From 34660b12311338f647c1f9a92a46ebe4edb4cdb0 Mon Sep 17 00:00:00 2001 From: Valentin Haudiquet Date: Sun, 23 Aug 2026 10:43:07 +0200 Subject: [PATCH] openclaw: deploy openclaw on kube --- .github/dependabot.yml | 1 + kubernetes/kustomization.yaml | 2 ++ .../personal/openclaw/kustomization.yaml | 6 ++++ .../personal/openclaw/openclaw-instance.yaml | 30 ++++++++++++++++ .../personal/openclaw/openclaw-secrets.yaml | 35 +++++++++++++++++++ kubernetes/system/flux/kustomization.yaml | 2 ++ kubernetes/system/flux/openclaw-operator.yaml | 20 +++++++++++ kubernetes/system/flux/openclaw.yaml | 25 +++++++++++++ .../openclaw-operator/kustomization.yaml | 7 ++++ .../system/openclaw-operator/namespace.yaml | 4 +++ .../openclaw-operator/openclaw-namespace.yaml | 7 ++++ .../system/openclaw-operator/release.yaml | 25 +++++++++++++ .../system/openclaw-operator/repository.yaml | 9 +++++ 13 files changed, 173 insertions(+) create mode 100644 kubernetes/personal/openclaw/kustomization.yaml create mode 100644 kubernetes/personal/openclaw/openclaw-instance.yaml create mode 100644 kubernetes/personal/openclaw/openclaw-secrets.yaml create mode 100644 kubernetes/system/flux/openclaw-operator.yaml create mode 100644 kubernetes/system/flux/openclaw.yaml create mode 100644 kubernetes/system/openclaw-operator/kustomization.yaml create mode 100644 kubernetes/system/openclaw-operator/namespace.yaml create mode 100644 kubernetes/system/openclaw-operator/openclaw-namespace.yaml create mode 100644 kubernetes/system/openclaw-operator/release.yaml create mode 100644 kubernetes/system/openclaw-operator/repository.yaml diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 7bf8a66..a67aa09 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -65,6 +65,7 @@ updates: - "/kubernetes/system/csi-driver-nfs" - "/kubernetes/system/external-dns" - "/kubernetes/system/longhorn" + - "/kubernetes/system/openclaw-operator" - "/kubernetes/utilities/dashy" - "/kubernetes/utilities/glance" - "/kubernetes/utilities/open-webui" diff --git a/kubernetes/kustomization.yaml b/kubernetes/kustomization.yaml index cff9cf3..dad9c97 100644 --- a/kubernetes/kustomization.yaml +++ b/kubernetes/kustomization.yaml @@ -7,6 +7,8 @@ # - cert-manager-issuer: managed by Flux Kustomization (depends on cert-manager + webhook) # - caddy-certificates: managed by Flux Kustomization (Certificate CRDs need cert-manager) # - stalwart-certificates: managed by Flux Kustomization (Certificate CRDs need cert-manager) +# - openclaw-operator: managed by Flux Kustomization (operator CRDs must be installed first) +# - openclaw: managed by Flux Kustomization (OpenClawInstance CRD needs openclaw-operator) apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: diff --git a/kubernetes/personal/openclaw/kustomization.yaml b/kubernetes/personal/openclaw/kustomization.yaml new file mode 100644 index 0000000..e9257fe --- /dev/null +++ b/kubernetes/personal/openclaw/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: openclaw +resources: + - openclaw-instance.yaml + - openclaw-secrets.yaml diff --git a/kubernetes/personal/openclaw/openclaw-instance.yaml b/kubernetes/personal/openclaw/openclaw-instance.yaml new file mode 100644 index 0000000..61cba3c --- /dev/null +++ b/kubernetes/personal/openclaw/openclaw-instance.yaml @@ -0,0 +1,30 @@ +apiVersion: openclaw.rocks/v1alpha1 +kind: OpenClawInstance +metadata: + name: openclaw +spec: + # Provider API keys come from the SOPS-encrypted Secret below. + # The gateway token is auto-generated by