Compare commits

...

35 Commits

Author SHA1 Message Date
gitea-admin 1e2c451dfb feat: deploy Tailscale Operator
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-09 19:07:00 +00:00
gitea-admin 20423ab28a feat: deploy Tailscale Operator 2026-05-09 19:07:00 +00:00
gitea-admin cdeb5241a4 feat: deploy Tailscale Operator 2026-05-09 19:07:00 +00:00
gitea-admin aef5f9b702 Merge pull request 'feat: deploy Tailscale Operator for remote cluster access' (#6) from orion/auto/feat-deploy-tailscale-operator-for-remot-1778353397574 into main
Auto-merged by ORION: feat: deploy Tailscale Operator for remote cluster access
2026-05-09 19:03:19 +00:00
gitea-admin 16e2b4e9b2 feat: deploy Tailscale Operator for remote cluster access
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-09 19:03:18 +00:00
gitea-admin b3527c2b16 feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:18 +00:00
gitea-admin 5fe154d80d feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:18 +00:00
gitea-admin b0042e5510 feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:18 +00:00
gitea-admin cb1b83907b feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:17 +00:00
gitea-admin 116a118b0b Merge pull request 'chore: remove Tailscale operator and all related manifests' (#5) from orion/auto/chore-remove-tailscale-operator-and-all--1778352258236 into main
Reviewed-on: #5
2026-05-09 19:00:37 +00:00
gitea-admin 1a274c625b chore: remove Tailscale operator and all related manifests
Validate Manifests / validate (pull_request) Failing after 29s
2026-05-09 18:44:20 +00:00
gitea-admin f8f180566e chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:20 +00:00
gitea-admin 8ed5a211ba chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:19 +00:00
gitea-admin f69fc01fd1 chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:19 +00:00
gitea-admin 94fbc325d4 chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:19 +00:00
gitea-admin d7114b159e chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:19 +00:00
gitea-admin a185abe525 chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:18 +00:00
gitea-admin 2a66adfd69 chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:18 +00:00
gitea-admin 4684bc1fca ci: add manifest validation workflow 2026-05-09 18:37:41 +00:00
gitea-admin 839045b831 chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:19:00 +00:00
gitea-admin ce984792cc chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:19:00 +00:00
gitea-admin 0f88fa4953 chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:59 +00:00
gitea-admin 8c088c2008 chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:59 +00:00
gitea-admin ec8369cfc9 chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:59 +00:00
gitea-admin 39f87dfcdd chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:59 +00:00
gitea-admin 4d928cac0b chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:58 +00:00
gitea-admin 82fa0b71ab chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:58 +00:00
gitea-admin f8d61d0f1c chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:58 +00:00
gitea-admin 51718a46dc Merge pull request 'feat: add Tailscale operator and DaemonSet' (#4) from orion/auto/feat-add-tailscale-operator-and-daemonse-1778347811370 into main
test
2026-05-09 17:36:55 +00:00
gitea-admin 5b8af9c537 feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:12 +00:00
gitea-admin 462eebad61 feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:12 +00:00
gitea-admin 81fc72b3eb feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:12 +00:00
gitea-admin b5f7f2bd50 feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:11 +00:00
gitea-admin 4ff6f4de76 feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:11 +00:00
gitea-admin 74b55be570 Merge pull request 'feat: deploy Tailscale Operator for secure cluster access' (#3) from orion/auto/feat-deploy-tailscale-operator-for-secur-1778347768093 into main
Auto-merged by ORION: feat: deploy Tailscale Operator for secure cluster access
2026-05-09 17:29:29 +00:00
20 changed files with 280 additions and 80 deletions
+58
View File
@@ -0,0 +1,58 @@
name: Validate Manifests
on:
pull_request:
branches: [main]
jobs:
validate:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install kubeconform
run: |
curl -sL https://github.com/yannh/kubeconform/releases/download/v0.6.7/kubeconform-linux-amd64.tar.gz \
| tar xz -C /usr/local/bin
chmod +x /usr/local/bin/kubeconform
- name: Schema validation (kubeconform)
run: |
find . -name '*.yaml' -o -name '*.yml' \
| grep -v '\.gitea/' \
| sort \
| xargs kubeconform \
-strict \
-ignore-missing-schemas \
-kubernetes-version 1.30.0 \
-summary
- name: Install kubectl
run: |
K8S_VER=$(curl -sL https://dl.k8s.io/release/stable.txt)
curl -sLO "https://dl.k8s.io/release/${K8S_VER}/bin/linux/amd64/kubectl"
chmod +x kubectl && mv kubectl /usr/local/bin/kubectl
- name: Server-side dry-run (CRD existence check)
env:
KUBECONFIG_DATA: ${{ secrets.KUBECONFIG }}
run: |
echo "$KUBECONFIG_DATA" | base64 -d > /tmp/kube.yaml
# Apply all YAML files in sorted order — server-side dry-run rejects
# any apiVersion/Kind whose CRD is not installed in the cluster.
find . -name '*.yaml' -o -name '*.yml' \
