mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-09-25 18:28:25 +00:00
Compare commits
13
Commits
bc48538689
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
818ed232e4 | ||
|
|
b2f656c757 | ||
|
|
3f986b65ab
|
||
|
|
e354a56e15
|
||
|
|
bd5fab7419
|
||
|
|
e242b2ddce | ||
|
|
0d81f4a5d2 | ||
|
|
56e5992536 | ||
|
|
77a5225358 | ||
|
|
7fd1a5e52f | ||
|
|
23748ee4fc | ||
|
|
45c3970a27 | ||
|
|
fdb2634a46 |
@@ -383,6 +383,13 @@ photos:
|
|||||||
ttl: 300
|
ttl: 300
|
||||||
type: A
|
type: A
|
||||||
value: 82.64.154.58
|
value: 82.64.154.58
|
||||||
|
pkgatlas:
|
||||||
|
octodns:
|
||||||
|
cloudflare:
|
||||||
|
auto-ttl: true
|
||||||
|
ttl: 300
|
||||||
|
type: A
|
||||||
|
value: 82.64.154.58
|
||||||
sse-nook:
|
sse-nook:
|
||||||
octodns:
|
octodns:
|
||||||
cloudflare:
|
cloudflare:
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ terraform {
|
|||||||
required_providers {
|
required_providers {
|
||||||
docker = {
|
docker = {
|
||||||
source = "kreuzwerker/docker"
|
source = "kreuzwerker/docker"
|
||||||
version = "3.6.2"
|
version = "3.9.0"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ valkey-cluster:
|
|||||||
# Use standalone Valkey (replaces 'redis' in chart 12.x)
|
# Use standalone Valkey (replaces 'redis' in chart 12.x)
|
||||||
valkey:
|
valkey:
|
||||||
enabled: true
|
enabled: true
|
||||||
master:
|
primary:
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 100m
|
cpu: 100m
|
||||||
@@ -30,10 +30,10 @@ postgresql:
|
|||||||
global:
|
global:
|
||||||
postgresql:
|
postgresql:
|
||||||
auth:
|
auth:
|
||||||
postgressPassword: ENC[AES256_GCM,data:PtWMsukqbrWiVg==,iv:iQtDckrih/3ZKopzD9eEViOMZrvSulmCI5tHCsJph1A=,tag:7S54w4ADG7+8QNiLDw2Q0A==,type:str]
|
postgressPassword: ENC[AES256_GCM,data:AGdZp0KNk6+v+w==,iv:dc7B8GYA1hlC6VgO1m3jdHimIVb4QeR1DTmh9kqRDa4=,tag:JEFWOgvgvUDJ+S9yS446cA==,type:str]
|
||||||
password: ENC[AES256_GCM,data:jLC1oEl+ZAnpbw==,iv:PliGMmxHKn3eEt8uvsv9wL4syk91EC5OpA7AL5J0+4o=,tag:Oan4ek7m0Cxnl5bzOCGHXw==,type:str]
|
password: ENC[AES256_GCM,data:kuR59jqrN/YFmA==,iv:qAIwiTzi2Fr9R9fIc3sfPqhIHSPI8K3eNmed8DBm7PQ=,tag:hf7CMUissSbO4RVn+kRUJw==,type:str]
|
||||||
database: gitea
|
database: gitea
|
||||||
username: ENC[AES256_GCM,data:ricveNc=,iv:rPrHKhIzsNEQzoaX2cPDvVWjR7NIxsN1tBlzLB80IQ0=,tag:n64SpL6qM/IT9D7t85/Lvg==,type:str]
|
username: ENC[AES256_GCM,data:rCEYTAA=,iv:zeWzB+vpMl+oGUfQRPYFneLwnXF7Dlg4XAYB4QynAyk=,tag:zqJDiBiKJJIDgNKdOtGlMg==,type:str]
|
||||||
volumePermissions:
|
volumePermissions:
|
||||||
enabled: true
|
enabled: true
|
||||||
primary:
|
primary:
|
||||||
@@ -63,6 +63,7 @@ postgresql-ha:
|
|||||||
persistence:
|
persistence:
|
||||||
enabled: true
|
enabled: true
|
||||||
subPath: data
|
subPath: data
|
||||||
|
size: 30Gi
|
||||||
extraVolumes:
|
extraVolumes:
|
||||||
- name: git
|
- name: git
|
||||||
nfs:
|
nfs:
|
||||||
@@ -76,8 +77,8 @@ gitea:
|
|||||||
oauth:
|
oauth:
|
||||||
- name: Authentik
|
- name: Authentik
|
||||||
provider: openidConnect
|
provider: openidConnect
|
||||||
key: ENC[AES256_GCM,data:9UuG23PYFiWrQKJX5xGxMgyWKLPFCxKjDUYJd59rMWcdAw619/v/Bw==,iv:AfHV1MzbYi5Z5Bb63/51Hmy9rM247b4quwKCzo7MpYw=,tag:pfpz7hhZyIUjIGGcxZVx/w==,type:str]
|
key: ENC[AES256_GCM,data:LekdKlJJX6AYZX2PgooenJtANvE8HNdzePN9yeljrnoKV7pbexDnAw==,iv:pZm4+Dj2uqprBRIgchq78nEzqkC/zVoiyRK0cj98WPo=,tag:iSiuwP8N6BBVeGWS54j+dw==,type:str]
|
||||||
secret: ENC[AES256_GCM,data:PKFx/LhjwWJluC6/RHc1eMgw4TZXkXymNCrc7TQU6Bp5rGKHMvACC+G+MjXGylIMZVt65LHWq5YEHJNjO8HMsa4ejGukXDuU9sCgKaOOniCs3EQivfVsCCHtF/G48eULPkege7JRzTbmJSYJDnscsSikwvUDChy+zGlC2ZmBZjk=,iv:qsIaaeXepJ9ECilo+05+A0i2joxV0svBOjgL37DkimE=,tag:/3Xer7Yb6QyUtmPIOvSLQQ==,type:str]
|
secret: ENC[AES256_GCM,data:J7WJghH6Xp9Fg3Y+PO1lN1mEEJ0HbVSM1YP2d8//NX2xmYK/PK1y6xSVQ4+VSsYTZhIAM3ZXVrBE/5smuNLUZkoj2EKY275fXcN2kOkEwiftdsJHSKdevCtO57TQipJToh6mfLxz51LDxpz85rVNj4Rvra1d9UvC5x1nUBm8AR0=,iv:lMiMQGsKn4ZxFctakj5MyVlX+8Wu93d5wM9cIqEBhSc=,tag:CkuTAGJqg+dUzyP9z5gwzw==,type:str]
|
||||||
autoDiscoverUrl: https://authentik.vhaudiquet.fr/application/o/gitea/.well-known/openid-configuration
|
autoDiscoverUrl: https://authentik.vhaudiquet.fr/application/o/gitea/.well-known/openid-configuration
|
||||||
config:
|
config:
|
||||||
APP_NAME: Gitea
|
APP_NAME: Gitea
|
||||||
@@ -113,27 +114,27 @@ resources:
|
|||||||
memory: 1Gi
|
memory: 1Gi
|
||||||
replicaCount: 1
|
replicaCount: 1
|
||||||
sops:
|
sops:
|
||||||
lastmodified: "2026-09-09T21:39:30Z"
|
lastmodified: "2026-09-22T20:35:36Z"
|
||||||
mac: ENC[AES256_GCM,data:ACBKJLGUfWw9T3fOhQMT251gcLzG3bUXjUqBxG1DuPl8c8bblaIpLOu0QsrfQziQY3jM0DFJ2W/I2vjkrhCuCaZhZCtRg2nzUk+7HelqjEdKLphSuIdlHIkz7Icu+khShrwTgmQiE00Gg1WUsLRkKBgNsOm3TMK4wB874iBvSYY=,iv:Idp0+UBXaRFkpOFKFoRrLKuN1mOmfM7pukC22KkNiCU=,tag:fL9DzAo8FSx4PblVlTHtaQ==,type:str]
|
mac: ENC[AES256_GCM,data:xGtSdlGuJL3qSbnfbh/ON1q3c+n6l991fCy9t9ZLnrvSrU15vkK/WVHh84V132C72pEakwRy8nFcUl7KT3C3J2l2uJHJyDWDqA8NTvHq7FAcomKGKpNOqAOFXVUKSr6O4BtQr9x6h4jzAZSlpaTx3GEiLRzygSkZmcEcaXZ6/hU=,iv:JfQ3W3UZV1m1SkapNmUpZ1lkxgTs5F0auXukupK/yAg=,tag:xCNpJUc5mPv2dBhS+ob+fA==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-09-09T21:39:30Z"
|
- created_at: "2026-09-22T20:35:36Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMA7uy4qQr71wiAQ/+PK0/kUHlc+exa8slolUeTGjHzd/R1Dtux/+HJdC9Vpow
|
hQIMA7uy4qQr71wiAQ/8DiM04ZZ18qFndWSlo+hHV05hlt7GmwG9dx/3xEXgpdEb
|
||||||
ImAQvIdkEjwL0FmoA7Z4val/Wzx/YzFJ5r6sADNaQ9EG7QO+I8WY3VrKj5aRi0Qz
|
TkA3HNi5rUMvA8j/mStmP4sZiqrxlPk9sdMtVsPAppT3qAihcF3DyyUFYkSoY3oF
|
||||||
+FgHAgng+wdRCCBoxv9Z+MTPSl4TwrKsbrulHAg7EayDKxwGzkyMrnxvukRqD8GB
|
Et5qeeC6DP1aKdsgAQVVZyeLy7l/CbO5CYORm5+TuGmnr0HxN1qZimbF15pspvNN
|
||||||
iMQCUadudR458fzB04dkhljAbl/FqX5ppflzEoGVCiRSBcWNkaHgyYqopYGzMASy
|
9pprI7XDKb6QEbXhADN9gafNwTIQgv3LGQVdoQgfyzZEcQR8O5bxUFTwdR9LO646
|
||||||
KTzoV01adnOZY+xeZa5GasgCEbCU3BDesD9vBb+sFsRugVuRHzdyqp3nVBwudpeh
|
zogHuQfPC70jpA2IRxdBHuSTjDkZimyehsKPzq7MpBso/85q3q1TlSQKJsjxZWrZ
|
||||||
OcE9MOMyBN1SAdx9RCsB8aHWYndF1dim84ZWgQThkLlA+7CWJt/NyFYwmMdqqzSv
|
NBKmEhL/Q4M+8mj+N/aVFJldIUF2Juto5d2BUuIG/lBtNL2QHdiJN3Rxc1gL4qP2
|
||||||
C7slojC6B8bb3863c5w3qe9TPPBwyTOcuNTMunr6wXidlPZWtsImhu/RX9fqzFjZ
|
eZYESQ6IRXAycUXAQgMJf5p/lhgmVjv8b3lhKSFJq66hZyo5g6wdhLIEunPglNbP
|
||||||
9X1+wAjAfs7AASeNJLFYqiPrknSAA3JumQZtrFC5dejpTj9H2ns6DkiHSZy8FA8O
|
BcJXUbl5SScTgOAi9o/soezUuggvzgg3zwM38PAghve1/j0rL7EupYX+u2v7zbUH
|
||||||
RuZ8hv/L8L8oilbubKnKFZLhR8lh8A1jXHUxzaEC/L4o4cd7/3TlEms/51yM9qYx
|
BA7T30SnkvDCmTzW4+Sac1dg/w06u+4oSGTNnTuKOzmzfIjGlwkJeAtPVcvSFAgK
|
||||||
WJOz4H8lbphDYO4tFgsGAhL/yHbLHvww/X1hNldwI7mqYrFLSjIwxW2Oxo8c+QB6
|
TCKDmvtkPWUxGrxjBbJZUwqCp4HEOwOp6HeGeNbWFZ2UU+JTvTizkxbReN37Q4+f
|
||||||
yZ3VxTXuS9jEVpGTVhIOfepwS8rJQbTUeewqok3riw9GpSEFpOMWsBxlT6+HI8zS
|
8oIyQuyRpDHgDV5IrbDtCcqWsEFpUXyi8snIMDTCkKdLZv1WjYhjoNmvOoRagQvS
|
||||||
XgHPVohxe93kk51O7WjBgq8PAwG7DtWrygqWYORz+pTYN8wTtC4pfotiJZ7hv7Gv
|
XgEQDrDBeC3HZvUuvqMqgmHI+IEjmpad1CNVGE2q7FnAhFYutjBGF78co2X9t+ib
|
||||||
NICEZlirrTUdIol8jyM+yRv1gWuYwQJpjnrQVY2AoAQX6ta5/3st24cyuGwGHO0=
|
B9o6aIwPzS4ANsh47rupGDBt/x46RCorCYhCaJm4B3v0+tYSA7mSBoHQwp1p+AY=
|
||||||
=Q6Pu
|
=kRPK
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*PASS|.*SOCIALACCOUNT_PROVIDERS|.*\.ya?ml)$
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*PASS|.*SOCIALACCOUNT_PROVIDERS|.*\.ya?ml)$
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: pkgatlas
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- repository.yaml
|
||||||
|
- release.yaml
|
||||||
|
secretGenerator:
|
||||||
|
- name: pkgatlas-values
|
||||||
|
files:
|
||||||
|
- values.yaml=values.yaml
|
||||||
|
configurations:
|
||||||
|
- kustomizeconfig.yaml
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
nameReference:
|
||||||
|
- kind: Secret
|
||||||
|
version: v1
|
||||||
|
fieldSpecs:
|
||||||
|
- path: spec/valuesFrom/name
|
||||||
|
kind: HelmRelease
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: pkgatlas
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: pkgatlas
|
||||||
|
namespace: pkgatlas
|
||||||
|
spec:
|
||||||
|
interval: 1m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: pkgatlas
|
||||||
|
namespace: pkgatlas
|
||||||
|
chart: pkgatlas
|
||||||
|
# CI publishes a timestamped version on every main push and
|
||||||
|
# stamps appVersion with the commit SHA of the image it
|
||||||
|
# builds; this range always picks the latest one.
|
||||||
|
version: '>=0.4.0-0'
|
||||||
|
interval: 1m
|
||||||
|
valuesFrom:
|
||||||
|
- kind: Secret
|
||||||
|
name: pkgatlas-values
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: source.toolkit.fluxcd.io/v1
|
||||||
|
kind: HelmRepository
|
||||||
|
metadata:
|
||||||
|
name: pkgatlas
|
||||||
|
namespace: pkgatlas
|
||||||
|
spec:
|
||||||
|
interval: 1m
|
||||||
|
url: https://git.vhaudiquet.fr/api/packages/vhaudiquet/helm
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
# Chart: https://git.vhaudiquet.fr/vhaudiquet/pkgatlas (chart/pkgatlas).
|
||||||
|
# The image ships both binaries (build + serve) and runs as nonroot
|
||||||
|
# (uid 65532, distroless). Everything else is chart default: discovery
|
||||||
|
# first — build.enabled=false, the first refresh pass builds the whole
|
||||||
|
# live rotation and /v1/readyz stays 503 until it lands; weekly
|
||||||
|
# refresh after that.
|
||||||
|
image:
|
||||||
|
repository: git.vhaudiquet.fr/vhaudiquet/pkgatlas
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
className: traefik
|
||||||
|
hosts:
|
||||||
|
- host: pkgatlas.vhaudiquet.fr
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
# TLS terminates at Caddy with the *.vhaudiquet.fr wildcard cert;
|
||||||
|
# Caddy proxies to Traefik by host, so no tls block here (same as
|
||||||
|
# gitea's ingress).
|
||||||
|
tls: []
|
||||||
|
sops:
|
||||||
|
lastmodified: "2026-09-24T19:57:42Z"
|
||||||
|
mac: ENC[AES256_GCM,data:cidn6U0EFjuEx98GA8Jlppg3GobcGGrhs20dPoAnUXdpFogfsp3YOTPCKuKi0LrOw/fxBP84U4drx5lJcjL11Ft/Ozn6Z8tk3l8cdqK+BUm6yijtQ0PXHjPUJYNIeqxrQKJzFlVHS+tOARbhQ3DjoNt71WBMfSPUDcPxrbnwVAA=,iv:Yz85yh9jrLXf6DKeVmOLeiVCWcthKCPGCJJwR3RVikg=,tag:7Mdv4VZUpsjuysitx4b2DA==,type:str]
|
||||||
|
pgp:
|
||||||
|
- created_at: "2026-09-24T19:57:42Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMA7uy4qQr71wiAQ/+N+gGPOCbuxleT6xx0FduVN1vspYJlCyrtLsy632Yz17x
|
||||||
|
ucwqSuGciqUf2kF3GwnOzINEY0eLskbKHMX5wkbJg8+X6dXoRyiseX3fdNrpvMGR
|
||||||
|
P1ZC/C4O6BzQoPJOXDQZHuWPI0Imx61PlzDPzsJ44JBvwrkCKgoaWOvzMyTjZHiC
|
||||||
|
iplyHpzDR2sqfMe29aQICrEV6Z87eMWQ3wie6CzX2OYTj89BejsN2Ibg4n5cqdNO
|
||||||
|
c+mM7Ek2nSWMWYGbdL0W2N6WSIbGuQj/aVbS0s6585NUPJtmcznB7uosRroqfbd2
|
||||||
|
9SMP1gaUOr+00kykRxKtd/ZoW7S/21kGbZ8FwvtKZFrBwcoUuLehbSGAHRYLo6dI
|
||||||
|
5WGeky65IrvpKen8Q/B6o6EByTONt2h+XiyJyLwDLeFh13/ldkGqa1oW+4BTHuX9
|
||||||
|
2WvLOboHpr4MGQdO53Q8zm8VCGAltusII6ZVaoEyjilqZtC/Aa9XZIT/HshOGTQi
|
||||||
|
4CITE1BfGEApOcBbBQKdjYofdWcyuLSF/ertXvcvNiCoVe0wYiHSYUht+HulQ3t+
|
||||||
|
Z0K7C2sJ2bx8C+316b2MzCGVrVOuqDABpQJjIr4aiRG9v8BtYTaUc425CLm9TMtA
|
||||||
|
PmZR1Rqowy4ECekrbvk3lNjPoq13HLSqkm2ppL9WFub5zY2XY0npprSeUknTmSDS
|
||||||
|
XgGFDhcroUq0vTUlJbC015kpa6cpynwTmMuQrFaMPeKeBPkL4Le6QFJMjpIi3yg3
|
||||||
|
65bSBv5t7YXoHFJWVFYej005Lz1lxp1VtaMiA0bnKEnyh/SbfcUqD4d9P1WNx+4=
|
||||||
|
=ulvs
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*PASS|.*SOCIALACCOUNT_PROVIDERS|.*\.ya?ml)$
|
||||||
|
mac_only_encrypted: true
|
||||||
|
version: 3.10.2
|
||||||
@@ -40,6 +40,8 @@ data:
|
|||||||
|
|
||||||
@umami host umami.vhaudiquet.fr
|
@umami host umami.vhaudiquet.fr
|
||||||
|
|
||||||
|
@pkgatlas host pkgatlas.vhaudiquet.fr
|
||||||
|
|
||||||
handle @authentik {
|
handle @authentik {
|
||||||
reverse_proxy traefik.traefik.svc.cluster.local.:80
|
reverse_proxy traefik.traefik.svc.cluster.local.:80
|
||||||
}
|
}
|
||||||
@@ -70,6 +72,9 @@ data:
|
|||||||
handle @umami {
|
handle @umami {
|
||||||
reverse_proxy traefik.traefik.svc.cluster.local.:80
|
reverse_proxy traefik.traefik.svc.cluster.local.:80
|
||||||
}
|
}
|
||||||
|
handle @pkgatlas {
|
||||||
|
reverse_proxy traefik.traefik.svc.cluster.local.:80
|
||||||
|
}
|
||||||
|
|
||||||
# Docker VM services (via Docker Traefik)
|
# Docker VM services (via Docker Traefik)
|
||||||
@alexscript host alexscript.vhaudiquet.fr
|
@alexscript host alexscript.vhaudiquet.fr
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ spec:
|
|||||||
name: stalwart-helm
|
name: stalwart-helm
|
||||||
namespace: stalwart
|
namespace: stalwart
|
||||||
chart: stalwart
|
chart: stalwart
|
||||||
version: "0.7.16"
|
version: "0.7.18"
|
||||||
interval: 1m
|
interval: 1m
|
||||||
valuesFrom:
|
valuesFrom:
|
||||||
- kind: Secret
|
- kind: Secret
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
# Container image
|
# Container image
|
||||||
image:
|
image:
|
||||||
repository: stalwartlabs/stalwart
|
repository: stalwartlabs/stalwart
|
||||||
tag: v0.16.20
|
tag: v0.16.22
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
# Single-node RocksDB deployment.
|
# Single-node RocksDB deployment.
|
||||||
replicaCount: 1
|
replicaCount: 1
|
||||||
|
|||||||
@@ -29,12 +29,14 @@ resources:
|
|||||||
- dev/gitea
|
- dev/gitea
|
||||||
- dev/harbor
|
- dev/harbor
|
||||||
- dev/renovate
|
- dev/renovate
|
||||||
|
- dev/pkgatlas
|
||||||
# Home (home automation)
|
# Home (home automation)
|
||||||
- home/home-assistant
|
- home/home-assistant
|
||||||
- home/zigbee2mqtt
|
- home/zigbee2mqtt
|
||||||
# Personal (apps storing my own content, grouped by content type)
|
# Personal (apps storing my own content, grouped by content type)
|
||||||
- personal/paperless
|
- personal/paperless
|
||||||
- personal/radicale
|
- personal/radicale
|
||||||
|
- personal/syncthing
|
||||||
- personal/media/photoprism
|
- personal/media/photoprism
|
||||||
- personal/notes/notesnook
|
- personal/notes/notesnook
|
||||||
- personal/notes/obsidian-livesync
|
- personal/notes/obsidian-livesync
|
||||||
|
|||||||
@@ -5,5 +5,6 @@ resources:
|
|||||||
- openclaw-instance.yaml
|
- openclaw-instance.yaml
|
||||||
- openclaw-secrets.yaml
|
- openclaw-secrets.yaml
|
||||||
- networkpolicy.yaml
|
- networkpolicy.yaml
|
||||||
|
- networkpolicy-lan-egress.yaml
|
||||||
- networkpolicy-mail-egress.yaml
|
- networkpolicy-mail-egress.yaml
|
||||||
- networkpolicy-radicale-egress.yaml
|
- networkpolicy-radicale-egress.yaml
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
# Supplementary egress policy: the operator's managed default-deny NetworkPolicy
|
||||||
|
# only allows DNS (53) and TCP 443 outbound, so any other port toward the local
|
||||||
|
# network is dropped. That blocks the OpenClaw pod from reaching LAN services
|
||||||
|
# that do not speak HTTPS on 443. Measured from inside the pod against
|
||||||
|
# 10.4.1.222, 443 returns RST (admitted, nothing listening) while 7020 times
|
||||||
|
# out, which shows LAN routing works and only the port is being refused.
|
||||||
|
#
|
||||||
|
# The egress rule below sets no `ports`, because the goal is arbitrary LAN
|
||||||
|
# services rather than one known port. Cluster CIDRs are excluded so this does
|
||||||
|
# not become a blanket "any pod, any port" grant; the LAN is what gets admitted.
|
||||||
|
# Note this is additive to the operator's rules, so DNS and 443 everywhere still
|
||||||
|
# hold.
|
||||||
|
#
|
||||||
|
# Written as a sidecar policy rather than via the CR fields
|
||||||
|
# spec.security.networkPolicy.additionalEgress / allowedEgressCIDRs, matching
|
||||||
|
# the existing networkpolicy-mail-egress / -radicale-egress pattern. Those CR
|
||||||
|
# fields DO appear in the 0.39.0 CRD template, contrary to the comments on the
|
||||||
|
# sibling policies, so they are worth retrying once the installed CRD version is
|
||||||
|
# confirmed. Until then the sidecar route is the one known to take effect.
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: NetworkPolicy
|
||||||
|
metadata:
|
||||||
|
name: openclaw-lan-egress
|
||||||
|
namespace: openclaw
|
||||||
|
spec:
|
||||||
|
podSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: openclaw
|
||||||
|
app.kubernetes.io/name: openclaw
|
||||||
|
policyTypes:
|
||||||
|
- Egress
|
||||||
|
egress:
|
||||||
|
- to:
|
||||||
|
- ipBlock:
|
||||||
|
cidr: 10.0.0.0/8
|
||||||
|
except:
|
||||||
|
# Service CIDR and pod CIDR (infra/kube/talconfig.yaml).
|
||||||
|
- 10.96.0.0/12
|
||||||
|
- 10.244.0.0/16
|
||||||
@@ -12,7 +12,7 @@ spec:
|
|||||||
name: cloudpirates
|
name: cloudpirates
|
||||||
namespace: paperless
|
namespace: paperless
|
||||||
chart: postgres
|
chart: postgres
|
||||||
version: "0.20.4"
|
version: "0.20.5"
|
||||||
interval: 1m
|
interval: 1m
|
||||||
valuesFrom:
|
valuesFrom:
|
||||||
- kind: Secret
|
- kind: Secret
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ spec:
|
|||||||
name: cloudpirates
|
name: cloudpirates
|
||||||
namespace: paperless
|
namespace: paperless
|
||||||
chart: redis
|
chart: redis
|
||||||
version: "0.34.26"
|
version: "0.35.1"
|
||||||
interval: 1m
|
interval: 1m
|
||||||
valuesFrom:
|
valuesFrom:
|
||||||
- kind: Secret
|
- kind: Secret
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ spec:
|
|||||||
name: derwitt
|
name: derwitt
|
||||||
namespace: radicale
|
namespace: radicale
|
||||||
chart: radicale
|
chart: radicale
|
||||||
version: "2.1.0"
|
version: "2.1.1"
|
||||||
interval: 1m
|
interval: 1m
|
||||||
valuesFrom:
|
valuesFrom:
|
||||||
- kind: Secret
|
- kind: Secret
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: syncthing
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- repository.yaml
|
||||||
|
- release.yaml
|
||||||
|
secretGenerator:
|
||||||
|
- name: syncthing-values
|
||||||
|
files:
|
||||||
|
- values.yaml=values.yaml
|
||||||
|
configurations:
|
||||||
|
- kustomizeconfig.yaml
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
nameReference:
|
||||||
|
- kind: Secret
|
||||||
|
version: v1
|
||||||
|
fieldSpecs:
|
||||||
|
- path: spec/valuesFrom/name
|
||||||
|
kind: HelmRelease
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: syncthing
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: syncthing
|
||||||
|
app.kubernetes.io/component: file-sync
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: syncthing
|
||||||
|
namespace: syncthing
|
||||||
|
spec:
|
||||||
|
interval: 1m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: k8s-home-lab
|
||||||
|
namespace: syncthing
|
||||||
|
chart: syncthing
|
||||||
|
version: "5.2.0"
|
||||||
|
interval: 1m
|
||||||
|
valuesFrom:
|
||||||
|
- kind: Secret
|
||||||
|
name: syncthing-values
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: source.toolkit.fluxcd.io/v1
|
||||||
|
kind: HelmRepository
|
||||||
|
metadata:
|
||||||
|
name: k8s-home-lab
|
||||||
|
namespace: syncthing
|
||||||
|
spec:
