infra/stacks/meshcentral/main.tf
Viktor Barzin cba79cde35 fix(meshcentral): disable certUrl when using TLSOffload
MeshCentral was failing to start with "Zipencryptionmodule failed" error
because the service tried to fetch TLS certificates from an HTTPS endpoint
during bootstrap. When using TLSOffload (reverse proxy terminating TLS),
MeshCentral should not attempt to load certificates.

Root cause: The existing config.json had "certUrl" set to HTTPS, causing
MeshCentral to try fetching the certificate during startup. Since the pod
was bootstrapping, this failed and cascaded into the Zipencryptionmodule
failure.

Fix: Add init container that runs before the main container to disable
the certUrl by prefixing it with underscore (MeshCentral's convention for
disabled settings). The sed command ensures the fix applies to both new
and existing config.json files.

This ensures MeshCentral behaves correctly with TLSOffload enabled:
- Runs in plain HTTP mode on port 443
- Traefik/Ingress handles HTTPS termination
- No certificate bootstrap failures
2026-04-06 13:22:59 +03:00

239 lines
5.9 KiB
HCL

variable "tls_secret_name" {
type = string
sensitive = true
}
variable "nfs_server" { type = string }
resource "kubernetes_namespace" "meshcentral" {
metadata {
name = "meshcentral"
labels = {
"istio-injection" : "disabled"
tier = local.tiers.aux
}
}
}
module "tls_secret" {
source = "../../modules/kubernetes/setup_tls_secret"
namespace = kubernetes_namespace.meshcentral.metadata[0].name
tls_secret_name = var.tls_secret_name
}
resource "kubernetes_persistent_volume_claim" "data_proxmox" {
wait_until_bound = false
metadata {
name = "meshcentral-data-proxmox"
namespace = kubernetes_namespace.meshcentral.metadata[0].name
annotations = {
"resize.topolvm.io/threshold" = "80%"
"resize.topolvm.io/increase" = "100%"
"resize.topolvm.io/storage_limit" = "5Gi"
}
}
spec {
access_modes = ["ReadWriteOnce"]
storage_class_name = "proxmox-lvm"
resources {
requests = {
storage = "1Gi"
}
}
}
}
resource "kubernetes_persistent_volume_claim" "files_proxmox" {
wait_until_bound = false
metadata {
name = "meshcentral-files-proxmox"
namespace = kubernetes_namespace.meshcentral.metadata[0].name
annotations = {
"resize.topolvm.io/threshold" = "80%"
"resize.topolvm.io/increase" = "100%"
"resize.topolvm.io/storage_limit" = "5Gi"
}
}
spec {
access_modes = ["ReadWriteOnce"]
storage_class_name = "proxmox-lvm"
resources {
requests = {
storage = "1Gi"
}
}
}
}
module "nfs_backups" {
source = "../../modules/kubernetes/nfs_volume"
name = "meshcentral-backups"
namespace = kubernetes_namespace.meshcentral.metadata[0].name
nfs_server = var.nfs_server
nfs_path = "/mnt/main/meshcentral/meshcentral-backups"
}
resource "kubernetes_deployment" "meshcentral" {
metadata {
name = "meshcentral"
namespace = kubernetes_namespace.meshcentral.metadata[0].name
labels = {
app = "meshcentral"
tier = local.tiers.aux
}
annotations = {
"reloader.stakater.com/search" = "true"
"meshcentral.enable" = "true"
}
}
spec {
replicas = 1
strategy {
type = "Recreate"
}
selector {
match_labels = {
app = "meshcentral"
}
}
template {
metadata {
labels = {
app = "meshcentral"
}
annotations = {
"diun.enable" = "true"
"diun.include_tags" = "^\\d+(?:\\.\\d+)?(?:\\.\\d+)?$,latest"
}
}
spec {
init_container {
name = "fix-config"
image = "alpine:latest"
image_pull_policy = "IfNotPresent"
command = ["/bin/sh"]
args = ["-c", <<-EOT
if [ -f /opt/meshcentral/meshcentral-data/config.json ]; then
# Replace "certUrl" with "_certUrl" to disable it when using TLSOffload
sed -i 's/"certUrl":/"_certUrl":/g' /opt/meshcentral/meshcentral-data/config.json
fi
EOT
]
volume_mount {
name = "data"
mount_path = "/opt/meshcentral/meshcentral-data"
}
}
container {
image = "typhonragewind/meshcentral:latest"
name = "meshcentral"
port {
name = "http"
container_port = 443
}
env {
name = "TZ"
value = "Europe/Sofia"
}
env {
name = "HOSTNAME"
value = "meshcentral.viktorbarzin.me"
}
env {
name = "REVERSE_PROXY"
value = "true"
}
env {
name = "ALLOW_NEW_ACCOUNTS"
value = "false"
}
env {
name = "WEBRTC"
value = "false"
}
volume_mount {
name = "data"
mount_path = "/opt/meshcentral/meshcentral-data"
}
volume_mount {
name = "files"
mount_path = "/opt/meshcentral/meshcentral-files"
}
resources {
requests = {
cpu = "15m"
memory = "256Mi"
}
limits = {
memory = "256Mi"
}
}
volume_mount {
name = "backups"
mount_path = "/opt/meshcentral/meshcentral-backups"
}
}
volume {
name = "data"
persistent_volume_claim {
claim_name = kubernetes_persistent_volume_claim.data_proxmox.metadata[0].name
}
}
volume {
name = "files"
persistent_volume_claim {
claim_name = kubernetes_persistent_volume_claim.files_proxmox.metadata[0].name
}
}
volume {
name = "backups"
persistent_volume_claim {
claim_name = module.nfs_backups.claim_name
}
}
}
}
}
}
resource "kubernetes_service" "meshcentral" {
metadata {
name = "meshcentral"
namespace = kubernetes_namespace.meshcentral.metadata[0].name
labels = {
"app" = "meshcentral"
}
}
spec {
selector = {
app = "meshcentral"
}
port {
name = "http"
port = 443
protocol = "TCP"
}
}
}
module "ingress" {
source = "../../modules/kubernetes/ingress_factory"
namespace = kubernetes_namespace.meshcentral.metadata[0].name
name = "meshcentral"
tls_secret_name = var.tls_secret_name
port = 443
protected = true
extra_annotations = {
"gethomepage.dev/enabled" = "true"
"gethomepage.dev/name" = "MeshCentral"
"gethomepage.dev/description" = "Remote management"
"gethomepage.dev/icon" = "meshcentral.png"
"gethomepage.dev/group" = "Infrastructure"
"gethomepage.dev/pod-selector" = ""
}
}