Files
homeprod/kubernetes/system/longhorn/values.yaml
T

125 lines
6.5 KiB
YAML

# Longhorn Helm Values
# Single-node R740 cluster, backup target on TrueNAS NFS
defaultSettings:
# Single node — only 1 replica needed
defaultReplicaCount: 1
# NFS backup target on TrueNAS
backupTarget: nfs://truenas.lan:/mnt/fast_app_data/longhorn-backup
# Allow full disk usage on single-node
storageOverProvisioningPercentage: 100
storageMinimalAvailablePercentage: 10
# Auto-salvage on node reboot (single-node)
autoSalvage: true
# Disable strict flushing for better single-node performance
strictSyncReplicas: false
# Toleration for system-managed Longhorn pods (instance-manager, engine,
# replica, CSI plugin). These pods are created dynamically by
# longhorn-manager — NOT from Helm templates — so their tolerations must be
# set here via the `taintToleration` setting (semicolon-separated `kubectl
# taint` syntax), not via per-component `tolerations` blocks.
#
# The P330 node is tainted `dedicated=failover:NoSchedule` (see
# infra/p330/kube/variables.tf). Tolerating it lets Longhorn schedule
# engine/replica pods there so a volume can be failed over to the P330.
# The control-plane taint is also tolerated defensively, although with
# allowSchedulingOnControlPlanes=true on the R740 it is not actually applied.
taintToleration: dedicated=failover:NoSchedule;node-role.kubernetes.io/control-plane:NoSchedule
persistence:
defaultClass: true
defaultClassReplicaCount: 1
# Retain volumes on PVC delete — safer during migration
reclaimPolicy: Retain
# Mount options for ext4
fstype: ext4
# longhorn-manager is a DaemonSet — it must run on every storage node,
# including the P330 failover node. The control-plane toleration is defensive
# (allowSchedulingOnControlPlanes=true means it is not actually applied on the
# R740, but keeps things correct if that ever changes).
longhornManager:
tolerations:
- key: ENC[AES256_GCM,data:ZvL4q5WzJQbz/+jBCaH4Gpp5PdCqwrqcIDCXwPq1oVintCYXxg==,iv:SASkDRml7AG+wJTWe/CRaAm7kv7tJ/IRXfpWzeewHuo=,tag:ToVKgaQeLVav7Qt2bdlpnw==,type:str]
operator: Exists
effect: NoSchedule
# Tolerate the failover taint so longhorn-manager runs on the P330
- key: ENC[AES256_GCM,data:B+Y/ckOHz6xq,iv:27M/gUOPZ09BNZP2OwyjNsK8Ld0opec9l2FjiRiN0Wg=,tag:3UGdvzOsXgSAs7KwBJ5oKQ==,type:str]
value: ENC[AES256_GCM,data:YT/EL6wwlYI=,iv:H8CCtKbzmWRahFxtZguzghVLK3/qvHFaE8IQPALL0Oo=,tag:HIMsMtxutYh3HVASeIrxtw==,type:str]
operator: Equal
effect: NoSchedule
# longhorn-driver (CSI provisioner/attacher deployer) — tolerate the same
# taints so CSI operations work from the failover node.
longhornDriver:
tolerations:
- key: ENC[AES256_GCM,data:ks2denq5PQL6UjGUe5JFahXJqLDY8jQgAPjQkn3fhryTCsd1Tg==,iv:gR8QtaRW5+4GptIa92hh2v+pk41ve1FmCMC+qlitdOs=,tag:NDGn8o5btPbfqDWg1nS6wQ==,type:str]
operator: Exists
effect: NoSchedule
- key: ENC[AES256_GCM,data:nRPej7F1wIQr,iv:fRF9YaiqpPCAEGSXCHJublN7OYoikb3xK1RacxMKDcw=,tag:+leZjB1PGhWvxhrEBHxImg==,type:str]
value: ENC[AES256_GCM,data:QdMlIx5PYgU=,iv:TJ+i5qwY6G2j+87HdmOZwDWPzJOd9bDeJUmkC3yl9oA=,tag:niNS/IwVVaw+83e4jJrgag==,type:str]
operator: Equal
effect: NoSchedule
# longhorn-ui — tolerate the same taints so the UI is reachable even if it
# lands on the failover node.
longhornUI:
replicas: 1
tolerations:
- key: ENC[AES256_GCM,data:mYYdyvTvfbP57Tr7zEUgAYZmtSmTougPSbou75YNqD93LvQEuw==,iv:vcKiaYE2ikIAornOIs7LB4iIp6XczB8VmW1FgeUO2ho=,tag:i1yOrLaUX1+AzviTLYQFUw==,type:str]
operator: Exists
effect: NoSchedule
- key: ENC[AES256_GCM,data:rqykd/I0zsFq,iv:lixb2ezSpU2GjXsi8li4z0d1TjNpCRiPXrSMiOASH64=,tag:rMg3tE4fw7jFpidBRZBkIQ==,type:str]
value: ENC[AES256_GCM,data:S7G6SgmWjA0=,iv:Wwo3U/bFkch+dNlLZLDNCiaUVID8bIVxhPtizIUt/rE=,tag:7R8s/D6IX4SfZgT/PCkbVw==,type:str]
operator: Equal
effect: NoSchedule
# NOTE: There is no `longhorn-instance-manager` Helm key. The instance-manager,
# engine and replica pods are system-managed and created dynamically by
# longhorn-manager; their tolerations come from `defaultSettings.taintToleration`
# above. Do not add a `longhorn-instance-manager` block here — it would be
# silently ignored.
# Disable ingress for now
ingress:
enabled: false
# Recurring backup and snapshot schedules
# - Daily snapshots: fast local recovery from accidental deletes
# - Daily NFS backups: DR if node is lost
recurringJobs:
enable: true
jobs:
- name: daily-snapshot
task: snapshot
cron: 0 2 * * *
retain: 7
concurrency: 2
labels:
type: snapshot
- name: daily-backup
task: backup
cron: 0 3 * * *
retain: 7
concurrency: 2
labels:
type: backup
sops:
lastmodified: "2026-07-22T09:25:21Z"
mac: ENC[AES256_GCM,data:H61nccieTaqp4w6cySS8EG6VZvplmUdSSo2MFi+mGzZohJFjTfdHxIaJgfKuN7/+/dMoacgozl73CmwSnelzgKMm9CZNf0ucWXRPG/8EiM5IeDXBhRChP+Y8BHX6h7FNS6la6Jzdqy8/jKUPw5sdDQaHT6KnQ37ie+D3JjZAwic=,iv:qb/Cr0upi9qQfYVDAwFyLqnVHSlktkVVbsmhTaFsZu0=,tag:q0jPEGtNl4BmBJpdghgRJg==,type:str]
pgp:
- created_at: "2026-07-22T09:25:21Z"
enc: |-
-----BEGIN PGP MESSAGE-----
hQIMA7uy4qQr71wiARAAwf/RSzNAtZ+BY13bYXQstWAs+7HYZLm1fNKcqNKevSHT
+LKy+YkfXgDk67PZNz2H5v3N3GJi/cDEo1MhfXeutYLioZ7WFVaeXsvd3hxisbzi
noliuQtu9b63l5UwZPbWvfFDKLJqVKG2JTfXSp+G0Nv11VYCYKftRNd/KH+xEP89
hGWGuL+AhbPW9dFimiAICLk/sGyVXNq1SAKu3rL9o/mtRDh+igSg5YohhYhiA7TC
PMp/7SRY6swfZ0xfyw9PKlbR5Gm7i5Wtml6MP5myZ90cjzMAkjOL8NavxGogvfib
ajjdN5AqdoSU5Kr+rKx8I3Eq9V0Fs/oXfmLeHYYdNoqNOqpqtupXKnMVEdHyUdeq
shBuDUE4dvZWyYKfZKzQz2WASN1GDiVm89IvhQ2MP1nEhRE92UyixKHQmLgNolpm
LTkuGzWU3dNzHO1c3JLgjF/lWve5KV01Wa/HrAZFH5rSG3qLN8rkmhB+q4C2jjkN
4aXyPY8/vRLbIwQgSnxBKYzD6yNFNj76W8kmdEe7c1sMcJZZdjC2pqmEzlfoP9sl
vzLkHQeFe2IGYMVna0KVCuEk+5pTvnU7KaoMjfbGFPvDwv3heRUzSTBAF3furx03
QHi9bOVCrhrt3QLb7cQSrhGMwtV+XiphfQVAJqKSS3la0XjIoJzm297hNgXv0OTS
XAGMF0oFo/1bytZZY0+BSe10y4g+G8q47cqWq0/bnvG4fP95/U3/tH8njIFeNg0U
yqm9O+1fQ6I2b6hRlGyv6RjovRc32J+RVPgEkK5a5dlvSTQf97tw9Bo3tKc6
=SxRv
-----END PGP MESSAGE-----
fp: DC6910268E657FF70BA7EC289974494E76938DDC
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*\.ya?ml)$
version: 3.10.2