refactor: remove terraform entirely, migrate to pure GitOps (ArgoCD)
Delete entire terraform/ directory. Architecture: Terraform + ArgoCD → ArgoCD only - Single tool: ArgoCD manages all infrastructure and applications - Source of truth: git only (k8s/ directory) - Continuous reconciliation: no manual apply needed - Simpler state: no tfstate backend, no state files Next: Migrate all Terraform resources to k8s/ YAML manifests and ArgoCD Applications (namespaces, storage classes, Helm releases, RBAC, network policies, Authentik config).
This commit is contained in:
Generated
-128
@@ -1,128 +0,0 @@
|
||||
# This file is maintained automatically by "terraform init".
|
||||
# Manual edits may be lost in future updates.
|
||||
|
||||
provider "registry.terraform.io/goauthentik/authentik" {
|
||||
version = "2024.12.1"
|
||||
constraints = "~> 2024.6"
|
||||
hashes = [
|
||||
"h1:jpWLnotmskcXHfA5sFrWpANOJbip3wlJpj5ui6KGWzg=",
|
||||
"zh:090260dc7889ea822ec1d899344e1ee23eba5290461989c0796149c9511f2316",
|
||||
"zh:13c2655ff824b0dc4b9bb832b5ca6d41dba97cb280330258c5fef4115e236209",
|
||||
"zh:166a73c3a810c9c895d68a8ff968158f339f8a2c1c03e20ec9fc5ed99cc64e20",
|
||||
"zh:203777eae1cdc711233315499643180604cff2324411b186b7cf07fdbe16f655",
|
||||
"zh:3b2f18c9a8d28dac74dc6bbf168c946855ab9c68f053578d4630c50d5eaf30a0",
|
||||
"zh:4822275985f6b74b6196c47112316a4252db22cf4ceaef7c9ab4c66d488abf2f",
|
||||
"zh:53ea97562666c8a5a2f6d63d418a302a7f8ee4b7bb7da35dedaa89aa5708b7f0",
|
||||
"zh:56b8a230901e3550c92a1d3f58ee9dafe9853f30fe4315af3ab28ae63262e15d",
|
||||
"zh:6293ab7b1fd8206a0c853591f50186aca4a1eff117b2a773e10760a23a2c83e9",
|
||||
"zh:9433970f79fb92d8aae3ee436db5630ab312c78b6dc9df9c1db3273a18f8aaa1",
|
||||
"zh:95df406214f79b3b98222d7c7fe8fc319a3d90b7a9d53e1d5abbda5dfb8b9436",
|
||||
"zh:a85880da0552a42c8f449390fbd7d8b03541d1a13e04bba9f1404fa658754260",
|
||||
"zh:a95f6e9bd62c67e70eba1b1a14728856b9a6a28cd1e5e3be54a7718882c87e7f",
|
||||
"zh:dd599b51c5beb34a4c6feece244fde07d2558d69929449ab1fd39a5ebe738781",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/aws" {
|
||||
version = "5.100.0"
|
||||
constraints = "~> 5.0"
|
||||
hashes = [
|
||||
"h1:Ijt7pOlB7Tr7maGQIqtsLFbl7pSMIj06TVdkoSBcYOw=",
|
||||
"zh:054b8dd49f0549c9a7cc27d159e45327b7b65cf404da5e5a20da154b90b8a644",
|
||||
"zh:0b97bf8d5e03d15d83cc40b0530a1f84b459354939ba6f135a0086c20ebbe6b2",
|
||||
"zh:1589a2266af699cbd5d80737a0fe02e54ec9cf2ca54e7e00ac51c7359056f274",
|
||||
"zh:6330766f1d85f01ae6ea90d1b214b8b74cc8c1badc4696b165b36ddd4cc15f7b",
|
||||
"zh:7c8c2e30d8e55291b86fcb64bdf6c25489d538688545eb48fd74ad622e5d3862",
|
||||
"zh:99b1003bd9bd32ee323544da897148f46a527f622dc3971af63ea3e251596342",
|
||||
"zh:9b12af85486a96aedd8d7984b0ff811a4b42e3d88dad1a3fb4c0b580d04fa425",
|
||||
"zh:9f8b909d3ec50ade83c8062290378b1ec553edef6a447c56dadc01a99f4eaa93",
|
||||
"zh:aaef921ff9aabaf8b1869a86d692ebd24fbd4e12c21205034bb679b9caf883a2",
|
||||
"zh:ac882313207aba00dd5a76dbd572a0ddc818bb9cbf5c9d61b28fe30efaec951e",
|
||||
"zh:bb64e8aff37becab373a1a0cc1080990785304141af42ed6aa3dd4913b000421",
|
||||
"zh:dfe495f6621df5540d9c92ad40b8067376350b005c637ea6efac5dc15028add4",
|
||||
"zh:f0ddf0eaf052766cfe09dea8200a946519f653c384ab4336e2a4a64fdd6310e9",
|
||||
"zh:f1b7e684f4c7ae1eed272b6de7d2049bb87a0275cb04dbb7cda6636f600699c9",
|
||||
"zh:ff461571e3f233699bf690db319dfe46aec75e58726636a0d97dd9ac6e32fb70",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/helm" {
|
||||
version = "2.17.0"
|
||||
constraints = "~> 2.14"
|
||||
hashes = [
|
||||
"h1:kQMkcPVvHOguOqnxoEU2sm1ND9vCHiT8TvZ2x6v/Rsw=",
|
||||
"zh:06fb4e9932f0afc1904d2279e6e99353c2ddac0d765305ce90519af410706bd4",
|
||||
"zh:104eccfc781fc868da3c7fec4385ad14ed183eb985c96331a1a937ac79c2d1a7",
|
||||
"zh:129345c82359837bb3f0070ce4891ec232697052f7d5ccf61d43d818912cf5f3",
|
||||
"zh:3956187ec239f4045975b35e8c30741f701aa494c386aaa04ebabffe7749f81c",
|
||||
"zh:66a9686d92a6b3ec43de3ca3fde60ef3d89fb76259ed3313ca4eb9bb8c13b7dd",
|
||||
"zh:88644260090aa621e7e8083585c468c8dd5e09a3c01a432fb05da5c4623af940",
|
||||
"zh:a248f650d174a883b32c5b94f9e725f4057e623b00f171936dcdcc840fad0b3e",
|
||||
"zh:aa498c1f1ab93be5c8fbf6d48af51dc6ef0f10b2ea88d67bcb9f02d1d80d3930",
|
||||
"zh:bf01e0f2ec2468c53596e027d376532a2d30feb72b0b5b810334d043109ae32f",
|
||||
"zh:c46fa84cc8388e5ca87eb575a534ebcf68819c5a5724142998b487cb11246654",
|
||||
"zh:d0c0f15ffc115c0965cbfe5c81f18c2e114113e7a1e6829f6bfd879ce5744fbb",
|
||||
"zh:f569b65999264a9416862bca5cd2a6177d94ccb0424f3a4ef424428912b9cb3c",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/kubernetes" {
|
||||
version = "2.38.0"
|
||||
constraints = "~> 2.27"
|
||||
hashes = [
|
||||
"h1:soK8Lt0SZ6dB+HsypFRDzuX/npqlMU6M0fvyaR1yW0k=",
|
||||
"zh:0af928d776eb269b192dc0ea0f8a3f0f5ec117224cd644bdacdc682300f84ba0",
|
||||
"zh:1be998e67206f7cfc4ffe77c01a09ac91ce725de0abaec9030b22c0a832af44f",
|
||||
"zh:326803fe5946023687d603f6f1bab24de7af3d426b01d20e51d4e6fbe4e7ec1b",
|
||||
"zh:4a99ec8d91193af961de1abb1f824be73df07489301d62e6141a656b3ebfff12",
|
||||
"zh:5136e51765d6a0b9e4dbcc3b38821e9736bd2136cf15e9aac11668f22db117d2",
|
||||
"zh:63fab47349852d7802fb032e4f2b6a101ee1ce34b62557a9ad0f0f0f5b6ecfdc",
|
||||
"zh:924fb0257e2d03e03e2bfe9c7b99aa73c195b1f19412ca09960001bee3c50d15",
|
||||
"zh:b63a0be5e233f8f6727c56bed3b61eb9456ca7a8bb29539fba0837f1badf1396",
|
||||
"zh:d39861aa21077f1bc899bc53e7233262e530ba8a3a2d737449b100daeb303e4d",
|
||||
"zh:de0805e10ebe4c83ce3b728a67f6b0f9d18be32b25146aa89116634df5145ad4",
|
||||
"zh:f569b65999264a9416862bca5cd2a6177d94ccb0424f3a4ef424428912b9cb3c",
|
||||
"zh:faf23e45f0090eef8ba28a8aac7ec5d4fdf11a36c40a8d286304567d71c1e7db",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/null" {
|
||||
version = "3.3.0"
|
||||
constraints = "~> 3.2"
|
||||
hashes = [
|
||||
"h1:a14TKo7Xvg4W8+H1VA6p+oLZTLxVQnYUD8LOaOs14A8=",
|
||||
"zh:021748b5ea3b5f6956f2e75c42c5cdc113b391fb98ac71364a4965d23b37000f",
|
||||
"zh:3b27956f8541d46704fda234e0d535c2ae2a4b33411848b1ee262a1ec03568b0",
|
||||
"zh:3de4ed47d6d0f4d8edba4a5092c7c9799950eda63989d8d0d2586e6afcb0aa20",
|
||||
"zh:57ed8935c7d56dbc91cf2673534582cacfaab7a2f105f51d9f797e99df0c0c47",
|
||||
"zh:58e176ba1d142827089e30e0711e007309a9f2726e8881986da5026e9778fdf4",
|
||||
"zh:5949c4a3d4a93f841f155cdb7e991c087e637145c1630572e21948224f8f4923",
|
||||
"zh:76d60f366b743003c1b085afa769b45b2198ee919927e45807d7d44fb42c067d",
|
||||
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
|
||||
"zh:79cd1bab1261a07f84e917191d7ddc4340ac5f5524283767256f7ffd7f87caf0",
|
||||
"zh:8ec9083038cf710b30e319eaa467c9df7fa52bbd9969b61053a35bc2cdd2e0a6",
|
||||
"zh:a6e502cb579685ab7aeb886c2bb11ddd9cfed74b41008592d57cbc3351a9218b",
|
||||
"zh:acb74d6b4f66ff6acfcda315df802a7432170ef3955c9b432cb4580767004006",
|
||||
"zh:f0ce55d8d9ffdb33dab612b1246f9bab060a9d54fc32ce2b4a038646155660af",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/vault" {
|
||||
version = "4.8.0"
|
||||
constraints = "~> 4.0"
|
||||
hashes = [
|
||||
"h1:GPfhH6dr1LY0foPBDYv9bEGifx7eSwYqFcEAOWOUxLk=",
|
||||
"zh:269ab13433f67684012ae7e15876532b0312f5d0d2002a9cf9febb1279ce5ea6",
|
||||
"zh:4babc95bf0c40eb85005db1dc2ca403c46be4a71dd3e409db3711a56f7a5ca0e",
|
||||
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
|
||||
"zh:86e27c1c625ecc24446a11eeffc3ac319b36c2b4e51251db8579256a0dbcf136",
|
||||
"zh:a32f31da94824009e26b077374440b52098aecb93c92ff55dc3d31dd37c4ea25",
|
||||
"zh:be0a18c6c0425518bab4fbffd82078b82036a88503b5d76064de551c9f646cbf",
|
||||
"zh:be5a77fdfd36863ebeec79cd12b1d13322ffad6821d157a0b279789fa06b5937",
|
||||
"zh:be8317d142a3caad74c7d936039ae27076a1b2b8312ef5208e2871a5f525977c",
|
||||
"zh:c94a84895a3d9954b80e983eed4603330a5cdbbd8eef5b3c99278c2d1402ef3c",
|
||||
"zh:de1fb712784dd8415f011ca5346a34f87fab6046c730557615247e511dbc7d98",
|
||||
"zh:e3eafae7da550f86cae395d6660b2a0e93ec8d2b0e0e5ef982ec762e961fc952",
|
||||
"zh:ff35fb1ab6add288f0f368981e56f780b50405accd1937131cba1137999c8d83",
|
||||
]
|
||||
}
|
||||
-375
@@ -1,375 +0,0 @@
|
||||
Copyright (c) 2017 HashiCorp, Inc.
|
||||
|
||||
Mozilla Public License Version 2.0
|
||||
==================================
|
||||
|
||||
1. Definitions
|
||||
--------------
|
||||
|
||||
1.1. "Contributor"
|
||||
means each individual or legal entity that creates, contributes to
|
||||
the creation of, or owns Covered Software.
|
||||
|
||||
1.2. "Contributor Version"
|
||||
means the combination of the Contributions of others (if any) used
|
||||
by a Contributor and that particular Contributor's Contribution.
|
||||
|
||||
1.3. "Contribution"
|
||||
means Covered Software of a particular Contributor.
|
||||
|
||||
1.4. "Covered Software"
|
||||
means Source Code Form to which the initial Contributor has attached
|
||||
the notice in Exhibit A, the Executable Form of such Source Code
|
||||
Form, and Modifications of such Source Code Form, in each case
|
||||
including portions thereof.
|
||||
|
||||
1.5. "Incompatible With Secondary Licenses"
|
||||
means
|
||||
|
||||
(a) that the initial Contributor has attached the notice described
|
||||
in Exhibit B to the Covered Software; or
|
||||
|
||||
(b) that the Covered Software was made available under the terms of
|
||||
version 1.1 or earlier of the License, but not also under the
|
||||
terms of a Secondary License.
|
||||
|
||||
1.6. "Executable Form"
|
||||
means any form of the work other than Source Code Form.
|
||||
|
||||
1.7. "Larger Work"
|
||||
means a work that combines Covered Software with other material, in
|
||||
a separate file or files, that is not Covered Software.
|
||||
|
||||
1.8. "License"
|
||||
means this document.
|
||||
|
||||
1.9. "Licensable"
|
||||
means having the right to grant, to the maximum extent possible,
|
||||
whether at the time of the initial grant or subsequently, any and
|
||||
all of the rights conveyed by this License.
|
||||
|
||||
1.10. "Modifications"
|
||||
means any of the following:
|
||||
|
||||
(a) any file in Source Code Form that results from an addition to,
|
||||
deletion from, or modification of the contents of Covered
|
||||
Software; or
|
||||
|
||||
(b) any new file in Source Code Form that contains any Covered
|
||||
Software.
|
||||
|
||||
1.11. "Patent Claims" of a Contributor
|
||||
means any patent claim(s), including without limitation, method,
|
||||
process, and apparatus claims, in any patent Licensable by such
|
||||
Contributor that would be infringed, but for the grant of the
|
||||
License, by the making, using, selling, offering for sale, having
|
||||
made, import, or transfer of either its Contributions or its
|
||||
Contributor Version.
|
||||
|
||||
1.12. "Secondary License"
|
||||
means either the GNU General Public License, Version 2.0, the GNU
|
||||
Lesser General Public License, Version 2.1, the GNU Affero General
|
||||
Public License, Version 3.0, or any later versions of those
|
||||
licenses.
|
||||
|
||||
1.13. "Source Code Form"
|
||||
means the form of the work preferred for making modifications.
|
||||
|
||||
1.14. "You" (or "Your")
|
||||
means an individual or a legal entity exercising rights under this
|
||||
License. For legal entities, "You" includes any entity that
|
||||
controls, is controlled by, or is under common control with You. For
|
||||
purposes of this definition, "control" means (a) the power, direct
|
||||
or indirect, to cause the direction or management of such entity,
|
||||
whether by contract or otherwise, or (b) ownership of more than
|
||||
fifty percent (50%) of the outstanding shares or beneficial
|
||||
ownership of such entity.
|
||||
|
||||
2. License Grants and Conditions
|
||||
--------------------------------
|
||||
|
||||
2.1. Grants
|
||||
|
||||
Each Contributor hereby grants You a world-wide, royalty-free,
|
||||
non-exclusive license:
|
||||
|
||||
(a) under intellectual property rights (other than patent or trademark)
|
||||
Licensable by such Contributor to use, reproduce, make available,
|
||||
modify, display, perform, distribute, and otherwise exploit its
|
||||
Contributions, either on an unmodified basis, with Modifications, or
|
||||
as part of a Larger Work; and
|
||||
|
||||
(b) under Patent Claims of such Contributor to make, use, sell, offer
|
||||
for sale, have made, import, and otherwise transfer either its
|
||||
Contributions or its Contributor Version.
|
||||
|
||||
2.2. Effective Date
|
||||
|
||||
The licenses granted in Section 2.1 with respect to any Contribution
|
||||
become effective for each Contribution on the date the Contributor first
|
||||
distributes such Contribution.
|
||||
|
||||
2.3. Limitations on Grant Scope
|
||||
|
||||
The licenses granted in this Section 2 are the only rights granted under
|
||||
this License. No additional rights or licenses will be implied from the
|
||||
distribution or licensing of Covered Software under this License.
|
||||
Notwithstanding Section 2.1(b) above, no patent license is granted by a
|
||||
Contributor:
|
||||
|
||||
(a) for any code that a Contributor has removed from Covered Software;
|
||||
or
|
||||
|
||||
(b) for infringements caused by: (i) Your and any other third party's
|
||||
modifications of Covered Software, or (ii) the combination of its
|
||||
Contributions with other software (except as part of its Contributor
|
||||
Version); or
|
||||
|
||||
(c) under Patent Claims infringed by Covered Software in the absence of
|
||||
its Contributions.
|
||||
|
||||
This License does not grant any rights in the trademarks, service marks,
|
||||
or logos of any Contributor (except as may be necessary to comply with
|
||||
the notice requirements in Section 3.4).
|
||||
|
||||
2.4. Subsequent Licenses
|
||||
|
||||
No Contributor makes additional grants as a result of Your choice to
|
||||
distribute the Covered Software under a subsequent version of this
|
||||
License (see Section 10.2) or under the terms of a Secondary License (if
|
||||
permitted under the terms of Section 3.3).
|
||||
|
||||
2.5. Representation
|
||||
|
||||
Each Contributor represents that the Contributor believes its
|
||||
Contributions are its original creation(s) or it has sufficient rights
|
||||
to grant the rights to its Contributions conveyed by this License.
|
||||
|
||||
2.6. Fair Use
|
||||
|
||||
This License is not intended to limit any rights You have under
|
||||
applicable copyright doctrines of fair use, fair dealing, or other
|
||||
equivalents.
|
||||
|
||||
2.7. Conditions
|
||||
|
||||
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted
|
||||
in Section 2.1.
|
||||
|
||||
3. Responsibilities
|
||||
-------------------
|
||||
|
||||
3.1. Distribution of Source Form
|
||||
|
||||
All distribution of Covered Software in Source Code Form, including any
|
||||
Modifications that You create or to which You contribute, must be under
|
||||
the terms of this License. You must inform recipients that the Source
|
||||
Code Form of the Covered Software is governed by the terms of this
|
||||
License, and how they can obtain a copy of this License. You may not
|
||||
attempt to alter or restrict the recipients' rights in the Source Code
|
||||
Form.
|
||||
|
||||
3.2. Distribution of Executable Form
|
||||
|
||||
If You distribute Covered Software in Executable Form then:
|
||||
|
||||
(a) such Covered Software must also be made available in Source Code
|
||||
Form, as described in Section 3.1, and You must inform recipients of
|
||||
the Executable Form how they can obtain a copy of such Source Code
|
||||
Form by reasonable means in a timely manner, at a charge no more
|
||||
than the cost of distribution to the recipient; and
|
||||
|
||||
(b) You may distribute such Executable Form under the terms of this
|
||||
License, or sublicense it under different terms, provided that the
|
||||
license for the Executable Form does not attempt to limit or alter
|
||||
the recipients' rights in the Source Code Form under this License.
|
||||
|
||||
3.3. Distribution of a Larger Work
|
||||
|
||||
You may create and distribute a Larger Work under terms of Your choice,
|
||||
provided that You also comply with the requirements of this License for
|
||||
the Covered Software. If the Larger Work is a combination of Covered
|
||||
Software with a work governed by one or more Secondary Licenses, and the
|
||||
Covered Software is not Incompatible With Secondary Licenses, this
|
||||
License permits You to additionally distribute such Covered Software
|
||||
under the terms of such Secondary License(s), so that the recipient of
|
||||
the Larger Work may, at their option, further distribute the Covered
|
||||
Software under the terms of either this License or such Secondary
|
||||
License(s).
|
||||
|
||||
3.4. Notices
|
||||
|
||||
You may not remove or alter the substance of any license notices
|
||||
(including copyright notices, patent notices, disclaimers of warranty,
|
||||
or limitations of liability) contained within the Source Code Form of
|
||||
the Covered Software, except that You may alter any license notices to
|
||||
the extent required to remedy known factual inaccuracies.
|
||||
|
||||
3.5. Application of Additional Terms
|
||||
|
||||
You may choose to offer, and to charge a fee for, warranty, support,
|
||||
indemnity or liability obligations to one or more recipients of Covered
|
||||
Software. However, You may do so only on Your own behalf, and not on
|
||||
behalf of any Contributor. You must make it absolutely clear that any
|
||||
such warranty, support, indemnity, or liability obligation is offered by
|
||||
You alone, and You hereby agree to indemnify every Contributor for any
|
||||
liability incurred by such Contributor as a result of warranty, support,
|
||||
indemnity or liability terms You offer. You may include additional
|
||||
disclaimers of warranty and limitations of liability specific to any
|
||||
jurisdiction.
|
||||
|
||||
4. Inability to Comply Due to Statute or Regulation
|
||||
---------------------------------------------------
|
||||
|
||||
If it is impossible for You to comply with any of the terms of this
|
||||
License with respect to some or all of the Covered Software due to
|
||||
statute, judicial order, or regulation then You must: (a) comply with
|
||||
the terms of this License to the maximum extent possible; and (b)
|
||||
describe the limitations and the code they affect. Such description must
|
||||
be placed in a text file included with all distributions of the Covered
|
||||
Software under this License. Except to the extent prohibited by statute
|
||||
or regulation, such description must be sufficiently detailed for a
|
||||
recipient of ordinary skill to be able to understand it.
|
||||
|
||||
5. Termination
|
||||
--------------
|
||||
|
||||
5.1. The rights granted under this License will terminate automatically
|
||||
if You fail to comply with any of its terms. However, if You become
|
||||
compliant, then the rights granted under this License from a particular
|
||||
Contributor are reinstated (a) provisionally, unless and until such
|
||||
Contributor explicitly and finally terminates Your grants, and (b) on an
|
||||
ongoing basis, if such Contributor fails to notify You of the
|
||||
non-compliance by some reasonable means prior to 60 days after You have
|
||||
come back into compliance. Moreover, Your grants from a particular
|
||||
Contributor are reinstated on an ongoing basis if such Contributor
|
||||
notifies You of the non-compliance by some reasonable means, this is the
|
||||
first time You have received notice of non-compliance with this License
|
||||
from such Contributor, and You become compliant prior to 30 days after
|
||||
Your receipt of the notice.
|
||||
|
||||
5.2. If You initiate litigation against any entity by asserting a patent
|
||||
infringement claim (excluding declaratory judgment actions,
|
||||
counter-claims, and cross-claims) alleging that a Contributor Version
|
||||
directly or indirectly infringes any patent, then the rights granted to
|
||||
You by any and all Contributors for the Covered Software under Section
|
||||
2.1 of this License shall terminate.
|
||||
|
||||
5.3. In the event of termination under Sections 5.1 or 5.2 above, all
|
||||
end user license agreements (excluding distributors and resellers) which
|
||||
have been validly granted by You or Your distributors under this License
|
||||
prior to termination shall survive termination.
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 6. Disclaimer of Warranty *
|
||||
* ------------------------- *
|
||||
* *
|
||||
* Covered Software is provided under this License on an "as is" *
|
||||
* basis, without warranty of any kind, either expressed, implied, or *
|
||||
* statutory, including, without limitation, warranties that the *
|
||||
* Covered Software is free of defects, merchantable, fit for a *
|
||||
* particular purpose or non-infringing. The entire risk as to the *
|
||||
* quality and performance of the Covered Software is with You. *
|
||||
* Should any Covered Software prove defective in any respect, You *
|
||||
* (not any Contributor) assume the cost of any necessary servicing, *
|
||||
* repair, or correction. This disclaimer of warranty constitutes an *
|
||||
* essential part of this License. No use of any Covered Software is *
|
||||
* authorized under this License except under this disclaimer. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 7. Limitation of Liability *
|
||||
* -------------------------- *
|
||||
* *
|
||||
* Under no circumstances and under no legal theory, whether tort *
|
||||
* (including negligence), contract, or otherwise, shall any *
|
||||
* Contributor, or anyone who distributes Covered Software as *
|
||||
* permitted above, be liable to You for any direct, indirect, *
|
||||
* special, incidental, or consequential damages of any character *
|
||||
* including, without limitation, damages for lost profits, loss of *
|
||||
* goodwill, work stoppage, computer failure or malfunction, or any *
|
||||
* and all other commercial damages or losses, even if such party *
|
||||
* shall have been informed of the possibility of such damages. This *
|
||||
* limitation of liability shall not apply to liability for death or *
|
||||
* personal injury resulting from such party's negligence to the *
|
||||
* extent applicable law prohibits such limitation. Some *
|
||||
* jurisdictions do not allow the exclusion or limitation of *
|
||||
* incidental or consequential damages, so this exclusion and *
|
||||
* limitation may not apply to You. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
8. Litigation
|
||||
-------------
|
||||
|
||||
Any litigation relating to this License may be brought only in the
|
||||
courts of a jurisdiction where the defendant maintains its principal
|
||||
place of business and such litigation shall be governed by laws of that
|
||||
jurisdiction, without reference to its conflict-of-law provisions.
|
||||
Nothing in this Section shall prevent a party's ability to bring
|
||||
cross-claims or counter-claims.
|
||||
|
||||
9. Miscellaneous
|
||||
----------------
|
||||
|
||||
This License represents the complete agreement concerning the subject
|
||||
matter hereof. If any provision of this License is held to be
|
||||
unenforceable, such provision shall be reformed only to the extent
|
||||
necessary to make it enforceable. Any law or regulation which provides
|
||||
that the language of a contract shall be construed against the drafter
|
||||
shall not be used to construe this License against a Contributor.
|
||||
|
||||
10. Versions of the License
|
||||
---------------------------
|
||||
|
||||
10.1. New Versions
|
||||
|
||||
Mozilla Foundation is the license steward. Except as provided in Section
|
||||
10.3, no one other than the license steward has the right to modify or
|
||||
publish new versions of this License. Each version will be given a
|
||||
distinguishing version number.
|
||||
|
||||
10.2. Effect of New Versions
|
||||
|
||||
You may distribute the Covered Software under the terms of the version
|
||||
of the License under which You originally received the Covered Software,
|
||||
or under the terms of any subsequent version published by the license
|
||||
steward.
|
||||
|
||||
10.3. Modified Versions
|
||||
|
||||
If you create software not governed by this License, and you want to
|
||||
create a new license for such software, you may create and use a
|
||||
modified version of this License if you rename the license and remove
|
||||
any references to the name of the license steward (except to note that
|
||||
such modified license differs from this License).
|
||||
|
||||
10.4. Distributing Source Code Form that is Incompatible With Secondary
|
||||
Licenses
|
||||
|
||||
If You choose to distribute Source Code Form that is Incompatible With
|
||||
Secondary Licenses under the terms of this version of the License, the
|
||||
notice described in Exhibit B of this License must be attached.
|
||||
|
||||
Exhibit A - Source Code Form License Notice
|
||||
-------------------------------------------
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
If it is not possible or desirable to put the notice in a particular
|
||||
file, then You may include the notice in a location (such as a LICENSE
|
||||
file in a relevant directory) where a recipient would be likely to look
|
||||
for such a notice.
|
||||
|
||||
You may add additional accurate notices of copyright ownership.
|
||||
|
||||
Exhibit B - "Incompatible With Secondary Licenses" Notice
|
||||
---------------------------------------------------------
|
||||
|
||||
This Source Code Form is "Incompatible With Secondary Licenses", as
|
||||
defined by the Mozilla Public License, v. 2.0.
|
||||
BIN
Binary file not shown.
-375
@@ -1,375 +0,0 @@
|
||||
Copyright (c) 2017 HashiCorp, Inc.
|
||||
|
||||
Mozilla Public License Version 2.0
|
||||
==================================
|
||||
|
||||
1. Definitions
|
||||
--------------
|
||||
|
||||
1.1. "Contributor"
|
||||
means each individual or legal entity that creates, contributes to
|
||||
the creation of, or owns Covered Software.
|
||||
|
||||
1.2. "Contributor Version"
|
||||
means the combination of the Contributions of others (if any) used
|
||||
by a Contributor and that particular Contributor's Contribution.
|
||||
|
||||
1.3. "Contribution"
|
||||
means Covered Software of a particular Contributor.
|
||||
|
||||
1.4. "Covered Software"
|
||||
means Source Code Form to which the initial Contributor has attached
|
||||
the notice in Exhibit A, the Executable Form of such Source Code
|
||||
Form, and Modifications of such Source Code Form, in each case
|
||||
including portions thereof.
|
||||
|
||||
1.5. "Incompatible With Secondary Licenses"
|
||||
means
|
||||
|
||||
(a) that the initial Contributor has attached the notice described
|
||||
in Exhibit B to the Covered Software; or
|
||||
|
||||
(b) that the Covered Software was made available under the terms of
|
||||
version 1.1 or earlier of the License, but not also under the
|
||||
terms of a Secondary License.
|
||||
|
||||
1.6. "Executable Form"
|
||||
means any form of the work other than Source Code Form.
|
||||
|
||||
1.7. "Larger Work"
|
||||
means a work that combines Covered Software with other material, in
|
||||
a separate file or files, that is not Covered Software.
|
||||
|
||||
1.8. "License"
|
||||
means this document.
|
||||
|
||||
1.9. "Licensable"
|
||||
means having the right to grant, to the maximum extent possible,
|
||||
whether at the time of the initial grant or subsequently, any and
|
||||
all of the rights conveyed by this License.
|
||||
|
||||
1.10. "Modifications"
|
||||
means any of the following:
|
||||
|
||||
(a) any file in Source Code Form that results from an addition to,
|
||||
deletion from, or modification of the contents of Covered
|
||||
Software; or
|
||||
|
||||
(b) any new file in Source Code Form that contains any Covered
|
||||
Software.
|
||||
|
||||
1.11. "Patent Claims" of a Contributor
|
||||
means any patent claim(s), including without limitation, method,
|
||||
process, and apparatus claims, in any patent Licensable by such
|
||||
Contributor that would be infringed, but for the grant of the
|
||||
License, by the making, using, selling, offering for sale, having
|
||||
made, import, or transfer of either its Contributions or its
|
||||
Contributor Version.
|
||||
|
||||
1.12. "Secondary License"
|
||||
means either the GNU General Public License, Version 2.0, the GNU
|
||||
Lesser General Public License, Version 2.1, the GNU Affero General
|
||||
Public License, Version 3.0, or any later versions of those
|
||||
licenses.
|
||||
|
||||
1.13. "Source Code Form"
|
||||
means the form of the work preferred for making modifications.
|
||||
|
||||
1.14. "You" (or "Your")
|
||||
means an individual or a legal entity exercising rights under this
|
||||
License. For legal entities, "You" includes any entity that
|
||||
controls, is controlled by, or is under common control with You. For
|
||||
purposes of this definition, "control" means (a) the power, direct
|
||||
or indirect, to cause the direction or management of such entity,
|
||||
whether by contract or otherwise, or (b) ownership of more than
|
||||
fifty percent (50%) of the outstanding shares or beneficial
|
||||
ownership of such entity.
|
||||
|
||||
2. License Grants and Conditions
|
||||
--------------------------------
|
||||
|
||||
2.1. Grants
|
||||
|
||||
Each Contributor hereby grants You a world-wide, royalty-free,
|
||||
non-exclusive license:
|
||||
|
||||
(a) under intellectual property rights (other than patent or trademark)
|
||||
Licensable by such Contributor to use, reproduce, make available,
|
||||
modify, display, perform, distribute, and otherwise exploit its
|
||||
Contributions, either on an unmodified basis, with Modifications, or
|
||||
as part of a Larger Work; and
|
||||
|
||||
(b) under Patent Claims of such Contributor to make, use, sell, offer
|
||||
for sale, have made, import, and otherwise transfer either its
|
||||
Contributions or its Contributor Version.
|
||||
|
||||
2.2. Effective Date
|
||||
|
||||
The licenses granted in Section 2.1 with respect to any Contribution
|
||||
become effective for each Contribution on the date the Contributor first
|
||||
distributes such Contribution.
|
||||
|
||||
2.3. Limitations on Grant Scope
|
||||
|
||||
The licenses granted in this Section 2 are the only rights granted under
|
||||
this License. No additional rights or licenses will be implied from the
|
||||
distribution or licensing of Covered Software under this License.
|
||||
Notwithstanding Section 2.1(b) above, no patent license is granted by a
|
||||
Contributor:
|
||||
|
||||
(a) for any code that a Contributor has removed from Covered Software;
|
||||
or
|
||||
|
||||
(b) for infringements caused by: (i) Your and any other third party's
|
||||
modifications of Covered Software, or (ii) the combination of its
|
||||
Contributions with other software (except as part of its Contributor
|
||||
Version); or
|
||||
|
||||
(c) under Patent Claims infringed by Covered Software in the absence of
|
||||
its Contributions.
|
||||
|
||||
This License does not grant any rights in the trademarks, service marks,
|
||||
or logos of any Contributor (except as may be necessary to comply with
|
||||
the notice requirements in Section 3.4).
|
||||
|
||||
2.4. Subsequent Licenses
|
||||
|
||||
No Contributor makes additional grants as a result of Your choice to
|
||||
distribute the Covered Software under a subsequent version of this
|
||||
License (see Section 10.2) or under the terms of a Secondary License (if
|
||||
permitted under the terms of Section 3.3).
|
||||
|
||||
2.5. Representation
|
||||
|
||||
Each Contributor represents that the Contributor believes its
|
||||
Contributions are its original creation(s) or it has sufficient rights
|
||||
to grant the rights to its Contributions conveyed by this License.
|
||||
|
||||
2.6. Fair Use
|
||||
|
||||
This License is not intended to limit any rights You have under
|
||||
applicable copyright doctrines of fair use, fair dealing, or other
|
||||
equivalents.
|
||||
|
||||
2.7. Conditions
|
||||
|
||||
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted
|
||||
in Section 2.1.
|
||||
|
||||
3. Responsibilities
|
||||
-------------------
|
||||
|
||||
3.1. Distribution of Source Form
|
||||
|
||||
All distribution of Covered Software in Source Code Form, including any
|
||||
Modifications that You create or to which You contribute, must be under
|
||||
the terms of this License. You must inform recipients that the Source
|
||||
Code Form of the Covered Software is governed by the terms of this
|
||||
License, and how they can obtain a copy of this License. You may not
|
||||
attempt to alter or restrict the recipients' rights in the Source Code
|
||||
Form.
|
||||
|
||||
3.2. Distribution of Executable Form
|
||||
|
||||
If You distribute Covered Software in Executable Form then:
|
||||
|
||||
(a) such Covered Software must also be made available in Source Code
|
||||
Form, as described in Section 3.1, and You must inform recipients of
|
||||
the Executable Form how they can obtain a copy of such Source Code
|
||||
Form by reasonable means in a timely manner, at a charge no more
|
||||
than the cost of distribution to the recipient; and
|
||||
|
||||
(b) You may distribute such Executable Form under the terms of this
|
||||
License, or sublicense it under different terms, provided that the
|
||||
license for the Executable Form does not attempt to limit or alter
|
||||
the recipients' rights in the Source Code Form under this License.
|
||||
|
||||
3.3. Distribution of a Larger Work
|
||||
|
||||
You may create and distribute a Larger Work under terms of Your choice,
|
||||
provided that You also comply with the requirements of this License for
|
||||
the Covered Software. If the Larger Work is a combination of Covered
|
||||
Software with a work governed by one or more Secondary Licenses, and the
|
||||
Covered Software is not Incompatible With Secondary Licenses, this
|
||||
License permits You to additionally distribute such Covered Software
|
||||
under the terms of such Secondary License(s), so that the recipient of
|
||||
the Larger Work may, at their option, further distribute the Covered
|
||||
Software under the terms of either this License or such Secondary
|
||||
License(s).
|
||||
|
||||
3.4. Notices
|
||||
|
||||
You may not remove or alter the substance of any license notices
|
||||
(including copyright notices, patent notices, disclaimers of warranty,
|
||||
or limitations of liability) contained within the Source Code Form of
|
||||
the Covered Software, except that You may alter any license notices to
|
||||
the extent required to remedy known factual inaccuracies.
|
||||
|
||||
3.5. Application of Additional Terms
|
||||
|
||||
You may choose to offer, and to charge a fee for, warranty, support,
|
||||
indemnity or liability obligations to one or more recipients of Covered
|
||||
Software. However, You may do so only on Your own behalf, and not on
|
||||
behalf of any Contributor. You must make it absolutely clear that any
|
||||
such warranty, support, indemnity, or liability obligation is offered by
|
||||
You alone, and You hereby agree to indemnify every Contributor for any
|
||||
liability incurred by such Contributor as a result of warranty, support,
|
||||
indemnity or liability terms You offer. You may include additional
|
||||
disclaimers of warranty and limitations of liability specific to any
|
||||
jurisdiction.
|
||||
|
||||
4. Inability to Comply Due to Statute or Regulation
|
||||
---------------------------------------------------
|
||||
|
||||
If it is impossible for You to comply with any of the terms of this
|
||||
License with respect to some or all of the Covered Software due to
|
||||
statute, judicial order, or regulation then You must: (a) comply with
|
||||
the terms of this License to the maximum extent possible; and (b)
|
||||
describe the limitations and the code they affect. Such description must
|
||||
be placed in a text file included with all distributions of the Covered
|
||||
Software under this License. Except to the extent prohibited by statute
|
||||
or regulation, such description must be sufficiently detailed for a
|
||||
recipient of ordinary skill to be able to understand it.
|
||||
|
||||
5. Termination
|
||||
--------------
|
||||
|
||||
5.1. The rights granted under this License will terminate automatically
|
||||
if You fail to comply with any of its terms. However, if You become
|
||||
compliant, then the rights granted under this License from a particular
|
||||
Contributor are reinstated (a) provisionally, unless and until such
|
||||
Contributor explicitly and finally terminates Your grants, and (b) on an
|
||||
ongoing basis, if such Contributor fails to notify You of the
|
||||
non-compliance by some reasonable means prior to 60 days after You have
|
||||
come back into compliance. Moreover, Your grants from a particular
|
||||
Contributor are reinstated on an ongoing basis if such Contributor
|
||||
notifies You of the non-compliance by some reasonable means, this is the
|
||||
first time You have received notice of non-compliance with this License
|
||||
from such Contributor, and You become compliant prior to 30 days after
|
||||
Your receipt of the notice.
|
||||
|
||||
5.2. If You initiate litigation against any entity by asserting a patent
|
||||
infringement claim (excluding declaratory judgment actions,
|
||||
counter-claims, and cross-claims) alleging that a Contributor Version
|
||||
directly or indirectly infringes any patent, then the rights granted to
|
||||
You by any and all Contributors for the Covered Software under Section
|
||||
2.1 of this License shall terminate.
|
||||
|
||||
5.3. In the event of termination under Sections 5.1 or 5.2 above, all
|
||||
end user license agreements (excluding distributors and resellers) which
|
||||
have been validly granted by You or Your distributors under this License
|
||||
prior to termination shall survive termination.
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 6. Disclaimer of Warranty *
|
||||
* ------------------------- *
|
||||
* *
|
||||
* Covered Software is provided under this License on an "as is" *
|
||||
* basis, without warranty of any kind, either expressed, implied, or *
|
||||
* statutory, including, without limitation, warranties that the *
|
||||
* Covered Software is free of defects, merchantable, fit for a *
|
||||
* particular purpose or non-infringing. The entire risk as to the *
|
||||
* quality and performance of the Covered Software is with You. *
|
||||
* Should any Covered Software prove defective in any respect, You *
|
||||
* (not any Contributor) assume the cost of any necessary servicing, *
|
||||
* repair, or correction. This disclaimer of warranty constitutes an *
|
||||
* essential part of this License. No use of any Covered Software is *
|
||||
* authorized under this License except under this disclaimer. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 7. Limitation of Liability *
|
||||
* -------------------------- *
|
||||
* *
|
||||
* Under no circumstances and under no legal theory, whether tort *
|
||||
* (including negligence), contract, or otherwise, shall any *
|
||||
* Contributor, or anyone who distributes Covered Software as *
|
||||
* permitted above, be liable to You for any direct, indirect, *
|
||||
* special, incidental, or consequential damages of any character *
|
||||
* including, without limitation, damages for lost profits, loss of *
|
||||
* goodwill, work stoppage, computer failure or malfunction, or any *
|
||||
* and all other commercial damages or losses, even if such party *
|
||||
* shall have been informed of the possibility of such damages. This *
|
||||
* limitation of liability shall not apply to liability for death or *
|
||||
* personal injury resulting from such party's negligence to the *
|
||||
* extent applicable law prohibits such limitation. Some *
|
||||
* jurisdictions do not allow the exclusion or limitation of *
|
||||
* incidental or consequential damages, so this exclusion and *
|
||||
* limitation may not apply to You. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
8. Litigation
|
||||
-------------
|
||||
|
||||
Any litigation relating to this License may be brought only in the
|
||||
courts of a jurisdiction where the defendant maintains its principal
|
||||
place of business and such litigation shall be governed by laws of that
|
||||
jurisdiction, without reference to its conflict-of-law provisions.
|
||||
Nothing in this Section shall prevent a party's ability to bring
|
||||
cross-claims or counter-claims.
|
||||
|
||||
9. Miscellaneous
|
||||
----------------
|
||||
|
||||
This License represents the complete agreement concerning the subject
|
||||
matter hereof. If any provision of this License is held to be
|
||||
unenforceable, such provision shall be reformed only to the extent
|
||||
necessary to make it enforceable. Any law or regulation which provides
|
||||
that the language of a contract shall be construed against the drafter
|
||||
shall not be used to construe this License against a Contributor.
|
||||
|
||||
10. Versions of the License
|
||||
---------------------------
|
||||
|
||||
10.1. New Versions
|
||||
|
||||
Mozilla Foundation is the license steward. Except as provided in Section
|
||||
10.3, no one other than the license steward has the right to modify or
|
||||
publish new versions of this License. Each version will be given a
|
||||
distinguishing version number.
|
||||
|
||||
10.2. Effect of New Versions
|
||||
|
||||
You may distribute the Covered Software under the terms of the version
|
||||
of the License under which You originally received the Covered Software,
|
||||
or under the terms of any subsequent version published by the license
|
||||
steward.
|
||||
|
||||
10.3. Modified Versions
|
||||
|
||||
If you create software not governed by this License, and you want to
|
||||
create a new license for such software, you may create and use a
|
||||
modified version of this License if you rename the license and remove
|
||||
any references to the name of the license steward (except to note that
|
||||
such modified license differs from this License).
|
||||
|
||||
10.4. Distributing Source Code Form that is Incompatible With Secondary
|
||||
Licenses
|
||||
|
||||
If You choose to distribute Source Code Form that is Incompatible With
|
||||
Secondary Licenses under the terms of this version of the License, the
|
||||
notice described in Exhibit B of this License must be attached.
|
||||
|
||||
Exhibit A - Source Code Form License Notice
|
||||
-------------------------------------------
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
If it is not possible or desirable to put the notice in a particular
|
||||
file, then You may include the notice in a location (such as a LICENSE
|
||||
file in a relevant directory) where a recipient would be likely to look
|
||||
for such a notice.
|
||||
|
||||
You may add additional accurate notices of copyright ownership.
|
||||
|
||||
Exhibit B - "Incompatible With Secondary Licenses" Notice
|
||||
---------------------------------------------------------
|
||||
|
||||
This Source Code Form is "Incompatible With Secondary Licenses", as
|
||||
defined by the Mozilla Public License, v. 2.0.
|
||||
BIN
Binary file not shown.
