upgrade MetalLB v0.10.2 → v0.15.3 and update annotations

- Replace custom ViktorBarzin/metallb module with official Helm chart
- Migrate from ConfigMap-based config to CRD (IPAddressPool + L2Advertisement)
- Update Traefik LB annotations from metallb.universe.tf to metallb.io format
- Technitium DNS keeps stable IP 10.0.20.204 via MetalLB auto-assignment
- Headscale split DNS already configured to use 10.0.20.204
This commit is contained in:
Viktor Barzin 2026-03-24 17:24:05 +02:00
parent 957f13dfd6
commit 33037eba46
4 changed files with 53 additions and 27 deletions

View file

@ -1,9 +1,3 @@
# Creates namespace and everythin needed
# Do not use until https://github.com/colinwilson/terraform-kubernetes-metallb/issues/5 is solved
# module "metallb" {
# source = "colinwilson/metallb/kubernetes"
# version = "0.1.7"
# }
variable "tier" { type = string } variable "tier" { type = string }
resource "kubernetes_namespace" "metallb" { resource "kubernetes_namespace" "metallb" {
@ -11,30 +5,61 @@ resource "kubernetes_namespace" "metallb" {
name = "metallb-system" name = "metallb-system"
labels = { labels = {
app = "metallb" app = "metallb"
# "istio-injection" : "disabled"
# tier = var.tier
} }
} }
} }
module "metallb" { resource "helm_release" "metallb" {
source = "ViktorBarzin/metallb/kubernetes" name = "metallb"
version = "0.1.5" repository = "https://metallb.github.io/metallb"
depends_on = [kubernetes_namespace.metallb] chart = "metallb"
version = "0.15.3"
namespace = kubernetes_namespace.metallb.metadata[0].name
timeout = 600
values = [yamlencode({
controller = {
image = {
pullPolicy = "IfNotPresent"
}
}
speaker = {
image = {
pullPolicy = "IfNotPresent"
}
frr = {
enabled = false
}
}
})]
} }
resource "kubernetes_config_map" "config" { resource "kubernetes_manifest" "ip_address_pool" {
metadata { manifest = {
name = "config" apiVersion = "metallb.io/v1beta1"
namespace = kubernetes_namespace.metallb.metadata[0].name kind = "IPAddressPool"
} metadata = {
data = { name = "default"
config = <<EOT namespace = "metallb-system"
address-pools: }
- name: default spec = {
protocol: layer2 addresses = ["10.0.20.200-10.0.20.220"]
addresses: }
- 10.0.20.200-10.0.20.220
EOT
} }
depends_on = [helm_release.metallb]
}
resource "kubernetes_manifest" "l2_advertisement" {
manifest = {
apiVersion = "metallb.io/v1beta1"
kind = "L2Advertisement"
metadata = {
name = "default"
namespace = "metallb-system"
}
spec = {
ipAddressPools = ["default"]
}
}
depends_on = [helm_release.metallb]
} }

View file

@ -144,7 +144,7 @@ resource "helm_release" "traefik" {
service = { service = {
type = "LoadBalancer" type = "LoadBalancer"
annotations = { annotations = {
"metallb.universe.tf/loadBalancerIPs" = "10.0.20.202" "metallb.io/loadBalancerIPs" = "10.0.20.202"
} }
spec = { spec = {
externalTrafficPolicy = "Local" externalTrafficPolicy = "Local"

View file

@ -265,6 +265,7 @@ resource "kubernetes_service" "technitium-dns" {
labels = { labels = {
"app" = "technitium" "app" = "technitium"
} }
annotations = {}
} }
spec { spec {

View file

@ -144,7 +144,7 @@ resource "helm_release" "traefik" {
service = { service = {
type = "LoadBalancer" type = "LoadBalancer"
annotations = { annotations = {
"metallb.universe.tf/loadBalancerIPs" = "10.0.20.202" "metallb.io/loadBalancerIPs" = "10.0.20.202"
} }
spec = { spec = {
externalTrafficPolicy = "Local" externalTrafficPolicy = "Local"