Compare commits

...

111 Commits

Author SHA1 Message Date
gitea-admin 1652b56287 fix: update tailscale-operator to OAuth secrets mode
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 18:46:43 +00:00
gitea-admin 9031a97bf9 Merge pull request 'fix: migrate tailscale operator to OAuth file-based auth' (#27) from orion/auto/fix-migrate-tailscale-operator-to-oauth--1778955313506 into main
Reviewed-on: #27
2026-05-16 18:17:07 +00:00
gitea-admin c645233fe4 fix: migrate tailscale operator to OAuth file-based auth
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 18:15:13 +00:00
gitea-admin 256db3f6ad Merge pull request 'fix: correctly reference existing tailscale-auth secret' (#25) from orion/auto/fix-correctly-reference-existing-tailsca-1778809478719 into main
Reviewed-on: #25
2026-05-15 02:05:16 +00:00
gitea-admin 149d883b8a chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:40 +00:00
gitea-admin 0049a65d61 chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:39 +00:00
gitea-admin 20fa2bc6fb chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:39 +00:00
gitea-admin 3da23d5a39 chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:39 +00:00
gitea-admin 861999433a chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:38 +00:00
gitea-admin c605efa2d9 chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:38 +00:00
gitea-admin 48ba9f258c chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:38 +00:00
gitea-admin e9e929f103 fix: correct Vault path to Talos Cluster/tailscale and ESO API version 2026-05-15 02:00:06 +00:00
gitea-admin 781496c02f chore: remove duplicate tailscale-operator dir, consolidated into deployments/tailscale/operator/ 2026-05-15 01:59:57 +00:00
gitea-admin b9ea102375 chore: remove duplicate tailscale-operator dir, consolidated into deployments/tailscale/operator/ 2026-05-15 01:59:57 +00:00
gitea-admin 241a4f4241 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:14 +00:00
gitea-admin fe3ae675c8 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:14 +00:00
gitea-admin df4ea9ec06 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:13 +00:00
gitea-admin ed1becbf5f chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:13 +00:00
gitea-admin 608e6776ce chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:13 +00:00
gitea-admin da1315ce87 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:13 +00:00
gitea-admin ad014ea92e chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:12 +00:00
gitea-admin 3cec68fdae chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:12 +00:00
gitea-admin 0a87cf8a50 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:12 +00:00
gitea-admin fb670a1e64 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:11 +00:00
gitea-admin d7f4545de5 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:11 +00:00
gitea-admin b825855497 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:11 +00:00
gitea-admin 935906c256 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:11 +00:00
gitea-admin 1dae3e4618 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:10 +00:00
gitea-admin ab6adebfb5 fix: correctly reference existing tailscale-auth secret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-15 01:44:38 +00:00
gitea-admin d763511a8a Merge pull request 'feat: deploy Tailscale Operator via GitOps' (#23) from orion/auto/feat-deploy-tailscale-operator-via-gitop-1778426037111 into main
Reviewed-on: #23
2026-05-10 15:15:07 +00:00
gitea-admin e35f4d22f9 feat: deploy Tailscale Operator via GitOps
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 15:13:57 +00:00
gitea-admin 7829189b3a Merge pull request 'Deploy Tailscale Operator and ExternalSecret' (#22) from orion/auto/deploy-tailscale-operator-and-externalse-1778415920810 into main
Auto-merged by ORION: Deploy Tailscale Operator and ExternalSecret
2026-05-10 12:25:21 +00:00
gitea-admin 104fcf5eca Deploy Tailscale Operator and ExternalSecret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 12:25:21 +00:00
gitea-admin 58980c72ee Deploy Tailscale Operator and ExternalSecret 2026-05-10 12:25:21 +00:00
gitea-admin 4e58b30418 Merge pull request 'Deploy Tailscale Operator with correct secret' (#21) from orion/auto/deploy-tailscale-operator-with-correct-s-1778415897457 into main
Auto-merged by ORION: Deploy Tailscale Operator with correct secret
2026-05-10 12:24:58 +00:00
gitea-admin 0045292277 Deploy Tailscale Operator with correct secret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 12:24:57 +00:00
gitea-admin da5faa78f9 Merge pull request 'feat: deploy Tailscale Operator with auth secret' (#20) from orion/auto/feat-deploy-tailscale-operator-with-auth-1778415696837 into main
Reviewed-on: #20
2026-05-10 12:23:29 +00:00
gitea-admin 9bc3d2fe60 Merge pull request 'feat: deploy Tailscale Operator with auth secret' (#19) from orion/auto/feat-deploy-tailscale-operator-with-auth-1778415685599 into main
Reviewed-on: #19
2026-05-10 12:23:21 +00:00
gitea-admin 65cfcf17ce Merge pull request 'feat: deploy Tailscale Operator with auth secret' (#18) from orion/auto/feat-deploy-tailscale-operator-with-auth-1778415674454 into main
Reviewed-on: #18
2026-05-10 12:23:08 +00:00
gitea-admin e27aef4304 feat: deploy Tailscale Operator with auth secret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 12:21:37 +00:00
gitea-admin 080a189397 feat: deploy Tailscale Operator with auth secret 2026-05-10 12:21:37 +00:00
gitea-admin 75b5ca4f0e feat: deploy Tailscale Operator with auth secret 2026-05-10 12:21:37 +00:00
gitea-admin 96fe445998 feat: deploy Tailscale Operator with auth secret 2026-05-10 12:21:37 +00:00
gitea-admin c7bdc4a4ac feat: deploy Tailscale Operator with auth secret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 12:21:26 +00:00
gitea-admin 910aae7b46 feat: deploy Tailscale Operator with auth secret 2026-05-10 12:21:26 +00:00
gitea-admin 2a92c5a371 feat: deploy Tailscale Operator with auth secret 2026-05-10 12:21:26 +00:00
gitea-admin 01eb2ad04d feat: deploy Tailscale Operator with auth secret 2026-05-10 12:21:25 +00:00
gitea-admin c5eb76601e feat: deploy Tailscale Operator with auth secret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 12:21:15 +00:00
gitea-admin 9cc349466a feat: deploy Tailscale Operator with auth secret 2026-05-10 12:21:15 +00:00
gitea-admin 1a8d36eeb7 feat: deploy Tailscale Operator with auth secret 2026-05-10 12:21:14 +00:00
gitea-admin d35f234c14 feat: deploy Tailscale Operator with auth secret 2026-05-10 12:21:14 +00:00
gitea-admin a2eddee64e Merge pull request 'feat: deploy Tailscale Operator and auth secret' (#16) from orion/auto/feat-deploy-tailscale-operator-and-auth--1778378551457 into main
Reviewed-on: #16
2026-05-10 12:18:11 +00:00
gitea-admin 5aa3e9361c Merge pull request 'feat: deploy Tailscale Operator and auth secret' (#17) from orion/auto/feat-deploy-tailscale-operator-and-auth--1778378566626 into main
Reviewed-on: #17
2026-05-10 12:18:01 +00:00
gitea-admin cc8e6a8703 feat: deploy Tailscale Operator and auth secret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 02:02:48 +00:00
gitea-admin 82848e37d6 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:48 +00:00
gitea-admin b3dbc88e04 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:47 +00:00
gitea-admin 440d7bae96 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:47 +00:00
gitea-admin af493fb726 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:47 +00:00
gitea-admin 4d8e974632 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:47 +00:00
