mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-09-22 00:43:32 +00:00
97 lines
4.7 KiB
YAML
97 lines
4.7 KiB
YAML
# Default values for blocky (k8s-home-lab chart)
|
|
image:
|
|
repository: ghcr.io/0xerr0r/blocky
|
|
tag: v0.24
|
|
pullPolicy: IfNotPresent
|
|
controller:
|
|
replicas: 2
|
|
dnsPolicy: ClusterFirst
|
|
strategy: RollingUpdate
|
|
rollingUpdate:
|
|
maxUnavailable: 0
|
|
maxSurge: 1
|
|
env:
|
|
TZ: Europe/Paris
|
|
service:
|
|
main:
|
|
enabled: false
|
|
dns-tcp:
|
|
enabled: false
|
|
dns-udp:
|
|
enabled: true
|
|
type: LoadBalancer
|
|
loadBalancerIP: 10.2.2.3
|
|
# Cluster (not Local) so any node can forward to pods on any other node.
|
|
# Required for Cilium L2 announcement failover
|
|
externalTrafficPolicy: Cluster
|
|
ports:
|
|
dns:
|
|
port: 53
|
|
protocol: UDP
|
|
probes:
|
|
liveness:
|
|
enabled: true
|
|
custom: true
|
|
spec:
|
|
tcpSocket:
|
|
port: 53
|
|
initialDelaySeconds: 10
|
|
periodSeconds: 10
|
|
timeoutSeconds: 5
|
|
failureThreshold: 3
|
|
readiness:
|
|
enabled: true
|
|
custom: true
|
|
spec:
|
|
tcpSocket:
|
|
port: 53
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 5
|
|
timeoutSeconds: 3
|
|
failureThreshold: 3
|
|
startup:
|
|
enabled: true
|
|
custom: true
|
|
spec:
|
|
tcpSocket:
|
|
port: 53
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 2
|
|
timeoutSeconds: 3
|
|
failureThreshold: 30
|
|
resources:
|
|
limits:
|
|
cpu: 600m
|
|
memory: 768Mi
|
|
requests:
|
|
cpu: 200m
|
|
memory: 256Mi
|
|
# Full list of options https://github.com/0xERR0R/blocky/blob/main/docs/config.yml
|
|
config: "upstreams:\n groups:\n default:\n - 1.1.1.1\n - 1.0.0.1\n lan:\n - 10.99.121.92\n\nconditional:\n mapping:\n lan: 10.99.121.92\n cluster.local: 10.96.0.10\n\nblocking:\n allowlists:\n ads:\n - |\n dealabs.digidip.net\n s.click.aliexpress.com\n fonts.googleapis.com\n fonts.gstatic.com\n wl.spotify.com\n www.googleadservices.com\n \n denylists:\n ads:\n - https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts\n - https://adaway.org/hosts.txt\n \n clientGroupsBlock:\n default:\n - ads\n \n blockType: zeroIp\n blockTTL: 1m\n loading:\n refreshPeriod: 4h\n downloads:\n timeout: 60s\n\ncaching:\n minTime: 5m\n maxTime: 30m\n # Disable negative caching (NXDOMAIN responses) for dynamic DNS\n cacheTimeNegative: 0\n prefetching: true\n prefetchExpires: 2h\n prefetchThreshold: 5\n\nprometheus:\n enable: true\n path: /metrics\n\nports:\n dns: 53\n http: 4000\n\nbootstrapDns: tcp+udp:1.1.1.1\n\nlog:\n level: info\n format: text\n timestamp: true\n"
|
|
sops:
|
|
lastmodified: "2026-08-21T16:53:47Z"
|
|
mac: ENC[AES256_GCM,data:UurGQEnmn0HR8d6e7I6+TvNTGDkp+4z2qxA3qR6s2ckhSrri40Dbhl2zYMHPzkch50HLbLmgDmkLPuvwVvvtRA++46IWCvPsLyirRgHfLCF8rvvJ2ydbUyRKspQi0+HiWhoQzsmC7Qn442iUXoB1IoSNR1Y8n94uVvgUyqTalkA=,iv:XnNYtp6mFWILZqP5JqjmZMp26PQnefZQK7UJCgPMYnY=,tag:hexfIqW/+tKvVY8OT5pmag==,type:str]
|
|
pgp:
|
|
- created_at: "2026-08-21T16:53:47Z"
|
|
enc: |-
|
|
-----BEGIN PGP MESSAGE-----
|
|
|
|
hQIMA7uy4qQr71wiAQ//TuHosCarvDdeJK4Fo062JDb9KBUxlmSoSRuGFik/97wA
|
|
9xBDzqoMqptnDgd0J9FY4an9ie5M3aWyzFvV+LAgE104vD4jT0Zi35N5nKhTJLcX
|
|
KTLs61jgNnOo7NYww0zikzIXY0rqk+tIPFkuiQQRn6f5s5TB/FH1NAe4VNisenYF
|
|
6NhgFIZDyt10y1i75bLehG3s4c1OSvAQ2W0+Tti3kFGpJUqmf9+5jdC0sHQfpzFR
|
|
QOifTKaSp8zHuRx05/8DzRQrVohBjeIQRJzmgzQ8oynZTGTt3q0sP9+Eo9MZoPD+
|
|
Oe6cEoM8fPN2EO0BpeHWrEPsbF4V8KW/fd6sCUyGeGVxTIssupxeRVrN3jbANkXW
|
|
awz35sGhUBN2hloK7imy8tcw+FAZHZIFZhzMfEWGpg0rJSb8bZF8LEgmnEY7gq4C
|
|
x02lJSKHvnKpc2oKlyK3IrPnwqfr8ilZJn6Svh4IW59tyhJB/2eRjKT+S/laey4P
|
|
PEr9t/DC+kpndOPxkS2gxD7ENljdh6IfOLTQu9lQT3tA1mRM7HZUb0TVS5ZRL0VJ
|
|
zady8YZiKZCGTGl44pDdbG5d6r/h9lcmP6QeKnCU4KCPJrCUBWVYHxDz2fFQ5810
|
|
49FdWloWEGk2rM/7xW2wz5PD2XXLuiPyRhAz9nJ6iTMT0FkvxIseJ8uYgStQCnDS
|
|
XAEIZAmMcySSzP93SeevQTPPeTC3WrYcwfUVV5871+09M0eKURZqaWmnvZiaR1fs
|
|
fMPynVu7uwW65LDFdH2aMgp5NY77NZTDN4wgZkYQ7CG/IMA0GOvYS2J2XTFi
|
|
=7N0d
|
|
-----END PGP MESSAGE-----
|
|
fp: DC6910268E657FF70BA7EC289974494E76938DDC
|
|
encrypted_regex: ^(password|value|ssh-key|api-key|user|username|privateKey|clientSecret|clientId|apiKey|extraArgs.*|.*Secret.*|extraEnvVars|.*SECRET.*|.*secret.*|key|.*Password|.*PASS|.*SOCIALACCOUNT_PROVIDERS|.*\.ya?ml)$
|
|
version: 3.10.2
|