app namespaces in Istio ambient mesh ===" # Enroll app namespaces in ambient mesh APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole cattle-system) for ns in "${APP_NAMESPACES[@]}"; do echo "Enrolling $ns in ambient mesh..." kubectl label namespace "$ns" istio.io/dataplane-mode=ambient --overwrite 2>/dev/null || true kubectl label namespace "$ns" istio-injection- 2>/dev/null || true done # Attach waypoint proxies for L7 policy enforcement. # argocd excluded: its only AuthorizationPolicy (allow-argocd-access) # is a plain source-namespace/IP match with no L7 rules - it's # enforced directly by ztunnel (see its status: "attached to # ztunnel", not waypoint). Forcing waypoint L7 processing onto the # namespace anyway broke argocd-redis: waypoint doesn't handle # Redis's long-lived RESP protocol well, causing ~10s hang-then- # close on every connection (i/o timeout errors in argocd-server, # cluster info/session caching failing, new Applications from git # never getting picked up). ztunnel's plain mTLS still fully # covers argocd's actual security requirement here. echo "Attaching waypoint proxies to app namespaces..." WAYPOINT_APP_NAMESPACES=(gitlab n8n nextcloud teslamate home-assistant frigate guacamole) for ns in "${WAYPOINT_APP_NAMESPACES[@]}"; do kubectl label namespace "$ns" istio.io/use-waypoint=waypoint --overwrite 2>/dev/null || true done kubectl label namespace argocd istio.io/use-waypoint- 2>/dev/null || true # Annotate services for NetBird operator auto-discovery (netbird.io/expose triggers the operator) echo "Annotating services for NetBird operator exposure..." kubectl annotate svc -n gitlab gitlab-webservice-default netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n grafana grafana netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n home-assistant home-assistant netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n guacamole guacamole netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n nextcloud nextcloud netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n argocd argocd-server netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n frigate frigate netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n teslamate teslamate netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n home-assistant esphome netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n prometheus kube-prometheus-stack-prometheus netbird.io/expose="true" --overwrite 2>/dev/null || true kubectl annotate svc -n vault vault netbird.io/expose="true" --overwrite 2>/dev/null || true echo "App namespace enrollment and NetBird annotations complete"