Compare commits
8 Commits
f0f00ed71a
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| 9a01da0367 | |||
| a3e9362d56 | |||
| 1ce061b98f | |||
| e8071a7e98 | |||
| caf741d9df | |||
| c29bee6f33 | |||
| ae02d2ac7c | |||
| 1ce690c199 |
@@ -13,7 +13,6 @@ jobs:
|
|||||||
node-labels: ${{ steps.filter.outputs.node-labels }}
|
node-labels: ${{ steps.filter.outputs.node-labels }}
|
||||||
coredns: ${{ steps.filter.outputs.coredns }}
|
coredns: ${{ steps.filter.outputs.coredns }}
|
||||||
traefik: ${{ steps.filter.outputs.traefik }}
|
traefik: ${{ steps.filter.outputs.traefik }}
|
||||||
crowdsec: ${{ steps.filter.outputs.crowdsec }}
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
with:
|
with:
|
||||||
@@ -28,8 +27,6 @@ jobs:
|
|||||||
- 'coredns/**'
|
- 'coredns/**'
|
||||||
traefik:
|
traefik:
|
||||||
- 'traefik/**'
|
- 'traefik/**'
|
||||||
crowdsec:
|
|
||||||
- 'crowdsec/**'
|
|
||||||
|
|
||||||
deploy-node-labels:
|
deploy-node-labels:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
@@ -37,8 +34,8 @@ jobs:
|
|||||||
if: ${{ needs.check-changes.outputs.node-labels == 'true' || github.event_name == 'workflow_dispatch' }}
|
if: ${{ needs.check-changes.outputs.node-labels == 'true' || github.event_name == 'workflow_dispatch' }}
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
- uses: azure/setup-kubectl@776406bce94f63e41d621b960d78ee25c8b76ede # v4.0.1
|
- uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0
|
||||||
- uses: azure/k8s-set-context@ae59a723ba9abe7a9655538854a025448dbab4aa # v4.0.2
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
||||||
with:
|
with:
|
||||||
method: kubeconfig
|
method: kubeconfig
|
||||||
kubeconfig: ${{ secrets.KUBECONFIG }}
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
||||||
@@ -52,8 +49,8 @@ jobs:
|
|||||||
if: ${{ needs.check-changes.outputs.coredns == 'true' || github.event_name == 'workflow_dispatch' }}
|
if: ${{ needs.check-changes.outputs.coredns == 'true' || github.event_name == 'workflow_dispatch' }}
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
- uses: azure/setup-kubectl@776406bce94f63e41d621b960d78ee25c8b76ede # v4.0.1
|
- uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0
|
||||||
- uses: azure/k8s-set-context@ae59a723ba9abe7a9655538854a025448dbab4aa # v4.0.2
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
||||||
with:
|
with:
|
||||||
method: kubeconfig
|
method: kubeconfig
|
||||||
kubeconfig: ${{ secrets.KUBECONFIG }}
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
||||||
@@ -70,8 +67,8 @@ jobs:
|
|||||||
if: ${{ needs.check-changes.outputs.traefik == 'true' || github.event_name == 'workflow_dispatch' }}
|
if: ${{ needs.check-changes.outputs.traefik == 'true' || github.event_name == 'workflow_dispatch' }}
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
- uses: azure/setup-kubectl@776406bce94f63e41d621b960d78ee25c8b76ede # v4.0.1
|
- uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0
|
||||||
- uses: azure/k8s-set-context@ae59a723ba9abe7a9655538854a025448dbab4aa # v4.0.2
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
||||||
with:
|
with:
|
||||||
method: kubeconfig
|
method: kubeconfig
|
||||||
kubeconfig: ${{ secrets.KUBECONFIG }}
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
||||||
@@ -95,16 +92,6 @@ jobs:
|
|||||||
{
|
{
|
||||||
"auth": "${{ secrets.ADMIN_BASIC_AUTH_CREDENTIALS }}"
|
"auth": "${{ secrets.ADMIN_BASIC_AUTH_CREDENTIALS }}"
|
||||||
}
|
}
|
||||||
- name: Set crowdsec bouncer api key
|
|
||||||
uses: azure/k8s-create-secret@6e0ba8047235646753f2a3a3b359b4d0006ff218 # v5.0.1
|
|
||||||
with:
|
|
||||||
namespace: kube-system
|
|
||||||
secret-name: crowdsec-bouncer-api-key
|
|
||||||
secret-type: generic
|
|
||||||
data: |
|
|
||||||
{
|
|
||||||
"api-key": "${{ secrets.CROWDSEC_BOUNCER_API_KEY }}"
|
|
||||||
}
|
|
||||||
- name: Deploy
|
- name: Deploy
|
||||||
uses: azure/k8s-deploy@c8cfec839dc09896b3b8cc40cd13d04792680771 # v5.1.0
|
uses: azure/k8s-deploy@c8cfec839dc09896b3b8cc40cd13d04792680771 # v5.1.0
