Restore dashboard skip-login; remove dead Flux config

Skip-login was stripped in the earlier "harden security" pass, which
is why the dashboard started demanding a token. Re-added
--enable-skip-login; it now runs as the dashboard's own view-only
ServiceAccount (get/list/watch), so opening it needs no token but
write access still requires the admin-user token.

Also removes clusters/production/ (flux-system bootstrap, the
apps-alaska/core/nearle Kustomizations, gitea webhook receiver) since
Flux was removed on the server side - deploys are manual kubectl
apply / deploy-*.sh from here on, and this config had no controller
left to read it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-07-20 12:37:31 +05:30
parent 1b629d8ea3
commit dd5dfe10f7
8 changed files with 0 additions and 6202 deletions

View File

@@ -1,14 +0,0 @@
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: alaska
namespace: flux-system
spec:
interval: 10m
sourceRef:
kind: GitRepository
name: flux-system
path: ./manifests/alaska
prune: true
wait: true
timeout: 3m

View File

@@ -1,14 +0,0 @@
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: core
namespace: flux-system
spec:
interval: 10m
sourceRef:
kind: GitRepository
name: flux-system
path: ./manifests/core
prune: true
wait: true
timeout: 3m

View File

@@ -1,14 +0,0 @@
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: nearle
namespace: flux-system
spec:
interval: 10m
sourceRef:
kind: GitRepository
name: flux-system
path: ./manifests/nearle
prune: true
wait: true
timeout: 5m

File diff suppressed because it is too large Load Diff

View File

@@ -1,27 +0,0 @@
# This manifest was generated by flux. DO NOT EDIT.
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
name: flux-system
namespace: flux-system
spec:
interval: 1m0s
ref:
branch: main
secretRef:
name: flux-system
url: https://gitapp.workolik.com/Nearle/kubernetes.git
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: flux-system
namespace: flux-system
spec:
interval: 10m0s
path: ./clusters/production
prune: true
sourceRef:
kind: GitRepository
name: flux-system

View File

@@ -1,5 +0,0 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- gotk-components.yaml
- gotk-sync.yaml

View File

@@ -1,20 +0,0 @@
# The referenced Secret (gitea-webhook-token) is created directly on the
# cluster, not committed here - see the server-side command sequence.
apiVersion: notification.toolkit.fluxcd.io/v1
kind: Receiver
metadata:
name: gitea-receiver
namespace: flux-system
spec:
# This Flux version's Receiver CRD has no "gitea" type - valid values are
# generic, generic-hmac, generic-oidc, github, gitlab, bitbucket, harbor,
# dockerhub, quay, gcr, nexus, acr, cdevents. "generic" accepts any POST
# to the hook path without payload/signature parsing, which is fine here:
# worst case is an early sync trigger, not a permission escalation.
type: generic
secretRef:
name: gitea-webhook-token
resources:
- apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
name: flux-system

View File

@@ -1,19 +0,0 @@
# Exposes Flux's webhook-receiver directly via NodePort, bypassing
# Traefik/Ingress/DNS entirely - no A record needed. Selector matches the
# notification-controller pod labels from Flux's own bundled manifests; if
# `kubectl get endpoints webhook-receiver-external -n flux-system` comes up
# empty after this applies, check the pod's real labels with
# `kubectl get pods -n flux-system --show-labels` and fix the selector below.
apiVersion: v1
kind: Service
metadata:
name: webhook-receiver-external
namespace: flux-system
spec:
type: NodePort
selector:
app: notification-controller
ports:
- port: 80
targetPort: 9292
protocol: TCP