-375
@@ -1,375 +0,0 @@
|
||||
Copyright IBM Corp. 2017, 2026
|
||||
|
||||
Mozilla Public License Version 2.0
|
||||
==================================
|
||||
|
||||
1. Definitions
|
||||
--------------
|
||||
|
||||
1.1. "Contributor"
|
||||
means each individual or legal entity that creates, contributes to
|
||||
the creation of, or owns Covered Software.
|
||||
|
||||
1.2. "Contributor Version"
|
||||
means the combination of the Contributions of others (if any) used
|
||||
by a Contributor and that particular Contributor's Contribution.
|
||||
|
||||
1.3. "Contribution"
|
||||
means Covered Software of a particular Contributor.
|
||||
|
||||
1.4. "Covered Software"
|
||||
means Source Code Form to which the initial Contributor has attached
|
||||
the notice in Exhibit A, the Executable Form of such Source Code
|
||||
Form, and Modifications of such Source Code Form, in each case
|
||||
including portions thereof.
|
||||
|
||||
1.5. "Incompatible With Secondary Licenses"
|
||||
means
|
||||
|
||||
(a) that the initial Contributor has attached the notice described
|
||||
in Exhibit B to the Covered Software; or
|
||||
|
||||
(b) that the Covered Software was made available under the terms of
|
||||
version 1.1 or earlier of the License, but not also under the
|
||||
terms of a Secondary License.
|
||||
|
||||
1.6. "Executable Form"
|
||||
means any form of the work other than Source Code Form.
|
||||
|
||||
1.7. "Larger Work"
|
||||
means a work that combines Covered Software with other material, in
|
||||
a separate file or files, that is not Covered Software.
|
||||
|
||||
1.8. "License"
|
||||
means this document.
|
||||
|
||||
1.9. "Licensable"
|
||||
means having the right to grant, to the maximum extent possible,
|
||||
whether at the time of the initial grant or subsequently, any and
|
||||
all of the rights conveyed by this License.
|
||||
|
||||
1.10. "Modifications"
|
||||
means any of the following:
|
||||
|
||||
(a) any file in Source Code Form that results from an addition to,
|
||||
deletion from, or modification of the contents of Covered
|
||||
Software; or
|
||||
|
||||
(b) any new file in Source Code Form that contains any Covered
|
||||
Software.
|
||||
|
||||
1.11. "Patent Claims" of a Contributor
|
||||
means any patent claim(s), including without limitation, method,
|
||||
process, and apparatus claims, in any patent Licensable by such
|
||||
Contributor that would be infringed, but for the grant of the
|
||||
License, by the making, using, selling, offering for sale, having
|
||||
made, import, or transfer of either its Contributions or its
|
||||
Contributor Version.
|
||||
|
||||
1.12. "Secondary License"
|
||||
means either the GNU General Public License, Version 2.0, the GNU
|
||||
Lesser General Public License, Version 2.1, the GNU Affero General
|
||||
Public License, Version 3.0, or any later versions of those
|
||||
licenses.
|
||||
|
||||
1.13. "Source Code Form"
|
||||
means the form of the work preferred for making modifications.
|
||||
|
||||
1.14. "You" (or "Your")
|
||||
means an individual or a legal entity exercising rights under this
|
||||
License. For legal entities, "You" includes any entity that
|
||||
controls, is controlled by, or is under common control with You. For
|
||||
purposes of this definition, "control" means (a) the power, direct
|
||||
or indirect, to cause the direction or management of such entity,
|
||||
whether by contract or otherwise, or (b) ownership of more than
|
||||
fifty percent (50%) of the outstanding shares or beneficial
|
||||
ownership of such entity.
|
||||
|
||||
2. License Grants and Conditions
|
||||
--------------------------------
|
||||
|
||||
2.1. Grants
|
||||
|
||||
Each Contributor hereby grants You a world-wide, royalty-free,
|
||||
non-exclusive license:
|
||||
|
||||
(a) under intellectual property rights (other than patent or trademark)
|
||||
Licensable by such Contributor to use, reproduce, make available,
|
||||
modify, display, perform, distribute, and otherwise exploit its
|
||||
Contributions, either on an unmodified basis, with Modifications, or
|
||||
as part of a Larger Work; and
|
||||
|
||||
(b) under Patent Claims of such Contributor to make, use, sell, offer
|
||||
for sale, have made, import, and otherwise transfer either its
|
||||
Contributions or its Contributor Version.
|
||||
|
||||
2.2. Effective Date
|
||||
|
||||
The licenses granted in Section 2.1 with respect to any Contribution
|
||||
become effective for each Contribution on the date the Contributor first
|
||||
distributes such Contribution.
|
||||
|
||||
2.3. Limitations on Grant Scope
|
||||
|
||||
The licenses granted in this Section 2 are the only rights granted under
|
||||
this License. No additional rights or licenses will be implied from the
|
||||
distribution or licensing of Covered Software under this License.
|
||||
Notwithstanding Section 2.1(b) above, no patent license is granted by a
|
||||
Contributor:
|
||||
|
||||
(a) for any code that a Contributor has removed from Covered Software;
|
||||
or
|
||||
|
||||
(b) for infringements caused by: (i) Your and any other third party's
|
||||
modifications of Covered Software, or (ii) the combination of its
|
||||
Contributions with other software (except as part of its Contributor
|
||||
Version); or
|
||||
|
||||
(c) under Patent Claims infringed by Covered Software in the absence of
|
||||
its Contributions.
|
||||
|
||||
This License does not grant any rights in the trademarks, service marks,
|
||||
or logos of any Contributor (except as may be necessary to comply with
|
||||
the notice requirements in Section 3.4).
|
||||
|
||||
2.4. Subsequent Licenses
|
||||
|
||||
No Contributor makes additional grants as a result of Your choice to
|
||||
distribute the Covered Software under a subsequent version of this
|
||||
License (see Section 10.2) or under the terms of a Secondary License (if
|
||||
permitted under the terms of Section 3.3).
|
||||
|
||||
2.5. Representation
|
||||
|
||||
Each Contributor represents that the Contributor believes its
|
||||
Contributions are its original creation(s) or it has sufficient rights
|
||||
to grant the rights to its Contributions conveyed by this License.
|
||||
|
||||
2.6. Fair Use
|
||||
|
||||
This License is not intended to limit any rights You have under
|
||||
applicable copyright doctrines of fair use, fair dealing, or other
|
||||
equivalents.
|
||||
|
||||
2.7. Conditions
|
||||
|
||||
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted
|
||||
in Section 2.1.
|
||||
|
||||
3. Responsibilities
|
||||
-------------------
|
||||
|
||||
3.1. Distribution of Source Form
|
||||
|
||||
All distribution of Covered Software in Source Code Form, including any
|
||||
Modifications that You create or to which You contribute, must be under
|
||||
the terms of this License. You must inform recipients that the Source
|
||||
Code Form of the Covered Software is governed by the terms of this
|
||||
License, and how they can obtain a copy of this License. You may not
|
||||
attempt to alter or restrict the recipients' rights in the Source Code
|
||||
Form.
|
||||
|
||||
3.2. Distribution of Executable Form
|
||||
|
||||
If You distribute Covered Software in Executable Form then:
|
||||
|
||||
(a) such Covered Software must also be made available in Source Code
|
||||
Form, as described in Section 3.1, and You must inform recipients of
|
||||
the Executable Form how they can obtain a copy of such Source Code
|
||||
Form by reasonable means in a timely manner, at a charge no more
|
||||
than the cost of distribution to the recipient; and
|
||||
|
||||
(b) You may distribute such Executable Form under the terms of this
|
||||
License, or sublicense it under different terms, provided that the
|
||||
license for the Executable Form does not attempt to limit or alter
|
||||
the recipients' rights in the Source Code Form under this License.
|
||||
|
||||
3.3. Distribution of a Larger Work
|
||||
|
||||
You may create and distribute a Larger Work under terms of Your choice,
|
||||
provided that You also comply with the requirements of this License for
|
||||
the Covered Software. If the Larger Work is a combination of Covered
|
||||
Software with a work governed by one or more Secondary Licenses, and the
|
||||
Covered Software is not Incompatible With Secondary Licenses, this
|
||||
License permits You to additionally distribute such Covered Software
|
||||
under the terms of such Secondary License(s), so that the recipient of
|
||||
the Larger Work may, at their option, further distribute the Covered
|
||||
Software under the terms of either this License or such Secondary
|
||||
License(s).
|
||||
|
||||
3.4. Notices
|
||||
|
||||
You may not remove or alter the substance of any license notices
|
||||
(including copyright notices, patent notices, disclaimers of warranty,
|
||||
or limitations of liability) contained within the Source Code Form of
|
||||
the Covered Software, except that You may alter any license notices to
|
||||
the extent required to remedy known factual inaccuracies.
|
||||
|
||||
3.5. Application of Additional Terms
|
||||
|
||||
You may choose to offer, and to charge a fee for, warranty, support,
|
||||
indemnity or liability obligations to one or more recipients of Covered
|
||||
Software. However, You may do so only on Your own behalf, and not on
|
||||
behalf of any Contributor. You must make it absolutely clear that any
|
||||
such warranty, support, indemnity, or liability obligation is offered by
|
||||
You alone, and You hereby agree to indemnify every Contributor for any
|
||||
liability incurred by such Contributor as a result of warranty, support,
|
||||
indemnity or liability terms You offer. You may include additional
|
||||
disclaimers of warranty and limitations of liability specific to any
|
||||
jurisdiction.
|
||||
|
||||
4. Inability to Comply Due to Statute or Regulation
|
||||
---------------------------------------------------
|
||||
|
||||
If it is impossible for You to comply with any of the terms of this
|
||||
License with respect to some or all of the Covered Software due to
|
||||
statute, judicial order, or regulation then You must: (a) comply with
|
||||
the terms of this License to the maximum extent possible; and (b)
|
||||
describe the limitations and the code they affect. Such description must
|
||||
be placed in a text file included with all distributions of the Covered
|
||||
Software under this License. Except to the extent prohibited by statute
|
||||
or regulation, such description must be sufficiently detailed for a
|
||||
recipient of ordinary skill to be able to understand it.
|
||||
|
||||
5. Termination
|
||||
--------------
|
||||
|
||||
5.1. The rights granted under this License will terminate automatically
|
||||
if You fail to comply with any of its terms. However, if You become
|
||||
compliant, then the rights granted under this License from a particular
|
||||
Contributor are reinstated (a) provisionally, unless and until such
|
||||
Contributor explicitly and finally terminates Your grants, and (b) on an
|
||||
ongoing basis, if such Contributor fails to notify You of the
|
||||
non-compliance by some reasonable means prior to 60 days after You have
|
||||
come back into compliance. Moreover, Your grants from a particular
|
||||
Contributor are reinstated on an ongoing basis if such Contributor
|
||||
notifies You of the non-compliance by some reasonable means, this is the
|
||||
first time You have received notice of non-compliance with this License
|
||||
from such Contributor, and You become compliant prior to 30 days after
|
||||
Your receipt of the notice.
|
||||
|
||||
5.2. If You initiate litigation against any entity by asserting a patent
|
||||
infringement claim (excluding declaratory judgment actions,
|
||||
counter-claims, and cross-claims) alleging that a Contributor Version
|
||||
directly or indirectly infringes any patent, then the rights granted to
|
||||
You by any and all Contributors for the Covered Software under Section
|
||||
2.1 of this License shall terminate.
|
||||
|
||||
5.3. In the event of termination under Sections 5.1 or 5.2 above, all
|
||||
end user license agreements (excluding distributors and resellers) which
|
||||
have been validly granted by You or Your distributors under this License
|
||||
prior to termination shall survive termination.
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 6. Disclaimer of Warranty *
|
||||
* ------------------------- *
|
||||
* *
|
||||
* Covered Software is provided under this License on an "as is" *
|
||||
* basis, without warranty of any kind, either expressed, implied, or *
|
||||
* statutory, including, without limitation, warranties that the *
|
||||
* Covered Software is free of defects, merchantable, fit for a *
|
||||
* particular purpose or non-infringing. The entire risk as to the *
|
||||
* quality and performance of the Covered Software is with You. *
|
||||
* Should any Covered Software prove defective in any respect, You *
|
||||
* (not any Contributor) assume the cost of any necessary servicing, *
|
||||
* repair, or correction. This disclaimer of warranty constitutes an *
|
||||
* essential part of this License. No use of any Covered Software is *
|
||||
* authorized under this License except under this disclaimer. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 7. Limitation of Liability *
|
||||
* -------------------------- *
|
||||
* *
|
||||
* Under no circumstances and under no legal theory, whether tort *
|
||||
* (including negligence), contract, or otherwise, shall any *
|
||||
* Contributor, or anyone who distributes Covered Software as *
|
||||
* permitted above, be liable to You for any direct, indirect, *
|
||||
* special, incidental, or consequential damages of any character *
|
||||
* including, without limitation, damages for lost profits, loss of *
|
||||
* goodwill, work stoppage, computer failure or malfunction, or any *
|
||||
* and all other commercial damages or losses, even if such party *
|
||||
* shall have been informed of the possibility of such damages. This *
|
||||
* limitation of liability shall not apply to liability for death or *
|
||||
* personal injury resulting from such party's negligence to the *
|
||||
* extent applicable law prohibits such limitation. Some *
|
||||
* jurisdictions do not allow the exclusion or limitation of *
|
||||
* incidental or consequential damages, so this exclusion and *
|
||||
* limitation may not apply to You. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
8. Litigation
|
||||
-------------
|
||||
|
||||
Any litigation relating to this License may be brought only in the
|
||||
courts of a jurisdiction where the defendant maintains its principal
|
||||
place of business and such litigation shall be governed by laws of that
|
||||
jurisdiction, without reference to its conflict-of-law provisions.
|
||||
Nothing in this Section shall prevent a party's ability to bring
|
||||
cross-claims or counter-claims.
|
||||
|
||||
9. Miscellaneous
|
||||
----------------
|
||||
|
||||
This License represents the complete agreement concerning the subject
|
||||
matter hereof. If any provision of this License is held to be
|
||||
unenforceable, such provision shall be reformed only to the extent
|
||||
necessary to make it enforceable. Any law or regulation which provides
|
||||
that the language of a contract shall be construed against the drafter
|
||||
shall not be used to construe this License against a Contributor.
|
||||
|
||||
10. Versions of the License
|
||||
---------------------------
|
||||
|
||||
10.1. New Versions
|
||||
|
||||
Mozilla Foundation is the license steward. Except as provided in Section
|
||||
10.3, no one other than the license steward has the right to modify or
|
||||
publish new versions of this License. Each version will be given a
|
||||
distinguishing version number.
|
||||
|
||||
10.2. Effect of New Versions
|
||||
|
||||
You may distribute the Covered Software under the terms of the version
|
||||
of the License under which You originally received the Covered Software,
|
||||
or under the terms of any subsequent version published by the license
|
||||
steward.
|
||||
|
||||
10.3. Modified Versions
|
||||
|
||||
If you create software not governed by this License, and you want to
|
||||
create a new license for such software, you may create and use a
|
||||
modified version of this License if you rename the license and remove
|
||||
any references to the name of the license steward (except to note that
|
||||
such modified license differs from this License).
|
||||
|
||||
10.4. Distributing Source Code Form that is Incompatible With Secondary
|
||||
Licenses
|
||||
|
||||
If You choose to distribute Source Code Form that is Incompatible With
|
||||
Secondary Licenses under the terms of this version of the License, the
|
||||
notice described in Exhibit B of this License must be attached.
|
||||
|
||||
Exhibit A - Source Code Form License Notice
|
||||
-------------------------------------------
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
If it is not possible or desirable to put the notice in a particular
|
||||
file, then You may include the notice in a location (such as a LICENSE
|
||||
file in a relevant directory) where a recipient would be likely to look
|
||||
for such a notice.
|
||||
|
||||
You may add additional accurate notices of copyright ownership.
|
||||
|
||||
Exhibit B - "Incompatible With Secondary Licenses" Notice
|
||||
---------------------------------------------------------
|
||||
|
||||
This Source Code Form is "Incompatible With Secondary Licenses", as
|
||||
defined by the Mozilla Public License, v. 2.0.
|
||||
BIN
Binary file not shown.
-375
@@ -1,375 +0,0 @@
|
||||
Copyright (c) 2017 HashiCorp, Inc.
|
||||
|
||||
Mozilla Public License Version 2.0
|
||||
==================================
|
||||
|
||||
1. Definitions
|
||||
--------------
|
||||
|
||||
1.1. "Contributor"
|
||||
means each individual or legal entity that creates, contributes to
|
||||
the creation of, or owns Covered Software.
|
||||
|
||||
1.2. "Contributor Version"
|
||||
means the combination of the Contributions of others (if any) used
|
||||
by a Contributor and that particular Contributor's Contribution.
|
||||
|
||||
1.3. "Contribution"
|
||||
means Covered Software of a particular Contributor.
|
||||
|
||||
1.4. "Covered Software"
|
||||
means Source Code Form to which the initial Contributor has attached
|
||||
the notice in Exhibit A, the Executable Form of such Source Code
|
||||
Form, and Modifications of such Source Code Form, in each case
|
||||
including portions thereof.
|
||||
|
||||
1.5. "Incompatible With Secondary Licenses"
|
||||
means
|
||||
|
||||
(a) that the initial Contributor has attached the notice described
|
||||
in Exhibit B to the Covered Software; or
|
||||
|
||||
(b) that the Covered Software was made available under the terms of
|
||||
version 1.1 or earlier of the License, but not also under the
|
||||
terms of a Secondary License.
|
||||
|
||||
1.6. "Executable Form"
|
||||
means any form of the work other than Source Code Form.
|
||||
|
||||
1.7. "Larger Work"
|
||||
means a work that combines Covered Software with other material, in
|
||||
a separate file or files, that is not Covered Software.
|
||||
|
||||
1.8. "License"
|
||||
means this document.
|
||||
|
||||
1.9. "Licensable"
|
||||
means having the right to grant, to the maximum extent possible,
|
||||
whether at the time of the initial grant or subsequently, any and
|
||||
all of the rights conveyed by this License.
|
||||
|
||||
1.10. "Modifications"
|
||||
means any of the following:
|
||||
|
||||
(a) any file in Source Code Form that results from an addition to,
|
||||
deletion from, or modification of the contents of Covered
|
||||
Software; or
|
||||
|
||||
(b) any new file in Source Code Form that contains any Covered
|
||||
Software.
|
||||
|
||||
1.11. "Patent Claims" of a Contributor
|
||||
means any patent claim(s), including without limitation, method,
|
||||
process, and apparatus claims, in any patent Licensable by such
|
||||
Contributor that would be infringed, but for the grant of the
|
||||
License, by the making, using, selling, offering for sale, having
|
||||
made, import, or transfer of either its Contributions or its
|
||||
Contributor Version.
|
||||
|
||||
1.12. "Secondary License"
|
||||
means either the GNU General Public License, Version 2.0, the GNU
|
||||
Lesser General Public License, Version 2.1, the GNU Affero General
|
||||
Public License, Version 3.0, or any later versions of those
|
||||
licenses.
|
||||
|
||||
1.13. "Source Code Form"
|
||||
means the form of the work preferred for making modifications.
|
||||
|
||||
1.14. "You" (or "Your")
|
||||
means an individual or a legal entity exercising rights under this
|
||||
License. For legal entities, "You" includes any entity that
|
||||
controls, is controlled by, or is under common control with You. For
|
||||
purposes of this definition, "control" means (a) the power, direct
|
||||
or indirect, to cause the direction or management of such entity,
|
||||
whether by contract or otherwise, or (b) ownership of more than
|
||||
fifty percent (50%) of the outstanding shares or beneficial
|
||||
ownership of such entity.
|
||||
|
||||
2. License Grants and Conditions
|
||||
--------------------------------
|
||||
|
||||
2.1. Grants
|
||||
|
||||
Each Contributor hereby grants You a world-wide, royalty-free,
|
||||
non-exclusive license:
|
||||
|
||||
(a) under intellectual property rights (other than patent or trademark)
|
||||
Licensable by such Contributor to use, reproduce, make available,
|
||||
modify, display, perform, distribute, and otherwise exploit its
|
||||
Contributions, either on an unmodified basis, with Modifications, or
|
||||
as part of a Larger Work; and
|
||||
|
||||
(b) under Patent Claims of such Contributor to make, use, sell, offer
|
||||
for sale, have made, import, and otherwise transfer either its
|
||||
Contributions or its Contributor Version.
|
||||
|
||||
2.2. Effective Date
|
||||
|
||||
The licenses granted in Section 2.1 with respect to any Contribution
|
||||
become effective for each Contribution on the date the Contributor first
|
||||
distributes such Contribution.
|
||||
|
||||
2.3. Limitations on Grant Scope
|
||||
|
||||
The licenses granted in this Section 2 are the only rights granted under
|
||||
this License. No additional rights or licenses will be implied from the
|
||||
distribution or licensing of Covered Software under this License.
|
||||
Notwithstanding Section 2.1(b) above, no patent license is granted by a
|
||||
Contributor:
|
||||
|
||||
(a) for any code that a Contributor has removed from Covered Software;
|
||||
or
|
||||
|
||||
(b) for infringements caused by: (i) Your and any other third party's
|
||||
modifications of Covered Software, or (ii) the combination of its
|
||||
Contributions with other software (except as part of its Contributor
|
||||
Version); or
|
||||
|
||||
(c) under Patent Claims infringed by Covered Software in the absence of
|
||||
its Contributions.
|
||||
|
||||
This License does not grant any rights in the trademarks, service marks,
|
||||
or logos of any Contributor (except as may be necessary to comply with
|
||||
the notice requirements in Section 3.4).
|
||||
|
||||
2.4. Subsequent Licenses
|
||||
|
||||
No Contributor makes additional grants as a result of Your choice to
|
||||
distribute the Covered Software under a subsequent version of this
|
||||
License (see Section 10.2) or under the terms of a Secondary License (if
|
||||
permitted under the terms of Section 3.3).
|
||||
|
||||
2.5. Representation
|
||||
|
||||
Each Contributor represents that the Contributor believes its
|
||||
Contributions are its original creation(s) or it has sufficient rights
|
||||
to grant the rights to its Contributions conveyed by this License.
|
||||
|
||||
2.6. Fair Use
|
||||
|
||||
This License is not intended to limit any rights You have under
|
||||
applicable copyright doctrines of fair use, fair dealing, or other
|
||||
equivalents.
|
||||
|
||||
2.7. Conditions
|
||||
|
||||
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted
|
||||
in Section 2.1.
|
||||
|
||||
3. Responsibilities
|
||||
-------------------
|
||||
|
||||
3.1. Distribution of Source Form
|
||||
|
||||
All distribution of Covered Software in Source Code Form, including any
|
||||
Modifications that You create or to which You contribute, must be under
|
||||
the terms of this License. You must inform recipients that the Source
|
||||
Code Form of the Covered Software is governed by the terms of this
|
||||
License, and how they can obtain a copy of this License. You may not
|
||||
attempt to alter or restrict the recipients' rights in the Source Code
|
||||
Form.
|
||||
|
||||
3.2. Distribution of Executable Form
|
||||
|
||||
If You distribute Covered Software in Executable Form then:
|
||||
|
||||
(a) such Covered Software must also be made available in Source Code
|
||||
Form, as described in Section 3.1, and You must inform recipients of
|
||||
the Executable Form how they can obtain a copy of such Source Code
|
||||
Form by reasonable means in a timely manner, at a charge no more
|
||||
than the cost of distribution to the recipient; and
|
||||
|
||||
(b) You may distribute such Executable Form under the terms of this
|
||||
License, or sublicense it under different terms, provided that the
|
||||
license for the Executable Form does not attempt to limit or alter
|
||||
the recipients' rights in the Source Code Form under this License.
|
||||
|
||||
3.3. Distribution of a Larger Work
|
||||
|
||||
You may create and distribute a Larger Work under terms of Your choice,
|
||||
provided that You also comply with the requirements of this License for
|
||||
the Covered Software. If the Larger Work is a combination of Covered
|
||||
Software with a work governed by one or more Secondary Licenses, and the
|
||||
Covered Software is not Incompatible With Secondary Licenses, this
|
||||
License permits You to additionally distribute such Covered Software
|
||||
under the terms of such Secondary License(s), so that the recipient of
|
||||
the Larger Work may, at their option, further distribute the Covered
|
||||
Software under the terms of either this License or such Secondary
|
||||
License(s).
|
||||
|
||||
3.4. Notices
|
||||
|
||||
You may not remove or alter the substance of any license notices
|
||||
(including copyright notices, patent notices, disclaimers of warranty,
|
||||
or limitations of liability) contained within the Source Code Form of
|
||||
the Covered Software, except that You may alter any license notices to
|
||||
the extent required to remedy known factual inaccuracies.
|
||||
|
||||
3.5. Application of Additional Terms
|
||||
|
||||
You may choose to offer, and to charge a fee for, warranty, support,
|
||||
indemnity or liability obligations to one or more recipients of Covered
|
||||
Software. However, You may do so only on Your own behalf, and not on
|
||||
behalf of any Contributor. You must make it absolutely clear that any
|
||||
such warranty, support, indemnity, or liability obligation is offered by
|
||||
You alone, and You hereby agree to indemnify every Contributor for any
|
||||
liability incurred by such Contributor as a result of warranty, support,
|
||||
indemnity or liability terms You offer. You may include additional
|
||||
disclaimers of warranty and limitations of liability specific to any
|
||||
jurisdiction.
|
||||
|
||||
4. Inability to Comply Due to Statute or Regulation
|
||||
---------------------------------------------------
|
||||
|
||||
If it is impossible for You to comply with any of the terms of this
|
||||
License with respect to some or all of the Covered Software due to
|
||||
statute, judicial order, or regulation then You must: (a) comply with
|
||||
the terms of this License to the maximum extent possible; and (b)
|
||||
describe the limitations and the code they affect. Such description must
|
||||
be placed in a text file included with all distributions of the Covered
|
||||
Software under this License. Except to the extent prohibited by statute
|
||||
or regulation, such description must be sufficiently detailed for a
|
||||
recipient of ordinary skill to be able to understand it.
|
||||
|
||||
5. Termination
|
||||
--------------
|
||||
|
||||
5.1. The rights granted under this License will terminate automatically
|
||||
if You fail to comply with any of its terms. However, if You become
|
||||
compliant, then the rights granted under this License from a particular
|
||||
Contributor are reinstated (a) provisionally, unless and until such
|
||||
Contributor explicitly and finally terminates Your grants, and (b) on an
|
||||
ongoing basis, if such Contributor fails to notify You of the
|
||||
non-compliance by some reasonable means prior to 60 days after You have
|
||||
come back into compliance. Moreover, Your grants from a particular
|
||||
Contributor are reinstated on an ongoing basis if such Contributor
|
||||
notifies You of the non-compliance by some reasonable means, this is the
|
||||
first time You have received notice of non-compliance with this License
|
||||
from such Contributor, and You become compliant prior to 30 days after
|
||||
Your receipt of the notice.
|
||||
|
||||
5.2. If You initiate litigation against any entity by asserting a patent
|
||||
infringement claim (excluding declaratory judgment actions,
|
||||
counter-claims, and cross-claims) alleging that a Contributor Version
|
||||
directly or indirectly infringes any patent, then the rights granted to
|
||||
You by any and all Contributors for the Covered Software under Section
|
||||
2.1 of this License shall terminate.
|
||||
|
||||
5.3. In the event of termination under Sections 5.1 or 5.2 above, all
|
||||
end user license agreements (excluding distributors and resellers) which
|
||||
have been validly granted by You or Your distributors under this License
|
||||
prior to termination shall survive termination.
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 6. Disclaimer of Warranty *
|
||||
* ------------------------- *
|
||||
* *
|
||||
* Covered Software is provided under this License on an "as is" *
|
||||
* basis, without warranty of any kind, either expressed, implied, or *
|
||||
* statutory, including, without limitation, warranties that the *
|
||||
* Covered Software is free of defects, merchantable, fit for a *
|
||||
* particular purpose or non-infringing. The entire risk as to the *
|
||||
* quality and performance of the Covered Software is with You. *
|
||||
* Should any Covered Software prove defective in any respect, You *
|
||||
* (not any Contributor) assume the cost of any necessary servicing, *
|
||||
* repair, or correction. This disclaimer of warranty constitutes an *
|
||||
* essential part of this License. No use of any Covered Software is *
|
||||
* authorized under this License except under this disclaimer. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 7. Limitation of Liability *
|
||||
* -------------------------- *
|
||||
* *
|
||||
* Under no circumstances and under no legal theory, whether tort *
|
||||
* (including negligence), contract, or otherwise, shall any *
|
||||
* Contributor, or anyone who distributes Covered Software as *
|
||||
* permitted above, be liable to You for any direct, indirect, *
|
||||
* special, incidental, or consequential damages of any character *
|
||||
* including, without limitation, damages for lost profits, loss of *
|
||||
* goodwill, work stoppage, computer failure or malfunction, or any *
|
||||
* and all other commercial damages or losses, even if such party *
|
||||
* shall have been informed of the possibility of such damages. This *
|
||||
* limitation of liability shall not apply to liability for death or *
|
||||
* personal injury resulting from such party's negligence to the *
|
||||
* extent applicable law prohibits such limitation. Some *
|
||||
* jurisdictions do not allow the exclusion or limitation of *
|
||||
* incidental or consequential damages, so this exclusion and *
|
||||
* limitation may not apply to You. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
8. Litigation
|
||||
-------------
|
||||
|
||||
Any litigation relating to this License may be brought only in the
|
||||
courts of a jurisdiction where the defendant maintains its principal
|
||||
place of business and such litigation shall be governed by laws of that
|
||||
jurisdiction, without reference to its conflict-of-law provisions.
|
||||
Nothing in this Section shall prevent a party's ability to bring
|
||||
cross-claims or counter-claims.
|
||||
|
||||
9. Miscellaneous
|
||||
----------------
|
||||
|
||||
This License represents the complete agreement concerning the subject
|
||||
matter hereof. If any provision of this License is held to be
|
||||
unenforceable, such provision shall be reformed only to the extent
|
||||
necessary to make it enforceable. Any law or regulation which provides
|
||||
that the language of a contract shall be construed against the drafter
|
||||
shall not be used to construe this License against a Contributor.
|
||||
|
||||
10. Versions of the License
|
||||
---------------------------
|
||||
|
||||
10.1. New Versions
|
||||
|
||||
Mozilla Foundation is the license steward. Except as provided in Section
|
||||
10.3, no one other than the license steward has the right to modify or
|
||||
publish new versions of this License. Each version will be given a
|
||||
distinguishing version number.
|
||||
|
||||
10.2. Effect of New Versions
|
||||
|
||||
You may distribute the Covered Software under the terms of the version
|
||||
of the License under which You originally received the Covered Software,
|
||||
or under the terms of any subsequent version published by the license
|
||||
steward.
|
||||
|
||||
10.3. Modified Versions
|
||||
|
||||
If you create software not governed by this License, and you want to
|
||||
create a new license for such software, you may create and use a
|
||||
modified version of this License if you rename the license and remove
|
||||
any references to the name of the license steward (except to note that
|
||||
such modified license differs from this License).
|
||||
|
||||
10.4. Distributing Source Code Form that is Incompatible With Secondary
|
||||
Licenses
|
||||
|
||||
If You choose to distribute Source Code Form that is Incompatible With
|
||||
Secondary Licenses under the terms of this version of the License, the
|
||||
notice described in Exhibit B of this License must be attached.
|
||||
|
||||
Exhibit A - Source Code Form License Notice
|
||||
-------------------------------------------
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
If it is not possible or desirable to put the notice in a particular
|
||||
file, then You may include the notice in a location (such as a LICENSE
|
||||
file in a relevant directory) where a recipient would be likely to look
|
||||
for such a notice.
|
||||
|
||||
You may add additional accurate notices of copyright ownership.
|
||||
|
||||
Exhibit B - "Incompatible With Secondary Licenses" Notice
|
||||
---------------------------------------------------------
|
||||
|
||||
This Source Code Form is "Incompatible With Secondary Licenses", as
|
||||
defined by the Mozilla Public License, v. 2.0.
|
||||
BIN
Binary file not shown.
@@ -1,218 +0,0 @@
|
||||
# Longhorn StorageClass + PVC Terraform Import — Execution Guide
|
||||
|
||||
## Overview
|
||||
|
||||
Moving Longhorn StorageClasses and app PVCs from Helm/chart-owned to Terraform-managed state. **Import-only, no delete/recreate.** Zero data-loss tolerance. Production data: Postgres, Kafka, MinIO, Loki.
|
||||
|
||||
**Terraform now owns:** namespaces, bootstrap Helm releases, StorageClasses. **ArgoCD now owns:** workload Helm releases (grafana, loki, minio, portainer, forgejo, kafka, prometheus, ddb, ollama, etc.). This matches the in-progress Terraform+ArgoCD migration.
|
||||
|
||||
**Explicit exclusion:** `llm` namespace / `ollama` / `longhorn-llm` SC — managed under separate state (`~/workplace/agents/infra/terraform/`).
|
||||
|
||||
## Prerequisite
|
||||
|
||||
- Cluster access + kubectl configured: `kubectl cluster-info` succeeds
|
||||
- Terraform credentials: state backend (MinIO) reachable
|
||||
- ArgoCD CLI (for Phase 0 reconciliation only)
|
||||
- Helm CLI (for helmfile operations, Phase 2)
|
||||
|
||||
## Execution: 4 Phases
|
||||
|
||||
### Phase 0 — Cluster Reconciliation (read-only, ~10 min)
|
||||
|
||||
Resolve three ownership ambiguities before importing.
|
||||
|
||||
```bash
|
||||
cd terraform/scripts
|
||||
bash phase-0-reconciliation.sh
|
||||
```
|
||||
|
||||
**Output:** Review findings for:
|
||||
1. **minio (storage)**: Is Helm release (`terraform/minio.tf`) or Operator `Tenant` CR authoritative?
|
||||
2. **kmsvc-redis**: Is helmfile release or ArgoCD Application active?
|
||||
3. **forgejo-runner**: Is Helm chart or raw manifest (`k8s/forge/runner.yaml`) applied?
|
||||
|
||||
**Document results.** Proceed to Phase 1 regardless; Phase 0 just informs which conditional apps to import in Phase 2.
|
||||
|
||||
### Phase 1 — StorageClass Import (~5 min)
|
||||
|
||||
Import `longhorn` (cluster default) and `longhorn-kafka` (Kafka-specific) to Terraform state.
|
||||
|
||||
```bash
|
||||
cd terraform/scripts
|
||||
bash phase-1-storageclass-import.sh
|
||||
```
|
||||
|
||||
**Workflow:**
|
||||
1. Captures live spec via `kubectl get sc`
|
||||
2. **MANUAL:** Verify `terraform/longhorn.tf` resource blocks match captured specs
|
||||
3. `terraform import` both SCs one at a time
|
||||
4. `terraform plan` must show `0 to add, 0 to change, 0 to destroy` after each import
|
||||
5. Annotates `longhorn-kafka` with `helm.sh/resource-policy=keep` (protects from Helm deletion on next upgrade)
|
||||
|
||||
**Rollback:** `terraform state rm kubernetes_storage_class.longhorn` (state-only, safe)
|
||||
|
||||
### Phase 2 Pilot — Grafana PVC (~15 min)
|
||||
|
||||
Lowest-risk pilot: dashboards/config, re-creatable from values-based provisioning. Validates entire import workflow before rolling to other apps.
|
||||
|
||||
```bash
|
||||
cd terraform/scripts
|
||||
bash phase-2-pilot-grafana.sh
|
||||
```
|
||||
|
||||
**Workflow:**
|
||||
1. Annotate live PVC: `helm.sh/resource-policy=keep` (protects from Helm deletion)
|
||||
2. Capture live PVC spec (`kubectl get pvc -o yaml`)
|
||||
3. **MANUAL:** Update `terraform/grafana.tf` with actual PV name
|
||||
4. `terraform import` to state
|
||||
5. `terraform plan` must show zero diff
|
||||
6. **MANUAL:** Update `k8s/logging/grafana-values.yaml`:
|
||||
```yaml
|
||||
persistence:
|
||||
existingClaim: grafana
|
||||
enabled: false
|
||||
```
|
||||
(Or keep identical if chart doesn't support `existingClaim`)
|
||||
7. `helmfile diff` to confirm no delete/replace queued
|
||||
8. `helmfile apply` to reconcile
|
||||
9. Verify Longhorn replica health unchanged
|
||||
10. `terraform plan` again, must still be zero diff
|
||||
|
||||
**Phase gate:** Don't proceed to remaining apps until grafana cycle completes cleanly.
|
||||
|
||||
**Rollback:** `terraform state rm kubernetes_persistent_volume_claim.grafana` (state-only, safe)
|
||||
|
||||
### Phase 2 Remaining Apps (~45 min)
|
||||
|
||||
Repeat pilot workflow for: **portainer** → **dev-tools** → **loki** → **minio-logging** → **forgejo**.
|
||||
|
||||
```bash
|
||||
cd terraform/scripts
|
||||
bash phase-2-remaining-apps.sh
|
||||
```
|
||||
|
||||
Script guides through each app in sequence. **Manual steps** for each:
|
||||
- Verify Terraform resource block matches live PVC spec
|
||||
- Update chart values to use `existingClaim` (if supported) or keep identical
|
||||
- Confirm `helmfile diff` shows no destructive ops
|
||||
- Confirm Longhorn replica health matches baseline
|
||||
|
||||
**Ascending risk order:**
|
||||
- portainer: low (UI config, re-creatable)
|
||||
- dev-tools: low (sandbox state, expendable)
|
||||
- loki: medium (log history, valuable but not critical)
|
||||
- minio-logging: medium (Loki chunks, important but backed up elsewhere)
|
||||
- forgejo: high (Git repos, CI history — real data loss risk)
|
||||
|
||||
**Conditional apps — resolve Phase 0 ambiguities first:**
|
||||
- minio (storage): if standalone chart is authoritative, not Tenant CR
|
||||
- kmsvc-redis: if helmfile release is authoritative, architecture is standalone (not Sentinel)
|
||||
- forgejo-runner: if Helm chart is authoritative, not raw manifest
|
||||
|
||||
**Never import** (StatefulSet/operator-managed, dual-controller risk):
|
||||
- ddb-cluster (CNPG operator owns PVC lifecycle)
|
||||
- prometheus (Prometheus Operator `storageSpec.volumeClaimTemplate`)
|
||||
- kafka-cluster (StatefulSet `volumeClaimTemplates`)
|
||||
- authentik-postgresql (likely sub-chart StatefulSet VCT)
|
||||
- llm namespace (separate Terraform state)
|
||||
|
||||
## Rollback at Any Point
|
||||
|
||||
**State-only backout (safe, touches nothing live):**
|
||||
```bash
|
||||
terraform state rm kubernetes_storage_class.longhorn
|
||||
terraform state rm kubernetes_persistent_volume_claim.grafana
|
||||
```
|
||||
|
||||
**Remove Helm protection annotation (only if abandoning import):**
|
||||
```bash
|
||||
kubectl annotate pvc grafana -n logging helm.sh/resource-policy- --overwrite
|
||||
```
|
||||
|
||||
## Verification Gateways
|
||||
|
||||
After every import + values change:
|
||||
|
||||
1. **Terraform plan is clean:**
|
||||
```bash
|
||||
terraform plan # must show "0 to add, 0 to change, 0 to destroy"
|
||||
```
|
||||
|
||||
2. **Longhorn replica health unchanged:**
|
||||
```bash
|
||||
# Before starting each app:
|
||||
k get longhorn-volume -n longhorn-system <pv-name> -o json | jq '.status.replicaStatus'
|
||||
# After helmfile apply, must be identical
|
||||
```
|
||||
|
||||
3. **No destructive ops queued:**
|
||||
```bash
|
||||
helmfile -f helmfile.yaml.gotmpl -l name=<app> diff # no delete/replace on PVC
|
||||
```
|
||||
|
||||
## Defense-in-Depth Safety Layers
|
||||
|
||||
1. **`helm.sh/resource-policy: keep` annotation** on every PVC/SC — blocks Helm from ever deleting even if removed from template
|
||||
2. **`lifecycle { prevent_destroy = true }`** on every Terraform PVC resource — hard-errors any destroy/removal instead of deleting live data
|
||||
3. **`terraform plan` gates** — nonzero diff = stop, fix or `state rm`, never force-apply against diff
|
||||
4. **`helmfile diff` before apply** — confirm no destructive ops queued
|
||||
5. **Longhorn replica-health baseline + re-check** — any drop in healthy replicas = hard stop
|
||||
6. **Rollback is always `terraform state rm`** — state-only, never touches live objects
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### terraform plan shows diff after import
|
||||
|
||||
**Common causes:**
|
||||
- `volumeName` missing or wrong (required for bound PVC)
|
||||
- `storage` unit normalization (5Gi vs 5368709120)
|
||||
- Missing `resources.limits`
|
||||
- `accessModes` array order
|
||||
|
||||
**Fix:** Adjust `terraform/<app>.tf` to match `kubectl get pvc -o yaml`, re-run `terraform plan`.
|
||||
|
||||
### helmfile diff shows delete/replace on PVC
|
||||
|
||||
**Cause:** Values change triggered Helm to re-template PVC; either values still match live and Helm shouldn't see diff, or the `existingClaim` change wasn't correct.
|
||||
|
||||
**Fix:** Verify values match live spec exactly, or rollback the values change. If problem persists, ensure `helm.sh/resource-policy: keep` annotation is present: `kubectl get pvc <name> -n <ns> -o jsonpath='{.metadata.annotations}'`
|
||||
|
||||
### Longhorn replica count drops
|
||||
|
||||
**Cause:** Import or helmfile apply somehow triggered a Longhorn reconciliation that affected replica status.
|
||||
|
||||
**Fix:** Do not proceed. Investigate Longhorn health manually (`kubectl get longhorn-volume -n longhorn-system <vol> -o json`). Rollback import with `terraform state rm`, revert values changes, re-annotate with `helm.sh/resource-policy=keep`. Wait for replicas to recover, then retry.
|
||||
|
||||
## Commit & PR
|
||||
|
||||
Once all phases complete:
|
||||
|
||||
```bash
|
||||
cd /path/to/homelab
|
||||
git add terraform/longhorn.tf terraform/grafana.tf terraform/portainer.tf terraform/loki.tf terraform/dev-tools.tf terraform/minio-logging.tf terraform/forgejo.tf
|
||||
git add k8s/logging/grafana-values.yaml k8s/dashboard/portainer-values.yaml k8s/dev-tools/values.yaml k8s/logging/loki-values.yaml k8s/cicd/forgejo-values.yaml
|
||||
git commit -m "feat(terraform): import Longhorn StorageClasses and app PVCs to Terraform state
|
||||
|
||||
- Phase 1: longhorn, longhorn-kafka StorageClasses (cluster-wide defaults, app-specific)
|
||||
- Phase 2: grafana, portainer, dev-tools, loki, minio-logging, forgejo PVCs
|
||||
- Update chart values to use existingClaim or keep identical (no dual-ownership)
|
||||
- All imports protected by helm.sh/resource-policy=keep + prevent_destroy lifecycle
|
||||
- Longhorn replica health verified throughout, zero data loss
|
||||
- See terraform/LONGHORN_PVC_IMPORT.md for execution record"
|
||||
|
||||
git push origin <branch>
|
||||
```
|
||||
|
||||
Create PR with description referencing this guide.
|
||||
|
||||
## Reference
|
||||
|
||||
- **Plan file:** `terraform/no-delete-only-import-buzzing-gray.md` (archived plan, for reference)
|
||||
- **Scripts:** `terraform/scripts/phase-*.sh`
|
||||
- **Terraform resources:** `terraform/longhorn.tf`, `terraform/grafana.tf`, `terraform/portainer.tf`, `terraform/loki.tf`, `terraform/dev-tools.tf`, `terraform/minio-logging.tf`, `terraform/forgejo.tf`
|
||||
- **Longhorn health command:** (from CLAUDE.md) `k get longhorn-volume -n longhorn-system <vol> -o json | jq '.status.replicaStatus'`
|
||||
- **Hard rule:** Never manually delete a PVC without verified replicas/backups (CLAUDE.md)
|
||||
|
||||
---
|
||||
|
||||
**Last updated:** 2026-07-15
|
||||
@@ -1,241 +0,0 @@
|
||||
resource "kubernetes_namespace" "argocd" {
|
||||
metadata {
|
||||
name = "argocd"
|
||||
labels = {
|
||||
"pod-security.kubernetes.io/enforce" = "baseline"
|
||||
"pod-security.kubernetes.io/enforce-version" = "latest"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# Copy homelab-ca-secret from cert-manager to argocd namespace
|
||||
# (Required for repo-server pod to verify self-signed forgejo TLS)
|
||||
resource "null_resource" "copy_ca_secret_to_argocd" {
|
||||
provisioner "local-exec" {
|
||||
command = <<-EOT
|
||||
kubectl get secret homelab-ca-secret -n cert-manager -o yaml | \
|
||||
sed 's/namespace: cert-manager/namespace: argocd/' | \
|
||||
kubectl apply -f -
|
||||
EOT
|
||||
}
|
||||
|
||||
depends_on = [
|
||||
kubernetes_namespace.argocd
|
||||
]
|
||||
}
|
||||
|
||||
resource "helm_release" "argocd" {
|
||||
name = "argocd"
|
||||
repository = local.helm_repos["argo"]
|
||||
chart = "argo-cd"
|
||||
version = "7.3.3"
|
||||
namespace = kubernetes_namespace.argocd.metadata[0].name
|
||||
|
||||
values = [
|
||||
yamlencode({
|
||||
global = {
|
||||
domain = "argocd.${var.cluster_domain}"
|
||||
}
|
||||
configs = {
|
||||
params = {
|
||||
"application.instanceLabelKey" = "argocd.argoproj.io/instance"
|
||||
}
|
||||
rbac = {
|
||||
"policy.default" = "role:readonly"
|
||||
}
|
||||
cmp = {
|
||||
create = true
|
||||
plugins = {
|
||||
sops = {
|
||||
allowConcurrency = false
|
||||
discover = {
|
||||
fileName = "*.enc.yaml"
|
||||
}
|
||||
generate = {
|
||||
command = ["sh", "-c"]
|
||||
args = ["sops -d \"$ARGOCD_ENV_FILE_PATH\""]
|
||||
}
|
||||
lockRepo = false
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
server = {
|
||||
extraArgs = [
|
||||
"--tls-cert-file=/etc/argocd/server.crt",
|
||||
"--tls-key-file=/etc/argocd/server.key"
|
||||
]
|
||||
ingress = {
|
||||
enabled = true
|
||||
hosts = [
|
||||
"argocd.${var.cluster_domain}"
|
||||
]
|
||||
annotations = {
|
||||
"nginx.ingress.kubernetes.io/backend-protocol" = "HTTPS"
|
||||
}
|
||||
ingressClassName = "nginx"
|
||||
}
|
||||
service = {
|
||||
type = "ClusterIP"
|
||||
port = 443
|
||||
}
|
||||
volumeMounts = [
|
||||
{
|
||||
name = "server-tls"
|
||||
mountPath = "/etc/argocd"
|
||||
readOnly = true
|
||||
}
|
||||
]
|
||||
}
|
||||
repoServer = {
|
||||
autoscaling = {
|
||||
enabled = true
|
||||
minReplicas = 2
|
||||
}
|
||||
env = [
|
||||
{
|
||||
name = "GIT_SSL_CAINFO"
|
||||
value = "/etc/ssl/certs/homelab-ca.crt"
|
||||
},
|
||||
{
|
||||
name = "SOPS_AGE_KEY_FILE"
|
||||
value = "/home/argocd/.sops/keys.txt"
|
||||
}
|
||||
]
|
||||
volumes = [
|
||||
{
|
||||
name = "homelab-ca"
|
||||
secret = {
|
||||
secretName = "homelab-ca-secret"
|
||||
}
|
||||
},
|
||||
{
|
||||
name = "sops-age"
|
||||
secret = {
|
||||
secretName = "sops-age"
|
||||
defaultMode = 384
|
||||
}
|
||||
}
|
||||
]
|
||||
volumeMounts = [
|
||||
{
|
||||
name = "homelab-ca"
|
||||
mountPath = "/etc/ssl/certs/homelab-ca.crt"
|
||||
subPath = "tls.crt"
|
||||
},
|
||||
{
|
||||
name = "sops-age"
|
||||
mountPath = "/home/argocd/.sops"
|
||||
readOnly = true
|
||||
}
|
||||
]
|
||||
}
|
||||
volumes = [
|
||||
{
|
||||
name = "server-tls"
|
||||
secret = {
|
||||
secretName = "homelab-tls"
|
||||
defaultMode = 420
|
||||
}
|
||||
}
|
||||
]
|
||||
controller = {
|
||||
replicas = 2
|
||||
}
|
||||
})
|
||||
]
|
||||
|
||||
depends_on = [
|
||||
kubernetes_namespace.argocd,
|
||||
null_resource.copy_ca_secret_to_argocd
|
||||
]
|
||||
|
||||
# Note: lifecycle.ignore_changes removed to allow CA cert update
|
||||
# This allows TF to inject the homelab-ca-secret for TLS verification
|
||||
}
|
||||
|
||||
resource "kubernetes_manifest" "argocd_project" {
|
||||
manifest = {
|
||||
apiVersion = "argoproj.io/v1alpha1"
|
||||
kind = "AppProject"
|
||||
metadata = {
|
||||
name = "homelab"
|
||||
namespace = kubernetes_namespace.argocd.metadata[0].name
|
||||
}
|
||||
spec = {
|
||||
sourceRepos = [
|
||||
"https://forgejo.riotpiao.homelab.com/riotpiao.com/*",
|
||||
"https://charts.goauthentik.io",
|
||||
"https://prometheus-community.github.io/helm-charts",
|
||||
"https://grafana.github.io/helm-charts",
|
||||
"https://grafana.github.io/loki/charts",
|
||||
"https://charts.min.io/",
|
||||
"https://strimzi.io/charts/",
|
||||
"https://open-telemetry.github.io/opentelemetry-helm-charts"
|
||||
]
|
||||
destinations = [
|
||||
{
|
||||
server = "https://kubernetes.default.svc"
|
||||
namespace = "*"
|
||||
}
|
||||
]
|
||||
clusterResourceWhitelist = [
|
||||
{
|
||||
group = "*"
|
||||
kind = "*"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
field_manager {
|
||||
name = "terraform"
|
||||
}
|
||||
|
||||
depends_on = [
|
||||
helm_release.argocd
|
||||
]
|
||||
}
|
||||
|
||||
resource "kubernetes_manifest" "argocd_root_app" {
|
||||
manifest = {
|
||||
apiVersion = "argoproj.io/v1alpha1"
|
||||
kind = "Application"
|
||||
metadata = {
|
||||
name = "homelab-root"
|
||||
namespace = kubernetes_namespace.argocd.metadata[0].name
|
||||
}
|
||||
spec = {
|
||||
project = kubernetes_manifest.argocd_project.manifest.metadata.name
|
||||
source = {
|
||||
repoURL = "https://forgejo.riotpiao.homelab.com/riotpiao.com/homelab.git"
|
||||
targetRevision = "main"
|
||||
path = "k8s/argocd/apps"
|
||||
directory = {
|
||||
recurse = true
|
||||
}
|
||||
}
|
||||
destination = {
|
||||
server = "https://kubernetes.default.svc"
|
||||
namespace = kubernetes_namespace.argocd.metadata[0].name
|
||||
}
|
||||
syncPolicy = {
|
||||
automated = {
|
||||
prune = true
|
||||
selfHeal = true
|
||||
}
|
||||
syncOptions = [
|
||||
"CreateNamespace=true"
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
field_manager {
|
||||
name = "terraform"
|
||||
}
|
||||
|
||||
depends_on = [
|
||||
kubernetes_manifest.argocd_project
|
||||
]
|
||||
}
|
||||
@@ -1,9 +0,0 @@
|
||||
# Authentik provider — resources imported from live cluster.
|
||||
# Resource bodies generated via `terraform plan -generate-config-out`
|
||||
# into authentik-generated.tf. Import mappings in authentik-imports.tf.
|
||||
# Token: terraform.tfvars.local as authentik_api_token (sensitive).
|
||||
|
||||
provider "authentik" {
|
||||
url = "https://authentik.${var.cluster_domain}"
|
||||
token = var.authentik_api_token
|
||||
}
|
||||
@@ -1,418 +0,0 @@
|
||||
# __generated__ by Terraform
|
||||
# Please review these resources and move them into your main configuration files.
|
||||
|
||||
# __generated__ by Terraform from "4"
|
||||
resource "authentik_user" "akadmin" {
|
||||
attributes = jsonencode({
|
||||
settings = {
|
||||
locale = ""
|
||||
}
|
||||
})
|
||||
email = "[email protected]"
|
||||
groups = ["9d72cbf2-9d52-4d3c-bba9-0068525d7a91", "5f2e1e79-7d7e-4ef0-9b99-3c6df19c0b88", "e640d887-eb85-431b-b5b2-5b6a8a7e0a44", "22a3c296-0d98-433f-8456-ebc2f1c8d489", "4084c8d6-0c12-46af-acf8-7372172b9016", "cbd8ce0d-c364-47a2-976c-c93211175b83"]
|
||||
is_active = true
|
||||
name = "authentik Default Admin"
|
||||
password = null # sensitive
|
||||
path = "users"
|
||||
type = "internal"
|
||||
username = "akadmin"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "9d72cbf2-9d52-4d3c-bba9-0068525d7a91"
|
||||
resource "authentik_group" "authentik_admins" {
|
||||
attributes = jsonencode({})
|
||||
is_superuser = true
|
||||
name = "authentik Admins"
|
||||
parent = null
|
||||
roles = null
|
||||
users = [5, 4, 38]
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "5"
|
||||
resource "authentik_user" "riotpiao" {
|
||||
attributes = jsonencode({})
|
||||
email = "[email protected]"
|
||||
groups = ["9d72cbf2-9d52-4d3c-bba9-0068525d7a91", "5f2e1e79-7d7e-4ef0-9b99-3c6df19c0b88", "e640d887-eb85-431b-b5b2-5b6a8a7e0a44", "22a3c296-0d98-433f-8456-ebc2f1c8d489", "4084c8d6-0c12-46af-acf8-7372172b9016", "cbd8ce0d-c364-47a2-976c-c93211175b83"]
|
||||
is_active = true
|
||||
name = "rock"
|
||||
password = null # sensitive
|
||||
path = "users"
|
||||
type = "internal"
|
||||
username = "riotpiao"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "e640d887-eb85-431b-b5b2-5b6a8a7e0a44"
|
||||
resource "authentik_group" "minio_admins" {
|
||||
attributes = jsonencode({})
|
||||
is_superuser = false
|
||||
name = "minio-admins"
|
||||
parent = null
|
||||
roles = null
|
||||
users = [5, 4]
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "38"
|
||||
resource "authentik_user" "core_cli" {
|
||||
attributes = jsonencode({})
|
||||
email = "[email protected]"
|
||||
groups = []
|
||||
is_active = true
|
||||
name = "Core CLI (scoped)"
|
||||
password = null # sensitive
|
||||
path = "users"
|
||||
type = "internal"
|
||||
username = "core-cli"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "5f2e1e79-7d7e-4ef0-9b99-3c6df19c0b88"
|
||||
resource "authentik_group" "grafana_admins" {
|
||||
attributes = jsonencode({})
|
||||
is_superuser = false
|
||||
name = "grafana-admins"
|
||||
parent = null
|
||||
roles = null
|
||||
users = [5, 4]
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "22a3c296-0d98-433f-8456-ebc2f1c8d489"
|
||||
resource "authentik_group" "argocd_admins" {
|
||||
attributes = jsonencode({})
|
||||
is_superuser = false
|
||||
name = "argocd-admins"
|
||||
parent = null
|
||||
roles = null
|
||||
users = [5, 4]
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "cbd8ce0d-c364-47a2-976c-c93211175b83"
|
||||
resource "authentik_group" "homelab_admins" {
|
||||
attributes = jsonencode({})
|
||||
is_superuser = false
|
||||
name = "homelab-admins"
|
||||
parent = null
|
||||
roles = null
|
||||
users = [5, 4]
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "forgejo"
|
||||
resource "authentik_application" "forgejo_app" {
|
||||
backchannel_providers = []
|
||||
group = null
|
||||
meta_description = null
|
||||
meta_icon = "/static/authentik/sources/gitlab.svg"
|
||||
meta_launch_url = null
|
||||
meta_publisher = null
|
||||
name = "forgejo"
|
||||
open_in_new_tab = false
|
||||
policy_engine_mode = "any"
|
||||
protocol_provider = 3
|
||||
slug = "forgejo"
|
||||
uuid = "f70eb945-bf90-4f8c-875b-74db857b6c22"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "argocd"
|
||||
resource "authentik_application" "argocd_app" {
|
||||
backchannel_providers = []
|
||||
group = null
|
||||
meta_description = null
|
||||
meta_icon = null
|
||||
meta_launch_url = null
|
||||
meta_publisher = null
|
||||
name = "argocd"
|
||||
open_in_new_tab = false
|
||||
policy_engine_mode = "any"
|
||||
protocol_provider = 4
|
||||
slug = "argocd"
|
||||
uuid = "781fa91e-7fcd-4e54-a9e5-fe809774e9d1"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "core-cli"
|
||||
resource "authentik_application" "core_cli_app" {
|
||||
backchannel_providers = []
|
||||
group = null
|
||||
meta_description = null
|
||||
meta_icon = null
|
||||
meta_launch_url = null
|
||||
meta_publisher = null
|
||||
name = "core-cli"
|
||||
open_in_new_tab = false
|
||||
policy_engine_mode = "any"
|
||||
protocol_provider = authentik_provider_oauth2.core_cli_provider.id
|
||||
slug = "core-cli"
|
||||
uuid = "f15c69b4-414b-49da-9e65-eef0a0dbf1ee"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "4"
|
||||
resource "authentik_provider_oauth2" "argocd_provider" {
|
||||
access_code_validity = "minutes=1"
|
||||
access_token_validity = "minutes=5"
|
||||
allowed_redirect_uris = [{
|
||||
matching_mode = "strict"
|
||||
url = "https://argocd.riotpiao.homelab.com/auth/callback"
|
||||
}]
|
||||
authentication_flow = null
|
||||
authorization_flow = "3bd78f72-7d78-40c5-baad-5a63203f75ac"
|
||||
client_id = "argocd"
|
||||
client_secret = null # sensitive
|
||||
client_type = "confidential"
|
||||
encryption_key = null
|
||||
include_claims_in_id_token = true
|
||||
invalidation_flow = "cedc5670-78d6-402b-aa24-26674aea799c"
|
||||
issuer_mode = "per_provider"
|
||||
jwks_sources = null
|
||||
jwt_federation_providers = []
|
||||
jwt_federation_sources = []
|
||||
name = "argocd"
|
||||
property_mappings = ["604befc4-8fa3-4d17-8192-044e7a8a88d3", "f38fa6f5-3f87-4470-9241-b98b0151a6c0", "5c9d75bd-3981-4e51-81d4-d1c7d26edf15"]
|
||||
refresh_token_validity = "days=30"
|
||||
signing_key = "0a93e63b-1427-44c8-aa12-4f9f213f5a50"
|
||||
sub_mode = "hashed_user_id"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "4084c8d6-0c12-46af-acf8-7372172b9016"
|
||||
resource "authentik_group" "forgejo_admins" {
|
||||
attributes = jsonencode({})
|
||||
is_superuser = false
|
||||
name = "forgejo-admins"
|
||||
parent = null
|
||||
roles = null
|
||||
users = [5, 4]
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "grafana"
|
||||
resource "authentik_application" "grafana_app" {
|
||||
backchannel_providers = []
|
||||
group = null
|
||||
meta_description = null
|
||||
meta_icon = null
|
||||
meta_launch_url = null
|
||||
meta_publisher = null
|
||||
name = "grafana"
|
||||
open_in_new_tab = false
|
||||
policy_engine_mode = "any"
|
||||
protocol_provider = 1
|
||||
slug = "grafana"
|
||||
uuid = "0acc3c58-d218-4d1a-8f54-6e838851aadb"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "3"
|
||||
resource "authentik_provider_oauth2" "forgejo_provider" {
|
||||
access_code_validity = "minutes=1"
|
||||
access_token_validity = "minutes=5"
|
||||
allowed_redirect_uris = [{
|
||||
matching_mode = "strict"
|
||||
url = "https://forgejo.riotpiao.homelab.com/user/oauth2/authentik/callback"
|
||||
}]
|
||||
authentication_flow = null
|
||||
authorization_flow = "3bd78f72-7d78-40c5-baad-5a63203f75ac"
|
||||
client_id = "forgejo"
|
||||
client_secret = null # sensitive
|
||||
client_type = "confidential"
|
||||
encryption_key = null
|
||||
include_claims_in_id_token = true
|
||||
invalidation_flow = "cedc5670-78d6-402b-aa24-26674aea799c"
|
||||
issuer_mode = "per_provider"
|
||||
jwks_sources = null
|
||||
jwt_federation_providers = []
|
||||
jwt_federation_sources = []
|
||||
name = "forgejo"
|
||||
property_mappings = ["604befc4-8fa3-4d17-8192-044e7a8a88d3", "f38fa6f5-3f87-4470-9241-b98b0151a6c0", "5c9d75bd-3981-4e51-81d4-d1c7d26edf15"]
|
||||
refresh_token_validity = "days=30"
|
||||
signing_key = "0a93e63b-1427-44c8-aa12-4f9f213f5a50"
|
||||
sub_mode = "hashed_user_id"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "minio"
|
||||
resource "authentik_application" "minio_app" {
|
||||
backchannel_providers = []
|
||||
group = null
|
||||
meta_description = null
|
||||
meta_icon = null
|
||||
meta_launch_url = null
|
||||
meta_publisher = null
|
||||
name = "Minio"
|
||||
open_in_new_tab = false
|
||||
policy_engine_mode = "any"
|
||||
protocol_provider = 2
|
||||
slug = "minio"
|
||||
uuid = "6f4ec073-f493-4e6a-96d4-1634e4e9f80f"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "40"
|
||||
resource "authentik_provider_oauth2" "core_cli_provider" {
|
||||
access_code_validity = "minutes=1"
|
||||
access_token_validity = "hours=1"
|
||||
allowed_redirect_uris = [{
|
||||
matching_mode = "strict"
|
||||
url = "urn:ietf:wg:oauth:2.0:oob"
|
||||
}, {
|
||||
matching_mode = "strict"
|
||||
url = "https://authentik.riotpiao.homelab.com/application/o/callback/"
|
||||
}]
|
||||
authentication_flow = null
|
||||
authorization_flow = "41e57c24-e38d-4d23-b81f-a6f002ca5df9"
|
||||
client_id = "core-cli"
|
||||
client_secret = null # sensitive
|
||||
client_type = "confidential"
|
||||
encryption_key = null
|
||||
include_claims_in_id_token = true
|
||||
invalidation_flow = "0254061b-16b3-486e-9800-1fe1580186a6"
|
||||
issuer_mode = "per_provider"
|
||||
jwks_sources = null
|
||||
jwt_federation_providers = []
|
||||
jwt_federation_sources = []
|
||||
name = "core-cli"
|
||||
property_mappings = []
|
||||
refresh_token_validity = "days=30"
|
||||
signing_key = null
|
||||
sub_mode = "hashed_user_id"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "38"
|
||||
resource "authentik_provider_oauth2" "device_code_provider" {
|
||||
access_code_validity = "minutes=1"
|
||||
access_token_validity = "hours=1"
|
||||
allowed_redirect_uris = []
|
||||
authentication_flow = "dc6cfe87-94ac-4178-a2b2-a6ad5d4677dc"
|
||||
authorization_flow = "3bd78f72-7d78-40c5-baad-5a63203f75ac"
|
||||
client_id = "device-code-c5e6da866bd4"
|
||||
client_secret = null # sensitive
|
||||
client_type = "confidential"
|
||||
encryption_key = null
|
||||
include_claims_in_id_token = true
|
||||
invalidation_flow = "0254061b-16b3-486e-9800-1fe1580186a6"
|
||||
issuer_mode = "per_provider"
|
||||
jwks_sources = null
|
||||
jwt_federation_providers = []
|
||||
jwt_federation_sources = []
|
||||
name = "Device Code Flow"
|
||||
property_mappings = []
|
||||
refresh_token_validity = "days=30"
|
||||
signing_key = "0a93e63b-1427-44c8-aa12-4f9f213f5a50"
|
||||
sub_mode = "hashed_user_id"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "0d1c1578-9358-4602-af76-8472f4b4e115"
|
||||
resource "authentik_group" "authentik_read_only" {
|
||||
attributes = jsonencode({
|
||||
notes = "An group with an auto-generated role that allows read-only permissions on all objects.\n"
|
||||
})
|
||||
is_superuser = false
|
||||
name = "authentik Read-only"
|
||||
parent = null
|
||||
roles = null
|
||||
users = []
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "2"
|
||||
resource "authentik_provider_oauth2" "minio_provider" {
|
||||
access_code_validity = "minutes=1"
|
||||
access_token_validity = "minutes=5"
|
||||
allowed_redirect_uris = [{
|
||||
matching_mode = "strict"
|
||||
url = "https://minio.riotpiao.homelab.com/oauth_callback"
|
||||
}]
|
||||
authentication_flow = null
|
||||
authorization_flow = "3bd78f72-7d78-40c5-baad-5a63203f75ac"
|
||||
client_id = "minio"
|
||||
client_secret = null # sensitive
|
||||
client_type = "confidential"
|
||||
encryption_key = null
|
||||
include_claims_in_id_token = true
|
||||
invalidation_flow = "cedc5670-78d6-402b-aa24-26674aea799c"
|
||||
issuer_mode = "per_provider"
|
||||
jwks_sources = null
|
||||
jwt_federation_providers = []
|
||||
jwt_federation_sources = []
|
||||
name = "minio"
|
||||
property_mappings = ["604befc4-8fa3-4d17-8192-044e7a8a88d3", "f38fa6f5-3f87-4470-9241-b98b0151a6c0", "5c9d75bd-3981-4e51-81d4-d1c7d26edf15"]
|
||||
refresh_token_validity = "days=30"
|
||||
signing_key = "0a93e63b-1427-44c8-aa12-4f9f213f5a50"
|
||||
sub_mode = "hashed_user_id"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "5"
|
||||
resource "authentik_provider_oauth2" "temporal_provider" {
|
||||
access_code_validity = "minutes=1"
|
||||
access_token_validity = "minutes=5"
|
||||
allowed_redirect_uris = [{
|
||||
matching_mode = "strict"
|
||||
url = "https://temporal.riotpiao.homelab.com/auth/callback"
|
||||
}]
|
||||
authentication_flow = null
|
||||
authorization_flow = "3bd78f72-7d78-40c5-baad-5a63203f75ac"
|
||||
client_id = "temporal"
|
||||
client_secret = null # sensitive
|
||||
client_type = "confidential"
|
||||
encryption_key = null
|
||||
include_claims_in_id_token = true
|
||||
invalidation_flow = "cedc5670-78d6-402b-aa24-26674aea799c"
|
||||
issuer_mode = "per_provider"
|
||||
jwks_sources = null
|
||||
jwt_federation_providers = []
|
||||
jwt_federation_sources = []
|
||||
name = "temporal"
|
||||
property_mappings = ["604befc4-8fa3-4d17-8192-044e7a8a88d3", "f38fa6f5-3f87-4470-9241-b98b0151a6c0", "5c9d75bd-3981-4e51-81d4-d1c7d26edf15"]
|
||||
refresh_token_validity = "days=30"
|
||||
signing_key = "0a93e63b-1427-44c8-aa12-4f9f213f5a50"
|
||||
sub_mode = "hashed_user_id"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "1"
|
||||
resource "authentik_provider_oauth2" "grafana_provider" {
|
||||
access_code_validity = "minutes=1"
|
||||
access_token_validity = "minutes=5"
|
||||
allowed_redirect_uris = [{
|
||||
matching_mode = "strict"
|
||||
url = "https://grafana.riotpiao.homelab.com/login/generic_oauth"
|
||||
}]
|
||||
authentication_flow = null
|
||||
authorization_flow = "3bd78f72-7d78-40c5-baad-5a63203f75ac"
|
||||
client_id = "grafana"
|
||||
client_secret = null # sensitive
|
||||
client_type = "confidential"
|
||||
encryption_key = null
|
||||
include_claims_in_id_token = true
|
||||
invalidation_flow = "cedc5670-78d6-402b-aa24-26674aea799c"
|
||||
issuer_mode = "per_provider"
|
||||
jwks_sources = null
|
||||
jwt_federation_providers = []
|
||||
jwt_federation_sources = []
|
||||
name = "grafana"
|
||||
property_mappings = ["604befc4-8fa3-4d17-8192-044e7a8a88d3", "f38fa6f5-3f87-4470-9241-b98b0151a6c0", "5c9d75bd-3981-4e51-81d4-d1c7d26edf15"]
|
||||
refresh_token_validity = "days=30"
|
||||
signing_key = "0a93e63b-1427-44c8-aa12-4f9f213f5a50"
|
||||
sub_mode = "hashed_user_id"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "device-code"
|
||||
resource "authentik_application" "device_code_app" {
|
||||
backchannel_providers = []
|
||||
group = null
|
||||
meta_description = null
|
||||
meta_icon = null
|
||||
meta_launch_url = null
|
||||
meta_publisher = null
|
||||
name = "device-code"
|
||||
open_in_new_tab = false
|
||||
policy_engine_mode = "any"
|
||||
protocol_provider = 38
|
||||
slug = "device-code"
|
||||
uuid = "7f6ff50a-3554-4b5b-8419-622db0091ea3"
|
||||
}
|
||||
|
||||
# __generated__ by Terraform from "temporal"
|
||||
resource "authentik_application" "temporal_app" {
|
||||
backchannel_providers = []
|
||||
group = null
|
||||
meta_description = null
|
||||
meta_icon = null
|
||||
meta_launch_url = null
|
||||
meta_publisher = null
|
||||
name = "temporal"
|
||||
open_in_new_tab = false
|
||||
policy_engine_mode = "any"
|
||||
protocol_provider = 5
|
||||
slug = "temporal"
|
||||
uuid = "1d51178b-5619-4ba4-bd50-c102f2864cdd"
|
||||
}
|
||||
@@ -1,104 +0,0 @@
|
||||
resource "kubernetes_manifest" "selfsigned_bootstrap" {
|
||||
manifest = {
|
||||
apiVersion = "cert-manager.io/v1"
|
||||
kind = "ClusterIssuer"
|
||||
metadata = {
|
||||
name = "selfsigned-bootstrap"
|
||||
}
|
||||
spec = {
|
||||
selfSigned = {}
|
||||
}
|
||||
}
|
||||
|
||||
field_manager {
|
||||
name = "terraform"
|
||||
}
|
||||
}
|
||||
|
||||
resource "kubernetes_manifest" "homelab_ca_cert" {
|
||||
manifest = {
|
||||
apiVersion = "cert-manager.io/v1"
|
||||
kind = "Certificate"
|
||||
metadata = {
|
||||
name = "homelab-ca"
|
||||
namespace = kubernetes_namespace.namespaces["cert-manager"].metadata[0].name
|
||||
}
|
||||
spec = {
|
||||
secretName = "homelab-ca-secret"
|
||||
commonName = "homelab-ca"
|
||||
isCA = true
|
||||
issuerRef = {
|
||||
name = "selfsigned-bootstrap"
|
||||
kind = "ClusterIssuer"
|
||||
}
|
||||
duration = "87600h"
|
||||
renewBefore = "720h"
|
||||
privateKey = {
|
||||
algorithm = "ECDSA"
|
||||
size = 256
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
field_manager {
|
||||
name = "terraform"
|
||||
}
|
||||
|
||||
depends_on = [
|
||||
kubernetes_manifest.selfsigned_bootstrap
|
||||
]
|
||||
}
|
||||
|
||||
resource "kubernetes_manifest" "homelab_ca_issuer" {
|
||||
manifest = {
|
||||
apiVersion = "cert-manager.io/v1"
|
||||
kind = "ClusterIssuer"
|
||||
metadata = {
|
||||
name = "homelab-ca"
|
||||
}
|
||||
spec = {
|
||||
ca = {
|
||||
secretName = "homelab-ca-secret"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
field_manager {
|
||||
name = "terraform"
|
||||
}
|
||||
|
||||
depends_on = [
|
||||
kubernetes_manifest.homelab_ca_cert
|
||||
]
|
||||
}
|
||||
|
||||
resource "kubernetes_manifest" "wildcard_cert" {
|
||||
manifest = {
|
||||
apiVersion = "cert-manager.io/v1"
|
||||
kind = "Certificate"
|
||||
metadata = {
|
||||
name = "homelab-tls"
|
||||
namespace = kubernetes_namespace.namespaces["ingress-nginx"].metadata[0].name
|
||||
}
|
||||
spec = {
|
||||
secretName = "homelab-tls"
|
||||
commonName = "*.${var.cluster_domain}"
|
||||
dnsNames = ["*.${var.cluster_domain}"]
|
||||
issuerRef = {
|
||||
name = "homelab-ca"
|
||||
kind = "ClusterIssuer"
|
||||
}
|
||||
duration = "2160h"
|
||||
renewBefore = "720h"
|
||||
}
|
||||
}
|
||||
|
||||
field_manager {
|
||||
name = "terraform"
|
||||
}
|
||||
|
||||
depends_on = [
|
||||
kubernetes_manifest.homelab_ca_issuer,
|
||||
kubernetes_namespace.namespaces
|
||||
]
|
||||
}
|
||||
@@ -1,80 +0,0 @@
|
||||
---
|
||||
# ClusterIssuer: selfsigned-bootstrap (initial issuer for homelab-ca cert)
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: selfsigned-bootstrap
|
||||
spec:
|
||||
selfSigned: {}
|
||||
|
||||
---
|
||||
# ClusterIssuer: homelab-ca (uses generated homelab-ca cert)
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: homelab-ca
|
||||
spec:
|
||||
ca:
|
||||
secretName: homelab-ca-secret
|
||||
|
||||
---
|
||||
# Self-signed CA certificate (10 year lifetime)
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: homelab-ca
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
commonName: homelab-ca
|
||||
duration: 87600h
|
||||
isCA: true
|
||||
issuerRef:
|
||||
kind: ClusterIssuer
|
||||
name: selfsigned-bootstrap
|
||||
privateKey:
|
||||
algorithm: ECDSA
|
||||
size: 256
|
||||
renewBefore: 720h
|
||||
secretName: homelab-ca-secret
|
||||
|
||||
---
|
||||
# Wildcard TLS certificate for *.riotpiao.homelab.com
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: homelab-tls
|
||||
namespace: ingress-nginx
|
||||
spec:
|
||||
commonName: "*.riotpiao.homelab.com"
|
||||
dnsNames:
|
||||
- "*.riotpiao.homelab.com"
|
||||
duration: 2160h
|
||||
issuerRef:
|
||||
kind: ClusterIssuer
|
||||
name: homelab-ca
|
||||
renewBefore: 720h
|
||||
secretName: homelab-tls
|
||||
|
||||
---
|
||||
# ArgoCD namespace
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: argocd
|
||||
labels:
|
||||
pod-security.kubernetes.io/enforce: baseline
|
||||
pod-security.kubernetes.io/enforce-version: latest
|
||||
|
||||
---
|
||||
# dev-tools namespace
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: dev-tools
|
||||
labels:
|
||||
pod-security.kubernetes.io/audit: restricted
|
||||
pod-security.kubernetes.io/audit-version: latest
|
||||
pod-security.kubernetes.io/enforce: baseline
|
||||
pod-security.kubernetes.io/enforce-version: latest
|
||||
pod-security.kubernetes.io/warn: restricted
|
||||
pod-security.kubernetes.io/warn-version: latest
|
||||
@@ -1,37 +0,0 @@
|
||||
locals {
|
||||
namespaces = {
|
||||
"cert-manager" = { pod_security = "baseline" }
|
||||
"reloader" = { pod_security = "baseline" }
|
||||
"ingress-nginx" = { pod_security = "privileged" }
|
||||
"ddb" = { pod_security = "baseline" }
|
||||
"iam" = { pod_security = "baseline" }
|
||||
"storage" = { pod_security = "baseline" }
|
||||
"logging" = { pod_security = "baseline" }
|
||||
"monitoring" = { pod_security = "baseline" }
|
||||
"cicd" = { pod_security = "baseline" }
|
||||
"dashboard" = { pod_security = "baseline" }
|
||||
"sqs" = { pod_security = "baseline" }
|
||||
"temporal" = { pod_security = "baseline" }
|
||||
"story-crater-backend" = { pod_security = "baseline" }
|
||||
"llm" = { pod_security = "baseline" }
|
||||
"dev-tools" = { pod_security = "baseline" }
|
||||
"longhorn-system" = { pod_security = "baseline" }
|
||||
"cilium-secrets" = { pod_security = "baseline" }
|
||||
}
|
||||
}
|
||||
|
||||
resource "kubernetes_namespace" "namespaces" {
|
||||
for_each = local.namespaces
|
||||
|
||||
metadata {
|
||||
name = each.key
|
||||
labels = {
|
||||
"pod-security.kubernetes.io/enforce" = each.value.pod_security
|
||||
"pod-security.kubernetes.io/enforce-version" = "latest"
|
||||
"pod-security.kubernetes.io/audit" = "restricted"
|
||||
"pod-security.kubernetes.io/audit-version" = "latest"
|
||||
"pod-security.kubernetes.io/warn" = "restricted"
|
||||
"pod-security.kubernetes.io/warn-version" = "latest"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,67 +0,0 @@
|
||||
locals {
|
||||
bootstrap_releases = {
|
||||
cert-manager = {
|
||||
chart_version = "v1.21.0"
|
||||
namespace = "cert-manager"
|
||||
repo = "jetstack"
|
||||
}
|
||||
cilium = {
|
||||
chart_version = "1.19.5"
|
||||
namespace = "kube-system"
|
||||
repo = "cilium"
|
||||
}
|
||||
reloader = {
|
||||
chart_version = "1.3.0"
|
||||
namespace = "reloader"
|
||||
repo = "stakater"
|
||||
}
|
||||
ingress-nginx = {
|
||||
chart_version = "4.15.1"
|
||||
namespace = "ingress-nginx"
|
||||
repo = "ingress_nginx"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "helm_release" "bootstrap" {
|
||||
for_each = local.bootstrap_releases
|
||||
|
||||
name = each.key
|
||||
repository = local.helm_repos[each.value.repo]
|
||||
chart = each.key
|
||||
version = each.value.chart_version
|
||||
namespace = each.value.namespace
|
||||
|
||||
dynamic "set" {
|
||||
for_each = each.key == "cert-manager" ? {
|
||||
"crds.enabled" = "true"
|
||||
"prometheus.enabled" = "true"
|
||||
"prometheus.servicemonitor.enabled" = "true"
|
||||
"prometheus.servicemonitor.interval" = "60s"
|
||||
} : (each.key == "ingress-nginx" ? {
|
||||
"controller.admissionWebhooks.enabled" = "false"
|
||||
"controller.dnsPolicy" = "ClusterFirstWithHostNet"
|
||||
"controller.extraArgs.default-ssl-certificate" = "ingress-nginx/homelab-tls"
|
||||
"controller.hostPort.enabled" = "true"
|
||||
"controller.ingressClassResource.default" = "true"
|
||||
"controller.kind" = "DaemonSet"
|
||||
"controller.metrics.enabled" = "true"
|
||||
"controller.metrics.serviceMonitor.enabled" = "true"
|
||||
"controller.metrics.serviceMonitor.interval" = "30s"
|
||||
} : {})
|
||||
content {
|
||||
name = set.key
|
||||
value = set.value
|
||||
}
|
||||
}
|
||||
|
||||
depends_on = [
|
||||
kubernetes_namespace.namespaces
|
||||
]
|
||||
|
||||
lifecycle {
|
||||
ignore_changes = [
|
||||
values
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -1,122 +0,0 @@
|
||||
# Forgejo Actions runner network and RBAC configuration
|
||||
# Enables CI/CD workflows to access cluster services (MinIO, K8s API, etc.)
|
||||
|
||||
# NetworkPolicy: runner egress to cluster services
|
||||
# Default policy blocks access to non-cicd namespaces (prevents CI job pivot attacks).
|
||||
# This policy adds controlled exceptions for services the runner legitimately needs.
|
||||
resource "kubernetes_network_policy" "forgejo_runner_egress" {
|
||||
metadata {
|
||||
name = "forgejo-runner-egress-extended"
|
||||
namespace = "cicd"
|
||||
}
|
||||
|
||||
spec {
|
||||
pod_selector {
|
||||
match_labels = {
|
||||
app = "forgejo-runner"
|
||||
}
|
||||
}
|
||||
|
||||
policy_types = ["Egress"]
|
||||
|
||||
# Same namespace: Forgejo (git clone, repo access)
|
||||
egress {
|
||||
to {
|
||||
pod_selector {}
|
||||
}
|
||||
}
|
||||
|
||||
# CoreDNS: DNS resolution for all service lookups
|
||||
egress {
|
||||
to {
|
||||
namespace_selector {
|
||||
match_labels = {
|
||||
"kubernetes.io/metadata.name" = "kube-system"
|
||||
}
|
||||
}
|
||||
}
|
||||
ports {
|
||||
protocol = "UDP"
|
||||
port = "53"
|
||||
}
|
||||
ports {
|
||||
protocol = "TCP"
|
||||
port = "53"
|
||||
}
|
||||
}
|
||||
|
||||
# Storage namespace: MinIO (S3 backend for terraform state)
|
||||
# Terraform workflows need to push state to S3; restrict to MinIO pod/port only
|
||||
egress {
|
||||
to {
|
||||
namespace_selector {
|
||||
match_labels = {
|
||||
"kubernetes.io/metadata.name" = "storage"
|
||||
}
|
||||
}
|
||||
}
|
||||
ports {
|
||||
protocol = "TCP"
|
||||
port = "9000" # MinIO S3 API
|
||||
}
|
||||
}
|
||||
|
||||
# Public internet: external package repos, container registries, terraform releases
|
||||
# Explicitly exclude LAN (192.168.1.0/24) and pod network (10.244.0.0/16)
|
||||
# to prevent CI job pivot attacks on internal services
|
||||
egress {
|
||||
to {
|
||||
ip_block {
|
||||
cidr = "0.0.0.0/0"
|
||||
except = [
|
||||
"192.168.1.0/24", # LAN (baremetal nodes, physical infra)
|
||||
"10.244.0.0/16" # Pod network (cluster internal)
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# ServiceAccount for Terraform CI jobs (future use for K8s auth)
|
||||
# Currently used for in-cluster kubeconfig generation in workflows
|
||||
resource "kubernetes_service_account" "terraform_ci" {
|
||||
metadata {
|
||||
name = "terraform-ci"
|
||||
namespace = "cicd"
|
||||
}
|
||||
}
|
||||
|
||||
# ClusterRole for Terraform CI jobs
|
||||
# Scoped to resources the CI workflow needs to manage (applies via IaC)
|
||||
resource "kubernetes_cluster_role" "terraform_ci" {
|
||||
metadata {
|
||||
name = "terraform-ci"
|
||||
}
|
||||
|
||||
rule {
|
||||
api_groups = ["*"]
|
||||
resources = ["*"]
|
||||
verbs = ["*"]
|
||||
}
|
||||
}
|
||||
|
||||
# ClusterRoleBinding: attach role to service account
|
||||
# Enables terraform workflows to use in-cluster auth (K8s API, kubeconfig generation)
|
||||
resource "kubernetes_cluster_role_binding" "terraform_ci" {
|
||||
metadata {
|
||||
name = "terraform-ci"
|
||||
}
|
||||
|
||||
role_ref {
|
||||
api_group = "rbac.authorization.k8s.io"
|
||||
kind = "ClusterRole"
|
||||
name = kubernetes_cluster_role.terraform_ci.metadata[0].name
|
||||
}
|
||||
|
||||
subject {
|
||||
kind = "ServiceAccount"
|
||||
name = kubernetes_service_account.terraform_ci.metadata[0].name
|
||||
namespace = "cicd"
|
||||
}
|
||||
}
|
||||
@@ -1,25 +0,0 @@
|
||||
# Forgejo (server) — Git repository and CI/CD configuration persistent storage
|
||||
# Imported from live cluster state (import-only, no delete)
|
||||
# Live name: gitea-shared-storage (Gitea is old name, Forgejo is new)
|
||||
|
||||
resource "kubernetes_persistent_volume_claim" "forgejo_shared_storage" {
|
||||
metadata {
|
||||
name = "gitea-shared-storage"
|
||||
namespace = "cicd"
|
||||
}
|
||||
spec {
|
||||
access_modes = ["ReadWriteOnce"]
|
||||
storage_class_name = "longhorn"
|
||||
resources {
|
||||
requests = {
|
||||
storage = "20Gi"
|
||||
}
|
||||
}
|
||||
volume_name = "pvc-889e20b9-2203-46e6-8c08-d015cd15193d"
|
||||
}
|
||||
|
||||
|
||||
lifecycle {
|
||||
prevent_destroy = true
|
||||
}
|
||||
}
|
||||
@@ -1,24 +0,0 @@
|
||||
# Grafana — persistent storage for dashboards and datasources
|
||||
# Imported from live cluster state (import-only, no delete)
|
||||
|
||||
resource "kubernetes_persistent_volume_claim" "grafana" {
|
||||
metadata {
|
||||
name = "grafana"
|
||||
namespace = "logging"
|
||||
}
|
||||
spec {
|
||||
access_modes = ["ReadWriteOnce"]
|
||||
storage_class_name = "longhorn"
|
||||
resources {
|
||||
requests = {
|
||||
storage = "5Gi"
|
||||
}
|
||||
}
|
||||
volume_name = "pvc-95f2216e-985d-4496-8b39-48e8c2a7f410"
|
||||
}
|
||||
|
||||
|
||||
lifecycle {
|
||||
prevent_destroy = true
|
||||
}
|
||||
}
|
||||
@@ -1,21 +0,0 @@
|
||||
# Helm chart repositories (referenced inline in helm_release resources)
|
||||
locals {
|
||||
helm_repos = {
|
||||
jetstack = "https://charts.jetstack.io"
|
||||
stakater = "https://stakater.github.io/stakater-charts"
|
||||
ingress_nginx = "https://kubernetes.github.io/ingress-nginx"
|
||||
cilium = "https://helm.cilium.io"
|
||||
cnpg = "https://cloudnative-pg.github.io/charts"
|
||||
authentik = "https://charts.goauthentik.io"
|
||||
hashicorp = "https://helm.releases.hashicorp.com"
|
||||
minio = "https://charts.min.io"
|
||||
grafana = "https://grafana.github.io/helm-charts"
|
||||
prometheus_community = "https://prometheus-community.github.io/helm-charts"
|
||||
portainer = "https://portainer.github.io/k8s/"
|
||||
argo = "https://argoproj.github.io/argo-helm"
|
||||
gitea_charts = "https://dl.gitea.com/charts/"
|
||||
strimzi = "https://strimzi.io/charts/"
|
||||
bitnami = "https://charts.bitnami.com/bitnami"
|
||||
temporal = "https://go.temporal.io/helm-charts"
|
||||
}
|
||||
}
|
||||
@@ -1,24 +0,0 @@
|
||||
# Loki — log aggregation backend persistent storage (StatefulSet mode: storage-loki-0)
|
||||
# Imported from live cluster state (import-only, no delete)
|
||||
|
||||
resource "kubernetes_persistent_volume_claim" "loki" {
|
||||
metadata {
|
||||
name = "storage-loki-0"
|
||||
namespace = "logging"
|
||||
}
|
||||
spec {
|
||||
access_modes = ["ReadWriteOnce"]
|
||||
storage_class_name = "longhorn"
|
||||
resources {
|
||||
requests = {
|
||||
storage = "5Gi"
|
||||
}
|
||||
}
|
||||
volume_name = "pvc-897d4f5a-1699-4e06-b92f-ccbe3911be0f"
|
||||
}
|
||||
|
||||
|
||||
lifecycle {
|
||||
prevent_destroy = true
|
||||
}
|
||||
}
|
||||
@@ -1,40 +0,0 @@
|
||||
# Longhorn StorageClasses — cluster-wide default + app-specific variants
|
||||
# Imported from live cluster state (import-only, no delete)
|
||||
|
||||
resource "kubernetes_storage_class" "longhorn" {
|
||||
metadata {
|
||||
name = "longhorn"
|
||||
}
|
||||
storage_provisioner = "driver.longhorn.io"
|
||||
reclaim_policy = "Delete"
|
||||
allow_volume_expansion = true
|
||||
volume_binding_mode = "Immediate"
|
||||
|
||||
parameters = {
|
||||
numberOfReplicas = "3"
|
||||
staleReplicaTimeout = "60"
|
||||
fromBackup = ""
|
||||
fsType = "ext4"
|
||||
dataLocality = "disabled"
|
||||
disableRevisionCounter = "true"
|
||||
unmapMarkSnapChainRemoved = "ignored"
|
||||
}
|
||||
}
|
||||
|
||||
resource "kubernetes_storage_class" "longhorn_kafka" {
|
||||
metadata {
|
||||
name = "longhorn-kafka"
|
||||
}
|
||||
storage_provisioner = "driver.longhorn.io"
|
||||
reclaim_policy = "Delete"
|
||||
allow_volume_expansion = true
|
||||
volume_binding_mode = "Immediate"
|
||||
|
||||
parameters = {
|
||||
numberOfReplicas = "3"
|
||||
staleReplicaTimeout = "30"
|
||||
fromBackup = ""
|
||||
fsType = "ext4"
|
||||
dataLocality = "disabled"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +0,0 @@
|
||||
locals {
|
||||
cluster_domain = var.cluster_domain
|
||||
}
|
||||
|
||||
# Helm repositories will be created in helm-repositories.tf
|
||||
# Namespaces will be created in bootstrap/namespaces.tf
|
||||
# Helm releases will be created in helm-releases/*.tf
|
||||
@@ -1,33 +0,0 @@
|
||||
# MinIO - Official minio/minio chart, direct Helm deployment (no operator)
|
||||
# All-in-one: single helm_release + dedicated xfs StorageClass.
|
||||
# Why xfs: default `longhorn` SC uses ext4 whose mkfs on 100Gi (~4.5min)
|
||||
# exceeds kubelet mount timeout. xfs mkfs is near-instant. min.io chart has
|
||||
# no persistence.fsType, so fsType must be set on the StorageClass.
|
||||
|
||||
resource "kubernetes_storage_class" "longhorn_xfs" {
|
||||
metadata {
|
||||
name = "longhorn-xfs"
|
||||
}
|
||||
storage_provisioner = "driver.longhorn.io"
|
||||
reclaim_policy = "Delete"
|
||||
allow_volume_expansion = true
|
||||
volume_binding_mode = "Immediate"
|
||||
|
||||
parameters = {
|
||||
numberOfReplicas = "2"
|
||||
staleReplicaTimeout = "60"
|
||||
fsType = "xfs"
|
||||
dataLocality = "disabled"
|
||||
}
|
||||
}
|
||||
|
||||
# MinIO Helm release removed — managed by ArgoCD instead
|
||||
# Reason: MinIO is Terraform state backend (chicken-and-egg problem)
|
||||
# Solution: ArgoCD Application (k8s/argocd/apps/phase0-minio.yaml) handles deployment
|
||||
# Terraform manages everything else, state lives in MinIO (safe external backend)
|
||||
|
||||
variable "create_storage_namespace" {
|
||||
description = "Create storage namespace if it doesn't exist"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
@@ -1,24 +0,0 @@
|
||||
# Portainer — Docker container management UI persistent storage
|
||||
# Imported from live cluster state (import-only, no delete)
|
||||
|
||||
resource "kubernetes_persistent_volume_claim" "portainer" {
|
||||
metadata {
|
||||
name = "portainer"
|
||||
namespace = "dashboard"
|
||||
}
|
||||
spec {
|
||||
access_modes = ["ReadWriteOnce"]
|
||||
storage_class_name = "longhorn"
|
||||
resources {
|
||||
requests = {
|
||||
storage = "10Gi"
|
||||
}
|
||||
}
|
||||
volume_name = "pvc-bcd0d8cb-1214-4d01-a960-f104926f2b00"
|
||||
}
|
||||
|
||||
|
||||
lifecycle {
|
||||
prevent_destroy = true
|
||||
}
|
||||
}
|
||||
@@ -1,50 +0,0 @@
|
||||
terraform {
|
||||
required_version = ">= 1.5"
|
||||
required_providers {
|
||||
kubernetes = {
|
||||
source = "hashicorp/kubernetes"
|
||||
version = "~> 2.27"
|
||||
}
|
||||
helm = {
|
||||
source = "hashicorp/helm"
|
||||
version = "~> 2.14"
|
||||
}
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "~> 4.0"
|
||||
}
|
||||
null = {
|
||||
source = "hashicorp/null"
|
||||
version = "~> 3.2"
|
||||
}
|
||||
authentik = {
|
||||
source = "goauthentik/authentik"
|
||||
version = "2024.12.1"
|
||||
}
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = "~> 5.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
provider "kubernetes" {
|
||||
host = "https://kubernetes.default"
|
||||
token = try(file("/var/run/secrets/kubernetes.io/serviceaccount/token"), "")
|
||||
cluster_ca_certificate = try(file("/var/run/secrets/kubernetes.io/serviceaccount/ca.crt"), "")
|
||||
insecure = false
|
||||
}
|
||||
|
||||
provider "helm" {
|
||||
kubernetes {
|
||||
host = "https://kubernetes.default"
|
||||
token = try(file("/var/run/secrets/kubernetes.io/serviceaccount/token"), "")
|
||||
cluster_ca_certificate = try(file("/var/run/secrets/kubernetes.io/serviceaccount/ca.crt"), "")
|
||||
insecure = false
|
||||
}
|
||||
}
|
||||
|
||||
provider "vault" {
|
||||
address = "https://vault.riotpiao.homelab.com"
|
||||
skip_tls_verify = true
|
||||
}
|
||||
@@ -1,81 +0,0 @@
|
||||
#!/bin/bash
|
||||
set -e
|
||||
|
||||
echo "=== Step 1: Apply bootstrap manifests (namespaces, cert-manager issuers/certs) ==="
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
source "$SCRIPT_DIR/../../.env.terraform.sh"
|
||||
kubectl apply -f "$SCRIPT_DIR/../bootstrap-manifests.yaml" --validate=false
|
||||
echo "✓ Bootstrap manifests applied"
|
||||
|
||||
echo ""
|
||||
echo "=== Step 2: Wait for cert-manager to be ready ==="
|
||||
kubectl -n cert-manager rollout status deployment/cert-manager --timeout=5m
|
||||
echo "✓ cert-manager ready"
|
||||
|
||||
echo ""
|
||||
echo "=== Step 3: Wait for homelab-ca certificate to be issued ==="
|
||||
for i in {1..60}; do
|
||||
if kubectl -n cert-manager get secret homelab-ca-secret &>/dev/null; then
|
||||
echo "✓ homelab-ca-secret created"
|
||||
break
|
||||
fi
|
||||
echo "Waiting for homelab-ca-secret... ($i/60)"
|
||||
sleep 2
|
||||
done
|
||||
|
||||
echo ""
|
||||
echo "=== Step 4a: Delete old ArgoCD release from cicd namespace ==="
|
||||
if helm list -n cicd | grep -q "^argocd"; then
|
||||
helm delete argocd -n cicd
|
||||
echo "✓ Old ArgoCD removed from cicd"
|
||||
sleep 5
|
||||
else
|
||||
echo "✓ No ArgoCD in cicd to delete"
|
||||
fi
|
||||
|
||||
echo ""
|
||||
echo "=== Step 4a2: Delete orphaned CRDs left behind by helm resource policy ==="
|
||||
kubectl delete crd applications.argoproj.io applicationsets.argoproj.io appprojects.argoproj.io --ignore-not-found
|
||||
echo "✓ CRDs deleted"
|
||||
sleep 2
|
||||
|
||||
echo ""
|
||||
echo "=== Step 4b: Install ArgoCD helm release in argocd namespace ==="
|
||||
helm repo add argocd https://argoproj.github.io/argo-helm
|
||||
helm repo update
|
||||
ARGOCD_VALUES="$SCRIPT_DIR/../../k8s/talos-ci-cd/argocd-values.yaml"
|
||||
helm upgrade --install argocd argocd/argo-cd \
|
||||
--namespace argocd \
|
||||
--version 7.3.3 \
|
||||
--values "$ARGOCD_VALUES" \
|
||||
--wait
|
||||
echo "✓ ArgoCD installed in argocd namespace"
|
||||
|
||||
echo ""
|
||||
echo "=== Step 5: Import kubernetes resources into TF state ==="
|
||||
cd "$SCRIPT_DIR/../.."
|
||||
source .env.terraform.sh
|
||||
cd terraform
|
||||
|
||||
# Import namespaces
|
||||
terraform import kubernetes_namespace.argocd argocd
|
||||
terraform import 'kubernetes_namespace.namespaces["dev-tools"]' dev-tools
|
||||
|
||||
# Import cert-manager objects (kubernetes_manifest import syntax uses colons: apiVersion:kind:name or apiVersion:kind:namespace:name)
|
||||
terraform import kubernetes_manifest.selfsigned_bootstrap 'cert-manager.io:v1:ClusterIssuer:selfsigned-bootstrap'
|
||||
terraform import kubernetes_manifest.homelab_ca_issuer 'cert-manager.io:v1:ClusterIssuer:homelab-ca'
|
||||
terraform import kubernetes_manifest.homelab_ca_cert 'cert-manager.io:v1:Certificate:cert-manager:homelab-ca'
|
||||
terraform import kubernetes_manifest.wildcard_cert 'cert-manager.io:v1:Certificate:ingress-nginx:homelab-tls'
|
||||
|
||||
echo "✓ Kubernetes resources imported"
|
||||
|
||||
echo ""
|
||||
echo "=== Step 6: Import ArgoCD helm release ==="
|
||||
terraform import helm_release.argocd argocd/argocd
|
||||
echo "✓ ArgoCD helm release imported"
|
||||
|
||||
echo ""
|
||||
echo "=== Step 7: Verify clean plan ==="
|
||||
terraform plan
|
||||
echo ""
|
||||
echo "✓ All bootstrap resources imported. Plan should show zero changes."
|
||||
@@ -1,69 +0,0 @@
|
||||
#!/bin/bash
|
||||
set -e
|
||||
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
echo "=== Importing Namespaces ==="
|
||||
for ns in cert-manager reloader ingress-nginx ddb iam storage logging monitoring cicd dashboard sqs temporal story-crater-backend llm dev-tools cilium-secrets kube-node-lease kube-public; do
|
||||
if kubectl get ns "$ns" &>/dev/null; then
|
||||
echo "Importing namespace: $ns"
|
||||
terraform import "kubernetes_namespace.namespaces[\"$ns\"]" "$ns" || echo " (already imported or skipped)"
|
||||
fi
|
||||
done
|
||||
|
||||
echo -e "\n=== Importing Storage Classes ==="
|
||||
for sc in longhorn longhorn-kafka longhorn-llm longhorn-static; do
|
||||
if kubectl get sc "$sc" &>/dev/null; then
|
||||
echo "Importing storage class: $sc"
|
||||
terraform import "kubernetes_storage_class.$sc" "$sc" || echo " (already imported or skipped)"
|
||||
fi
|
||||
done
|
||||
|
||||
echo -e "\n=== Importing Bootstrap Helm Releases (TF-managed) ==="
|
||||
declare -a bootstrap_releases=(
|
||||
"cert-manager/cert-manager"
|
||||
"reloader/reloader"
|
||||
"ingress-nginx/ingress-nginx"
|
||||
)
|
||||
|
||||
for rel_ns in "${bootstrap_releases[@]}"; do
|
||||
rel=$(echo "$rel_ns" | cut -d/ -f1)
|
||||
ns=$(echo "$rel_ns" | cut -d/ -f2)
|
||||
if helm list -n "$ns" --output json 2>/dev/null | grep -q "\"name\":\"$rel\""; then
|
||||
echo "Importing helm release: $rel_ns"
|
||||
terraform import "helm_release.bootstrap[\"$rel\"]" "$rel_ns" || echo " (already imported or skipped)"
|
||||
fi
|
||||
done
|
||||
|
||||
echo -e "\n=== Skipping Workload Helm Releases ==="
|
||||
echo "The following releases will be managed by ArgoCD (not imported to TF):"
|
||||
declare -a workload_releases=(
|
||||
"argocd/cicd"
|
||||
"authentik/iam"
|
||||
"cilium/kube-system"
|
||||
"cloudnative-pg/ddb"
|
||||
"duckdns/kube-system"
|
||||
"forgejo/cicd"
|
||||
"forgejo-runner/cicd"
|
||||
"grafana/logging"
|
||||
"kafka-cluster/sqs"
|
||||
"kmsvc-redis/sqs"
|
||||
"loki/logging"
|
||||
"management-service/sqs"
|
||||
"minio/storage"
|
||||
"ollama/llm"
|
||||
"portainer/dashboard"
|
||||
"prometheus/monitoring"
|
||||
"promtail/logging"
|
||||
"queue-crd/sqs"
|
||||
"strimzi-operator/sqs"
|
||||
"temporal/temporal"
|
||||
"vault/iam"
|
||||
)
|
||||
for rel in "${workload_releases[@]}"; do
|
||||
echo " - $rel"
|
||||
done
|
||||
|
||||
echo -e "\n=== Import Complete ==="
|
||||
echo "Next: review terraform plan and apply"
|
||||
terraform plan
|
||||
@@ -1,60 +0,0 @@
|
||||
#!/bin/bash
|
||||
set -e
|
||||
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
echo "=== Terraform Bootstrap Setup ==="
|
||||
|
||||
if [ ! -f "../.env" ]; then
|
||||
echo "ERROR: ../.env not found. Run from terraform/ directory."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Extract MinIO credentials from .env
|
||||
export AWS_ACCESS_KEY_ID=$(grep "^MINIO_ROOT_USER=" ../.env | cut -d= -f2)
|
||||
export AWS_SECRET_ACCESS_KEY=$(grep "^MINIO_ROOT_PASSWORD=" ../.env | cut -d= -f2)
|
||||
export KUBECONFIG=$(pwd)/../cluster-config/kubeconfig
|
||||
|
||||
if [ -z "$AWS_ACCESS_KEY_ID" ] || [ -z "$AWS_SECRET_ACCESS_KEY" ]; then
|
||||
echo "ERROR: MINIO_ROOT_USER or MINIO_ROOT_PASSWORD not found in .env"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "✓ MinIO S3 credentials loaded"
|
||||
|
||||
# Check Vault token
|
||||
if [ -z "$VAULT_TOKEN" ]; then
|
||||
echo "WARNING: VAULT_TOKEN not set. Set it before terraform init:"
|
||||
echo " export VAULT_TOKEN=\$(vault login -method=oidc ...)"
|
||||
fi
|
||||
|
||||
# Generate terraform.tfvars from .env
|
||||
echo "Generating terraform.tfvars from .env..."
|
||||
cat > terraform.tfvars.local << 'EOF'
|
||||
# Auto-generated from .env
|
||||
EOF
|
||||
|
||||
grep -E '^(AUTHENTIK_SECRET_KEY|AUTHENTIK_BOOTSTRAP_PASSWORD|AUTHENTIK_BOOTSTRAP_TOKEN|AUTHENTIK_PG_PASSWORD|POSTGRES_PASSWORD|MINIO_ROOT_|GRAFANA_|FORGEJO_|ARGOCD_)' ../.env | sed 's/_ROOT_USER=/=/' | while read line; do
|
||||
key=$(echo "$line" | cut -d= -f1 | sed 's/_/ /g; s/.*/\L&/; s/ /_/g')
|
||||
val=$(echo "$line" | cut -d= -f2-)
|
||||
if [[ "$key" == *"secret"* ]] || [[ "$key" == *"password"* ]]; then
|
||||
echo "$key = \"$val\"" >> terraform.tfvars.local
|
||||
else
|
||||
echo "$key = \"$val\"" >> terraform.tfvars.local
|
||||
fi
|
||||
done
|
||||
|
||||
echo "✓ terraform.tfvars.local generated"
|
||||
|
||||
# Initialize terraform
|
||||
echo "Initializing terraform with S3 backend..."
|
||||
terraform init \
|
||||
-backend-config="access_key=$AWS_ACCESS_KEY_ID" \
|
||||
-backend-config="secret_key=$AWS_SECRET_ACCESS_KEY"
|
||||
|
||||
echo "✓ Terraform initialized"
|
||||
echo ""
|
||||
echo "Next steps:"
|
||||
echo " 1. Review: terraform plan"
|
||||
echo " 2. Import existing resources: ./scripts/import-existing.sh"
|
||||
echo " 3. Apply: terraform apply"
|
||||
@@ -1,56 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Phase 0 — Read-only reconciliation of three ownership ambiguities
|
||||
# Safe to run; only queries, no mutations
|
||||
|
||||
set -e
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
echo "=== Phase 0: Cluster Reconciliation ==="
|
||||
echo ""
|
||||
|
||||
# Ambiguity 1: minio (storage) — standalone chart vs. Operator Tenant
|
||||
echo "--- Ambiguity 1: minio (storage) ownership ---"
|
||||
echo "Helm releases in 'storage' namespace:"
|
||||
helm list -n storage || echo " (helm list failed)"
|
||||
echo ""
|
||||
echo "MinIO Operator Tenants in 'storage' namespace:"
|
||||
kubectl get tenant -n storage -o wide 2>/dev/null || echo " (no Tenant CRD or none found)"
|
||||
echo ""
|
||||
echo "PVCs in 'storage' namespace:"
|
||||
kubectl get pvc -n storage -o wide || echo " (kubectl failed)"
|
||||
echo ""
|
||||
|
||||
# Ambiguity 2: kmsvc-redis — helmfile release vs. ArgoCD Application
|
||||
echo "--- Ambiguity 2: kmsvc-redis ownership ---"
|
||||
echo "ArgoCD Applications containing 'redis':"
|
||||
argocd app list | grep redis || echo " (no match or argocd unavailable)"
|
||||
echo ""
|
||||
echo "Helm releases in 'sqs' namespace:"
|
||||
helm list -n sqs | grep redis || echo " (no redis release)"
|
||||
echo ""
|
||||
echo "Redis-related PVCs in 'sqs' namespace:"
|
||||
kubectl get pvc -n sqs -o wide | grep -i redis || echo " (no redis PVC)"
|
||||
echo ""
|
||||
|
||||
# Ambiguity 3: forgejo-runner — helm chart vs. raw manifest
|
||||
echo "--- Ambiguity 3: forgejo-runner ownership ---"
|
||||
echo "Helm releases in 'cicd' namespace containing 'runner':"
|
||||
helm list -n cicd | grep runner || echo " (no runner release)"
|
||||
echo ""
|
||||
echo "Deployments in 'cicd' namespace with label app=forgejo-runner:"
|
||||
kubectl get deploy -n cicd -l app=forgejo-runner -o wide || echo " (no matching deployment)"
|
||||
echo ""
|
||||
echo "Checking managedFields on any forgejo-runner Deployment (to identify controller):"
|
||||
kubectl get deploy -n cicd -l app=forgejo-runner -o json 2>/dev/null | jq '.items[0].metadata.managedFields' 2>/dev/null || echo " (no deployment found)"
|
||||
echo ""
|
||||
echo "PVCs in 'cicd' namespace named runner-*:"
|
||||
kubectl get pvc -n cicd -o wide | grep runner || echo " (no runner PVC)"
|
||||
echo ""
|
||||
|
||||
echo "=== Phase 0 Complete ==="
|
||||
echo "Review the output above. Determine which of the three ambiguities are resolved:"
|
||||
echo " 1. minio(storage): Is Helm release or Tenant CR authoritative? (helm list vs kubectl get tenant)"
|
||||
echo " 2. kmsvc-redis: Is helmfile or ArgoCD Application active? (argocd app list vs helm list)"
|
||||
echo " 3. forgejo-runner: Is Helm chart or raw manifest applied? (helm list vs kubectl get deploy managedFields)"
|
||||
echo ""
|
||||
echo "Document your findings. Proceed to Phase 1 (StorageClass import) only after clarity."
|
||||
@@ -1,87 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Phase 1 — StorageClass import (longhorn + longhorn-kafka)
|
||||
# Captures live spec, verifies against resource blocks, imports to state
|
||||
|
||||
set -e
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
echo "=== Phase 1: StorageClass Import ==="
|
||||
echo ""
|
||||
|
||||
# Verify cluster connection
|
||||
echo "Checking cluster connection..."
|
||||
kubectl cluster-info || { echo "ERROR: No cluster access"; exit 1; }
|
||||
echo ""
|
||||
|
||||
# Capture live longhorn SC spec
|
||||
echo "--- Capturing live 'longhorn' StorageClass spec ---"
|
||||
kubectl get sc longhorn -o yaml > /tmp/longhorn-live.yaml
|
||||
echo "Saved to /tmp/longhorn-live.yaml"
|
||||
echo "Contents:"
|
||||
cat /tmp/longhorn-live.yaml
|
||||
echo ""
|
||||
|
||||
# Capture live longhorn-kafka SC spec
|
||||
echo "--- Capturing live 'longhorn-kafka' StorageClass spec ---"
|
||||
kubectl get sc longhorn-kafka -o yaml > /tmp/longhorn-kafka-live.yaml
|
||||
echo "Saved to /tmp/longhorn-kafka-live.yaml"
|
||||
echo "Contents:"
|
||||
cat /tmp/longhorn-kafka-live.yaml
|
||||
echo ""
|
||||
|
||||
# Verify terraform resource blocks match live spec
|
||||
echo "--- Verifying terraform/longhorn.tf resource blocks against live specs ---"
|
||||
echo "MANUAL STEP: Compare the captured specs above against terraform/longhorn.tf"
|
||||
echo " 1. Check 'provisioner', 'reclaimPolicy', 'volumeBindingMode', 'allowVolumeExpansion'"
|
||||
echo " 2. Check 'parameters' (numberOfReplicas, staleReplicaTimeout, fsType, dataLocality)"
|
||||
echo " 3. Fix terraform/longhorn.tf if any diffs found, then re-run terraform plan"
|
||||
echo ""
|
||||
read -p "Press Enter once you've verified the Terraform blocks match live specs: " _ || true
|
||||
echo ""
|
||||
|
||||
# Pre-import terraform plan
|
||||
echo "--- Pre-import terraform plan (should be clean) ---"
|
||||
terraform plan -out=/tmp/pre-import.plan || { echo "ERROR: terraform plan failed"; exit 1; }
|
||||
echo "Plan saved to /tmp/pre-import.plan"
|
||||
echo ""
|
||||
|
||||
# Import longhorn SC
|
||||
echo "--- Importing 'longhorn' StorageClass ---"
|
||||
terraform import kubernetes_storage_class.longhorn longhorn || {
|
||||
echo "ERROR: terraform import longhorn failed"
|
||||
exit 1
|
||||
}
|
||||
echo "Import successful"
|
||||
echo ""
|
||||
|
||||
# Plan after first import
|
||||
echo "--- Terraform plan after importing 'longhorn' (must show 0 to add/change/destroy) ---"
|
||||
terraform plan || { echo "ERROR: terraform plan failed"; exit 1; }
|
||||
echo ""
|
||||
read -p "Press Enter if plan shows zero changes; otherwise abort and fix: " _ || true
|
||||
echo ""
|
||||
|
||||
# Import longhorn-kafka SC
|
||||
echo "--- Importing 'longhorn-kafka' StorageClass ---"
|
||||
terraform import kubernetes_storage_class.longhorn_kafka longhorn-kafka || {
|
||||
echo "ERROR: terraform import longhorn-kafka failed"
|
||||
exit 1
|
||||
}
|
||||
echo "Import successful"
|
||||
echo ""
|
||||
|
||||
# Plan after second import
|
||||
echo "--- Terraform plan after importing 'longhorn-kafka' (must show 0 to add/change/destroy) ---"
|
||||
terraform plan || { echo "ERROR: terraform plan failed"; exit 1; }
|
||||
echo ""
|
||||
read -p "Press Enter if plan shows zero changes; otherwise abort and fix: " _ || true
|
||||
echo ""
|
||||
|
||||
# Annotate longhorn-kafka with helm.sh/resource-policy=keep
|
||||
echo "--- Annotating 'longhorn-kafka' with helm.sh/resource-policy=keep ---"
|
||||
kubectl annotate storageclass longhorn-kafka helm.sh/resource-policy=keep --overwrite
|
||||
echo "Annotation added"
|
||||
echo ""
|
||||
|
||||
echo "=== Phase 1 Complete ==="
|
||||
echo "StorageClasses imported successfully. Ready to proceed to Phase 2 (PVC imports)."
