Compare commits
76
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6e88f2d3d9 | ||
|
|
fa2504d6a8 | ||
|
|
b0cb2bd03c | ||
|
|
00d6808f34 | ||
|
|
611c0e61cb | ||
|
|
400846fba6 | ||
|
|
4d41238932 | ||
|
|
2411a5c447 | ||
|
|
52df4409e1 | ||
|
|
6006113dd5 | ||
|
|
388bb5a8e3 | ||
|
|
1203966e82 | ||
|
|
48fedbd8fd | ||
|
|
68a7bd7a49 | ||
|
|
9732384a8a | ||
|
|
eaecc92958 | ||
|
|
4ed9cb8ee7 | ||
|
|
75854ef7f5 | ||
|
|
6f7784defd | ||
|
|
a02116be71 | ||
|
|
601180e53a | ||
|
|
420025db26 | ||
|
|
c5f5b4faa3 | ||
|
|
1b7d1aa23a | ||
|
|
a7cda8f0dc | ||
|
|
67cf4c3278 | ||
|
|
06f2ebd169 | ||
|
|
2d47062519 | ||
|
|
389d5fdff5 | ||
|
|
a83b2961ab | ||
|
|
f90710071f | ||
|
|
b54e0f2912 | ||
|
|
a223f41f68 | ||
|
|
b7043778d4 | ||
|
|
e3d0cb7066 | ||
|
|
f719a59bbb | ||
|
|
74fc958ac5 | ||
|
|
e317e8d63c | ||
|
|
5fcb7ee681 | ||
|
|
e0eba1bfdc | ||
|
|
e485f136d5 | ||
|
|
d6763b043d | ||
|
|
e1f2e1b704 | ||
|
|
2d6dcdb9ac | ||
|
|
247601d9a3 | ||
|
|
f192b6d000 | ||
|
|
736722a4b1 | ||
|
|
98088724e0 | ||
|
|
6f27b82367 | ||
|
|
19c94cf471 | ||
|
|
060f0f6b8f | ||
|
|
82ae7508ff | ||
|
|
103e8e8c88 | ||
|
|
ac60b2994d | ||
|
|
84ba1b3d6f | ||
|
|
f2e29969a1 | ||
|
|
be00413b8d | ||
|
|
51acbbd54f | ||
|
|
e26801182d | ||
|
|
f487f5d23e | ||
|
|
3882fe6ccc | ||
|
|
e962dd22a0 | ||
|
|
96dc9e9334 | ||
|
|
23a072ddb6 | ||
|
|
11857cfe35 | ||
|
|
7027e07b8c | ||
|
|
5194d9fea2 | ||
|
|
f69d1a79e7 | ||
|
|
50b3daa95d | ||
|
|
68ec6c23f6 | ||
|
|
1af0f807dd | ||
|
|
5cdb393c1d | ||
|
|
1fcf8af0fd | ||
|
|
15d349a8f6 | ||
|
|
f91e95b231 | ||
|
|
c77439819f |
@@ -1,5 +1,7 @@
|
||||
# GitOps repository
|
||||
|
||||
## Hypervisor
|
||||
|
||||
### 1) Harvester Hyperconverged Infrastructure
|
||||
[...]
|
||||
|
||||
@@ -7,6 +9,180 @@ Configure Harvester HCI nodes through cloud-init (requires node reboot):
|
||||
```shell
|
||||
kubectl apply -f system/Harvester/cloudinit-disable-nic-offloading.yaml
|
||||
```
|
||||
## Downstream cluster(s)
|
||||
|
||||
Cluster configuration for RKE2 cluster using kube-vip with Traefik ingress controller:
|
||||
```yaml
|
||||
apiVersion: provisioning.cattle.io/v1
|
||||
kind: Cluster
|
||||
spec:
|
||||
[...]
|
||||
rkeConfig:
|
||||
chartValues:
|
||||
harvester-cloud-provider:
|
||||
[...]
|
||||
kube-vip:
|
||||
env:
|
||||
svc_election: 'true'
|
||||
[...]
|
||||
rke2-traefik:
|
||||
service:
|
||||
[...]
|
||||
spec:
|
||||
externalTrafficPolicy: Local
|
||||
```
|
||||
|
||||
Traefik advanced configuration:
|
||||
```yaml
|
||||
additionalArguments:
|
||||
- --providers.file.directory=/etc/traefik/dynamic
|
||||
- --providers.file.watch=true
|
||||
- --entryPoints.websecure.transport.respondingTimeouts.readTimeout=300s
|
||||
certificatesResolvers:
|
||||
default:
|
||||
acme:
|
||||
dnsChallenge:
|
||||
propagation:
|
||||
delayBeforeChecks: 5m0s
|
||||
provider: cloudflare
|
||||
resolvers:
|
||||
- 1.1.1.1:53
|
||||
- 1.0.0.1:53
|
||||
email: <omitted>
|
||||
storage: /data/acme.json
|
||||
deployment:
|
||||
initContainers:
|
||||
- command:
|
||||
- sh
|
||||
- -c
|
||||
- touch /data/acme.json; chown 65532 /data/acme.json; chmod -v 600 /data/acme.json
|
||||
image: busybox:latest
|
||||
name: volume-permissions
|
||||
securityContext:
|
||||
runAsGroup: 0
|
||||
runAsNonRoot: false
|
||||
runAsUser: 0
|
||||
volumeMounts:
|
||||
- mountPath: /data
|
||||
name: traefik-data
|
||||
kind: Deployment
|
||||
env:
|
||||
- name: CF_API_EMAIL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: CF_API_EMAIL
|
||||
name: traefik-cloudflare
|
||||
- name: CF_API_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: CF_API_KEY
|
||||
name: traefik-cloudflare
|
||||
extraObjects:
|
||||
- apiVersion: v1
|
||||
data:
|
||||
config.yml: |
|
||||
http:
|
||||
middlewares:
|
||||
2fa-authentication:
|
||||
forwardAuth:
|
||||
address: "https://auth.spamasaurus.com/api/verify?rd=https://auth.spamasaurus.com/"
|
||||
trustForwardHeader: true
|
||||
security-headers:
|
||||
headers:
|
||||
forceSTSHeader: true
|
||||
stsSeconds: 315360000
|
||||
stsIncludeSubdomains: true
|
||||
stsPreload: true
|
||||
tls:
|
||||
options:
|
||||
defaults:
|
||||
minVersion: VersionTLS12
|
||||
sniStrict: false
|
||||
curvePreferences:
|
||||
- secp521r1
|
||||
- secp384r1
|
||||
- secp256r1
|
||||
cipherSuites:
|
||||
- TLS_AES_128_GCM_SHA256
|
||||
- TLS_AES_256_GCM_SHA384
|
||||
- TLS_CHACHA20_POLY1305_SHA256
|
||||
- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
|
||||
- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
|
||||
- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
|
||||
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
|
||||
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
|
||||
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305
|
||||
- TLS_FALLBACK_SCSV
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: traefik-file-provider
|
||||
namespace: kube-system
|
||||
ingressRoute:
|
||||
dashboard:
|
||||
enabled: true
|
||||
entryPoints:
|
||||
- websecure
|
||||
matchRule: Host(`ingress.lab.spamasaurus.com`)
|
||||
middlewares:
|
||||
- name: 2fa-authentication@file
|
||||
- name: security-headers@file
|
||||
logs:
|
||||
general:
|
||||
level: INFO
|
||||
persistence:
|
||||
enabled: true
|
||||
name: traefik-data
|
||||
ports:
|
||||
web:
|
||||
http:
|
||||
redirections:
|
||||
entryPoint:
|
||||
permanent: true
|
||||
scheme: https
|
||||
to: websecure
|
||||
websecure:
|
||||
forwardedHeaders:
|
||||
insecure: true
|
||||
http:
|
||||
tls:
|
||||
certResolver: default
|
||||
domains:
|
||||
- main: '*.pvr.spamasaurus.com'
|
||||
- main: '*.lab.spamasaurus.com'
|
||||
- main: '*.spamasaurus.com'
|
||||
sans:
|
||||
- spamasaurus.com
|
||||
- main: '*.bessems.com'
|
||||
sans:
|
||||
- bessems.com
|
||||
- main: '*.bessems.eu'
|
||||
sans:
|
||||
- bessems.eu
|
||||
- main: '*.gabaldon.eu'
|
||||
sans:
|
||||
- gabaldon.eu
|
||||
- main: '*.gabaldon.nl'
|
||||
sans:
|
||||
- gabaldon.nl
|
||||
- main: '*.itch.fyi'
|
||||
sans:
|
||||
- itch.fyi
|
||||
options: defaults@file
|
||||
providers:
|
||||
kubernetesCRD:
|
||||
ingressClass: ""
|
||||
service:
|
||||
annotations:
|
||||
cloudprovider.harvesterhci.io/ip-pool: <ippoolname>
|
||||
cloudprovider.harvesterhci.io/ipam: pool
|
||||
spec:
|
||||
externalTrafficPolicy: Local
|
||||
type: LoadBalancer
|
||||
volumes:
|
||||
- mountPath: /etc/traefik/dynamic
|
||||
name: traefik-file-provider
|
||||
type: configMap
|
||||
```
|
||||
|
||||
### 2) Persistent storage
|
||||
|
||||
@@ -48,6 +224,12 @@ Retrieve public/private keys (*store these on a **secure** location!*):
|
||||
kubectl get secret -n kube-system -l sealedsecrets.bitnami.com/sealed-secrets-key -o yaml > BitnamiSealedSecrets.masterkey.yml
|
||||
```
|
||||
|
||||
Restoring public/private keys:
|
||||
```shell
|
||||
kubectl apply -f BitnamiSealedSecrets.masterkey.yml
|
||||
kubectl rollout restart deployment -n kube-system sealed-secrets-controller
|
||||
```
|
||||
|
||||
### 5) Services
|
||||
##### 5.1) [Gitea](https://gitea.io/) <small>(git repository)</small>
|
||||
*Required for all other workloads*
|
||||
|
||||
@@ -1,38 +0,0 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: argus
|
||||
namespace: argus
|
||||
labels:
|
||||
app: argus
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: argus
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: argus
|
||||
spec:
|
||||
serviceAccountName: argus
|
||||
containers:
|
||||
- name: argus
|
||||
image: releaseargus/argus:0.21.0
|
||||
args:
|
||||
- -config.file=/app/config/config.yml
|
||||
ports:
|
||||
- name: web
|
||||
containerPort: 8080
|
||||
volumeMounts:
|
||||
- name: csismb-argus-config
|
||||
mountPath: /app/config
|
||||
- name: csismb-argus-data
|
||||
mountPath: /app/data
|
||||
volumes:
|
||||
- name: csismb-argus-config
|
||||
persistentVolumeClaim:
|
||||
claimName: csismb-argus-config
|
||||
- name: csismb-argus-data
|
||||
persistentVolumeClaim:
|
||||
claimName: csismb-argus-data
|
||||
@@ -1,16 +0,0 @@
|
||||
apiVersion: bitnami.com/v1alpha1
|
||||
kind: SealedSecret
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
name: smb-credentials
|
||||
namespace: argus
|
||||
spec:
|
||||
encryptedData:
|
||||
password: AgB8gU7Lj+Pn5B/oC8HtyKnKUzSvB7NRvxJOC2UmKjt3hj3pcRmfKrEh2khkcfSksb6x3f4ttIxYV2uFsXJfL4Wvi6zhsgvfgUHT12oD1/fuxD0LvHCm9otlGp8yyiQu5mPrFBdsGJswreBY53sD0UUdgu2riAlX0ESm+xKhzDJ6eSM8/Iz9Dq4GIhivLZ3OcZJw9hbgbelICIgvuxJZ3bWLfakPdeNDQUoayZuG3Z4GW0KPiqOMyaWz1/rljMHFaZHnFaszgKobwzPihsWWAnXEWmn54fwVBqfe/jNIo8CBvjlZGnMzinaS5lKTHObEVIG+F0XRI5VNFPa89NbsGKN71HJMFYU729lzdl58yy6B/5K789JRtxWUi/8I/7H8kLZWzUhUOqAcmLpVHKWnkH0Ub4MLtDyAaTJam5HqTtsvPDMW3+njiC+8vxC3n0X7q7pzAQQzM5JPZ7G/On6irFKe4LryfrphHiCB/gyJlLpBMXUqKJ4MvzUQU8G8e8W3OLMbtPl0O6oFuFxD8bUA4gdkoPO04bxlLvRmxlmavkbA0vFi60L6eyIOq5yzxvuEd7tzyD7SEO49hb8zW/LS/+H/PE/fCVT6crn+UbNOhgyaHR8pxlNpy6Z4PAti3mG8ZOtKVD0mx6fm8BCPHfWVFyC5YO6kNI285o4uuqsQI+SSZ+zkxwlFwvLcp1RdfJZFLUNyrQm3mlvMUY9xjZANlCHZ
|
||||
username: AgB67La0V5HRLzZ1RqR0Y0nufYKq3z0SK/go4AQ0aaZwQEE/mIy0c6xhdkwup7ava4PzTyOavEEQoluhojOcrVTz9qKUHoMQHcnhS3NagBc/QCeA+2rL15qw9ZUn5+sSU4OhM3UNCTy2jF1kMoXr2cdCi9pALRdAXPLhrccPoaItmWkA4bMRIe3on78BQUOlhF+zJjcMciPlDo+9ywY8ArShMHj5YlRgWQ6uOJmIH5FFp2BcXKP5d0gALoVQ4/Ek4zIkk4YubtO1C0sqfbvkTW+oxeymUSLd2PddGyF18iohfrgje6PQAvvtkDBX2hUuVcp8h2oFj2JkeZld4neOYpDFbdKwe1aGep24GxbYIt24j+iFfs8txqXhQQsHJWJmwHNB2798gPvjIxPC+G90V4/drsjr7KiAgdWKUaqU5JMDVo2HTSplyWpS1LZIGQmloafWiAXvTWQVIEg2044TXQIq2X7k3npbHU/KcWmlMqR1546QawsZAnohWaOIskqEBkG7nXx/eeYk7LVppP2TqdRtt+VfuvptXgfFhkOB2wUSOwqWH7OkQu/k3jtPR0FVJni+Hc1/+fKfuStwvEX+/1bdjZuS8DUGelOb1d/pXrHw+KypfzXcOoDaO31hJMQOEalXZc2GNJleAvLAxv34s8fFWKWvnEXqwYIaNwRPvX64GtencJwyFo/rdO/HH7gVIhA2DCDQwB0=
|
||||
template:
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
name: smb-credentials
|
||||
namespace: argus
|
||||
type: Opaque
|
||||
@@ -1,7 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: argus
|
||||
namespace: argus
|
||||
labels:
|
||||
app: argus
|
||||
@@ -28,4 +28,4 @@ spec:
|
||||
subDir: ddclient/config
|
||||
nodeStageSecretRef:
|
||||
name: smb-credentials
|
||||
namespace: argus
|
||||
namespace: ddclient
|
||||
|
||||
@@ -21,8 +21,7 @@ spec:
|
||||
targetRevision: master
|
||||
- repoURL: https://dl.gitea.com/charts/
|
||||
chart: gitea
|
||||
# targetRevision: 11.0.0
|
||||
targetRevision: 12.4.0
|
||||
targetRevision: 12.7.0
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/services/Gitea/values.yaml
|
||||
|
||||
@@ -70,12 +70,15 @@ spec:
|
||||
- mountPath: /data
|
||||
name: data-act-runner
|
||||
- name: dind
|
||||
image: "docker:28.3.2-dind"
|
||||
# image: "docker:28.3.2-dind"
|
||||
image: "docker:29.7.2-dind"
|
||||
imagePullPolicy: IfNotPresent
|
||||
args:
|
||||
- dockerd
|
||||
- --host=tcp://127.0.0.1:2375
|
||||
- --host=unix:///var/run/docker.sock
|
||||
- --mtu=1450
|
||||
- --default-network-opt=bridge=com.docker.network.driver.mtu=1450
|
||||
env:
|
||||
- name: DOCKER_TLS_VERIFY
|
||||
value: ""
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: argus
|
||||
name: kutt
|
||||
@@ -1,11 +1,11 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: argus
|
||||
name: kutt
|
||||
namespace: argo-cd
|
||||
spec:
|
||||
destination:
|
||||
namespace: argus
|
||||
namespace: kutt
|
||||
server: https://kubernetes.default.svc
|
||||
project: default
|
||||
syncPolicy:
|
||||
@@ -14,5 +14,5 @@ spec:
|
||||
- CreateNamespace=true
|
||||
sources:
|
||||
- repoURL: https://code.spamasaurus.com/djpbessems/Kubernetes.K3s.installLog
|
||||
path: services/Argus
|
||||
path: services/Kutt
|
||||
targetRevision: HEAD
|
||||
@@ -0,0 +1,37 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: kutt
|
||||
namespace: kutt
|
||||
labels:
|
||||
app: kutt
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: kutt
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: kutt
|
||||
spec:
|
||||
containers:
|
||||
- name: kutt
|
||||
image: kutt/kutt:v3.2.6
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
name: http
|
||||
env:
|
||||
- name: JWT_SECRET
|
||||
value: Gfn2rJaiAPqRQyauxdIVKj6kWcyt2MSj
|
||||
- name: DEFAULT_DOMAIN
|
||||
value: renewal.bessems.com
|
||||
- name: DB_FILENAME
|
||||
value: /var/lib/kutt/data.sqlite
|
||||
volumeMounts:
|
||||
- mountPath: /var/lib/kutt
|
||||
name: csismb-kutt-db
|
||||
volumes:
|
||||
- name: csismb-kutt-db
|
||||
persistentVolumeClaim:
|
||||
claimName: csismb-kutt-db
|
||||
@@ -0,0 +1,16 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: kutt
|
||||
namespace: kutt
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`renewal.bessems.com`) || Host(`p.itch.fyi`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: kutt
|
||||
port: 3000
|
||||
middlewares:
|
||||
- name: security-headers@file
|
||||
+5
-5
@@ -3,14 +3,14 @@ kind: PersistentVolume
|
||||
metadata:
|
||||
annotations:
|
||||
pv.kubernetes.io/provisioned-by: smb.csi.k8s.io
|
||||
name: csismb-argus-data
|
||||
name: csismb-kutt-db
|
||||
spec:
|
||||
capacity:
|
||||
storage: 1Gi
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: csismb-argus-data
|
||||
storageClassName: csismb-kutt-db
|
||||
mountOptions:
|
||||
- dir_mode=0777
|
||||
- file_mode=0777
|
||||
@@ -22,10 +22,10 @@ spec:
|
||||
driver: smb.csi.k8s.io
|
||||
# volumeHandle format: {smb-server-address}#{sub-dir-name}#{share-name}
|
||||
# make sure this value is unique for every share in the cluster
|
||||
volumeHandle: 192.168.154.195#argus#data
|
||||
volumeHandle: 192.168.154.195#kutt#db
|
||||
volumeAttributes:
|
||||
source: //192.168.154.195/K3s.Volumes
|
||||
subDir: argus/data
|
||||
subDir: kutt/db
|
||||
nodeStageSecretRef:
|
||||
name: smb-credentials
|
||||
namespace: argus
|
||||
namespace: kutt
|
||||
+3
-3
@@ -1,12 +1,12 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: csismb-argus-data
|
||||
namespace: argus
|
||||
name: csismb-kutt-db
|
||||
namespace: kutt
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
storageClassName: csismb-argus-data
|
||||
storageClassName: csismb-kutt-db
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: bitnami.com/v1alpha1
|
||||
kind: SealedSecret
|
||||
metadata:
|
||||
name: smb-credentials
|
||||
namespace: kutt
|
||||
spec:
|
||||
encryptedData:
|
||||
password: AgCRyItWRmD4KN9z0PupawuTVVhwvUovcgOC7HThLDiP56uI7WLo45ZmZYDdMZ0PeLv9KH5eWhimSch8+M9gH3dZXwarbXJ5VrSmNUF5fodP3LrL3Tgoq3rijppfLRpYL00mHclldCkCjsBfJpO5YKzPHo5ovmWx/i7p7BzegeokKyOe8l/2Rsn6qeU2UDFarqaUAjYvOWAGmjxwlZwtE3VGy52qujsSEKOcH0whk+GTcqWb8/tdIrT8yiW6OWQaUjI9LS3uBt3ZPKc65AQld4Jk0bS+Kxb3JDletbbo1qBuDTw1IGGziGDHZ1cCYamaywYmgqFs/NvGZ94tiXV66vZaPDRJH7w+2aaGTHAZPU1pCS08Nmd6kgECXm31TbyO4asFZ2bY+wR3Hpo369rjmh0btH829FzKC8xLoqkb9r9HnYX7AGb5hBkKGzboKBsx/RuzNBwdGJKFTGaYX7pVgqFDdtdyjlbppkBNN1WfGwS/Zuyam1ZryjMfgRdg97ihVCQBOoLXgqIKxgqettc1bOzFIGp1qsDyzG530EhCP3c6NE3AQabXTJ6LNTwM9DZROwCcHhekdnlarHif7sjng/jdVlmgxX0VY6L+4hUhDeX8IJ2QBqIwk9voO7QFz4c2CMLupho+EIz9TxF+CHrdsnRa5xKP2gjaggRLtYrD/3O7A3I1uefN7P6sn2Im2KWgXiV4PXQvW50iZmcooQMYTbT1
|
||||
username: AgAF7+KE/BWxojaQNtIkAGiz4++Eb/Dlu6631vzrYX8T9oFwcnL3X0dUJ3ImmRX11Kn0Xba7U99kinv16RrcYkdBqWSrjSY0V4RvvHZ9Y4B5F5rSHXUavdr9CqHQRa7wvTVBRw2eH44kypnxH+WMR5derLINCKojXPbwWndY+iGQ+I/RhIsCOoY9E0L2YCGLWYJmQFnWLTv1q08w1UJwdo/uOmtrtrneNzkHhtHcg/DNsAZ6oNYpWqspLR0hfwiO2FxHOq0J3Hmf1DIsH/m9BIaIcRX3k0ZlIlIQaxnkHPUT++vSCy1Nrsa0le9K5lsoS53A7F68gRqv/Yj0qawYhcI4CfHndW5IpE7COld4Ko4J6PqBilOtPN1Lzv67grUbi9yOaYCjknZOoUdXJGAaWY8+7n4ajEM5DqOltbarQtZNjYW7U12DNwqDZeJl4gWzKUqHSLyPxLwwXP/MQJCupU4aLBL6U3pheUNfYWe8EHzFRmDB40Gin1YxRshuC+PHndzFuXSi8jvlvwPWpSDDC9/J23NWJENi68iDL6xKnGpgHXwucUZ+WyJj9ItrLSA3AQfbhZCXYQ0fA3TlRRcbtC09L8XVo4O6CO+p7Efu5XWWey24BGx+HphtuDUZDcdiRBTtAKmJZm3v9nyuthrH4xQZoEPh7zZfBsY6b0bubhj7xdoy7tA4l01NJ/eQ9PZyz4Zi2fyVmu8=
|
||||
template:
|
||||
metadata:
|
||||
name: smb-credentials
|
||||
namespace: kutt
|
||||
type: Opaque
|
||||
@@ -0,0 +1,13 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: kutt
|
||||
namespace: kutt
|
||||
spec:
|
||||
type: ClusterIP
|
||||
selector:
|
||||
app: kutt
|
||||
ports:
|
||||
- port: 3000
|
||||
targetPort: 3000
|
||||
name: http
|
||||
@@ -7,7 +7,7 @@ spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`bessems.com`) || Host(`bessems.eu`) || Host(`gabaldon.eu`) || Host(`gabaldon.nl`) || Host(`sn.itch.fyi`) || Host(`spamasaurus.com`)
|
||||
- match: Host(`bessems.com`) || Host(`bessems.eu`) || Host(`gabaldon.eu`) || Host(`gabaldon.nl`) || Host(`spamasaurus.com`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: lighttpd
|
||||
|
||||
@@ -17,7 +17,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: app
|
||||
image: neosmemo/memos:0.25
|
||||
image: neosmemo/memos:0.26
|
||||
imagePullPolicy: Always
|
||||
env:
|
||||
- name: MEMOS_PORT
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: nextexplorer
|
||||
@@ -0,0 +1,18 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: nextexplorer
|
||||
namespace: argo-cd
|
||||
spec:
|
||||
destination:
|
||||
namespace: nextexplorer
|
||||
server: https://kubernetes.default.svc
|
||||
project: default
|
||||
syncPolicy:
|
||||
automated: {}
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
sources:
|
||||
- repoURL: https://code.spamasaurus.com/djpbessems/Kubernetes.K3s.installLog
|
||||
path: services/NextExplorer
|
||||
targetRevision: HEAD
|
||||
@@ -0,0 +1,51 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: nextexplorer
|
||||
namespace: nextexplorer
|
||||
labels:
|
||||
app: nextexplorer
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: nextexplorer
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: nextexplorer
|
||||
spec:
|
||||
containers:
|
||||
- name: nextexplorer
|
||||
image: ghcr.io/cerede2000/explorer:3.7.0-lean
|
||||
env:
|
||||
- name: PUBLIC_URL
|
||||
value: https://st.itch.fyi
|
||||
- name: TRASH_ENABLED
|
||||
value: "false"
|
||||
- name: VERSIONS_ENABLED
|
||||
value: "false"
|
||||
ports:
|
||||
- name: web
|
||||
containerPort: 3000
|
||||
volumeMounts:
|
||||
- mountPath: /config
|
||||
name: csismb-nextexplorer-config
|
||||
- mountPath: /cache
|
||||
name: csismb-nextexplorer-cache
|
||||
- mountPath: /mnt/Storage
|
||||
name: csismb-nextexplorer-storage
|
||||
securityContext:
|
||||
fsGroup: 1000
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
volumes:
|
||||
- name: csismb-nextexplorer-config
|
||||
persistentVolumeClaim:
|
||||
claimName: csismb-nextexplorer-config
|
||||
- name: csismb-nextexplorer-cache
|
||||
persistentVolumeClaim:
|
||||
claimName: csismb-nextexplorer-cache
|
||||
- name: csismb-nextexplorer-storage
|
||||
persistentVolumeClaim:
|
||||
claimName: csismb-nextexplorer-storage
|
||||
+5
-6
@@ -1,18 +1,17 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: argus
|
||||
namespace: argus
|
||||
name: nextexplorer
|
||||
namespace: nextexplorer
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`release.spamasaurus.com`)
|
||||
- match: Host(`st.itch.fyi`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: argus
|
||||
port: 8080
|
||||
- name: nextexplorer
|
||||
port: 3000
|
||||
middlewares:
|
||||
- name: 2fa-authentication@file
|
||||
- name: security-headers@file
|
||||
# - name: compression@file
|
||||
+5
-5
@@ -3,14 +3,14 @@ kind: PersistentVolume
|
||||
metadata:
|
||||
annotations:
|
||||
pv.kubernetes.io/provisioned-by: smb.csi.k8s.io
|
||||
name: csismb-argus-config
|
||||
name: csismb-nextexplorer-cache
|
||||
spec:
|
||||
capacity:
|
||||
storage: 1Gi
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: csismb-argus-config
|
||||
storageClassName: csismb-nextexplorer-cache
|
||||
mountOptions:
|
||||
- dir_mode=0777
|
||||
- file_mode=0777
|
||||
@@ -22,10 +22,10 @@ spec:
|
||||
driver: smb.csi.k8s.io
|
||||
# volumeHandle format: {smb-server-address}#{sub-dir-name}#{share-name}
|
||||
# make sure this value is unique for every share in the cluster
|
||||
volumeHandle: 192.168.154.195#argus#config
|
||||
volumeHandle: 192.168.154.195#nextexplorer#cache
|
||||
volumeAttributes:
|
||||
source: //192.168.154.195/K3s.Volumes
|
||||
subDir: argus/config
|
||||
subDir: nextexplorer/cache
|
||||
nodeStageSecretRef:
|
||||
name: smb-credentials
|
||||
namespace: argus
|
||||
namespace: nextexplorer
|
||||
@@ -0,0 +1,31 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata:
|
||||
annotations:
|
||||
pv.kubernetes.io/provisioned-by: smb.csi.k8s.io
|
||||
name: csismb-nextexplorer-config
|
||||
spec:
|
||||
capacity:
|
||||
storage: 1Gi
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: csismb-nextexplorer-config
|
||||
mountOptions:
|
||||
- dir_mode=0777
|
||||
- file_mode=0777
|
||||
- nobrl
|
||||
- cache=strict
|
||||
- mfsymlinks
|
||||
- noserverino # required to prevent data corruption
|
||||
csi:
|
||||
driver: smb.csi.k8s.io
|
||||
# volumeHandle format: {smb-server-address}#{sub-dir-name}#{share-name}
|
||||
# make sure this value is unique for every share in the cluster
|
||||
volumeHandle: 192.168.154.195#nextexplorer#config
|
||||
volumeAttributes:
|
||||
source: //192.168.154.195/K3s.Volumes
|
||||
subDir: nextexplorer/config
|
||||
nodeStageSecretRef:
|
||||
name: smb-credentials
|
||||
namespace: nextexplorer
|
||||
@@ -0,0 +1,31 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata:
|
||||
annotations:
|
||||
pv.kubernetes.io/provisioned-by: smb.csi.k8s.io
|
||||
name: csismb-nextexplorer-storage
|
||||
spec:
|
||||
capacity:
|
||||
storage: 1Gi
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: csismb-nextexplorer-storage
|
||||
mountOptions:
|
||||
- dir_mode=0777
|
||||
- file_mode=0777
|
||||
- nobrl
|
||||
- cache=strict
|
||||
- mfsymlinks
|
||||
- noserverino # required to prevent data corruption
|
||||
csi:
|
||||
driver: smb.csi.k8s.io
|
||||
# volumeHandle format: {smb-server-address}#{sub-dir-name}#{share-name}
|
||||
# make sure this value is unique for every share in the cluster
|
||||
volumeHandle: 192.168.154.195#nextexplorer#storage
|
||||
volumeAttributes:
|
||||
source: //192.168.154.195/K3s.Volumes
|
||||
subDir: nextexplorer/storage
|
||||
nodeStageSecretRef:
|
||||
name: smb-credentials
|
||||
namespace: nextexplorer
|
||||
+3
-3
@@ -1,12 +1,12 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: csismb-jellyseerr-config
|
||||
namespace: jellyseerr
|
||||
name: csismb-nextexplorer-cache
|
||||
namespace: nextexplorer
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
storageClassName: csismb-jellyseerr-config
|
||||
storageClassName: csismb-nextexplorer-cache
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
@@ -0,0 +1,12 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: csismb-nextexplorer-config
|
||||
namespace: nextexplorer
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
storageClassName: csismb-nextexplorer-config
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
@@ -0,0 +1,12 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: csismb-nextexplorer-storage
|
||||
namespace: nextexplorer
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
storageClassName: csismb-nextexplorer-storage
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: bitnami.com/v1alpha1
|
||||
kind: SealedSecret
|
||||
metadata:
|
||||
name: smb-credentials
|
||||
namespace: nextexplorer
|
||||
spec:
|
||||
encryptedData:
|
||||
password: AgAALnoFrXInmYq1KdcLcjbIyVHO+5GL9j/tDC/iOimKeW+ZfSY0EuXQnyDvk3a6F1qLObHTDv7Ur+aMQlvgZtg/FyAoQuzGYtf0DBgdRqFa0xIkz/zPOE0UaT2Tm1UFCm5TSrqWKlxg+T44z9aOJtW9KdWJEstLThmxVGNBZs5/QLrhWmke/WnDtcBz/GSGqS82YXntAl7kbygoG7/y/TNo91dhgPil7kB1ot7cQAsmCpncAFoWKN3Y1xjfs2zdWi8LqfdI5hNvY43AmOEeIirD+am53OgqsjdeQZ2xi+sTH5bHqLcH6Cjvw2HuKLyiDGnqBdAQhK+fZKwJp/GD3mdUWSrBtt6DHoyrYCBL/Sf0v+P7uyDDhdfMi+O+hZb2sEImKJNbzPTznKwVWL2fmCdiE/ga5pk2nW1YVzPCfAE3JywvtY3KJxyRuaybS9LLGYSC71PRJqZFcPs0gNzecb/YliN+Aexm6g+VXG13MN3o31ldLyk0zuo5/IX8m8KU5dWUH1iS1jN1Af1at6nk5hbJzs2GtxtlvV8AlfA74gRar+R4m6PesVFJ53EHQiqzNmr54yw4MF4hJiP9z82K3UWFlXWOY0YmOBwuAyJogxm+4ULcFAGE/4xrV/jpKHBFkowGBOMuIDBx2gLTG7IJjsRmgLJfhzOIHoVdvkuOvm69JqJIdPkOJTACVLJgZ07wcXYHdFgennlKwEY2r9lIZVdu
|
||||
username: AgCFLkXZc0goPZNSCDbks1gT84rY4Gp/pWGg+64WAhKyCjq75o3oLJeaiQtXHbdcltFvklUQcXrn5Ee+QXqknZo6yLvD7NmRxJih4XuCQnpfci2ZHybABeQfrD3qSG1dgp2KFNv7BfSlUk++xC+jhOr5wyDG8vfVEORlpYcuVkV0oPJPKq4ujhexTFGlsbY7VKOHgzEmMn/X6e0ExO50qKCNnKBDsrnRwag3looV5CpG6cwvs8A6/jfnW6OMyBFi3I71snl65bZYnPst9nhurGpv8ueaWeUMkAei03UJwDi43P6+M2zU6H9xhTW85AHmaqfTpZUzrOgLXkSnm52J3wYshk/rD2K/kdMO9HL47NNDrzQbaA0gNyi+1xDwdoJ8zwbY1rO475SO6l4MGV/7y6OeM9fzgo5JSBA4aBoy34QBrjZ5OokAuUFZENJDxTIXSESf8Xnk9Eh7MKJXEsehrifc+q1Nw+PIyWHVPRU8LlBMn8VbGvwrbk/mqaq1cv1CgSIZok7c9YTnWTvcMO+2lKu5DFLvC/M4JNnc3x0OxehQbEQjahWz5Hmia1vremJy9TIEP267/bXF5E/ZNH2UxUqxSA8KDXTER1nVO2Yvfjenu2DFdnfCXYN/6URXf7sBWsG5pLfb4qBeVSYEtTT+pI2CfpjcGyGlxGabEDxDgFpDb6PuMuO26geKmlRfflje73V66StczwM=
|
||||
template:
|
||||
metadata:
|
||||
name: smb-credentials
|
||||
namespace: nextexplorer
|
||||
type: Opaque
|
||||
@@ -1,12 +1,12 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: argus
|
||||
namespace: argus
|
||||
name: nextexplorer
|
||||
namespace: nextexplorer
|
||||
spec:
|
||||
ports:
|
||||
- protocol: TCP
|
||||
name: web
|
||||
port: 8080
|
||||
port: 3000
|
||||
selector:
|
||||
app: argus
|
||||
app: nextexplorer
|
||||
@@ -13,12 +13,15 @@ spec:
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
sources:
|
||||
- repoURL: https://code.spamasaurus.com/djpbessems/Kubernetes.K3s.installLog
|
||||
path: services/PVR/Jellyfin
|
||||
targetRevision: HEAD
|
||||
- repoURL: https://code.spamasaurus.com/djpbessems/Kubernetes.K3s.installLog
|
||||
path: services/PVR/Jellyfin/manifests
|
||||
targetRevision: HEAD
|
||||
- repoURL: https://jellyfin.github.io/jellyfin-helm
|
||||
chart: jellyfin
|
||||
targetRevision: 2.5.0
|
||||
targetRevision: 3.2.0
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/services/PVR/Jellyfin/values.yaml
|
||||
|
||||
@@ -1,16 +0,0 @@
|
||||
apiVersion: bitnami.com/v1alpha1
|
||||
kind: SealedSecret
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
name: smb-credentials
|
||||
namespace: jellyseerr
|
||||
spec:
|
||||
encryptedData:
|
||||
password: AgAXVD3WsMzueRvwCYyh5mrkZsWr6vtR2WegrW3lMa3etjOAAy7ARhrx25pmfX3vzo0PaEbZBLyusMQ04hU0n96TG4+Q5k3H61t9KO6JIjJl3/4myMWfok6H+UuR6qpJl+H3H+A6lYm3M/rwpzvWrq7r3TiepYARHm+MLhI2zSwXn322Pht7Gu8yrshx0mq7ADf/rko9iBBixSGUOuol3eMG+5JNfVCdgb4EQWl5qUwZmXQjWN1Kp3lqRAKXpS5bxqwAmKFP0WRAlMsI63ZBdJeFg+hYcV3PTssDbL6I4hDa+8cVqOMN/JDYnZnNkPxIFy1X7hlOONfNVAda0PYgQO+C2fGuLBFyK2YVcL2uAn84FlEMshdaDpJ0AYlDndattbXSjUVXN04E3/wTsDo5bKzivamyphjeeLlrK0O82yJJvhBPvrQvy0LMtpoIIk39rlctckJKInZbFrl7wCVPUj3d1oCTV4z+quBNIFNCUZmK0aWvjmctW5h6zCFhSnyoWSsc8u+u2Zu/H3vCE3aPSfqg+DLKjv9Dz+itPFMU57kS6SfgcREVeNiqH97Y5wA/wOFcDutb7HHS7dw/l4QCwkBqJiVHDWe45tEsi1ZYmdBlNjKTjCtYzEpxcaO1d6HfRhA2JryrUpqH+WNM1kNA00yTIvfDDC+yKAaEN6y64sUEDhI33ygipo2LLuvB9Moy7DVyBCjYHVtnU0yQiEBoonFn
|
||||
username: AgAGdnx+CIi0PFgSUx+X2LFChH9IlcMAXjlkB0rqM3XM0ht4ghl9HKk4nLa0R2cho6ISSNfpKeBQItMOTxmb5wWbkav0uTLone0nF4Eq0eKysQ4L0yApvKfipl0ZiVb4Z9hsve7MyVcNuE/H5NqLMkgqNPkLaK4yixlxb3KTwDi7/K8NvZjf0a073c1rpfgvbiV7Aodbda+2dmnAcI7k398RuEqTeY7xeBIgg4nR5grsDV448RIeouRX1t4NFvVwdF/6xaVTc085iTxoH9HWf5bpVbP8IxHUtbS+zjMxPz3rwZy1/0nXw8HOs+QFgtFIxNxgsQ1wIH5V46aufPzSc4JUCi0IpV3FsPlHMtv+6aFk4RNv/Z06aa+kT/WY2GHUU+3GdGoFVe2cV2Ty463K4SPluZ/R4UtVtRsCMp1SPkgMOZeUs0g9tK9CBu8l6+comSSny+ub2rAzGpRW0x/i5rEqXBsQqY28Gm36Cv175kB2UOXUTNAY868yaOzgo1LEgMyhFgKzYchju3nWFxyhY+AoG06XRSKzU1ClqlkCwnQBu77Yxu+FjZqXbv6ywUa9TvSVcs8RLGXX/+svM/xXztuots26VMrHLUfcnE23NIHSVkDy5JfDbzn6i2nUnOOJzrm+DUTeRQziu7LIlCFLVjVjygegupMMSC2+F8FbOyKuu5GDBXkZqycfM+n0CA+6Sh+Rrh2LqT4=
|
||||
template:
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
name: smb-credentials
|
||||
namespace: jellyseerr
|
||||
type: Opaque
|
||||
+7
-7
@@ -1,12 +1,12 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: jellyseerr
|
||||
name: seerr
|
||||
namespace: argo-cd
|
||||
spec:
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: jellyseerr
|
||||
namespace: seerr
|
||||
project: default
|
||||
syncPolicy:
|
||||
automated: {}
|
||||
@@ -14,14 +14,14 @@ spec:
|
||||
- CreateNamespace=true
|
||||
sources:
|
||||
- repoURL: https://code.spamasaurus.com/djpbessems/Kubernetes.K3s.installLog
|
||||
path: services/PVR/Jellyseerr/manifests
|
||||
path: services/PVR/Seerr/manifests
|
||||
targetRevision: HEAD
|
||||
- repoURL: ghcr.io/fallenbagel/jellyseerr
|
||||
chart: jellyseerr-chart
|
||||
targetRevision: 2.7.0
|
||||
- repoURL: oci://ghcr.io/seerr-team/seerr/seerr-chart
|
||||
chart: seerr
|
||||
targetRevision: 3.9.1
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/services/PVR/Jellyseerr/values.yaml
|
||||
- $values/services/PVR/Seerr/values.yaml
|
||||
- repoURL: https://code.spamasaurus.com/djpbessems/Kubernetes.K3s.installLog
|
||||
targetRevision: HEAD
|
||||
ref: values
|
||||
+5
-5
@@ -3,14 +3,14 @@ kind: PersistentVolume
|
||||
metadata:
|
||||
annotations:
|
||||
pv.kubernetes.io/provisioned-by: smb.csi.k8s.io
|
||||
name: csismb-jellyseerr-config
|
||||
name: csismb-seerr-config
|
||||
spec:
|
||||
capacity:
|
||||
storage: 1Gi
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: csismb-jellyseerr-config
|
||||
storageClassName: csismb-seerr-config
|
||||
mountOptions:
|
||||
- dir_mode=0777
|
||||
- file_mode=0777
|
||||
@@ -24,10 +24,10 @@ spec:
|
||||
driver: smb.csi.k8s.io
|
||||
# volumeHandle format: {smb-server-address}#{sub-dir-name}#{share-name}
|
||||
# make sure this value is unique for every share in the cluster
|
||||
volumeHandle: 192.168.154.195#jellyseerr#config
|
||||
volumeHandle: 192.168.154.195#seerr#config
|
||||
volumeAttributes:
|
||||
source: //192.168.154.195/K3s.Volumes
|
||||
subDir: jellyseerr/config
|
||||
subDir: seerr/config
|
||||
nodeStageSecretRef:
|
||||
name: smb-credentials
|
||||
namespace: jellyseerr
|
||||
namespace: seerr
|
||||
+3
-3
@@ -1,12 +1,12 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: csismb-argus-config
|
||||
namespace: argus
|
||||
name: csismb-seerr-config
|
||||
namespace: seerr
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
storageClassName: csismb-argus-config
|
||||
storageClassName: csismb-seerr-config
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: bitnami.com/v1alpha1
|
||||
kind: SealedSecret
|
||||
metadata:
|
||||
name: smb-credentials
|
||||
namespace: seerr
|
||||
spec:
|
||||
encryptedData:
|
||||
password: AgAHq9+fxdZtWTNEd6yrfUlTwPewBHwIwfElk3MP2TJccxs2kPiuuQ2GtDiDmaVMiACm9iUaf8CPFZbzWfkUdu2PiqGJWh+Pn76ell2r6oRHDfAGfivqjG/VAspdYtClxSzIuShYLdd+klGj4aRkNLPkc+QJLOPdZ/8gIS9BUe1c+c57BhbH4fN5H+g2pIKkEVepWwG5WqaV63UdcsQoPi95CGUPoZQFqdj7QBTsc+0NIurMPs/Lx/8awu2cqJRvUrPkGnBQZgWbeuKVjYKzUeDRHfosv1K28YrVrn7VfKoLxEtTPDCLzxi+38KWNYyIAxjRqkbhPeT//I9ZhaIJ0xVz8GDJTaLW02Dz6pz2jqnjVbE0OlrnfJqSxLzFyMgyeRu8qVV+mI1OqWTqpAFZeZs4YFyTpEY2Zr7uEc4o9YIo7fqplbWiAat1yo+RpLREOa/nRTqNSp0kmQDIv+0GltoZC+k6/zL71ttioTColsNAXunvJXDzmEJErgiBYaF7reGbOz6IxCYShQCBJ1F6M0rpJJ+Qh4uq3eyRB9WDGlZR2nUxZtYs07q5pmtyKZXjFUHIBvdbViyZdrLG34IgM+RlNSbU51TAHIB4Mcx1SMzma/eMJUbfW9JTWVwgl0kPkD0KMvyVM6ZdxWzDkw1VpHsF6OUZQM0iWsXWwd8q//Tu1qVjC+d/fQph/jDaQ+BmFc9NR2HC7APhTxhF4CgCbMZK
|
||||
username: AgCqVYzkzBi1rUSHf8jzAeNi9863Dn3BvVUTYwE9qUtRojwr4HxqLd2NIc6r4AHl7S217xIih9OM8612FdBz1bPu5E7ZNyKvreI0xailmMhhO8Lbu4P/RBg+quY4hD6JPkwfJyVavE0YsGHKrKPKUf5EwVcIsWZNjdMuqZ4H0jrNG/bdfOzcaryCs5R5ASw0s29C74rWB9hzSs2dwGTUhRx61vWsYOuEq0m0FTUlBZnbN7KgAfCL8p8fQFKGB1vvd75sERRe2GHIIEe6qWqLymaOhl9xBbiUCMj86e+3KqyKu2WZgVk1PBXL4FqwAcWHUQ32fSNJWLd18z8rvF8eb4FfP6uGIGNZy9u3D1MUsj1KRRdegxbsOsv1zezJmYmxxbUmISQ1XP74dPwYjTG4o+sHUlhXSzKYcmwjhKRjcz/K/9T0DUtVdU93nhb8dGk57ssKN3jo2+91Myiah9h28Kv6o2QOkXE7V0wEuLk8UqgggfNTv8oG6ut8JUvziTjTxFSQ3Sv9kejJEyOPZl8Mpnj8vGXI0EucPPn1wQDU5bHfYPZH35M8zr4mE5UlzXc5eRq9S1WgXWN2YAOv95CJPoInYlu8brvY259dSgB0kt/mnTpwNAscEHr8Z/qfSzXCILi0ZO80ps+pFoXM6e94FlQ49GgdIpuA0mH7U/6z8f8814RUJ8HEKjVOMutOVREyKxScu4wfHRE=
|
||||
template:
|
||||
metadata:
|
||||
name: smb-credentials
|
||||
namespace: seerr
|
||||
type: Opaque
|
||||
@@ -9,7 +9,7 @@ ingress:
|
||||
|
||||
config:
|
||||
persistence:
|
||||
name: csismb-jellyseerr-config
|
||||
storageClass: csismb-jellyseerr-config
|
||||
name: csismb-seerr-config
|
||||
storageClass: csismb-seerr-config
|
||||
accessModes: ["ReadWriteMany"]
|
||||
size: 1Gi
|
||||
@@ -1,57 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: kubectl-rolloutrestart
|
||||
namespace: pvr
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: kubectl-rolloutrestart
|
||||
namespace: pvr
|
||||
rules:
|
||||
- apiGroups: ["apps", "extensions"]
|
||||
resources: ["deployments", "statefulsets"]
|
||||
verbs: ["get", "list", "patch"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: kubectl-rolloutrestart-pvr
|
||||
namespace: pvr
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: kubectl-rolloutrestart
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: kubectl-rolloutrestart
|
||||
namespace: pvr
|
||||
---
|
||||
apiVersion: batch/v1
|
||||
kind: CronJob
|
||||
metadata:
|
||||
name: kubectl-rolloutrestart
|
||||
namespace: pvr
|
||||
spec:
|
||||
concurrencyPolicy: Forbid
|
||||
failedJobsHistoryLimit: 1
|
||||
successfulJobsHistoryLimit: 1
|
||||
schedule: '30 2 * * *'
|
||||
jobTemplate:
|
||||
spec:
|
||||
backoffLimit: 2
|
||||
activeDeadlineSeconds: 600
|
||||
template:
|
||||
spec:
|
||||
serviceAccountName: kubectl-rolloutrestart
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: kubectl
|
||||
image: bitnami/kubectl
|
||||
command:
|
||||
- '/bin/bash'
|
||||
- '-c'
|
||||
args:
|
||||
- for workload in `kubectl get deployments -n pvr --no-headers | cut -d " " -f 1`; do kubectl rollout restart deployment -n pvr $workload; done;
|
||||
for workload in `kubectl get statefulsets -n pvr --no-headers | cut -d " " -f 1`; do kubectl rollout restart statefulsets -n pvr $workload; done;
|
||||
@@ -18,7 +18,7 @@ spec:
|
||||
serviceAccountName: vaultwarden
|
||||
containers:
|
||||
- name: vaultwarden
|
||||
image: vaultwarden/server:1.33.2
|
||||
image: vaultwarden/server:1.37.3
|
||||
env:
|
||||
- name: ENABLE_DB_WAL
|
||||
value: "false"
|
||||
|
||||
@@ -13,7 +13,7 @@ spec:
|
||||
sources:
|
||||
- repoURL: https://raw.githubusercontent.com/kubernetes-csi/csi-driver-smb/master/charts
|
||||
chart: csi-driver-smb
|
||||
targetRevision: 1.19.1
|
||||
targetRevision: 1.20.3
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/storage/csi-driver-smb/values.yaml
|
||||
|
||||
@@ -9,10 +9,12 @@ spec:
|
||||
namespace: argo-cd
|
||||
project: default
|
||||
sources:
|
||||
- repoURL: https://code.spamasaurus.com/djpbessems/Kubernetes.K3s.installLog
|
||||
path: system/ArgoCD
|
||||
targetRevision: HEAD
|
||||
- repoURL: https://argoproj.github.io/argo-helm
|
||||
chart: argo-cd
|
||||
# targetRevision: 8.1.2
|
||||
targetRevision: 9.1.4
|
||||
targetRevision: 10.9.4
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/system/ArgoCD/values.yaml
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
apiVersion: network.harvesterhci.io/v1alpha1
|
||||
kind: IPPool
|
||||
metadata:
|
||||
annotations:
|
||||
kubectl.kubernetes.io/last-applied-configuration: |
|
||||
{"apiVersion":"network.harvesterhci.io/v1alpha1","kind":"IPPool","metadata":{"annotations":{},"name":"vmn-lan","namespace":"default"},"spec":{"ipv4Config":{"cidr":"192.168.154.0/24","dns":["192.168.154.200"],"leaseTime":86400,"pool":{"end":"192.168.154.99","exclude":["192.168.154.99"],"start":"192.168.154.50"},"router":"192.168.154.1","serverIP":"192.168.154.99"},"networkName":"default/vmn-lan"}}
|
||||
creationTimestamp: "2025-12-29T22:22:23Z"
|
||||
generation: 1
|
||||
name: vmn-lan
|
||||
namespace: default
|
||||
resourceVersion: "277614389"
|
||||
uid: 8400a6ec-9f7a-4570-934d-1ee3299e04aa
|
||||
spec:
|
||||
ipv4Config:
|
||||
cidr: 192.168.154.0/24
|
||||
dns:
|
||||
- 192.168.154.150
|
||||
leaseTime: 86400
|
||||
pool:
|
||||
end: 192.168.154.99
|
||||
exclude:
|
||||
- 192.168.154.99
|
||||
start: 192.168.154.50
|
||||
router: 192.168.154.1
|
||||
serverIP: 192.168.154.99
|
||||
networkName: default/vmn-lan
|
||||
status:
|
||||
agentPodRef:
|
||||
image: rancher/harvester-vm-dhcp-agent:v1.8.2
|
||||
name: default-vmn-lan-agent
|
||||
namespace: harvester-system
|
||||
uid: fde98493-a67c-4279-b48e-f7a70ea089b7
|
||||
conditions:
|
||||
- lastUpdateTime: "2025-12-29T22:22:23Z"
|
||||
status: "True"
|
||||
type: Registered
|
||||
- lastUpdateTime: "2025-12-29T22:23:00Z"
|
||||
status: "True"
|
||||
type: CacheReady
|
||||
- lastUpdateTime: "2025-12-29T22:22:26Z"
|
||||
status: "True"
|
||||
type: AgentReady
|
||||
- lastUpdateTime: "2025-12-29T22:22:23Z"
|
||||
status: "False"
|
||||
type: Stopped
|
||||
ipv4:
|
||||
allocated:
|
||||
192.168.154.50: ce:73:61:52:b7:35
|
||||
192.168.154.56: d2:f6:70:98:42:6e
|
||||
192.168.154.57: ea:ad:6d:52:3e:b9
|
||||
192.168.154.58: 9a:b4:56:2d:57:7d
|
||||
192.168.154.66: c2:a3:f7:c4:13:95
|
||||
192.168.154.87: 0a:59:bb:81:a7:6d
|
||||
192.168.154.98: 0a:15:10:a2:78:22
|
||||
192.168.154.99: EXCLUDED
|
||||
available: 42
|
||||
used: 7
|
||||
lastUpdate: "2025-12-30T05:10:35Z"
|
||||
@@ -11,7 +11,7 @@ spec:
|
||||
syncPolicy:
|
||||
automated: {}
|
||||
sources:
|
||||
- repoURL: https://bitnami-labs.github.io/sealed-secrets
|
||||
- repoURL: https://bitnami.github.io/sealed-secrets
|
||||
chart: sealed-secrets
|
||||
targetRevision: 2.17.7
|
||||
helm:
|
||||
|
||||
Reference in New Issue
Block a user