Skip to content

spike - how cluster bootstrapping could happen via terraform #2205

@enekofb

Description

@enekofb

At the back of weaveworks/weave-gitops-private#101

We would like to discover whether cluster bootstrapping could happen via terraform and its limitations/tradeoffs

AC

We have discovered whether it is feasible to bootstrap a cluster with the following capabilities

  • a set of compliance and security runtime capabilities = policy agent and secrets management
  • a set of compliance and security runtime resources = policy library, secrets for flux to access a git repo, and secrets for flux to sync a profile from a private helm repo
  • we are able to deliver changes to this layer by upgrading secrets management or a secret in particular
  • the solution works with CAPI or Terraform provisioned infrastructure

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions