lint / yaml (pull_request) Successful in 17s
lint / yaml (push) Successful in 17s
lint / terraform (push) Successful in 37s
lint / terraform (pull_request) Successful in 29s
lint / ansible (push) Successful in 3m51s
lint / ansible (pull_request) Successful in 4m6s
Homelab 集群
这里是单节点 k3s 集群的 Flux reconciliation 入口。集群当前运行 Kubernetes
v1.36.4+k3s1,Flux 固定为 v2.9.5。
首次 bootstrap
仓库经过 PR 审查并合并后,在本机从合并后的 main 执行:
sudo k3s kubectl apply -f clusters/homelab/flux-system/gotk-components.yaml
sudo k3s kubectl apply -f clusters/homelab/flux-system/gotk-sync.yaml
GitRepository/flux-system 通过集群内 Gitea Service 读取公开仓库,不需要长期
管理员 token,也不依赖 Cloudflare、公网 DNS 或 Envoy Gateway。Gitea 暂时不可用
时,已经应用的资源继续运行,Flux 在 Gitea 恢复后重新同步。
root Kustomization 从 ./clusters/homelab 开始 reconciliation。初始设置
prune: false;在逐项审计现有资源和 field ownership 之前不得开启全局 prune。
计划中的 reconciliation 顺序:
- namespaces 和 CRD;
- platform controllers;
- secret references 和 storage;
- applications。
首次部署后的最低验证:
sudo k3s kubectl -n flux-system get pods
sudo k3s kubectl -n flux-system get gitrepositories,kustomizations
四个 controller、GitRepository 和 root Kustomization 都必须为 Ready,随后才能 通过单独 PR 引入低风险 canary workload。
当前状态
- Flux
v2.9.5、GitRepository 和 root Kustomization 均为 Ready; http-echocanary 已验证 merge 后自动部署和 replicas 漂移修复;http-echo的专用测试 ConfigMap 已在prune: true生效后重新纳管,并由下一 revision 自动删除;http-echo保持prune: true,root 保持prune: false;- 下一个接管对象是现有
gitea-actionsHelm release,先使用相同 chart/version 完成零变化 adoption,再通过独立 PR 升级。