From 8baf47a08fce9725c5265df818c8f494d3fc09ef Mon Sep 17 00:00:00 2001 From: xnoto Date: Fri, 31 Jul 2026 18:21:42 -0600 Subject: [PATCH] chore: remove Headlamp DNS record --- README.md | 25 +++++++++++++++++++++++++ cf-tunnels.tf | 1 - 2 files changed, 25 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index d93212f..17b2b81 100644 --- a/README.md +++ b/README.md @@ -61,3 +61,28 @@ No inputs. | ---- | ----------- | | [tunnel\_ids](#output\_tunnel\_ids) | Cloudflare Tunnel IDs for reference in kustomize-cluster ConfigMaps | + +## Kubernetes API access + +This root manages the Cloudflare side of kubectl connectivity: + +- `cf-warp.tf` defines the GitHub identity provider and + `makeitworkcloud:admins` Access group. +- `cf-access-k3s.tf` applies that group to `k3s.makeitwork.cloud`. +- `cf-tunnels.tf` keeps the `k3s` CNAME pointed at the operator-owned + `cluster-apps-k3s` tunnel. + +The separate `kustomize-cluster/workloads/kubectl-tunnel` desired state owns +the in-cluster route from that tunnel to the Kubernetes API Service. + +Cloudflare Access authenticates the network connection; Kubernetes still +requires a Dex-issued kubectl OIDC token. The canonical kubeconfig and +`cloudflared`/`kubelogin` procedure lives in the +[`kustomize-cluster` README](https://github.com/makeitworkcloud/kustomize-cluster#kubectl-access). +Do not store kubeconfigs, Access tokens, client certificates, or Cloudflare +credentials in this repository. + +The CNAME and the `TunnelBinding` are coordinated control points. When +retiring a hostname, reconcile the binding first so cloudflare-operator clears +its `_managed.` TXT record, then remove the hostname here and review the +OpenTofu plan before apply. diff --git a/cf-tunnels.tf b/cf-tunnels.tf index 8d4ffb7..09b6592 100644 --- a/cf-tunnels.tf +++ b/cf-tunnels.tf @@ -22,7 +22,6 @@ locals { "argocd", "forgejo", "grafana", - "headlamp", "k3s", "status", ]