Files

4.1 KiB

Operations and validation

Bootstrap

export KUBE_CONTEXT_LAB='<expected-context>'
bash scripts/bin/bootstrap.sh lab

각 stage는 render -> server-side dry-run -> diff -> confirm -> apply 순서로 실행됩니다. CONFIRM=yes는 비대화 환경에서만 사용하고 context 확인을 우회하지 않습니다.

Order Entrypoint / task Completion boundary
1 namespaces Namespace Active
2 00-platform cert-manager와 Keycloak Operator Available
3 MinIO/VSO Helm task controller Ready, CRD registered
4 10-vault vault-0 Running
5 Vault init/unseal/policy/seed KV와 Kubernetes auth 준비
6 20-secrets data 선행 destination Secret 생성
7 30-data PostgreSQL/MinIO/Keycloak Ready
8 MinIO registry provision task bucket/access key 생성 후 Vault 기록
9 35-registry registry Secret 생성과 Deployment rollout 완료
10 40-operations Flyway Complete, RealmImport Done
11 50-apps auth-server/oauth2-proxy rollout 완료

gitops/clusters/lab/main/all은 절대 apply하지 않습니다.

Vault init material

기본 lab 경로는 repo root의 ignored vault-init-keys.json입니다. 스크립트는 0600으로 쓰지만 암호화 파일은 아닙니다. VAULT_KEYS_FILE로 repo 밖의 안전한 위치를 지정하는 방식을 권장하며 prod에서는 필수입니다.

키, root token, password, MinIO secret key를 argv로 전달하지 않습니다. unseal/login, JSON 조립, Vault 기록은 stdin 경로를 사용합니다.

docker-registry/minio는 일반 seed 대상이 아닙니다. 30-data에서 MinIO가 Ready가 된 뒤 MinIO가 bucket-scoped access key를 생성하고, bootstrap task가 그 결과를 Vault에 기록합니다. 35-registry는 그 이후에만 VSO CR과 registry Deployment를 적용하므로 missing Secret 상태의 Pod를 만들지 않습니다.

Secret rotation

VSO destination은 overwrite: true로 선언되어 Vault 변경을 Kubernetes Secret에 반영합니다. auth-server와 oauth2-proxy는 지원되는 Secret 변경 시 rollout target을 사용합니다.

다음 credential은 외부 시스템 상태와 함께 회전해야 하므로 Vault 값만 바꾸면 안 됩니다.

  • PostgreSQL role password
  • Keycloak DB password
  • MinIO access key credential
  • registry basic-auth/pull credential

각 소비자와 backend credential을 순서대로 갱신하고 stage health를 확인하는 별도 rotation runbook이 필요합니다.

Teardown

기본 teardown은 앱과 one-shot operation만 삭제합니다.

bash scripts/bin/teardown.sh lab

데이터, Vault, namespace까지 삭제하려면 명시적으로 opt-in합니다.

DELETE_DATA=yes bash scripts/bin/teardown.sh lab

공유 operator와 cluster-scoped 리소스까지 삭제하는 것은 전용 lab cluster에서만 사용합니다.

DELETE_DATA=yes TEARDOWN_PLATFORM=yes \
  bash scripts/bin/teardown.sh lab

FORCE_FINALIZERS=yes는 정상 삭제가 반복해서 실패한 namespace 복구의 최후 수단입니다. orphaned volume과 controller state를 만들 수 있습니다.

Validation

make check

로컬 profile은 render를 항상 수행하고 설치되지 않은 부가 도구는 알려준 뒤 건너뜁니다. full profile은 다음 도구가 모두 없으면 실패합니다.

  • kustomize 또는 kubectl
  • kubeconform
  • kube-linter
  • shellcheck
  • shfmt
  • gitleaks
mise install
VALIDATION_PROFILE=full make check

Gitea workflow는 full profile을 실행합니다. 검증 entrypoint의 source of truth는 tests/kustomize-entrypoints.txt입니다.

External incident actions

현재 tree에서 민감 파일을 untrack/ignore하는 것만으로 과거 노출은 해결되지 않습니다. 다음 작업은 live Vault와 모든 협업자에게 영향을 주므로 repository refactor와 분리합니다.

  1. root token과 unseal/recovery material 회전
  2. 영향 credential 전체 회전
  3. 백업과 감사 로그에서 노출 범위 확인
  4. 협업자에게 force-fetch/reclone 절차 공지
  5. 승인된 maintenance window에서 원격 Git history 정리