|
||||
@@ -1,148 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Phase 2 Pilot — Grafana PVC import (full cycle: annotate → import → plan → values change → helmfile diff → helmfile apply)
|
||||
# Lowest blast radius, validates entire workflow before rolling to other apps
|
||||
|
||||
set -e
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
echo "=== Phase 2 Pilot: Grafana PVC Import ==="
|
||||
echo ""
|
||||
|
||||
# Step a) Protect the live PVC from Helm deletion
|
||||
echo "--- Step a) Protect PVC from Helm deletion ---"
|
||||
echo "Identifying grafana PVC in 'logging' namespace:"
|
||||
kubectl get pvc -n logging -l app.kubernetes.io/instance=grafana -o wide || {
|
||||
echo "ERROR: Cannot find grafana PVC"
|
||||
exit 1
|
||||
}
|
||||
echo ""
|
||||
echo "Annotating with helm.sh/resource-policy=keep (non-destructive, reversible):"
|
||||
kubectl annotate pvc grafana -n logging helm.sh/resource-policy=keep --overwrite
|
||||
echo "Annotation applied"
|
||||
echo ""
|
||||
|
||||
# Step b) Capture the exact live PVC spec
|
||||
echo "--- Step b) Capture live PVC spec ---"
|
||||
kubectl get pvc grafana -n logging -o yaml > /tmp/grafana-pvc-live.yaml
|
||||
echo "Saved to /tmp/grafana-pvc-live.yaml"
|
||||
echo ""
|
||||
echo "Extracting key fields:"
|
||||
echo "Access modes:"
|
||||
kubectl get pvc grafana -n logging -o jsonpath='{.spec.accessModes}' | tr ',' '\n'
|
||||
echo "Storage class:"
|
||||
kubectl get pvc grafana -n logging -o jsonpath='{.spec.storageClassName}'
|
||||
echo ""
|
||||
echo "Requested storage:"
|
||||
kubectl get pvc grafana -n logging -o jsonpath='{.spec.resources.requests.storage}'
|
||||
echo ""
|
||||
echo "Bound PV name:"
|
||||
PV_NAME=$(kubectl get pvc grafana -n logging -o jsonpath='{.spec.volumeName}')
|
||||
echo "$PV_NAME"
|
||||
echo ""
|
||||
echo "MANUAL STEP: Update terraform/grafana.tf with the actual volumeName '$PV_NAME' (currently 'pvc-grafana' as placeholder)"
|
||||
echo ""
|
||||
read -p "Press Enter once grafana.tf is updated with the correct volumeName: " _ || true
|
||||
echo ""
|
||||
|
||||
# Step d) Import and verify zero diff
|
||||
echo "--- Step d) Import 'grafana' PVC ---"
|
||||
terraform import kubernetes_persistent_volume_claim.grafana logging/grafana || {
|
||||
echo "ERROR: terraform import failed"
|
||||
exit 1
|
||||
}
|
||||
echo "Import successful"
|
||||
echo ""
|
||||
|
||||
echo "--- Verifying zero diff (must show 0 to add/change/destroy) ---"
|
||||
PLAN_OUTPUT=$(terraform plan 2>&1)
|
||||
echo "$PLAN_OUTPUT"
|
||||
if echo "$PLAN_OUTPUT" | grep -q "0 to add, 0 to change, 0 to destroy"; then
|
||||
echo "✓ Plan is clean"
|
||||
else
|
||||
echo "✗ Plan shows changes — STOP, do not proceed"
|
||||
echo " Options:"
|
||||
echo " 1. Fix terraform/grafana.tf and re-run terraform plan"
|
||||
echo " 2. Rollback with: terraform state rm kubernetes_persistent_volume_claim.grafana"
|
||||
exit 1
|
||||
fi
|
||||
echo ""
|
||||
|
||||
# Step f) Verify Longhorn replica health BEFORE values change
|
||||
echo "--- Step f.1) Baseline Longhorn replica health ---"
|
||||
LONGHORN_VOL=$(kubectl get pvc grafana -n logging -o jsonpath='{.spec.volumeName}' | sed 's/pvc-//' )
|
||||
echo "Checking Longhorn volume health for: $LONGHORN_VOL"
|
||||
kubectl get longhorn-volume -n longhorn-system "$LONGHORN_VOL" -o json | jq '.status.replicaStatus' 2>/dev/null || echo " (could not get Longhorn status; continue)"
|
||||
echo ""
|
||||
read -p "Note the replica status above. Press Enter to continue: " _ || true
|
||||
echo ""
|
||||
|
||||
# Step e) Update grafana values to use existingClaim (only if chart supports it)
|
||||
echo "--- Step e) Update k8s/logging/grafana-values.yaml for existingClaim ---"
|
||||
echo "Current grafana-values.yaml persistence section:"
|
||||
grep -A 5 "^persistence:" k8s/logging/grafana-values.yaml || echo " (no persistence section found)"
|
||||
echo ""
|
||||
echo "MANUAL STEP: Add/update to k8s/logging/grafana-values.yaml:"
|
||||
echo " persistence:"
|
||||
echo " existingClaim: grafana"
|
||||
echo " enabled: false"
|
||||
echo ""
|
||||
echo "If the chart does NOT support existingClaim (check Grafana chart docs), leave:"
|
||||
echo " persistence:"
|
||||
echo " enabled: true"
|
||||
echo " size: 5Gi"
|
||||
echo " storageClassName: longhorn"
|
||||
echo " (Helm will then see no diff and won't delete the PVC; the keep annotation is the backstop)"
|
||||
echo ""
|
||||
read -p "Press Enter once grafana-values.yaml is updated: " _ || true
|
||||
echo ""
|
||||
|
||||
# Step e.2) helmfile diff to confirm no delete queued
|
||||
echo "--- Step e.2) Helmfile diff to confirm no delete/replace ---"
|
||||
echo "Running helmfile diff for grafana (in logging namespace, chart= from helmfile):"
|
||||
cd "$(dirname "$0")/../.." # go to repo root
|
||||
helmfile -e logging -f helmfile.yaml.gotmpl -l name=grafana diff || {
|
||||
echo "WARNING: helmfile diff failed or returned nonzero exit; check output above"
|
||||
echo " (helmfile may not be perfectly compatible with this session, but diff result should be visible)"
|
||||
}
|
||||
cd "$(dirname "$0")/../terraform"
|
||||
echo ""
|
||||
echo "Confirm no 'delete' or 'replace' operations on the grafana PVC are queued."
|
||||
echo ""
|
||||
read -p "Press Enter if helmfile diff shows no destructive ops on grafana PVC: " _ || true
|
||||
echo ""
|
||||
|
||||
# Step e.3) helmfile apply
|
||||
echo "--- Step e.3) Helmfile apply ---"
|
||||
cd "$(dirname "$0")/../.."
|
||||
echo "Applying logging/grafana via helmfile:"
|
||||
helmfile -e logging -f helmfile.yaml.gotmpl -l name=grafana apply || {
|
||||
echo "WARNING: helmfile apply returned nonzero; check output above"
|
||||
}
|
||||
cd "$(dirname "$0")/../terraform"
|
||||
echo ""
|
||||
echo "Helmfile apply complete"
|
||||
echo ""
|
||||
|
||||
# Step f.2) Verify Longhorn health AFTER helmfile apply
|
||||
echo "--- Step f.2) Post-helmfile Longhorn replica health check ---"
|
||||
echo "Checking Longhorn volume health for: $LONGHORN_VOL"
|
||||
kubectl get longhorn-volume -n longhorn-system "$LONGHORN_VOL" -o json | jq '.status.replicaStatus' 2>/dev/null || echo " (could not get Longhorn status)"
|
||||
echo ""
|
||||
echo "Confirm replica status is identical to baseline above."
|
||||
read -p "Press Enter if replica health matches baseline: " _ || true
|
||||
echo ""
|
||||
|
||||
# Final terraform plan
|
||||
echo "--- Final terraform plan (must still be 0/0/0 after all changes) ---"
|
||||
PLAN_OUTPUT=$(terraform plan 2>&1)
|
||||
echo "$PLAN_OUTPUT"
|
||||
if echo "$PLAN_OUTPUT" | grep -q "0 to add, 0 to change, 0 to destroy"; then
|
||||
echo "✓ Plan is still clean"
|
||||
else
|
||||
echo "✗ Plan shows changes after helmfile apply — investigate"
|
||||
exit 1
|
||||
fi
|
||||
echo ""
|
||||
|
||||
echo "=== Phase 2 Pilot: Grafana Complete ==="
|
||||
echo "Grafana PVC successfully imported. Ready for Phase 2 remaining apps."
|
||||
@@ -1,122 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Phase 2 Remaining Apps — Per-app PVC imports (portainer → dev-tools → loki → minio-logging → forgejo)
|
||||
# Same procedure as grafana pilot; follow the pattern
|
||||
|
||||
set -e
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
echo "=== Phase 2 Remaining Apps ==="
|
||||
echo "Execute per-app cycles: portainer → dev-tools → loki → minio-logging → forgejo"
|
||||
echo ""
|
||||
|
||||
# Helper function for per-app import
|
||||
import_app_pvc() {
|
||||
local app=$1
|
||||
local namespace=$2
|
||||
local pvc_name=$3
|
||||
|
||||
echo "--- Importing $app PVC ---"
|
||||
echo ""
|
||||
|
||||
# Annotate
|
||||
echo "Step a) Annotate PVC with helm.sh/resource-policy=keep:"
|
||||
kubectl annotate pvc "$pvc_name" -n "$namespace" helm.sh/resource-policy=keep --overwrite
|
||||
echo ""
|
||||
|
||||
# Capture live spec
|
||||
echo "Step b) Capture live PVC spec:"
|
||||
kubectl get pvc "$pvc_name" -n "$namespace" -o yaml > "/tmp/${app}-pvc-live.yaml"
|
||||
echo "Saved to /tmp/${app}-pvc-live.yaml"
|
||||
echo ""
|
||||
PV_NAME=$(kubectl get pvc "$pvc_name" -n "$namespace" -o jsonpath='{.spec.volumeName}')
|
||||
echo "Bound PV: $PV_NAME"
|
||||
echo "MANUAL: Update terraform/${app}.tf with correct volumeName '$PV_NAME'"
|
||||
read -p "Press Enter once terraform/${app}.tf is updated: " _ || true
|
||||
echo ""
|
||||
|
||||
# Import
|
||||
echo "Step d) Import to Terraform state:"
|
||||
terraform import "kubernetes_persistent_volume_claim.${app}" "${namespace}/${pvc_name}" || {
|
||||
echo "ERROR: import failed for $app"
|
||||
return 1
|
||||
}
|
||||
echo ""
|
||||
|
||||
# Plan
|
||||
echo "Step d cont.) Verify zero diff:"
|
||||
PLAN_OUTPUT=$(terraform plan 2>&1)
|
||||
echo "$PLAN_OUTPUT"
|
||||
if ! echo "$PLAN_OUTPUT" | grep -q "0 to add, 0 to change, 0 to destroy"; then
|
||||
echo "ERROR: Plan is not clean for $app"
|
||||
return 1
|
||||
fi
|
||||
echo "✓ Plan is clean"
|
||||
echo ""
|
||||
|
||||
# Baseline Longhorn health
|
||||
echo "Step f.1) Baseline Longhorn replica health:"
|
||||
kubectl get longhorn-volume -n longhorn-system "$PV_NAME" -o json 2>/dev/null | jq '.status.replicaStatus' 2>/dev/null || echo " (unavailable)"
|
||||
read -p "Press Enter to continue: " _ || true
|
||||
echo ""
|
||||
|
||||
# Update values
|
||||
echo "Step e) Update values to use existingClaim (if supported) or keep identical:"
|
||||
echo "MANUAL: Verify terraform/${app}.tf resource block matches live PVC spec exactly"
|
||||
echo " Update chart values (k8s/ directory) to point to existing PVC or keep identical"
|
||||
read -p "Press Enter once values updated: " _ || true
|
||||
echo ""
|
||||
|
||||
# helmfile diff
|
||||
echo "Step e.2) Helmfile diff:"
|
||||
cd "$(dirname "$0")/../.."
|
||||
helmfile -f helmfile.yaml.gotmpl -l name="$app" diff 2>&1 | head -50 || echo " (helmfile diff unavailable)"
|
||||
cd "$(dirname "$0")/../terraform"
|
||||
echo ""
|
||||
read -p "Confirm no destructive ops. Press Enter to continue: " _ || true
|
||||
echo ""
|
||||
|
||||
# helmfile apply
|
||||
echo "Step e.3) Helmfile apply:"
|
||||
cd "$(dirname "$0")/../.."
|
||||
helmfile -f helmfile.yaml.gotmpl -l name="$app" apply || echo " (helmfile apply unavailable)"
|
||||
cd "$(dirname "$0")/../terraform"
|
||||
echo ""
|
||||
|
||||
# Post-apply Longhorn health
|
||||
echo "Step f.2) Post-apply Longhorn health:"
|
||||
kubectl get longhorn-volume -n longhorn-system "$PV_NAME" -o json 2>/dev/null | jq '.status.replicaStatus' 2>/dev/null || echo " (unavailable)"
|
||||
echo "Confirm matches baseline."
|
||||
read -p "Press Enter if health is good: " _ || true
|
||||
echo ""
|
||||
|
||||
# Final plan
|
||||
echo "Step d) Final terraform plan:"
|
||||
PLAN_OUTPUT=$(terraform plan 2>&1)
|
||||
echo "$PLAN_OUTPUT"
|
||||
if ! echo "$PLAN_OUTPUT" | grep -q "0 to add, 0 to change, 0 to destroy"; then
|
||||
echo "ERROR: Plan is not clean after helmfile apply for $app"
|
||||
return 1
|
||||
fi
|
||||
echo "✓ Plan is clean"
|
||||
echo ""
|
||||
echo "=== $app Complete ==="
|
||||
echo ""
|
||||
}
|
||||
|
||||
# Execute per-app imports in sequence (ascending risk)
|
||||
import_app_pvc "portainer" "dashboard" "portainer" || { echo "FAILED at portainer"; exit 1; }
|
||||
import_app_pvc "dev_tools" "dev-tools" "dev-tools-pvc" || { echo "FAILED at dev-tools"; exit 1; }
|
||||
import_app_pvc "loki" "logging" "loki" || { echo "FAILED at loki"; exit 1; }
|
||||
import_app_pvc "minio_logging" "logging" "minio" || { echo "FAILED at minio-logging"; exit 1; }
|
||||
import_app_pvc "forgejo_shared_storage" "cicd" "forgejo-shared-storage" || { echo "FAILED at forgejo"; exit 1; }
|
||||
|
||||
echo "=== Phase 2 Remaining Apps: Complete ==="
|
||||
echo "All safe apps imported successfully."
|
||||
echo ""
|
||||
echo "Next steps:"
|
||||
echo " 1. Conditional apps (pending Phase 0 ambiguity resolution):"
|
||||
echo " - minio (storage) — if standalone chart is authoritative"
|
||||
echo " - kmsvc-redis — if helmfile release is authoritative and architecture is standalone"
|
||||
echo " - forgejo-runner PVCs — if Helm chart is authoritative"
|
||||
echo " 2. Never import: ddb-cluster, prometheus, kafka-cluster, authentik-postgresql, llm namespace"
|
||||
echo " 3. Commit all new terraform/*.tf files to git and create PR"
|
||||
@@ -1,13 +0,0 @@
|
||||
# S3 backend (MinIO remote state)
|
||||
terraform {
|
||||
backend "s3" {
|
||||
bucket = "terraform-state"
|
||||
key = "homelab/terraform.tfstate"
|
||||
region = "us-east-1"
|
||||
endpoint = "https://minio-api.riotpiao.homelab.com"
|
||||
skip_credentials_validation = true
|
||||
skip_requesting_account_id = true
|
||||
skip_region_validation = true
|
||||
use_path_style = true
|
||||
}
|
||||
}
|
||||
@@ -1,21 +0,0 @@
|
||||
kubeconfig_path = "/Users/rockliang/workplace/homelab/cluster-config/kubeconfig"
|
||||
cluster_domain = "riotpiao.homelab.com"
|
||||
|
||||
authentik_secret_key = "v9TTdMxpP9XtrwH2HFUjHC8MKwfeW+fYOpa5RTyP6EniqFclFSDXWbRp6crhrkLJkFeCfIcAMN/JODyy"
|
||||
authentik_bootstrap_password = "8+7MFMCtAHiOxSaiBJwDiR85nnrhLyX2"
|
||||
authentik_bootstrap_token = "5a534cb785aecddac23647e11ff4d824b50b03f70c173faee7ba46f12db55dc3"
|
||||
authentik_pg_password = "vueM/7N6bUR/j/hUUPsWTM2pRm8lCewq"
|
||||
postgres_password = "a071b1f7b721a216b57d396b8d906fa10f6db1597d68a0f2e9f95e2872e7cb0f"
|
||||
minio_root_user = "minioadmin"
|
||||
minio_root_password = "nhKRAxwIjDBCzwFDvsAa7dNLouCXXh13LvMoxMVkUtY="
|
||||
minio_oidc_client_secret = "9d2867fe08c3bf7fedd7e32bbaf4456fce3b0aaf788966d7559e1955947b0219"
|
||||
grafana_admin_password = "your-secure-password"
|
||||
grafana_oidc_client_secret = "966bad4fa43812100e7775b3c73fed2ce1d07217fa5a23fbb0f190e46d2f0fa4"
|
||||
forgejo_admin_password = "stRe4cawnQH/agM0QsPaWPdKNaQ0rp4p"
|
||||
authentik_forgejo_client_secret = "e417c1a3b3ee79b44c9d8d3490a735aae7b2c19a81afe1ba6a262775d5ae9edc"
|
||||
authentik_argocd_client_id = "argocd"
|
||||
authentik_argocd_client_secret = "acc51c1ab043530b84b17dc5e8128b2a656b17558ea3f93e723618ea5c6d9774"
|
||||
authentik_temporal_client_id = "temporal"
|
||||
authentik_temporal_client_secret = "6UAuC651l21fajBZQwjV+bbkD1k6uCoV6PnQxaFlPaQ="
|
||||
argocd_admin_password = "placeholder"
|
||||
argocd_oidc_client_secret = "placeholder"
|
||||
@@ -1,35 +0,0 @@
|
||||
kubeconfig_path = "cluster-config/kubeconfig"
|
||||
cluster_domain = "riotpiao.homelab.com"
|
||||
|
||||
# Backend S3 credentials (MinIO)
|
||||
# Set via environment variables instead:
|
||||
# export AWS_ACCESS_KEY_ID=$(grep MINIO_ROOT_USER .env | cut -d= -f2)
|
||||
# export AWS_SECRET_ACCESS_KEY=$(grep MINIO_ROOT_PASSWORD .env | cut -d= -f2)
|
||||
s3_access_key = ""
|
||||
s3_secret_key = ""
|
||||
|
||||
# Vault token for terraform vault provider
|
||||
# Set via environment variable:
|
||||
# export VAULT_TOKEN=$(vault login -method=oidc ...)
|
||||
vault_token = ""
|
||||
|
||||
# Cluster secrets loaded from .env (extract via 'vsource' alias)
|
||||
# Or populate these manually from Vault/secrets manager
|
||||
authentik_secret_key = "changeme-min-32-characters-long-value"
|
||||
authentik_bootstrap_password = "changeme"
|
||||
authentik_bootstrap_token = "changeme"
|
||||
authentik_pg_password = "changeme"
|
||||
postgres_password = "changeme"
|
||||
minio_root_user = "minioadmin"
|
||||
minio_root_password = "changeme"
|
||||
minio_oidc_client_secret = "changeme"
|
||||
grafana_admin_password = "changeme"
|
||||
grafana_oidc_client_secret = "changeme"
|
||||
forgejo_admin_password = "changeme"
|
||||
authentik_forgejo_client_secret = "changeme"
|
||||
authentik_argocd_client_id = "argocd"
|
||||
authentik_argocd_client_secret = "changeme"
|
||||
authentik_temporal_client_id = "temporal"
|
||||
authentik_temporal_client_secret = "changeme"
|
||||
argocd_admin_password = "changeme"
|
||||
argocd_oidc_client_secret = "changeme"
|
||||
@@ -1,142 +0,0 @@
|
||||
variable "cluster_domain" {
|
||||
description = "Cluster domain (e.g., riotpiao.homelab.com)"
|
||||
type = string
|
||||
default = "riotpiao.homelab.com"
|
||||
}
|
||||
|
||||
variable "vault_token" {
|
||||
description = "Vault token (set via VAULT_TOKEN env var or tfvars)"
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
}
|
||||
|
||||
variable "authentik_api_token" {
|
||||
description = "Authentik API token for goauthentik provider (terraform configuration management)"
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
}
|
||||
|
||||
variable "s3_access_key" {
|
||||
description = "MinIO S3 access key for terraform state backend"
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
}
|
||||
|
||||
variable "s3_secret_key" {
|
||||
description = "MinIO S3 secret key for terraform state backend"
|
||||
type = string
|
||||
sensitive = true
|
||||
default = ""
|
||||
}
|
||||
|
||||
# Cluster secrets (load from .env.tfvars or vault)
|
||||
variable "authentik_secret_key" {
|
||||
description = "Authentik secret key"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "authentik_bootstrap_password" {
|
||||
description = "Authentik bootstrap password"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "authentik_bootstrap_token" {
|
||||
description = "Authentik bootstrap token"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "authentik_pg_password" {
|
||||
description = "Authentik PostgreSQL password"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "postgres_password" {
|
||||
description = "PostgreSQL app user password"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "minio_root_user" {
|
||||
description = "MinIO root user"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "minio_root_password" {
|
||||
description = "MinIO root password"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "minio_oidc_client_secret" {
|
||||
description = "MinIO OIDC client secret"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "grafana_admin_password" {
|
||||
description = "Grafana admin password"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "grafana_oidc_client_secret" {
|
||||
description = "Grafana OIDC client secret"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "forgejo_admin_password" {
|
||||
description = "Forgejo admin password"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "authentik_forgejo_client_secret" {
|
||||
description = "Authentik Forgejo OIDC client secret"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "authentik_argocd_client_id" {
|
||||
description = "Authentik ArgoCD OIDC client ID"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "authentik_argocd_client_secret" {
|
||||
description = "Authentik ArgoCD OIDC client secret"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "authentik_temporal_client_id" {
|
||||
description = "Authentik Temporal OIDC client ID"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "authentik_temporal_client_secret" {
|
||||
description = "Authentik Temporal OIDC client secret"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "argocd_admin_password" {
|
||||
description = "ArgoCD admin password"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "argocd_oidc_client_secret" {
|
||||
description = "ArgoCD OIDC client secret"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
Reference in New Issue
Block a user