gitops: assorted leftovers and fixes
This commit is contained in:
@@ -6,13 +6,13 @@ metadata:
|
|||||||
spec:
|
spec:
|
||||||
provider:
|
provider:
|
||||||
vault:
|
vault:
|
||||||
server: "https://vault.hrajfrisbee.cz:8200"
|
server: "https://vault.hrajfrisbee.cz"
|
||||||
path: "secret"
|
path: "secret"
|
||||||
version: "v2"
|
version: "v2"
|
||||||
auth:
|
auth:
|
||||||
appRole:
|
appRole:
|
||||||
path: "approle"
|
path: "approle"
|
||||||
roleId: "8833d0f8-d35d-d7ea-658b-c27837d121ab" # or reference a secret
|
roleId: "864e352d-2064-2bf9-2c73-dbd676a95368" # or reference a secret
|
||||||
secretRef:
|
secretRef:
|
||||||
name: vault-approle
|
name: vault-approle
|
||||||
key: secret-id
|
key: secret-id
|
||||||
|
|||||||
@@ -6,5 +6,5 @@ metadata:
|
|||||||
annotations:
|
annotations:
|
||||||
kustomize.toolkit.fluxcd.io/reconcile: disabled
|
kustomize.toolkit.fluxcd.io/reconcile: disabled
|
||||||
type: Opaque
|
type: Opaque
|
||||||
data:
|
stringData:
|
||||||
secret-id: # --- find me in keepass bro ---
|
secret-id: --- fill in the secret_id ---
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ data:
|
|||||||
ttl 30
|
ttl 30
|
||||||
}
|
}
|
||||||
hosts {
|
hosts {
|
||||||
192.168.0.30 vault.hrajfrisbee.cz
|
# 192.168.0.30 vault.hrajfrisbee.cz
|
||||||
fallthrough
|
fallthrough
|
||||||
}
|
}
|
||||||
prometheus :9153
|
prometheus :9153
|
||||||
|
|||||||
24
gitops/home-kubernetes/tetragon/helmrelease.yaml
Normal file
24
gitops/home-kubernetes/tetragon/helmrelease.yaml
Normal file
@@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: tetragon
|
||||||
|
namespace: kube-system
|
||||||
|
spec:
|
||||||
|
interval: 1h
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: tetragon
|
||||||
|
version: "1.6.0"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: cilium
|
||||||
|
namespace: flux-system
|
||||||
|
values:
|
||||||
|
export:
|
||||||
|
stdout:
|
||||||
|
enabledEvents:
|
||||||
|
- PROCESS_EXEC
|
||||||
|
- PROCESS_EXIT
|
||||||
|
- PROCESS_TRACEPOINT # required for oom tracepoint
|
||||||
|
tetragon:
|
||||||
|
btf: /sys/kernel/btf/vmlinux
|
||||||
16
gitops/home-kubernetes/tetragon/tracing_policy-oomkill.yaml
Normal file
16
gitops/home-kubernetes/tetragon/tracing_policy-oomkill.yaml
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: cilium.io/v1alpha1
|
||||||
|
kind: TracingPolicy
|
||||||
|
metadata:
|
||||||
|
name: oom-kill
|
||||||
|
spec:
|
||||||
|
tracepoints:
|
||||||
|
- subsystem: oom
|
||||||
|
# event: oom_kill
|
||||||
|
event: mark_victim
|
||||||
|
args:
|
||||||
|
- index: 4
|
||||||
|
type: int32
|
||||||
|
label: killed_pid
|
||||||
|
- index: 5
|
||||||
|
type: string
|
||||||
|
label: killed_comm
|
||||||
Reference in New Issue
Block a user