From 9dac6f3668a08d4158502ae1f60becfd6756ab57 Mon Sep 17 00:00:00 2001 From: GersonRS Date: Sun, 15 Feb 2026 12:47:10 -0300 Subject: [PATCH 1/6] feat: improvement docker build workflow --- .github/workflows/modules-docker-build-push.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/modules-docker-build-push.yaml b/.github/workflows/modules-docker-build-push.yaml index 03444d3..bac181a 100644 --- a/.github/workflows/modules-docker-build-push.yaml +++ b/.github/workflows/modules-docker-build-push.yaml @@ -75,7 +75,7 @@ jobs: - name: Set up QEMU uses: docker/setup-qemu-action@v3 - - name: Set up Docker Buildx + - name: Set up Docker Buildx 🐳 uses: docker/setup-buildx-action@v3 - name: Login to DockerHub @@ -94,10 +94,10 @@ jobs: file: ${{ inputs.context }}/${{ inputs.dockerfile }} platforms: ${{ inputs.platforms }} push: ${{ github.event_name != 'pull_request' }} - load: ${{ github.event_name == 'pull_request' }} tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} annotations: ${{ steps.meta.outputs.annotations }} + sbom: true cache-from: type=gha cache-to: type=gha,mode=max build-args: | From 60f85604003cd14cb2d22a61eb4661c728ee9b49 Mon Sep 17 00:00:00 2001 From: GersonRS Date: Mon, 18 May 2026 03:27:04 -0300 Subject: [PATCH 2/6] feat: enable loki-stack, thanos, and kube-prometheus-stack with Istio HTTPRoute - Uncomment and update module "loki-stack" with istio dependency - Uncomment and update module "thanos" with istio dependency (removed traefik) - Uncomment and update module "kube-prometheus-stack" with istio dependency (removed traefik) - All three modules use target_revision = "develop" --- examples/kind/main.tf | 118 ++++++++++++++++++++++++------------------ 1 file changed, 69 insertions(+), 49 deletions(-) diff --git a/examples/kind/main.tf b/examples/kind/main.tf index 6c25658..dff6c04 100644 --- a/examples/kind/main.tf +++ b/examples/kind/main.tf @@ -27,7 +27,7 @@ module "argocd_bootstrap" { repositories = [ "git@github.com:GersonRS/modern-gitops-stack-module-argocd.git", "git@github.com:GersonRS/modern-gitops-stack-module-metrics-server.git", - "git@github.com:GersonRS/modern-gitops-stack-module-traefik.git", + "git@github.com:GersonRS/modern-gitops-stack-module-istio.git", "git@github.com:GersonRS/modern-gitops-stack-module-cert-manager.git", "git@github.com:GersonRS/modern-gitops-stack-module-keycloak.git", "git@github.com:GersonRS/modern-gitops-stack-module-postgresql.git", @@ -68,9 +68,12 @@ module "metrics-server" { } } -module "traefik" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-traefik.git//kind?ref=v2.9.0" +module "istio" { + source = "../../../modern-gitops-stack-module-istio//kind" + cluster_name = local.cluster_name + subdomain = local.subdomain + cluster_issuer = local.cluster_issuer argocd_project = local.cluster_name app_autosync = local.app_autosync @@ -110,7 +113,7 @@ module "postgresql" { } module "keycloak" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-keycloak.git?ref=develop" + source = "../../../modern-gitops-stack-module-keycloak" cluster_name = local.cluster_name base_domain = local.base_domain @@ -128,14 +131,14 @@ module "keycloak" { } dependency_ids = { - traefik = module.traefik.id + istio = module.istio.id cert-manager = module.cert-manager.id postgresql = module.postgresql.id } } module "oidc" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-keycloak.git//oidc_bootstrap?ref=develop" + source = "../../../modern-gitops-stack-module-keycloak//oidc_bootstrap" cluster_name = local.cluster_name base_domain = local.base_domain @@ -150,7 +153,7 @@ module "oidc" { module "minio" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-minio.git?ref=v2.8.0" + source = "../../../modern-gitops-stack-module-minio" cluster_name = local.cluster_name base_domain = local.base_domain @@ -162,16 +165,20 @@ module "minio" { config_minio = local.minio_config oidc = module.oidc.oidc + target_revision = "develop" dependency_ids = { - traefik = module.traefik.id + istio = module.istio.id cert-manager = module.cert-manager.id oidc = module.oidc.id } } +# --- Everything below is commented out for Phase 1 (Istio migration up to MinIO) --- + module "mlflow" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-mlflow.git?ref=v1.3.0" + source = "../../../modern-gitops-stack-module-mlflow" + cluster_name = local.cluster_name base_domain = local.base_domain subdomain = local.subdomain @@ -180,6 +187,14 @@ module "mlflow" { app_autosync = local.app_autosync enable_service_monitor = local.enable_service_monitor + target_revision = "develop" + + oidc = module.oidc.oidc + allowed_groups = [ + "modern-gitops-stack-admins", + "modern-gitops-stack-data-scientists", + "modern-gitops-stack-ml-engineers", + ] storage = { bucket_name = "mlflow" @@ -195,9 +210,10 @@ module "mlflow" { } dependency_ids = { argocd = module.argocd_bootstrap.id - traefik = module.traefik.id + istio = module.istio.id minio = module.minio.id postgresql = module.postgresql.id + oidc = module.oidc.id } } @@ -348,13 +364,14 @@ module "mlflow" { # # # } module "loki-stack" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-loki-stack.git//kind?ref=v2.7.0" + source = "../../../modern-gitops-stack-module-loki-stack//kind" argocd_project = local.cluster_name app_autosync = local.app_autosync enable_service_monitor = local.enable_service_monitor + target_revision = "develop" logs_storage = { bucket_name = local.minio_config.buckets.0.name @@ -364,12 +381,13 @@ module "loki-stack" { } dependency_ids = { + istio = module.istio.id minio = module.minio.id } } module "thanos" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-thanos.git//kind?ref=v2.7.0" + source = "../../../modern-gitops-stack-module-thanos//kind" cluster_name = local.cluster_name base_domain = local.base_domain @@ -380,6 +398,7 @@ module "thanos" { app_autosync = local.app_autosync enable_service_monitor = local.enable_service_monitor + target_revision = "develop" metrics_storage = { bucket_name = local.minio_config.buckets.1.name @@ -394,7 +413,7 @@ module "thanos" { dependency_ids = { argocd = module.argocd_bootstrap.id - traefik = module.traefik.id + istio = module.istio.id cert-manager = module.cert-manager.id minio = module.minio.id keycloak = module.keycloak.id @@ -403,7 +422,7 @@ module "thanos" { } module "kube-prometheus-stack" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-kube-prometheus-stack.git//kind?ref=v2.7.0" + source = "../../../modern-gitops-stack-module-kube-prometheus-stack//kind" cluster_name = local.cluster_name base_domain = local.base_domain @@ -413,6 +432,7 @@ module "kube-prometheus-stack" { app_autosync = local.app_autosync + target_revision = "develop" metrics_storage = { bucket_name = local.minio_config.buckets.1.name @@ -432,7 +452,7 @@ module "kube-prometheus-stack" { } dependency_ids = { - traefik = module.traefik.id + istio = module.istio.id cert-manager = module.cert-manager.id minio = module.minio.id oidc = module.oidc.id @@ -591,37 +611,37 @@ module "kube-prometheus-stack" { # # } # # } -module "argocd" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-argocd.git?ref=v4.1.0" - - base_domain = local.base_domain - cluster_name = local.cluster_name - subdomain = local.subdomain - cluster_issuer = local.cluster_issuer - server_secretkey = module.argocd_bootstrap.argocd_server_secretkey - accounts_pipeline_tokens = module.argocd_bootstrap.argocd_accounts_pipeline_tokens - argocd_project = local.cluster_name - app_autosync = local.app_autosync - - admin_enabled = false - exec_enabled = true - - oidc = { - name = "OIDC" - issuer = module.oidc.oidc.issuer_url - clientID = module.oidc.oidc.client_id - clientSecret = module.oidc.oidc.client_secret - requestedIDTokenClaims = { - groups = { - essential = true - } - } - } - - dependency_ids = { - traefik = module.traefik.id - cert-manager = module.cert-manager.id - oidc = module.oidc.id - kube-prometheus-stack = module.kube-prometheus-stack.id - } -} +# module "argocd" { +# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-argocd.git?ref=v4.1.0" +# +# base_domain = local.base_domain +# cluster_name = local.cluster_name +# subdomain = local.subdomain +# cluster_issuer = local.cluster_issuer +# server_secretkey = module.argocd_bootstrap.argocd_server_secretkey +# accounts_pipeline_tokens = module.argocd_bootstrap.argocd_accounts_pipeline_tokens +# argocd_project = local.cluster_name +# app_autosync = local.app_autosync +# +# admin_enabled = false +# exec_enabled = true +# +# oidc = { +# name = "OIDC" +# issuer = module.oidc.oidc.issuer_url +# clientID = module.oidc.oidc.client_id +# clientSecret = module.oidc.oidc.client_secret +# requestedIDTokenClaims = { +# groups = { +# essential = true +# } +# } +# } +# +# dependency_ids = { +# istio = module.istio.id +# cert-manager = module.cert-manager.id +# oidc = module.oidc.id +# kube-prometheus-stack = module.kube-prometheus-stack.id +# } +# } From 6988f00edd3bfbb6639aebbc47e1f2324fa1a7e1 Mon Sep 17 00:00:00 2001 From: GersonRS Date: Mon, 18 May 2026 20:14:58 -0300 Subject: [PATCH 3/6] feat: enable airflow module with Istio HTTPRoute and minio/postgresql integration --- examples/kind/main.tf | 154 +++++++++++++++++++++++------------------- 1 file changed, 83 insertions(+), 71 deletions(-) diff --git a/examples/kind/main.tf b/examples/kind/main.tf index dff6c04..5078fa2 100644 --- a/examples/kind/main.tf +++ b/examples/kind/main.tf @@ -411,6 +411,14 @@ module "thanos" { oidc = module.oidc.oidc } + allowed_groups = [ + "modern-gitops-stack-admins", + "modern-gitops-stack-editors", + "modern-gitops-stack-data-engineers", + "modern-gitops-stack-ml-engineers", + "modern-gitops-stack-data-scientists", + ] + dependency_ids = { argocd = module.argocd_bootstrap.id istio = module.istio.id @@ -451,6 +459,15 @@ module "kube-prometheus-stack" { oidc = module.oidc.oidc } + allowed_groups = [ + "modern-gitops-stack-admins", + "modern-gitops-stack-viewers", + "modern-gitops-stack-editors", + "modern-gitops-stack-data-engineers", + "modern-gitops-stack-ml-engineers", + "modern-gitops-stack-data-scientists", + ] + dependency_ids = { istio = module.istio.id cert-manager = module.cert-manager.id @@ -517,43 +534,37 @@ module "kube-prometheus-stack" { # # } # # } -# # module "airflow" { -# # source = "git::https://github.com/GersonRS/modern-gitops-stack-module-airflow.git?ref=v1.6.2" -# # cluster_name = local.cluster_name -# # base_domain = local.base_domain -# # subdomain = local.subdomain -# # cluster_issuer = local.cluster_issuer -# # argocd_project = local.cluster_name -# # app_autosync = local.app_autosync -# # enable_service_monitor = local.enable_service_monitor -# # oidc = module.oidc.oidc -# # fernetKey = base64encode(resource.random_password.airflow_fernetKey.result) -# # storage = { -# # bucket_name = "airflow" -# # endpoint = module.minio.endpoint -# # access_key = module.minio.minio_root_user_credentials.username -# # secret_access_key = module.minio.minio_root_user_credentials.password -# # } -# # database = { -# # database = "airflow" -# # user = module.postgresql.credentials.user -# # password = module.postgresql.credentials.password -# # endpoint = module.postgresql.cluster_dns -# # } -# # # mlflow = { -# # # endpoint = module.mlflow.cluster_dns -# # # } -# # # ray = { -# # # endpoint = module.ray.cluster_dns -# # # } -# # dependency_ids = { -# # argocd = module.argocd_bootstrap.id -# # traefik = module.traefik.id -# # oidc = module.oidc.id -# # minio = module.minio.id -# # postgresql = module.postgresql.id -# # } -# # } +module "airflow" { + source = "../../../modern-gitops-stack-module-airflow" + cluster_name = local.cluster_name + base_domain = local.base_domain + subdomain = local.subdomain + cluster_issuer = local.cluster_issuer + argocd_project = local.cluster_name + app_autosync = local.app_autosync + enable_service_monitor = local.enable_service_monitor + oidc = module.oidc.oidc + fernetKey = base64encode(resource.random_password.airflow_fernetKey.result) + storage = { + bucket_name = local.minio_config.buckets.3.name + endpoint = module.minio.endpoint + access_key = local.minio_config.users.3.accessKey + secret_access_key = local.minio_config.users.3.secretKey + } + database = { + database = "airflow" + user = module.postgresql.credentials.username + password = module.postgresql.credentials.password + endpoint = module.postgresql.cluster_dns + } + dependency_ids = { + argocd = module.argocd_bootstrap.id + istio = module.istio.id + oidc = module.oidc.id + minio = module.minio.id + postgresql = module.postgresql.id + } +} # module "jupyterhub" { # source = "git::https://github.com/GersonRS/modern-gitops-stack-module-jupyterhub.git?ref=develop" @@ -611,37 +622,38 @@ module "kube-prometheus-stack" { # # } # # } -# module "argocd" { -# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-argocd.git?ref=v4.1.0" -# -# base_domain = local.base_domain -# cluster_name = local.cluster_name -# subdomain = local.subdomain -# cluster_issuer = local.cluster_issuer -# server_secretkey = module.argocd_bootstrap.argocd_server_secretkey -# accounts_pipeline_tokens = module.argocd_bootstrap.argocd_accounts_pipeline_tokens -# argocd_project = local.cluster_name -# app_autosync = local.app_autosync -# -# admin_enabled = false -# exec_enabled = true -# -# oidc = { -# name = "OIDC" -# issuer = module.oidc.oidc.issuer_url -# clientID = module.oidc.oidc.client_id -# clientSecret = module.oidc.oidc.client_secret -# requestedIDTokenClaims = { -# groups = { -# essential = true -# } -# } -# } -# -# dependency_ids = { -# istio = module.istio.id -# cert-manager = module.cert-manager.id -# oidc = module.oidc.id -# kube-prometheus-stack = module.kube-prometheus-stack.id -# } -# } +module "argocd" { + source = "../../../modern-gitops-stack-module-argocd" + + base_domain = local.base_domain + cluster_name = local.cluster_name + subdomain = local.subdomain + cluster_issuer = local.cluster_issuer + target_revision = "feature/argocd-httproute" + server_secretkey = module.argocd_bootstrap.argocd_server_secretkey + accounts_pipeline_tokens = module.argocd_bootstrap.argocd_accounts_pipeline_tokens + argocd_project = local.cluster_name + app_autosync = local.app_autosync + + admin_enabled = false + exec_enabled = true + + oidc = { + name = "OIDC" + issuer = module.oidc.oidc.issuer_url + clientID = module.oidc.oidc.client_id + clientSecret = module.oidc.oidc.client_secret + requestedIDTokenClaims = { + groups = { + essential = true + } + } + } + + dependency_ids = { + istio = module.istio.id + cert-manager = module.cert-manager.id + oidc = module.oidc.id + kube-prometheus-stack = module.kube-prometheus-stack.id + } +} From 698691c230cae96eb67bcd7808a85ca09ec715b6 Mon Sep 17 00:00:00 2001 From: GersonRS Date: Mon, 18 May 2026 20:28:55 -0300 Subject: [PATCH 4/6] feat: set airflow target_revision to develop branch --- examples/kind/main.tf | 1 + 1 file changed, 1 insertion(+) diff --git a/examples/kind/main.tf b/examples/kind/main.tf index 5078fa2..bb8a176 100644 --- a/examples/kind/main.tf +++ b/examples/kind/main.tf @@ -543,6 +543,7 @@ module "airflow" { argocd_project = local.cluster_name app_autosync = local.app_autosync enable_service_monitor = local.enable_service_monitor + target_revision = "develop" oidc = module.oidc.oidc fernetKey = base64encode(resource.random_password.airflow_fernetKey.result) storage = { From cce91a94c91e9298a2adcf4b59a8404a8cc07105 Mon Sep 17 00:00:00 2001 From: GersonRS Date: Wed, 20 May 2026 01:09:44 -0300 Subject: [PATCH 5/6] fix: switch kind example to released module refs and istio base domain --- examples/kind/locals.tf | 2 +- examples/kind/main.tf | 588 ++++++++++++++++++++-------------------- 2 files changed, 299 insertions(+), 291 deletions(-) diff --git a/examples/kind/locals.tf b/examples/kind/locals.tf index 3d6606b..8e1508d 100644 --- a/examples/kind/locals.tf +++ b/examples/kind/locals.tf @@ -5,7 +5,7 @@ resource "random_password" "airflow_fernetKey" { locals { kubernetes_version = "v1.35.0" cluster_name = "kind" - base_domain = format("%s.nip.io", replace(module.traefik.external_ip, ".", "-")) + base_domain = format("%s.nip.io", replace(module.istio.external_ip, ".", "-")) subdomain = "apps" cluster_issuer = module.cert-manager.cluster_issuers.ca enable_service_monitor = false # Can be enabled after the first bootstrap. diff --git a/examples/kind/main.tf b/examples/kind/main.tf index bb8a176..8596943 100644 --- a/examples/kind/main.tf +++ b/examples/kind/main.tf @@ -69,12 +69,13 @@ module "metrics-server" { } module "istio" { - source = "../../../modern-gitops-stack-module-istio//kind" + source = "git::https://github.com/GersonRS/modern-gitops-stack-module-istio.git//kind?ref=v1.1.1" - cluster_name = local.cluster_name - subdomain = local.subdomain - cluster_issuer = local.cluster_issuer - argocd_project = local.cluster_name + cluster_name = local.cluster_name + subdomain = local.subdomain + cluster_issuer = local.cluster_issuer + argocd_project = local.cluster_name + target_revision = "v1.1.1" app_autosync = local.app_autosync enable_service_monitor = local.enable_service_monitor @@ -113,7 +114,7 @@ module "postgresql" { } module "keycloak" { - source = "../../../modern-gitops-stack-module-keycloak" + source = "git::https://github.com/GersonRS/modern-gitops-stack-module-keycloak.git?ref=v2.8.0" cluster_name = local.cluster_name base_domain = local.base_domain @@ -121,7 +122,7 @@ module "keycloak" { cluster_issuer = local.cluster_issuer argocd_project = local.cluster_name - target_revision = "develop" + target_revision = "v2.8.0" app_autosync = local.app_autosync database = { @@ -138,7 +139,7 @@ module "keycloak" { } module "oidc" { - source = "../../../modern-gitops-stack-module-keycloak//oidc_bootstrap" + source = "git::https://github.com/GersonRS/modern-gitops-stack-module-keycloak.git//oidc_bootstrap?ref=v2.8.0" cluster_name = local.cluster_name base_domain = local.base_domain @@ -152,133 +153,140 @@ module "oidc" { -module "minio" { - source = "../../../modern-gitops-stack-module-minio" +# module "minio" { +# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-minio.git?ref=v2.9.0" +# +# cluster_name = local.cluster_name +# base_domain = local.base_domain +# subdomain = local.subdomain +# cluster_issuer = local.cluster_issuer +# argocd_project = local.cluster_name +# app_autosync = local.app_autosync +# enable_service_monitor = local.enable_service_monitor +# config_minio = local.minio_config +# oidc = module.oidc.oidc +# +# target_revision = "v2.9.0" +# +# dependency_ids = { +# istio = module.istio.id +# cert-manager = module.cert-manager.id +# oidc = module.oidc.id +# } +# } + +# --- Modules below commented out - migrating one by one --- + +# module "mlflow" { +# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-mlflow.git?ref=v1.4.0" +# +# cluster_name = local.cluster_name +# base_domain = local.base_domain +# subdomain = local.subdomain +# cluster_issuer = local.cluster_issuer +# argocd_project = local.cluster_name +# app_autosync = local.app_autosync +# enable_service_monitor = local.enable_service_monitor +# +# target_revision = "v1.4.0" +# +# oidc = module.oidc.oidc +# allowed_groups = [ +# "modern-gitops-stack-admins", +# "modern-gitops-stack-data-scientists", +# "modern-gitops-stack-ml-engineers", +# ] +# +# storage = { +# bucket_name = "mlflow" +# endpoint = module.minio.endpoint +# access_key = module.minio.minio_root_user_credentials.username +# secret_access_key = module.minio.minio_root_user_credentials.password +# } +# database = { +# user = module.postgresql.credentials.username +# password = module.postgresql.credentials.password +# database = "mlflow" +# service = module.postgresql.cluster_dns +# } +# dependency_ids = { +# argocd = module.argocd_bootstrap.id +# istio = module.istio.id +# minio = module.minio.id +# postgresql = module.postgresql.id +# oidc = module.oidc.id +# } +# } +module "strimzi" { + source = "git::https://github.com/GersonRS/modern-gitops-stack-module-strimzi.git?ref=v1.5.0" cluster_name = local.cluster_name base_domain = local.base_domain subdomain = local.subdomain cluster_issuer = local.cluster_issuer argocd_project = local.cluster_name + target_revision = "v1.5.0" app_autosync = local.app_autosync enable_service_monitor = local.enable_service_monitor - config_minio = local.minio_config - oidc = module.oidc.oidc - - target_revision = "develop" - dependency_ids = { - istio = module.istio.id - cert-manager = module.cert-manager.id - oidc = module.oidc.id + argocd = module.argocd_bootstrap.id } } -# --- Everything below is commented out for Phase 1 (Istio migration up to MinIO) --- - -module "mlflow" { - source = "../../../modern-gitops-stack-module-mlflow" - +module "kafka" { + source = "git::https://github.com/GersonRS/modern-gitops-stack-module-kafka.git?ref=v2.12.0" cluster_name = local.cluster_name base_domain = local.base_domain subdomain = local.subdomain cluster_issuer = local.cluster_issuer argocd_project = local.cluster_name + target_revision = "v2.12.0" app_autosync = local.app_autosync enable_service_monitor = local.enable_service_monitor - - target_revision = "develop" - - oidc = module.oidc.oidc - allowed_groups = [ - "modern-gitops-stack-admins", - "modern-gitops-stack-data-scientists", - "modern-gitops-stack-ml-engineers", - ] - - storage = { - bucket_name = "mlflow" - endpoint = module.minio.endpoint - access_key = module.minio.minio_root_user_credentials.username - secret_access_key = module.minio.minio_root_user_credentials.password - } - database = { - user = module.postgresql.credentials.username - password = module.postgresql.credentials.password - database = "mlflow" - service = module.postgresql.cluster_dns - } dependency_ids = { - argocd = module.argocd_bootstrap.id - istio = module.istio.id - minio = module.minio.id - postgresql = module.postgresql.id - oidc = module.oidc.id + argocd = module.argocd_bootstrap.id + strimzi = module.strimzi.id } } -# # # module "strimzi" { -# # # source = "git::https://github.com/GersonRS/modern-gitops-stack-module-strimzi.git?ref=v1.4.3" -# # # cluster_name = local.cluster_name -# # # base_domain = local.base_domain -# # # subdomain = local.subdomain -# # # cluster_issuer = local.cluster_issuer -# # # argocd_project = local.cluster_name -# # # app_autosync = local.app_autosync -# # # enable_service_monitor = local.enable_service_monitor -# # # dependency_ids = { -# # # argocd = module.argocd_bootstrap.id -# # # } -# # # } - -# # # module "kafka" { -# # # source = "git::https://github.com/GersonRS/modern-gitops-stack-module-kafka.git?ref=v2.11.0" -# # # cluster_name = local.cluster_name -# # # base_domain = local.base_domain -# # # subdomain = local.subdomain -# # # cluster_issuer = local.cluster_issuer -# # # argocd_project = local.cluster_name -# # # app_autosync = local.app_autosync -# # # enable_service_monitor = local.enable_service_monitor -# # # dependency_ids = { -# # # argocd = module.argocd_bootstrap.id -# # # traefik = module.traefik.id -# # # strimzi = module.strimzi.id -# # # } -# # # } - -# # # module "cp-schema-registry" { -# # # source = "git::https://github.com/GersonRS/modern-gitops-stack-module-cp-schema-registry.git?ref=v1.3.2" -# # # cluster_name = local.cluster_name -# # # base_domain = local.base_domain -# # # subdomain = local.subdomain -# # # cluster_issuer = local.cluster_issuer -# # # argocd_project = local.cluster_name -# # # app_autosync = local.app_autosync -# # # enable_service_monitor = local.enable_service_monitor -# # # kafka_broker_name = module.kafka.broker_name -# # # dependency_ids = { -# # # argocd = module.argocd_bootstrap.id -# # # kafka = module.kafka.id -# # # } -# # # } +module "cp-schema-registry" { + source = "git::https://github.com/GersonRS/modern-gitops-stack-module-cp-schema-registry.git?ref=v1.4.0" + cluster_name = local.cluster_name + base_domain = local.base_domain + subdomain = local.subdomain + cluster_issuer = local.cluster_issuer + argocd_project = local.cluster_name + target_revision = "v1.4.0" + app_autosync = local.app_autosync + enable_service_monitor = local.enable_service_monitor + kafka_broker_name = module.kafka.broker_name + gateway_name = module.istio.gateway_name + gateway_namespace = module.istio.gateway_namespace + dependency_ids = { + argocd = module.argocd_bootstrap.id + kafka = module.kafka.id + } +} -# # # module "kafka-ui" { -# # # source = "git::https://github.com/GersonRS/modern-gitops-stack-module-kafka-ui.git?ref=v1.3.3" -# # # cluster_name = local.cluster_name -# # # base_domain = local.base_domain -# # # subdomain = local.subdomain -# # # cluster_issuer = local.cluster_issuer -# # # argocd_project = local.cluster_name -# # # app_autosync = local.app_autosync -# # # enable_service_monitor = local.enable_service_monitor -# # # kafka_broker_name = module.kafka.broker_name -# # # dependency_ids = { -# # # argocd = module.argocd_bootstrap.id -# # # kafka = module.kafka.id -# # # cp-schema-registry = module.cp-schema-registry.id -# # # } -# # # } +module "kafka-ui" { + source = "git::https://github.com/GersonRS/modern-gitops-stack-module-kafka-ui.git?ref=v1.4.0" + cluster_name = local.cluster_name + base_domain = local.base_domain + subdomain = local.subdomain + cluster_issuer = local.cluster_issuer + argocd_project = local.cluster_name + target_revision = "v1.4.0" + app_autosync = local.app_autosync + enable_service_monitor = local.enable_service_monitor + kafka_broker_name = module.kafka.broker_name + gateway_name = module.istio.gateway_name + gateway_namespace = module.istio.gateway_namespace + dependency_ids = { + argocd = module.argocd_bootstrap.id + kafka = module.kafka.id + cp-schema-registry = module.cp-schema-registry.id + } +} # # # module "pinot" { # # # source = "git::https://github.com/GersonRS/modern-gitops-stack-module-pinot.git?ref=v1.1.1" @@ -363,118 +371,118 @@ module "mlflow" { # # # } # # # } -module "loki-stack" { - source = "../../../modern-gitops-stack-module-loki-stack//kind" - - argocd_project = local.cluster_name - - app_autosync = local.app_autosync - enable_service_monitor = local.enable_service_monitor - - target_revision = "develop" - - logs_storage = { - bucket_name = local.minio_config.buckets.0.name - endpoint = module.minio.endpoint - access_key = local.minio_config.users.0.accessKey - secret_key = local.minio_config.users.0.secretKey - } - - dependency_ids = { - istio = module.istio.id - minio = module.minio.id - } -} - -module "thanos" { - source = "../../../modern-gitops-stack-module-thanos//kind" - - cluster_name = local.cluster_name - base_domain = local.base_domain - subdomain = local.subdomain - cluster_issuer = local.cluster_issuer - argocd_project = local.cluster_name - - app_autosync = local.app_autosync - enable_service_monitor = local.enable_service_monitor - - target_revision = "develop" - - metrics_storage = { - bucket_name = local.minio_config.buckets.1.name - endpoint = module.minio.endpoint - access_key = local.minio_config.users.1.accessKey - secret_key = local.minio_config.users.1.secretKey - } - - thanos = { - oidc = module.oidc.oidc - } - - allowed_groups = [ - "modern-gitops-stack-admins", - "modern-gitops-stack-editors", - "modern-gitops-stack-data-engineers", - "modern-gitops-stack-ml-engineers", - "modern-gitops-stack-data-scientists", - ] - - dependency_ids = { - argocd = module.argocd_bootstrap.id - istio = module.istio.id - cert-manager = module.cert-manager.id - minio = module.minio.id - keycloak = module.keycloak.id - oidc = module.oidc.id - } -} - -module "kube-prometheus-stack" { - source = "../../../modern-gitops-stack-module-kube-prometheus-stack//kind" - - cluster_name = local.cluster_name - base_domain = local.base_domain - subdomain = local.subdomain - cluster_issuer = local.cluster_issuer - argocd_project = local.cluster_name - - app_autosync = local.app_autosync - - target_revision = "develop" - - metrics_storage = { - bucket_name = local.minio_config.buckets.1.name - endpoint = module.minio.endpoint - access_key = local.minio_config.users.1.accessKey - secret_key = local.minio_config.users.1.secretKey - } - - prometheus = { - oidc = module.oidc.oidc - } - alertmanager = { - oidc = module.oidc.oidc - } - grafana = { - oidc = module.oidc.oidc - } +# module "loki-stack" { +# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-loki-stack.git//kind?ref=v2.8.0" +# +# argocd_project = local.cluster_name +# +# app_autosync = local.app_autosync +# enable_service_monitor = local.enable_service_monitor +# +# target_revision = "v2.8.0" +# +# logs_storage = { +# bucket_name = local.minio_config.buckets.0.name +# endpoint = module.minio.endpoint +# access_key = local.minio_config.users.0.accessKey +# secret_key = local.minio_config.users.0.secretKey +# } +# +# dependency_ids = { +# istio = module.istio.id +# minio = module.minio.id +# } +# } - allowed_groups = [ - "modern-gitops-stack-admins", - "modern-gitops-stack-viewers", - "modern-gitops-stack-editors", - "modern-gitops-stack-data-engineers", - "modern-gitops-stack-ml-engineers", - "modern-gitops-stack-data-scientists", - ] +# module "thanos" { +# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-thanos.git//kind?ref=v2.8.0" +# +# cluster_name = local.cluster_name +# base_domain = local.base_domain +# subdomain = local.subdomain +# cluster_issuer = local.cluster_issuer +# argocd_project = local.cluster_name +# +# app_autosync = local.app_autosync +# enable_service_monitor = local.enable_service_monitor +# +# target_revision = "v2.8.0" +# +# metrics_storage = { +# bucket_name = local.minio_config.buckets.1.name +# endpoint = module.minio.endpoint +# access_key = local.minio_config.users.1.accessKey +# secret_key = local.minio_config.users.1.secretKey +# } +# +# thanos = { +# oidc = module.oidc.oidc +# } +# +# allowed_groups = [ +# "modern-gitops-stack-admins", +# "modern-gitops-stack-editors", +# "modern-gitops-stack-data-engineers", +# "modern-gitops-stack-ml-engineers", +# "modern-gitops-stack-data-scientists", +# ] +# +# dependency_ids = { +# argocd = module.argocd_bootstrap.id +# istio = module.istio.id +# cert-manager = module.cert-manager.id +# minio = module.minio.id +# keycloak = module.keycloak.id +# oidc = module.oidc.id +# } +# } - dependency_ids = { - istio = module.istio.id - cert-manager = module.cert-manager.id - minio = module.minio.id - oidc = module.oidc.id - } -} +# module "kube-prometheus-stack" { +# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-kube-prometheus-stack.git//kind?ref=v2.8.0" +# +# cluster_name = local.cluster_name +# base_domain = local.base_domain +# subdomain = local.subdomain +# cluster_issuer = local.cluster_issuer +# argocd_project = local.cluster_name +# +# app_autosync = local.app_autosync +# +# target_revision = "v2.8.0" +# +# metrics_storage = { +# bucket_name = local.minio_config.buckets.1.name +# endpoint = module.minio.endpoint +# access_key = local.minio_config.users.1.accessKey +# secret_key = local.minio_config.users.1.secretKey +# } +# +# prometheus = { +# oidc = module.oidc.oidc +# } +# alertmanager = { +# oidc = module.oidc.oidc +# } +# grafana = { +# oidc = module.oidc.oidc +# } +# +# allowed_groups = [ +# "modern-gitops-stack-admins", +# "modern-gitops-stack-viewers", +# "modern-gitops-stack-editors", +# "modern-gitops-stack-data-engineers", +# "modern-gitops-stack-ml-engineers", +# "modern-gitops-stack-data-scientists", +# ] +# +# dependency_ids = { +# istio = module.istio.id +# cert-manager = module.cert-manager.id +# minio = module.minio.id +# oidc = module.oidc.id +# } +# } # # module "spark" { # # source = "git::https://github.com/GersonRS/modern-gitops-stack-module-spark.git?ref=v1.5.1" @@ -534,41 +542,41 @@ module "kube-prometheus-stack" { # # } # # } -module "airflow" { - source = "../../../modern-gitops-stack-module-airflow" - cluster_name = local.cluster_name - base_domain = local.base_domain - subdomain = local.subdomain - cluster_issuer = local.cluster_issuer - argocd_project = local.cluster_name - app_autosync = local.app_autosync - enable_service_monitor = local.enable_service_monitor - target_revision = "develop" - oidc = module.oidc.oidc - fernetKey = base64encode(resource.random_password.airflow_fernetKey.result) - storage = { - bucket_name = local.minio_config.buckets.3.name - endpoint = module.minio.endpoint - access_key = local.minio_config.users.3.accessKey - secret_access_key = local.minio_config.users.3.secretKey - } - database = { - database = "airflow" - user = module.postgresql.credentials.username - password = module.postgresql.credentials.password - endpoint = module.postgresql.cluster_dns - } - dependency_ids = { - argocd = module.argocd_bootstrap.id - istio = module.istio.id - oidc = module.oidc.id - minio = module.minio.id - postgresql = module.postgresql.id - } -} +# module "airflow" { +# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-airflow.git?ref=v1.7.0" +# cluster_name = local.cluster_name +# base_domain = local.base_domain +# subdomain = local.subdomain +# cluster_issuer = local.cluster_issuer +# argocd_project = local.cluster_name +# app_autosync = local.app_autosync +# enable_service_monitor = local.enable_service_monitor +# target_revision = "v1.7.0" +# oidc = module.oidc.oidc +# fernetKey = base64encode(resource.random_password.airflow_fernetKey.result) +# storage = { +# bucket_name = local.minio_config.buckets.3.name +# endpoint = module.minio.endpoint +# access_key = local.minio_config.users.3.accessKey +# secret_access_key = local.minio_config.users.3.secretKey +# } +# database = { +# database = "airflow" +# user = module.postgresql.credentials.username +# password = module.postgresql.credentials.password +# endpoint = module.postgresql.cluster_dns +# } +# dependency_ids = { +# argocd = module.argocd_bootstrap.id +# istio = module.istio.id +# oidc = module.oidc.id +# minio = module.minio.id +# postgresql = module.postgresql.id +# } +# } # module "jupyterhub" { -# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-jupyterhub.git?ref=develop" +# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-jupyterhub.git?ref=v1.2.0" # cluster_name = local.cluster_name # base_domain = local.base_domain # subdomain = local.subdomain @@ -576,7 +584,7 @@ module "airflow" { # argocd_project = local.cluster_name # app_autosync = local.app_autosync # oidc = module.oidc.oidc -# target_revision = "develop" +# target_revision = "v1.2.0" # storage = { # bucket_name = "mlflow" # endpoint = module.minio.endpoint @@ -623,38 +631,38 @@ module "airflow" { # # } # # } -module "argocd" { - source = "../../../modern-gitops-stack-module-argocd" - - base_domain = local.base_domain - cluster_name = local.cluster_name - subdomain = local.subdomain - cluster_issuer = local.cluster_issuer - target_revision = "feature/argocd-httproute" - server_secretkey = module.argocd_bootstrap.argocd_server_secretkey - accounts_pipeline_tokens = module.argocd_bootstrap.argocd_accounts_pipeline_tokens - argocd_project = local.cluster_name - app_autosync = local.app_autosync - - admin_enabled = false - exec_enabled = true - - oidc = { - name = "OIDC" - issuer = module.oidc.oidc.issuer_url - clientID = module.oidc.oidc.client_id - clientSecret = module.oidc.oidc.client_secret - requestedIDTokenClaims = { - groups = { - essential = true - } - } - } - - dependency_ids = { - istio = module.istio.id - cert-manager = module.cert-manager.id - oidc = module.oidc.id - kube-prometheus-stack = module.kube-prometheus-stack.id - } -} +# module "argocd" { +# source = "git::https://github.com/GersonRS/modern-gitops-stack-module-argocd.git?ref=v4.2.0" +# +# base_domain = local.base_domain +# cluster_name = local.cluster_name +# subdomain = local.subdomain +# cluster_issuer = local.cluster_issuer +# target_revision = "v4.2.0" +# server_secretkey = module.argocd_bootstrap.argocd_server_secretkey +# accounts_pipeline_tokens = module.argocd_bootstrap.argocd_accounts_pipeline_tokens +# argocd_project = local.cluster_name +# app_autosync = local.app_autosync +# +# admin_enabled = false +# exec_enabled = true +# +# oidc = { +# name = "OIDC" +# issuer = module.oidc.oidc.issuer_url +# clientID = module.oidc.oidc.client_id +# clientSecret = module.oidc.oidc.client_secret +# requestedIDTokenClaims = { +# groups = { +# essential = true +# } +# } +# } +# +# dependency_ids = { +# istio = module.istio.id +# cert-manager = module.cert-manager.id +# oidc = module.oidc.id +# kube-prometheus-stack = module.kube-prometheus-stack.id +# } +# } From f0a69d39283bdd8868d835b9c63cf8da6ad8075d Mon Sep 17 00:00:00 2001 From: GersonRS Date: Wed, 20 May 2026 01:27:19 -0300 Subject: [PATCH 6/6] feat: enable OIDC-protected kafka-ui and schema-registry modules --- examples/kind/main.tf | 18 ++++++++++++++---- 1 file changed, 14 insertions(+), 4 deletions(-) diff --git a/examples/kind/main.tf b/examples/kind/main.tf index 8596943..e38ff44 100644 --- a/examples/kind/main.tf +++ b/examples/kind/main.tf @@ -250,18 +250,23 @@ module "kafka" { } module "cp-schema-registry" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-cp-schema-registry.git?ref=v1.4.0" + source = "git::https://github.com/GersonRS/modern-gitops-stack-module-cp-schema-registry.git?ref=v1.5.0" cluster_name = local.cluster_name base_domain = local.base_domain subdomain = local.subdomain cluster_issuer = local.cluster_issuer argocd_project = local.cluster_name - target_revision = "v1.4.0" + target_revision = "v1.5.0" app_autosync = local.app_autosync enable_service_monitor = local.enable_service_monitor kafka_broker_name = module.kafka.broker_name gateway_name = module.istio.gateway_name gateway_namespace = module.istio.gateway_namespace + oidc = module.oidc.oidc + allowed_groups = [ + "modern-gitops-stack-admins", + "modern-gitops-stack-data-engineers", + ] dependency_ids = { argocd = module.argocd_bootstrap.id kafka = module.kafka.id @@ -269,18 +274,23 @@ module "cp-schema-registry" { } module "kafka-ui" { - source = "git::https://github.com/GersonRS/modern-gitops-stack-module-kafka-ui.git?ref=v1.4.0" + source = "git::https://github.com/GersonRS/modern-gitops-stack-module-kafka-ui.git?ref=v1.5.0" cluster_name = local.cluster_name base_domain = local.base_domain subdomain = local.subdomain cluster_issuer = local.cluster_issuer argocd_project = local.cluster_name - target_revision = "v1.4.0" + target_revision = "v1.5.0" app_autosync = local.app_autosync enable_service_monitor = local.enable_service_monitor kafka_broker_name = module.kafka.broker_name gateway_name = module.istio.gateway_name gateway_namespace = module.istio.gateway_namespace + oidc = module.oidc.oidc + allowed_groups = [ + "modern-gitops-stack-admins", + "modern-gitops-stack-data-engineers", + ] dependency_ids = { argocd = module.argocd_bootstrap.id kafka = module.kafka.id