mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-09-26 02:43:23 +00:00
Compare commits
7
Commits
7521d67e90
...
3efa9deb34
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3efa9deb34 | ||
|
|
32397ced96
|
||
|
|
b3047cbe3e
|
||
|
|
c9af935148
|
||
|
|
bac134e2d4
|
||
|
|
30276fa4fb
|
||
|
|
aa9452354a
|
@@ -47,6 +47,7 @@ updates:
|
|||||||
- "/kubernetes/home/home-assisant"
|
- "/kubernetes/home/home-assisant"
|
||||||
- "/kubernetes/home/zigbee2mqtt"
|
- "/kubernetes/home/zigbee2mqtt"
|
||||||
- "/kubernetes/infrastructure/authentik"
|
- "/kubernetes/infrastructure/authentik"
|
||||||
|
- "/kubernetes/infrastructure/mail/stalwart"
|
||||||
- "/kubernetes/personal/linkwarden"
|
- "/kubernetes/personal/linkwarden"
|
||||||
- "/kubernetes/personal/notesnook"
|
- "/kubernetes/personal/notesnook"
|
||||||
- "/kubernetes/personal/photoprism"
|
- "/kubernetes/personal/photoprism"
|
||||||
|
|||||||
@@ -77,70 +77,14 @@ _25._tcp:
|
|||||||
ttl: 300
|
ttl: 300
|
||||||
type: TLSA
|
type: TLSA
|
||||||
values:
|
values:
|
||||||
- certificate_association_data: 5dfdb3cf31b26f23d87c09f3a0cef642f64069a9fb7cfe29270bb5dc0f1e16bb
|
- certificate_association_data: CC6230E3A88A173D11C7F614ACFB4FE7B57A01F649ED1ADEE5F953213D4C6607
|
||||||
certificate_usage: 2
|
certificate_usage: 3
|
||||||
matching_type: 1
|
matching_type: 1
|
||||||
selector: 0
|
selector: 1
|
||||||
- certificate_association_data: 76e9e288aafc0e37f4390cbf946aad997d5c1c901b3ce513d3d8fadbabe2ab85
|
- certificate_association_data: 731B7CD6FA08C4A56060172BF8E30563919139F16265A38EC35B2A1F41CE2B6B
|
||||||
certificate_usage: 2
|
certificate_usage: 3
|
||||||
matching_type: 1
|
matching_type: 1
|
||||||
selector: 0
|
selector: 0
|
||||||
- certificate_association_data: 4e32b7ee52c9bd2a15b2df3cae5e3b060d737d71faaaac25336c5f193cbdb52ed2fdf38b29aea9fb97f59c8f86e75b5c364309a232623a99e638116ed66063fd
|
|
||||||
certificate_usage: 2
|
|
||||||
matching_type: 2
|
|
||||||
selector: 0
|
|
||||||
- certificate_association_data: afab698cbbbf892ebb555e09175056c1d4630fe7c350f44dcc6e71843d3b290df00d30ab4e356b630c69169d7633788338922fb637cf5b9f7be20a413eeaa518
|
|
||||||
certificate_usage: 2
|
|
||||||
matching_type: 2
|
|
||||||
selector: 0
|
|
||||||
- certificate_association_data: 3586d4ecf070578cbd27aedce20b964e48bc149faeb9dad72f46b857869172b8
|
|
||||||
certificate_usage: 2
|
|
||||||
matching_type: 1
|
|
||||||
selector: 1
|
|
||||||
- certificate_association_data: d016e1fe311948aca64f2de44ce86c9a51ca041df6103bb52a88eb3f761f57d7
|
|
||||||
certificate_usage: 2
|
|
||||||
matching_type: 1
|
|
||||||
selector: 1
|
|
||||||
- certificate_association_data: a1ef14fea3ca15a552d42665d2fe685672cfdd903de4b370b0d7d87c6d31b5df07142483f36e0e15e16b58f9ba1cbdeeebd4bcb8d74ab7ea32a087db2105f402
|
|
||||||
certificate_usage: 2
|
|
||||||
matching_type: 2
|
|
||||||
selector: 1
|
|
||||||
- certificate_association_data: f8a2b4e23e82a4494e9998fcc4242bef1277656a118beede55ddfadcb82e20c5dc036dcb3b6c48d2ce04e362a9f477c82ad5a557b06b6f33b45ca6662b37c1c9
|
|
||||||
certificate_usage: 2
|
|
||||||
matching_type: 2
|
|
||||||
selector: 1
|
|
||||||
- certificate_association_data: a69ec216999308f0ee575cdef98d6edabed8a6b4d2328e050ac9c7fa06404ad9
|
|
||||||
certificate_usage: 3
|
|
||||||
matching_type: 1
|
|
||||||
selector: 0
|
|
||||||
- certificate_association_data: ccae2719a01f7a6d17d939d8ec13324b7bdb0921ea55d5bfc2f226e54b8c15dd
|
|
||||||
certificate_usage: 3
|
|
||||||
matching_type: 1
|
|
||||||
selector: 0
|
|
||||||
- certificate_association_data: 7cd33aa6bafc850cc89d008fbd0a5cea942c6a573d605984f174fbe7360abbf71fc157ffe0324e380a8dfea62047b9aa140d5899188402ac677c29f96cc1118e
|
|
||||||
certificate_usage: 3
|
|
||||||
matching_type: 2
|
|
||||||
selector: 0
|
|
||||||
- certificate_association_data: 8149784990ba7e448295f9c4eb22abcaa4ecefa1b44f1a71ea13d6827d7068c6469cf5fb08a8ae772c1ef59cddbcfd84d744713c48e985136a234b494511fd03
|
|
||||||
certificate_usage: 3
|
|
||||||
matching_type: 2
|
|
||||||
selector: 0
|
|
||||||
- certificate_association_data: 08f3ffd1b6027093c136f6bb5bc1645a8db31cf2a4392b779c2a2045e152b8b8
|
|
||||||
certificate_usage: 3
|
|
||||||
matching_type: 1
|
|
||||||
selector: 1
|
|
||||||
- certificate_association_data: 12b3946513281ab20ebee4d38d2e139cac1688420015db90ee8e932fe153bc89
|
|
||||||
certificate_usage: 3
|
|
||||||
matching_type: 1
|
|
||||||
selector: 1
|
|
||||||
- certificate_association_data: 7b60aee1a230de2c32c0252540c606897ad66cbabc7331c2d40b7dd0e3249e0cc53e145605e610d8dc2f41dd16e12f51dca4641d13e748553bd0f596455dae77
|
|
||||||
certificate_usage: 3
|
|
||||||
matching_type: 2
|
|
||||||
selector: 1
|
|
||||||
- certificate_association_data: 8cee22274c3f828eda9d18c9954ed0a3ad5172e71b7852c780384bf3828ff1bb26fca899395e99e4d191c2d1e0a55404f97e76bb7d4ad8dff71c6c271d34de49
|
|
||||||
certificate_usage: 3
|
|
||||||
matching_type: 2
|
|
||||||
selector: 1
|
|
||||||
_caldavs._tcp:
|
_caldavs._tcp:
|
||||||
octodns:
|
octodns:
|
||||||
cloudflare:
|
cloudflare:
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
services:
|
services:
|
||||||
stalwart:
|
stalwart:
|
||||||
image: stalwartlabs/stalwart:v0.16.10
|
image: stalwartlabs/stalwart:v0.15.5
|
||||||
container_name: stalwart
|
container_name: stalwart
|
||||||
networks:
|
networks:
|
||||||
- default
|
- default
|
||||||
|
|||||||
@@ -0,0 +1,24 @@
|
|||||||
|
# TLS certificate for the Stalwart mail listeners (SMTP/IMAP/POP3 STARTTLS + implicit TLS)
|
||||||
|
# and the management WebUI hostname.
|
||||||
|
#
|
||||||
|
# Issued by cert-manager via the letsencrypt-production ClusterIssuer (Cloudflare DNS-01).
|
||||||
|
# The resulting Secret (mail-vhaudiquet-fr-tls) is consumed in two places:
|
||||||
|
# 1. The Stalwart HelmRelease mailTls block -> mounted into the pod + pushed to
|
||||||
|
# Stalwart by the tls-sync sidecar (JMAP) so SMTP/IMAP/POP3 present this cert.
|
||||||
|
# 2. The chart ingress (TLS termination is handled by Caddy in this cluster, so the
|
||||||
|
# ingress is TLS-less and only routes HTTP to the mgmt port).
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: mail-vhaudiquet-fr
|
||||||
|
namespace: stalwart
|
||||||
|
spec:
|
||||||
|
secretName: mail-vhaudiquet-fr-tls
|
||||||
|
issuerRef:
|
||||||
|
name: letsencrypt-production
|
||||||
|
kind: ClusterIssuer
|
||||||
|
commonName: mail.vhaudiquet.fr
|
||||||
|
dnsNames:
|
||||||
|
- mail.vhaudiquet.fr
|
||||||
|
duration: 2160h # 90 days
|
||||||
|
renewBefore: 360h # 15 days before expiry
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: stalwart
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- repository.yaml
|
||||||
|
- certificate.yaml
|
||||||
|
- recovery-admin-secret.yaml
|
||||||
|
- release.yaml
|
||||||
|
secretGenerator:
|
||||||
|
- name: stalwart-values
|
||||||
|
files:
|
||||||
|
- values.yaml=values.yaml
|
||||||
|
configurations:
|
||||||
|
- kustomizeconfig.yaml
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
nameReference:
|
||||||
|
- kind: Secret
|
||||||
|
version: v1
|
||||||
|
fieldSpecs:
|
||||||
|
- path: spec/valuesFrom/name
|
||||||
|
kind: HelmRelease
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: stalwart
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
# Recovery / bootstrap administrator credential for Stalwart.
|
||||||
|
#
|
||||||
|
# This Secret is referenced by:
|
||||||
|
# - recoveryAdmin.existingSecret in the HelmRelease, which injects it into the
|
||||||
|
# Stalwart pod (and the tls-sync sidecar) so the cert-manager certificate can
|
||||||
|
# be pushed to Stalwart via JMAP. Keep it present for the lifetime of the
|
||||||
|
# deployment; the tls-sync sidecar needs it on every cert renewal.
|
||||||
|
#
|
||||||
|
# The username/password here are ONLY the recovery account.
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: stalwart-recovery-admin
|
||||||
|
namespace: stalwart
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: stalwart
|
||||||
|
app.kubernetes.io/component: recovery-admin
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
username: ENC[AES256_GCM,data:CYm0+Kw=,iv:UdgReqdb8GdoOfv1ZEW/7BAvY3vV88httj3W976eV0Y=,tag:PPrDQY/mo0RcJiz/cmxFSA==,type:str]
|
||||||
|
password: ENC[AES256_GCM,data:r0mPJ4qKIhAWDw==,iv:L5+OKTznQgDUgqttHwdW0X66vz+JPTqWdwYPGklCuj0=,tag:WNOj7ZjC6Lx76UlPsgSDhg==,type:str]
|
||||||
|
sops:
|
||||||
|
lastmodified: "2026-07-02T20:57:39Z"
|
||||||
|
mac: ENC[AES256_GCM,data:lIVOaMsFV9F1/yLvykA3LH5ukn9PIba6N8cE9RGdcFepM56tBYlY6fbkcKTtojyAkoYov6OCjgTsOkMtUzRdGES4Zti6zHB3cTPal8bJCf5cAfYnGFRcQaASIkVjNZkQSJ2pDRP4rZqioCHuj2/a6uJZ4hhtSpxrECYbpzD2Gk8=,iv:31fXHsWH1ZP00Od5DSxgYPuw87NqQNfWl4vFtoouIHk=,tag:u5cJn231VT2ZTmlcdpBz0g==,type:str]
