Compare commits

..

26 Commits

Author SHA1 Message Date
gitea-admin cc8e6a8703 feat: deploy Tailscale Operator and auth secret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 02:02:48 +00:00
gitea-admin 82848e37d6 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:48 +00:00
gitea-admin b3dbc88e04 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:47 +00:00
gitea-admin 440d7bae96 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:47 +00:00
gitea-admin af493fb726 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:47 +00:00
gitea-admin 4d8e974632 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:47 +00:00
gitea-admin ee32969622 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:46 +00:00
gitea-admin 9dc53835d3 Merge pull request 'feat: add ExternalSecret for Tailscale auth key' (#14) from orion/auto/feat-add-externalsecret-for-tailscale-au-1778373309640 into main
Reviewed-on: #14
2026-05-10 00:36:57 +00:00
gitea-admin 418e32e4eb Merge pull request 'feat: add ExternalSecret for Tailscale' (#15) from orion/auto/feat-add-externalsecret-for-tailscale-1778373314635 into main
Auto-merged by ORION: feat: add ExternalSecret for Tailscale
2026-05-10 00:35:15 +00:00
gitea-admin 21c7856bbd feat: add ExternalSecret for Tailscale
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 00:35:14 +00:00
gitea-admin 501913ad5f feat: add ExternalSecret for Tailscale auth key
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 00:35:09 +00:00
gitea-admin 14f2e6bd99 Merge pull request 'feat: add ClusterSecretStore and ExternalSecret for Tailscale' (#13) from orion/auto/feat-add-clustersecretstore-and-external-1778373293466 into main
Auto-merged by ORION: feat: add ClusterSecretStore and ExternalSecret for Tailscale
2026-05-10 00:34:54 +00:00
gitea-admin 53e8a505bd feat: add ClusterSecretStore and ExternalSecret for Tailscale
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 00:34:53 +00:00
gitea-admin 2d8cc39df2 feat: add ClusterSecretStore and ExternalSecret for Tailscale 2026-05-10 00:34:53 +00:00
gitea-admin 9b9c164312 Merge pull request 'feat: apply tailscale-auth ExternalSecret' (#11) from orion/auto/feat-apply-tailscale-auth-externalsecret-1778363886223 into main
Auto-merged by ORION: feat: apply tailscale-auth ExternalSecret
2026-05-09 21:58:07 +00:00
gitea-admin 0f9575042c feat: apply tailscale-auth ExternalSecret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-09 21:58:06 +00:00
gitea-admin 7088256cf4 Merge pull request 'feat: deploy Tailscale operator' (#10) from orion/auto/feat-deploy-tailscale-operator-1778357494349 into main
Reviewed-on: #10
2026-05-09 21:42:39 +00:00
gitea-admin faa45e87da feat: deploy Tailscale operator
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-09 20:11:34 +00:00
gitea-admin 142911c8d2 feat: deploy Tailscale operator 2026-05-09 20:11:34 +00:00
gitea-admin aef5f9b702 Merge pull request 'feat: deploy Tailscale Operator for remote cluster access' (#6) from orion/auto/feat-deploy-tailscale-operator-for-remot-1778353397574 into main
Auto-merged by ORION: feat: deploy Tailscale Operator for remote cluster access
2026-05-09 19:03:19 +00:00
gitea-admin 16e2b4e9b2 feat: deploy Tailscale Operator for remote cluster access
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-09 19:03:18 +00:00
gitea-admin b3527c2b16 feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:18 +00:00
gitea-admin 5fe154d80d feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:18 +00:00
gitea-admin b0042e5510 feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:18 +00:00
gitea-admin cb1b83907b feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:17 +00:00
gitea-admin 116a118b0b Merge pull request 'chore: remove Tailscale operator and all related manifests' (#5) from orion/auto/chore-remove-tailscale-operator-and-all--1778352258236 into main
Reviewed-on: #5
2026-05-09 19:00:37 +00:00
16 changed files with 378 additions and 0 deletions
@@ -0,0 +1,45 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app: tailscale-operator
spec:
replicas: 1
selector:
matchLabels:
app: tailscale-operator
template:
metadata:
labels:
app: tailscale-operator
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:v1.78.0
env:
- name: TS_AUTHKEY
valueFrom:
secretKeyRef:
name: tailscale-auth
key: TS_AUTH_KEY
- name: DEPLOYMENT_TYPE
value: "k8s"
ports:
- containerPort: 8080
name: http-metrics
readinessProbe:
httpGet:
path: /metrics
port: http-metrics
initialDelaySeconds: 10
periodSeconds: 15
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 200m
memory: 256Mi
+33
View File
@@ -0,0 +1,33 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: tailscale
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
rules:
- apiGroups: [""]
resources: ["secrets", "services", "endpoints", "namespaces", "nodes"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["apps"]
resources: ["deployments", "statefulsets", "daemonsets"]
verbs: ["get", "list", "watch", "update", "patch"]
- apiGroups: ["tailscale.com"]
resources: ["*"]
verbs: ["*"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: tailscale
@@ -0,0 +1,14 @@
apiVersion: external-secrets.io/v1
kind: ClusterSecretStore
metadata:
name: orion-vault
namespace: vault
spec:
provider:
vault:
server: "http://vault.vault.svc.cluster.local:8200"
path: "secret"
auth:
agentAuth:
path: "kubernetes"
namespace: "vault"
+19
View File
@@ -0,0 +1,19 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
labels:
app: tailscale-operator
rules:
- apiGroups: [""]
resources: ["pods", "services", "secrets", "configmaps"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["apps"]
resources: ["deployments", "statefulsets"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["discovery.k8s.io"]
resources: ["endpointslices"]
verbs: ["get", "list", "watch"]
- apiGroups: ["coordination.k8s.io"]
resources: ["leases"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
@@ -0,0 +1,14 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
labels:
app: tailscale-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: apps
+9
View File
@@ -0,0 +1,9 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: tailscale-operator
namespace: apps
labels:
app: tailscale-operator
data:
TS_KUBE_OBJECT_STORE: "true"
+42
View File
@@ -0,0 +1,42 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: apps
labels:
app: tailscale-operator
spec:
replicas: 1
selector:
matchLabels:
app: tailscale-operator
template:
metadata:
labels:
app: tailscale-operator
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:1.72.0
env:
- name: TS_AUTH_KEY
valueFrom:
secretKeyRef:
name: tailscale-auth
key: TS_AUTH_KEY
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 100m
memory: 128Mi
@@ -0,0 +1,20 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: tailscale-auth
namespace: apps
labels:
app: tailscale-operator
spec:
refreshInterval: 1h
secretStoreRef:
name: orion-vault
kind: ClusterSecretStore
target:
name: tailscale-auth
creationPolicy: Owner
data:
- secretKey: TS_AUTH_KEY
remoteRef:
key: secret/data/tailscale
property: TS_AUTH_KEY
+6
View File
@@ -0,0 +1,6 @@
apiVersion: v1
kind: Namespace
metadata:
name: apps
labels:
name: apps
@@ -0,0 +1,7 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: apps
labels:
app: tailscale-operator
+12
View File
@@ -0,0 +1,12 @@
apiVersion: v1
kind: Secret
metadata:
name: tailscale-operator-secret
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
type: Opaque
data:
# TODO: Fill in the Tailscale auth key (base64 encoded)
authkey: PLACEHOLDER
+66
View File
@@ -0,0 +1,66 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
template:
metadata:
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
spec:
serviceAccountName: tailscale-operator
securityContext:
runAsNonRoot: true
containers:
- name: operator
image: ghcr.io/tailscale/operator:v1.76.0
args:
- --hostname=$(POD_NAME)
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
envFrom:
- secretRef:
name: tailscale-operator-secret
ports:
- containerPort: 8080
name: metrics
protocol: TCP
resources:
requests:
cpu: 10m
memory: 64Mi
limits:
cpu: 100m
memory: 128Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsUser: 1000
runAsGroup: 1000
capabilities:
drop:
- ALL
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: node-role.kubernetes.io/control-plane
operator: Exists
@@ -0,0 +1,18 @@
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: tailscale-auth
namespace: tailscale
spec:
refreshInterval: 1h
secretStoreRef:
name: orion-vault
kind: ClusterSecretStore
target:
name: tailscale-auth
creationPolicy: Owner
data:
- secretKey: TS_AUTH_KEY
remoteRef:
key: secret/tailscale
property: TS_AUTH_KEY
+7
View File
@@ -0,0 +1,7 @@
apiVersion: v1
kind: Namespace
metadata:
name: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
+48
View File
@@ -0,0 +1,48 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
rules:
- apiGroups: ['']
resources: ['secrets', 'services', 'endpoints']
verbs: ['get', 'list', 'watch', 'create', 'update', 'patch', 'delete']
- apiGroups: ['']
resources: ['nodes']
verbs: ['get', 'list', 'update', 'patch']
- apiGroups: ['apps']
resources: ['daemonsets']
verbs: ['get', 'list', 'watch']
- apiGroups: ['tailscale.com']
resources: ['*']
verbs: ['get', 'list', 'watch', 'create', 'update', 'patch', 'delete']
- apiGroups: ['coordination.k8s.io']
resources: ['leases']
verbs: ['get', 'create', 'update']
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: tailscale
+18
View File
@@ -0,0 +1,18 @@
apiVersion: v1
kind: Service
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
spec:
type: ClusterIP
ports:
- name: metrics
port: 8080
targetPort: 8080
protocol: TCP
selector:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator