Files
Homelabv4/infrastructure/istio/manifests/apps/namespace-enrollment-job.yaml
T
Scooby HuskyandClaude Opus 4.6 02632d06a4 Fix NetBird service annotations: use netbird.io/expose for operator
The operator watches for netbird.io/expose (presence-based), not
netbird.io/resource which was from the old Helmfile bootstrap script.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 16:25:35 -05:00

56 lines
3.1 KiB
YAML

apiVersion: batch/v1
kind: Job
metadata:
name: istio-mesh-app-enrollment
namespace: istio-system
annotations:
argocd.argoproj.io/hook: PostSync
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
argocd.argoproj.io/sync-wave: "1"
spec:
backoffLimit: 3
ttlSecondsAfterFinished: 300
template:
spec:
serviceAccountName: argocd-hook-sa
restartPolicy: Never
containers:
- name: enroll
image: alpine/k8s:1.32.13
command:
- /bin/bash
- -c
- |
set -euo pipefail
echo "=== Enrolling app namespaces in Istio ambient mesh ==="
# Enroll app namespaces in ambient mesh
APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole cattle-system)
for ns in "${APP_NAMESPACES[@]}"; do
echo "Enrolling $ns in ambient mesh..."
kubectl label namespace "$ns" istio.io/dataplane-mode=ambient --overwrite 2>/dev/null || true
kubectl label namespace "$ns" istio-injection- 2>/dev/null || true
done
# Attach waypoint proxies for L7 policy enforcement
echo "Attaching waypoint proxies to app namespaces..."
WAYPOINT_APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole)
for ns in "${WAYPOINT_APP_NAMESPACES[@]}"; do
kubectl label namespace "$ns" istio.io/use-waypoint=waypoint --overwrite 2>/dev/null || true
done
# Annotate services for NetBird operator auto-discovery (netbird.io/expose triggers the operator)
echo "Annotating services for NetBird operator exposure..."
kubectl annotate svc -n gitlab gitlab-webservice-default netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n grafana grafana netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n home-assistant home-assistant netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n guacamole guacamole netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n nextcloud nextcloud netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n argocd argocd-server netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n frigate frigate netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n teslamate teslamate netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n home-assistant esphome netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n prometheus kube-prometheus-stack-prometheus netbird.io/expose="true" --overwrite 2>/dev/null || true
kubectl annotate svc -n vault vault netbird.io/expose="true" --overwrite 2>/dev/null || true
echo "App namespace enrollment and NetBird annotations complete"