Week 1, Devops Notes and Lessons Learned
I'm still not entirely sure why I am building this beyond just seeing whether I can or not. Generally:
- I want to se how much these LLM tools can do.
- I want a better understanding of how one setups up and maintains a devops stack
- I have an itch to build something but I'm not entirely sure what.
Secrets, Security, and Gitops
- Gitleaks is useful as when initially starting to launch apps on kubernetes, the bot (and human) will usually leave passwords out in your yaml files.
- Telling the bot you want gitops and tools like ArgoCD would make you think that it would set up each app after ArgoCD to be deployed through a GitOps pattern. You would be wrong. So having multiple models review the implementation helped handle this.
- Sealing secrets in Kubernetes was new to me. In the beginning there was a mix of using Github secrets in addition to Bitnami Sealed Secrets in Kubernetes, but eventually
- Keycloak was reasonably quick to setup as the authentication service. I haven't setup 2FA or a full registraation process but it looks like all of those features are there.
Networking and access
I was dreading this the most but I got to say Tailscale and Cloudflare are awesome. Setting up VPN like service used to suck and now definitely doesn't. It is really when i can just immediately ssh from my ipad to home computers without having to slog through inevitable errors that used to occur.
In terms of setting up a domain, and a reverse proxy (Cloudflare Tunnel) to my home network, Cloudflare made the whole process relatively painless. Although Im still not sure what the difference between "Cloudflare" and "Cloudflare One" is.