mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-08-03 11:30:44 +00:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| fde6b5f23a |
@@ -55,7 +55,6 @@ updates:
|
|||||||
- "/kubernetes/system/blocky"
|
- "/kubernetes/system/blocky"
|
||||||
- "/kubernetes/system/caddy"
|
- "/kubernetes/system/caddy"
|
||||||
- "/kubernetes/system/cert-manager"
|
- "/kubernetes/system/cert-manager"
|
||||||
- "/kubernetes/system/cert-manager-webhook-ovh"
|
|
||||||
- "/kubernetes/system/coredns"
|
- "/kubernetes/system/coredns"
|
||||||
- "/kubernetes/system/csi-driver-nfs"
|
- "/kubernetes/system/csi-driver-nfs"
|
||||||
- "/kubernetes/system/external-dns"
|
- "/kubernetes/system/external-dns"
|
||||||
|
|||||||
@@ -9,6 +9,3 @@ terraform.tfstate.backup
|
|||||||
kubeconfig
|
kubeconfig
|
||||||
talosconfig
|
talosconfig
|
||||||
|
|
||||||
# Ignore rendered Talos machine configs (may contain cluster secrets)
|
|
||||||
p330.yaml
|
|
||||||
|
|
||||||
|
|||||||
@@ -1,195 +0,0 @@
|
|||||||
# Talos node for the P330 — joins the r740 "kube" cluster.
|
|
||||||
terraform {
|
|
||||||
required_providers {
|
|
||||||
talos = {
|
|
||||||
source = "siderolabs/talos"
|
|
||||||
version = "0.9.0"
|
|
||||||
}
|
|
||||||
null = {
|
|
||||||
source = "hashicorp/null"
|
|
||||||
version = "3.2.3"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# Read the r740 kube module state to reuse the cluster secrets & endpoint.
|
|
||||||
# The r740 module exposes: client_configuration, machine_secrets, cluster_name,
|
|
||||||
# cluster_endpoint, kube_host.
|
|
||||||
data "terraform_remote_state" "r740_kube" {
|
|
||||||
backend = var.r740_backend
|
|
||||||
|
|
||||||
config = var.r740_backend == "local" ? {
|
|
||||||
path = "${var.r740_state_path}/terraform.tfstate"
|
|
||||||
} : var.r740_backend_config
|
|
||||||
}
|
|
||||||
|
|
||||||
locals {
|
|
||||||
cluster_name = data.terraform_remote_state.r740_kube.outputs.cluster_name
|
|
||||||
cluster_endpoint = data.terraform_remote_state.r740_kube.outputs.cluster_endpoint
|
|
||||||
machine_secrets = data.terraform_remote_state.r740_kube.outputs.machine_secrets
|
|
||||||
client_config = data.terraform_remote_state.r740_kube.outputs.client_configuration
|
|
||||||
|
|
||||||
# kubeconfig produced by the r740 kube module — used to wait for the node and
|
|
||||||
# apply labels/taints. There is no in-tree kubernetes provider here on
|
|
||||||
# purpose: managing a `kubernetes_node` resource conflicts with the node
|
|
||||||
# object that kubelet itself creates, so we use a null_resource with kubectl
|
|
||||||
# to wait + label + taint idempotently.
|
|
||||||
kubeconfig_path = "${var.r740_state_path}/kubeconfig"
|
|
||||||
|
|
||||||
# Network config: static if node_subnet is provided, otherwise Talos DHCPs.
|
|
||||||
static_network = var.node_subnet == null ? {} : {
|
|
||||||
interfaces = [{
|
|
||||||
interface = var.network_interface
|
|
||||||
addresses = [var.node_subnet]
|
|
||||||
routes = var.node_gateway == null ? [] : [{ gateway = var.node_gateway }]
|
|
||||||
}]
|
|
||||||
}
|
|
||||||
|
|
||||||
network_patch = {
|
|
||||||
nameservers = var.nameservers
|
|
||||||
}
|
|
||||||
network_patch_merged = merge(local.network_patch, local.static_network)
|
|
||||||
|
|
||||||
machine_patch = {
|
|
||||||
install = {
|
|
||||||
image = var.installer_image
|
|
||||||
disk = var.install_disk
|
|
||||||
}
|
|
||||||
network = merge(local.network_patch_merged, {
|
|
||||||
# Pin the Kubernetes node name. Talos otherwise auto-generates a hostname
|
|
||||||
# (e.g. "talos-8ec-vd1"), so the node registers with that random name
|
|
||||||
# instead of var.p330_node_name — and our label/taint null_resource waits
|
|
||||||
# for the wrong node. Setting machine.network.hostname fixes the node name.
|
|
||||||
hostname = var.p330_node_name
|
|
||||||
})
|
|
||||||
# Kernel modules required by Longhorn (iSCSI + ext4) — must match the
|
|
||||||
# control-plane nodes so Longhorn can schedule replicas on the failover node.
|
|
||||||
kernel = {
|
|
||||||
modules = [
|
|
||||||
{ name = "iscsi_tcp" },
|
|
||||||
{ name = "libiscsi" },
|
|
||||||
{ name = "scsi_transport_iscsi" },
|
|
||||||
{ name = "ext4" },
|
|
||||||
]
|
|
||||||
}
|
|
||||||
sysctls = {
|
|
||||||
"fs.inotify.max_user_instances" = "1024"
|
|
||||||
"fs.inotify.max_user_watches" = "1048576"
|
|
||||||
}
|
|
||||||
kubelet = {
|
|
||||||
# Keep the failover node from accumulating non-essential DaemonSet pods
|
|
||||||
# via the regular scheduler; the taint does the heavy lifting, this is
|
|
||||||
# belt-and-braces.
|
|
||||||
extraArgs = {
|
|
||||||
"register-with-taints" = "${var.failover_taint_key}=${var.failover_taint_value}:${var.failover_taint_effect}"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# Control-plane machine configuration. machine_type = "controlplane" makes
|
|
||||||
# Talos generate a join config that runs the apiserver/controller-manager/
|
|
||||||
# scheduler AND joins the existing etcd cluster as a new member (the cluster
|
|
||||||
# was already bootstrapped by the r740 module's talos_machine_bootstrap).
|
|
||||||
data "talos_machine_configuration" "p330" {
|
|
||||||
cluster_name = local.cluster_name
|
|
||||||
machine_type = "controlplane"
|
|
||||||
cluster_endpoint = local.cluster_endpoint
|
|
||||||
machine_secrets = local.machine_secrets
|
|
||||||
config_patches = [
|
|
||||||
yamlencode({
|
|
||||||
machine = local.machine_patch
|
|
||||||
})
|
|
||||||
]
|
|
||||||
}
|
|
||||||
|
|
||||||
# Rendered config is written to disk so it can also be applied manually with
|
|
||||||
# `talosctl apply-config --nodes <p330_host> --file p330.yaml` if needed.
|
|
||||||
resource "local_file" "p330_machine_config" {
|
|
||||||
filename = "${path.module}/p330.yaml"
|
|
||||||
content = data.talos_machine_configuration.p330.machine_configuration
|
|
||||||
}
|
|
||||||
|
|
||||||
# Apply the machine config to the running (maintenance-mode) node over the
|
|
||||||
# Talos API. Because the config patch contains a `machine.install` block, when
|
|
||||||
# Talos receives this config on a node booted from the USB (maintenance) image
|
|
||||||
# it installs itself to install.disk and reboots into the installed system.
|
|
||||||
# For a controlplane node it then joins the existing etcd cluster as a new
|
|
||||||
# member and runs the control-plane components; for a worker it just registers
|
|
||||||
# via kubelet.
|
|
||||||
resource "talos_machine_configuration_apply" "p330" {
|
|
||||||
client_configuration = local.client_config
|
|
||||||
machine_configuration_input = data.talos_machine_configuration.p330.machine_configuration
|
|
||||||
node = var.p330_host
|
|
||||||
depends_on = [local_file.p330_machine_config]
|
|
||||||
}
|
|
||||||
|
|
||||||
# Emit a talosconfig scoped to this node for ad-hoc `talosctl` use.
|
|
||||||
data "talos_client_configuration" "p330" {
|
|
||||||
cluster_name = local.cluster_name
|
|
||||||
client_configuration = local.client_config
|
|
||||||
nodes = [var.p330_host]
|
|
||||||
}
|
|
||||||
|
|
||||||
resource "local_file" "talosconfig" {
|
|
||||||
content = data.talos_client_configuration.p330.talos_config
|
|
||||||
filename = "${path.module}/talosconfig"
|
|
||||||
depends_on = [data.talos_client_configuration.p330]
|
|
||||||
}
|
|
||||||
|
|
||||||
# Wait for the node to register with Kubernetes (kubelet creates the Node
|
|
||||||
# object after Talos installs and reboots), then label it and (re)apply the
|
|
||||||
# failover taint. This is idempotent: kubectl exits 0 if the label/taint already
|
|
||||||
# exists. The taint is also set via kubelet `register-with-taints`, so this
|
|
||||||
# null_resource is a safety net for manual edits / drift.
|
|
||||||
resource "null_resource" "p330_node_label_and_taint" {
|
|
||||||
triggers = {
|
|
||||||
node = var.p330_node_name
|
|
||||||
key = var.failover_taint_key
|
|
||||||
value = var.failover_taint_value
|
|
||||||
effect = var.failover_taint_effect
|
|
||||||
kubeconfig = local.kubeconfig_path
|
|
||||||
}
|
|
||||||
|
|
||||||
provisioner "local-exec" {
|
|
||||||
# Wait for the node to show up, then label + taint. The wait loop is bounded
|
|
||||||
# by kubectl --timeout; tune it via TF_LOG / re-run if the node is slow to
|
|
||||||
# join (a controlplane node must first complete the etcd join handshake).
|
|
||||||
command = <<-EOT
|
|
||||||
set -euo pipefail
|
|
||||||
KUBECONFIG="${local.kubeconfig_path}"
|
|
||||||
export KUBECONFIG
|
|
||||||
NODE="${var.p330_node_name}"
|
|
||||||
|
|
||||||
echo "Waiting for node $NODE to be registered (kubelet creates the Node object once Talos has installed, rebooted and joined etcd)..."
|
|
||||||
# kubectl wait --for=condition=Ready fails instantly with NotFound if the
|
|
||||||
# node object doesn't exist yet, so poll for existence first.
|
|
||||||
# /bin/sh (dash) has no $SECONDS, so count iterations with a bounded loop.
|
|
||||||
tries=240 # 240 * 5s = 20 minutes max
|
|
||||||
until kubectl get node "$NODE" >/dev/null 2>&1; do
|
|
||||||
tries=$((tries - 1))
|
|
||||||
if [ "$tries" -le 0 ]; then
|
|
||||||
echo "Timed out waiting for node $NODE to register." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
sleep 5
|
|
||||||
done
|
|
||||||
echo "Node $NODE registered. Waiting for it to become Ready..."
|
|
||||||
|
|
||||||
# Now wait for Ready (a controlplane node needs etcd joined + apiserver up).
|
|
||||||
kubectl wait --for=condition=Ready "node/$NODE" --timeout=20m || \
|
|
||||||
kubectl wait --for=jsonpath='{.status.conditions[?(@.reason=="KubeletReady")].status}'=True "node/$NODE" --timeout=20m
|
|
||||||
|
|
||||||
# Failover marker + taint (applied to both controlplane and worker nodes).
|
|
||||||
kubectl label --overwrite node "$NODE" homeprod.io/failover=true
|
|
||||||
|
|
||||||
# Apply the taint idempotently (kubectl taint --overwrite is a no-op if it exists).
|
|
||||||
kubectl taint --overwrite node "$NODE" \
|
|
||||||
"${var.failover_taint_key}=${var.failover_taint_value}:${var.failover_taint_effect}"
|
|
||||||
|
|
||||||
echo "Node $NODE ready, labeled and tainted for failover-only scheduling."
|
|
||||||
EOT
|
|
||||||
}
|
|
||||||
|
|
||||||
depends_on = [talos_machine_configuration_apply.p330]
|
|
||||||
}
|
|
||||||
@@ -1,118 +0,0 @@
|
|||||||
# Variables for the P330 Talos worker node that joins the r740 cluster.
|
|
||||||
|
|
||||||
variable "p330_host" {
|
|
||||||
description = "Reachable IP/hostname of the P330 Talos node (for Talos API access)."
|
|
||||||
type = string
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "p330_node_name" {
|
|
||||||
description = "Kubernetes/Talos node name for the P330 (e.g. p330)."
|
|
||||||
type = string
|
|
||||||
default = "p330"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "r740_state_path" {
|
|
||||||
description = <<EOT
|
|
||||||
Path to the Terraform state of the r740 kube module, used by terraform_remote_state
|
|
||||||
to read the cluster secrets and endpoint so this node can join the existing cluster.
|
|
||||||
Path is resolved by terraform_remote_state relative to the working directory where
|
|
||||||
terraform runs (this module dir). The default points two levels up to the repo
|
|
||||||
root and back down to the r740 kube module.
|
|
||||||
EOT
|
|
||||||
type = string
|
|
||||||
default = "../../r740/kube"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "r740_backend" {
|
|
||||||
description = <<EOT
|
|
||||||
Terraform backend type used by the r740 kube module.
|
|
||||||
Set to "local" (default) when r740 uses a local tfstate file in its own directory,
|
|
||||||
or the matching remote backend name ("s3", "remote", ...) if the r740 module uses
|
|
||||||
a configured backend.
|
|
||||||
EOT
|
|
||||||
type = string
|
|
||||||
default = "local"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "r740_backend_config" {
|
|
||||||
description = <<EOT
|
|
||||||
Backend configuration map passed to terraform_remote_state when r740_backend is
|
|
||||||
not "local". For a local backend this is ignored.
|
|
||||||
EOT
|
|
||||||
type = map(string)
|
|
||||||
default = {}
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "installer_image" {
|
|
||||||
description = <<EOT
|
|
||||||
Talos installer image to use on the P330 (bare metal).
|
|
||||||
Must be a **metal** Image Factory build that includes ixgbe.allow_unsupported_sfp=1
|
|
||||||
in the kernel command line (sd-boot/UKI ignores machine.install.extraKernelArgs, so
|
|
||||||
the param must be baked into the image). The default is a custom factory build
|
|
||||||
(a18165114...).
|
|
||||||
EOT
|
|
||||||
type = string
|
|
||||||
default = "factory.talos.dev/installer/a18165114f80c28601d05bc4ff1f6ea6d6b214882c5b9af7928aaf4d09741beb:v1.13.6"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "install_disk" {
|
|
||||||
description = "Block device path to install Talos on (e.g. /dev/sda, /dev/nvme0n1)."
|
|
||||||
type = string
|
|
||||||
default = "/dev/nvme0n1"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "node_subnet" {
|
|
||||||
description = <<EOT
|
|
||||||
Static IPv4 address in CIDR notation for the P330 node (e.g. 10.1.2.132/24).
|
|
||||||
Set to null to use DHCP. A static address is recommended for a failover node so
|
|
||||||
DNS/affinity rules stay stable.
|
|
||||||
EOT
|
|
||||||
type = string
|
|
||||||
default = "10.1.2.132/24"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "node_gateway" {
|
|
||||||
description = "IPv4 gateway for the P330 node. Ignored when node_subnet is null."
|
|
||||||
type = string
|
|
||||||
default = "10.1.2.1"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "network_interface" {
|
|
||||||
description = <<EOT
|
|
||||||
Primary network interface name on the P330. Defaults to enp3s0f1 (the 10G Intel
|
|
||||||
X520 NIC), which must be on the same L2/subnet as the r740 control plane so etcd
|
|
||||||
peer traffic (TLS-verified against the r740's etcd cert SANs) doesn't cross a
|
|
||||||
router. eno1 (1G) is left unconfigured.
|
|
||||||
EOT
|
|
||||||
type = string
|
|
||||||
default = "enp3s0f1"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "nameservers" {
|
|
||||||
description = "DNS nameservers configured on the node (must work independently of kube)."
|
|
||||||
type = list(string)
|
|
||||||
default = ["10.1.2.148", "1.1.1.1"]
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "failover_taint_key" {
|
|
||||||
description = "Taint key applied to the node to reserve it for failover workloads."
|
|
||||||
type = string
|
|
||||||
default = "dedicated"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "failover_taint_value" {
|
|
||||||
description = "Taint value applied to the node."
|
|
||||||
type = string
|
|
||||||
default = "failover"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "failover_taint_effect" {
|
|
||||||
description = "Taint effect applied to the node (NoSchedule / NoExecute)."
|
|
||||||
type = string
|
|
||||||
default = "NoSchedule"
|
|
||||||
|
|
||||||
validation {
|
|
||||||
condition = contains(["NoSchedule", "PreferNoSchedule", "NoExecute"], var.failover_taint_effect)
|
|
||||||
error_message = "failover_taint_effect must be NoSchedule, PreferNoSchedule or NoExecute."
|
|
||||||
}
|
|
||||||
}
|
|
||||||
+1
-52
@@ -40,9 +40,7 @@ data "talos_machine_configuration" "kube" {
|
|||||||
yamlencode({
|
yamlencode({
|
||||||
machine = {
|
machine = {
|
||||||
install = {
|
install = {
|
||||||
# Image Factory image with iSCSI extension for Longhorn.
|
image = "factory.talos.dev/installer/ce4c980550dd2ab1b17bbf2b08801c7eb59418eafe8f279833297925d67c7515:v1.11.5"
|
||||||
# Generated at https://factory.talos.dev — siderolabs/iscsi-tools + qemu-guest-agent
|
|
||||||
image = "factory.talos.dev/installer/dc7b152cb3ea99b821fcb7340ce7168313ce393d663740b791c36f6e95fc8586:v1.13.6"
|
|
||||||
}
|
}
|
||||||
network = {
|
network = {
|
||||||
nameservers = [
|
nameservers = [
|
||||||
@@ -55,28 +53,6 @@ data "talos_machine_configuration" "kube" {
|
|||||||
certSANs = [
|
certSANs = [
|
||||||
"${var.kube_host}", "${var.kube_hostname}"
|
"${var.kube_host}", "${var.kube_hostname}"
|
||||||
]
|
]
|
||||||
# Kernel modules required by Longhorn (iSCSI + ext4)
|
|
||||||
kernel = {
|
|
||||||
modules = [
|
|
||||||
{
|
|
||||||
name = "iscsi_tcp"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name = "libiscsi"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name = "scsi_transport_iscsi"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name = "ext4"
|
|
||||||
},
|
|
||||||
]
|
|
||||||
}
|
|
||||||
# Sysctls for Longhorn
|
|
||||||
sysctls = {
|
|
||||||
"fs.inotify.max_user_instances" = "1024"
|
|
||||||
"fs.inotify.max_user_watches" = "1048576"
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
cluster = {
|
cluster = {
|
||||||
clusterName = "kube-${var.physical_hostname}"
|
clusterName = "kube-${var.physical_hostname}"
|
||||||
@@ -130,33 +106,6 @@ output "kubeconfig" {
|
|||||||
value = talos_cluster_kubeconfig.kube.kubeconfig_raw
|
value = talos_cluster_kubeconfig.kube.kubeconfig_raw
|
||||||
}
|
}
|
||||||
|
|
||||||
output "client_configuration" {
|
|
||||||
description = "Talos client configuration (sensitive) used to manage nodes."
|
|
||||||
sensitive = true
|
|
||||||
value = talos_machine_secrets.kube.client_configuration
|
|
||||||
}
|
|
||||||
|
|
||||||
output "machine_secrets" {
|
|
||||||
description = "Talos machine secrets (sensitive) used to generate node configs."
|
|
||||||
sensitive = true
|
|
||||||
value = talos_machine_secrets.kube.machine_secrets
|
|
||||||
}
|
|
||||||
|
|
||||||
output "cluster_name" {
|
|
||||||
description = "Name of the Talos cluster the worker joins."
|
|
||||||
value = "kube-${var.physical_hostname}"
|
|
||||||
}
|
|
||||||
|
|
||||||
output "cluster_endpoint" {
|
|
||||||
description = "Endpoint (host:port) of the Talos/Kubernetes API on the cluster."
|
|
||||||
value = "https://${var.kube_host}:6443"
|
|
||||||
}
|
|
||||||
|
|
||||||
output "kube_host" {
|
|
||||||
description = "Reachable IP/hostname of the control-plane node."
|
|
||||||
value = var.kube_host
|
|
||||||
}
|
|
||||||
|
|
||||||
resource "local_file" "kubeconfig" {
|
resource "local_file" "kubeconfig" {
|
||||||
content = "${talos_cluster_kubeconfig.kube.kubeconfig_raw}"
|
content = "${talos_cluster_kubeconfig.kube.kubeconfig_raw}"
|
||||||
filename = "${path.module}/kubeconfig"
|
filename = "${path.module}/kubeconfig"
|
||||||
|
|||||||
@@ -19,9 +19,9 @@ pushShard: ""
|
|||||||
# with these credentials on every cert-manager renewal.
|
# with these credentials on every cert-manager renewal.
|
||||||
recoveryAdmin:
|
recoveryAdmin:
|
||||||
enabled: true
|
enabled: true
|
||||||
username: ENC[AES256_GCM,data:kpf88Vc=,iv:k2kGcGlH0jQkLmb35V4+IIrBpDM93PaG6atcO/SLDB4=,tag:qZIR2LZlv1g0XBkEh0y8qA==,type:str]
|
username: ENC[AES256_GCM,data:83oORcE=,iv:X07gQXkAx2wdqEcOPi5mGTVoFkJjDHBKMCYUjpg3qv4=,tag:qvspLaPSsrld4UV/qXb0cw==,type:str]
|
||||||
password: ""
|
password: ""
|
||||||
existingSecret: ENC[AES256_GCM,data:DnjFoj8VNeqHmwM/KVebjOOHvYHPgZQ=,iv:JWBs6OeZzsa+8uJt/FjptI6t+tf+CRQDKA7149rBg1o=,tag:M4CXA2k8M65mbSUF0mnGvQ==,type:str]
|
existingSecret: ENC[AES256_GCM,data:KuZYrQk+YQhciNRTHqOlZdqZWJ3o15I=,iv:x/cm4USFZqWE5xuuF7tUPm593NqX1kbmeKv0x2wzk8s=,tag:G9FRYYaJhWovN+LB/gLaoQ==,type:str]
|
||||||
usernameKey: username
|
usernameKey: username
|
||||||
passwordKey: password
|
passwordKey: password
|
||||||
# Recovery mode suspends mail services and exposes only the management listener.
|
# Recovery mode suspends mail services and exposes only the management listener.
|
||||||
@@ -40,7 +40,7 @@ bootstrap:
|
|||||||
# certificate.yaml (letsencrypt-production, Cloudflare DNS-01).
|
# certificate.yaml (letsencrypt-production, Cloudflare DNS-01).
|
||||||
mailTls:
|
mailTls:
|
||||||
enabled: true
|
enabled: true
|
||||||
existingSecret: ENC[AES256_GCM,data:e8rzv2mvlpoZR/vMfd5sgNuYLDvptQ==,iv:qIQfpHxAOameSdDzOHh89n+RIOd9CcJcl0oRumSHAQQ=,tag:xwbQR5Jabvz+lEju5zuW2g==,type:str]
|
existingSecret: ENC[AES256_GCM,data:Y+LfFx7nuCSMGqo2o3QoHG1Br+MYlQ==,iv:dLJDYmK2gEmNq5VnbpEJWFM1xLLT5jXqxB2WQQ4dr3E=,tag:Ya2cTf/ZpJdzFnwH53iZZQ==,type:str]
|
||||||
certKey: tls.crt
|
certKey: tls.crt
|
||||||
privateKeyKey: tls.key
|
privateKeyKey: tls.key
|
||||||
mountPath: /etc/stalwart/tls/ingress
|
mountPath: /etc/stalwart/tls/ingress
|
||||||
@@ -96,7 +96,7 @@ ingress:
|
|||||||
persistence:
|
persistence:
|
||||||
enabled: true
|
enabled: true
|
||||||
accessMode: ReadWriteOnce
|
accessMode: ReadWriteOnce
|
||||||
storageClass: longhorn
|
storageClass: ""
|
||||||
size: 50Gi
|
size: 50Gi
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
@@ -120,27 +120,27 @@ podSecurityContext:
|
|||||||
type: RuntimeDefault
|
type: RuntimeDefault
|
||||||
containerSecurityContext: {}
|
containerSecurityContext: {}
|
||||||
sops:
|
sops:
|
||||||
lastmodified: "2026-07-18T14:22:17Z"
|
lastmodified: "2026-07-03T13:00:45Z"
|
||||||
mac: ENC[AES256_GCM,data:JjN4ziOnd65U8AzI9ZnMiPUBiYFGqjGjM3HJ7XoSJuJ+fgYjOH+WX/U2IAfSeqEIMkzvP435BxKGoylrwEVM1k5v07slul5zEclPZglphDjiX+md403lVDtYEXdCSo0+3nqv1DFEQDkKItEEEz882sZBbhMotBHhgcd41RSA1aY=,iv:MaSmisJoj3aobpMw1HGgEOktegX2LtOaXLh3601xgvc=,tag:acWtTiu4ub7GDNp8nM/yVA==,type:str]
|
mac: ENC[AES256_GCM,data:qoGDDt03xtJbPH+I3edSsFJagZSlCcMk4XoFc/I2QZEm+45DjsCWe9Q7e9zhn5kF3HBNBwNCgEzJmq2Fn/vemMWHwI4+QZW6nkk5cYTb3r8+WysSeUyt2+Y7EjyQGwI6+2LrCBlJIqmKfpPtT7Y8ZbwRBedoVqFtnNVH5441FMY=,iv:fvfnedCEGXyPw4yRLCtKoAnzz8h3jyJOwpqA33NNJOI=,tag:fPd7RJAMMounXVkIoKrptQ==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-07-18T14:22:17Z"
|
- created_at: "2026-07-03T13:00:45Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiAQ/9G7UtHO7Ux0YNAPlnkVmU5BI+crzwbWPhdaUZFf5dmCkg
|
hQIMA7uy4qQr71wiAQ//WA7P2WeKV6QFKotw5UP1MXcdI9THypFFly4sweJ5MC+e
|
||||||
r67EAi/DjqFHR9Ew1Dhpn0InTA/Ld+mGZAAbWeP7xhIEQ+AqACmm/Oxgf3IkHKzE
|
Lzy/zCidGCM3Cu+dJaaPJNKtfPfagQJ9FzHrnvRcHoCbKS7sTAqugdwt4uyplem9
|
||||||
P7dvco6lQO50W/m3fiU0Pv4A7w3Oq+AdFHcPr3UBi8YGYLgkCbzLs2r9JNviCJsl
|
l03kQWZfDj8R8MHQnAKWNmJDiJkjCoqHdR5f2JtS+n7MngI53SecY2fsFOXRbYJI
|
||||||
uuvz438g92aXfa5JcyUjzxtxKFjzHrZ8seDx38X4fveS/mROpRqiw+G8aQ0BlXDM
|
hfH1BR+agLjIHc+gOF340GJp4UT+Q6BZOKg8K5O4PYk1Xwj3pi6YFuhiedKHSybF
|
||||||
9wfiQtiM9CcuahPUWopv4RCOjuqrSc14sxv9xRGsYt1YZFxZ/4Q7rqM+HXBsFp4u
|
Ij9OWdTqpofeG3fhwd3jHLW+0WYiFNrVlchfClEDWMMc0UfS6Bfo96IL0JIoYlHD
|
||||||
8r4MgE+EflrhKp1aWPGnSn2kalDy3o+yFuk7IhWsrSKsNIU4j1J5xCfhliey+kNJ
|
4Zt8EEyjvAJ5478RTKTobMlsSUC5U51Wn6paapZ5zicCHDzdP2yTtwtSKK0Mdp3W
|
||||||
387cVf7Bjw+iqoy+qiV7Q7XGip6NgF8WwSudZhznv/pS6LL5H5yHaKxjz5rny/TQ
|
qt/pZoR4EyM+I2XCKp+z7N5FtH8cahtfZiUOBwQ4NK9Fz+2UBxtP2QzGj8YpJmWu
|
||||||
0upK///2YGuiE66sBb8h2sqzIgr6hZecvb2VdY7BQX4FCo2uAmxTEh+h1fHlervc
|
OkbGoSgwn+8bcNnRwnADTzdiTWf/a56WErp1NvuqF8VqdGzsJR9EgyYwENl+m+U8
|
||||||
i/03B9kNSjP5fSufhE9lsLl0oZgaFIKSpkzLlPdy6z0X5vDEXJGSL+qFudo9RKtf
|
fbTY58iAJDDpY5ipPL5v+lo0Fw5DrnQ0NPAm1ORi+rMJy0KUjgAzdS6lL5oWGfAC
|
||||||
aaEwaQ+I+snmhWyBeeywxpdyRE5g3xhRwuwaxp7zzVt5ykCnyrZIPvzaSxu/QjaF
|
rzbzThGpRt0E7O296pht8TCBFHqiKbiOdGEBXO3+w9NrvOgULno4+s88vu6KMvFL
|
||||||
jCUmvPp0ZLzAB2xY9AMwOHIrym9lPmcBEEqCiHywCauOQzsGJE3vLF8x3/nzZnvS
|
s3MHz7oIgfwel7V6bVc/ZQvHYS3YHjG41fwn00cpKI/WRN8z5MnSwwkegD2Wv8fS
|
||||||
XgEE9z1NxK8o0ntL+JZO3+GYvm28Hyw0eXgDJbjJ+tlBYeWH8lfBUOsk2V485OJZ
|
XgEqL6kQPgk97779c0jo9CJA8O6QaSvGyd1j680tN1NN9V64rJOaj/818SgwFLrA
|
||||||
4SDNvxzxpyF/4RJY4P4KR7HgwDC8gOCsDgqcyn1s4KzECXyQlqmrXxOrL8cFRhY=
|
XWaqrOnz8FIspqO836t6OaLq5WwzOtOR6zs7cUk6h1RHgwlFQ+0n1o6qYf6Q+CA=
|
||||||
=aeJw
|
=HnWo
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
||||||
|
|||||||
@@ -11,7 +11,6 @@ resources:
|
|||||||
- system/caddy
|
- system/caddy
|
||||||
- system/coredns
|
- system/coredns
|
||||||
- system/csi-driver-nfs
|
- system/csi-driver-nfs
|
||||||
- system/longhorn
|
|
||||||
- system/external-dns
|
- system/external-dns
|
||||||
- system/flux
|
- system/flux
|
||||||
- system/traefik
|
- system/traefik
|
||||||
|
|||||||
@@ -18,46 +18,46 @@ configuration:
|
|||||||
disableNewSSOUsers: false
|
disableNewSSOUsers: false
|
||||||
PublicCredentialsEnabled: false
|
PublicCredentialsEnabled: false
|
||||||
authURL: http://linkwarden.lan/api/v1/auth
|
authURL: http://linkwarden.lan/api/v1/auth
|
||||||
authSecret: ENC[AES256_GCM,data:Qaxb9o3xtrDo9rsxHFpm6tkRd7OWPDyjiIyoPvc1SiIQIthOwXyHQ0b7YAW8rGg1vKBg2fDCIUK4Kgoyr26qUw==,iv:KFt4KqTUwB830flAmxfw7tQrLktacTtWmYDjBAiugk4=,tag:IAi0x3AlCdCTXz7MBryg8A==,type:str]
|
authSecret: ENC[AES256_GCM,data:UUZagqAY6+9AM4gMv9WFsWFSzjLxAALUz2iGg3dBIrpP+JCdJWVbXIRpZ8bZPJxvwnTcZSPOsLHlqzeqJRHubA==,iv:xgPnCNp2dpy8UG/fjEHPUxdXYXEQzFn3K/EX9lfjpWo=,tag:1uFZDdgGUvMvyKHj93z4yw==,type:str]
|
||||||
sso:
|
sso:
|
||||||
enabled: true
|
enabled: true
|
||||||
authentik:
|
authentik:
|
||||||
enabled: true
|
enabled: true
|
||||||
clientId: ENC[AES256_GCM,data:1u8Xe9ZMosAJWwPGZCloAFEQE6n0eTtBzaw149zsuL/yrVoiU8s7Pg==,iv:uxfiXfpocKbiFIu0dPq0So6Kdfr3iMFUM4hRJm3eQPQ=,tag:BxgV/Wl2ZE80+08uaDnsDw==,type:str]
|
clientId: ENC[AES256_GCM,data:6XqAMjwywGgZK23ywm1GKWpIhIrXNa28Z52+0J1yhocBxLXoJAiocw==,iv:DiIpcD0H6wnIkXCMPmhLEHTzE6qKQrotGZ7q7Lv2iME=,tag:Kx80RoPf7BFMWEO1lZ4wCQ==,type:str]
|
||||||
clientSecret: ENC[AES256_GCM,data:LBIh0Jc2MtS5pvOhmFbWSrQaOMiM05e2i5aeMbDJJGNArQ7PGK+okbltWnZHonIwGU/sriFm/x4BMz+snrd+NgTUR2aPPXnomK6f9dEmSXNjLxgnVFUmgcT2P7zqlKUBjMT+SKjZLELfYGzysKTRkXHOCrOoGX8ZobEgOXGflpQ=,iv:iADfUCL30NrwPPof7r/ppO3Rt7ap4RoOkKpBuzyoO8A=,tag:lrt50iqFsZcEdBx25BY0PA==,type:str]
|
clientSecret: ENC[AES256_GCM,data:OO8vjjWVxzUNuY/Jhk348RykWnVRQ/xthunOyI4XVzCmT0WXAH/uWSupljfWQW8aj4WzUUHMpJOvFpd3iYTExFn6QqyBisOgVzS9jy4sP4qdhnSpu9jXzEUNmKyjQncl3QTQCcPZMjlGGf0oJzZgHivVWl6rFbnYQOJHDlu3r48=,iv:H2OvOpH2yxUivH8RTvSnM9k86i9jUJKcUmNPpSSos6g=,tag:XXTyOC+Hj7BvgZJ7qxEZyA==,type:str]
|
||||||
customName: Authentik
|
customName: Authentik
|
||||||
issuer: https://authentik.vhaudiquet.fr/application/o/linkwarden
|
issuer: https://authentik.vhaudiquet.fr/application/o/linkwarden
|
||||||
persistence:
|
persistence:
|
||||||
enabled: true
|
enabled: true
|
||||||
storageClass: longhorn
|
storageClass: nfs-csi
|
||||||
postgres:
|
postgres:
|
||||||
enabled: true
|
enabled: true
|
||||||
host: linkwarden-postgresql.linkwarden.svc.kube-talos.lan
|
host: linkwarden-postgresql.linkwarden.svc.kube-talos.lan
|
||||||
username: ENC[AES256_GCM,data:eUTE15OnJZ4dBQ==,iv:bN7y9EwD9rzzH3pm6JJvFkSHmdXkCunui2tyerb3z98=,tag:apU0hdiJbp5fgKjesLfdrw==,type:str]
|
username: ENC[AES256_GCM,data:N+ozpU6TgAZSLA==,iv:XJT1fUe2XqSxpuuPfmzbyrJUUInUEhLyNddOX0jogZQ=,tag:z9rCjOKISMT+wpfwUzFd1Q==,type:str]
|
||||||
password: ENC[AES256_GCM,data:qA/FQZdMQG3vdQ==,iv:S0fBAfNiNUi1t7coaKFLloaXolv7l//tUVnSui0Tmo0=,tag:SbW/QBMoNqUSENkSCR83AQ==,type:str]
|
password: ENC[AES256_GCM,data:G7dF3Oo+1wzL9g==,iv:yAjh22rwaBhKtHgYAmQEjFSMFspOpG2hThwwjAo2KJk=,tag:DdXlyNk+TfR0IuSpQG3+Zg==,type:str]
|
||||||
database: linkwarden
|
database: linkwarden
|
||||||
sops:
|
sops:
|
||||||
lastmodified: "2026-07-18T14:22:17Z"
|
lastmodified: "2025-09-15T21:48:06Z"
|
||||||
mac: ENC[AES256_GCM,data:DoHEvtWEetZGb/lCzQalLAMUlAZ7OVG66bDSaGY7s0i8mhDzRxrkvPq7FL07rnDQoLSW+SFSq6h7LB1PV1HodW35b4rmDzpCCHQ/S7Gj8WW/sX0t6dFpF1GlYeseqAMtNMPeMf095Q9LIHmQlILmjPAKbAuOg6shQ9oIesBzSDw=,iv:3D+wZjBHp0gZRDOvmVHaTIyZlC9IzMupvXfbvYYZVm4=,tag:ui9jt5/F/9NJ08P7MD+7AQ==,type:str]
|
mac: ENC[AES256_GCM,data:i9Mg17Z72cBJOSvmOlHkl0x0/FqhpCqS8iTGTYKlXacXi9E0nYYZr/y74qVjhubEaI1y6cRYXgaePI47lkyfvTzB3VGEpEs/y5fiL+PfiuV8Z18J9244+TyoasYR/a2sdRuJcY5jm6PSTKoGiwGnyZEthVwt1T38yr5msW3D79A=,iv:yj7uCySaoZcnO+7XsgB1EMfZOMwHSA0mtJXUq66MUgQ=,tag:YRvUG0/hj8Bjp+pMdJvePQ==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-07-18T14:22:16Z"
|
- created_at: "2025-09-15T21:48:06Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiAQ/+LxkvBdTDic8D31VBAtMiKJJ4nHAIpxja6gHsyVCmS+LP
|
hQIMA7uy4qQr71wiAQ//dICUFaREdeVKhKkK7iPji73IRFZEnwoZwEnR0vtCBL3d
|
||||||
VOqnEvvEBxf3ifXqwlYh/rY7ywjMyuQAW03zIlNq+9Ufv5QV9Py+UTiQV1mfmRoa
|
HXFfdXUMOVcXOvkkuF9zG52flUZBpVgilQz2W8Y7xI3tU8xX6wxmuz8LjegidCHk
|
||||||
73kINswzbUGvH+HXVkcRGjusS/StPMWKC6jwyrov09gtTF1rJUfcfenqy2waHZOk
|
R2xKAJ5iCEWZTIouFwg4fM399Mm9xhiIPuM4+25DAZnSJJAc7fQ2NaNaA8vjbJQ7
|
||||||
JhwcxhrPUnHGOsv4f1+91CCjKHux3/FVagpxJcEvxckMJweuZWm59z77dbwF1lQ3
|
YUnqkmE+QPGbyeykudlTFfl/zZzrgKbQqWuUmD/vq1XckUaPxM5cdeFDsg87AZCs
|
||||||
ws4VMLKzt2wiYSULCDr5KM2YlYWkvzheqhwnOVKXk11ewM+6n8RHIvsE03nvkfRf
|
o51lQ39b+CpWmdbDbJDF5nMWUrCzIz9okptoNfHM/5E0Jg53JBsXBvsqwWTOI5vo
|
||||||
tJduJYmXnz249SM4hq3GvyMq+j3qShIMvvKRMv6+aYMZ3SFzAIxtV0dA3lCoA9oy
|
djilDfsyu5nQj7UDstaax839T7P5gm5ass2/YtIjgrJUczyRt6vS97zuXLsbEGpH
|
||||||
mGWvImrA7JX4GsG44tEzu0ECvoFV8lEb39QKBXBf8fN6UExasF4pSm276ZGG4Eom
|
6hXHan7OormqbmISnFrL68Q4w6JUZev43bdzqtX0EnYHNZVLXH3qAxD5EnuL/i20
|
||||||
IpfpuaB9oYL4TOEH0/56IEc2BRlvAm62ibra5jNCVLnLB0pzE3KdN7ZYMQyXooZi
|
oY/oMEteFh86Smw/LXwtWjVfPKYzNQ6GTkTCzM3hVcfMOzdFVPgYDM+5EXF+/oAB
|
||||||
dOa56z4KidI4N5oDTc63Hkg0tApdV0x+Rtm7qgdhEp/1i4zqciQqb8//yN6CAb7I
|
+BGqZvWW4G3G9sbPTRSJ1k+toWuC/erY41r+g3+KHbW73YdqIVwBsTDAFhPPNbe5
|
||||||
DkyPilrvNkZw95iGqpKVLrAp57BaFHLYNr0O7+WS9urCIUQl3Q37Nz2HyNLJt0Ej
|
hnr1JFLQ75GHdDRnKRl3nZSPc2j9JMUtMhX+rKwLb/0DoVjNz0lFut/Tj+6xiG/1
|
||||||
i3VgiJUIoy5NcAIBIFvuAJDsXB+FQxzg+7XUZL44xxsSvA248Shz1CYH9CgwbszS
|
SqHTpROU1tkip+rP0shzdu218+hjrzj+cDKkawoqmpD9gOm83P7YEqrIwcBj+TPS
|
||||||
XgHdJTIcrq3ReybtFVDPtqMkLyItA1fbJzpCr4Fwk922hmEpqBeMHx1Upy81MZJj
|
XgE3UHtwHdJM38kfPm1fkTuCejlAQ3Hsz6W4PSbXJfY8w1gO241dEzy+b0At9Rv2
|
||||||
T+4v8xBo7KR/6sx3U9kO/TjV7AhdTJPRlgG0WfnfLMncCkrvg4cQWxEIkySShFo=
|
6IklhRBAs4ioH/hD653yz0mkCYRpOLYDJU2iMWZdv61YLXb4rsnAwr6xLbDHDXM=
|
||||||
=XPzS
|
=69Pc
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
# This file contains all route definitions, imported by the main Caddyfile.
|
# This file contains all route definitions, imported by the main Caddyfile.
|
||||||
# Edit this file to add/modify routes.
|
# Edit this file to add/modify routes.
|
||||||
#
|
#
|
||||||
# Certificate files are mounted from cert-manager-managed TLS Secrets
|
# Certificate files are mounted from the caddy-certificates Secret
|
||||||
# at /etc/caddy/certs/
|
# at /etc/caddy/certs/
|
||||||
|
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
|
|||||||
File diff suppressed because one or more lines are too long
@@ -10,7 +10,7 @@ image:
|
|||||||
repository: caddy
|
repository: caddy
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
tagSuffix: ""
|
tagSuffix: ""
|
||||||
tag: 2.11.2
|
tag: 2.11.4
|
||||||
service:
|
service:
|
||||||
type: LoadBalancer
|
type: LoadBalancer
|
||||||
externalTrafficPolicy: Local
|
externalTrafficPolicy: Local
|
||||||
@@ -35,25 +35,25 @@ health:
|
|||||||
volumes:
|
volumes:
|
||||||
- name: vhaudiquet-fr-tls
|
- name: vhaudiquet-fr-tls
|
||||||
secret:
|
secret:
|
||||||
secretName: ENC[AES256_GCM,data:VQPfRq0dCtIN5nnubua5o34=,iv:TMieVEMpFldPMT4YJnEd6ecvOC9PWhpWpCe4u30Rg2E=,tag:7ZMIryVzEtGBZTzLj5a76g==,type:str]
|
secretName: ENC[AES256_GCM,data:mdTS+RBfbQiY0c5aezbTURE=,iv:gQRWoRmGujhptSXm16JhX6VSHbB4yMdC3T7tPH1vfJs=,tag:DViHZOwOIPmHJQWTPUO8cw==,type:str]
|
||||||
optional: ENC[AES256_GCM,data:EPxqBw==,iv:HYAyOFMAMMXPLFCcmgqC5XNTqenL5A/ZqK7Td/x81mg=,tag:uRdyTRPjbP1bUreP9cwj2w==,type:bool]
|
optional: ENC[AES256_GCM,data:apLSVg==,iv:4ZZa85zmTuYb7D/p4mLZO++esFrPQyQ5xHCtT+aghS4=,tag:wWAEf3XWYKvsjwpfpyCb7w==,type:bool]
|
||||||
- name: wildcard-vhaudiquet-fr-tls
|
- name: wildcard-vhaudiquet-fr-tls
|
||||||
secret:
|
secret:
|
||||||
secretName: ENC[AES256_GCM,data:ohWn2gmc4WkRV59KTd9sRsbbHQqwiIMLpl0=,iv:hmLbftvEF7kDz2ZqrPCUhwD2QV/S34QQVcCKyYcSR0U=,tag:Ok8enop6KDGqwCpoCS+52Q==,type:str]
|
secretName: ENC[AES256_GCM,data:Ww5/viWqr5mI51FqHizTRerAZnEyQONqdEg=,iv:VAMLvZ9yJxUCh7Kjf43J+M+ellkm5Xi3ZD5AlO95Rm4=,tag:F6H8LBi9kL9rrXJgVSbAmA==,type:str]
|
||||||
optional: ENC[AES256_GCM,data:6W/i/Q==,iv:zcVzTOGfC4ki4ZfY3PkMyhNC0u1t39QG1Uoxb07QrWo=,tag:I6pcotOaeaTErrQBu8itdw==,type:bool]
|
optional: ENC[AES256_GCM,data:LQEFAA==,iv:JkudOsHgn8qLEwqWhsuWnXjpCLJ3XrEexXtzjmOD+/Y=,tag:amUBIkXQIZnGQtxAAQ5mcw==,type:bool]
|
||||||
# semery.fr certs from cert-manager (OVH DNS-01)
|
# semery.fr certs from cert-manager (OVH DNS-01)
|
||||||
- name: semery-fr-tls
|
- name: semery-fr-tls
|
||||||
secret:
|
secret:
|
||||||
secretName: ENC[AES256_GCM,data:w5YPfljvWgH0V5tkKw==,iv:atxebg81R2BztmDPORRFs/HJRNHIejvdL+wPz/NoRFU=,tag:VJynVAHGoh/yQmibnz4CDA==,type:str]
|
secretName: ENC[AES256_GCM,data:dmLfoVbH9QKPMXPZZw==,iv:l9BKz66sdl9SssNzaz8yWoQ84ewDQprMv3rcHJQZhRA=,tag:NudQDM8eKC5aF6vX2ZQVVg==,type:str]
|
||||||
optional: ENC[AES256_GCM,data:U+HoTA==,iv:I6lUk9k1eL5U4OYeZW96CLPdGmHZ1TJVaPGesMH623g=,tag:8IIpdcPoD65vDPy40utJIQ==,type:bool]
|
optional: ENC[AES256_GCM,data:Xc2tmw==,iv:xSa/xz/WibDqExKXjKSwLm5w8DOw9aZY44O1TZalfO8=,tag:Mpqi2ipn82+eWv8T2YvSng==,type:bool]
|
||||||
- name: wildcard-semery-fr-tls
|
- name: wildcard-semery-fr-tls
|
||||||
secret:
|
secret:
|
||||||
secretName: ENC[AES256_GCM,data:lD0v/r4YvzPN+Xa617BEjjwDQfZARQ==,iv:ByAUmmfli9pU1on7I3h2cbATaHqXGIEzDS79zoCxyU4=,tag:6+ZSzIwhaD2XVJbn4/iEcg==,type:str]
|
secretName: ENC[AES256_GCM,data:jwwNceE6ZAD0bdUFceBBG+HQPjmLSQ==,iv:15rvS8NjtKszT8LFS9Z3DLCVMBwQ0GnY+o3DSr+G3jA=,tag:GMZ68i+1XmcvIJrOZxBo1w==,type:str]
|
||||||
optional: ENC[AES256_GCM,data:J5m77g==,iv:dqGRx5zVtr2IbR4fruHuJ+9lX4N2RUqDXFbFqJcL7I4=,tag:vc5pCXQzqmJxOadRa5OetQ==,type:bool]
|
optional: ENC[AES256_GCM,data:8p7hYQ==,iv:a3Al2ph6xuJCXkLaFW6K7WSJss51/d9kVrX3Xuh/5e4=,tag:JYUYRsmEN7brNrENFPe/DA==,type:bool]
|
||||||
- name: buildpath-win-tls
|
- name: buildpath-win-tls
|
||||||
secret:
|
secret:
|
||||||
secretName: ENC[AES256_GCM,data:ylwpc1mncHCXEoucDxVJanM=,iv:+vzMspw9NPcT6LGvLJv+5CPSmKmMsUgl0usMHTAOoGo=,tag:mvdt+ty2+LdANic5Mk7avA==,type:str]
|
secretName: ENC[AES256_GCM,data:kTI0dBzdTAYXuvSZwZC9REg=,iv:xf4pQABQGiuv3IJtiZhNMsLeDPVef2awVW1DmDThOHI=,tag:74IqPca8TuCFuIpJ8RpQ2Q==,type:str]
|
||||||
optional: ENC[AES256_GCM,data:B/DGpQ==,iv:2h1FOz4onqxRUyDVTXdTKGphUnHNKDDEF6IPPnze24g=,tag:AINZfLh8wen4ClUeGejdxg==,type:bool]
|
optional: ENC[AES256_GCM,data:mxxqOA==,iv:p1omSzhLh4yYs303OZCE5DfCNrzjAxEo+TOfezw/oCo=,tag:4ye1QalWmtW98B37DtkcuQ==,type:bool]
|
||||||
- name: routes
|
- name: routes
|
||||||
configMap:
|
configMap:
|
||||||
name: caddy-routes
|
name: caddy-routes
|
||||||
@@ -100,33 +100,28 @@ affinity:
|
|||||||
matchLabels:
|
matchLabels:
|
||||||
app.kubernetes.io/name: caddy
|
app.kubernetes.io/name: caddy
|
||||||
topologyKey: kubernetes.io/hostname
|
topologyKey: kubernetes.io/hostname
|
||||||
tolerations:
|
|
||||||
- key: ENC[AES256_GCM,data:huw9H7nWgpK2,iv:mLMip5c1ubS8ZnipsDIBpmy6qdP5viG73Dn9dBJJbLo=,tag:MAFiUjJX/1updYbzpSCS8w==,type:str]
|
|
||||||
operator: Equal
|
|
||||||
value: ENC[AES256_GCM,data:6ScxT0nUuKU=,iv:skaDlzXbBXGQHjk/SnKrNCvHVe3JovnWMtpA6zhqlFo=,tag:LAW6xol1cASA/tYwab7AVQ==,type:str]
|
|
||||||
effect: NoSchedule
|
|
||||||
sops:
|
sops:
|
||||||
lastmodified: "2026-07-22T15:24:50Z"
|
lastmodified: "2026-07-09T21:17:10Z"
|
||||||
mac: ENC[AES256_GCM,data:K3c6hp9KPe9s992kaGJ60jCLN2FAvKnTLA44EQ0IG7FPHL5FFMbWNBxukQmI2q5E0U6oLzO7JlmOh4ZGRScIi2Z2gRz9td6DTYNBYvgO45kLFJrRAe7D0V5cb28WW44w1OhN+4ETw7VuU24kwKGHYergn5eBo1JtNLnty96ToLY=,iv:X2MkW15mPps4gVR4Pscx72t78wsLWlcRrxZJVKTMC1I=,tag:8ku82p8BIasJ3a/pkDSZTw==,type:str]
|
mac: ENC[AES256_GCM,data:5APgoOMa+m5xjn+wurqyOtBoohpV271AnW1Ic4Thcg88bXryhr4Xn86Yo7fMbE+N3YqJMCaeaH6hm4iY8IIhCHgO2ybgMq50Bo8AqWxr6MKEpTJDQS5vSSWPq/Y5qr7B3f5/gOyxwIGslF4isVRaQzlcjoKzfvHsZX8SPdFhXT8=,iv:ZuareabZmxIyhh8kZs+eHGeUI7NZhzxER6KJE1/EiWE=,tag:zQuTYSrU76YEf1u2312ruw==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-07-22T15:24:50Z"
|
- created_at: "2026-07-09T21:17:10Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiARAAsoEMSw07cHFenSUrbW+prBls/qB4YT0vkZ4Pjpp2zyzw
|
hQIMA7uy4qQr71wiAQ//eR5eIclcLkl8wtERUoVHXL5KGKzEaxyVv9D5gHz51C31
|
||||||
UTTASjXSYXYGutOkQgO42vtKE5HkEh+FB2qhWnLy9on4xPR/epFJox0Y+EFWPLQJ
|
kmAfrAnjT9G5UeeoJlW8XLkh1IWNhArNBMtoiCNUPAtfVDxszs5IwPWul+s3wJhc
|
||||||
fu7Q+C+aG9JqoFgsBX+7JAPMHcH/afT4SGvvfOMTC3+aOLiFFyicbqZtkumw9bCr
|
X7sDq7EnIgaJr2IszIOTJ4PYxZ/uhyMdqmvRTZXMaz43F96cuDLctV4CFaiig4aJ
|
||||||
jD7VLRvPALTLokPdoer3cmY99bIQ9+51ms/cc1/SNXv8qxR+CKG1wnqtYBSdhUtY
|
IcNlPIyYyS4tuaGB+ScLtbcDDhNc/8VRWn09SRtpTop+PV4KRX6AqLmhGOc9Jf9l
|
||||||
vTIuEY3uIrYfxJlKlsyCRQj1RPj6o64+IsLcwXTNV5WHuy7srrsSMf7qFsD9f4ZV
|
Dg3Gqdkaxl3OuqIvcrTmEPBe3sjnjIIdtJeG4SAbMUzj1xoKupXeDBZDnfmS5nku
|
||||||
7a17K/6JaRom62YqPn73HoyktBf71oPePwl8xeHqs3En/VS1T8MRa7dQjD7Qb4Xo
|
42WR5H4RInzusj5NXP50C7AeLD4qavB9hl5CaxzA6TVG1X7LcpmcqBsVVuFcSjZj
|
||||||
00eLRGTOqTJlVmtMOg6ZqQiROmAS9W9X0ZOv4uxLK2fDG48WrDIcZMuBzI4OQaY+
|
T80iKklV6Ct0MLlmbxlKFTJm8fSKevhS/hdfrkUNcqc4N6eBb8tx93x+FcDn0A6P
|
||||||
prSeVvkcZm9cTrNHj8ZWxgWHp04qPBFWg0tqXSyXnr0cXjLUI/cOqis5+segHeSt
|
c1zPSKj1vs326nJSHw87wvooQWn/f9j+Om1KLOR/MiUWmoEAbgkIHi3+k2wpzFb/
|
||||||
B8n8E/rLZqhvBrB58/3PaWvSRWVEAD2L1zBbNrfCleDsHIN+SgfPkPdvzEv4JYk8
|
faKpshye0/XA/CZHFePv/U7sw8nKhfPhJCuO/IRrHKYzx0u/aqgOtPCURh5hS/fU
|
||||||
bVauG9wZh6Z3fgoT0NgzG8XtquIShviw2q5EOE3VEh1X1O90aLOpvQH4YJddgSBB
|
8dPQkbywgN67IRRKVz70cxn367cP1vn7L1AmzJfBd56NnViXXlS/DuitpnyTQpnP
|
||||||
i8VjACMnq+NPODJVIJCzqI5bHyhq1K666/HpMTR2H9eWCCmfB6HVhpJ37tdA/S/S
|
tLG6qelq3Ul2A1J3BB1pfHR27IpKzd1UPD7HMhvvgSA7ErLq/VhF/kT1dx6s1fXS
|
||||||
XgHwqbomlaxeU6e5pkUXHaxO336ObSA6/75/UZQSdQUqwZVkFOzQDE6CADE+p/qG
|
XgFZ5XcyJQRc4Uxh2eFeEPOdWMAFRps6scfBsQuWR8m3cQvLatzcku1S/YDp56Kn
|
||||||
mYahltV1nQRdkLa8bNC6oLtPteeKP9DhmYV60LaB1ZYE5qE5CAypl7YLy2+Ql0Y=
|
oUZmfvdQGpUuxsumVYCqk1+mQn02lkA1p2Y4ztrpLDCbhZXZ/fIT6Y1uYX+c0ew=
|
||||||
=oRLO
|
=0kw6
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
||||||
|
|||||||
@@ -22,23 +22,19 @@ spec:
|
|||||||
dnsZones:
|
dnsZones:
|
||||||
- vhaudiquet.fr
|
- vhaudiquet.fr
|
||||||
- buildpath.win
|
- buildpath.win
|
||||||
# OVH solver for semery.fr (via cert-manager-webhook-ovh)
|
# OVH solver for semery.fr
|
||||||
- dns01:
|
- dns01:
|
||||||
webhook:
|
ovh:
|
||||||
groupName: acme.aureq.com
|
endpoint: ovh-eu
|
||||||
solverName: ovh
|
applicationKeyRef:
|
||||||
config:
|
name: ovh-credentials
|
||||||
endpoint: ovh-eu
|
key: applicationKey
|
||||||
authenticationMethod: application
|
applicationSecretRef:
|
||||||
applicationKeyRef:
|
name: ovh-credentials
|
||||||
name: ovh-credentials
|
key: applicationSecret
|
||||||
key: applicationKey
|
consumerKeyRef:
|
||||||
applicationSecretRef:
|
name: ovh-credentials
|
||||||
name: ovh-credentials
|
key: consumerKey
|
||||||
key: applicationSecret
|
|
||||||
applicationConsumerKeyRef:
|
|
||||||
name: ovh-credentials
|
|
||||||
key: consumerKey
|
|
||||||
selector:
|
selector:
|
||||||
dnsZones:
|
dnsZones:
|
||||||
- semery.fr
|
- semery.fr
|
||||||
|
|||||||
@@ -3,5 +3,3 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
- clusterissuer.yaml
|
- clusterissuer.yaml
|
||||||
- ovh-credentials-secret.yaml
|
|
||||||
- ovh-secret-reader-rbac.yaml
|
|
||||||
|
|||||||
@@ -1,50 +0,0 @@
|
|||||||
# OVH API Credentials for DNS-01 Challenges
|
|
||||||
#
|
|
||||||
# OVH API credentials with the following permissions:
|
|
||||||
# - GET, POST, PUT, DELETE on /domain/zone/*
|
|
||||||
#
|
|
||||||
# The secret MUST live in the cert-manager-webhook-ovh namespace (cert-manager),
|
|
||||||
# because for a ClusterIssuer cert-manager sets the webhook's ResourceNamespace
|
|
||||||
# to the webhook's own namespace, and the webhook looks up credential secrets
|
|
||||||
# there (see ch.ResourceNamespace in the webhook's ovhClient() function).
|
|
||||||
#
|
|
||||||
# SOPS will encrypt the stringData fields on pre-commit.
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: ovh-credentials
|
|
||||||
namespace: cert-manager
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: cert-manager-webhook-ovh
|
|
||||||
app.kubernetes.io/component: ovh-credentials
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
applicationKey: ENC[AES256_GCM,data:0+y+m8n/eup5lY/vGW5ASQ==,iv:VSIhfNAvSNOLq92TVcaW54ygU1wgAv+u35HZ0cbP6UU=,tag:KD+cyIesTQgqEzGMro8xyA==,type:str]
|
|
||||||
applicationSecret: ENC[AES256_GCM,data:sP0febHRFF/atAFlRM6sYXoM+Lp6Rnf7d0IQKcsa0vY=,iv:nHYMHSsOclkZmQJSjcz2oXMHsDTct5hTmJz1L7xgvpA=,tag:oCGoRP7R0W+PTNRCeLFvyg==,type:str]
|
|
||||||
consumerKey: ENC[AES256_GCM,data:vw/Q39CpSc5o1ntPDMT3844aLbTHQrSYH8RhoZFFZrQ=,iv:6B0F9Zq56inpW7AS8okbpqJkRK3WkBjX6sIqclOP9Hs=,tag:nnbgwBMBM4JZg/IEYzRvVw==,type:str]
|
|
||||||
sops:
|
|
||||||
lastmodified: "2026-07-10T05:06:52Z"
|
|
||||||
mac: ENC[AES256_GCM,data:0/VEDE1ZuIyzkaleosS/KHYX44762TbScrJGJylwV21d7U6YgpwRMOXvU9xn3rHsDXnh5IAmAtrXQTYJFN1vcF1DNw5O9+TQKVoO6B5rsel/YyKRU4s7aYcfDgbW9dO1wn33K65KFtM+0Qv187DzEn1by449TgWIWP/M5U40PE4=,iv:hIGzMwsas8VxC4941ABeoocYWSlVSz9KW7a5tTAoRXI=,tag:n/EJEkEBL20carqVesMBsw==,type:str]
|
|
||||||
pgp:
|
|
||||||
- created_at: "2026-07-10T05:06:52Z"
|
|
||||||
enc: |-
|
|
||||||
-----BEGIN PGP MESSAGE-----
|
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiARAAu0va03SPYOU23iUjoTMiXJ6+nMhIX8lsurvmCvi+wIqk
|
|
||||||
c7qu0lTfXv62IjkY6fIKtOE7TN9TiipjzXG2QJaK94QeiFpe9M90qNo09qEIje9m
|
|
||||||
DepTrLfyINFT0SY2eihl+nXhBXuEDSiD5K60OsXGPN92hJMwCad5jJuB7xpmrX0m
|
|
||||||
X0A1Bl9orce/do/YJoy5hq0persB/VSeCKlptNzqpmpRIA3J6AdCDKXQOMqAymXN
|
|
||||||
FXAxbjEQNcXhfU12Y/cVpa1hS7ap5OJCnWOPkFEA8y1ESVnPpryuTIfVlFUhW3/Z
|
|
||||||
Dhpb9OXKdi2IVYdbaY8+3UfSsXxTVOge7jCMbJq3aa7ZvGt5fTjXG4zc9A6RqSGh
|
|
||||||
ASOPSkRRSZB0d97NhUQJGgfcaWFvsfkaTAUVB2Ip/+Udnt/tGIE99RGJizxSVO9N
|
|
||||||
2aVJIukqng8aNPfth8mgWYJpCETMb4piLmVg2ptDqelCqXlUAskxWzMWtAhyzOgw
|
|
||||||
lZ2dcAn7aj9YtLaKAW9rjV8EqHEqQg0ychRNMeyRiN/CnNJp6Q2wl1/EyQUpzb0a
|
|
||||||
1I/ifFAW8FbWTVIbZv6njkl1XNaoav54qEn1qSABcljM0h1Ulb9WKMJiXH4368jf
|
|
||||||
Yhl38JDAn5NZBEzxpuaih1XK5yVri0/1ascpuMvfOxLKniUR9tla8+WEL97+aejS
|
|
||||||
XgGsrH+/uzRVSAT+44rExi43MWCAwNRUaVrX8UiGjA/z8qPVdwBVih4CMKgfQ8VW
|
|
||||||
1KewStOY217BXuVrDbvHEAkuOotEP0Jnan0epoWs47DSasNgzAcWrBgom0l/avI=
|
|
||||||
=Gdou
|
|
||||||
-----END PGP MESSAGE-----
|
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
|
||||||
encrypted_regex: ^(data|stringData|.*.key|.*.crt)$
|
|
||||||
version: 3.10.2
|
|
||||||
@@ -1,41 +0,0 @@
|
|||||||
# RBAC granting the cert-manager-webhook-ovh service account read access to the
|
|
||||||
# OVH credentials secret.
|
|
||||||
#
|
|
||||||
# The cert-manager-webhook-ovh chart only auto-creates this secret-reader Role
|
|
||||||
# when using its built-in `issuers[]` mechanism. Since we manage the
|
|
||||||
# ClusterIssuer and the credentials secret manually, we declare the RBAC here.
|
|
||||||
#
|
|
||||||
# The webhook runs in the cert-manager namespace under the
|
|
||||||
# `cert-manager-webhook-ovh` service account (created by the Helm release).
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh:ovh-secret-reader
|
|
||||||
namespace: cert-manager
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: cert-manager-webhook-ovh
|
|
||||||
app.kubernetes.io/component: ovh-secret-reader
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["secrets"]
|
|
||||||
verbs: ["get", "watch"]
|
|
||||||
resourceNames:
|
|
||||||
- ovh-credentials
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh:ovh-secret-reader
|
|
||||||
namespace: cert-manager
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: cert-manager-webhook-ovh
|
|
||||||
app.kubernetes.io/component: ovh-secret-reader
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: cert-manager-webhook-ovh:ovh-secret-reader
|
|
||||||
subjects:
|
|
||||||
- apiGroup: ""
|
|
||||||
kind: ServiceAccount
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: cert-manager
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
namespace: cert-manager
|
|
||||||
resources:
|
|
||||||
- repository.yaml
|
|
||||||
- release.yaml
|
|
||||||
secretGenerator:
|
|
||||||
- name: cert-manager-webhook-ovh-values
|
|
||||||
files:
|
|
||||||
- values.yaml=values.yaml
|
|
||||||
configurations:
|
|
||||||
- kustomizeconfig.yaml
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
nameReference:
|
|
||||||
- kind: HelmRepository
|
|
||||||
version: v1
|
|
||||||
fieldSpecs:
|
|
||||||
- path: spec/chart/spec/sourceRef/name
|
|
||||||
kind: HelmRelease
|
|
||||||
- kind: Secret
|
|
||||||
version: v1
|
|
||||||
fieldSpecs:
|
|
||||||
- path: spec/valuesFrom/name
|
|
||||||
kind: HelmRelease
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
apiVersion: helm.toolkit.fluxcd.io/v2
|
|
||||||
kind: HelmRelease
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: cert-manager
|
|
||||||
spec:
|
|
||||||
interval: 1m
|
|
||||||
chart:
|
|
||||||
spec:
|
|
||||||
sourceRef:
|
|
||||||
kind: HelmRepository
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: cert-manager
|
|
||||||
chart: cert-manager-webhook-ovh
|
|
||||||
version: "v0.9.13"
|
|
||||||
interval: 1m
|
|
||||||
valuesFrom:
|
|
||||||
- kind: Secret
|
|
||||||
name: cert-manager-webhook-ovh-values
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
apiVersion: source.toolkit.fluxcd.io/v1
|
|
||||||
kind: HelmRepository
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: cert-manager
|
|
||||||
spec:
|
|
||||||
interval: 1m
|
|
||||||
url: https://aureq.github.io/cert-manager-webhook-ovh
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
# cert-manager-webhook-ovh Values
|
|
||||||
# groupName must match the ClusterIssuer webhook stanza
|
|
||||||
groupName: acme.aureq.com
|
|
||||||
# cert-manager deployment configuration for RBAC
|
|
||||||
# The webhook creates ClusterRole/RoleBinding so cert-manager's
|
|
||||||
# service account can create the "ovh" ChallengePayload resources
|
|
||||||
certManager:
|
|
||||||
namespace: cert-manager
|
|
||||||
serviceAccountName: cert-manager
|
|
||||||
# Pod configuration
|
|
||||||
pod:
|
|
||||||
replicas: 1
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 10m
|
|
||||||
memory: 32Mi
|
|
||||||
limits:
|
|
||||||
cpu: 100m
|
|
||||||
memory: 128Mi
|
|
||||||
sops:
|
|
||||||
lastmodified: "2026-07-09T22:31:08Z"
|
|
||||||
mac: ENC[AES256_GCM,data:QjrNj355tJVZRsYQdkM73Ld7X8EvMM7O/1vF3QnTYJ9vWbh78irLocbtnyBeaR9o3g0mxO6Ugjlukj+S0HhIX/WS1XHEfs/3n3rE0zS/fxGJ0D3Alam/n/WPOsYHUiCBD86JtU83AjgncISY4yp/VheV3kRgSdl+ye4AGAjhq7A=,iv:p8yqNCcskTfDfEGbM5Qyb60C4pFv4BOuLpEApEzHLFY=,tag:KntExeQwJbBREaz2nY+1uQ==,type:str]
|
|
||||||
pgp:
|
|
||||||
- created_at: "2026-07-09T22:31:08Z"
|
|
||||||
enc: |-
|
|
||||||
-----BEGIN PGP MESSAGE-----
|
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiAQ/8Dn4nEIbQXuETxE6RUBkNTO/eN5pHh47lqSwBBbYDSi8C
|
|
||||||
8rcJmdq8P+v00geLdMlM35OcjHFb9UCVeHFsAEYt6Q2jL4QNa2aOEDOqGnhKP+zx
|
|
||||||
KKtW2Ngx76Ow9N2C5JN9DXk9n+PC/qWdPLNJY+GiW/KbPmVxAulJpmYlJHfs1EOh
|
|
||||||
0mSRSS+7sgGLHWmgU362zC508lkKxh8HKxmq1+1lf+fWIe8N7Sl0fx55kq168hae
|
|
||||||
NcdogRpoVT555hRils7eqzj0C/KTVOi7CR4pS7VJyiNy2fu2OASmmcM6UEqCyJfV
|
|
||||||
NTUdMpnjb05UwfbuUnIg6j/FoqS49ufGxKPrM9t7JrFSuyGqduF7P/ifv5zwMuIZ
|
|
||||||
SNeR/X8xUksK6R4/uTmUx5sgF+Jv7tCRvcp+DhsDe1mMmO8czXC5Mt3cR+uwYoms
|
|
||||||
hN+9/oYEZr13qn5Ek0dy9NESkZIzYPCXYXZrx8GLqaHCJEQbpIZCAN+llOyQaQzU
|
|
||||||
jcvPAYbTewBw4ewKUS0KcvLd1pfzvYyvtzwHuMIVJwrf7x5bzhzxAgVOGkEVlVq/
|
|
||||||
7pGO9TYXGl3kD7tf25oCGzAerVC+EVcL11sq4zawvL4PovEZFP9mzhR7EfY3t/3C
|
|
||||||
vGVu6vPmCJOwdis9+Kdr3PKubnMqWGn5KCCX1x13qhsHc239N7cVKkyx3dTBaArS
|
|
||||||
XAG6KxKe/cQicIVC8/N1Cna9uQnTF5ZnFVfJNW1nkYyF1E+ofW6kKDr3ITotKLDP
|
|
||||||
hXXPT+vsB2fL3faBG4xb6owrMuQ1S0DmB3mqjSCXtpS7q0FDg22Tq9BtaEni
|
|
||||||
=x1th
|
|
||||||
-----END PGP MESSAGE-----
|
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
|
||||||
version: 3.10.2
|
|
||||||
@@ -6,6 +6,7 @@ resources:
|
|||||||
- repository.yaml
|
- repository.yaml
|
||||||
- release.yaml
|
- release.yaml
|
||||||
- cloudflare-api-token-secret.yaml
|
- cloudflare-api-token-secret.yaml
|
||||||
|
- ovh-credentials-secret.yaml
|
||||||
secretGenerator:
|
secretGenerator:
|
||||||
- name: cert-manager-values
|
- name: cert-manager-values
|
||||||
files:
|
files:
|
||||||
|
|||||||
@@ -0,0 +1,45 @@
|
|||||||
|
# OVH API Credentials for DNS-01 Challenges
|
||||||
|
#
|
||||||
|
# OVH API credentials with the following permissions:
|
||||||
|
# - GET, POST, PUT, DELETE on /domain/zone/*
|
||||||
|
#
|
||||||
|
# SOPS will encrypt them on pre-commit.
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: ovh-credentials
|
||||||
|
namespace: cert-manager
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: cert-manager
|
||||||
|
app.kubernetes.io/component: ovh-credentials
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
applicationKey: ENC[AES256_GCM,data:YhH6Ty+JJOelaq7G975wLw==,iv:zbwPRv1tdsyoN+rFoOIItzYC7wmv20zMX/ij6RnC8cI=,tag:n+NIrIp9IgunK9ZD15cULA==,type:str]
|
||||||
|
applicationSecret: ENC[AES256_GCM,data:5jxfV5a0jyCtXQKZJjxNmNTiyZ71nLoP0A/KYm+oQ9k=,iv:77SewJ13vouMbEey2oZav32bHsi/cvyKgE1VQapdzhw=,tag:Be58t/rpZrbHun3mMzrWww==,type:str]
|
||||||
|
consumerKey: ENC[AES256_GCM,data:zYTI4cHz36Is5pwUObL9XPDi6XEftonrjz+32jsNkEM=,iv:saNZrLThBa0b+D7S37IO2WpUmnm7ixshMbJaryZzYuE=,tag:v/BhwdJVlxDaeBi570b3Ig==,type:str]
|
||||||
|
sops:
|
||||||
|
lastmodified: "2026-07-09T21:17:10Z"
|
||||||
|
mac: ENC[AES256_GCM,data:pakPqwigSb9Q1nuAcT4w4VumqQ1f1AGGx3WqNASs04eN/RxhWE+LQbY8BgNQ/YUx6HveypU6UH+ppMgPDwCZS7tUwTR/tXpDp/r3WIlhoQghtNGVp/eCpj9Tu91rnjc9Prv9wH8AWaJESeuK5dhZm+LAIvUczP3a+mUhQkXTtok=,iv:WQPfvLOODtvv88+vcTHMfiYcskS394mw+xBPacgCEgw=,tag:l5VMpNnInaeTXWWfkVonrw==,type:str]
|
||||||
|
pgp:
|
||||||
|
- created_at: "2026-07-09T21:17:10Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMA7uy4qQr71wiARAAn1Wjcdq7Asc920TamGFdlQiDJa4T5iZKJohtXWbJXMSK
|
||||||
|
fqdDgMGWb5OdiCFprRkysckxsY0sWBzc/lOXlj2rw0UV2q66Rxrq19esvUDTfGfK
|
||||||
|
K1cKJ/tegcQ4heQsC+QUgC9SBZlqiA88yDGSO9j9hyBcaSWgkeTUWvrEBFeyLHDn
|
||||||
|
Yha0gxJibNSqmv+B6d5HepkwW6tpESXNX1NFJbYCx46nA6nrttbZCOxzQbS/oBKC
|
||||||
|
pmG4NzU6rQE57zcGpZOGYX8sQWjas0mhPiSAgFOdCdINuWFnONC1jUj5EnBM4LZH
|
||||||
|
+pkZtVmEl7D2SpPNtslTqJKCUbyIHGabblM76p2NKVL8vrTR3k2AM+aL5jS4536d
|
||||||
|
fRRWiWZihsn9PUHsSVLGZPkFe2ceHtM1JjGaX/M+0ZDag3gDUSCR8GdVbDd/95Xs
|
||||||
|
GeGGcVzmuTP16bYsTkXOMixvx7/q3yqAWP2FDvgJqJ3oataRlYwpVZBWDQo50eSb
|
||||||
|
w1fzARbMRz+OWNd+uFgWiHddFR12Xow1tfCSog9WAFjZQ++yjrRsqMH/x8NgWb0l
|
||||||
|
oq/vkHAg4WDqlKUa47vW56c8pZqsiWP8d8V/7b8avhHDdCb+SNOSe5QxO2AA8EAr
|
||||||
|
bjdwSpsErZNFWasYKqfs5ye4ct2tpCI5llRoR6WwnmM3mJflZAt983TPiZC8QLLS
|
||||||
|
XAHLR9ap5zx2shcdyyGOV5+7VmkDaSeB1baxeiORaQKK7CvVblhuIz0ZS097KUI5
|
||||||
|
HBTYvvIdEdXMn3hRalYzyuayKCiC6WEl/UKzXLiCiu94ijbaKqlOtW07anP/
|
||||||
|
=B+/W
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
|
encrypted_regex: ^(data|stringData|.*.key|.*.crt)$
|
||||||
|
version: 3.10.2
|
||||||
@@ -54,7 +54,6 @@ spec:
|
|||||||
- metadata:
|
- metadata:
|
||||||
name: etcd-data
|
name: etcd-data
|
||||||
spec:
|
spec:
|
||||||
storageClassName: longhorn
|
|
||||||
accessModes: ["ReadWriteOnce"]
|
accessModes: ["ReadWriteOnce"]
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
|
|||||||
@@ -30,9 +30,6 @@ data:
|
|||||||
docker-r740 IN A 10.1.2.212
|
docker-r740 IN A 10.1.2.212
|
||||||
truenas IN A 10.1.2.139
|
truenas IN A 10.1.2.139
|
||||||
|
|
||||||
; P330
|
|
||||||
p330 IN A 10.1.2.132
|
|
||||||
|
|
||||||
; PVE
|
; PVE
|
||||||
pve IN A 10.1.2.10
|
pve IN A 10.1.2.10
|
||||||
docker-homeprod IN A 10.1.2.12
|
docker-homeprod IN A 10.1.2.12
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ storageClass:
|
|||||||
create: true
|
create: true
|
||||||
name: nfs-csi
|
name: nfs-csi
|
||||||
annotations:
|
annotations:
|
||||||
storageclass.kubernetes.io/is-default-class: "false"
|
storageclass.kubernetes.io/is-default-class: "true"
|
||||||
parameters:
|
parameters:
|
||||||
server: truenas.lan
|
server: truenas.lan
|
||||||
share: /mnt/fast_app_data/kube/
|
share: /mnt/fast_app_data/kube/
|
||||||
|
|||||||
@@ -14,7 +14,6 @@ spec:
|
|||||||
path: ./kubernetes/system/cert-manager-issuer
|
path: ./kubernetes/system/cert-manager-issuer
|
||||||
dependsOn:
|
dependsOn:
|
||||||
- name: cert-manager
|
- name: cert-manager
|
||||||
- name: cert-manager-webhook-ovh
|
|
||||||
decryption:
|
decryption:
|
||||||
provider: sops
|
provider: sops
|
||||||
secretRef:
|
secretRef:
|
||||||
|
|||||||
@@ -1,20 +0,0 @@
|
|||||||
# Flux Kustomization for cert-manager-webhook-ovh
|
|
||||||
# Depends on cert-manager being fully operational (CRDs installed)
|
|
||||||
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
|
||||||
kind: Kustomization
|
|
||||||
metadata:
|
|
||||||
name: cert-manager-webhook-ovh
|
|
||||||
namespace: flux-system
|
|
||||||
spec:
|
|
||||||
interval: 10m
|
|
||||||
prune: true
|
|
||||||
sourceRef:
|
|
||||||
kind: GitRepository
|
|
||||||
name: homeprod
|
|
||||||
path: ./kubernetes/system/cert-manager-webhook-ovh
|
|
||||||
dependsOn:
|
|
||||||
- name: cert-manager
|
|
||||||
decryption:
|
|
||||||
provider: sops
|
|
||||||
secretRef:
|
|
||||||
name: flux-sops
|
|
||||||
@@ -5,5 +5,4 @@ kind: Kustomization
|
|||||||
resources:
|
resources:
|
||||||
- webhook.yaml
|
- webhook.yaml
|
||||||
- cert-manager.yaml
|
- cert-manager.yaml
|
||||||
- cert-manager-webhook-ovh.yaml
|
|
||||||
- cert-manager-issuer.yaml
|
- cert-manager-issuer.yaml
|
||||||
|
|||||||
@@ -1,13 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
namespace: longhorn-system
|
|
||||||
resources:
|
|
||||||
- namespace.yaml
|
|
||||||
- repository.yaml
|
|
||||||
- release.yaml
|
|
||||||
secretGenerator:
|
|
||||||
- name: longhorn-values
|
|
||||||
files:
|
|
||||||
- values.yaml=values.yaml
|
|
||||||
configurations:
|
|
||||||
- kustomizeconfig.yaml
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
nameReference:
|
|
||||||
- kind: Secret
|
|
||||||
version: v1
|
|
||||||
fieldSpecs:
|
|
||||||
- path: spec/valuesFrom/name
|
|
||||||
kind: HelmRelease
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: longhorn-system
|
|
||||||
labels:
|
|
||||||
pod-security.kubernetes.io/enforce: privileged
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
apiVersion: helm.toolkit.fluxcd.io/v2
|
|
||||||
kind: HelmRelease
|
|
||||||
metadata:
|
|
||||||
name: longhorn
|
|
||||||
namespace: longhorn-system
|
|
||||||
spec:
|
|
||||||
interval: 1m
|
|
||||||
chart:
|
|
||||||
spec:
|
|
||||||
sourceRef:
|
|
||||||
kind: HelmRepository
|
|
||||||
name: longhorn
|
|
||||||
namespace: longhorn-system
|
|
||||||
chart: longhorn
|
|
||||||
version: '1.12.0'
|
|
||||||
interval: 1m
|
|
||||||
valuesFrom:
|
|
||||||
- kind: Secret
|
|
||||||
name: longhorn-values
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
apiVersion: source.toolkit.fluxcd.io/v1
|
|
||||||
kind: HelmRepository
|
|
||||||
metadata:
|
|
||||||
name: longhorn
|
|
||||||
namespace: longhorn-system
|
|
||||||
spec:
|
|
||||||
interval: 1m
|
|
||||||
url: https://charts.longhorn.io
|
|
||||||
@@ -1,124 +0,0 @@
|
|||||||
# Longhorn Helm Values
|
|
||||||
# Single-node R740 cluster, backup target on TrueNAS NFS
|
|
||||||
defaultSettings:
|
|
||||||
# Single node — only 1 replica needed
|
|
||||||
defaultReplicaCount: 1
|
|
||||||
# NFS backup target on TrueNAS
|
|
||||||
backupTarget: nfs://truenas.lan:/mnt/fast_app_data/longhorn-backup
|
|
||||||
# Allow full disk usage on single-node
|
|
||||||
storageOverProvisioningPercentage: 100
|
|
||||||
storageMinimalAvailablePercentage: 10
|
|
||||||
# Auto-salvage on node reboot (single-node)
|
|
||||||
autoSalvage: true
|
|
||||||
# Disable strict flushing for better single-node performance
|
|
||||||
strictSyncReplicas: false
|
|
||||||
# Toleration for system-managed Longhorn pods (instance-manager, engine,
|
|
||||||
# replica, CSI plugin). These pods are created dynamically by
|
|
||||||
# longhorn-manager — NOT from Helm templates — so their tolerations must be
|
|
||||||
# set here via the `taintToleration` setting (semicolon-separated `kubectl
|
|
||||||
# taint` syntax), not via per-component `tolerations` blocks.
|
|
||||||
#
|
|
||||||
# The P330 node is tainted `dedicated=failover:NoSchedule` (see
|
|
||||||
# infra/p330/kube/variables.tf). Tolerating it lets Longhorn schedule
|
|
||||||
# engine/replica pods there so a volume can be failed over to the P330.
|
|
||||||
# The control-plane taint is also tolerated defensively, although with
|
|
||||||
# allowSchedulingOnControlPlanes=true on the R740 it is not actually applied.
|
|
||||||
taintToleration: dedicated=failover:NoSchedule;node-role.kubernetes.io/control-plane:NoSchedule
|
|
||||||
persistence:
|
|
||||||
defaultClass: true
|
|
||||||
defaultClassReplicaCount: 1
|
|
||||||
# Retain volumes on PVC delete — safer during migration
|
|
||||||
reclaimPolicy: Retain
|
|
||||||
# Mount options for ext4
|
|
||||||
fstype: ext4
|
|
||||||
# longhorn-manager is a DaemonSet — it must run on every storage node,
|
|
||||||
# including the P330 failover node. The control-plane toleration is defensive
|
|
||||||
# (allowSchedulingOnControlPlanes=true means it is not actually applied on the
|
|
||||||
# R740, but keeps things correct if that ever changes).
|
|
||||||
longhornManager:
|
|
||||||
tolerations:
|
|
||||||
- key: ENC[AES256_GCM,data:ZvL4q5WzJQbz/+jBCaH4Gpp5PdCqwrqcIDCXwPq1oVintCYXxg==,iv:SASkDRml7AG+wJTWe/CRaAm7kv7tJ/IRXfpWzeewHuo=,tag:ToVKgaQeLVav7Qt2bdlpnw==,type:str]
|
|
||||||
operator: Exists
|
|
||||||
effect: NoSchedule
|
|
||||||
# Tolerate the failover taint so longhorn-manager runs on the P330
|
|
||||||
- key: ENC[AES256_GCM,data:B+Y/ckOHz6xq,iv:27M/gUOPZ09BNZP2OwyjNsK8Ld0opec9l2FjiRiN0Wg=,tag:3UGdvzOsXgSAs7KwBJ5oKQ==,type:str]
|
|
||||||
value: ENC[AES256_GCM,data:YT/EL6wwlYI=,iv:H8CCtKbzmWRahFxtZguzghVLK3/qvHFaE8IQPALL0Oo=,tag:HIMsMtxutYh3HVASeIrxtw==,type:str]
|
|
||||||
operator: Equal
|
|
||||||
effect: NoSchedule
|
|
||||||
# longhorn-driver (CSI provisioner/attacher deployer) — tolerate the same
|
|
||||||
# taints so CSI operations work from the failover node.
|
|
||||||
longhornDriver:
|
|
||||||
tolerations:
|
|
||||||
- key: ENC[AES256_GCM,data:ks2denq5PQL6UjGUe5JFahXJqLDY8jQgAPjQkn3fhryTCsd1Tg==,iv:gR8QtaRW5+4GptIa92hh2v+pk41ve1FmCMC+qlitdOs=,tag:NDGn8o5btPbfqDWg1nS6wQ==,type:str]
|
|
||||||
operator: Exists
|
|
||||||
effect: NoSchedule
|
|
||||||
- key: ENC[AES256_GCM,data:nRPej7F1wIQr,iv:fRF9YaiqpPCAEGSXCHJublN7OYoikb3xK1RacxMKDcw=,tag:+leZjB1PGhWvxhrEBHxImg==,type:str]
|
|
||||||
value: ENC[AES256_GCM,data:QdMlIx5PYgU=,iv:TJ+i5qwY6G2j+87HdmOZwDWPzJOd9bDeJUmkC3yl9oA=,tag:niNS/IwVVaw+83e4jJrgag==,type:str]
|
|
||||||
operator: Equal
|
|
||||||
effect: NoSchedule
|
|
||||||
# longhorn-ui — tolerate the same taints so the UI is reachable even if it
|
|
||||||
# lands on the failover node.
|
|
||||||
longhornUI:
|
|
||||||
replicas: 1
|
|
||||||
tolerations:
|
|
||||||
- key: ENC[AES256_GCM,data:mYYdyvTvfbP57Tr7zEUgAYZmtSmTougPSbou75YNqD93LvQEuw==,iv:vcKiaYE2ikIAornOIs7LB4iIp6XczB8VmW1FgeUO2ho=,tag:i1yOrLaUX1+AzviTLYQFUw==,type:str]
|
|
||||||
operator: Exists
|
|
||||||
effect: NoSchedule
|
|
||||||
- key: ENC[AES256_GCM,data:rqykd/I0zsFq,iv:lixb2ezSpU2GjXsi8li4z0d1TjNpCRiPXrSMiOASH64=,tag:rMg3tE4fw7jFpidBRZBkIQ==,type:str]
|
|
||||||
value: ENC[AES256_GCM,data:S7G6SgmWjA0=,iv:Wwo3U/bFkch+dNlLZLDNCiaUVID8bIVxhPtizIUt/rE=,tag:7R8s/D6IX4SfZgT/PCkbVw==,type:str]
|
|
||||||
operator: Equal
|
|
||||||
effect: NoSchedule
|
|
||||||
# NOTE: There is no `longhorn-instance-manager` Helm key. The instance-manager,
|
|
||||||
# engine and replica pods are system-managed and created dynamically by
|
|
||||||
# longhorn-manager; their tolerations come from `defaultSettings.taintToleration`
|
|
||||||
# above. Do not add a `longhorn-instance-manager` block here — it would be
|
|
||||||
# silently ignored.
|
|
||||||
# Disable ingress for now
|
|
||||||
ingress:
|
|
||||||
enabled: false
|
|
||||||
# Recurring backup and snapshot schedules
|
|
||||||
# - Daily snapshots: fast local recovery from accidental deletes
|
|
||||||
# - Daily NFS backups: DR if node is lost
|
|
||||||
recurringJobs:
|
|
||||||
enable: true
|
|
||||||
jobs:
|
|
||||||
- name: daily-snapshot
|
|
||||||
task: snapshot
|
|
||||||
cron: 0 2 * * *
|
|
||||||
retain: 7
|
|
||||||
concurrency: 2
|
|
||||||
labels:
|
|
||||||
type: snapshot
|
|
||||||
- name: daily-backup
|
|
||||||
task: backup
|
|
||||||
cron: 0 3 * * *
|
|
||||||
retain: 7
|
|
||||||
concurrency: 2
|
|
||||||
labels:
|
|
||||||
type: backup
|
|
||||||
sops:
|
|
||||||
lastmodified: "2026-07-22T09:25:21Z"
|
|
||||||
mac: ENC[AES256_GCM,data:H61nccieTaqp4w6cySS8EG6VZvplmUdSSo2MFi+mGzZohJFjTfdHxIaJgfKuN7/+/dMoacgozl73CmwSnelzgKMm9CZNf0ucWXRPG/8EiM5IeDXBhRChP+Y8BHX6h7FNS6la6Jzdqy8/jKUPw5sdDQaHT6KnQ37ie+D3JjZAwic=,iv:qb/Cr0upi9qQfYVDAwFyLqnVHSlktkVVbsmhTaFsZu0=,tag:q0jPEGtNl4BmBJpdghgRJg==,type:str]
|
|
||||||
pgp:
|
|
||||||
- created_at: "2026-07-22T09:25:21Z"
|
|
||||||
enc: |-
|
|
||||||
-----BEGIN PGP MESSAGE-----
|
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiARAAwf/RSzNAtZ+BY13bYXQstWAs+7HYZLm1fNKcqNKevSHT
|
|
||||||
+LKy+YkfXgDk67PZNz2H5v3N3GJi/cDEo1MhfXeutYLioZ7WFVaeXsvd3hxisbzi
|
|
||||||
noliuQtu9b63l5UwZPbWvfFDKLJqVKG2JTfXSp+G0Nv11VYCYKftRNd/KH+xEP89
|
|
||||||
hGWGuL+AhbPW9dFimiAICLk/sGyVXNq1SAKu3rL9o/mtRDh+igSg5YohhYhiA7TC
|
|
||||||
PMp/7SRY6swfZ0xfyw9PKlbR5Gm7i5Wtml6MP5myZ90cjzMAkjOL8NavxGogvfib
|
|
||||||
ajjdN5AqdoSU5Kr+rKx8I3Eq9V0Fs/oXfmLeHYYdNoqNOqpqtupXKnMVEdHyUdeq
|
|
||||||
shBuDUE4dvZWyYKfZKzQz2WASN1GDiVm89IvhQ2MP1nEhRE92UyixKHQmLgNolpm
|
|
||||||
LTkuGzWU3dNzHO1c3JLgjF/lWve5KV01Wa/HrAZFH5rSG3qLN8rkmhB+q4C2jjkN
|
|
||||||
4aXyPY8/vRLbIwQgSnxBKYzD6yNFNj76W8kmdEe7c1sMcJZZdjC2pqmEzlfoP9sl
|
|
||||||
vzLkHQeFe2IGYMVna0KVCuEk+5pTvnU7KaoMjfbGFPvDwv3heRUzSTBAF3furx03
|
|
||||||
QHi9bOVCrhrt3QLb7cQSrhGMwtV+XiphfQVAJqKSS3la0XjIoJzm297hNgXv0OTS
|
|
||||||
XAGMF0oFo/1bytZZY0+BSe10y4g+G8q47cqWq0/bnvG4fP95/U3/tH8njIFeNg0U
|
|
||||||
yqm9O+1fQ6I2b6hRlGyv6RjovRc32J+RVPgEkK5a5dlvSTQf97tw9Bo3tKc6
|
|
||||||
=SxRv
|
|
||||||
-----END PGP MESSAGE-----
|
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
|
||||||
version: 3.10.2
|
|
||||||
@@ -1,38 +1,11 @@
|
|||||||
ingress:
|
ingress:
|
||||||
main:
|
main:
|
||||||
enabled: true
|
enabled: true
|
||||||
hosts:
|
hosts:
|
||||||
- host: dashy.lan
|
- host: dashy.lan
|
||||||
paths:
|
paths:
|
||||||
- path: /
|
- path: /
|
||||||
pathType: ImplementationSpecific
|
pathType: ImplementationSpecific
|
||||||
persistence:
|
persistence:
|
||||||
data:
|
data:
|
||||||
enabled: true
|
enabled: true
|
||||||
storageClass: longhorn
|
|
||||||
sops:
|
|
||||||
lastmodified: "2026-07-18T14:22:16Z"
|
|
||||||
mac: ENC[AES256_GCM,data:Svz0vne+sbEj5wlL4FHUrTPMHlprWnZqR/X3tEmpDIxKBD0C/C9G1LgPYBiHviHEiiD/XbxxgH9nGcJIo4blbWc6xRNyUjnhGoLPIPJlG9LclXVh7dm4w4bETq4VfQZjLpY6bhv0q2d5GgxI6i+Hp16FSk8Y4kReErmQdg/Vh9I=,iv:zt3Rjt9KapI7LMMlpA/MPWK8EgGVFRpLJ4d2r4P74eY=,tag:fo2CgvaoT6bz1xmYA9DvGg==,type:str]
|
|
||||||
pgp:
|
|
||||||
- created_at: "2026-07-18T14:22:16Z"
|
|
||||||
enc: |-
|
|
||||||
-----BEGIN PGP MESSAGE-----
|
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiAQ//RB59ULu3tagTsLKGU+2azz+yTgnRKUsauEhC2trzbpRO
|
|
||||||
Au0RYwQMyDmYwTAvIIRM5gWUGlIFpsiftpK6rZbvJiwb8npYVSF7/shqKzlqYiSi
|
|
||||||
+BHJCSqfk+emN9ULivxmq3i+t4YZ97Ap7uo+pUyBmpz4jis0vdiIDIszLwtJ3U0J
|
|
||||||
t6s2gVl4KE2STyVH+ShERG3yjSBuzvFpJVwSdAfGKeA8K6Umr1LQH/2JSlq8/2fV
|
|
||||||
Zubfu6aGXg564rsbZNs+P9/b5M4FmpSlSOlp6OLWnIosl9CfRVDynnRyLImvQ/8p
|
|
||||||
2Asf6vrAQZJVXHraGMfePNNA9sRxhMa8f1qgHDWGfHh8D8/7JwK5xoFWrNoO7Gb6
|
|
||||||
aex15qielE0N4jpiEC3t+jjRUQLdjMuSlRET/0RVrZRhZ4lUTOOINnw8eUic0vRz
|
|
||||||
OjPj/ffVI4+zqfq7GnopISWBtfMdc23Y+7IhL/8LWRJGLRSqB0fNQxWeS7dtze2o
|
|
||||||
2BWk+DsHiG/1bz2hdezuR+KTRoj7qPDI/eKPc1BpyHfVm8k1y3pFmwWY3rwGAGA0
|
|
||||||
6bB1VSBriE3pcvUiJw4N+Ja/C7gLcUVAtNKGLqxuWr+2bm/ExWItAbnZ/3cZzKtC
|
|
||||||
bULu5ic/zN3O3rRWCS5nFU+nD37pq1Iq3eHXOWygwNOJJcGGHl9+3j01y2iXUl3S
|
|
||||||
XgGKWMKthF+9AD1bASp8tZ1lfNuqyxjbdVyWb7xqRGa2jzWgAcVUaCWWaJU6yASF
|
|
||||||
LdXY6xVKr1DgBs666nv4xAESsgvZ9xP6e+YaxAr3piRuDhzoNFeveOD99tsgZOg=
|
|
||||||
=zi2x
|
|
||||||
-----END PGP MESSAGE-----
|
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
|
||||||
version: 3.10.2
|
|
||||||
|
|||||||
Reference in New Issue
Block a user