Compare commits

..
Author SHA1 Message Date
renovate-bot f64e232a66 chore(deps): update helm release authentik to v2026.8.1 2026-09-01 15:00:10 +00:00
williamp 99b1bbc8c1 gitea: move ALLOWED_HOST_LIST to security per warning on site admin 2026-08-29 16:04:14 -04:00
williamp d704a0808d Merge pull request 'chore(deps): update helm release gitea to v12.7.3' (#118) from renovate/gitea-12.x into main
Reviewed-on: #118
2026-08-29 20:00:42 +00:00
renovate-bot 8819bbd2b4 chore(deps): update helm release gitea to v12.7.3 2026-08-29 20:00:10 +00:00
actions b94a849172 yt-dlp-bot: deploy update to 1060228 2026-08-20 00:49:57 +00:00
actions 4744761cdf yt-dlp-bot: deploy update to 8ebdabc 2026-08-19 00:38:55 +00:00
williamp 5c5498e6b4 Merge pull request 'chore(deps): update helm release authentik to v2026.8.0' (#117) from renovate/authentik-2026.x into main
Reviewed-on: #117
2026-08-18 23:11:20 +00:00
renovate-bot 9a5cf6cd99 chore(deps): update helm release authentik to v2026.8.0 2026-08-18 23:00:11 +00:00
williamp aadbfd0077 Merge pull request 'chore(deps): update helm release gitea to v12.7.2' (#116) from renovate/gitea-12.x into main
Reviewed-on: #116
2026-08-08 02:03:55 +00:00
renovate-bot 07124fef38 chore(deps): update helm release gitea to v12.7.2 2026-08-08 02:00:11 +00:00
williamp 6d89a26447 Merge pull request 'chore(deps): update helm release gitea to v12.7.1' (#115) from renovate/gitea-12.x into main
Reviewed-on: #115
2026-07-29 00:11:22 +00:00
renovate-bot 8394a5971d chore(deps): update helm release gitea to v12.7.1 2026-07-29 00:00:11 +00:00
williamp 22ab0ef53a vaultwarden: upgrade to 1.37.0 2026-07-25 18:18:22 -04:00
williamp 56d65605aa Merge pull request 'chore(deps): update helm release authentik to v2026.5.6' (#114) from renovate/authentik-2026.x into main
Reviewed-on: #114
2026-07-22 23:09:41 +00:00
williamp 16296a4144 Merge pull request 'chore(deps): update docker.io/bats/bats docker tag to v1.14.0' (#113) from renovate/docker.io-bats-bats-1.x into main
Reviewed-on: #113
2026-07-22 23:08:21 +00:00
williamp 0c2ed1f76a vaultwarden: upgrade to 1.36.0 2026-07-22 19:04:04 -04:00
renovate-bot 58bc1b2ce4 chore(deps): update helm release authentik to v2026.5.6 2026-07-22 17:00:12 +00:00
renovate-bot 4567854c12 chore(deps): update docker.io/bats/bats docker tag to v1.14.0 2026-07-21 20:00:27 +00:00
williamp 944d5793af netmaker: upgrade to v1.6.0 2026-07-21 15:20:08 -04:00
williamp 85db172de8 Merge pull request 'chore(deps): update helm release authentik to v2026.5.5' (#112) from renovate/authentik-2026.x into main
Reviewed-on: #112
2026-07-17 14:35:30 +00:00
renovate-bot d0263b767b chore(deps): update helm release authentik to v2026.5.5 2026-07-15 18:00:11 +00:00
williamp a913dc0989 authentik: add gateway object to prepare for gateway api migration 2026-07-08 18:07:45 -04:00
williamp 08ceba58c2 Merge pull request 'chore(deps): update helm release authentik to v2026.5.4' (#111) from renovate/authentik-2026.x into main
Reviewed-on: #111
2026-07-08 21:58:24 +00:00
renovate-bot 0e6ba2c4d9 chore(deps): update helm release authentik to v2026.5.4 2026-07-08 13:00:10 +00:00
actions eab7f0a533 yt-dlp-bot: deploy update to f48776c 2026-07-05 01:04:40 +00:00
williamp ac2ae0c3df attic: migrate to gateway API 2026-07-04 16:34:03 -04:00
williamp 93663535bc jellyfin: migrate metrics-block to httproute as well 2026-07-04 16:27:27 -04:00
williamp d06ef83ee2 jellyfin: rm ssl cert secret 2026-07-04 16:23:59 -04:00
williamp 8ad2c46c20 jellyfin: migrate to gateway API 2026-07-04 16:23:06 -04:00
williamp c83625bc88 gitea: migrate to gateway API for ingress 2026-07-04 16:14:20 -04:00
williamp ef81d700a8 Merge pull request 'chore(deps): update helm release gitea to v12.7.0' (#110) from renovate/gitea-12.x into main
Reviewed-on: #110
2026-07-04 17:08:00 +00:00
renovate-bot b62f3935be chore(deps): update helm release gitea to v12.7.0 2026-07-04 17:00:09 +00:00
