Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2cfc3077de
|
@@ -2,7 +2,7 @@ version: "3.8"
|
||||
services:
|
||||
discovery:
|
||||
restart: unless-stopped
|
||||
image: ghcr.io/siderolabs/discovery-service:v1.1.0
|
||||
image: ghcr.io/siderolabs/discovery-service:v1.0.17
|
||||
ports:
|
||||
- 10.105.6.215:3000:3000
|
||||
- 10.105.6.215:3001:3001
|
||||
@@ -5,7 +5,7 @@ services:
|
||||
command: tunnel run weyma-vault
|
||||
env_file: ".env"
|
||||
vault:
|
||||
image: hashicorp/vault:2.1
|
||||
image: hashicorp/vault:2.0
|
||||
env_file: ".env.vault"
|
||||
environment:
|
||||
VAULT_ADDR: "https://weyma-vault.infra.dubyatp.xyz:8200"
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
kind: Cluster
|
||||
name: weyma-talos
|
||||
kubernetes:
|
||||
version: v1.36.4
|
||||
version: v1.34.2
|
||||
talos:
|
||||
version: v1.13.9
|
||||
version: v1.11.5
|
||||
features:
|
||||
backupConfiguration:
|
||||
interval: 6h0m0s
|
||||
@@ -332,7 +332,7 @@ kind: ControlPlane
|
||||
machines:
|
||||
- 20b4c826-e699-43b3-826d-73eb5173680b
|
||||
- 5fdea709-56ad-45f2-966d-5e344dbe4fdf
|
||||
- 30303031-3030-3030-6335-303731636600
|
||||
- 30303031-3030-3030-6335-303731636665
|
||||
---
|
||||
kind: Workers
|
||||
machines:
|
||||
@@ -427,9 +427,9 @@ patches:
|
||||
interface: br0
|
||||
---
|
||||
kind: Machine
|
||||
name: 30303031-3030-3030-6335-303731636600
|
||||
name: 30303031-3030-3030-6335-303731636665
|
||||
patches:
|
||||
- idOverride: 400-cm-30303031-3030-3030-6335-303731636600
|
||||
- idOverride: 400-cm-30303031-3030-3030-6335-303731636665
|
||||
inline:
|
||||
machine:
|
||||
network:
|
||||
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: argo-cd
|
||||
version: 10.6.0
|
||||
version: 9.5.3
|
||||
repository: https://argoproj.github.io/argo-helm
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: cert-manager
|
||||
version: v1.21.1
|
||||
version: v1.20.2
|
||||
repository: https://charts.jetstack.io
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: argocd
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: argocd
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: attic
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: attic
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: authentik
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: authentik
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: duby-blog
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: duby-blog
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: dubyatp-xyz
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: dubyatp-xyz
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: frenworld-archive
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: frenworld-archive
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-frenworld-archive-io
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: gitea
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: gitea
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: grafana
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: grafana
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: jellyfin
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: jellyfin
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: kite
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: kite
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: lumfao-dubyatp-xyz
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: lumfao-dubyatp-xyz
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: netmaker
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: netmaker
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: nextcloud
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: nextcloud
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: rook-ceph
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: rook-ceph
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: test-dubyatp-xyz
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: default
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: traefik
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: traefik
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: vaultwarden
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: vaultwarden
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: whatismyip
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: whatismyip
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-dubyatp-xyz
|
||||
@@ -1,14 +0,0 @@
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: ReferenceGrant
|
||||
metadata:
|
||||
name: williamtpeebles-com
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
from:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
namespace: williamtpeebles-com
|
||||
to:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: cert-williamtpeebles-com
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: external-secrets
|
||||
version: 2.10.0
|
||||
version: 2.3.0
|
||||
repository: https://charts.external-secrets.io
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: kite
|
||||
version: 0.15.0
|
||||
version: 0.9.0
|
||||
repository: https://zxh326.github.io/kite
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: kubernetes-replicator
|
||||
version: 2.12.4
|
||||
version: 2.12.3
|
||||
repository: https://helm.mittwald.de
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: metallb
|
||||
version: 0.16.1
|
||||
version: 0.15.3
|
||||
repository: https://metallb.github.io/metallb
|
||||
@@ -1,6 +1,4 @@
|
||||
metallb:
|
||||
frrk8s:
|
||||
enabled: false
|
||||
prometheus:
|
||||
rbacPrometheus: false
|
||||
podMonitor:
|
||||
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: kube-prometheus-stack
|
||||
version: 88.6.2
|
||||
version: 83.7.0
|
||||
repository: https://prometheus-community.github.io/helm-charts
|
||||
@@ -21,24 +21,11 @@ spec:
|
||||
# versions running within the cluster. See tags available at https://hub.docker.com/r/ceph/ceph/tags/.
|
||||
# If you want to be more precise, you can always use a timestamp tag such as quay.io/ceph/ceph:v19.2.1-20250202
|
||||
# This tag might not contain a new Ceph version, just security fixes from the underlying operating system, which will reduce vulnerabilities
|
||||
image: quay.io/ceph/ceph:v20.2.4-20260818
|
||||
image: quay.io/ceph/ceph:v20.2.0-20251104
|
||||
# Whether to allow unsupported versions of Ceph. Currently Reef and Squid are supported.
|
||||
# Future versions such as Tentacle (v20) would require this to be set to `true`.
|
||||
# Do not set to true in production.
|
||||
allowUnsupported: false
|
||||
security:
|
||||
cephx:
|
||||
daemon:
|
||||
keyRotationPolicy: KeyGeneration
|
||||
keyGeneration: 2 # must be greater than the current keyGeneration
|
||||
csi:
|
||||
keyRotationPolicy: KeyGeneration
|
||||
keyGeneration: 3 # must be greater than the current keyGeneration
|
||||
keyType: aes # Talos kernel 6.18 / cephcsi v3.17.0 don't support aes256k yet
|
||||
rbdMirrorPeer:
|
||||
keyRotationPolicy: KeyGeneration
|
||||
keyGeneration: 3 # must be greater than the current keyGeneration
|
||||
keyType: aes # Talos kernel 6.18 / cephcsi v3.17.0 don't support aes256k yet
|
||||
# The path on the host where configuration files will be persisted. Must be specified. If there are multiple clusters, the directory must be unique for each cluster.
|
||||
# Important: if you reinstall the cluster, make sure you delete this directory from each host or else the mons will fail to start on the new cluster.
|
||||
# In Minikube, the '/data' directory is configured to persist across reboots. Use "/data/rook" in Minikube environment.
|
||||
@@ -77,7 +64,7 @@ spec:
|
||||
# List of modules to optionally enable or disable.
|
||||
# Note the "dashboard" and "monitoring" modules are already configured by other settings in the cluster CR.
|
||||
- name: rook
|
||||
enabled: false
|
||||
enabled: true
|
||||
# enable the ceph dashboard for viewing cluster status
|
||||
dashboard:
|
||||
enabled: true
|
||||
@@ -371,12 +358,3 @@ spec:
|
||||
disabled: false
|
||||
osd:
|
||||
disabled: false
|
||||
muteHealthWarning: # Remove these after Talos uses 7.0+ kernel
|
||||
AUTH_INSECURE_ROTATING_SERVICE_KEY_TYPE:
|
||||
policy: mute
|
||||
AUTH_INSECURE_CLIENT_KEY_TYPE:
|
||||
policy: mute
|
||||
AUTH_INSECURE_KEYS_ALLOWED:
|
||||
policy: mute
|
||||
AUTH_INSECURE_KEYS_CREATABLE:
|
||||
policy: mute
|
||||
@@ -24,8 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: rook-ceph
|
||||
version: v1.20.6
|
||||
version: v1.19.4
|
||||
repository: https://charts.rook.io/release
|
||||
- name: ceph-csi-drivers
|
||||
version: 1.0.4
|
||||
repository: https://ceph.github.io/ceph-csi-operator
|
||||
@@ -1,12 +1,2 @@
|
||||
monitoring:
|
||||
enabled: true
|
||||
ceph-csi-drivers:
|
||||
drivers:
|
||||
rbd:
|
||||
name: rook-ceph.rbd.csi.ceph.com
|
||||
cephfs:
|
||||
name: rook-ceph.cephfs.csi.ceph.com
|
||||
nvmeof:
|
||||
enabled: false
|
||||
nfs:
|
||||
enabled: false
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: traefik
|
||||
version: 41.4.0
|
||||
version: 39.0.8
|
||||
repository: https://traefik.github.io/charts
|
||||
@@ -37,7 +37,7 @@ traefik:
|
||||
kind: DaemonSet
|
||||
additionalContainers:
|
||||
- name: cloudflared
|
||||
image: cloudflare/cloudflared:2026.8.3
|
||||
image: cloudflare/cloudflared:2026.3.0
|
||||
command:
|
||||
- cloudflared
|
||||
- tunnel
|
||||
@@ -69,12 +69,10 @@ traefik:
|
||||
dashboard:
|
||||
enabled: true
|
||||
providers:
|
||||
kubernetesGateway:
|
||||
enabled: true
|
||||
file:
|
||||
enabled: true
|
||||
watch: true
|
||||
content:
|
||||
content: |
|
||||
http:
|
||||
middlewares:
|
||||
cloudflarewarp:
|
||||
|
||||
@@ -24,5 +24,5 @@ appVersion: "1.0"
|
||||
|
||||
dependencies:
|
||||
- name: velero
|
||||
version: 12.1.0
|
||||
version: 12.0.0
|
||||
repository: https://vmware-tanzu.github.io/helm-charts
|
||||
@@ -59,7 +59,7 @@ velero:
|
||||
insecureSkipTLSVerify: "true"
|
||||
initContainers:
|
||||
- name: velero-plugin-for-aws
|
||||
image: velero/velero-plugin-for-aws:v1.14.2
|
||||
image: velero/velero-plugin-for-aws:v1.14.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
volumeMounts:
|
||||
- mountPath: /target
|
||||
|
||||
Reference in New Issue
Block a user