forust
0859479c0f
feat(ingress): replace traefik crowdsec plugin with firewall bouncer
...
ci / lint-compose (push) Successful in 9s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 7s
ci / lint-prettier (push) Successful in 12s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 9s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 5s
renovate-ci / validate-renovate (push) Successful in 7s
ci / build (push) Failing after 14m22s
Move L3 enforcement to the host firewall-bouncer (systemd, nftables): drop the Traefik plugin, its secrets volume and the crowdsec Middleware, remove bouncer refs from all IngressRoutes. Disable the http-generic-bf scenario (403-burst bans hurt legit automation under L3 enforcement). Add a Gateway API PoC for homepages prod and CrowdSec PrometheusRule alerts.
2026-09-30 20:14:25 +02:00
forust
a90fb19ed4
fix(traefik): size probes for HDD stalls
...
ci / lint-compose (push) Successful in 12s
ci / lint-actionlint (push) Successful in 9s
ci / lint-shellcheck (push) Failing after 25s
ci / lint-prettier (push) Successful in 19s
ci / lint-ruff (push) Successful in 9s
ci / lint-yaml (push) Successful in 12s
ci / lint-dockerfiles (push) Successful in 8s
ci / validate (push) Successful in 9s
ci / build (push) Skipped
renovate-ci / validate-renovate (push) Successful in 12s
Single replica is the whole ingress; liveness kills at 2s timeouts took every public service down in a loop. Same stall-sized budgets as postgres/metallb. Applied live via helm (pinned 41.5.0, values from git).
2026-09-29 14:47:53 +02:00
forust
a6af69dca0
fix(k8s): Recreate singletons and trim requests for scheduler headroom
...
ci / lint-actionlint (push) Successful in 1s
ci / lint-shellcheck (push) Successful in 2s
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-compose (push) Successful in 3s
ci / test-backend (push) Successful in 8s
ci / test-frontend (push) Successful in 11s
ci / validate (push) Successful in 3s
renovate-ci / validate-renovate (push) Successful in 13s
ci / lint-dockerfiles (push) Successful in 2s
ci / scan-deps (push) Successful in 18s
ci / build (push) Successful in 1m30s
RollingUpdate with default maxSurge needs a spare pod the single node does not have (99% CPU requested), so multi-workload restarts end Pending and verify times out. Recreate on all replicas:1 Deployments (immich-server and bentopdf keep RollingUpdate at replicas 2). Also trims CPU/memory requests toward measured use (adguard, authentik, gitea, netbox, uptime-kuma, netbird-server) and gives traefik requests/limits so it is no longer BestEffort.
2026-09-28 22:36:46 +02:00
forust
1d81410cd8
fix(traefik): persist plugin storage on a PVC
...
ci / lint-compose (push) Successful in 4s
ci / lint-actionlint (push) Successful in 3s
ci / lint-shellcheck (push) Successful in 4s
ci / lint-prettier (push) Successful in 5s
ci / lint-ruff (push) Successful in 3s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 3s
ci / scan-deps (push) Successful in 18s
ci / test-backend (push) Successful in 8s
ci / test-frontend (push) Successful in 11s
ci / validate (push) Successful in 4s
renovate-ci / validate-renovate (push) Successful in 1m28s
ci / build (push) Successful in 37s
Mount traefik-plugins PVC at /plugins-storage instead of the chart default emptyDir, so the crowdsec-bouncer download survives node reboots. Without this Traefik starts before the network is ready, the download from plugins.traefik.io times out, plugins get disabled and every route behind the middleware returns 404/503 until a manual restart.
2026-09-28 13:36:46 +02:00
forust
a4a4bb4cc5
feat(netbird): add tailscale-alternative
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
deploy / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-prettier (pull_request) Successful in 3s
ci / lint-ruff (pull_request) Successful in 1s
ci / lint-yaml (pull_request) Successful in 5s
ci / lint-dockerfiles (pull_request) Successful in 1s
ci / validate (pull_request) Successful in 1s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 10s
2026-09-25 20:26:11 +02:00
forust
bc1e69ebe0
feat(tls): internal CA wildcard for *.internal routes
...
ci / lint-prettier (push) Successful in 2s
ci / lint-ruff (push) Successful in 0s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 1s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
Selfsigned root (10y) + internal-ca issuer; per-namespace
internal-wildcard-tls certs referenced by all -local routers.
Root public cert committed for client trust stores.
2026-09-23 14:45:05 +02:00
forust
ef325cd3b1
feat(tls): migrate public ingress TLS from Traefik ACME to cert-manager
...
ci / lint-ruff (push) Successful in 1s
ci / lint-prettier (push) Successful in 3s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
All prod IngressRoutes switch tls.certResolver to tls.secretName
backed by per-router Certificates (HTTP-01, letsencrypt-prod).
adguard-prod reuses the shared adguard-certs secret (also feeds
DoT :853); sync CronJob removed as redundant.
