blumeops/argocd/manifests/tailscale-operator
Erich Blume dbfe7365d8 Document that ArgoCD excludes Endpoints resources
ArgoCD's resource.exclusions in argocd-cm skips all Endpoints objects
(they're normally auto-managed by the control plane). The manual
forge-external Endpoints must be applied directly with kubectl.

Removed endpoints-forge.yaml from kustomization resources and added
comments in both files explaining the situation and the apply command.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-03 08:24:24 -08:00
..
endpoints-forge.yaml Document that ArgoCD excludes Endpoints resources 2026-03-03 08:24:24 -08:00
external-secret.yaml Switch all ExternalSecrets to creationPolicy: Owner 2026-01-28 20:27:16 -08:00
ingress-forge.yaml Add Tailscale Ingress for Forge via ExternalName Service 2026-03-03 07:51:28 -08:00
kustomization.yaml Document that ArgoCD excludes Endpoints resources 2026-03-03 08:24:24 -08:00
proxygroup-ingress.yaml Restrict flyio-proxy ACLs to dedicated tag:flyio-target endpoints (#126) 2026-02-08 21:54:18 -08:00
README.md Remove deprecated forge egress proxy from tailscale-operator 2026-03-03 06:56:33 -08:00
svc-forge-external.yaml Split Endpoints into separate file for kustomize discovery 2026-03-03 08:19:03 -08:00

Tailscale Kubernetes Operator

Manifests for the Tailscale Kubernetes Operator, managed via ArgoCD.

Source

Prerequisites

  1. OAuth client in Tailscale admin console with:
    • Devices: Core (Read & Write) - tag: tag:k8s-operator
    • Auth Keys: Read & Write
    • Services: Write
  2. ACL with tag:k8s-operator owning tag:k8s (so operator can tag resources it creates)

Manual Bootstrap (Before ArgoCD)

Tailscale operator must be deployed before ArgoCD since ArgoCD uses Tailscale for ingress.

# 1. Create namespace
kubectl create namespace tailscale

# 2. Apply OAuth secret (uses 1Password)
op inject -i argocd/manifests/tailscale-operator/secret.yaml.tpl | kubectl apply -f -

# 3. Apply manifests via kustomize
kubectl apply -k argocd/manifests/tailscale-operator/

Ongoing Management (After ArgoCD)

Once ArgoCD is running, the operator is managed by the tailscale-operator ArgoCD Application. ArgoCD pulls manifests from forge and applies them automatically.

ArgoCD CLI Commands

# Check application status
argocd app get tailscale-operator

# Trigger a sync (pull latest from forge and apply)
argocd app sync tailscale-operator

# Preview what would change without applying
argocd app diff tailscale-operator

# View deployment history
argocd app history tailscale-operator

# Hard refresh (clear cache and re-fetch from git)
argocd app get tailscale-operator --hard-refresh

Verification

# Check operator pod is running
kubectl get pods -n tailscale

# Check operator logs
kubectl logs -n tailscale -l app.kubernetes.io/name=operator

Files

File Description
kustomization.yaml Kustomize configuration for all manifests
operator.yaml Operator deployment, CRDs, RBAC (secret removed)
proxyclass.yaml ProxyClass with fully-qualified images
dnsconfig.yaml DNSConfig for cluster-to-tailnet name resolution
secret.yaml.tpl 1Password template for OAuth credentials (manual)
README.md This file

Notes

  • TODO: The OAuth secret (operator-oauth) is not managed by ArgoCD and must be applied manually. Future improvement: integrate with a secrets operator (e.g., External Secrets).
  • Services using the Tailscale LoadBalancer should reference the ProxyClass:
    annotations:
      tailscale.com/proxy-class: "default"