Compare commits
1
Commits
main
..
3730def176
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3730def176
|
@@ -2,7 +2,7 @@ version: "3.8"
|
||||
services:
|
||||
discovery:
|
||||
restart: unless-stopped
|
||||
image: ghcr.io/siderolabs/discovery-service:v1.1.0
|
||||
image: ghcr.io/siderolabs/discovery-service:v1.0.17
|
||||
ports:
|
||||
- 10.105.6.215:3000:3000
|
||||
- 10.105.6.215:3001:3001
|
||||
@@ -1,9 +1,9 @@
|
||||
kind: Cluster
|
||||
name: weyma-talos
|
||||
kubernetes:
|
||||
version: v1.36.4
|
||||
version: v1.35.4
|
||||
talos:
|
||||
version: v1.13.9
|
||||
version: v1.12.7
|
||||
features:
|
||||
backupConfiguration:
|
||||
interval: 6h0m0s
|
||||
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: argo-cd
|
||||
version: 10.5.0
|
||||
version: 10.0.1
|
||||
repository: https://argoproj.github.io/argo-helm
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: cert-manager
|
||||
version: v1.21.1
|
||||
version: v1.20.3
|
||||
repository: https://charts.jetstack.io
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: argocd
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: argocd
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: attic
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: attic
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: authentik
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: authentik
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: duby-blog
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: duby-blog
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: dubyatp-xyz
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: dubyatp-xyz
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: frenworld-archive
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: frenworld-archive
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-frenworld-archive-io
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: gitea
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: gitea
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: grafana
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: grafana
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: jellyfin
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: jellyfin
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: kite
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: kite
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: lumfao-dubyatp-xyz
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: lumfao-dubyatp-xyz
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: netmaker
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: netmaker
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: nextcloud
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: nextcloud
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: rook-ceph
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: rook-ceph
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: test-dubyatp-xyz
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: default
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: traefik
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: traefik
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: vaultwarden
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: vaultwarden
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: whatismyip
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: whatismyip
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: williamtpeebles-com
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: williamtpeebles-com
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-williamtpeebles-com
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: external-secrets
|
||||
version: 2.10.0
|
||||
version: 2.7.0
|
||||
repository: https://charts.external-secrets.io
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: kite
|
||||
version: 0.15.0
|
||||
version: 0.13.0
|
||||
repository: https://zxh326.github.io/kite
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: kubernetes-replicator
|
||||
version: 2.12.4
|
||||
version: 2.12.3
|
||||
repository: https://helm.mittwald.de
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: kube-prometheus-stack
|
||||
version: 88.6.2
|
||||
version: 87.4.0
|
||||
repository: https://prometheus-community.github.io/helm-charts
|
||||
@@ -21,24 +21,11 @@ spec:
|
||||
# versions running within the cluster. See tags available at https://hub.docker.com/r/ceph/ceph/tags/.
|
||||
# If you want to be more precise, you can always use a timestamp tag such as quay.io/ceph/ceph:v19.2.1-20250202
|
||||
# This tag might not contain a new Ceph version, just security fixes from the underlying operating system, which will reduce vulnerabilities
|
||||
image: quay.io/ceph/ceph:v20.2.4-20260818
|
||||
image: quay.io/ceph/ceph:v20.2.0-20251104
|
||||
# Whether to allow unsupported versions of Ceph. Currently Reef and Squid are supported.
|
||||
# Future versions such as Tentacle (v20) would require this to be set to `true`.
|
||||
# Do not set to true in production.
|
||||
allowUnsupported: false
|
||||
security:
|
||||
cephx:
|
||||
daemon:
|
||||
keyRotationPolicy: KeyGeneration
|
||||
keyGeneration: 2 # must be greater than the current keyGeneration
|
||||
csi:
|
||||
keyRotationPolicy: KeyGeneration
|
||||
keyGeneration: 3 # must be greater than the current keyGeneration
|
||||
keyType: aes # Talos kernel 6.18 / cephcsi v3.17.0 don't support aes256k yet
|
||||
rbdMirrorPeer:
|
||||
keyRotationPolicy: KeyGeneration
|
||||
keyGeneration: 3 # must be greater than the current keyGeneration
|
||||
keyType: aes # Talos kernel 6.18 / cephcsi v3.17.0 don't support aes256k yet
|
||||
# The path on the host where configuration files will be persisted. Must be specified. If there are multiple clusters, the directory must be unique for each cluster.
|
||||
# Important: if you reinstall the cluster, make sure you delete this directory from each host or else the mons will fail to start on the new cluster.
|
||||
# In Minikube, the '/data' directory is configured to persist across reboots. Use "/data/rook" in Minikube environment.
|
||||
@@ -77,7 +64,7 @@ spec:
|
||||
# List of modules to optionally enable or disable.
|
||||
# Note the "dashboard" and "monitoring" modules are already configured by other settings in the cluster CR.
|
||||
- name: rook
|
||||
enabled: false
|
||||
enabled: true
|
||||
# enable the ceph dashboard for viewing cluster status
|
||||
dashboard:
|
||||
enabled: true
|
||||
@@ -371,12 +358,3 @@ spec:
|
||||
disabled: false
|
||||
osd:
|
||||
disabled: false
|
||||
muteHealthWarning: # Remove these after Talos uses 7.0+ kernel
|
||||
AUTH_INSECURE_ROTATING_SERVICE_KEY_TYPE:
|
||||
policy: mute
|
||||
AUTH_INSECURE_CLIENT_KEY_TYPE:
|
||||
policy: mute
|
||||
AUTH_INSECURE_KEYS_ALLOWED:
|
||||
policy: mute
|
||||
AUTH_INSECURE_KEYS_CREATABLE:
|
||||
policy: mute
|
||||
@@ -24,8 +24,8 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: rook-ceph
|
||||
version: v1.20.6
|
||||
version: v1.20.1
|
||||
repository: https://charts.rook.io/release
|
||||
- name: ceph-csi-drivers
|
||||
version: 1.0.4
|
||||
version: 1.0.1
|
||||
repository: https://ceph.github.io/ceph-csi-operator
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: traefik
|
||||
version: 41.4.0
|
||||
version: 41.0.1
|
||||
repository: https://traefik.github.io/charts
|
||||
@@ -37,7 +37,7 @@ traefik:
|
||||
kind: DaemonSet
|
||||
additionalContainers:
|
||||
- name: cloudflared
|
||||
image: cloudflare/cloudflared:2026.8.3
|
||||
image: cloudflare/cloudflared:2026.6.1
|
||||
command:
|
||||
- cloudflared
|
||||
- tunnel
|
||||
@@ -69,8 +69,6 @@ traefik:
|
||||
dashboard:
|
||||
enabled: true
|
||||
providers:
|
||||
kubernetesGateway:
|
||||
enabled: true
|
||||
file:
|
||||
enabled: true
|
||||
watch: true
|
||||
|
||||
Reference in New Issue
Block a user