Configuration values¶
Redirecting alpstack to your domain, cluster and cloud is largely a matter of setting a
handful of values in values/global.yaml — the file every ArgoCD Application
already includes as a value source — rather than editing dozens of charts.
What's a global, and what isn't
cluster.name, cluster.rootCA, dns.baseDomain, dns.appsDomain, realm,
git.* and notifications.adminEmail are driven from values/global.yaml across all
three GitOps repos — set them and the whole domain / realm / CA surface follows. What's
left to touch is only genuinely per-site facts (IPs, NodePorts, S3 buckets); see
what you still edit by hand.
The global.yaml you set¶
Each repo's values/global.yaml carries the keys that repo actually consumes:
global:
# ArgoCD wiring
sourceRepo:
url: https://codeberg.org/<you>/platform-argocd.git
revision: main
server: https://kubernetes.default.svc
namePrefix: platform # platform | addons | opendesk (per repo)
# Cluster identity. The cert-manager CA + ClusterIssuer derive from this as
# <name>-ca / <name>-issuer; it's also the clusters/<name>/ overlay dir name.
cluster:
name: mycluster # example: coeurli
# The cluster's own internal root CA (PEM). Trusted by workloads that must reach
# internally-issued TLS — ArgoCD's Dex OIDC, headlamp. One copy for every consumer.
rootCA: |
-----BEGIN CERTIFICATE-----
...your cluster CA...
-----END CERTIFICATE-----
# DNS. baseDomain = the public apex; appsDomain = the internal wildcard for
# the platform's own admin UIs.
dns:
baseDomain: example.com # example: coeur.li
appsDomain: apps.int.example.com # example: apps.int.coeur.li
# Keycloak realm slug backing SSO (addons + openDesk). Every OIDC issuer is
# https://id.<dns.baseDomain>/realms/<realm>. (addons-argocd)
realm: opendesk
# Git host for Renovate + the cluster-digest bot (platform-argocd only)
git:
owner: <you> # example: alpstack
platform: forgejo # forgejo | github | gitlab
endpoint: https://codeberg.org
# Notifications — ACME registration email + digest recipient (platform-argocd only)
notifications:
adminEmail: admin@example.com # example: admin@coeur.li
# Backup object storage — the shared S3-compatible provider host + region every backup
# track uses. Bare host; consumers that need a URL prepend the scheme. (all repos)
backup:
s3:
endpoint: s3.example.com # example: sos-ch-dk-2.exo.io
region: your-region # example: ch-dk-2
What each global controls¶
| Value | Controls | Repos |
|---|---|---|
sourceRepo.* / server / namePrefix |
ArgoCD repo + deploy wiring | all |
cluster.name |
VMRule name prefixes + cluster-digest report (platform); the cert-manager <name>-ca / <name>-issuer, internal-gateway, garage S3 Ingress issuer; each ArgoCD instance's <name>-argocd UI domain |
platform, opendesk, addons |
cluster.rootCA |
the CA cert ArgoCD's Dex OIDC (oidc.config rootCA) and headlamp's CA mount trust — one copy for every consumer |
platform, opendesk, addons |
dns.baseDomain |
the whole openDesk public cert-SAN set (21 hosts), netbird/vaultwarden certs, the NetBird DNS-zone, garage's S3 host, coturn realm + dnsName |
opendesk, addons |
dns.appsDomain |
internal HTTPRoutes, the internal-gateway wildcard, ops-proxy (11 hosts + its OIDC config), imapsync, each ArgoCD Dex issuer + oauth2-proxy/grafana/headlamp OIDC | platform, opendesk, addons |
realm |
the Keycloak realm slug in every OIDC issuer URL — https://id.<baseDomain>/realms/<realm> (netbird, vaultwarden) |
addons |
git.owner / platform / endpoint |
Renovate repo list + cluster-digest API / issue repo | platform |
notifications.adminEmail |
cert-manager ACME registration + cluster-digest recipient + Alertmanager to |
platform |
backup.s3.endpoint / region |
the S3 endpoint + region for every backup track — longhorn, garage, postgres, mariadb, vaultwarden (per-store bucket names stay per-chart) | all |
The templates read global.<key> directly (or, for values Helm can't template in a
subchart values.yaml, via the app-of-apps Application's inline helm.values), so
setting any of these in values/global.yaml redirects every chart that references it.
What you still edit by hand¶
Only genuinely per-site facts need a manual edit; the domain / realm / CA surface is entirely global-driven.
Subchart values are global-driven too
Some domain / realm / CA values are consumed by an upstream subchart's static
values.yaml, which Helm never templates. They come from global.yaml through the
app-of-apps Application's inline helm.values string, so they need no manual edit
either. Each such key carries a # [set-in-template] breadcrumb in the chart's
values.yaml pointing back to global.yaml.
Genuinely per-site facts (no shared default exists)¶
- Physical network — LAN/WAN CIDRs, the LB IP pool, HAProxy publish IPs, etcd scrape targets, and the NodePort contract.
- NetBird
management.configinaddons-argocd— the pinned ClusterIPs, hand-rolled EndpointSlices and server-assigned Network UUID (danger note), plus the OIDC issuer URLs embedded in the same per-site JSON blob. Re-pin / re-set per cluster. - Backup S3 buckets — the per-store bucket names (postgres / mariadb / garage /
longhorn / vaultwarden). Set per chart; the shared endpoint + region are
global.backup.s3.*. - The openDesk application content (13 DB/user names, the realm, Matrix
server_name) — entwined with the upstream render; change via the render inputs. - Secrets — never in values at all; see Secrets.
Next: Secrets →