9330107fcc
Implements Option A: move Vault (3x GCE e2-small) and Gitea (Legion k8s) onto a new GKE Autopilot cluster (neuron-platform, us-central1) managed through Legion Argo CD. Terraform (servers/gcp/): - gke.tf: GKE Autopilot cluster, Workload Identity bindings for Vault (KMS) and Gitea (Cloud SQL) - cloud-sql.tf: gitea database + user on neuron-prod-pg15, gitea GCP SA, gitea-database-url and gitea-db-password Secret Manager secrets - vault-nodes.tf: PENDING DECOMMISSION comment with migration checklist k8s manifests (servers/gcp/k8s/): - vault/: namespace.yaml - gitea/: namespace, serviceaccount (Workload Identity annotation), pvc (50Gi standard-rwo), deployment (Gitea + Cloud SQL Auth Proxy sidecar), service, configmap (custom CSS carried from Legion), external-secrets (GCP SM provider) - argocd-apps/: vault-gke.yaml, vault-helm-gke.yaml (Helm chart, HA Raft 3 replicas, GCP KMS auto-unseal, topologySpread across zones, 10Gi premium-rwo), gitea-gke.yaml — all target GKE_CLUSTER_ENDPOINT placeholder Legion (servers/legion/): - apps/gke-apps.yaml: App-of-Apps entry point on Legion Argo CD that syncs the GKE Application manifests - k8s/gitea-runner/Dockerfile: add system-level git insteadOf so GKE CI runners resolve Gitea in-cluster without Cloudflare Access headers
39 lines
1.5 KiB
YAML
39 lines
1.5 KiB
YAML
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: gitea-gke
|
|
namespace: argocd
|
|
annotations:
|
|
# Apply to the Legion Argo CD instance after registering the GKE cluster.
|
|
# See vault-gke.yaml for the cluster registration steps.
|
|
#
|
|
# Migration checklist (Gitea from Legion to GKE):
|
|
# 1. terraform apply (creates GKE cluster, Cloud SQL gitea DB, secrets)
|
|
# 2. Register GKE cluster with Legion Argo CD (see vault-gke.yaml)
|
|
# 3. Install ESO on GKE: helm install external-secrets external-secrets/external-secrets
|
|
# --namespace external-secrets --create-namespace
|
|
# 4. Apply this Application to Legion Argo CD
|
|
# 5. Verify gitea pod is running on GKE with DB connectivity
|
|
# 6. Take a tar of /data from the Legion Gitea pod and restore to GKE PVC
|
|
# 7. Update Cloudflare Tunnel on Legion: remove git.neuralplatform.ai route
|
|
# 8. Add GKE ingress / GCP LB rule for git.neuralplatform.ai
|
|
# 9. Decommission Gitea on Legion (remove gitea*.yaml from servers/legion/apps/)
|
|
spec:
|
|
project: default
|
|
source:
|
|
repoURL: http://gitea.git.svc.cluster.local:3000/will/infrastructure.git
|
|
targetRevision: main
|
|
path: servers/gcp/k8s/gitea
|
|
destination:
|
|
# Replace GKE_CLUSTER_ENDPOINT after `terraform apply`:
|
|
# terraform -chdir=servers/gcp output -raw gke_cluster_endpoint
|
|
server: https://GKE_CLUSTER_ENDPOINT
|
|
namespace: gitea
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
- ServerSideApply=true
|