diff --git a/.devcontainer/devcontainer.json b/.devcontainer/devcontainer.json index a5cf3d177..d280ae350 100755 --- a/.devcontainer/devcontainer.json +++ b/.devcontainer/devcontainer.json @@ -2,7 +2,7 @@ { "name": "Kubernetes Management", - "image": "ghcr.io/darkfella91/devcontainer:v1.0.0@sha256:7ce939d82eef728d9c6b2842b2e13b14bb15f31b6089ba26e7679daa5b5e34f4", + "image": "ghcr.io/darkfella91/devcontainer:v1.0.0@sha256:a06b8ce552810af306bb41935ad984cd6d3f0bd16d735f5bd0d5485c27b6eba5", "postStartCommand": "/usr/bin/direnv allow /project/.envrc", diff --git a/kubernetes/main/apps/kubernetes-dashboard/app/rbac.yaml b/kubernetes/main/apps/kubernetes-dashboard/app/rbac.yaml index 6f30ae3dd..e1689439d 100644 --- a/kubernetes/main/apps/kubernetes-dashboard/app/rbac.yaml +++ b/kubernetes/main/apps/kubernetes-dashboard/app/rbac.yaml @@ -1,23 +1,4 @@ --- -apiVersion: v1 -kind: ServiceAccount -metadata: - name: darkfella - namespace: kubernetes-dashboard ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - name: darkfella -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: cluster-admin -subjects: -- kind: ServiceAccount - name: darkfella - namespace: kubernetes-dashboard ---- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: diff --git a/kubernetes/main/bootstrap/talos/k8s-0.secret.sops.yaml b/kubernetes/main/bootstrap/talos/k8s-0.secret.sops.yaml index f7db9a95e..364265993 100644 --- a/kubernetes/main/bootstrap/talos/k8s-0.secret.sops.yaml +++ b/kubernetes/main/bootstrap/talos/k8s-0.secret.sops.yaml @@ -180,10 +180,9 @@ cluster: rules: - level: Metadata extraArgs: - oidcIssuerURL: https://accounts.${PUBLIC_DOMAIN}/realms/DarkfellaNET - oidcClientID: 0a2511ec-d7c2-45ae-adfe-092ac7ebf657 - oidcUsernameClaim: email - oidcGroupsClaim: groups + oidc-issuer-url: https://accounts.darkfellanetwork.com/realms/DarkfellaNET + oidc-client-id: 0a2511ec-d7c2-45ae-adfe-092ac7ebf657 + oidc-groups-claim: groups controllerManager: image: registry.k8s.io/kube-controller-manager:${KUBERNETES_VERSION} extraArgs: @@ -216,8 +215,8 @@ sops: ZVU5MWNwWVlFbENGRFVPWXRiWjVhUHcKzObF23w2RB0KQ4mTUOM8G1hnScMV0fXX hcF5Q8CpLpo1JAZHl3iUJscWHDzluUkaCJEZ7qTwAP2JawaptH9/5Q== -----END AGE ENCRYPTED FILE----- - lastmodified: "2024-11-28T20:09:33Z" - mac: ENC[AES256_GCM,data:QeD/x69otcamGsS1SUlkUB8HLhFyOK87m1zO9eDfEoI7JpI+enEcO+XaNNwI9wcon6PxzYPOu2qeVNggevo8Ub79gPhGeD5oREAthfKyrr/M9LdvoYMe6TKENFO4GHf30oTBBhNx6WT8diw26SXB29qrszZUneVkkDBqKZURxY4=,iv:6M3xUp6lEDbRPBEqEoMnnDRoI/i4gJdnonvtCY6zcr4=,tag:yR+WrNIP/pketiBG84tYYQ==,type:str] + lastmodified: "2024-11-28T22:54:37Z" + mac: ENC[AES256_GCM,data:Obc384TGqmAjpmh9svgAI6rsUr03jEAaRrwF1R/PTYtR4bOwlDNzWMC+sXeBaXZjeUXizamk8CS7MaE5mBHpu1PaJ7UcPHdHNjJV/hQkTIC6ekpUYfQqkUCJXDnqPEDLBXQ36XcewYF3Rrur696dQeu7Y8+fDE6vEqbdV8RxgXU=,iv:ii/Ck9aVlUHHoqy1e+QdT37gijOXUoYItVFbsNHZdNc=,tag:nZVUE4Jk3QW68c+Be4VPCg==,type:str] pgp: [] encrypted_regex: ^(token|crt|key|id|secret|secretboxEncryptionSecret|ca|urls|extraManifests)$ mac_only_encrypted: true