|
||||||
|
pgp:
|
||||||
|
- created_at: "2026-07-02T20:57:39Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMA7uy4qQr71wiAQ//fYBIypexVfQJn5BxVCRgZKRBcYw78XSoPjFYWFyk5F7I
|
||||||
|
UFRQKtdZOVVhgNHtFJOVyBvl1sAmmzAt3xq3L+Z5bvtrUfZ33tTp7ty+MmSmuutS
|
||||||
|
wquSh4NOHUYENGvo5pWsgVwQDj5bI2qUq4L92aedpB2XJycb7/Df7BWFKNMNgWdt
|
||||||
|
l+Hj9HEJWxmFjrz1MQJEL2r5WOx9/hK7uatbDTXVFPqyyW1aCM5XOkKErTuc3Avn
|
||||||
|
8tNNlvP1aqhI/2dHfOSZ1l0/PHhdi3RBmGa3BfAZUXEseBEesIK/EaJZXMjQYhF2
|
||||||
|
5tAPQ1irqg8LLv9mhrUD2mWaUigcuZ1EeyfZFvNtY/noF8fyZny1jra0sDe4CmQP
|
||||||
|
7uyP6CNRWPCikutUw45oxtw+/Us5Ld8xzJxhDEm0e+8FFiAK/SFSOx57JbjNzoCj
|
||||||
|
dqHU3UIzyp9VVZohqW7xdHOW64fgDI41BDKBsEiKraLnZUoXL2Lx0lnjxayJqVsD
|
||||||
|
2pX9D5YXzmtwFvUU5ZpcCzUWFu9MVxSfp6HdKvocGdtpSz7J23PQvHtkv20GxJYd
|
||||||
|
J45RYGgekuJ2EXc9kPaCuSex/0BKtYybOk5ANRv2yGeUZlc6EoW8/GZ4sHXPY6um
|
||||||
|
tt1DdIsMNMjAU68EgRkhmQnFAkZixJVdDR3u4MNXFUr0WdVIqzjFBavyrkcK6HjS
|
||||||
|
XAGhFNWdk5DNZ1ChGrMKEnYCZEB6XNkofa7S2xAomEoxyuCq7X2vbfBfqDQ/Rtcf
|
||||||
|
kSx0TpIOSHxefSFMduPz90rDqdZgUW0D3GND0PD5XRFFiJxxdrRYPux9MDMd
|
||||||
|
=Ef8e
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
|
encrypted_regex: ^(data|stringData|.*.key|.*.crt)$
|
||||||
|
version: 3.10.2
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: stalwart
|
||||||
|
namespace: stalwart
|
||||||
|
annotations:
|
||||||
|
homeprod.io/essential: "true"
|
||||||
|
spec:
|
||||||
|
interval: 1m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: stalwart-helm
|
||||||
|
namespace: stalwart
|
||||||
|
chart: stalwart
|
||||||
|
version: "0.7.5"
|
||||||
|
interval: 1m
|
||||||
|
valuesFrom:
|
||||||
|
- kind: Secret
|
||||||
|
name: stalwart-values
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: source.toolkit.fluxcd.io/v1
|
||||||
|
kind: HelmRepository
|
||||||
|
metadata:
|
||||||
|
name: stalwart-helm
|
||||||
|
namespace: stalwart
|
||||||
|
spec:
|
||||||
|
interval: 1m
|
||||||
|
url: https://kgrubb.github.io/stalwart-helm-chart
|
||||||
@@ -0,0 +1,147 @@
|
|||||||
|
# Stalwart Mail Server - Helm values
|
||||||
|
#
|
||||||
|
# TLS for the mail listeners is sourced from cert-manager: the
|
||||||
|
# mail-vhaudiquet-fr-tls Secret (see certificate.yaml) is mounted into the pod
|
||||||
|
# and pushed to Stalwart by the chart's tls-sync sidecar over JMAP, which also
|
||||||
|
# calls ReloadTlsCertificates on every cert-manager renewal.
|
||||||
|
# Container image
|
||||||
|
image:
|
||||||
|
repository: stalwartlabs/stalwart
|
||||||
|
tag: v0.16.11
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
# Single-node RocksDB deployment.
|
||||||
|
replicaCount: 1
|
||||||
|
role: ""
|
||||||
|
pushShard: ""
|
||||||
|
# Recovery / bootstrap administrator.
|
||||||
|
# The Secret (stalwart-recovery-admin) is required for the lifetime of the
|
||||||
|
# deployment because the tls-sync sidecar authenticates to Stalwart's JMAP API
|
||||||
|
# with these credentials on every cert-manager renewal.
|
||||||
|
recoveryAdmin:
|
||||||
|
enabled: true
|
||||||
|
username: ENC[AES256_GCM,data:83oORcE=,iv:X07gQXkAx2wdqEcOPi5mGTVoFkJjDHBKMCYUjpg3qv4=,tag:qvspLaPSsrld4UV/qXb0cw==,type:str]
|
||||||
|
password: ""
|
||||||
|
existingSecret: ENC[AES256_GCM,data:KuZYrQk+YQhciNRTHqOlZdqZWJ3o15I=,iv:x/cm4USFZqWE5xuuF7tUPm593NqX1kbmeKv0x2wzk8s=,tag:G9FRYYaJhWovN+LB/gLaoQ==,type:str]
|
||||||
|
usernameKey: username
|
||||||
|
passwordKey: password
|
||||||
|
# Recovery mode suspends mail services and exposes only the management listener.
|
||||||
|
# Ship production values with this OFF.
|
||||||
|
recoveryMode:
|
||||||
|
enabled: false
|
||||||
|
port: 8080
|
||||||
|
logLevel: info
|
||||||
|
extraEnv: {}
|
||||||
|
extraSecretEnv: {}
|
||||||
|
# The bootstrap hook Job provisions a *fresh* domain/accounts/OIDC directory.
|
||||||
|
bootstrap:
|
||||||
|
enabled: false
|
||||||
|
# cert-manager TLS integration for the mail (SMTP/IMAP/POP3 STARTTLS + implicit
|
||||||
|
# TLS) listeners. The Secret below is produced by the Certificate in
|
||||||
|
# certificate.yaml (letsencrypt-production, Cloudflare DNS-01).
|
||||||
|
mailTls:
|
||||||
|
enabled: true
|
||||||
|
existingSecret: ENC[AES256_GCM,data:Y+LfFx7nuCSMGqo2o3QoHG1Br+MYlQ==,iv:dLJDYmK2gEmNq5VnbpEJWFM1xLLT5jXqxB2WQQ4dr3E=,tag:Ya2cTf/ZpJdzFnwH53iZZQ==,type:str]
|
||||||
|
certKey: tls.crt
|
||||||
|
privateKeyKey: tls.key
|
||||||
|
mountPath: /etc/stalwart/tls/ingress
|
||||||
|
hostname: mail.vhaudiquet.fr
|
||||||
|
domain: vhaudiquet.fr
|
||||||
|
# How often the sidecar re-checks the mounted cert for changes.
|
||||||
|
reloadIntervalSeconds: 300
|
||||||
|
# config.json contents - ONLY the DataStore object. All other settings
|
||||||
|
# (listeners, storage backends, domains, accounts, certs) live in the database
|
||||||
|
# and are managed via JMAP/WebUI.
|
||||||
|
config:
|
||||||
|
'@type': RocksDb
|
||||||
|
path: /var/lib/stalwart
|
||||||
|
# Main Service: ClusterIP. Used by the Ingress for the management WebUI (mgmt)
|
||||||
|
# and for in-cluster access. Mail L4 ports are exposed separately via mailService.
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
smtp: 25
|
||||||
|
smtps: 465
|
||||||
|
submission: 587
|
||||||
|
imap: 143
|
||||||
|
imaps: 993
|
||||||
|
pop3: 110
|
||||||
|
pop3s: 995
|
||||||
|
sieve: 4190
|
||||||
|
http: 80
|
||||||
|
https: 443
|
||||||
|
mgmt: 8080
|
||||||
|
# Dedicated LoadBalancer for SMTP/IMAP/POP3/Sieve (L4). HTTP/HTTPS/mgmt are NOT
|
||||||
|
# exposed here - the WebUI is reached via the Ingress (Traefik) below.
|
||||||
|
# The WAN router NAT for 25/465/587/993/995/4190 must be repointed to this IP.
|
||||||
|
mailService:
|
||||||
|
enabled: true
|
||||||
|
name: stalwart-mail
|
||||||
|
type: LoadBalancer
|
||||||
|
loadBalancerIP: 10.1.2.143
|
||||||
|
annotations: {}
|
||||||
|
# WebUI ingress. TLS is terminated by Caddy at the edge (wildcard cert), so the
|
||||||
|
# path is: public -> Caddy (TLS) -> Traefik (HTTP) -> this Ingress -> mgmt:8080.
|
||||||
|
# No TLS block here.
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
annotations: {}
|
||||||
|
hosts:
|
||||||
|
- host: mail.vhaudiquet.fr
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
portName: mgmt
|
||||||
|
tls: []
|
||||||
|
# Persistent volume for the RocksDB data directory.
|
||||||
|
persistence:
|
||||||
|
enabled: true
|
||||||
|
accessMode: ReadWriteOnce
|
||||||
|
storageClass: ""
|
||||||
|
size: 50Gi
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 250m
|
||||||
|
memory: 256Mi
|
||||||
|
limits:
|
||||||
|
cpu: "1"
|
||||||
|
memory: 1Gi
|
||||||
|
# Override chart defaults to add fsGroupChangePolicy: OnRootMismatch.
|
||||||
|
# Without this, kubelet recursively chowns every file in the NFS-backed PVC
|
||||||
|
# on every pod start (15k+ RocksDB files), causing multi-minute delays.
|
||||||
|
# OnRootMismatch skips the recursive chown if the volume root already
|
||||||
|
# has the correct owner (UID 2000).
|
||||||
|
podSecurityContext:
|
||||||
|
fsGroup: 2000
|
||||||
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
|
runAsUser: 2000
|
||||||
|
runAsGroup: 2000
|
||||||
|
runAsNonRoot: true
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
containerSecurityContext: {}
|
||||||
|
sops:
|
||||||
|
lastmodified: "2026-07-03T13:00:45Z"
|
||||||
|
mac: ENC[AES256_GCM,data:qoGDDt03xtJbPH+I3edSsFJagZSlCcMk4XoFc/I2QZEm+45DjsCWe9Q7e9zhn5kF3HBNBwNCgEzJmq2Fn/vemMWHwI4+QZW6nkk5cYTb3r8+WysSeUyt2+Y7EjyQGwI6+2LrCBlJIqmKfpPtT7Y8ZbwRBedoVqFtnNVH5441FMY=,iv:fvfnedCEGXyPw4yRLCtKoAnzz8h3jyJOwpqA33NNJOI=,tag:fPd7RJAMMounXVkIoKrptQ==,type:str]
|
||||||
|
pgp:
|
||||||
|
- created_at: "2026-07-03T13:00:45Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMA7uy4qQr71wiAQ//WA7P2WeKV6QFKotw5UP1MXcdI9THypFFly4sweJ5MC+e
|
||||||
|
Lzy/zCidGCM3Cu+dJaaPJNKtfPfagQJ9FzHrnvRcHoCbKS7sTAqugdwt4uyplem9
|
||||||
|
l03kQWZfDj8R8MHQnAKWNmJDiJkjCoqHdR5f2JtS+n7MngI53SecY2fsFOXRbYJI
|
||||||
|
hfH1BR+agLjIHc+gOF340GJp4UT+Q6BZOKg8K5O4PYk1Xwj3pi6YFuhiedKHSybF
|
||||||
|
Ij9OWdTqpofeG3fhwd3jHLW+0WYiFNrVlchfClEDWMMc0UfS6Bfo96IL0JIoYlHD
|
||||||
|
4Zt8EEyjvAJ5478RTKTobMlsSUC5U51Wn6paapZ5zicCHDzdP2yTtwtSKK0Mdp3W
|
||||||
|
qt/pZoR4EyM+I2XCKp+z7N5FtH8cahtfZiUOBwQ4NK9Fz+2UBxtP2QzGj8YpJmWu
|
||||||
|
OkbGoSgwn+8bcNnRwnADTzdiTWf/a56WErp1NvuqF8VqdGzsJR9EgyYwENl+m+U8
|
||||||
|
fbTY58iAJDDpY5ipPL5v+lo0Fw5DrnQ0NPAm1ORi+rMJy0KUjgAzdS6lL5oWGfAC
|
||||||
|
rzbzThGpRt0E7O296pht8TCBFHqiKbiOdGEBXO3+w9NrvOgULno4+s88vu6KMvFL
|
||||||
|
s3MHz7oIgfwel7V6bVc/ZQvHYS3YHjG41fwn00cpKI/WRN8z5MnSwwkegD2Wv8fS
|
||||||
|
XgEqL6kQPgk97779c0jo9CJA8O6QaSvGyd1j680tN1NN9V64rJOaj/818SgwFLrA
|
||||||
|
XWaqrOnz8FIspqO836t6OaLq5WwzOtOR6zs7cUk6h1RHgwlFQ+0n1o6qYf6Q+CA=
|
||||||
|
=HnWo
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
||||||
|
version: 3.10.2
|
||||||
@@ -22,6 +22,7 @@ resources:
|
|||||||
- home/zigbee2mqtt
|
- home/zigbee2mqtt
|
||||||
# Infrastructure
|
# Infrastructure
|
||||||
- infrastructure/authentik
|
- infrastructure/authentik
|
||||||
|
- infrastructure/mail/stalwart
|
||||||