|
||||||
with:
|
with:
|
||||||
@@ -113,37 +100,13 @@ jobs:
|
|||||||
strategy: basic
|
strategy: basic
|
||||||
namespace: kube-system
|
namespace: kube-system
|
||||||
|
|
||||||
deploy-crowdsec:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
needs: check-changes
|
|
||||||
if: ${{ needs.check-changes.outputs.crowdsec == 'true' || github.event_name == 'workflow_dispatch' }}
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
||||||
- uses: https://gitea.t000-n.de/t.behrendt/k_deploy_workflows/.gitea/actions/extract-namespace-from-repo-name@a7cfa06300b45468b86d351e78a0330ee3ef483d # 0.0.4
|
|
||||||
id: namespace
|
|
||||||
with:
|
|
||||||
repo: ${{ github.repository }}
|
|
||||||
- uses: azure/setup-kubectl@776406bce94f63e41d621b960d78ee25c8b76ede # v4.0.1
|
|
||||||
- uses: azure/setup-helm@1a275c3b69536ee54be43f2070a358922e12c8d4 # v4
|
|
||||||
with:
|
|
||||||
version: "3.15.0"
|
|
||||||
- uses: azure/k8s-set-context@ae59a723ba9abe7a9655538854a025448dbab4aa # v4.0.2
|
|
||||||
with:
|
|
||||||
method: kubeconfig
|
|
||||||
kubeconfig: ${{ secrets.KUBECONFIG }}
|
|
||||||
- name: Deploy helm
|
|
||||||
uses: helmfile/helmfile-action@c58e4737b8a69764d8294a70fcbcb0a63573dae9 # v2.3.1
|
|
||||||
with:
|
|
||||||
helmfile-args: apply
|
|
||||||
helmfile-workdirectory: "crowdsec"
|
|
||||||
|
|
||||||
deploy-docker-registry-secret:
|
deploy-docker-registry-secret:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
needs: check-changes
|
needs: check-changes
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
- uses: azure/setup-kubectl@776406bce94f63e41d621b960d78ee25c8b76ede # v4.0.1
|
- uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0
|
||||||
- uses: azure/k8s-set-context@ae59a723ba9abe7a9655538854a025448dbab4aa # v4.0.2
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
||||||
with:
|
with:
|
||||||
method: kubeconfig
|
method: kubeconfig
|
||||||
kubeconfig: ${{ secrets.KUBECONFIG }}
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
||||||
|
|||||||
@@ -10,8 +10,8 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
- uses: azure/setup-kubectl@776406bce94f63e41d621b960d78ee25c8b76ede # v4.0.1
|
- uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0
|
||||||
- uses: azure/k8s-set-context@ae59a723ba9abe7a9655538854a025448dbab4aa # v4.0.2
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
||||||
with:
|
with:
|
||||||
method: kubeconfig
|
method: kubeconfig
|
||||||
kubeconfig: ${{ secrets.KUBECONFIG }}
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
||||||
@@ -23,8 +23,8 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
- uses: azure/setup-kubectl@776406bce94f63e41d621b960d78ee25c8b76ede # v4.0.1
|
- uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0
|
||||||
- uses: azure/k8s-set-context@ae59a723ba9abe7a9655538854a025448dbab4aa # v4.0.2
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
||||||
with:
|
with:
|
||||||
method: kubeconfig
|
method: kubeconfig
|
||||||
kubeconfig: ${{ secrets.KUBECONFIG }}
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
||||||
@@ -36,8 +36,8 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
- uses: azure/setup-kubectl@776406bce94f63e41d621b960d78ee25c8b76ede # v4.0.1
|
- uses: azure/setup-kubectl@15650b3ad78fff148532a140b8a4c821796b2d7b # v5.0.0
|
||||||
- uses: azure/k8s-set-context@ae59a723ba9abe7a9655538854a025448dbab4aa # v4.0.2
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
||||||
with:
|
with:
|
||||||
method: kubeconfig
|
method: kubeconfig
|
||||||
kubeconfig: ${{ secrets.KUBECONFIG }}
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
||||||
@@ -47,23 +47,3 @@ jobs:
|
|||||||
namespace: kube-system
|
namespace: kube-system
|
||||||
lintType: dryrun
|
lintType: dryrun
|
||||||
manifests: "traefik/"
|
manifests: "traefik/"
|
||||||
|
|
||||||
validate-crowdsec:
|
|
||||||
runs-on:
|
|
||||||
- ubuntu-latest
|
|
||||||
- linux_amd64
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
||||||