|
||||||
|
interval: 1h
|
||||||
|
url: https://k8s-home-lab.github.io/helm-charts/
|
||||||
@@ -0,0 +1,152 @@
|
|||||||
|
# Syncthing continuous file synchronization
|
||||||
|
#
|
||||||
|
# Sync ports (22000 TCP+QUIC, 21027 UDP) are exposed through LoadBalancer
|
||||||
|
# services on the dedicated Cilium pool IP 10.2.2.7 (appended to
|
||||||
|
# kubernetes/system/cilium/pool.yaml). The GUI goes through Traefik like the
|
||||||
|
# other *.lan services.
|
||||||
|
controller:
|
||||||
|
replicas: 1
|
||||||
|
image:
|
||||||
|
repository: syncthing/syncthing
|
||||||
|
tag: "2.1"
|
||||||
|
env:
|
||||||
|
- name: TZ
|
||||||
|
value: Europe/Paris
|
||||||
|
- name: PUID
|
||||||
|
value: "1000"
|
||||||
|
- name: PGID
|
||||||
|
value: "1000"
|
||||||
|
podSecurityContext:
|
||||||
|
fsGroup: 1000
|
||||||
|
service:
|
||||||
|
main:
|
||||||
|
ports:
|
||||||
|
http:
|
||||||
|
port: 8384
|
||||||
|
# Sync protocol and QUIC share 22000 on the pooled IP; LAN discovery
|
||||||
|
# rides on UDP 21027. externalTrafficPolicy Local preserves client IPs.
|
||||||
|
listen:
|
||||||
|
enabled: true
|
||||||
|
type: LoadBalancer
|
||||||
|
externalTrafficPolicy: Local
|
||||||
|
loadBalancerIP: 10.2.2.7
|
||||||
|
ports:
|
||||||
|
listen:
|
||||||
|
enabled: true
|
||||||
|
port: 22000
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: 22000
|
||||||
|
quic:
|
||||||
|
enabled: true
|
||||||
|
port: 22000
|
||||||
|
protocol: UDP
|
||||||
|
targetPort: 22000
|
||||||
|
discovery:
|
||||||
|
enabled: true
|
||||||
|
type: LoadBalancer
|
||||||
|
externalTrafficPolicy: Local
|
||||||
|
loadBalancerIP: 10.2.2.7
|
||||||
|
ports:
|
||||||
|
discovery:
|
||||||
|
enabled: true
|
||||||
|
port: 21027
|
||||||
|
protocol: UDP
|
||||||
|
targetPort: 21027
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
custom: true
|
||||||
|
spec:
|
||||||
|
httpGet:
|
||||||
|
path: /rest/noauth/health
|
||||||
|
port: http
|
||||||
|
readiness:
|
||||||
|
custom: true
|
||||||
|
spec:
|
||||||
|
httpGet:
|
||||||
|
path: /rest/noauth/health
|
||||||
|
port: http
|
||||||
|
ingress:
|
||||||
|
main:
|
||||||
|
enabled: true
|
||||||
|
ingressClassName: traefik
|
||||||
|
annotations:
|
||||||
|
external-dns.alpha.kubernetes.io/enabled: "true"
|
||||||
|
hosts:
|
||||||
|
- host: syncthing.lan
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
persistence:
|
||||||
|
config:
|
||||||
|
enabled: true
|
||||||
|
mountPath: /var/syncthing/config
|
||||||
|
storageClass: longhorn
|
||||||
|
size: 5Gi
|
||||||
|
# Shares are recreated by hand in the GUI after cutover — the instance
|
||||||
|
# boots with a fresh config (see plans/syncthing-docker-to-kube-migration.md):
|
||||||
|
# valentin's folders at /data/valentin/… and sarah's at /data/sarah/…, all
|
||||||
|
# backed by the same TrueNAS exports as the docker stack. Photoprism
|
||||||
|
# already mounts the valentin Photos export concurrently.
|
||||||
|
valentin-documents:
|
||||||
|
enabled: true
|
||||||
|
type: custom
|
||||||
|
mountPath: /data/valentin/Documents
|
||||||
|
volumeSpec:
|
||||||
|
nfs:
|
||||||
|
server: truenas.lan
|
||||||
|
path: /mnt/main_storage/valentin/Documents
|
||||||
|
valentin-photos:
|
||||||
|
enabled: true
|
||||||
|
type: custom
|
||||||
|
mountPath: /data/valentin/Photos
|
||||||
|
volumeSpec:
|
||||||
|
nfs:
|
||||||
|
server: truenas.lan
|
||||||
|
path: /mnt/main_storage/valentin/Photos
|
||||||
|
sarah-documents:
|
||||||
|
enabled: true
|
||||||
|
type: custom
|
||||||
|
mountPath: /data/sarah/Documents
|
||||||
|
volumeSpec:
|
||||||
|
nfs:
|
||||||
|
server: truenas.lan
|
||||||
|
path: /mnt/main_storage/sarah/Documents
|
||||||
|
sarah-photos:
|
||||||
|
enabled: true
|
||||||
|
type: custom
|
||||||
|
mountPath: /data/sarah/Photos
|
||||||
|
volumeSpec:
|
||||||
|
nfs:
|
||||||
|
server: truenas.lan
|
||||||
|
path: /mnt/main_storage/sarah/Photos
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: 512Mi
|
||||||
|
limits:
|
||||||
|
memory: 2Gi
|
||||||
|
sops:
|
||||||
|
lastmodified: "2026-09-21T22:28:39Z"
|
||||||
|
mac: ENC[AES256_GCM,data:BR4P4s4C9n4bEHryqfHpzzFHxAlKeujFBO2Qhsc4qdkcI5dftJ7jrknWtW0uv1E2Aljp50Mx1Rk4wglaWh3MS/ZnY/1dUxCfKuXOGkv9+mymQxDk6zJLsUNTH7sMr5kzlVWfv3yzXF50HWuiNl71BAv4mtlrtarXS1KVQrCKNaA=,iv:aG9OxDOhwk7xYNbvESNMFnXIjKhbYNO0gvDn1a9QQvc=,tag:QxM3EX8V2KJzosRz5damrw==,type:str]
|
||||||
|
pgp:
|
||||||
|
- created_at: "2026-09-21T22:28:39Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMA7uy4qQr71wiAQ//cvlMqPSaED2y5dsq8H/W/dqYVOeG7E/ZOuJGaYnImrrp
|
||||||
|
V2W6vPTzQ8QuYTKa1X4aOIlda04n7i2kDQCvpszmdpsU2y0SWtsgOBbyloIU3cAM
|
||||||
|
69HGd1SNqP/FayeZy/hHNvvEjmsgKX/9IV1YBGOcikmd7MqoxgGRgIxXORzY0dBG
|
||||||
|
7oREwV0HubdIBG6Fi6HUyN+Pugftpcumfwtl8ppPUYi1HGKzL5LzIT6gfqXtUcBg
|
||||||
|
8Wl2f0kMZsat1e05sZZah41dg+BAlyDgCRFo/ZQIhzHi28rJkZWG2aZxQfvAFMYJ
|
||||||
|
hUkjVyN7rAO01b2PsXK3bleFjD8iL8PhHY/Rio0/Uizjub7inako2SUd38D7X+ce
|
||||||
|
M1c2GoDVNmwZyXg7jBzb67JxLPn4Ic1kbjUi/JJL22rDzN0pBf6J7ExCpVGxrwK8
|
||||||
|
++YDD1m/rY3YA8/ioM+pTu3ktEd1zu0T1yFySjgtvX8QVmOkrG1AA8E/N3+pzFWP
|
||||||
|
9wrJJ+yp5CYQl9d3j5LQcOzmvROi0EHjeZY75IHw8NwkyWdnRgWFIPsXxVoSUhSk
|
||||||
|
909RE//BuKSSRd1r9D/4w14Eb9KC74bIsUIflyK2Qs/N3rh9+/O8FS/5saryq7Er
|
||||||
|
GO3oAmFqC2F4Y6zFlmXkr43gBFjCPWl0DxI3uUK/gcw8kBpLSJex3j2sDaLViS/S
|
||||||
|
XgFsDLAjHnEo5DC+xyJQI5xMWsQzx/ASNZdBVLrnYPsRt+YG7qfu3lKNS9ujAG7K
|
||||||
|
ti58fACtT97K8IrUMNyEDGieFz65TYPcie4qILnDt2Hkr6QUEdBR8rvn/8z36D8=
|
||||||
|
=47Rw
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
||||||
|
encrypted_regex: ^(data|stringData|.*key|.*crt)$
|
||||||
|
version: 3.10.2
|
||||||
@@ -8,3 +8,4 @@ spec:
|
|||||||
- cidr: "10.2.2.4/32"
|
- cidr: "10.2.2.4/32"
|
||||||
- cidr: "10.2.2.5/32"
|
- cidr: "10.2.2.5/32"
|
||||||
- cidr: "10.2.2.6/32"
|
- cidr: "10.2.2.6/32"
|
||||||
|
- cidr: "10.2.2.7/32"
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ spec:
|
|||||||
name: kyverno
|
name: kyverno
|
||||||
namespace: kyverno
|
namespace: kyverno
|
||||||
chart: kyverno
|
chart: kyverno
|
||||||
version: '3.9.0'
|
version: '3.9.1'
|
||||||
interval: 5m
|
interval: 5m
|
||||||
# Minimal footprint for a single-node cluster:
|
# Minimal footprint for a single-node cluster:
|
||||||
# - admissionReports disabled (no extra Redis/Postgres)
|
# - admissionReports disabled (no extra Redis/Postgres)
|
||||||
|
|||||||
Reference in New Issue
Block a user