upgrade MetalLB v0.10.2 → v0.15.3 and update annotations

- Replace custom ViktorBarzin/metallb module with official Helm chart
- Migrate from ConfigMap-based config to CRD (IPAddressPool + L2Advertisement)
- Update Traefik LB annotations from metallb.universe.tf to metallb.io format
- Technitium DNS keeps stable IP 10.0.20.204 via MetalLB auto-assignment
- Headscale split DNS already configured to use 10.0.20.204
This commit is contained in:
Viktor Barzin 2026-03-24 17:24:05 +02:00
parent 957f13dfd6
commit 33037eba46
4 changed files with 53 additions and 27 deletions

View file

@ -1,9 +1,3 @@
# Creates namespace and everythin needed
# Do not use until https://github.com/colinwilson/terraform-kubernetes-metallb/issues/5 is solved
# module "metallb" {
# source = "colinwilson/metallb/kubernetes"
# version = "0.1.7"
# }
variable "tier" { type = string }
resource "kubernetes_namespace" "metallb" {
@ -11,30 +5,61 @@ resource "kubernetes_namespace" "metallb" {
name = "metallb-system"
labels = {
app = "metallb"
# "istio-injection" : "disabled"
# tier = var.tier
}
}
}
module "metallb" {
source = "ViktorBarzin/metallb/kubernetes"
version = "0.1.5"
depends_on = [kubernetes_namespace.metallb]
resource "helm_release" "metallb" {
name = "metallb"
repository = "https://metallb.github.io/metallb"
chart = "metallb"
version = "0.15.3"
namespace = kubernetes_namespace.metallb.metadata[0].name
timeout = 600
values = [yamlencode({
controller = {
image = {
pullPolicy = "IfNotPresent"
}
}
speaker = {
image = {
pullPolicy = "IfNotPresent"
}
frr = {
enabled = false
}
}
})]
}
resource "kubernetes_config_map" "config" {
metadata {
name = "config"
namespace = kubernetes_namespace.metallb.metadata[0].name
}
data = {
config = <<EOT
address-pools:
- name: default
protocol: layer2
addresses:
- 10.0.20.200-10.0.20.220
EOT
resource "kubernetes_manifest" "ip_address_pool" {
manifest = {
apiVersion = "metallb.io/v1beta1"
kind = "IPAddressPool"
metadata = {
name = "default"
namespace = "metallb-system"
}
spec = {
addresses = ["10.0.20.200-10.0.20.220"]
}
}
depends_on = [helm_release.metallb]
}
resource "kubernetes_manifest" "l2_advertisement" {
manifest = {
apiVersion = "metallb.io/v1beta1"
kind = "L2Advertisement"
metadata = {
name = "default"
namespace = "metallb-system"
}
spec = {
ipAddressPools = ["default"]
}
}
depends_on = [helm_release.metallb]
}

View file

@ -144,7 +144,7 @@ resource "helm_release" "traefik" {
service = {
type = "LoadBalancer"
annotations = {
"metallb.universe.tf/loadBalancerIPs" = "10.0.20.202"
"metallb.io/loadBalancerIPs" = "10.0.20.202"
}
spec = {
externalTrafficPolicy = "Local"

View file

@ -265,6 +265,7 @@ resource "kubernetes_service" "technitium-dns" {
labels = {
"app" = "technitium"
}
annotations = {}
}
spec {

View file

@ -144,7 +144,7 @@ resource "helm_release" "traefik" {
service = {
type = "LoadBalancer"
annotations = {
"metallb.universe.tf/loadBalancerIPs" = "10.0.20.202"
"metallb.io/loadBalancerIPs" = "10.0.20.202"
}
spec = {
externalTrafficPolicy = "Local"