Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 8902feada7 |
+4
-2
@@ -102,6 +102,7 @@ dig aqi.leeworks.dev +short
|
|||||||
dig docs.leeworks.dev +short
|
dig docs.leeworks.dev +short
|
||||||
dig status.leeworks.dev +short
|
dig status.leeworks.dev +short
|
||||||
dig registry.leeworks.dev +short
|
dig registry.leeworks.dev +short
|
||||||
|
dig grafana.leeworks.dev +short
|
||||||
|
|
||||||
# Check TLS certificates (once services are deployed)
|
# Check TLS certificates (once services are deployed)
|
||||||
curl -v https://zip.leeworks.dev/health 2>&1 | grep -E "SSL|certificate|issuer"
|
curl -v https://zip.leeworks.dev/health 2>&1 | grep -E "SSL|certificate|issuer"
|
||||||
@@ -125,7 +126,7 @@ The following actions require human operator access to the DNS provider:
|
|||||||
|
|
||||||
1. Log into the DNS provider managing `leeworks.dev`
|
1. Log into the DNS provider managing `leeworks.dev`
|
||||||
2. Find the cluster ingress IP: `kubectl get svc -n ingress-nginx ingress-nginx-controller`
|
2. Find the cluster ingress IP: `kubectl get svc -n ingress-nginx ingress-nginx-controller`
|
||||||
3. Create/update the 6 A records listed in the table above
|
3. Create/update the 7 A records listed in the table above
|
||||||
4. Verify propagation: `dig +trace zip.leeworks.dev`
|
4. Verify propagation: `dig +trace zip.leeworks.dev`
|
||||||
|
|
||||||
DNS propagation typically takes 5–60 minutes.
|
DNS propagation typically takes 5–60 minutes.
|
||||||
@@ -141,4 +142,5 @@ DNS propagation typically takes 5–60 minutes.
|
|||||||
- [ ] `docs.leeworks.dev` → DNS record created
|
- [ ] `docs.leeworks.dev` → DNS record created
|
||||||
- [ ] `status.leeworks.dev` → DNS record created
|
- [ ] `status.leeworks.dev` → DNS record created
|
||||||
- [ ] `registry.leeworks.dev` → DNS record created
|
- [ ] `registry.leeworks.dev` → DNS record created
|
||||||
- [ ] TLS certificates issued and valid for all 6 subdomains
|
- [ ] `grafana.leeworks.dev` → DNS record created
|
||||||
|
- [ ] TLS certificates issued and valid for all 7 subdomains
|
||||||
|
|||||||
@@ -188,7 +188,7 @@ kubectl create secret generic gitea-image-automation-token \
|
|||||||
|
|
||||||
## Phase 4 — DNS for API services (issue #33)
|
## Phase 4 — DNS for API services (issue #33)
|
||||||
|
|
||||||
Add DNS A records for all six leeworks.dev subdomains (all point to the same
|
Add DNS A records for all seven leeworks.dev subdomains (all point to the same
|
||||||
cluster ingress IP):
|
cluster ingress IP):
|
||||||
|
|
||||||
| Hostname | Target |
|
| Hostname | Target |
|
||||||
@@ -199,6 +199,16 @@ cluster ingress IP):
|
|||||||
| `docs.leeworks.dev` | `<cluster ingress IP>` |
|
| `docs.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
| `grafana.leeworks.dev` | `<cluster ingress IP>` |
|
| `grafana.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
| `status.leeworks.dev` | `<cluster ingress IP>` |
|
| `status.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
|
| `registry.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
|
|
||||||
|
Verify DNS propagation:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
for host in zip holidays aqi docs grafana status registry; do
|
||||||
|
echo -n "${host}.leeworks.dev: "
|
||||||
|
dig ${host}.leeworks.dev +short
|
||||||
|
done
|
||||||
|
```
|
||||||
|
|
||||||
cert-manager will obtain Let's Encrypt certificates automatically once DNS
|
cert-manager will obtain Let's Encrypt certificates automatically once DNS
|
||||||
propagates (typically minutes, up to 48 h).
|
propagates (typically minutes, up to 48 h).
|
||||||
|
|||||||
@@ -18,7 +18,6 @@ Follow this list top-to-bottom; each step unblocks the next.
|
|||||||
- [ ] 7. Add api-company Flux source + kustomization to 0xWheatyz/Talos — unblocks all GitOps reconciliation
|
- [ ] 7. Add api-company Flux source + kustomization to 0xWheatyz/Talos — unblocks all GitOps reconciliation
|
||||||
- [ ] 8. `gitea-registry` (zip-enrichment, holidays, air-quality, docs-site) — imagePullSecret for pods pulling from `registry.leeworks.dev`
|
- [ ] 8. `gitea-registry` (zip-enrichment, holidays, air-quality, docs-site) — imagePullSecret for pods pulling from `registry.leeworks.dev`
|
||||||
- [ ] 9. `gitea-image-automation-token` (flux-system) — write-scoped token for Flux ImageUpdateAutomation to push image-tag commits
|
- [ ] 9. `gitea-image-automation-token` (flux-system) — write-scoped token for Flux ImageUpdateAutomation to push image-tag commits
|
||||||
- [ ] 10. `rapidapi-proxy-secret` (zip-enrichment, holidays, air-quality) — RapidAPI Proxy Secret for server-side request validation
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -156,44 +155,6 @@ Unblocks: Issue #2 (Flux reconciliation of all `flux/` manifests in this repo).
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### 10. `rapidapi-proxy-secret` — RapidAPI Proxy Secret (per API namespace)
|
|
||||||
|
|
||||||
| Field | Value |
|
|
||||||
|-----------|-------|
|
|
||||||
| Name | `rapidapi-proxy-secret` |
|
|
||||||
| Namespaces | `zip-enrichment`, `holidays`, `air-quality` |
|
|
||||||
| Purpose | Every API service validates the `X-RapidAPI-Proxy-Secret` header on every route. Requests without a valid secret return HTTP 403. |
|
|
||||||
| Source | RapidAPI dashboard → API Settings → Security → **Proxy Secret** (generated after each API listing is created) |
|
|
||||||
| Unblocks | Phase 3 server middleware; API services will start but reject all traffic without this secret |
|
|
||||||
|
|
||||||
```bash
|
|
||||||
for NS in zip-enrichment holidays air-quality; do
|
|
||||||
kubectl create secret generic rapidapi-proxy-secret \
|
|
||||||
--namespace=$NS \
|
|
||||||
--from-literal=X-RapidAPI-Proxy-Secret=<value-from-rapidapi-dashboard>
|
|
||||||
done
|
|
||||||
```
|
|
||||||
|
|
||||||
**Source:** RapidAPI dashboard → select your API → Settings → Security → Proxy Secret
|
|
||||||
|
|
||||||
> **Note:** Placeholder `ExternalSecret` manifests are committed at
|
|
||||||
> `flux/zip-enrichment/externalsecret.yaml`, `flux/holidays/externalsecret.yaml`,
|
|
||||||
> and `flux/air-quality/externalsecret.yaml`. These will auto-sync this secret
|
|
||||||
> from the configured backend once the External Secrets Operator (ESO) is
|
|
||||||
> deployed (see issue #61). Until then, create manually using the commands above.
|
|
||||||
|
|
||||||
Verify:
|
|
||||||
```bash
|
|
||||||
for NS in zip-enrichment holidays air-quality; do
|
|
||||||
echo -n "$NS: "
|
|
||||||
kubectl get secret rapidapi-proxy-secret -n $NS -o jsonpath='{.data.X-RapidAPI-Proxy-Secret}' | base64 -d | wc -c
|
|
||||||
echo " chars"
|
|
||||||
done
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
## Dependency Order
|
## Dependency Order
|
||||||
|
|
||||||
```
|
```
|
||||||
@@ -205,7 +166,6 @@ done
|
|||||||
5 + 6 (GITEA_TOKEN + registry packages) → CI pushes images → API services deploy
|
5 + 6 (GITEA_TOKEN + registry packages) → CI pushes images → API services deploy
|
||||||
8 (gitea-registry) → pods can pull images from registry.leeworks.dev → services start
|
8 (gitea-registry) → pods can pull images from registry.leeworks.dev → services start
|
||||||
9 (gitea-image-automation-token) → Flux ImageUpdateAutomation pushes tag-update commits
|
9 (gitea-image-automation-token) → Flux ImageUpdateAutomation pushes tag-update commits
|
||||||
10 (rapidapi-proxy-secret × 3) → API server middleware validates RapidAPI requests → revenue enabled
|
|
||||||
```
|
```
|
||||||
|
|
||||||
Once all nine items are complete, the full stack (runner, registry, Prometheus, Grafana, Gatus, docs-site, three API services) reconciles automatically via FluxCD with no further manual steps.
|
Once all nine items are complete, the full stack (runner, registry, Prometheus, Grafana, Gatus, docs-site, three API services) reconciles automatically via FluxCD with no further manual steps.
|
||||||
|
|||||||
Reference in New Issue
Block a user