| grep -v '\.gitea/' \
| sort \
| xargs -I{} kubectl apply \
--dry-run=server \
--kubeconfig /tmp/kube.yaml \
-f {} 2>&1 \
| tee /tmp/dryrun.log
rm -f /tmp/kube.yaml
# Fail if any "no kind is registered" or "no matches for kind" errors
if grep -qE "no kind is registered|no matches for kind|unknown field" /tmp/dryrun.log; then
echo "❌ Dry-run found unknown resources or fields — manifests reference CRDs not installed in the cluster"
exit 1
fi
echo "✅ All manifests passed server-side dry-run"
-34
View File
@@ -1,34 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale-operator
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: tailscale-operator
template:
metadata:
labels:
app.kubernetes.io/name: tailscale-operator
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/kubernetes-operator:v1.70.1
env:
- name: TS_AUTH_KEY
valueFrom:
secretKeyRef:
name: tailscale-auth
key: TS_AUTH_KEY
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 100m
memory: 128Mi
-36
View File
@@ -1,36 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: tailscale
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
rules:
- apiGroups: ["apps"]
resources: ["deployments", "statefulsets", "daemonsets"]
verbs: ["get", "list", "watch", "update", "patch"]
- apiGroups: [""]
resources: ["services", "endpoints"]
verbs: ["get", "list", "watch", "update", "patch"]
- apiGroups: ["policy.tailscale.com"]
resources: ["tailnets", "tailscales"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["policy.tailscale.com"]
resources: ["tailnets/status", "tailscales/status"]
verbs: ["get", "update", "patch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: tailscale
-9
View File
@@ -1,9 +0,0 @@
apiVersion: policy.tailscale.com/v1alpha1
kind: Tailnet
metadata:
name: default
namespace: tailscale
spec:
tagAuths:
- tag: k8s-tailscale-operator
approved: true
+12
View File
@@ -0,0 +1,12 @@
apiVersion: v1
kind: Secret
metadata:
name: tailscale-operator-secret
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
type: Opaque
data:
# TODO: Fill in the Tailscale auth key (base64 encoded)
authkey: PLACEHOLDER
+66
View File
@@ -0,0 +1,66 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
template:
metadata:
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
spec:
serviceAccountName: tailscale-operator
securityContext:
runAsNonRoot: true
containers:
- name: operator
image: ghcr.io/tailscale/operator:v1.76.0
args:
- --hostname=$(POD_NAME)
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
envFrom:
- secretRef:
name: tailscale-operator-secret
ports:
- containerPort: 8080
name: metrics
protocol: TCP
resources:
requests:
cpu: 10m
memory: 64Mi
limits:
cpu: 100m
memory: 128Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsUser: 1000
runAsGroup: 1000
capabilities:
drop:
- ALL
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: node-role.kubernetes.io/control-plane
operator: Exists
+7
View File
@@ -0,0 +1,7 @@
apiVersion: v1
kind: Namespace
metadata:
name: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
+48
View File
@@ -0,0 +1,48 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
rules:
- apiGroups: ['']
resources: ['secrets', 'services', 'endpoints']
verbs: ['get', 'list', 'watch', 'create', 'update', 'patch', 'delete']
- apiGroups: ['']
resources: ['nodes']
verbs: ['get', 'list', 'update', 'patch']
- apiGroups: ['apps']
resources: ['daemonsets']
verbs: ['get', 'list', 'watch']
- apiGroups: ['tailscale.com']
resources: ['*']
verbs: ['get', 'list', 'watch', 'create', 'update', 'patch', 'delete']
- apiGroups: ['coordination.k8s.io']
resources: ['leases']
verbs: ['get', 'create', 'update']
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: tailscale
+18
View File
@@ -0,0 +1,18 @@
apiVersion: v1
kind: Service
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
spec:
type: ClusterIP
ports:
- name: metrics
port: 8080
targetPort: 8080
protocol: TCP
selector:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
@@ -3,4 +3,4 @@ kind: Namespace
metadata:
name: tailscale
labels:
app.kubernetes.io/name: tailscale
name: tailscale
@@ -0,0 +1,34 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app: tailscale-operator
spec:
replicas: 1
selector:
matchLabels:
app: tailscale-operator
template:
metadata:
labels:
app: tailscale-operator
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:v1.78.3
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: TAILSCALE_API_CLIENT_ID
value: ""
- name: TAILSCALE_API_CLIENT_SECRET
value: ""
@@ -0,0 +1,36 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: tailscale
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
rules:
- apiGroups: [""]
resources: ["pods", "services", "endpoints", "namespaces", "events", "configmaps"]
verbs: ["get", "list", "watch", "create", "update", "patch"]
- apiGroups: ["apps"]
resources: ["deployments", "daemonsets"]
verbs: ["get", "list", "watch", "create", "update", "patch"]
- apiGroups: ["tailscale.com"]
resources: ["*"]
verbs: ["get", "list", "watch", "create", "update", "patch"]
- apiGroups: ["networking.k8s.io"]
resources: ["ingressclasses"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: tailscale