- uses: azure/setup-kubectl@776406bce94f63e41d621b960d78ee25c8b76ede # v4.0.1
|
|
||||||
- uses: azure/setup-helm@1a275c3b69536ee54be43f2070a358922e12c8d4 # v4
|
|
||||||
with:
|
|
||||||
version: "3.15.0"
|
|
||||||
- uses: azure/k8s-set-context@ae59a723ba9abe7a9655538854a025448dbab4aa # v4.0.2
|
|
||||||
with:
|
|
||||||
method: kubeconfig
|
|
||||||
kubeconfig: ${{ secrets.KUBECONFIG }}
|
|
||||||
- name: Validate Helm
|
|
||||||
uses: helmfile/helmfile-action@c58e4737b8a69764d8294a70fcbcb0a63573dae9 # v2.3.1
|
|
||||||
with:
|
|
||||||
helmfile-args: diff
|
|
||||||
helmfile-workdirectory: "crowdsec"
|
|
||||||
|
|||||||
@@ -1,12 +0,0 @@
|
|||||||
repositories:
|
|
||||||
- name: crowdsec
|
|
||||||
url: https://crowdsecurity.github.io/helm-charts
|
|
||||||
|
|
||||||
releases:
|
|
||||||
- name: crowdsec
|
|
||||||
namespace: kube-system
|
|
||||||
createNamespace: false
|
|
||||||
chart: crowdsec/crowdsec
|
|
||||||
version: 0.20.0
|
|
||||||
values:
|
|
||||||
- values.yaml
|
|
||||||
@@ -1,35 +0,0 @@
|
|||||||
container_runtime: containerd
|
|
||||||
|
|
||||||
agent:
|
|
||||||
enabled: true
|
|
||||||
acquisition:
|
|
||||||
- namespace: kube-system
|
|
||||||
podName: traefik-*
|
|
||||||
program: traefik
|
|
||||||
metrics:
|
|
||||||
enabled: false
|
|
||||||
|
|
||||||
lapi:
|
|
||||||
enabled: true
|
|
||||||
replicas: 1
|
|
||||||
metrics:
|
|
||||||
enabled: true
|
|
||||||
persistentVolume:
|
|
||||||
data:
|
|
||||||
enabled: true
|
|
||||||
size: 1Gi
|
|
||||||
config:
|
|
||||||
enabled: true
|
|
||||||
size: 100Mi
|
|
||||||
|
|
||||||
config:
|
|
||||||
config.yaml.local: |
|
|
||||||
api:
|
|
||||||
server:
|
|
||||||
auto_registration:
|
|
||||||
enabled: true
|
|
||||||
token: "${REGISTRATION_TOKEN}"
|
|
||||||
allowed_ranges:
|
|
||||||
- "10.0.0.0/8"
|
|
||||||
- "172.16.0.0/12"
|
|
||||||
- "192.168.0.0/16"
|
|
||||||
34
traefik/pvc.yaml
Normal file
34
traefik/pvc.yaml
Normal file
@@ -0,0 +1,34 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: pv-traefik-hostpath-static
|
||||||
|
spec:
|
||||||
|
capacity:
|
||||||
|
storage: 10Gi
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
persistentVolumeReclaimPolicy: Retain
|
||||||
|
storageClassName: traefik-certificates
|
||||||
|
local:
|
||||||
|
path: /mnt/longhorn1/svc/kube-system/main/traefik/data
|
||||||
|
nodeAffinity:
|
||||||
|
required:
|
||||||
|
nodeSelectorTerms:
|
||||||
|
- matchExpressions:
|
||||||
|
- key: kubernetes.io/hostname
|
||||||
|
operator: In
|
||||||
|
values:
|
||||||
|
- k3sh0
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: pvc-traefik
|
||||||
|
namespace: kube-system
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
storageClassName: traefik-certificates
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 10Gi
|
||||||
@@ -32,11 +32,6 @@ spec:
|
|||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
key: apiKey
|
key: apiKey
|
||||||
name: ionos-api-credentials
|
name: ionos-api-credentials
|
||||||
- name: CROWDSEC_BOUNCER_API_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: crowdsec-bouncer-api-key
|
|
||||||
key: api-key
|
|
||||||
ports:
|
ports:
|
||||||
web:
|
web:
|
||||||
port: 8000
|
port: 8000
|
||||||
@@ -65,16 +60,5 @@ spec:
|
|||||||
persistence:
|
persistence:
|
||||||
enabled: true
|
enabled: true
|
||||||
name: data
|
name: data
|
||||||
accessMode: ReadWriteMany
|
existingClaim: pvc-traefik
|
||||||
size: 1Gi
|
|
||||||
storageClass: longhorn
|
|
||||||
path: /data
|
path: /data
|
||||||
#experimental:
|
|
||||||
# plugins:
|
|
||||||
# crowdsec-bouncer-traefik-plugin:
|
|
||||||
# moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
|
|
||||||
# version: v1.4.6
|
|
||||||
#additionalArguments:
|
|
||||||
# - "--providers.kubernetescrd"
|
|
||||||
# - "--entrypoints.web.http.middlewares=crowdsec-bouncer@kubernetescrd"
|
|
||||||
# - "--entrypoints.websecure.http.middlewares=kube-system-crowdsec-bouncer@kubernetescrd"
|
|
||||||
|
|||||||
Reference in New Issue
Block a user