Traefik certificatesResolvers removed: its internal
acme-http@internal router hijacks HTTP-01 for every host while
enabled, blocking external solvers. Dormant files (kener,
downtify) converted for consistency but not applied; n8n
untouched per live-only rule.
2026-09-23 14:12:36 +02:00
forust
c42bf14c9a
fix(adguard): drop retired adguard.forust.xyz from prod route so dns.forust.xyz gets LE cert
...
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 1s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 1s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
adguard.forust.xyz is NXDOMAIN (host retired); the combo SAN cert kept
failing and dns.forust.xyz served TRAEFIK DEFAULT CERT. Scope prod route
to dns.forust.xyz only.
Also commit live traefik-values state (remove letsencrypt-staging
resolver, live since helm rev 33).
2026-09-23 13:42:04 +02:00
forust
c139d700f1
feat(adguard,traefik,cert-manager,reloader): foundation for adguard cert sync
...
- traefik: enable kubernetesIngress provider (needed for cert-manager HTTP-01)
- adguard: add reloader auto annotation for secret-driven restarts
- cert-manager: namespace, helm values (crds), staging+prod ClusterIssuers
- reloader: namespace manifest
2026-09-23 13:19:26 +02:00
forust and Copilot
23ed72826a
chore(images): pin service image updates
...
Replace floating service images with reviewable tags or digests.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-09-14 09:16:01 +02:00
forust and Copilot
ed1ddaad5d
feat(crowdsec): restore web traffic protection
...
Protect public Traefik routes with CrowdSec HTTP decisions and restore access logging for web traffic analysis.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-09-12 21:05:12 +02:00
forust
13309b26e0
fix: add checkmk agent entrypoint
...
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 5s
ci / deploy-userbot-panel (push) Has been skipped
ci / lint-prettier (push) Successful in 10s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 7s
ci / build (push) Successful in 2s
update traefik to v3.7.13
2026-09-10 14:52:49 +02:00
forust
861d89d36a
ci(deploy): split runtime by k8s/active marker
...
services marked k8s/active are applied via kubectl; the rest via docker
compose. inactive services with k8s/ keep only routing manifests
(external Services, EndpointSlices, Ingresses) to reach docker backends.
headscale/nextcloud routing moved to k8s/routing/.
validations: compose config --quiet + kubectl apply --dry-run=client.
namespace manifests applied first. pull_policy:build stacks get
build+push before up so the registry image stays fresh.
2026-09-06 20:39:12 +02:00
forust
587611ca88
chore: remove empty middlewares blocks from k8s ingresses
2026-09-02 12:17:04 +02:00
forust
92aa731e44
deleted crowdsec stack from the repo. will figure something else
...
ci / lint-prettier (push) Successful in 18s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 6s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 6s
ci / build (push) Successful in 43s
Signed-off-by: mr-forust <vzlomdsisma@gmail.com >
2026-07-19 23:16:14 +02:00
forust
73a1132beb
Align Traefik Helm log values with chart v41
lint / prettier (push) Successful in 1m59s
lint / ruff (push) Successful in 4s
lint / yamllint (push) Successful in 5s
lint / hadolint (push) Successful in 4s
validate / yaml (push) Successful in 6s
validate / k8s (push) Successful in 3s
2026-06-29 23:02:26 +02:00
forust
a128523c24
Fix CrowdSec middleware references in Traefik ingresses
2026-06-29 22:47:21 +02:00
forust
bacb2f4b9f
fix: correct Traefik rule syntax for local IngressRoutes
...
Move parentheses outside Host() calls so that || and && operators
are properly grouped in Traefik rule expressions.
2026-06-28 11:59:52 +02:00
forust
d53b14b1de
chore: apply yaml lint fixes across compose files
...
- Fix trailing whitespace in compose files
- Add missing final newlines (EOF)
- Fix indentation in dockmon (3-space -> 2-space) and glance monitor.yml
- Align comments consistently
2026-06-19 11:57:14 +02:00
forust
0803f3efff
chore(k8s): returned to Host || Host standart instead of regexp.
...
Deploy to Server / deploy (push) Has been cancelled
Yaml lint (yamllint)
2026-06-18 21:02:40 +02:00
forust
b9b8474455
feat(k8s): protect all prod routers with crowdsec middleware
2026-06-17 01:50:33 +02:00
forust
76853637bc
feat: traefik prometheus metrics
2026-06-17 01:41:45 +02:00
forust
dac3777fc4
fix: authentik k8s url
2026-06-17 01:41:13 +02:00
forust
85d35f86a7
feat: switch adguard dns to a dedicated metallb IP
2026-06-16 12:36:31 +02:00
forust
4ca3ccdad3
chore(k8s): router rewrite
...
- returned to Host matcher instead of Hostregexp
- switched dockercompose labels to letsencrypt
- renamed DoH route
2026-06-16 12:34:15 +02:00
forust
10e26cda72
feat: crowdsec
...
