feat(omni): the talosconfig resource carries the node IPs and is not a secret #3

Merged
beddari merged 2 commits from talosctl-owns-volumes into main 2026-09-19 20:31:19 +00:00
Owner

The two commits that landed on the branch after PR 2 merged: the talosconfig resource records the cluster node IPs (2026.09.19.3, needed because the workflow model validator accepts only data.latest, swamp-club Lab 2295), and its content is no longer marked sensitive (2026.09.19.4), since it names an identity and the proxy, not a key, and vaulting it rewrote the consuming repository vault on every run. Both versions are already published.

The two commits that landed on the branch after PR 2 merged: the talosconfig resource records the cluster node IPs (2026.09.19.3, needed because the workflow model validator accepts only data.latest, swamp-club Lab 2295), and its content is no longer marked sensitive (2026.09.19.4), since it names an identity and the proxy, not a key, and vaulting it rewrote the consuming repository vault on every run. Both versions are already published.
A talosctl model wired to an Omni cluster needs two things from Omni: the
minted talosconfig and the machines' addresses. Swamp's workflow-path model
validator accepts only data.latest() in a model definition (swamp-club Lab
2295), so a list built with data.findBySpec() or data.query() plus
filter/map fails the moment a workflow runs the model. The talosconfig
resource now also records nodes and hostnames from clustermachineidentity,
sorted by hostname, and the talosctl model reads both with data.latest().
2026.09.19.3.
Marked sensitive, the content was stored as a vault entry on every run,
which rewrites the whole SOPS-encrypted vault file in the consuming
repository and leaves a dirty checkout after each scheduled run. The
config names Omni's proxy and the service account's identity and is inert
without OMNI_SERVICE_ACCOUNT_KEY, which stays in the vault, so it is an
ordinary resource. 2026.09.19.4.
beddari deleted branch talosctl-owns-volumes 2026-09-19 20:31:19 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/swamp-extensions!3
No description provided.