Add Flux CD GitOps sync for alaska/core stacks

Prepares clusters/production/ for `flux bootstrap git` - Kustomizations
for manifests/alaska and manifests/core, plus a Gitea push Receiver so
new commits reconcile immediately instead of waiting on the poll
interval. Webhook exposed on a dedicated host (flux-webhook.workolik.com)
to avoid the existing queue.workolik.com Gateway/Ingress overlap.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-07-20 10:10:58 +05:30
parent c38a36709b
commit f58f339b43
5 changed files with 74 additions and 0 deletions

View File

@@ -0,0 +1,14 @@
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: alaska
namespace: flux-system
spec:
interval: 10m
sourceRef:
kind: GitRepository
name: flux-system
path: ./manifests/alaska
prune: true
wait: true
timeout: 3m

View File

@@ -0,0 +1,14 @@
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: core
namespace: flux-system
spec:
interval: 10m
sourceRef:
kind: GitRepository
name: flux-system
path: ./manifests/core
prune: true
wait: true
timeout: 3m

View File

@@ -0,0 +1,23 @@
# Dedicated host so this never shares a routing table with
# queue.workolik.com, which already has a Gateway + Ingress conflict history.
# Requires a DNS A record for flux-webhook.workolik.com pointing at the same
# LB IP the other *.workolik.com hosts use.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: flux-webhook-ingress
namespace: flux-system
annotations:
traefik.ingress.kubernetes.io/router.tls: "true"
spec:
rules:
- host: flux-webhook.workolik.com
http:
paths:
- path: /hook
pathType: Prefix
backend:
service:
name: webhook-receiver
port:
number: 80

View File

@@ -0,0 +1,17 @@
# The referenced Secret (gitea-webhook-token) is created directly on the
# cluster, not committed here - see the server-side command sequence.
apiVersion: notification.toolkit.fluxcd.io/v1
kind: Receiver
metadata:
name: gitea-receiver
namespace: flux-system
spec:
type: gitea
events:
- push
secretRef:
name: gitea-webhook-token
resources:
- apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
name: flux-system