确保 OpenSandbox values 立即生效
yaml / yaml (pull_request) Successful in 27s
ansible / collection-test (pull_request) Successful in 1m16s
ansible / lint (pull_request) Successful in 2m33s

This commit is contained in:
2026-09-18 17:49:26 +00:00
parent 8290082fb4
commit 4c823f8181
5 changed files with 20 additions and 0 deletions
@@ -13,6 +13,9 @@ homelab 集群的 ESO Pod、ServiceAccount 或 Kubernetes auth backend。
值未输出或落盘;
- sandbox ESO operator、`ClusterSecretStore/openbao` 与 OpenSandbox `ExternalSecret`
由 Flux 管理;
- 线上 `ClusterSecretStore/openbao` 为 `Valid/Ready`,`ExternalSecret/opensandbox-api-key`
为 `SecretSynced/Ready`;
- OpenSandbox 已切换到 API key:无 key 请求返回 `401`,正确 key 请求返回 `200`;
- homelab runner 对同一 key 的投影不在本目录,留给 runner 项目管理。
OpenBao 的 `auth/kubernetes-sandbox`、对应 role、policy、sandbox API 地址与公开 CA
+2
View File
@@ -27,6 +27,8 @@ runner 项目后续声明,本目录不预制。
仓库与 Helm values 均不保存 API key。OpenSandbox 不支持更丰富的原生 workload
authentication;runner 后续读取同一 Bao 路径并在请求头中使用 API key。
`opensandbox-values` 带 Flux watch label,values 变化会立即触发 Helm reconcile,不依赖
30 分钟的 HelmRelease interval。
## 验收
+2
View File
@@ -4,6 +4,8 @@ kind: ConfigMap
metadata:
name: opensandbox-values
namespace: opensandbox-system
labels:
reconcile.fluxcd.io/watch: Enabled
data:
values.yaml: |
opensandbox-controller: