Compare commits

..
7 Commits
Author SHA1 Message Date
vhaudiquet 3efa9deb34 photoprism: truenas .local .lan artifact migration 2026-07-06 21:30:14 +02:00
vhaudiquet 32397ced96 stalwart: use OnRootMismatch groupChangePolicy 2026-07-03 15:00:45 +02:00
vhaudiquet b3047cbe3e dns: update TLSA records for stalwart 2026-07-03 09:43:00 +02:00
vhaudiquet c9af935148 stalwart: disable recovery mode 2026-07-03 00:38:44 +02:00
vhaudiquet bac134e2d4 stalwart: deploy to kube 2026-07-02 22:57:39 +02:00
vhaudiquet 30276fa4fb kube: expand ip pool allocation 2026-07-02 22:42:12 +02:00
vhaudiquet aa9452354a stalwart: restore 0.15.x for pre-migration phase
v0.16 introduced compatibility break with below. we will migrate to v0.16 on kube. for pre-migration we restore working setup.
2026-07-02 22:40:27 +02:00
15 changed files with 307 additions and 86 deletions
+1
View File
@@ -47,6 +47,7 @@ updates:
- "/kubernetes/home/home-assisant" - "/kubernetes/home/home-assisant"
- "/kubernetes/home/zigbee2mqtt" - "/kubernetes/home/zigbee2mqtt"
- "/kubernetes/infrastructure/authentik" - "/kubernetes/infrastructure/authentik"
- "/kubernetes/infrastructure/mail/stalwart"
- "/kubernetes/personal/linkwarden" - "/kubernetes/personal/linkwarden"
- "/kubernetes/personal/notesnook" - "/kubernetes/personal/notesnook"
- "/kubernetes/personal/photoprism" - "/kubernetes/personal/photoprism"
+8 -64
View File
@@ -77,70 +77,14 @@ _25._tcp:
ttl: 300 ttl: 300
type: TLSA type: TLSA
values: values:
- certificate_association_data: 5dfdb3cf31b26f23d87c09f3a0cef642f64069a9fb7cfe29270bb5dc0f1e16bb - certificate_association_data: CC6230E3A88A173D11C7F614ACFB4FE7B57A01F649ED1ADEE5F953213D4C6607
certificate_usage: 2 certificate_usage: 3
matching_type: 1 matching_type: 1
selector: 0 selector: 1
- certificate_association_data: 76e9e288aafc0e37f4390cbf946aad997d5c1c901b3ce513d3d8fadbabe2ab85 - certificate_association_data: 731B7CD6FA08C4A56060172BF8E30563919139F16265A38EC35B2A1F41CE2B6B
certificate_usage: 2 certificate_usage: 3
matching_type: 1 matching_type: 1
selector: 0 selector: 0
- certificate_association_data: 4e32b7ee52c9bd2a15b2df3cae5e3b060d737d71faaaac25336c5f193cbdb52ed2fdf38b29aea9fb97f59c8f86e75b5c364309a232623a99e638116ed66063fd
certificate_usage: 2
matching_type: 2
selector: 0
- certificate_association_data: afab698cbbbf892ebb555e09175056c1d4630fe7c350f44dcc6e71843d3b290df00d30ab4e356b630c69169d7633788338922fb637cf5b9f7be20a413eeaa518
certificate_usage: 2
matching_type: 2
selector: 0
- certificate_association_data: 3586d4ecf070578cbd27aedce20b964e48bc149faeb9dad72f46b857869172b8
certificate_usage: 2
matching_type: 1
selector: 1
- certificate_association_data: d016e1fe311948aca64f2de44ce86c9a51ca041df6103bb52a88eb3f761f57d7
certificate_usage: 2
matching_type: 1
selector: 1
- certificate_association_data: a1ef14fea3ca15a552d42665d2fe685672cfdd903de4b370b0d7d87c6d31b5df07142483f36e0e15e16b58f9ba1cbdeeebd4bcb8d74ab7ea32a087db2105f402
certificate_usage: 2
matching_type: 2
selector: 1
- certificate_association_data: f8a2b4e23e82a4494e9998fcc4242bef1277656a118beede55ddfadcb82e20c5dc036dcb3b6c48d2ce04e362a9f477c82ad5a557b06b6f33b45ca6662b37c1c9
certificate_usage: 2
matching_type: 2
selector: 1
- certificate_association_data: a69ec216999308f0ee575cdef98d6edabed8a6b4d2328e050ac9c7fa06404ad9
certificate_usage: 3
matching_type: 1
selector: 0
- certificate_association_data: ccae2719a01f7a6d17d939d8ec13324b7bdb0921ea55d5bfc2f226e54b8c15dd
certificate_usage: 3
matching_type: 1
selector: 0
- certificate_association_data: 7cd33aa6bafc850cc89d008fbd0a5cea942c6a573d605984f174fbe7360abbf71fc157ffe0324e380a8dfea62047b9aa140d5899188402ac677c29f96cc1118e
certificate_usage: 3
matching_type: 2
selector: 0
- certificate_association_data: 8149784990ba7e448295f9c4eb22abcaa4ecefa1b44f1a71ea13d6827d7068c6469cf5fb08a8ae772c1ef59cddbcfd84d744713c48e985136a234b494511fd03
certificate_usage: 3
matching_type: 2
selector: 0
- certificate_association_data: 08f3ffd1b6027093c136f6bb5bc1645a8db31cf2a4392b779c2a2045e152b8b8
certificate_usage: 3
matching_type: 1
selector: 1
- certificate_association_data: 12b3946513281ab20ebee4d38d2e139cac1688420015db90ee8e932fe153bc89
certificate_usage: 3
matching_type: 1
selector: 1
- certificate_association_data: 7b60aee1a230de2c32c0252540c606897ad66cbabc7331c2d40b7dd0e3249e0cc53e145605e610d8dc2f41dd16e12f51dca4641d13e748553bd0f596455dae77
certificate_usage: 3
matching_type: 2
selector: 1
- certificate_association_data: 8cee22274c3f828eda9d18c9954ed0a3ad5172e71b7852c780384bf3828ff1bb26fca899395e99e4d191c2d1e0a55404f97e76bb7d4ad8dff71c6c271d34de49
certificate_usage: 3
matching_type: 2
selector: 1
_caldavs._tcp: _caldavs._tcp:
octodns: octodns:
cloudflare: cloudflare:
@@ -1,6 +1,6 @@
services: services:
stalwart: stalwart:
image: stalwartlabs/stalwart:v0.16.10 image: stalwartlabs/stalwart:v0.15.5
container_name: stalwart container_name: stalwart
networks: networks:
- default - default
@@ -0,0 +1,24 @@
# TLS certificate for the Stalwart mail listeners (SMTP/IMAP/POP3 STARTTLS + implicit TLS)
# and the management WebUI hostname.
#
# Issued by cert-manager via the letsencrypt-production ClusterIssuer (Cloudflare DNS-01).
# The resulting Secret (mail-vhaudiquet-fr-tls) is consumed in two places:
# 1. The Stalwart HelmRelease mailTls block -> mounted into the pod + pushed to
# Stalwart by the tls-sync sidecar (JMAP) so SMTP/IMAP/POP3 present this cert.
# 2. The chart ingress (TLS termination is handled by Caddy in this cluster, so the
# ingress is TLS-less and only routes HTTP to the mgmt port).
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: mail-vhaudiquet-fr
namespace: stalwart
spec:
secretName: mail-vhaudiquet-fr-tls
issuerRef:
name: letsencrypt-production
kind: ClusterIssuer
commonName: mail.vhaudiquet.fr
dnsNames:
- mail.vhaudiquet.fr
duration: 2160h # 90 days
renewBefore: 360h # 15 days before expiry
@@ -0,0 +1,15 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: stalwart
resources:
- namespace.yaml
- repository.yaml
- certificate.yaml
- recovery-admin-secret.yaml
- release.yaml
secretGenerator:
- name: stalwart-values
files:
- values.yaml=values.yaml
configurations:
- kustomizeconfig.yaml
@@ -0,0 +1,6 @@
nameReference:
- kind: Secret
version: v1
fieldSpecs:
- path: spec/valuesFrom/name
kind: HelmRelease
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: stalwart
@@ -0,0 +1,47 @@
# Recovery / bootstrap administrator credential for Stalwart.
#
# This Secret is referenced by:
# - recoveryAdmin.existingSecret in the HelmRelease, which injects it into the
# Stalwart pod (and the tls-sync sidecar) so the cert-manager certificate can
# be pushed to Stalwart via JMAP. Keep it present for the lifetime of the
# deployment; the tls-sync sidecar needs it on every cert renewal.
#
# The username/password here are ONLY the recovery account.
apiVersion: v1
kind: Secret
metadata:
name: stalwart-recovery-admin
namespace: stalwart
labels:
app.kubernetes.io/name: stalwart
app.kubernetes.io/component: recovery-admin
type: Opaque
stringData:
username: ENC[AES256_GCM,data:CYm0+Kw=,iv:UdgReqdb8GdoOfv1ZEW/7BAvY3vV88httj3W976eV0Y=,tag:PPrDQY/mo0RcJiz/cmxFSA==,type:str]
password: ENC[AES256_GCM,data:r0mPJ4qKIhAWDw==,iv:L5+OKTznQgDUgqttHwdW0X66vz+JPTqWdwYPGklCuj0=,tag:WNOj7ZjC6Lx76UlPsgSDhg==,type:str]
sops:
lastmodified: "2026-07-02T20:57:39Z"
mac: ENC[AES256_GCM,data:lIVOaMsFV9F1/yLvykA3LH5ukn9PIba6N8cE9RGdcFepM56tBYlY6fbkcKTtojyAkoYov6OCjgTsOkMtUzRdGES4Zti6zHB3cTPal8bJCf5cAfYnGFRcQaASIkVjNZkQSJ2pDRP4rZqioCHuj2/a6uJZ4hhtSpxrECYbpzD2Gk8=,iv:31fXHsWH1ZP00Od5DSxgYPuw87NqQNfWl4vFtoouIHk=,tag:u5cJn231VT2ZTmlcdpBz0g==,type:str]
pgp:
- created_at: "2026-07-02T20:57:39Z"
enc: |-
-----BEGIN PGP MESSAGE-----
hQIMA7uy4qQr71wiAQ//fYBIypexVfQJn5BxVCRgZKRBcYw78XSoPjFYWFyk5F7I
UFRQKtdZOVVhgNHtFJOVyBvl1sAmmzAt3xq3L+Z5bvtrUfZ33tTp7ty+MmSmuutS
wquSh4NOHUYENGvo5pWsgVwQDj5bI2qUq4L92aedpB2XJycb7/Df7BWFKNMNgWdt
l+Hj9HEJWxmFjrz1MQJEL2r5WOx9/hK7uatbDTXVFPqyyW1aCM5XOkKErTuc3Avn
8tNNlvP1aqhI/2dHfOSZ1l0/PHhdi3RBmGa3BfAZUXEseBEesIK/EaJZXMjQYhF2
5tAPQ1irqg8LLv9mhrUD2mWaUigcuZ1EeyfZFvNtY/noF8fyZny1jra0sDe4CmQP
7uyP6CNRWPCikutUw45oxtw+/Us5Ld8xzJxhDEm0e+8FFiAK/SFSOx57JbjNzoCj
dqHU3UIzyp9VVZohqW7xdHOW64fgDI41BDKBsEiKraLnZUoXL2Lx0lnjxayJqVsD
2pX9D5YXzmtwFvUU5ZpcCzUWFu9MVxSfp6HdKvocGdtpSz7J23PQvHtkv20GxJYd
J45RYGgekuJ2EXc9kPaCuSex/0BKtYybOk5ANRv2yGeUZlc6EoW8/GZ4sHXPY6um
tt1DdIsMNMjAU68EgRkhmQnFAkZixJVdDR3u4MNXFUr0WdVIqzjFBavyrkcK6HjS
XAGhFNWdk5DNZ1ChGrMKEnYCZEB6XNkofa7S2xAomEoxyuCq7X2vbfBfqDQ/Rtcf
kSx0TpIOSHxefSFMduPz90rDqdZgUW0D3GND0PD5XRFFiJxxdrRYPux9MDMd
=Ef8e
-----END PGP MESSAGE-----
fp: DC6910268E657FF70BA7EC289974494E76938DDC
encrypted_regex: ^(data|stringData|.*.key|.*.crt)$
version: 3.10.2
@@ -0,0 +1,21 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: stalwart
namespace: stalwart
annotations:
homeprod.io/essential: "true"
spec:
interval: 1m
chart:
spec:
sourceRef:
kind: HelmRepository
name: stalwart-helm
namespace: stalwart
chart: stalwart
version: "0.7.5"
interval: 1m
valuesFrom:
- kind: Secret
name: stalwart-values
@@ -0,0 +1,8 @@
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: stalwart-helm
namespace: stalwart
spec:
interval: 1m
url: https://kgrubb.github.io/stalwart-helm-chart
@@ -0,0 +1,147 @@
# Stalwart Mail Server - Helm values
#
# TLS for the mail listeners is sourced from cert-manager: the
# mail-vhaudiquet-fr-tls Secret (see certificate.yaml) is mounted into the pod
# and pushed to Stalwart by the chart's tls-sync sidecar over JMAP, which also
# calls ReloadTlsCertificates on every cert-manager renewal.
# Container image
image:
repository: stalwartlabs/stalwart
tag: v0.16.11
pullPolicy: IfNotPresent
# Single-node RocksDB deployment.
replicaCount: 1
role: ""
pushShard: ""
# Recovery / bootstrap administrator.
# The Secret (stalwart-recovery-admin) is required for the lifetime of the
# deployment because the tls-sync sidecar authenticates to Stalwart's JMAP API
# with these credentials on every cert-manager renewal.
recoveryAdmin:
enabled: true
username: ENC[AES256_GCM,data:83oORcE=,iv:X07gQXkAx2wdqEcOPi5mGTVoFkJjDHBKMCYUjpg3qv4=,tag:qvspLaPSsrld4UV/qXb0cw==,type:str]
password: ""
existingSecret: ENC[AES256_GCM,data:KuZYrQk+YQhciNRTHqOlZdqZWJ3o15I=,iv:x/cm4USFZqWE5xuuF7tUPm593NqX1kbmeKv0x2wzk8s=,tag:G9FRYYaJhWovN+LB/gLaoQ==,type:str]
usernameKey: username
passwordKey: password
# Recovery mode suspends mail services and exposes only the management listener.
# Ship production values with this OFF.
recoveryMode:
enabled: false
port: 8080
logLevel: info
extraEnv: {}
extraSecretEnv: {}
# The bootstrap hook Job provisions a *fresh* domain/accounts/OIDC directory.
bootstrap:
enabled: false
# cert-manager TLS integration for the mail (SMTP/IMAP/POP3 STARTTLS + implicit
# TLS) listeners. The Secret below is produced by the Certificate in
# certificate.yaml (letsencrypt-production, Cloudflare DNS-01).
mailTls:
enabled: true
existingSecret: ENC[AES256_GCM,data:Y+LfFx7nuCSMGqo2o3QoHG1Br+MYlQ==,iv:dLJDYmK2gEmNq5VnbpEJWFM1xLLT5jXqxB2WQQ4dr3E=,tag:Ya2cTf/ZpJdzFnwH53iZZQ==,type:str]
certKey: tls.crt
privateKeyKey: tls.key
mountPath: /etc/stalwart/tls/ingress
hostname: mail.vhaudiquet.fr
domain: vhaudiquet.fr
# How often the sidecar re-checks the mounted cert for changes.
reloadIntervalSeconds: 300
# config.json contents - ONLY the DataStore object. All other settings
# (listeners, storage backends, domains, accounts, certs) live in the database
# and are managed via JMAP/WebUI.
config:
'@type': RocksDb
path: /var/lib/stalwart
# Main Service: ClusterIP. Used by the Ingress for the management WebUI (mgmt)
# and for in-cluster access. Mail L4 ports are exposed separately via mailService.
service:
type: ClusterIP
ports:
smtp: 25
smtps: 465
submission: 587
imap: 143
imaps: 993
pop3: 110
pop3s: 995
sieve: 4190
http: 80
https: 443
mgmt: 8080
# Dedicated LoadBalancer for SMTP/IMAP/POP3/Sieve (L4). HTTP/HTTPS/mgmt are NOT
# exposed here - the WebUI is reached via the Ingress (Traefik) below.
# The WAN router NAT for 25/465/587/993/995/4190 must be repointed to this IP.
mailService:
enabled: true
name: stalwart-mail
type: LoadBalancer
loadBalancerIP: 10.1.2.143
annotations: {}
# WebUI ingress. TLS is terminated by Caddy at the edge (wildcard cert), so the
# path is: public -> Caddy (TLS) -> Traefik (HTTP) -> this Ingress -> mgmt:8080.
# No TLS block here.
ingress:
enabled: true
annotations: {}
hosts:
- host: mail.vhaudiquet.fr
paths:
- path: /
pathType: Prefix
portName: mgmt
tls: []
# Persistent volume for the RocksDB data directory.
persistence:
enabled: true
accessMode: ReadWriteOnce
storageClass: ""
size: 50Gi
resources:
requests:
cpu: 250m
memory: 256Mi
limits:
cpu: "1"
memory: 1Gi
# Override chart defaults to add fsGroupChangePolicy: OnRootMismatch.
# Without this, kubelet recursively chowns every file in the NFS-backed PVC
# on every pod start (15k+ RocksDB files), causing multi-minute delays.
# OnRootMismatch skips the recursive chown if the volume root already
# has the correct owner (UID 2000).
podSecurityContext:
fsGroup: 2000
fsGroupChangePolicy: OnRootMismatch
runAsUser: 2000
runAsGroup: 2000
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containerSecurityContext: {}
sops:
lastmodified: "2026-07-03T13:00:45Z"
mac: ENC[AES256_GCM,data:qoGDDt03xtJbPH+I3edSsFJagZSlCcMk4XoFc/I2QZEm+45DjsCWe9Q7e9zhn5kF3HBNBwNCgEzJmq2Fn/vemMWHwI4+QZW6nkk5cYTb3r8+WysSeUyt2+Y7EjyQGwI6+2LrCBlJIqmKfpPtT7Y8ZbwRBedoVqFtnNVH5441FMY=,iv:fvfnedCEGXyPw4yRLCtKoAnzz8h3jyJOwpqA33NNJOI=,tag:fPd7RJAMMounXVkIoKrptQ==,type:str]
pgp:
- created_at: "2026-07-03T13:00:45Z"
enc: |-
-----BEGIN PGP MESSAGE-----
hQIMA7uy4qQr71wiAQ//WA7P2WeKV6QFKotw5UP1MXcdI9THypFFly4sweJ5MC+e
Lzy/zCidGCM3Cu+dJaaPJNKtfPfagQJ9FzHrnvRcHoCbKS7sTAqugdwt4uyplem9
l03kQWZfDj8R8MHQnAKWNmJDiJkjCoqHdR5f2JtS+n7MngI53SecY2fsFOXRbYJI
hfH1BR+agLjIHc+gOF340GJp4UT+Q6BZOKg8K5O4PYk1Xwj3pi6YFuhiedKHSybF
Ij9OWdTqpofeG3fhwd3jHLW+0WYiFNrVlchfClEDWMMc0UfS6Bfo96IL0JIoYlHD
4Zt8EEyjvAJ5478RTKTobMlsSUC5U51Wn6paapZ5zicCHDzdP2yTtwtSKK0Mdp3W
qt/pZoR4EyM+I2XCKp+z7N5FtH8cahtfZiUOBwQ4NK9Fz+2UBxtP2QzGj8YpJmWu
OkbGoSgwn+8bcNnRwnADTzdiTWf/a56WErp1NvuqF8VqdGzsJR9EgyYwENl+m+U8
fbTY58iAJDDpY5ipPL5v+lo0Fw5DrnQ0NPAm1ORi+rMJy0KUjgAzdS6lL5oWGfAC
rzbzThGpRt0E7O296pht8TCBFHqiKbiOdGEBXO3+w9NrvOgULno4+s88vu6KMvFL
s3MHz7oIgfwel7V6bVc/ZQvHYS3YHjG41fwn00cpKI/WRN8z5MnSwwkegD2Wv8fS
XgEqL6kQPgk97779c0jo9CJA8O6QaSvGyd1j680tN1NN9V64rJOaj/818SgwFLrA
XWaqrOnz8FIspqO836t6OaLq5WwzOtOR6zs7cUk6h1RHgwlFQ+0n1o6qYf6Q+CA=
=HnWo
-----END PGP MESSAGE-----