# Personal
|
# Personal
|
||||||
- personal/linkwarden
|
- personal/linkwarden
|
||||||
- personal/notesnook
|
- personal/notesnook
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ persistence:
|
|||||||
originals:
|
originals:
|
||||||
enabled: true
|
enabled: true
|
||||||
type: nfs
|
type: nfs
|
||||||
server: truenas.local
|
server: truenas.lan
|
||||||
path: /mnt/main_storage/valentin/Photos
|
path: /mnt/main_storage/valentin/Photos
|
||||||
mountPath: /photoprism/originals/photos/valentin
|
mountPath: /photoprism/originals/photos/valentin
|
||||||
mariadb:
|
mariadb:
|
||||||
@@ -36,27 +36,27 @@ mariadb:
|
|||||||
repository: bitnamilegacy/mariadb
|
repository: bitnamilegacy/mariadb
|
||||||
tag: 12.0.2-debian-12-r0
|
tag: 12.0.2-debian-12-r0
|
||||||
sops:
|
sops:
|
||||||
lastmodified: "2026-05-01T22:39:49Z"
|
lastmodified: "2026-07-06T19:30:14Z"
|
||||||
mac: ENC[AES256_GCM,data:YGVQb50DrFv/ehU+dxsoP/e8ARKVPfr/6c2x1pQbZ7cNiNu7k1Zgt+bEHkkKm+FT44bltL374Jf2HqT/0gvmgMGp/8ukjZ5hRLwbqS1fOKR8SVQ8fp2EId0P7HcRl7Qqr6lF15hKXQ+SPl6KDPvDWKh0pq192W8dP76D7h5aKDw=,iv:c1xytratCfO8V4nkdvxeKT2kWOYHBkwoTc5Ic+yjpWQ=,tag:kdxAidCO1VLPxiwq3eCRxQ==,type:str]
|
mac: ENC[AES256_GCM,data:QgOnL1dsq2S78nRD+xe08w3u0+bRfNML/ea9P9v0TBCQq5EmKj6yPKJApvttyeGUDJDGo9Ds17a9XLDFtOl9ORoax6E50VqJSnc1ElE2l5EFogl3JPuMdQxEzXniaCjOSrfMNWNdo7fHN/qcX0Gzs7BL9pw+NyQLv4kFcDYQv78=,iv:buV08iLiLB5BJ5JYfn4blmFb/eu/EtpnWsxT5IfyXfQ=,tag:8egGKWNa7CEql9t6zWHlOQ==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-05-01T22:39:48Z"
|
- created_at: "2026-07-06T19:30:14Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiAQ/9F+u/hWM4smi4yqnU7vzRfWwjCuvdtWAR6N4MqiBLFfqr
|
hQIMA7uy4qQr71wiAQ//Qg0OcwKr1mG40IoYmABD8b+/W+X5zTyyht9QCpNtRSVO
|
||||||
tpzY8UCfaTlfEtwDZWUSN/gzZG56YcMTR6OOrCQ8rkiKYGwuj92Z8LgpcDRBAHeG
|
JzhtMl9YZHLqwkiwBqW+hvfIKXYtYBNl2TsAZ57xcE60lr72bHfqXkO24hf9+jvq
|
||||||
gYaNG9vRmmzyZpD6K6pSoG8lk7mzB1Tp80me9E7LJTDhAn70cDATLp1wADkD0KF1
|
jmFwK1Mo/zf0/b3R8gFqEmg5mW97jdmEXHfRrzzyaAXhGk0rWfLGBSbaif71a/dj
|
||||||
pq44qPcRaem42kEx6Um1sAy5NiBBxvYqdKPRXLs0q1EyZByxKjlhZi0qasCfe4lJ
|
jVu+Vf48LsEnUYH3oO2ASY3OlVwKAn5njfyIz2MWwY5iohOsiJwJu2WiotI+zCFI
|
||||||
fsdduUgRi3Td7KvfhQ1e6jjNNMpyZIHbME3Hn18h5PxVd1B3FzzBzSHlaDKBQsYT
|
VOfftPCYvJyVKGG5bE3GHOjAlbNqHtRCn9Bm/mXQVyLkAU9ik+i1PABGEU9nc09q
|
||||||
2cx6VMGVqM4dy+CHkpE+QlAA0EOhS0b/7FwppCgEhlEvbH7uCjq/13vZdKoUIwqt
|
+IcO3Njo7MRtZU9pctMZLvRSbxvEx2bZOKSXe6nhVK324Qr0cETX+/GuDZn3SeVy
|
||||||
AaHPaf/HX7PipQjoQf7vjfaMjPwCFwqoeK2cVNmgK0j0b2CyjLDDs5xh0SuFt/Ia
