Story Crater Bot
d55e7ff31e
fix(vault): use minio-cluster-hl:9000 instead of service port
2026-07-21 15:36:11 -07:00
Story Crater Bot
eda152015c
fix(vault): clean up S3 config with timeout
2026-07-21 15:26:54 -07:00
Story Crater Bot
c9bf9f7dce
fix(vault): correct S3 timeout config placement
2026-07-21 15:26:41 -07:00
Story Crater Bot
5170921eea
fix(vault): add S3 session timeout to prevent hanging
2026-07-21 15:26:29 -07:00
Story Crater Bot
ef348d23f4
fix(vault): use minio service on port 80 (maps to 9000)
2026-07-21 14:52:24 -07:00
Story Crater Bot
04ec157c19
fix(vault): correct MinIO endpoint to minio-cluster-hl service
2026-07-21 14:46:54 -07:00
Story Crater Bot
3e7238f71c
fix(prometheus): scrapeTimeout must be <= scrapeInterval — authentik/nginx SMs (60s>30s) + global (60s>30s) blocked operator config gen, no Prometheus STS created
2026-07-21 11:08:23 -07:00
Story Crater Bot
3f4653ac56
fix(argocd): raise repo-server memory 512Mi->1Gi — OOMKilled under CMP+Helm rendering caused chronic restarts, not-ready endpoint, and cluster-wide sync 'no route to host' failures
2026-07-21 10:01:11 -07:00
Story Crater Bot
da925f3101
fix(forgejo-runner): add fsGroup 1000 so runner user can write /data/.runner — register hit permission denied on root-owned Longhorn PVC
2026-07-21 09:40:59 -07:00
Story Crater Bot
2443708abb
chore(ci): refresh forgejo runner registration token — prior token invalid/expired
2026-07-21 09:38:15 -07:00
Story Crater Bot
9a34c12068
fix(forgejo-runner): point at in-cluster forgejo Service :3000 not public :443 — runner i/o timeout, forgejo serves 3000 not 443
2026-07-21 09:35:32 -07:00
Story Crater Bot
4363739d59
fix(loki,vault,iam): loki minio endpoint :80 not :9000, emit vault-minio-creds via CMP, drop redundant broken authentik-migrations job
2026-07-21 09:24:52 -07:00
Story Crater Bot
0471177250
chore(ci): add SOPS-encrypted runner-token secret record for forgejo-runner registration
2026-07-21 07:55:28 -07:00
Story Crater Bot
7fb73d6a4c
fix(scheduling): pin portainer+forgejo-runner to az-a, add nodeSelector to runner chart template — WFFC alone insufficient with single Longhorn node (cp-1 only)
2026-07-20 23:51:46 -07:00
Story Crater Bot
e0b24c83d0
fix(storage): add longhorn-wffc WaitForFirstConsumer default SC, repoint portainer/forgejo-runner — Immediate binding placed PVCs on non-storage nodes (cp-2/cp-3), attach failed
2026-07-20 23:49:01 -07:00
Story Crater Bot
9117fd777a
fix(authentik): drop redundant authentik-migrate init container — server entrypoint migrates; old-image manage migrate tripped version-history precheck on empty DB
2026-07-20 23:40:08 -07:00
Story Crater Bot
89fa87f7c1
fix(sops-cmp): grafana-admin secret needs admin-user key too — chart existingSecret requires both user and password
2026-07-20 23:07:51 -07:00
Story Crater Bot
2ec6eba9d2
fix(sops-cmp): correct loki s3 path (.loki.storage.s3), emit authentik-secrets separately, drop broken discover — merge via server/worker/migrate envFrom
...
Loki keys are under .loki.storage.s3 not .loki.s3 (returned null). Emit a separate
authentik-secrets Secret (not 'authentik', which the Helm chart owns) and merge it
via envFrom on server/worker/migrate. Remove discover fileName (caused MatchRepository
timeouts; app names the plugin explicitly).
2026-07-20 22:55:23 -07:00
Story Crater Bot
d6f5b9ed69
feat(argocd): wire SOPS ConfigManagementPlugin properly — initContainer installs sops/yq, sidecar decrypts *.enc.yaml into app Secrets
...
Correct CMP setup (prior attempt used unsupported config): repoServer.initContainers
fetches sops v3.9.0 + yq v4.44.3 into a shared volume; repoServer.extraContainers
runs argocd-cmp-server with plugin.yaml from the sops-cmp-plugin ConfigMap, age key
from sops-age Secret. Plugin emits authentik/loki-s3-creds/grafana-admin/grafana-oidc
Secrets from decrypted enc files. sops-secrets Application (wave 0) uses the plugin at
repo root. Unblocks authentik/loki/grafana which were Degraded on missing secrets.
2026-07-20 13:13:47 -07:00
Story Crater Bot
abaea8823b
refactor(argocd): simplify secrets approach — use directory source, manual Secrets for Stage 0
...
Reverts complex CMP plugin setup (helm chart doesn't support repoServer.extraContainers).
Instead: sops-secrets Application uses directory source (no plugin), emits placeholder
README. Manually-created Secrets (grafana-admin) live in target namespaces.
Full CMP plugin work deferred to future stage. Grafana values still wired to
admin.existingSecret (no-op until Secret exists, which it now does).
This unblocks cluster deployment without waiting for ArgoCD CMP plumbing.
2026-07-20 11:49:23 -07:00
Story Crater Bot and Claude Haiku 4.5
d282ae1aa0
feat(argocd): deploy SOPS CMP plugin for secret decryption — Stage 0 grafana
...
Adds ConfigManagementPlugin (CMP) sidecar to argocd-repoServer. Plugin decrypts
*.enc.yaml files with age key from sops-age Secret, emits plain Kubernetes Secrets.
Stage 0: grafana only (2 Secrets: grafana-oidc + new grafana-admin). Updates
grafana-values.yaml to wire admin.existingSecret (chart-native support).
CMP Application (00-secrets.yaml) syncs at wave 0 before grafana/loki/authentik.
Decryption happens on-demand during sync, no pre-built Secret commits. Stages 1-4
(loki/authentik/forgejo/temporal) extend plugin script incrementally after
verification.
Co-Authored-By: Claude Haiku 4.5 <[email protected] >
2026-07-20 11:30:06 -07:00
Story Crater Bot
578a707867
feat(gitops): migrate domain to riotpiao.com, add CNPG + Forgejo HA on Redis/Postgres, wire ArgoCD apps — enables cluster rebuild after etcd wipe and unblocks the git-source chicken-egg via standalone Helm-source Applications
2026-07-19 09:29:17 -07:00
Story Crater Bot
2d7330798b
refactor(k8s): Reorganize into 5-layer structure with production kustomizations
2026-07-16 14:28:19 -07:00