the operator (no mDNS pairing in k8s). + envFrom: + - secretRef: + name: openclaw-api-keys + storage: + persistence: + enabled: true + size: 10Gi + storageClass: longhorn + networking: + ingress: + enabled: true + className: traefik + hosts: + - host: openclaw.lan + annotations: + external-dns.alpha.kubernetes.io/enabled: "true" + resources: + requests: + cpu: 250m + memory: 512Mi + limits: + cpu: "2" + memory: 4Gi diff --git a/kubernetes/personal/openclaw/openclaw-secrets.yaml b/kubernetes/personal/openclaw/openclaw-secrets.yaml new file mode 100644 index 0000000..b02bf64 --- /dev/null +++ b/kubernetes/personal/openclaw/openclaw-secrets.yaml @@ -0,0 +1,35 @@ +# Provider API keys for the OpenClaw instance. +apiVersion: v1 +kind: Secret +metadata: + name: openclaw-api-keys + namespace: openclaw +type: Opaque +stringData: + CHUTES_API_KEY: ENC[AES256_GCM,data:yEvvMJI+FDrexqA3In9cRJrzF98Iya8LgTat+EAykn+I5vdEmhdozfesZ6ROyhwNfHYVjKXDegtSZhGhZ/unhqUHb0w/EIOEYe172HLZsnACYAgQ+RioXsYTO1TtFfNJRTCCzVKg,iv:gPFQkjeL+BWksziHminWeD19PoJQK3gk0tFpTvmMazU=,tag:m4qrl/TufcKdqPSG7OxKUQ==,type:str] +sops: + lastmodified: "2026-08-23T08:43:07Z" + mac: ENC[AES256_GCM,data:7sddfyesPNXDr2c937J3BSxZk16Dm02BLCvHcVTjPReOJSbkG4dNVuEKM4ThWvXG2tKJkYKwCDQbOvLDXBd6ksZebJ3vVSMna6ijURTiUtWf+Gz8rFJUoTSSEb9p42nV0ki1E3azgmkydJJFA8RvnmB7nmSJe423d4fGEcJi5Zs=,iv:Z1I3zzsP/3iCn64nH1LdNKaac2e5oKAWSRO0lWN99HA=,tag:sBMHlhqFDtHWC210cYEfDg==,type:str] + pgp: + - created_at: "2026-08-23T08:43:07Z" + enc: |- + -----BEGIN PGP MESSAGE----- + + hQIMA7uy4qQr71wiARAAvlqjsVlnBSmoIfovSFZgNWvIbwbtYW7fpBcO6xUqtacs + lNS3tXElKiwpyj8Y6laePIoRzmah3H7qJGcK1JtEcL6EPYUw5HoVMgvn6wyiIdvx + 0djAeOVsvU9VAxjsC5pwMGoFdMzLvFe2nSjRkggAf4rblYlFD0cCOqNLAHZyhjED + 8DCC4hP7i15zcqwgdZ2fLTgYufJqefZcpLPmThp9ZTEqrVts8ieX9t+3IxlkznHo + FxP8gM9Hz+T9u/iWbshPRNZZYihaNIN/jsgWIMN8EZlJjS6B1z49pkNR/K0tmLwB + NUYcYqADyEJO+2mb4WsKh3Ljb7Bl7ki+0IgC6cIoHQ4U65+yUD3R9Hgx7QQd49Oq + +VoDV2K9R6zjbUTG+IuSBiAFZ8IgLp54ejUBtY3vPbVsz+xBW1OinFPw3uYbclJe + M5SRNq3VzqiQNn0CGVxt2DlMGIIrQtuyiMpWeucakfJNhTzESiwrTfGT8mSzor+A + XGfV9vwO4LgdiLk5vw3k03WMGfFQHZdRmg3wghQn7GWpfCI1mZZUvzyXAfmKmYbJ + EB+sgTctkb1+evGcpP9XOMvcdz5CUWkdv7pyDTJyyVA4cIiG+1nyHGDAqQW2hNCJ + rojj3R6NTjLyaEYXAlNc81dkVA3vT1fhjoMgLvcRx70Ytm9Qz0yyemTCYLfEeFjS + XgHzlwuM4zSITkJio00+8AqfKX/OWZKbKNqnuwMuFoX+PSNOHiWsywMuEskfFfni + HsvvQnmpFi2d7mr8bhNFdraeWnF4D/jJlpsNrnNDgYYVU6Ejv6GBH25FEpIDhQU= + =EAhW + -----END PGP MESSAGE----- + fp: DC6910268E657FF70BA7EC289974494E76938DDC + encrypted_regex: ^(data|stringData|.*key|.*crt)$ + version: 3.10.2 diff --git a/kubernetes/system/flux/kustomization.yaml b/kubernetes/system/flux/kustomization.yaml index 4c01c66..c7842b6 100644 --- a/kubernetes/system/flux/kustomization.yaml +++ b/kubernetes/system/flux/kustomization.yaml @@ -11,3 +11,5 @@ resources: - stalwart-certificates.yaml - longhorn.yaml - longhorn-jobs.yaml + - openclaw-operator.yaml + - openclaw.yaml diff --git a/kubernetes/system/flux/openclaw-operator.yaml b/kubernetes/system/flux/openclaw-operator.yaml new file mode 100644 index 0000000..cfcddcb --- /dev/null +++ b/kubernetes/system/flux/openclaw-operator.yaml @@ -0,0 +1,20 @@ +# Flux Kustomization for the OpenClaw operator +# Separate from main homeprod because the operator's CRDs must be installed +# before OpenClawInstance resources can be applied +apiVersion: kustomize.toolkit.fluxcd.io/v1 +kind: Kustomization +metadata: + name: openclaw-operator + namespace: flux-system +spec: + interval: 10m + prune: true + sourceRef: + kind: GitRepository + name: homeprod + path: ./kubernetes/system/openclaw-operator + healthChecks: + - apiVersion: apps/v1 + kind: Deployment + name: openclaw-operator + namespace: openclaw-operator-system diff --git a/kubernetes/system/flux/openclaw.yaml b/kubernetes/system/flux/openclaw.yaml new file mode 100644 index 0000000..dd268bd --- /dev/null +++ b/kubernetes/system/flux/openclaw.yaml @@ -0,0 +1,25 @@ +# Flux Kustomization for the OpenClaw instance +# Depends on the openclaw-operator so its CRDs exist before applying +apiVersion: kustomize.toolkit.fluxcd.io/v1 +kind: Kustomization +metadata: + name: openclaw + namespace: flux-system +spec: + interval: 10m + prune: true + dependsOn: + - name: openclaw-operator + sourceRef: + kind: GitRepository + name: homeprod + path: ./kubernetes/personal/openclaw + decryption: + provider: sops + secretRef: + name: flux-sops + healthChecks: + - apiVersion: apps/v1 + kind: StatefulSet + name: openclaw + namespace: openclaw diff --git a/kubernetes/system/openclaw-operator/kustomization.yaml b/kubernetes/system/openclaw-operator/kustomization.yaml new file mode 100644 index 0000000..d60cf1c --- /dev/null +++ b/kubernetes/system/openclaw-operator/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - namespace.yaml + - openclaw-namespace.yaml + - repository.yaml + - release.yaml diff --git a/kubernetes/system/openclaw-operator/namespace.yaml b/kubernetes/system/openclaw-operator/namespace.yaml new file mode 100644 index 0000000..ced9bd3 --- /dev/null +++ b/kubernetes/system/openclaw-operator/namespace.yaml @@ -0,0 +1,4 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: openclaw-operator-system diff --git a/kubernetes/system/openclaw-operator/openclaw-namespace.yaml b/kubernetes/system/openclaw-operator/openclaw-namespace.yaml new file mode 100644 index 0000000..9d47a57 --- /dev/null +++ b/kubernetes/system/openclaw-operator/openclaw-namespace.yaml @@ -0,0 +1,7 @@ +# Namespace watched by the operator for OpenClawInstance resources. +# Must exist before the operator deploys: watchNamespaces renders namespaced +# Role/RoleBinding into it and the chart does not create namespaces. +apiVersion: v1 +kind: Namespace +metadata: + name: openclaw diff --git a/kubernetes/system/openclaw-operator/release.yaml b/kubernetes/system/openclaw-operator/release.yaml new file mode 100644 index 0000000..f38f32d --- /dev/null +++ b/kubernetes/system/openclaw-operator/release.yaml @@ -0,0 +1,25 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: openclaw-operator + namespace: openclaw-operator-system +spec: + interval: 1m + chart: + spec: + chart: openclaw-operator + version: "0.39.0" + sourceRef: + kind: HelmRepository + name: openclaw-operator + namespace: openclaw-operator-system + interval: 1m + values: + # Scope the operator's watches and RBAC to the openclaw namespace only + # (renders Role/RoleBinding instead of cluster-wide ClusterRole). + watchNamespaces: + - openclaw + metrics: + serviceMonitor: + # No Prometheus Operator CRDs in this cluster (VictoriaMetrics stack). + enabled: false diff --git a/kubernetes/system/openclaw-operator/repository.yaml b/kubernetes/system/openclaw-operator/repository.yaml new file mode 100644 index 0000000..84377d6 --- /dev/null +++ b/kubernetes/system/openclaw-operator/repository.yaml @@ -0,0 +1,9 @@ +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository +metadata: + name: openclaw-operator + namespace: openclaw-operator-system +spec: + type: oci + interval: 1h + url: oci://ghcr.io/paperclipinc/charts