From f61d707d754c82b92b072c85914df0845e55672e Mon Sep 17 00:00:00 2001 From: Viktor Barzin Date: Sat, 13 Jun 2026 09:32:39 +0000 Subject: [PATCH] travel_blog: remove decommissioned stack (ADR-0002 infra#31) Service was already scaled 0/0 and unused (Viktor: 'not used anymore'). Live resources destroyed via scripts/tg destroy (10 resources: deployment, namespace, service, anubis-travel + PDB/cm/svc/secret, ingress, TLS). Removing the stack dir; old Woodpecker build (repo 5) deactivated separately. The harmless legacy 'travel' CNAME->apex in config.tfvars is left (now 404s; removing it would trigger a full-platform apply). Co-Authored-By: Claude Fable 5 --- stacks/travel_blog/.terraform.lock.hcl | 94 --------------- stacks/travel_blog/main.tf | 152 ------------------------- stacks/travel_blog/providers.tf | 37 ------ stacks/travel_blog/secrets | 1 - stacks/travel_blog/terragrunt.hcl | 8 -- 5 files changed, 292 deletions(-) delete mode 100644 stacks/travel_blog/.terraform.lock.hcl delete mode 100644 stacks/travel_blog/main.tf delete mode 100644 stacks/travel_blog/providers.tf delete mode 120000 stacks/travel_blog/secrets delete mode 100644 stacks/travel_blog/terragrunt.hcl diff --git a/stacks/travel_blog/.terraform.lock.hcl b/stacks/travel_blog/.terraform.lock.hcl deleted file mode 100644 index 7b0b0924..00000000 --- a/stacks/travel_blog/.terraform.lock.hcl +++ /dev/null @@ -1,94 +0,0 @@ -# This file is maintained automatically by "terraform init". -# Manual edits may be lost in future updates. - -provider "registry.terraform.io/cloudflare/cloudflare" { - version = "4.52.7" - constraints = "~> 4.0" - hashes = [ - "h1:pPItIWii5oymR+geZB219ROSPuSODPLTlM4S/u8xLvM=", - "zh:0c904ce31a4c6c4a5b3bf7ff1560e77c0cc7e2450c8553ded8e8c90398e1418b", - "zh:36183d310c36373fe4cb936b83c595c6fd3b0a94bc7827f28e5789ccbf59752e", - "zh:556a568a6f0235e8f41647de9e4d3a1e7b1d6502df8b19b54ec441f1c653ea10", - "zh:633ebbd5b0245e75e500ef9be4d9e62288f97e8da3baaa51323892a786d90285", - "zh:6acfe60cf52a65ba8f044f748548d2119e7f4fd7f8ebcb14698960d87c68f529", - "zh:890df766e9b839623b1f0437355032a3c006226a6c200cd911e15ee1a9014e9f", - "zh:904acc31ebb9d6ef68c792074b30532ee61bf515f19e0a3c75b46f126cca1f13", - "zh:a1d0a81246afc8750286d3f6fe7a8fbe6460dd2662407b28dbfbabb612e5fa9d", - "zh:a41a36fe253fc365fe2b7ffc749624688b2693b4634862fda161179ab100029f", - "zh:a7ef269e77ffa8715c8945a2c14322c7ff159ea44c15f62505f3cbb2cae3b32d", - "zh:b01aa3bed30610633b762df64332b26f8844a68c3960cebcb30f04918efc67fe", - "zh:b069cc2cd18cae10757df3ae030508eac8d55de7e49eda7a5e3e11f2f7fe6455", - "zh:b2d2c6313729ebb7465dceece374049e2d08bda34473901be9ff46a8836d42b2", - "zh:db0e114edaf4bc2f3d4769958807c83022bfbc619a00bdf4c4bd17faa4ab2d8b", - "zh:ecc0aa8b9044f664fd2aaf8fa992d976578f78478980555b4b8f6148e8d1a5fe", - ] -} - -provider "registry.terraform.io/goauthentik/authentik" { - version = "2024.12.1" - constraints = "~> 2024.10" - hashes = [ - "h1:roBMd+gi+TGgikH/bMzEI8JfvJiMAQWt+8FmokCrQIs=", - ] -} - -provider "registry.terraform.io/hashicorp/helm" { - version = "3.1.1" - hashes = [ - "h1:47CqNwkxctJtL/N/JuEj+8QMg8mRNI/NWeKO5/ydfZU=", - "h1:5b2ojWKT0noujHiweCds37ZreRFRQLNaErdJLusJN88=", - "zh:1a6d5ce931708aec29d1f3d9e360c2a0c35ba5a54d03eeaff0ce3ca597cd0275", - "zh:3411919ba2a5941801e677f0fea08bdd0ae22ba3c9ce3309f55554699e06524a", - "zh:81b36138b8f2320dc7f877b50f9e38f4bc614affe68de885d322629dd0d16a29", - "zh:95a2a0a497a6082ee06f95b38bd0f0d6924a65722892a856cfd914c0d117f104", - "zh:9d3e78c2d1bb46508b972210ad706dd8c8b106f8b206ecf096cd211c54f46990", - "zh:a79139abf687387a6efdbbb04289a0a8e7eaca2bd91cdc0ce68ea4f3286c2c34", - "zh:aaa8784be125fbd50c48d84d6e171d3fb6ef84a221dbc5165c067ce05faab4c8", - "zh:afecd301f469975c9d8f350cc482fe656e082b6ab0f677d1a816c3c615837cc1", - "zh:c54c22b18d48ff9053d899d178d9ffef7d9d19785d9bf310a07d648b7aac075b", - "zh:db2eefd55aea48e73384a555c72bac3f7d428e24147bedb64e1a039398e5b903", - "zh:ee61666a233533fd2be971091cecc01650561f1585783c381b6f6e8a390198a4", - "zh:f569b65999264a9416862bca5cd2a6177d94ccb0424f3a4ef424428912b9cb3c", - ] -} - -provider "registry.terraform.io/hashicorp/kubernetes" { - version = "3.0.1" - hashes = [ - "h1:P0c8knzZnouTNFIRij8IS7+pqd0OKaFDYX0j4GRsiqo=", - "h1:vyHdH0p6bf9xp1NPePObAJkXTJb/I09FQQmmevTzZe0=", - "zh:02d55b0b2238fd17ffa12d5464593864e80f402b90b31f6e1bd02249b9727281", - "zh:20b93a51bfeed82682b3c12f09bac3031f5bdb4977c47c97a042e4df4fb2f9ba", - "zh:6e14486ecfaee38c09ccf33d4fdaf791409f90795c1b66e026c226fad8bc03c7", - "zh:8d0656ff422df94575668e32c310980193fccb1c28117e5c78dd2d4050a760a6", - "zh:9795119b30ec0c1baa99a79abace56ac850b6e6fbce60e7f6067792f6eb4b5f4", - "zh:b388c87acc40f6bd9620f4e23f01f3c7b41d9b88a68d5255dec0a72f0bdec249", - "zh:b59abd0a980649c2f97f172392f080eaeb18e486b603f83bf95f5d93aeccc090", - "zh:ba6e3060fddf4a022087d8f09e38aa0001c705f21170c2ded3d1c26c12f70d97", - "zh:c12626d044b1d5501cf95ca78cbe507c13ad1dd9f12d4736df66eb8e5f336eb8", - "zh:c55203240d50f4cdeb3df1e1760630d677679f5b1a6ffd9eba23662a4ad05119", - "zh:ea206a5a32d6e0d6e32f1849ad703da9a28355d9c516282a8458b5cf1502b2a1", - "zh:f569b65999264a9416862bca5cd2a6177d94ccb0424f3a4ef424428912b9cb3c", - ] -} - -provider "registry.terraform.io/hashicorp/vault" { - version = "4.8.0" - constraints = "~> 4.0" - hashes = [ - "h1:GPfhH6dr1LY0foPBDYv9bEGifx7eSwYqFcEAOWOUxLk=", - "h1:aHqgWQhDBMeZO9iUKwJYMlh4q+xNMUlMIcjRbF4d02Y=", - "zh:269ab13433f67684012ae7e15876532b0312f5d0d2002a9cf9febb1279ce5ea6", - "zh:4babc95bf0c40eb85005db1dc2ca403c46be4a71dd3e409db3711a56f7a5ca0e", - "zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3", - "zh:86e27c1c625ecc24446a11eeffc3ac319b36c2b4e51251db8579256a0dbcf136", - "zh:a32f31da94824009e26b077374440b52098aecb93c92ff55dc3d31dd37c4ea25", - "zh:be0a18c6c0425518bab4fbffd82078b82036a88503b5d76064de551c9f646cbf", - "zh:be5a77fdfd36863ebeec79cd12b1d13322ffad6821d157a0b279789fa06b5937", - "zh:be8317d142a3caad74c7d936039ae27076a1b2b8312ef5208e2871a5f525977c", - "zh:c94a84895a3d9954b80e983eed4603330a5cdbbd8eef5b3c99278c2d1402ef3c", - "zh:de1fb712784dd8415f011ca5346a34f87fab6046c730557615247e511dbc7d98", - "zh:e3eafae7da550f86cae395d6660b2a0e93ec8d2b0e0e5ef982ec762e961fc952", - "zh:ff35fb1ab6add288f0f368981e56f780b50405accd1937131cba1137999c8d83", - ] -} diff --git a/stacks/travel_blog/main.tf b/stacks/travel_blog/main.tf deleted file mode 100644 index 1bc274d6..00000000 --- a/stacks/travel_blog/main.tf +++ /dev/null @@ -1,152 +0,0 @@ -variable "tls_secret_name" { - type = string - sensitive = true -} - - -resource "kubernetes_namespace" "travel-blog" { - metadata { - name = "travel-blog" - labels = { - "istio-injection" : "disabled" - tier = local.tiers.aux - "keel.sh/enrolled" = "true" - } - } - lifecycle { - # KYVERNO_LIFECYCLE_V1: goldilocks-vpa-auto-mode ClusterPolicy stamps this label on every namespace - ignore_changes = [metadata[0].labels["goldilocks.fairwinds.com/vpa-update-mode"]] - } -} - -module "tls_secret" { - source = "../../modules/kubernetes/setup_tls_secret" - namespace = kubernetes_namespace.travel-blog.metadata[0].name - tls_secret_name = var.tls_secret_name -} - -resource "kubernetes_deployment" "blog" { - metadata { - name = "travel-blog" - namespace = kubernetes_namespace.travel-blog.metadata[0].name - labels = { - app = "travel-blog" - tier = local.tiers.aux - } - } - spec { - replicas = 0 # Scaled down — clears ExternalAccessDivergence alert - selector { - match_labels = { - app = "travel-blog" - } - } - template { - metadata { - labels = { - app = "travel-blog" - } - } - spec { - container { - image = "viktorbarzin/travel_blog:latest" - name = "travel-blog" - resources { - limits = { - memory = "64Mi" - } - requests = { - cpu = "10m" - memory = "64Mi" - } - } - port { - container_port = 80 - } - } - - # container { - # image = "nginx/nginx-prometheus-exporter" - # name = "nginx-exporter" - # args = ["-nginx.scrape-uri", "http://127.0.0.1:8080/nginx_status"] - # port { - # container_port = 9113 - # } - # } - } - } - } - lifecycle { - ignore_changes = [ - spec[0].template[0].spec[0].dns_config, # KYVERNO_LIFECYCLE_V1 - metadata[0].annotations["keel.sh/policy"], - metadata[0].annotations["keel.sh/trigger"], - metadata[0].annotations["keel.sh/pollSchedule"], # KYVERNO_LIFECYCLE_V2 - metadata[0].annotations["keel.sh/match-tag"], - spec[0].template[0].spec[0].container[0].image, # KEEL_IGNORE_IMAGE — Keel manages tag updates - metadata[0].annotations["kubernetes.io/change-cause"], - metadata[0].annotations["deployment.kubernetes.io/revision"], - spec[0].template[0].metadata[0].annotations["keel.sh/update-time"], # KEEL_LIFECYCLE_V1 - ] - } -} - -resource "kubernetes_service" "travel-blog" { - metadata { - name = "travel-blog" - namespace = kubernetes_namespace.travel-blog.metadata[0].name - labels = { - app = "travel-blog" - } - } - - spec { - selector = { - app = "travel-blog" - } - port { - name = "http" - port = "80" - target_port = "80" - } - } -} - -module "anubis" { - source = "../../modules/kubernetes/anubis_instance" - name = "travel" - namespace = kubernetes_namespace.travel-blog.metadata[0].name - target_url = "http://${kubernetes_service.travel-blog.metadata[0].name}.