Commit Graph
7 Commits
Author SHA1 Message Date
Jeffrey 193b9db359 envoy-gateway: comment out netbox entries so the kustomization builds
My previous commit staged the whole kustomization file and swept in the
in-flight netbox lines, which I had said I would keep out. Those reference
infra/envoy-gateway/netbox/, which is untracked, so ArgoCD could not render
the app at all:

  kustomize build failed: accumulating resources from
  'netbox/netbox-certificate.yaml': no such file or directory

That left envoy-gateway-config unable to load target state, so the orphaned
listener cleanup never applied. The running gateways were unaffected.

Commenting the two entries keeps the work visible in place and makes it a
two line uncomment once infra/envoy-gateway/netbox/ is committed.
2026-08-26 20:18:44 +02:00
Jeffrey 304c8e71db envoy-gateway: comment out orphaned listeners and certificates
Ten Gateway listeners had zero attached routes. Eight of them are in this repo
and are removed here by commenting them out of the kustomization, which prunes
the listener and its cert-manager Certificate.

Deprecated, workloads already live in deprecated/:
  vaultwarden (vault.jsme.be), affine (affine.jsme.be)

Superseded by minio-aistor:
  resume-minio (resume-minio.jsme.be), resume-minioweb (resume-minioweb.jsme.be)

Written but never deployed, no namespace in the cluster:
  n8n (n8n.jsme.be), wikijs (wiki.jsme.be), ollama (ollama.jsme.be),
  openwebui (forge.jsme.be)

wiki.jsme.be was one of these on the PUBLIC gateway: a listener with a valid
certificate, no backend, and an allowedRoutes selector that would attach the
first HTTPRoute appearing in a matching namespace. Deploying Wiki.js later
expecting it to be internal would have published it.

Commented rather than deleted so redeploying an app is a two line uncomment.
The certificate and the gateway patch must be uncommented together.

Verified with kubectl kustomize: 45 listeners render, down from 53, with all
eight orphan hostnames gone and every live service still present.
2026-08-26 20:10:20 +02:00
Jeffrey 3451b755d4 envoy-gateway: enable CrowdSec ext_authz on the public gateway
Wires crowdsec/gateway-public-securitypolicy.yaml into the kustomization now
that LAPI, AppSec and the bouncer are all healthy and the envoy bouncer is
registered with LAPI.

Covers every listener on gateway-public rather than just one app, since EG
v1.3.2 rejects targetRefs.sectionName on SecurityPolicy. gateway-internal is a
separate Gateway and is untouched, so LAN access is unaffected. failOpen is
true, so a bouncer outage lets traffic through instead of denying it.
2026-08-26 17:31:19 +02:00
Jeffrey 17c84d2ba8 pelican: split wings into wings-mc and wings-ark domains 2026-08-16 21:09:00 +02:00
Jeffrey 571c5d5d0b Move Jenkins and ntfy to deprecated 2026-07-08 09:07:03 +02:00
Jeffrey be9bd3a227 Add Outline 2026-06-22 23:32:35 +02:00
Jeffrey c40577589d Split manifests into infra/ and applications/ 2026-06-21 12:23:20 +02:00