docs: the forge is Flux's source; portable cluster and vault definitions #3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "cluster-access"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Outcome
The README states the delivery truth as it now is: git.dataverket.org is the source of record and Flux reads it directly. The factory has two identities on the cluster, read-only for itself and admin for setup, and nothing committed names a home directory, so the definitions work for every developer.
What changed
dataverket-prodreads the forge sinceed79b27. Lesson recorded:flux bootstrapowns fields on the liveGitRepositorythrough server-side apply, so removingsecretRefin git alone did nothing until the live object was patched.runner-podsonfabrikk-readers, the newdataverket-prod-rbacondataverket-prod-admin. Contexts come from the developer's default kubeconfig, whereomnictl kubeconfigmerges by default. The admin model is named after the cluster because that identity is cluster-wide.fabrikkvault readsvaults/fabrikk.enc.jsonrelative to the repo root and leavesageKeyFileempty, so sops uses the host's default keys file, which holds the factory identity.Protected paths
Touches
models/,vaults/,README.md. No factory run behind this PR.Test plan
KUBECONFIGset:swamp model method run runner-pods listshows the runner pod;swamp model method run dataverket-prod-rbac listRoleBindingsrecords thefabrikk-readersbindingswamp vault list-keys fabrikklists both keys;swamp model method run forgejo healthgreen through the vaultflux get sources git -n flux-systemshows the forge URL, ready, ated79b27docs: the forge is Flux's source; two kubeconfig contexts for the clusterto docs: the forge is Flux's source; portable cluster and vault definitions