${kubernetes_namespace.travel-blog.metadata[0].name}.svc.cluster.local" - shared_store_url = "redis://redis-master.redis.svc.cluster.local:6379/11" -} - -module "ingress" { - source = "../../modules/kubernetes/ingress_factory" - auth = "none" # Anubis-fronted; PoW challenge gates bots, no Authentik - namespace = kubernetes_namespace.travel-blog.metadata[0].name - name = "travel" - tls_secret_name = var.tls_secret_name - service_name = module.anubis.service_name - port = module.anubis.service_port - extra_middlewares = ["traefik-x402@kubernetescrd"] - anti_ai_scraping = false - extra_annotations = { - "gethomepage.dev/enabled" = "true" - "gethomepage.dev/name" = "Travel Blog" - "gethomepage.dev/description" = "Travel stories" - "gethomepage.dev/icon" = "ghost.png" - "gethomepage.dev/group" = "Other" - "gethomepage.dev/pod-selector" = "" - } -} - -# CI retrigger 2026-05-16T13:42:57+00:00 — bulk enrollment apply (pipeline #689 killed) -# CI retrigger v2 2026-05-16T13:46:35+00:00 - -# CI retrigger v3 2026-05-16T14:06:39Z - -# CI retrigger v4 2026-05-16T14:13:59Z - -# CI retrigger v5 2026-05-16T23:10:38Z - -# CI retrigger v6 2026-05-16T23:18:58Z diff --git a/stacks/travel_blog/providers.tf b/stacks/travel_blog/providers.tf deleted file mode 100644 index 012af700..00000000 --- a/stacks/travel_blog/providers.tf +++ /dev/null @@ -1,37 +0,0 @@ -# Generated by Terragrunt. Sig: nIlQXj57tbuaRZEa -terraform { - required_providers { - vault = { - source = "hashicorp/vault" - version = "~> 4.0" - } - cloudflare = { - source = "cloudflare/cloudflare" - version = "~> 4" - } - authentik = { - source = "goauthentik/authentik" - version = "~> 2024.10" - } - } -} - -variable "kube_config_path" { - type = string - default = "~/.kube/config" -} - -provider "kubernetes" { - config_path = var.kube_config_path -} - -provider "helm" { - kubernetes = { - config_path = var.kube_config_path - } -} - -provider "vault" { - address = "https://vault.viktorbarzin.me" - skip_child_token = true -} diff --git a/stacks/travel_blog/secrets b/stacks/travel_blog/secrets deleted file mode 120000 index ca54a7cf..00000000 --- a/stacks/travel_blog/secrets +++ /dev/null @@ -1 +0,0 @@ -../../secrets \ No newline at end of file diff --git a/stacks/travel_blog/terragrunt.hcl b/stacks/travel_blog/terragrunt.hcl deleted file mode 100644 index 0d1c8e53..00000000 --- a/stacks/travel_blog/terragrunt.hcl +++ /dev/null @@ -1,8 +0,0 @@ -include "root" { - path = find_in_parent_folders() -} - -dependency "platform" { - config_path = "../platform" - skip_outputs = true -}