fp: DC6910268E657FF70BA7EC289974494E76938DDC
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
version: 3.10.2
+1
View File
@@ -22,6 +22,7 @@ resources:
- home/zigbee2mqtt - home/zigbee2mqtt
# Infrastructure # Infrastructure
- infrastructure/authentik - infrastructure/authentik
- infrastructure/mail/stalwart
# Personal # Personal
- personal/linkwarden - personal/linkwarden
- personal/notesnook - personal/notesnook
+18 -18
View File
@@ -23,7 +23,7 @@ persistence:
originals: originals:
enabled: true enabled: true
type: nfs type: nfs
server: truenas.local server: truenas.lan
path: /mnt/main_storage/valentin/Photos path: /mnt/main_storage/valentin/Photos
mountPath: /photoprism/originals/photos/valentin mountPath: /photoprism/originals/photos/valentin
mariadb: mariadb:
@@ -36,27 +36,27 @@ mariadb:
repository: bitnamilegacy/mariadb repository: bitnamilegacy/mariadb
tag: 12.0.2-debian-12-r0 tag: 12.0.2-debian-12-r0
sops: sops:
lastmodified: "2026-05-01T22:39:49Z" lastmodified: "2026-07-06T19:30:14Z"
mac: ENC[AES256_GCM,data:YGVQb50DrFv/ehU+dxsoP/e8ARKVPfr/6c2x1pQbZ7cNiNu7k1Zgt+bEHkkKm+FT44bltL374Jf2HqT/0gvmgMGp/8ukjZ5hRLwbqS1fOKR8SVQ8fp2EId0P7HcRl7Qqr6lF15hKXQ+SPl6KDPvDWKh0pq192W8dP76D7h5aKDw=,iv:c1xytratCfO8V4nkdvxeKT2kWOYHBkwoTc5Ic+yjpWQ=,tag:kdxAidCO1VLPxiwq3eCRxQ==,type:str] mac: ENC[AES256_GCM,data:QgOnL1dsq2S78nRD+xe08w3u0+bRfNML/ea9P9v0TBCQq5EmKj6yPKJApvttyeGUDJDGo9Ds17a9XLDFtOl9ORoax6E50VqJSnc1ElE2l5EFogl3JPuMdQxEzXniaCjOSrfMNWNdo7fHN/qcX0Gzs7BL9pw+NyQLv4kFcDYQv78=,iv:buV08iLiLB5BJ5JYfn4blmFb/eu/EtpnWsxT5IfyXfQ=,tag:8egGKWNa7CEql9t6zWHlOQ==,type:str]
pgp: pgp:
- created_at: "2026-05-01T22:39:48Z" - created_at: "2026-07-06T19:30:14Z"
enc: |- enc: |-
-----BEGIN PGP MESSAGE----- -----BEGIN PGP MESSAGE-----
hQIMA7uy4qQr71wiAQ/9F+u/hWM4smi4yqnU7vzRfWwjCuvdtWAR6N4MqiBLFfqr hQIMA7uy4qQr71wiAQ//Qg0OcwKr1mG40IoYmABD8b+/W+X5zTyyht9QCpNtRSVO
tpzY8UCfaTlfEtwDZWUSN/gzZG56YcMTR6OOrCQ8rkiKYGwuj92Z8LgpcDRBAHeG JzhtMl9YZHLqwkiwBqW+hvfIKXYtYBNl2TsAZ57xcE60lr72bHfqXkO24hf9+jvq
gYaNG9vRmmzyZpD6K6pSoG8lk7mzB1Tp80me9E7LJTDhAn70cDATLp1wADkD0KF1 jmFwK1Mo/zf0/b3R8gFqEmg5mW97jdmEXHfRrzzyaAXhGk0rWfLGBSbaif71a/dj
pq44qPcRaem42kEx6Um1sAy5NiBBxvYqdKPRXLs0q1EyZByxKjlhZi0qasCfe4lJ jVu+Vf48LsEnUYH3oO2ASY3OlVwKAn5njfyIz2MWwY5iohOsiJwJu2WiotI+zCFI
fsdduUgRi3Td7KvfhQ1e6jjNNMpyZIHbME3Hn18h5PxVd1B3FzzBzSHlaDKBQsYT VOfftPCYvJyVKGG5bE3GHOjAlbNqHtRCn9Bm/mXQVyLkAU9ik+i1PABGEU9nc09q
2cx6VMGVqM4dy+CHkpE+QlAA0EOhS0b/7FwppCgEhlEvbH7uCjq/13vZdKoUIwqt +IcO3Njo7MRtZU9pctMZLvRSbxvEx2bZOKSXe6nhVK324Qr0cETX+/GuDZn3SeVy
AaHPaf/HX7PipQjoQf7vjfaMjPwCFwqoeK2cVNmgK0j0b2CyjLDDs5xh0SuFt/Ia pyHR/BtpGXtqyWsaQyCvPUyOcU6IV/QP1P/8ovCK6Fek54xqrptTCYnov7U4VTBN
DviSBGNeIv9Vhm7jhlJH0odFzBmBOkiUyUFV1h/6u2qpjz+H+qAX+5xx/++cGkW6 WhVxpTY19ZlxPxY+umhhg4bTf6oiRKGMXPe3MlYTGN4DTF3NE8g+Rld860GypHTt
4G69+7NP6JUksSbcvAl6Nk1sRsvTrcRdpmBO42/aUq7nlgOAxk9e0y7INYHe3Ycv yHYr2sdibLV34JZk8W/E1S5RTeTWjKxMUHZCYaNadQEQRwyRWmFTdHkPiOLHOBru
N7ZTm7VOuIVopQfl8F2/tOIdJIm6hJfmJ/hdhxbDZKSRiejenU7vgdQgTM+PQ0l7 TBYAZJHP4DFegHL58+Z19vjdHtOHWMQWWKYNvKzV9m1lzbgT/MhrHqeGEWSQ9Tu0
0QVRP1mahh1EqsyqFrrVpv+o7XQsyldb8KCefWMEMGHrot944YTxzfwY3riaPXfS kcvDK9iTfjgZyISPe8rpDM/6YZMSydSUgQ8TiE6YQFsJ3rkyRSEKSkH6CcqUD1jS
XgESSHvPYIgLIj+6bvvopB5v2q+NwfBciOrZekmWYTkN6cFOizp36JKIOA4Dq6z5 XAGv1EpFowmHVUXzMY1TciufOek51nEDfhbzpCX9QeyKIn7MVAZSWhn83vQUBNiH
0hwGgiPvYsu9WgbWYUY21qO9jvDmjT5Yym5ktbNogckXw3/TusVqPeAkdNIjZNU= Y1wrvUB2X3egY6jQVv7nalsNvU7CeEvzxi1YrM7YtoSO6yPY7z2A6e/4Ev0h
=PSUH =krxN
-----END PGP MESSAGE----- -----END PGP MESSAGE-----
fp: DC6910268E657FF70BA7EC289974494E76938DDC fp: DC6910268E657FF70BA7EC289974494E76938DDC
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$ encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
+5 -3
View File
@@ -62,11 +62,10 @@ data:
reverse_proxy traefik.traefik.svc.cluster.local.:80 reverse_proxy traefik.traefik.svc.cluster.local.:80
} }
# Docker VM services (via Traefik) # Docker VM services (via Docker Traefik)
@alexscript host alexscript.vhaudiquet.fr @alexscript host alexscript.vhaudiquet.fr
@clips host clips.vhaudiquet.fr @clips host clips.vhaudiquet.fr
@jellyfin host flix.vhaudiquet.fr @jellyfin host flix.vhaudiquet.fr
@mail host mail.vhaudiquet.fr
handle @alexscript { handle @alexscript {
reverse_proxy 10.1.2.212:80 reverse_proxy 10.1.2.212:80
@@ -77,8 +76,11 @@ data:
handle @jellyfin { handle @jellyfin {
reverse_proxy 10.1.2.212:80 reverse_proxy 10.1.2.212:80
} }
# Stalwart WebUI (now in Kubernetes, via k8s Traefik)
@mail host mail.vhaudiquet.fr
handle @mail { handle @mail {
reverse_proxy 10.1.2.212:80 reverse_proxy traefik.traefik.svc.cluster.local.:80
} }
} }
+1
View File
@@ -7,3 +7,4 @@ spec:
- cidr: "10.1.2.171/32" - cidr: "10.1.2.171/32"
- cidr: "10.1.2.148/32" - cidr: "10.1.2.148/32"
- cidr: "10.1.2.152/32" - cidr: "10.1.2.152/32"
- cidr: "10.1.2.143/32"