williamp 412a6918b6 Merge pull request 'chore(deps): update helm release gitea to v12.6.3' (#109) from renovate/gitea-12.x into main
Reviewed-on: #109
2026-06-21 23:44:42 +00:00
renovate-bot 34dab7a09f chore(deps): update helm release gitea to v12.6.3 2026-06-21 22:00:08 +00:00
williamp ac1ad7359f Merge pull request 'chore(deps): update helm release gitea to v12.6.2' (#108) from renovate/gitea-12.x into main
Reviewed-on: #108
2026-06-20 22:00:37 +00:00
renovate-bot d8e470c623 chore(deps): update helm release gitea to v12.6.2 2026-06-20 22:00:12 +00:00
williamp 0cf458a6bb Merge pull request 'chore(deps): update helm release gitea to v12.6.1' (#107) from renovate/gitea-12.x into main
Reviewed-on: #107
2026-06-16 17:50:39 +00:00
renovate-bot 18fe757fe2 chore(deps): update helm release gitea to v12.6.1 2026-06-16 04:00:11 +00:00
williamp aa83a625ac Merge pull request 'chore(deps): update helm release authentik to v2026.5.3' (#106) from renovate/authentik-2026.x into main
Reviewed-on: #106
2026-06-12 23:17:38 +00:00
renovate-bot 30c821f5cd chore(deps): update helm release authentik to v2026.5.3 2026-06-11 22:00:11 +00:00
actions 4bde426243 yt-dlp-bot: deploy update to 7c4c14d 2026-06-10 03:00:04 +00:00
williamp 2d8a0297f5 Merge pull request 'chore(deps): update helm release searxng to v1.1.4' (#105) from renovate/searxng-1.x into main
Reviewed-on: #105
2026-06-10 00:58:09 +00:00
renovate-bot 9b10b90acd chore(deps): update helm release searxng to v1.1.4 2026-06-10 00:00:12 +00:00
17 changed files with 142 additions and 73 deletions
-10
View File
@@ -1,10 +0,0 @@
apiVersion: v1
kind: Secret
metadata:
name: cert-dubyatp-xyz
annotations:
replicator.v1.mittwald.de/replicate-from: "cert-manager/cert-dubyatp-xyz"
replicator.v1.mittwald.de/replicated-keys: "tls.crt,tls.key"
data:
tls.crt: ""
tls.key: ""
+18
View File
@@ -0,0 +1,18 @@
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: traefik
spec:
gatewayClassName: traefik
listeners:
- name: https
protocol: HTTPS
port: 8443
tls:
mode: Terminate
certificateRefs:
- name: cert-dubyatp-xyz
namespace: cert-manager
allowedRoutes:
namespaces:
from: Same
+19
View File
@@ -0,0 +1,19 @@
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: attic
spec:
parentRefs:
- name: traefik
sectionName: https
kind: Gateway
hostnames:
- nix-cache.dubyatp.xyz
rules:
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- name: attic-svc
port: 8080
+1 -1
View File
@@ -24,5 +24,5 @@ appVersion: "1.0"
dependencies:
- name: authentik
version: 2026.5.2
version: 2026.8.1
repository: https://charts.goauthentik.io
+18
View File
@@ -77,6 +77,24 @@ authentik:
name: authentik-files
key: AWS_SECRET_ACCESS_KEY
additionalObjects:
- apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: traefik
spec:
gatewayClassName: traefik
listeners:
- name: https
protocol: HTTPS
port: 8443
tls:
mode: Terminate
certificateRefs:
- name: cert-dubyatp-xyz
namespace: cert-manager
allowedRoutes:
namespaces:
from: Same
- apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
+1 -1
View File
@@ -24,5 +24,5 @@ appVersion: "1.0"
dependencies:
- name: gitea
version: 12.6.0
version: 12.7.3
repository: https://weyma-s3.infra.dubyatp.xyz/helm-bucket-ea34bc44-ef19-480d-a16a-1e583991f123/charts/
+40 -21
View File
@@ -1,15 +1,27 @@
gitea:
replicaCount: 3
ingress:
enabled: true
hosts:
- host: git.dubyatp.xyz
paths:
- path: /
tls:
- secretName: cert-dubyatp-xyz
hosts:
- git.dubyatp.xyz
# ingress:
# enabled: true
# hosts:
# - host: git.dubyatp.xyz
# paths:
# - path: /
# tls:
# - secretName: cert-dubyatp-xyz
# hosts:
# - git.dubyatp.xyz
gateway:
httpRoute:
enabled: true
hostnames:
- git.dubyatp.xyz
parentRefs:
- name: traefik
sectionName: https
kind: Gateway
pathType: PathPrefix
paths:
- path: /
persistence:
enabled: true
create: true
@@ -71,8 +83,6 @@ gitea:
OFFLINE_MODE: false
service:
DISABLE_REGISTRATION: true
webhook:
ALLOWED_HOST_LIST: "drone.infra.dubyatp.xyz,argocd.infra.dubyatp.xyz,discord.com,10.0.0.0/8"
