115 Commits

Author SHA1 Message Date
renovate-bot 4567854c12 chore(deps): update docker.io/bats/bats docker tag to v1.14.0 2026-07-21 20:00:27 +00:00
williamp 944d5793af netmaker: upgrade to v1.6.0 2026-07-21 15:20:08 -04:00
williamp 85db172de8 Merge pull request 'chore(deps): update helm release authentik to v2026.5.5' (#112) from renovate/authentik-2026.x into main
Reviewed-on: #112
2026-07-17 14:35:30 +00:00
renovate-bot d0263b767b chore(deps): update helm release authentik to v2026.5.5 2026-07-15 18:00:11 +00:00
williamp a913dc0989 authentik: add gateway object to prepare for gateway api migration 2026-07-08 18:07:45 -04:00
williamp 08ceba58c2 Merge pull request 'chore(deps): update helm release authentik to v2026.5.4' (#111) from renovate/authentik-2026.x into main
Reviewed-on: #111
2026-07-08 21:58:24 +00:00
renovate-bot 0e6ba2c4d9 chore(deps): update helm release authentik to v2026.5.4 2026-07-08 13:00:10 +00:00
actions eab7f0a533 yt-dlp-bot: deploy update to f48776c 2026-07-05 01:04:40 +00:00
williamp ac2ae0c3df attic: migrate to gateway API 2026-07-04 16:34:03 -04:00
williamp 93663535bc jellyfin: migrate metrics-block to httproute as well 2026-07-04 16:27:27 -04:00
williamp d06ef83ee2 jellyfin: rm ssl cert secret 2026-07-04 16:23:59 -04:00
williamp 8ad2c46c20 jellyfin: migrate to gateway API 2026-07-04 16:23:06 -04:00
williamp c83625bc88 gitea: migrate to gateway API for ingress 2026-07-04 16:14:20 -04:00
williamp ef81d700a8 Merge pull request 'chore(deps): update helm release gitea to v12.7.0' (#110) from renovate/gitea-12.x into main
Reviewed-on: #110
2026-07-04 17:08:00 +00:00
renovate-bot b62f3935be chore(deps): update helm release gitea to v12.7.0 2026-07-04 17:00:09 +00:00
williamp 412a6918b6 Merge pull request 'chore(deps): update helm release gitea to v12.6.3' (#109) from renovate/gitea-12.x into main
Reviewed-on: #109
2026-06-21 23:44:42 +00:00
renovate-bot 34dab7a09f chore(deps): update helm release gitea to v12.6.3 2026-06-21 22:00:08 +00:00
williamp ac1ad7359f Merge pull request 'chore(deps): update helm release gitea to v12.6.2' (#108) from renovate/gitea-12.x into main
Reviewed-on: #108
2026-06-20 22:00:37 +00:00
renovate-bot d8e470c623 chore(deps): update helm release gitea to v12.6.2 2026-06-20 22:00:12 +00:00
williamp 0cf458a6bb Merge pull request 'chore(deps): update helm release gitea to v12.6.1' (#107) from renovate/gitea-12.x into main
Reviewed-on: #107
2026-06-16 17:50:39 +00:00
renovate-bot 18fe757fe2 chore(deps): update helm release gitea to v12.6.1 2026-06-16 04:00:11 +00:00
williamp aa83a625ac Merge pull request 'chore(deps): update helm release authentik to v2026.5.3' (#106) from renovate/authentik-2026.x into main
Reviewed-on: #106
2026-06-12 23:17:38 +00:00
renovate-bot 30c821f5cd chore(deps): update helm release authentik to v2026.5.3 2026-06-11 22:00:11 +00:00
actions 4bde426243 yt-dlp-bot: deploy update to 7c4c14d 2026-06-10 03:00:04 +00:00
williamp 2d8a0297f5 Merge pull request 'chore(deps): update helm release searxng to v1.1.4' (#105) from renovate/searxng-1.x into main
Reviewed-on: #105
2026-06-10 00:58:09 +00:00
renovate-bot 9b10b90acd chore(deps): update helm release searxng to v1.1.4 2026-06-10 00:00:12 +00:00
williamp d672812300 Merge pull request 'chore(deps): update helm release gitea to v12.6.0' (#104) from renovate/gitea-12.x into main
Reviewed-on: #104
2026-06-08 01:04:24 +00:00
renovate-bot e7fccaa53c chore(deps): update helm release gitea to v12.6.0 2026-06-08 00:00:12 +00:00
williamp 0b5f4492a4 Merge pull request 'chore(deps): update helm release authentik to v2026.5.2' (#103) from renovate/authentik-2026.x into main
Reviewed-on: #103
2026-05-29 00:11:44 +00:00
renovate-bot b9bb385320 chore(deps): update helm release authentik to v2026.5.2 2026-05-28 16:00:10 +00:00