gitea-admin ee32969622 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:46 +00:00
gitea-admin 0f18dec449 feat: deploy Tailscale Operator and auth secret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 02:02:33 +00:00
gitea-admin 48885e73b5 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:33 +00:00
gitea-admin e032650eab feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:32 +00:00
gitea-admin 295168bbde feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:32 +00:00
gitea-admin d518b7866f feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:32 +00:00
gitea-admin 06405cc08f feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:31 +00:00
gitea-admin ecb9edb3c8 feat: deploy Tailscale Operator and auth secret 2026-05-10 02:02:31 +00:00
gitea-admin 9dc53835d3 Merge pull request 'feat: add ExternalSecret for Tailscale auth key' (#14) from orion/auto/feat-add-externalsecret-for-tailscale-au-1778373309640 into main
Reviewed-on: #14
2026-05-10 00:36:57 +00:00
gitea-admin 418e32e4eb Merge pull request 'feat: add ExternalSecret for Tailscale' (#15) from orion/auto/feat-add-externalsecret-for-tailscale-1778373314635 into main
Auto-merged by ORION: feat: add ExternalSecret for Tailscale
2026-05-10 00:35:15 +00:00
gitea-admin 21c7856bbd feat: add ExternalSecret for Tailscale
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 00:35:14 +00:00
gitea-admin 501913ad5f feat: add ExternalSecret for Tailscale auth key
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 00:35:09 +00:00
gitea-admin 14f2e6bd99 Merge pull request 'feat: add ClusterSecretStore and ExternalSecret for Tailscale' (#13) from orion/auto/feat-add-clustersecretstore-and-external-1778373293466 into main
Auto-merged by ORION: feat: add ClusterSecretStore and ExternalSecret for Tailscale
2026-05-10 00:34:54 +00:00
gitea-admin 53e8a505bd feat: add ClusterSecretStore and ExternalSecret for Tailscale
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-10 00:34:53 +00:00
gitea-admin 2d8cc39df2 feat: add ClusterSecretStore and ExternalSecret for Tailscale 2026-05-10 00:34:53 +00:00
gitea-admin 9b9c164312 Merge pull request 'feat: apply tailscale-auth ExternalSecret' (#11) from orion/auto/feat-apply-tailscale-auth-externalsecret-1778363886223 into main
Auto-merged by ORION: feat: apply tailscale-auth ExternalSecret
2026-05-09 21:58:07 +00:00
gitea-admin 0f9575042c feat: apply tailscale-auth ExternalSecret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-09 21:58:06 +00:00
gitea-admin 7088256cf4 Merge pull request 'feat: deploy Tailscale operator' (#10) from orion/auto/feat-deploy-tailscale-operator-1778357494349 into main
Reviewed-on: #10
2026-05-09 21:42:39 +00:00
gitea-admin faa45e87da feat: deploy Tailscale operator
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-09 20:11:34 +00:00
gitea-admin 142911c8d2 feat: deploy Tailscale operator 2026-05-09 20:11:34 +00:00
gitea-admin aef5f9b702 Merge pull request 'feat: deploy Tailscale Operator for remote cluster access' (#6) from orion/auto/feat-deploy-tailscale-operator-for-remot-1778353397574 into main
Auto-merged by ORION: feat: deploy Tailscale Operator for remote cluster access
2026-05-09 19:03:19 +00:00
gitea-admin 16e2b4e9b2 feat: deploy Tailscale Operator for remote cluster access
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-09 19:03:18 +00:00
gitea-admin b3527c2b16 feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:18 +00:00
gitea-admin 5fe154d80d feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:18 +00:00
gitea-admin b0042e5510 feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:18 +00:00
gitea-admin cb1b83907b feat: deploy Tailscale Operator for remote cluster access 2026-05-09 19:03:17 +00:00