mailer:
ENABLED: true
FROM: [email protected]
@@ -82,6 +92,7 @@ gitea:
USER: gitea_dubyatp
security:
INSTALL_LOCK: true
ALLOWED_HOST_LIST: "drone.infra.dubyatp.xyz,argocd.infra.dubyatp.xyz,discord.com,10.0.0.0/8"
metrics:
enabled: true
serviceMonitor:
@@ -105,16 +116,24 @@ gitea:
services:
- name: gitea-ssh
port: 22
- apiVersion: v1
kind: Secret
- apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: cert-dubyatp-xyz
annotations:
replicator.v1.mittwald.de/replicate-from: "cert-manager/cert-dubyatp-xyz"
replicator.v1.mittwald.de/replicated-keys: "tls.crt,tls.key"
data:
tls.crt: ""
tls.key: ""
name: traefik
spec:
gatewayClassName: traefik
listeners:
- name: https
protocol: HTTPS
port: 8443
tls:
mode: Terminate
certificateRefs:
- name: cert-dubyatp-xyz
namespace: cert-manager
allowedRoutes:
namespaces:
from: Same
- apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
+1 -1
View File
@@ -191,6 +191,6 @@ grafana:
image:
registry: docker.io
repository: bats/bats
tag: 1.13.0
tag: 1.14.0
imagePullPolicy: IfNotPresent
useStatefulSet: false
+18
View File
@@ -0,0 +1,18 @@
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: traefik
spec:
gatewayClassName: traefik
listeners:
- name: https
protocol: HTTPS
port: 8443
tls:
mode: Terminate
certificateRefs:
- name: cert-dubyatp-xyz
namespace: cert-manager
allowedRoutes:
namespaces:
from: Same
+14 -13
View File
@@ -1,4 +1,4 @@
{{- if and (.Values.jellyfin.metrics.enabled) (.Values.jellyfin.ingress.enabled) -}}
{{- if and (.Values.jellyfin.metrics.enabled) (.Values.jellyfin.httpRoute.enabled) -}}
---
apiVersion: v1
kind: Service
@@ -13,21 +13,22 @@ spec:
port: 6767
targetPort: 6767
---
apiVersion: networking.k8s.io/v1
kind: Ingress
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: block-metrics
namespace: {{ .Release.Namespace }}
spec:
parentRefs:
{{- toYaml .Values.jellyfin.httpRoute.parentRefs | nindent 4 }}
hostnames:
{{- toYaml .Values.jellyfin.httpRoute.hostnames | nindent 4 }}
rules:
- host: {{ (index .Values.jellyfin.ingress.hosts 0).host }}
http:
paths:
- pathType: Prefix
path: "/metrics"
backend:
service:
name: dummy-svc
port:
number: 6767
- matches:
- path:
type: PathPrefix
value: /metrics
backendRefs:
- name: dummy-svc
port: 6767
{{- end }}
-11
View File
@@ -1,11 +0,0 @@
apiVersion: v1
data:
tls.crt:
tls.key:
kind: Secret
metadata:
annotations:
replicator.v1.mittwald.de/replicate-from: cert-manager/cert-dubyatp-xyz
replicator.v1.mittwald.de/replicated-keys: tls.crt,tls.key
name: cert-dubyatp-xyz
type: Opaque
+7 -10
View File
@@ -1,17 +1,14 @@
jellyfin:
deploymentStrategy:
type: Recreate
ingress:
httpRoute:
enabled: true
hosts:
- host: jellyfin.dubyatp.xyz
paths:
- path: /
pathType: ImplementationSpecific
tls:
- secretName: cert-dubyatp.xyz
hosts:
- jellyfin.dubyatp.xyz
parentRefs:
- name: traefik
sectionName: https
kind: Gateway
hostnames:
- jellyfin.dubyatp.xyz
persistence:
config:
size: 25Gi
+1 -1
View File
@@ -54,7 +54,7 @@ spec:
envFrom:
- configMapRef:
name: netmaker-config
image: gravitl/netmaker:v1.4.0
image: gravitl/netmaker:v1.6.0
imagePullPolicy: Always
name: netmaker
ports:
+1 -1
View File
@@ -14,7 +14,7 @@ spec:
spec:
containers:
- name: netmaker-ui
image: gravitl/netmaker-ui:v1.1.0
image: gravitl/netmaker-ui:v1.6.0
env:
- name: BACKEND_URL
value: 'https://api.netmaker.infra.dubyatp.xyz'
+1 -1
View File
@@ -24,5 +24,5 @@ appVersion: "1.0"
dependencies:
- name: searxng
version: 1.1.2
version: 1.1.4
repository: https://charts.kubito.dev
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
spec:
containers:
- name: vaultwarden
image: vaultwarden/server:1.35.2-alpine
image: vaultwarden/server:1.37.0-alpine
livenessProbe:
exec:
command:
+1 -1
View File
@@ -14,7 +14,7 @@ spec:
spec:
containers:
- name: yt-dlp-bot
image: 'git.dubyatp.xyz/williamp/yt-dlp-bot:23993d7'
image: 'git.dubyatp.xyz/williamp/yt-dlp-bot:1060228'
env:
- name: OUT_PATH
value: /data/youtube-vids