- moved bouncer tokens to secrets
- experimental host ssh log parsing
- moved crowdsec to it's own directory
2026-06-16 00:23:29 +02:00
forust
2f97821dc6
feat: crowdsec lapi helm
Deploy to Server / deploy (push) Has been cancelled
2026-06-14 23:21:37 +02:00
forust
26d10f4e71
changed traefik bgp ip
Deploy to Server / deploy (push) Has been cancelled
2026-06-11 19:44:07 +02:00
forust
68c5eac164
chore: compact ingress rules with regex
2026-06-11 14:20:03 +02:00
forust
2dce972be2
feat(k8s): traefik metallb and minecraft ports
...
- MetalLB binded on 172.20.10.2
- disabled hostnetwork
- 25565 MC Java
- 19132 UDP MC Bedrock
2026-06-11 03:42:59 +02:00
forust
18d1e21690
fix(k8s): traefik log spam for non-existing local-tls secret, because of namespace isolation
2026-06-10 21:14:10 +02:00
forust
6232b77026
fix: traefik restart policy to fix port issue
2026-06-09 09:02:30 +02:00
forust
17b2dfdc2e
fix: gitea ssh tcp router, dns over tls adguard router
2026-06-08 14:20:28 +02:00
forust
e19660fdf4
feat(k8s): standardize IngressRoutes — LE prod certs, prod→local→dev order, Traefik values fix
2026-06-08 12:27:55 +02:00
forust
36922a177c
feat(k8s): add K8s manifests for all homelab services
...
traefik, gitea, adguard, nextcloud, errorpages, homepages,
uptime-kuma, kener, checkmk, headscale, dockmon, metube,
downtify, portainer, netronome, userbot
Includes Helm values, deployments, services, ingress routes,
configmaps, secrets (placeholders), postgres statefulsets,
kustomize overlays, and Traefik dynamic configuration.
2026-06-08 10:54:03 +02:00
forust
e5797e60b7
upd: traefik v3.7.2
Deploy to Server / deploy (push) Has been cancelled
2026-06-07 20:36:51 +02:00
forust
b8d5bc747d
hack: commented out local certs until i figure out how to route certs for local routers
2026-06-07 13:38:14 +02:00
forust
6dac841b2c
updated traefik to v3.7,
...
Deploy to Server / deploy (push) Has been cancelled
resolved maxResponseBodySize not set
2026-05-25 01:47:59 +02:00
forust
8362f45bdc
upd: updated image tags for services:
...
- gitea 1.25.1 --> 1.26
- portainer-ce latest --> 2.41.0
- traefik latest --> 3.6.15
2026-05-08 16:37:26 +02:00
forust
a22707770f
feat: update certificates logic:
...
Deploy to Server / deploy (push) Failing after 1s
- Switched xdfnx's homepage certificates to traefik-managed mode
- Renamed local fallback certs
2026-02-25 21:12:44 +01:00
forust
578a1ca544
revert: naio needs insecure transport
...
2593b54402 chore: add backquotes for downtify traefik labels removed insecureTransport
2026-02-20 01:25:23 +01:00
forust
2593b54402
chore: add backquotes for downtify traefik labels
...
removed insecureTransport
2026-02-05 01:33:04 +01:00
forust
d7a68237e5
chore: remove redundant or unnececary traefik labels
...
- traefik.docker.network= (defined by traefik cli)
- traefik.http.routers.<routername>.middlewares=security-headers@file" (applied globally by traefik cli)
2026-02-04 22:26:27 +01:00
forust
3dbb50c924
json logging
2026-01-29 17:30:09 +01:00
forust
b7ecf88052
fix: correct metube local router rule and fix TLS configuration comments
2026-01-23 17:54:00 +01:00
forust
5068591b8b
fix: xdfnx's certificate
2026-01-23 17:48:00 +01:00
forust
c6d00e525b
fix: comment-out CF Origin CA. (google trust service)
2026-01-22 00:51:15 +01:00
forust
95f0afbbee
feat: add traefik integration for error-handler
...
TODO: fix css
2026-01-21 20:14:02 +01:00
forust
45ce789f58
chore: compose cleanup:
...
- Remove TZ envs
- +- unified compose structure
- Minify where possible
- Remove <service>.internal routers
- Remove service specifications where possible
Affected services:
- adguardhome
- authentik
- cfddns
- checkmk
- dockmon
- downtify
- gitea
- glance
- headscale
- homepages
- metube
- nextcloud
- penpot
- portainer
- termix
- traefik
- uptime-kuma
TODO: Move data from directory to volumes
2026-01-19 23:33:50 +01:00
forust
5fe8af82d5
Revert "fix: clean up traefik configuration and add redirect middleware"
...
This reverts commit dc7fe64fbc .
2026-01-19 11:18:36 +01:00