gitea-admin 116a118b0b Merge pull request 'chore: remove Tailscale operator and all related manifests' (#5) from orion/auto/chore-remove-tailscale-operator-and-all--1778352258236 into main
Reviewed-on: #5
2026-05-09 19:00:37 +00:00
gitea-admin 1a274c625b chore: remove Tailscale operator and all related manifests
Validate Manifests / validate (pull_request) Failing after 29s
2026-05-09 18:44:20 +00:00
gitea-admin f8f180566e chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:20 +00:00
gitea-admin 8ed5a211ba chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:19 +00:00
gitea-admin f69fc01fd1 chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:19 +00:00
gitea-admin 94fbc325d4 chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:19 +00:00
gitea-admin d7114b159e chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:19 +00:00
gitea-admin a185abe525 chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:18 +00:00
gitea-admin 2a66adfd69 chore: remove Tailscale operator and all related manifests 2026-05-09 18:44:18 +00:00
gitea-admin 4684bc1fca ci: add manifest validation workflow 2026-05-09 18:37:41 +00:00
gitea-admin 839045b831 chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:19:00 +00:00
gitea-admin ce984792cc chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:19:00 +00:00
gitea-admin 0f88fa4953 chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:59 +00:00
gitea-admin 8c088c2008 chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:59 +00:00
gitea-admin ec8369cfc9 chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:59 +00:00
gitea-admin 39f87dfcdd chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:59 +00:00
gitea-admin 4d928cac0b chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:58 +00:00
gitea-admin 82fa0b71ab chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:58 +00:00
gitea-admin f8d61d0f1c chore: remove broken AI-generated Tailscale manifests 2026-05-09 18:18:58 +00:00
gitea-admin 51718a46dc Merge pull request 'feat: add Tailscale operator and DaemonSet' (#4) from orion/auto/feat-add-tailscale-operator-and-daemonse-1778347811370 into main
test
2026-05-09 17:36:55 +00:00
gitea-admin 5b8af9c537 feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:12 +00:00
gitea-admin 462eebad61 feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:12 +00:00
gitea-admin 81fc72b3eb feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:12 +00:00
gitea-admin b5f7f2bd50 feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:11 +00:00
gitea-admin 4ff6f4de76 feat: add Tailscale operator and DaemonSet 2026-05-09 17:30:11 +00:00
gitea-admin 74b55be570 Merge pull request 'feat: deploy Tailscale Operator for secure cluster access' (#3) from orion/auto/feat-deploy-tailscale-operator-for-secur-1778347768093 into main
Auto-merged by ORION: feat: deploy Tailscale Operator for secure cluster access
2026-05-09 17:29:29 +00:00
12 changed files with 248 additions and 52 deletions
+58
View File
@@ -0,0 +1,58 @@
name: Validate Manifests
on:
pull_request:
branches: [main]
jobs:
validate:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install kubeconform
run: |
curl -sL https://github.com/yannh/kubeconform/releases/download/v0.6.7/kubeconform-linux-amd64.tar.gz \
| tar xz -C /usr/local/bin
chmod +x /usr/local/bin/kubeconform
- name: Schema validation (kubeconform)
run: |
find . -name '*.yaml' -o -name '*.yml' \
| grep -v '\.gitea/' \
| sort \
| xargs kubeconform \
-strict \
-ignore-missing-schemas \
-kubernetes-version 1.30.0 \
-summary
- name: Install kubectl
run: |
K8S_VER=$(curl -sL https://dl.k8s.io/release/stable.txt)
curl -sLO "https://dl.k8s.io/release/${K8S_VER}/bin/linux/amd64/kubectl"
chmod +x kubectl && mv kubectl /usr/local/bin/kubectl
- name: Server-side dry-run (CRD existence check)
env:
KUBECONFIG_DATA: ${{ secrets.KUBECONFIG }}
run: |
echo "$KUBECONFIG_DATA" | base64 -d > /tmp/kube.yaml
# Apply all YAML files in sorted order — server-side dry-run rejects
# any apiVersion/Kind whose CRD is not installed in the cluster.
find . -name '*.yaml' -o -name '*.yml' \
| grep -v '\.gitea/' \
| sort \
| xargs -I{} kubectl apply \
--dry-run=server \
--kubeconfig /tmp/kube.yaml \
-f {} 2>&1 \
| tee /tmp/dryrun.log
rm -f /tmp/kube.yaml
# Fail if any "no kind is registered" or "no matches for kind" errors
if grep -qE "no kind is registered|no matches for kind|unknown field" /tmp/dryrun.log; then
echo "❌ Dry-run found unknown resources or fields — manifests reference CRDs not installed in the cluster"
exit 1
fi
echo "✅ All manifests passed server-side dry-run"
@@ -1,3 +1,13 @@
apiVersion: v1
kind: Namespace
metadata:
name: tailscale
labels:
app.kubernetes.io/name: tailscale-operator
app.kubernetes.io/part-of: infrastructure
management: gitops
managed-by: orion
---
apiVersion: apps/v1
kind: Deployment
metadata:
@@ -5,6 +15,9 @@ metadata:
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale-operator
app.kubernetes.io/part-of: infrastructure
management: gitops
managed-by: orion
spec:
replicas: 1
selector:
@@ -18,13 +31,15 @@ spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/kubernetes-operator:v1.70.1
image: ghcr.io/tailscale/k8s-operator:1.78.1
env:
- name: TS_AUTH_KEY
valueFrom:
secretKeyRef:
name: tailscale-auth
key: TS_AUTH_KEY
- name: TS_USERSPACE
value: "true"
resources:
requests:
cpu: 50m
@@ -0,0 +1,18 @@
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: tailscale-auth
namespace: tailscale
spec:
refreshInterval: 1h
secretStoreRef:
name: orion-vault
kind: ClusterSecretStore
target:
name: tailscale-auth
creationPolicy: Owner
data:
- secretKey: TS_AUTH_KEY
remoteRef:
key: Talos Cluster/tailscale
property: TS_AUTH_KEY
@@ -0,0 +1,17 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
rules:
- apiGroups: [""]
resources: ["secrets", "configmaps", "services", "pods", "endpoints"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["apps"]
resources: ["deployments", "statefulsets", "daemonsets"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["networking.k8s.io"]
resources: ["ingresses"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["tailscale.com"]
resources: ["*"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
@@ -0,0 +1,12 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: tailscale
@@ -0,0 +1,35 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app: tailscale-operator
spec:
replicas: 1
selector:
matchLabels:
app: tailscale-operator
template:
metadata:
labels:
app: tailscale-operator
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:v1.78.3
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: TS_AUTH_KEY
valueFrom:
secretKeyRef:
name: tailscale-auth
key: TS_AUTH_KEY
@@ -0,0 +1,7 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app: tailscale-operator
-6
View File
@@ -1,6 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: tailscale
labels:
app.kubernetes.io/name: tailscale
-36
View File
@@ -1,36 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: tailscale
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
rules:
- apiGroups: ["apps"]
resources: ["deployments", "statefulsets", "daemonsets"]
verbs: ["get", "list", "watch", "update", "patch"]
- apiGroups: [""]
resources: ["services", "endpoints"]
verbs: ["get", "list", "watch", "update", "patch"]
- apiGroups: ["policy.tailscale.com"]
resources: ["tailnets", "tailscales"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["policy.tailscale.com"]
resources: ["tailnets/status", "tailscales/status"]
verbs: ["get", "update", "patch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: tailscale
-9
View File
@@ -1,9 +0,0 @@
apiVersion: policy.tailscale.com/v1alpha1
kind: Tailnet
metadata:
name: default
namespace: tailscale
spec:
tagAuths:
- tag: k8s-tailscale-operator
approved: true
+43
View File
@@ -0,0 +1,43 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app: tailscale-operator
spec:
replicas: 1
selector:
matchLabels:
app: tailscale-operator
template:
metadata:
labels:
app: tailscale-operator
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:v1.78.3
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: CLIENT_ID_FILE
value: /etc/tailscale/operator/client-id
- name: CLIENT_SECRET_FILE
value: /etc/tailscale/operator/client-secret
volumeMounts:
- name: operator-secret
mountPath: /etc/tailscale/operator
readOnly: true
resources: {}
volumes:
- name: operator-secret
secret:
secretName: tailscale-operator-secret
@@ -0,0 +1,42 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app: tailscale-operator
spec:
replicas: 1
selector:
matchLabels:
app: tailscale-operator
template:
metadata:
labels:
app: tailscale-operator
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:v1.78.3
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: TS_CLIENT_ID_FILE
value: /etc/tailscale/oauth/client-id
- name: TS_CLIENT_SECRET_FILE
value: /etc/tailscale/oauth/client-secret
volumeMounts:
- name: oauth-secret
mountPath: /etc/tailscale/oauth
readOnly: true
volumes:
- name: oauth-secret
secret:
secretName: tailscale-operator-secret