验证 Flux canary 受控删除 #16
@@ -35,6 +35,7 @@ What changed in this homelab, when, and why. Newest first.
|
|||||||
| cleanup | 已把 `bao-acme` HTTP-01 solver 改到 Envoy Gateway 的明文 listener,并删除不再承载流量的 Contour namespace、provisioner、RBAC、GatewayClass 和全部 `projectcontour.io` CRD;Envoy Gateway、证书、DNS 与 Gitea 复查正常 |
|
| cleanup | 已把 `bao-acme` HTTP-01 solver 改到 Envoy Gateway 的明文 listener,并删除不再承载流量的 Contour namespace、provisioner、RBAC、GatewayClass 和全部 `projectcontour.io` CRD;Envoy Gateway、证书、DNS 与 Gitea 复查正常 |
|
||||||
| GitOps canary | 加入由 Flux 部署到独立 `gitops-canary` namespace 的 `http-echo` Deployment 和 Service;历史 Contour HTTPRoute 明确排除在 Kustomization 之外,初始保持 `prune: false` |
|
| GitOps canary | 加入由 Flux 部署到独立 `gitops-canary` namespace 的 `http-echo` Deployment 和 Service;历史 Contour HTTPRoute 明确排除在 Kustomization 之外,初始保持 `prune: false` |
|
||||||
| prune 验证 | 为 `http-echo` 加入无业务依赖的 `flux-prune-canary` ConfigMap;先在 `prune: false` 下确认 Flux inventory,后续通过独立 PR 删除并仅为 canary 开启 prune |
|
| prune 验证 | 为 `http-echo` 加入无业务依赖的 `flux-prune-canary` ConfigMap;先在 `prune: false` 下确认 Flux inventory,后续通过独立 PR 删除并仅为 canary 开启 prune |
|
||||||
|
| prune 验证第二阶段 | 第一阶段已确认 `flux-prune-canary` 带 Flux ownership 标签并进入 `http-echo` inventory;从 Git 删除该测试对象,同时仅为 `http-echo` 开启 `prune: true`,root 继续保持 `prune: false` |
|
||||||
|
|
||||||
`Carried forward`: re-verify OpenBao/ESO recovery and remaining Secret inventory;
|
`Carried forward`: re-verify OpenBao/ESO recovery and remaining Secret inventory;
|
||||||
configure an off-site Git mirror; plan the Gitea upgrade beyond 1.25.5;
|
configure an off-site Git mirror; plan the Gitea upgrade beyond 1.25.5;
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ Flux 将它部署到独立的 `gitops-canary` namespace。
|
|||||||
| --- | --- |
|
| --- | --- |
|
||||||
| `deployment.yaml` | 两个 `hashicorp/http-echo` 副本。 |
|
| `deployment.yaml` | 两个 `hashicorp/http-echo` 副本。 |
|
||||||
| `service.yaml` | 只在集群内可达的 ClusterIP Service。 |
|
| `service.yaml` | 只在集群内可达的 ClusterIP Service。 |
|
||||||
| `prune-canary-configmap.yaml` | 无业务依赖的临时资源,用于验证 Flux 受控删除。 |
|
|
||||||
| `kustomization.yaml` | Flux 实际构建入口;明确排除历史 HTTPRoute。 |
|
| `kustomization.yaml` | Flux 实际构建入口;明确排除历史 HTTPRoute。 |
|
||||||
| `httproute.yaml` | 保留的历史 Contour 示例,**不在 Kustomization 中,不会部署**。 |
|
| `httproute.yaml` | 保留的历史 Contour 示例,**不在 Kustomization 中,不会部署**。 |
|
||||||
|
|
||||||
@@ -20,10 +19,8 @@ sudo k3s kubectl -n flux-system get kustomization http-echo
|
|||||||
sudo k3s kubectl -n gitops-canary get deployment,service,pod
|
sudo k3s kubectl -n gitops-canary get deployment,service,pod
|
||||||
```
|
```
|
||||||
|
|
||||||
初始 `prune: false`。验证自动部署后,可以手动把 Deployment replicas 改成 1,
|
Deployment 漂移修复已经验证:手动把 replicas 改成 1 后,Flux 能按 Git 恢复为
|
||||||
确认 Flux 恢复为 Git 中的 2。删除行为应使用单独的无业务 ConfigMap 和 PR 测试,
|
2。删除验证使用无业务依赖的 `flux-prune-canary` ConfigMap:第一阶段已经在
|
||||||
验证完成前不得为此路径启用 prune。
|
`prune: false` 时创建并确认进入 Flux inventory;本阶段从 Git 删除该对象,并仅为
|
||||||
|
`http-echo` Kustomization 开启 `prune: true`。root Kustomization 仍保持
|
||||||
`flux-prune-canary` ConfigMap 分两次 PR 验证:第一次在 `prune: false` 时创建并
|
`prune: false`,brownfield 资源不会进入此次删除范围。
|
||||||
确认进入 Flux inventory;第二次从清单删除它,同时仅为 `http-echo`
|
|
||||||
Kustomization 开启 prune,确认 Flux 只删除这个测试对象。
|
|
||||||
|
|||||||
@@ -2,5 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
- deployment.yaml
|
- deployment.yaml
|
||||||
- prune-canary-configmap.yaml
|
|
||||||
- service.yaml
|
- service.yaml
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: flux-prune-canary
|
|
||||||
data:
|
|
||||||
purpose: verify-controlled-flux-pruning
|
|
||||||
@@ -11,7 +11,7 @@ spec:
|
|||||||
namespace: gitops-canary
|
namespace: gitops-canary
|
||||||
interval: 10m
|
interval: 10m
|
||||||
path: ./apps/http-echo
|
path: ./apps/http-echo
|
||||||
prune: false
|
prune: true
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: GitRepository
|
kind: GitRepository
|
||||||
name: flux-system
|
name: flux-system
|
||||||
|
|||||||
Reference in New Issue
Block a user