williamp a0b0997c1a arr-stack update ip to new seedbox 2026-05-26 19:55:34 -04:00
williamp 7ffa5c3341 searxng: add 2026-05-23 09:55:53 -04:00
williamp 2c5cf9b6c4 Merge pull request 'chore(deps): update helm release authentik to v2026.5.0' (#102) from renovate/authentik-2026.x into main
Reviewed-on: #102
2026-05-23 00:15:39 +00:00
renovate-bot 0456497133 chore(deps): update helm release authentik to v2026.5.0 2026-05-22 11:00:09 +00:00
williamp 7a31dac90c Merge pull request 'chore(deps): update helm release authentik to v2026.2.3' (#101) from renovate/authentik-2026.x into main
Reviewed-on: #101
2026-05-12 23:45:31 +00:00
renovate-bot c8ce349135 chore(deps): update helm release authentik to v2026.2.3 2026-05-12 21:00:09 +00:00
actions fc5786cdef yt-dlp-bot: deploy update to 23993d7 2026-05-09 16:47:24 +00:00
williamp 1007e8ee4b Merge pull request 'chore(deps): update helm release gitea to v12.5.12' (#100) from renovate/gitea-12.x into main
Reviewed-on: #100
2026-04-19 00:39:28 +00:00
renovate-bot 7f487b0990 chore(deps): update helm release gitea to v12.5.12 2026-04-19 00:00:12 +00:00
williamp 9137db2b9f Merge pull request 'chore(deps): update helm release gitea to v12.5.11' (#99) from renovate/gitea-12.x into main
Reviewed-on: #99
2026-04-18 23:02:17 +00:00
renovate-bot acaf66a39c chore(deps): update helm release gitea to v12.5.11 2026-04-18 23:00:12 +00:00
actions 2016580fa0 yt-dlp-bot: deploy update to fb0746e 2026-04-10 12:15:21 +00:00
williamp acb664318e Merge pull request 'chore(deps): update helm release jellyfin to v3.2.0' (#98) from renovate/jellyfin-3.x into main
Reviewed-on: #98
2026-04-08 18:18:52 +00:00
renovate-bot b39e6fdce8 chore(deps): update helm release jellyfin to v3.2.0 2026-04-08 18:00:18 +00:00
williamp c21f54cc2c Merge pull request 'chore(deps): update helm release authentik to v2026.2.2' (#97) from renovate/authentik-2026.x into main
Reviewed-on: #97
2026-04-08 02:07:19 +00:00
renovate-bot 5b8aa97081 chore(deps): update helm release authentik to v2026.2.2 2026-04-08 01:00:12 +00:00
williamp 9a94ccc337 Merge pull request 'chore(deps): update helm release gitea to v12.5.10' (#96) from renovate/gitea-12.x into main
Reviewed-on: #96
2026-04-02 22:09:14 +00:00
renovate-bot 2a2aeba921 chore(deps): update helm release gitea to v12.5.10 2026-04-02 01:00:13 +00:00
williamp a11fea834b jellyfin: rm old dvr share 2026-04-01 18:20:25 -04:00
williamp 4ba9a42b7e Merge pull request 'chore(deps): update helm release jellyfin to v3' (#95) from renovate/jellyfin-3.x into main
Reviewed-on: #95
2026-04-01 22:18:39 +00:00
renovate-bot 453956f5d1 chore(deps): update helm release jellyfin to v3 2026-04-01 15:00:10 +00:00
williamp 9972e1ecb9 Merge pull request 'chore(deps): update helm release gitea to v12.5.9' (#94) from renovate/gitea-12.x into main
Reviewed-on: #94
2026-03-22 00:27:05 +00:00
renovate-bot 674aaaea9c chore(deps): update helm release gitea to v12.5.9 2026-03-21 16:00:10 +00:00
actions c18ade7a7e yt-dlp-bot: deploy update to 5465bd4 2026-03-18 02:56:12 +00:00
actions 7f984f61af yt-dlp-bot: deploy update to a0e511b 2026-03-14 12:58:10 +00:00
williamp 4d2ac0b44d Merge pull request 'chore(deps): update helm release gitea to v12.5.8' (#93) from renovate/gitea-12.x into main
Reviewed-on: #93
2026-03-13 18:00:41 +00:00
renovate-bot 71372379b9 chore(deps): update helm release gitea to v12.5.8 2026-03-13 18:00:12 +00:00
williamp e02f3aa9fd arr-stack: update versions
flaresolverr: v3.4.6
prowlarr: 2.3.0.5236
radarr: 6.0.4.10291
sonarr: 4.0.16.2944
2026-03-13 13:18:28 -04:00
actions 67f852c737 yt-dlp-bot: deploy update to 509dab5 2026-03-10 01:01:19 +00:00
actions fd20dccf6c yt-dlp-bot: deploy update to adefe2f 2026-03-09 16:21:29 +00:00
actions 9745f6aa53 yt-dlp-bot: deploy update to 51e1cc5 2026-03-08 16:00:59 +00:00
actions fc3d187d99 yt-dlp-bot: deploy update to e0de621 2026-03-08 05:21:02 +00:00
actions b6a74c4a8f yt-dlp-bot: deploy update to 4513338 2026-03-08 05:03:18 +00:00
actions 1b44fd7ab5 yt-dlp-bot: deploy update to e3b5542 2026-03-08 02:19:50 +00:00
actions 37a0370bb3 yt-dlp-bot: deploy update to 8f2bda0 2026-03-08 00:03:57 +00:00
williamp f5a07f0810 gitea-runner: use slirp4netns 2026-03-07 18:21:05 -05:00
williamp 5b5c394581 gitea-runner: use DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS instead 2026-03-07 18:19:13 -05:00
williamp 0946ef68a3 gitea-runner: try using bridge network mode 2026-03-07 18:09:24 -05:00
williamp dbfecc1090 Merge pull request 'chore(deps): update helm release gitea to v12.5.7' (#92) from renovate/gitea-12.x into main
Reviewed-on: #92
2026-03-07 15:40:26 +00:00
actions 4e22ab2416 yt-dlp-bot: deploy update to 82b867a 2026-03-07 15:28:22 +00:00
renovate-bot 7719d488b7 chore(deps): update helm release gitea to v12.5.7 2026-03-07 04:00:16 +00:00
williamp 7f2a21d15d gitea-runner: specify dns server in container creation 2026-03-06 22:38:42 -05:00
actions 1d07f20850 yt-dlp-bot: deploy update to 5748834 2026-03-07 01:09:14 +00:00
williamp cc3a0ff414 yt-dlp-bot: try new refactor build 2026-03-06 19:45:49 -05:00
williamp d337a6ad3d attic: scale up to 3 2026-03-06 14:55:01 -05:00
williamp a55400a0ba attic: try to use postgres 2026-03-06 14:12:20 -05:00
williamp b04c27eaf1 yt-dlp-bot: revert 2026-03-06 10:29:10 -05:00
williamp 5fc38bf8f0 yt-dlp-bot: try dogfooding the refactor again, for real this time 2026-03-06 10:11:45 -05:00
williamp a83a8f9577 yt-dlp: revert back to 2c99fbf for now 2026-03-06 09:36:33 -05:00
williamp 5e3c0f386f yt-dlp-bot: use test image for dogfooding 2026-03-06 09:34:02 -05:00
actions 6cb6ba6e22 yt-dlp-bot: deploy update to 2c99fbf 2026-03-06 00:37:38 +00:00
actions 1043895e71 yt-dlp-bot: deploy update to 81968a6 2026-03-05 23:44:44 +00:00
actions b6952cec5c yt-dlp-bot: deploy update to 7b34919 2026-03-05 14:09:26 +00:00
williamp c2f8178b11 authentik: remove temp custom probes 2026-03-04 16:12:07 -05:00
actions dddbf25e45 yt-dlp-bot: deploy update to 2269104 2026-03-04 13:50:59 +00:00
actions 846aa2d534 yt-dlp-bot: deploy update to 4bea5e0 2026-03-04 13:46:47 +00:00
williamp 342ab378cd Merge pull request 'chore(deps): update helm release authentik to v2026.2.1' (#91) from renovate/authentik-2026.x into main
Reviewed-on: #91
2026-03-03 23:09:10 +00:00
renovate-bot 5ce3ac9a1e chore(deps): update helm release authentik to v2026.2.1 2026-03-03 21:00:09 +00:00
actions eeb45f24a4 yt-dlp-bot: deploy update to 204404b 2026-03-03 01:14:43 +00:00
actions 224102a066 yt-dlp-bot: deploy update to 6e7fc73 2026-03-02 18:37:04 +00:00
actions 9851a131d3 yt-dlp-bot: deploy update to b9088d9 2026-02-28 21:42:39 +00:00
williamp 20473263ae authentik: enable AUTHENTIK_POSTGRESQL__DISABLE_SERVER_SIDE_CURSORS
Per https://docs.goauthentik.io/install-config/configuration/#using-a-postgresql-connection-pooler
2026-02-26 09:20:16 -05:00
williamp cb3528b17b Merge pull request 'chore(deps): update helm release gitea to v12.5.6' (#90) from renovate/gitea-12.x into main
Reviewed-on: #90
2026-02-26 02:07:26 +00:00
renovate-bot 1a25c3fcf3 chore(deps): update helm release gitea to v12.5.6 2026-02-26 02:00:13 +00:00
williamp b2d6545070 authentik: add files support 2026-02-25 18:52:17 -05:00
williamp 053c36a877 authentik: increase replicas to 3 after stability testing 2026-02-25 18:45:51 -05:00
williamp 968ef8d621 authentik: use dedicated pooler 2026-02-25 18:39:10 -05:00
williamp 4215d89d0b Revert "authentik: raise workers to 3"
This reverts commit 3b38a2c3a9.
2026-02-24 22:38:15 -05:00
williamp 3b38a2c3a9 authentik: raise workers to 3 2026-02-24 22:34:06 -05:00
williamp 42fd1e5a92 authentik: adjust probes from default 2026-02-24 22:26:36 -05:00
williamp 8d6b3eb6b6 authentik: try upgrade again with only 1 replica 2026-02-24 22:08:19 -05:00
williamp 442ba532cd Revert "chore(deps): update helm release authentik to v2026"
Reverting Authentik update as pods have been crashing
2026-02-24 21:52:28 -05:00
williamp c71e4765e1 Merge pull request 'chore(deps): update helm release authentik to v2026' (#88) from renovate/authentik-2026.x into main
Reviewed-on: #88
2026-02-25 02:38:47 +00:00
renovate-bot b1e62ed191 chore(deps): update helm release authentik to v2026 2026-02-24 22:00:15 +00:00
actions 5855b78976 yt-dlp-bot: deploy update to f688ee0 2026-02-21 22:27:54 +00:00
williamp d849c4ca19 gitea-runner: ram scratch space 2026-02-19 18:06:15 -05:00
williamp 101be3512a attic: enable S3 support 2026-02-18 19:29:12 -05:00
williamp 893f10a45c gitea-runner: secure with rootless 2026-02-18 19:28:58 -05:00
williamp 11f881c24b attic: update tag to c4ffb5e86e928572e867bd3f81545293313e0a08 2026-02-17 21:08:37 -05:00
williamp f59574bda1 Merge pull request 'chore(deps): update helm release authentik to v2025.12.4' (#87) from renovate/authentik-2025.x into main
Reviewed-on: #87
2026-02-14 11:28:56 +00:00
renovate-bot a2273c4336 chore(deps): update helm release authentik to v2025.12.4 2026-02-12 17:00:10 +00:00
williamp f0ac9bbd6d gitea-runner: create configmap for custom config, enable host networking within dind 2026-02-08 12:33:48 -05:00
williamp 68026b743c Merge pull request 'chore(deps): update helm release gitea to v12.5.5' (#86) from renovate/gitea-12.x into main
Reviewed-on: #86
2026-02-08 13:03:51 +00:00
renovate-bot 980420d1cd chore(deps): update helm release gitea to v12.5.5 2026-02-08 04:00:08 +00:00
williamp 392e56b6ba gitea-runner: disable host networking as it breaks connectivity to buildkitd 2026-02-07 22:49:54 -05:00
28 changed files with 365 additions and 112 deletions
+1 -1
View File
@@ -14,7 +14,7 @@ spec:
spec: spec:
containers: containers:
- name: flaresolverr - name: flaresolverr
image: ghcr.io/flaresolverr/flaresolverr:v3.4.1 image: ghcr.io/flaresolverr/flaresolverr:v3.4.6
resources: resources:
requests: requests:
memory: "2Gi" memory: "2Gi"
+1 -1
View File
@@ -16,7 +16,7 @@ spec:
spec: spec:
containers: containers:
- name: prowlarr - name: prowlarr
image: linuxserver/prowlarr:version-2.0.5.5160 image: linuxserver/prowlarr:version-2.3.0.5236
volumeMounts: volumeMounts:
- name: config - name: config
mountPath: /config mountPath: /config
+1 -1
View File
@@ -16,7 +16,7 @@ spec:
spec: spec:
containers: containers:
- name: radarr - name: radarr
image: linuxserver/radarr:version-5.27.5.10198 image: linuxserver/radarr:version-6.0.4.10291
volumeMounts: volumeMounts:
- name: config - name: config
mountPath: /config mountPath: /config
+1 -1
View File
@@ -16,7 +16,7 @@ spec:
spec: spec:
containers: containers:
- name: sonarr - name: sonarr
image: linuxserver/sonarr:4.0.15 image: linuxserver/sonarr:version-4.0.16.2944
volumeMounts: volumeMounts:
- name: config - name: config
mountPath: /config mountPath: /config
+1 -1
View File
@@ -14,7 +14,7 @@ spec:
containers: containers:
- name: deluge-tunnel - name: deluge-tunnel
image: kroniak/ssh-client:3.21 image: kroniak/ssh-client:3.21
command: ["/bin/sh", "-c", "ssh -o StrictHostKeyChecking=no weyma-talos@45.152.211.243 -p 2222 -L 0.0.0.0:58846:127.0.0.1:58846 -L 0.0.0.0:8112:127.0.0.1:8112 -N"] command: ["/bin/sh", "-c", "ssh -o StrictHostKeyChecking=no weyma-talos@184.107.106.14 -L 0.0.0.0:58846:127.0.0.1:58846 -L 0.0.0.0:8112:127.0.0.1:8112 -N"]
volumeMounts: volumeMounts:
- name: ssh-keys - name: ssh-keys
mountPath: /root/.ssh mountPath: /root/.ssh
+10
View File
@@ -0,0 +1,10 @@
apiVersion: objectbucket.io/v1alpha1
kind: ObjectBucketClaim
metadata:
name: attic-bucket
namespace: attic
spec:
additionalConfig:
maxSize: 100Gi
bucketName: attic-bucket
storageClassName: weyma-s3-bucket
-10
View File
@@ -1,10 +0,0 @@
apiVersion: v1
kind: Secret
metadata:
name: cert-dubyatp-xyz
annotations:
replicator.v1.mittwald.de/replicate-from: "cert-manager/cert-dubyatp-xyz"
replicator.v1.mittwald.de/replicated-keys: "tls.crt,tls.key"
data:
tls.crt: ""
tls.key: ""
+36
View File
@@ -0,0 +1,36 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: attic-config
data:
server.toml: |
listen = "[::]:8080"
allowed-hosts = []
#api-endpoint = "https://nix-cache.dubyatp.xyz/"
[database]
url = "sqlite:///var/empty/.local/share/attic/server.db"
[storage]
path = "/data/.local/share/attic/storage"
type = "local"
#region = "us-east-1"
#bucket = "attic-bucket"
#endpoint = "https://weyma-s3.infra.dubyatp.xyz"
[chunking]
nar-size-threshold = 65536
min-size = 16384
avg-size = 65536
max-size = 262144
[compression]
type = "zstd"
[garbage-collection]
interval = "12 hours"
[jwt]
[jwt.signing]
+24
View File
@@ -0,0 +1,24 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: attic-db-auth
spec:
data:
- remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: cloudnativepg
metadataPolicy: None
property: attic_pw
secretKey: password
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
name: weyma-vault
target:
template:
data:
ATTIC_SERVER_DATABASE_URL: "postgres://attic:{{ .password }}@pooler-weyma-rw.cloudnativepg.svc.cluster.local/attic"
creationPolicy: Owner
deletionPolicy: Retain
name: attic-db-auth
+12 -2
View File
@@ -3,6 +3,7 @@ kind: Deployment
metadata: metadata:
name: attic name: attic
spec: spec:
replicas: 3
selector: selector:
matchLabels: matchLabels:
app: attic app: attic
@@ -13,17 +14,26 @@ spec:
spec: spec:
containers: containers:
- name: attic - name: attic
image: ghcr.io/zhaofengli/attic:ff8a897d1f4408ebbf4d45fa9049c06b3e1e3f4e image: ghcr.io/zhaofengli/attic:c4ffb5e86e928572e867bd3f81545293313e0a08
envFrom: envFrom:
- secretRef: - secretRef:
name: attic-secret name: attic-secret
- secretRef:
name: attic-db-auth
- secretRef:
name: attic-bucket
volumeMounts: volumeMounts:
- name: attic-pvc - name: attic-pvc
mountPath: /var/empty mountPath: /var/empty/
resources: resources:
limits: limits:
memory: "2Gi" memory: "2Gi"
cpu: "500m" cpu: "500m"
- name: multitool
image: wbitt/network-multitool
volumeMounts:
- name: attic-pvc
mountPath: /var/empty/
volumes: volumes:
- name: attic-pvc - name: attic-pvc
persistentVolumeClaim: persistentVolumeClaim:
+18
View File
@@ -0,0 +1,18 @@
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: traefik
spec:
gatewayClassName: traefik
listeners:
- name: https
protocol: HTTPS
port: 8443
tls:
mode: Terminate
certificateRefs:
- name: cert-dubyatp-xyz
namespace: cert-manager
allowedRoutes:
namespaces:
from: Same
+19
View File
@@ -0,0 +1,19 @@
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: attic
spec:
parentRefs:
- name: traefik
sectionName: https
kind: Gateway
hostnames:
- nix-cache.dubyatp.xyz
rules:
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- name: attic-svc
port: 8080
+1 -1
View File
@@ -24,5 +24,5 @@ appVersion: "1.0"
dependencies: dependencies:
- name: authentik - name: authentik
version: 2025.12.3 version: 2026.5.5
repository: https://charts.goauthentik.io repository: https://charts.goauthentik.io
+46 -1
View File
@@ -32,8 +32,10 @@ authentik:
secretKeyRef: secretKeyRef:
name: authentik-credentials name: authentik-credentials
key: authentik-secret-key key: authentik-secret-key
- name: AUTHENTIK_POSTGRESQL__DISABLE_SERVER_SIDE_CURSORS
value: "true"
- name: AUTHENTIK_POSTGRESQL__HOST - name: AUTHENTIK_POSTGRESQL__HOST
value: pooler-weyma-rw.cloudnativepg.svc.cluster.local value: pooler-weyma-rw-authentik.cloudnativepg.svc.cluster.local
- name: AUTHENTIK_POSTGRESQL__NAME - name: AUTHENTIK_POSTGRESQL__NAME
value: authentik value: authentik
- name: AUTHENTIK_POSTGRESQL__USER - name: AUTHENTIK_POSTGRESQL__USER
@@ -58,7 +60,41 @@ authentik:
key: smtp-password key: smtp-password
- name: AUTHENTIK_EMAIL__TIMEOUT - name: AUTHENTIK_EMAIL__TIMEOUT
value: "30" value: "30"
- name: AUTHENTIK_STORAGE__BACKEND
value: "s3"
- name: AUTHENTIK_STORAGE__S3__ENDPOINT
value: "https://weyma-s3.infra.dubyatp.xyz"
- name: AUTHENTIK_STORAGE__S3__BUCKET_NAME
value: "authentik-files"
- name: AUTHENTIK_STORAGE__S3__ACCESS_KEY
valueFrom:
secretKeyRef:
name: authentik-files
key: AWS_ACCESS_KEY_ID
- name: AUTHENTIK_STORAGE__S3__SECRET_KEY
valueFrom:
secretKeyRef:
name: authentik-files
key: AWS_SECRET_ACCESS_KEY
additionalObjects: additionalObjects:
- apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: traefik
spec:
gatewayClassName: traefik
listeners:
- name: https
protocol: HTTPS
port: 8443
tls:
mode: Terminate
certificateRefs:
- name: cert-dubyatp-xyz
namespace: cert-manager
allowedRoutes:
namespaces:
from: Same
- apiVersion: networking.k8s.io/v1 - apiVersion: networking.k8s.io/v1
kind: Ingress kind: Ingress
metadata: metadata:
@@ -146,3 +182,12 @@ authentik:
creationPolicy: Owner creationPolicy: Owner
deletionPolicy: Retain deletionPolicy: Retain
name: authentik-db-auth name: authentik-db-auth
- apiVersion: objectbucket.io/v1alpha1
kind: ObjectBucketClaim
metadata:
name: authentik-files
spec:
additionalConfig:
maxSize: 20Gi
bucketName: authentik-files
storageClassName: weyma-s3-bucket
+41
View File
@@ -0,0 +1,41 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: runner-config
data:
config.yaml: |-
log:
level: info
runner:
file: /data/.runner
capacity: 1
env_file: .env
timeout: 3h
shutdown_timeout: 0s
insecure: false
fetch_timeout: 5s
fetch_interval: 2s
labels:
- "ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
- "ubuntu-22.04:docker://docker.gitea.com/runner-images:ubuntu-22.04"
- "ubuntu-20.04:docker://docker.gitea.com/runner-images:ubuntu-20.04"
cache:
enabled: true
dir: ""
host: ""
port: 0
external_server: ""
container:
network: "host"
privileged: false
options: ""
workdir_parent: /scratch
valid_volumes:
- /scratch/**
docker_host: ""
force_pull: true
force_rebuild: false
require_docker: false
docker_timeout: 0s
host:
workdir_parent:
+38 -27
View File
@@ -16,22 +16,37 @@ spec:
labels: labels:
app: act-runner app: act-runner
spec: spec:
containers: initContainers:
- name: runner - name: sysctl
image: busybox
securityContext:
privileged: true
command: command:
- sh - sh
- -c - -c
- while ! nc -z localhost 2376 </dev/null; do echo 'waiting for docker daemon...'; - echo 28633 > /proc/sys/user/max_user_namespaces
sleep 5; done; /sbin/tini -- run.sh - name: chown-data
image: gitea/act_runner:nightly image: busybox
securityContext:
runAsUser: 0
command:
- sh
- -c
- chown -R 1000:1000 /data
volumeMounts:
- name: runner-data
mountPath: /data
containers:
- name: runner
image: gitea/act_runner:nightly-dind-rootless
imagePullPolicy: Always imagePullPolicy: Always
env: env:
- name: DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS
value: "--net=slirp4netns --copy-up=/etc"
- name: CONFIG_FILE
value: /config/config.yaml
- name: DOCKER_HOST - name: DOCKER_HOST
value: tcp://localhost:2376 value: unix:///run/user/1000/docker.sock
- name: DOCKER_CERT_PATH
value: /certs/client
- name: DOCKER_TLS_VERIFY
value: "1"
- name: GITEA_INSTANCE_URL - name: GITEA_INSTANCE_URL
value: https://git.dubyatp.xyz value: https://git.dubyatp.xyz
- name: GITEA_RUNNER_REGISTRATION_TOKEN - name: GITEA_RUNNER_REGISTRATION_TOKEN
@@ -39,33 +54,29 @@ spec:
secretKeyRef: secretKeyRef:
key: registration-token key: registration-token
name: gitea-runner-token name: gitea-runner-token
terminationMessagePath: /dev/termination-log
terminationMessagePolicy: File
volumeMounts:
- name: docker-certs
mountPath: /certs
- name: runner-data
mountPath: /data
- name: daemon
env:
- name: DOCKER_TLS_CERTDIR
value: /certs
image: docker:23.0.6-dind
imagePullPolicy: IfNotPresent
securityContext: securityContext:
privileged: true privileged: true
terminationMessagePath: /dev/termination-log terminationMessagePath: /dev/termination-log
terminationMessagePolicy: File terminationMessagePolicy: File
volumeMounts: volumeMounts:
- mountPath: /certs - name: runner-config
name: docker-certs mountPath: /config
- name: runner-data
mountPath: /data
- name: runner-scratch
mountPath: /scratch
dnsPolicy: ClusterFirst dnsPolicy: ClusterFirst
hostNetwork: true
restartPolicy: Always restartPolicy: Always
schedulerName: default-scheduler schedulerName: default-scheduler
terminationGracePeriodSeconds: 30 terminationGracePeriodSeconds: 30
volumes: volumes:
- name: docker-certs - name: runner-scratch
emptyDir:
medium: Memory
sizeLimit: 5Gi
- name: runner-config
configMap:
name: runner-config
volumeClaimTemplates: volumeClaimTemplates:
- metadata: - metadata:
name: runner-data name: runner-data
+1 -1
View File
@@ -24,5 +24,5 @@ appVersion: "1.0"
dependencies: dependencies:
- name: gitea - name: gitea
version: 12.5.4 version: 12.7.0
repository: https://weyma-s3.infra.dubyatp.xyz/helm-bucket-ea34bc44-ef19-480d-a16a-1e583991f123/charts/ repository: https://weyma-s3.infra.dubyatp.xyz/helm-bucket-ea34bc44-ef19-480d-a16a-1e583991f123/charts/
+36 -16
View File
@@ -1,15 +1,27 @@
gitea: gitea:
replicaCount: 3 replicaCount: 3
ingress: # ingress:
# enabled: true
# hosts:
# - host: git.dubyatp.xyz
# paths:
# - path: /
# tls:
# - secretName: cert-dubyatp-xyz
# hosts:
# - git.dubyatp.xyz
gateway:
httpRoute:
enabled: true enabled: true
hosts: hostnames:
- host: git.dubyatp.xyz - git.dubyatp.xyz
parentRefs:
- name: traefik
sectionName: https
kind: Gateway
pathType: PathPrefix
paths: paths:
- path: / - path: /
tls:
- secretName: cert-dubyatp-xyz
hosts:
- git.dubyatp.xyz
persistence: persistence:
enabled: true enabled: true
create: true create: true
@@ -105,16 +117,24 @@ gitea:
services: services:
- name: gitea-ssh - name: gitea-ssh
port: 22 port: 22
- apiVersion: v1 - apiVersion: gateway.networking.k8s.io/v1
kind: Secret kind: Gateway
metadata: metadata:
name: cert-dubyatp-xyz name: traefik
annotations: spec:
replicator.v1.mittwald.de/replicate-from: "cert-manager/cert-dubyatp-xyz" gatewayClassName: traefik
replicator.v1.mittwald.de/replicated-keys: "tls.crt,tls.key" listeners:
data: - name: https
tls.crt: "" protocol: HTTPS
tls.key: "" port: 8443
tls:
mode: Terminate
certificateRefs:
- name: cert-dubyatp-xyz
namespace: cert-manager
allowedRoutes:
namespaces:
from: Same
- apiVersion: external-secrets.io/v1 - apiVersion: external-secrets.io/v1
kind: ExternalSecret kind: ExternalSecret
metadata: metadata:
+1 -1
View File
@@ -191,6 +191,6 @@ grafana:
image: image:
registry: docker.io registry: docker.io
repository: bats/bats repository: bats/bats
tag: 1.13.0 tag: 1.14.0
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
useStatefulSet: false useStatefulSet: false
+1 -1
View File
@@ -24,5 +24,5 @@ appVersion: "1.0"
dependencies: dependencies:
- name: jellyfin - name: jellyfin
version: 2.7.0 version: 3.2.0
repository: https://jellyfin.github.io/jellyfin-helm repository: https://jellyfin.github.io/jellyfin-helm
+18
View File
@@ -0,0 +1,18 @@
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: traefik
spec:
gatewayClassName: traefik
listeners:
- name: https
protocol: HTTPS
port: 8443
tls:
mode: Terminate
certificateRefs:
- name: cert-dubyatp-xyz
namespace: cert-manager
allowedRoutes:
namespaces:
from: Same
+14 -13
View File
@@ -1,4 +1,4 @@
{{- if and (.Values.jellyfin.metrics.enabled) (.Values.jellyfin.ingress.enabled) -}} {{- if and (.Values.jellyfin.metrics.enabled) (.Values.jellyfin.httpRoute.enabled) -}}
--- ---
apiVersion: v1 apiVersion: v1
kind: Service kind: Service
@@ -13,21 +13,22 @@ spec:
port: 6767 port: 6767
targetPort: 6767 targetPort: 6767
--- ---
apiVersion: networking.k8s.io/v1 apiVersion: gateway.networking.k8s.io/v1
kind: Ingress kind: HTTPRoute
metadata: metadata:
name: block-metrics name: block-metrics
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
spec: spec:
parentRefs:
{{- toYaml .Values.jellyfin.httpRoute.parentRefs | nindent 4 }}
hostnames:
{{- toYaml .Values.jellyfin.httpRoute.hostnames | nindent 4 }}
rules: rules:
- host: {{ (index .Values.jellyfin.ingress.hosts 0).host }} - matches:
http: - path:
paths: type: PathPrefix
- pathType: Prefix value: /metrics
path: "/metrics" backendRefs:
backend: - name: dummy-svc
service: port: 6767
name: dummy-svc
port:
number: 6767
{{- end }} {{- end }}
-11
View File
@@ -1,11 +0,0 @@
apiVersion: v1
data:
tls.crt:
tls.key:
kind: Secret
metadata:
annotations:
replicator.v1.mittwald.de/replicate-from: cert-manager/cert-dubyatp-xyz
replicator.v1.mittwald.de/replicated-keys: tls.crt,tls.key
name: cert-dubyatp-xyz
type: Opaque
+6 -15
View File
@@ -1,16 +1,13 @@
jellyfin: jellyfin:
deploymentStrategy: deploymentStrategy:
type: Recreate type: Recreate
ingress: httpRoute:
enabled: true enabled: true
hosts: parentRefs:
- host: jellyfin.dubyatp.xyz - name: traefik
paths: sectionName: https
- path: / kind: Gateway
pathType: ImplementationSpecific hostnames:
tls:
- secretName: cert-dubyatp.xyz
hosts:
- jellyfin.dubyatp.xyz - jellyfin.dubyatp.xyz
persistence: persistence:
config: config:
@@ -26,10 +23,6 @@ jellyfin:
nfs: nfs:
server: 10.105.15.20 server: 10.105.15.20
path: /mnt/hdd-pool/movies path: /mnt/hdd-pool/movies
- name: dvr
nfs:
server: 10.105.15.20
path: /mnt/hdd-pool/DVR
- name: youtube-vids - name: youtube-vids
nfs: nfs:
server: 10.105.15.20 server: 10.105.15.20
@@ -50,8 +43,6 @@ jellyfin:
mountPath: /mnt/tv-shows mountPath: /mnt/tv-shows
- name: movies - name: movies
mountPath: /mnt/movies mountPath: /mnt/movies
- name: dvr
mountPath: /mnt/dvr
- name: youtube-vids - name: youtube-vids
mountPath: /mnt/youtube-vids mountPath: /mnt/youtube-vids
- name: transcode-temp - name: transcode-temp
+1 -1
View File
@@ -54,7 +54,7 @@ spec:
envFrom: envFrom:
- configMapRef: - configMapRef:
name: netmaker-config name: netmaker-config
image: gravitl/netmaker:v1.4.0 image: gravitl/netmaker:v1.6.0
imagePullPolicy: Always imagePullPolicy: Always
name: netmaker name: netmaker
ports: ports:
+1 -1
View File
@@ -14,7 +14,7 @@ spec:
spec: spec:
containers: containers:
- name: netmaker-ui - name: netmaker-ui
image: gravitl/netmaker-ui:v1.1.0 image: gravitl/netmaker-ui:v1.6.0
env: env:
- name: BACKEND_URL - name: BACKEND_URL
value: 'https://api.netmaker.infra.dubyatp.xyz' value: 'https://api.netmaker.infra.dubyatp.xyz'
+28
View File
@@ -0,0 +1,28 @@
apiVersion: v2
name: searxng
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
appVersion: "1.0"
dependencies:
- name: searxng
version: 1.1.4
repository: https://charts.kubito.dev
+3 -1
View File
@@ -14,12 +14,14 @@ spec:
spec: spec:
containers: containers:
- name: yt-dlp-bot - name: yt-dlp-bot
image: 'git.dubyatp.xyz/williamp/yt-dlp-bot:d7ad90a' image: 'git.dubyatp.xyz/williamp/yt-dlp-bot:f48776c'
env: env:
- name: OUT_PATH - name: OUT_PATH
value: /data/youtube-vids value: /data/youtube-vids
- name: TEMP_PATH - name: TEMP_PATH
value: /tmp/ytdlp-temp value: /tmp/ytdlp-temp
- name: LOADING_EMOJI
value: "<a:loading:1479485735076761848>"
envFrom: envFrom:
- secretRef: - secretRef:
name: yt-dlp-discord-token name: yt-dlp-discord-token