|
pyHR/BtpGXtqyWsaQyCvPUyOcU6IV/QP1P/8ovCK6Fek54xqrptTCYnov7U4VTBN
|
||||||
DviSBGNeIv9Vhm7jhlJH0odFzBmBOkiUyUFV1h/6u2qpjz+H+qAX+5xx/++cGkW6
|
WhVxpTY19ZlxPxY+umhhg4bTf6oiRKGMXPe3MlYTGN4DTF3NE8g+Rld860GypHTt
|
||||||
4G69+7NP6JUksSbcvAl6Nk1sRsvTrcRdpmBO42/aUq7nlgOAxk9e0y7INYHe3Ycv
|
yHYr2sdibLV34JZk8W/E1S5RTeTWjKxMUHZCYaNadQEQRwyRWmFTdHkPiOLHOBru
|
||||||
N7ZTm7VOuIVopQfl8F2/tOIdJIm6hJfmJ/hdhxbDZKSRiejenU7vgdQgTM+PQ0l7
|
TBYAZJHP4DFegHL58+Z19vjdHtOHWMQWWKYNvKzV9m1lzbgT/MhrHqeGEWSQ9Tu0
|
||||||
0QVRP1mahh1EqsyqFrrVpv+o7XQsyldb8KCefWMEMGHrot944YTxzfwY3riaPXfS
|
kcvDK9iTfjgZyISPe8rpDM/6YZMSydSUgQ8TiE6YQFsJ3rkyRSEKSkH6CcqUD1jS
|
||||||
XgESSHvPYIgLIj+6bvvopB5v2q+NwfBciOrZekmWYTkN6cFOizp36JKIOA4Dq6z5
|
XAGv1EpFowmHVUXzMY1TciufOek51nEDfhbzpCX9QeyKIn7MVAZSWhn83vQUBNiH
|
||||||
0hwGgiPvYsu9WgbWYUY21qO9jvDmjT5Yym5ktbNogckXw3/TusVqPeAkdNIjZNU=
|
Y1wrvUB2X3egY6jQVv7nalsNvU7CeEvzxi1YrM7YtoSO6yPY7z2A6e/4Ev0h
|
||||||
=PSUH
|
=krxN
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
|
||||||
|
|||||||
@@ -62,11 +62,10 @@ data:
|
|||||||
reverse_proxy traefik.traefik.svc.cluster.local.:80
|
reverse_proxy traefik.traefik.svc.cluster.local.:80
|
||||||
}
|
}
|
||||||
|
|
||||||
# Docker VM services (via Traefik)
|
# Docker VM services (via Docker Traefik)
|
||||||
@alexscript host alexscript.vhaudiquet.fr
|
@alexscript host alexscript.vhaudiquet.fr
|
||||||
@clips host clips.vhaudiquet.fr
|
@clips host clips.vhaudiquet.fr
|
||||||
@jellyfin host flix.vhaudiquet.fr
|
@jellyfin host flix.vhaudiquet.fr
|
||||||
@mail host mail.vhaudiquet.fr
|
|
||||||
|
|
||||||
handle @alexscript {
|
handle @alexscript {
|
||||||
reverse_proxy 10.1.2.212:80
|
reverse_proxy 10.1.2.212:80
|
||||||
@@ -77,8 +76,11 @@ data:
|
|||||||
handle @jellyfin {
|
handle @jellyfin {
|
||||||
reverse_proxy 10.1.2.212:80
|
reverse_proxy 10.1.2.212:80
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Stalwart WebUI (now in Kubernetes, via k8s Traefik)
|
||||||
|
@mail host mail.vhaudiquet.fr
|
||||||
handle @mail {
|
handle @mail {
|
||||||
reverse_proxy 10.1.2.212:80
|
reverse_proxy traefik.traefik.svc.cluster.local.:80
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -7,3 +7,4 @@ spec:
|
|||||||
- cidr: "10.1.2.171/32"
|
- cidr: "10.1.2.171/32"
|
||||||
- cidr: "10.1.2.148/32"
|
- cidr: "10.1.2.148/32"
|
||||||
- cidr: "10.1.2.152/32"
|
- cidr: "10.1.2.152/32"
|
||||||
|
- cidr: "10.1.2.143/32"
|
||||||
|
|||||||
Reference in New Issue
Block a user