Kubernetes CRD
Configuration stored in an RpduConfig custom resource instead of a ConfigMap. GUI Save patches the resource.
Enable
Helm:
kubernetesConfigSource:
enabled: true
Without Helm: Examples/Kubernetes/crd/ (crd.yaml, rbac.yaml, rpduconfig-sample.yaml, deployment.yaml). Installing the CRD needs cluster-admin once.
The app reads the resource when RPDU2MQTT_CONFIG_SOURCE=k8s and RPDU2MQTT_CR_NAME are set. See Environment variables.
Resource
apiVersion: rpdu2mqtt.xtremeownage.com/v1alpha1
kind: RpduConfig
metadata:
name: rpdu2mqtt
namespace: rpdu2mqtt
spec:
MQTT:
Connection: { Host: mqtt.example.com, Port: 1883 }
Pdus:
default:
Connection: { Host: rack-pdu-1.example.com, Port: 80 }
HomeAssistant:
DiscoveryEnabled: true
spechas the same shape asconfig.yaml. The CRD schema is generated from the config model.statusreportsconnected,deviceCount,lastPoll,message, andupdatewhen the operator runs.kubectl get rpduconfigshows them.
Secrets
- Never stored in
spec. The GUI writes credentials to a companion Secret named byRPDU2MQTT_SECRET_NAME(default: the CR name). - The chart creates the Secret once, mounts it as environment variables, and grants
get,patch,updateon it. - Without Helm, create the Secret, mount it and grant the same RBAC yourself.
Changes
- Changes to the resource apply live: MQTT broker and credentials, PDU pollers.
- Listen ports and GUI authentication (including OIDC) need a restart (Diagnostics › Restart).
- After a GUI save, the GUI reminds you to update your GitOps source. Export › RpduConfig manifest renders the resource with secrets redacted.
Upgrades and GitOps
| Tool | Keeps GUI edits with |
|---|---|
helm upgrade |
kubernetesConfigSource.preserveExisting: true (default). values.config seeds the resource on install only |
| Argo CD | ignoreDifferences plus RespectIgnoreDifferences=true. See Argo CD |
| Either | kubernetesConfigSource.manageResource: false. Create the resource once yourself; the chart does not render it |
Set preserveExisting: false to apply values.config on every upgrade.
The chart renders the CRD with the release (crds.enabled, default on), so the schema matches the app version.
RBAC
Namespaced Role: get, list, watch, patch on rpduconfigs; patch on rpduconfigs/status. With the operator: get, list, patch on apps/deployments, get, list on pods. Diagnostics pod logs and events: pods, pods/log, events.
Operator
Registry update checks and automatic updates with config.Operator.Enabled: true. See Updates and restarts.