mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-21 05:26:49 +00:00
The operator watches for netbird.io/expose (presence-based), not netbird.io/resource which was from the old Helmfile bootstrap script. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
56 lines
3.1 KiB
YAML
56 lines
3.1 KiB
YAML
apiVersion: batch/v1
|
|
kind: Job
|
|
metadata:
|
|
name: istio-mesh-app-enrollment
|
|
namespace: istio-system
|
|
annotations:
|
|
argocd.argoproj.io/hook: PostSync
|
|
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
|
|
argocd.argoproj.io/sync-wave: "1"
|
|
spec:
|
|
backoffLimit: 3
|
|
ttlSecondsAfterFinished: 300
|
|
template:
|
|
spec:
|
|
serviceAccountName: argocd-hook-sa
|
|
restartPolicy: Never
|
|
containers:
|
|
- name: enroll
|
|
image: alpine/k8s:1.32.13
|
|
command:
|
|
- /bin/bash
|
|
- -c
|
|
- |
|
|
set -euo pipefail
|
|
echo "=== Enrolling app namespaces in Istio ambient mesh ==="
|
|
|
|
# Enroll app namespaces in ambient mesh
|
|
APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole cattle-system)
|
|
for ns in "${APP_NAMESPACES[@]}"; do
|
|
echo "Enrolling $ns in ambient mesh..."
|
|
kubectl label namespace "$ns" istio.io/dataplane-mode=ambient --overwrite 2>/dev/null || true
|
|
kubectl label namespace "$ns" istio-injection- 2>/dev/null || true
|
|
done
|
|
|
|
# Attach waypoint proxies for L7 policy enforcement
|
|
echo "Attaching waypoint proxies to app namespaces..."
|
|
WAYPOINT_APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole)
|
|
for ns in "${WAYPOINT_APP_NAMESPACES[@]}"; do
|
|
kubectl label namespace "$ns" istio.io/use-waypoint=waypoint --overwrite 2>/dev/null || true
|
|
done
|
|
|
|
# Annotate services for NetBird operator auto-discovery (netbird.io/expose triggers the operator)
|
|
echo "Annotating services for NetBird operator exposure..."
|
|
kubectl annotate svc -n gitlab gitlab-webservice-default netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n grafana grafana netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n home-assistant home-assistant netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n guacamole guacamole netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n nextcloud nextcloud netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n argocd argocd-server netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n frigate frigate netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n teslamate teslamate netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n home-assistant esphome netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n prometheus kube-prometheus-stack-prometheus netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
kubectl annotate svc -n vault vault netbird.io/expose="true" --overwrite 2>/dev/null || true
|
|
echo "App namespace enrollment and NetBird annotations complete"
|