forust
bc1e69ebe0
feat(tls): internal CA wildcard for *.internal routes
...
ci / lint-prettier (push) Successful in 2s
ci / lint-ruff (push) Successful in 0s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 1s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
Selfsigned root (10y) + internal-ca issuer; per-namespace
internal-wildcard-tls certs referenced by all -local routers.
Root public cert committed for client trust stores.
2026-09-23 14:45:05 +02:00
forust
ef325cd3b1
feat(tls): migrate public ingress TLS from Traefik ACME to cert-manager
...
ci / lint-ruff (push) Successful in 1s
ci / lint-prettier (push) Successful in 3s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
All prod IngressRoutes switch tls.certResolver to tls.secretName
backed by per-router Certificates (HTTP-01, letsencrypt-prod).
adguard-prod reuses the shared adguard-certs secret (also feeds
DoT :853); sync CronJob removed as redundant.
Traefik certificatesResolvers removed: its internal
acme-http@internal router hijacks HTTP-01 for every host while
enabled, blocking external solvers. Dormant files (kener,
downtify) converted for consistency but not applied; n8n
untouched per live-only rule.
2026-09-23 14:12:36 +02:00
forust
c42bf14c9a
fix(adguard): drop retired adguard.forust.xyz from prod route so dns.forust.xyz gets LE cert
...
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 1s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 1s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
adguard.forust.xyz is NXDOMAIN (host retired); the combo SAN cert kept
failing and dns.forust.xyz served TRAEFIK DEFAULT CERT. Scope prod route
to dns.forust.xyz only.
Also commit live traefik-values state (remove letsencrypt-staging
resolver, live since helm rev 33).
2026-09-23 13:42:04 +02:00
forust
c139d700f1
feat(adguard,traefik,cert-manager,reloader): foundation for adguard cert sync
...
- traefik: enable kubernetesIngress provider (needed for cert-manager HTTP-01)
- adguard: add reloader auto annotation for secret-driven restarts
- cert-manager: namespace, helm values (crds), staging+prod ClusterIssuers
- reloader: namespace manifest
2026-09-23 13:19:26 +02:00
forust and Copilot
ed1ddaad5d
feat(crowdsec): restore web traffic protection
...
Protect public Traefik routes with CrowdSec HTTP decisions and restore access logging for web traffic analysis.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-09-12 21:05:12 +02:00
forust
13309b26e0
fix: add checkmk agent entrypoint
...
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 5s
ci / deploy-userbot-panel (push) Has been skipped
ci / lint-prettier (push) Successful in 10s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 7s
ci / build (push) Successful in 2s
update traefik to v3.7.13
2026-09-10 14:52:49 +02:00
forust
861d89d36a
ci(deploy): split runtime by k8s/active marker
...
services marked k8s/active are applied via kubectl; the rest via docker
compose. inactive services with k8s/ keep only routing manifests
(external Services, EndpointSlices, Ingresses) to reach docker backends.
headscale/nextcloud routing moved to k8s/routing/.
validations: compose config --quiet + kubectl apply --dry-run=client.
namespace manifests applied first. pull_policy:build stacks get
build+push before up so the registry image stays fresh.
2026-09-06 20:39:12 +02:00
forust
587611ca88
chore: remove empty middlewares blocks from k8s ingresses
2026-09-02 12:17:04 +02:00
forust
92aa731e44
deleted crowdsec stack from the repo. will figure something else
...
ci / lint-prettier (push) Successful in 18s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 6s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 6s
ci / build (push) Successful in 43s
Signed-off-by: mr-forust <vzlomdsisma@gmail.com >
2026-07-19 23:16:14 +02:00
forust
73a1132beb
Align Traefik Helm log values with chart v41
lint / prettier (push) Successful in 1m59s
lint / ruff (push) Successful in 4s
lint / yamllint (push) Successful in 5s
lint / hadolint (push) Successful in 4s
validate / yaml (push) Successful in 6s
validate / k8s (push) Successful in 3s
2026-06-29 23:02:26 +02:00
forust
a128523c24
Fix CrowdSec middleware references in Traefik ingresses
2026-06-29 22:47:21 +02:00
forust
bacb2f4b9f
fix: correct Traefik rule syntax for local IngressRoutes
...
Move parentheses outside Host() calls so that || and && operators
are properly grouped in Traefik rule expressions.
2026-06-28 11:59:52 +02:00
forust
0803f3efff
chore(k8s): returned to Host || Host standart instead of regexp.
...
Deploy to Server / deploy (push) Has been cancelled
Yaml lint (yamllint)
2026-06-18 21:02:40 +02:00
forust
b9b8474455
feat(k8s): protect all prod routers with crowdsec middleware
2026-06-17 01:50:33 +02:00
forust
76853637bc
feat: traefik prometheus metrics
2026-06-17 01:41:45 +02:00
forust
dac3777fc4
fix: authentik k8s url
2026-06-17 01:41:13 +02:00
forust
85d35f86a7
feat: switch adguard dns to a dedicated metallb IP
2026-06-16 12:36:31 +02:00
forust
4ca3ccdad3
chore(k8s): router rewrite
...
- returned to Host matcher instead of Hostregexp
- switched dockercompose labels to letsencrypt
- renamed DoH route
2026-06-16 12:34:15 +02:00
forust
10e26cda72
feat: crowdsec
...
- moved bouncer tokens to secrets
- experimental host ssh log parsing
- moved crowdsec to it's own directory
2026-06-16 00:23:29 +02:00
forust
2f97821dc6
feat: crowdsec lapi helm
Deploy to Server / deploy (push) Has been cancelled
2026-06-14 23:21:37 +02:00
forust
26d10f4e71
changed traefik bgp ip
Deploy to Server / deploy (push) Has been cancelled
2026-06-11 19:44:07 +02:00
forust
68c5eac164
chore: compact ingress rules with regex
2026-06-11 14:20:03 +02:00
forust
2dce972be2
feat(k8s): traefik metallb and minecraft ports
...
- MetalLB binded on 172.20.10.2
- disabled hostnetwork
- 25565 MC Java
- 19132 UDP MC Bedrock
2026-06-11 03:42:59 +02:00
forust
18d1e21690
fix(k8s): traefik log spam for non-existing local-tls secret, because of namespace isolation
2026-06-10 21:14:10 +02:00
forust
6232b77026
fix: traefik restart policy to fix port issue
2026-06-09 09:02:30 +02:00
forust
17b2dfdc2e
fix: gitea ssh tcp router, dns over tls adguard router
2026-06-08 14:20:28 +02:00
forust
e19660fdf4
feat(k8s): standardize IngressRoutes — LE prod certs, prod→local→dev order, Traefik values fix
2026-06-08 12:27:55 +02:00
forust
36922a177c
feat(k8s): add K8s manifests for all homelab services
...
traefik, gitea, adguard, nextcloud, errorpages, homepages,
uptime-kuma, kener, checkmk, headscale, dockmon, metube,
downtify, portainer, netronome, userbot
Includes Helm values, deployments, services, ingress routes,
configmaps, secrets (placeholders), postgres statefulsets,
kustomize overlays, and Traefik dynamic configuration.
2026-06-08 10:54:03 +02:00