Compare commits

..
Author SHA1 Message Date
forust 94ff1d12e3 fix(edu-master): bound session refreshes and expire stale cookies
renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 14s
ci / lint-actionlint (push) Successful in 8s
ci / lint-shellcheck (push) Successful in 9s
ci / lint-prettier (push) Successful in 18s
ci / lint-ruff (push) Successful in 10s
ci / lint-yaml (push) Successful in 13s
ci / lint-dockerfiles (push) Successful in 6s
ci / validate (push) Successful in 6s
ci / build (push) Skipped
ci / lint-compose (pull_request) Successful in 9s
ci / lint-actionlint (pull_request) Successful in 4s
ci / lint-shellcheck (pull_request) Successful in 7s
ci / lint-prettier (pull_request) Successful in 16s
ci / lint-ruff (pull_request) Successful in 9s
ci / lint-yaml (pull_request) Successful in 10s
ci / lint-dockerfiles (pull_request) Successful in 4s
ci / validate (pull_request) Successful in 6s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 8s
2026-10-06 15:58:44 +02:00
forust cc9c3dea88 feat(traefik): expose insecure API on 8080 for Homarr integration
ci / lint-compose (push) Successful in 10s
ci / lint-actionlint (push) Successful in 8s
ci / lint-shellcheck (push) Successful in 8s
ci / lint-prettier (push) Successful in 16s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 9s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 7s
renovate-ci / validate-renovate (push) Successful in 9s
ci / build (push) Successful in 38s
ClusterIP access to api@internal from Homarr pod. LAN-reachable on 192.168.80.2:8080, accepted.
2026-10-06 11:27:38 +02:00
forust 815cd85b9a feat(homarr): deploy dashboard to k8s on home subdomain
Local-only IngressRoute (home.workstation.internal, home.gigaforust.internal), prod commented out. Compose stack for test stand.
2026-10-06 11:27:35 +02:00
forust 9021eddbc3 chore(deps): pin streaming images, isolate python and floating tags
ci / lint-compose (push) Successful in 8s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 8s
ci / lint-prettier (push) Successful in 13s
ci / lint-ruff (push) Successful in 7s
ci / lint-yaml (push) Successful in 9s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 7s
renovate-ci / validate-renovate (push) Successful in 9s
ci / build (push) Successful in 19s
Python Y-bumps arrived as minor 3.11->3.14 and floating tags (:latest/:beta) were automerged blindly. Pin the linuxserver stack to digest-verified tags and keep python plus rolling images in manual review groups.
2026-10-05 23:53:38 +02:00
forust 2adf17c307 Merge pull request 'chore(deps): update all patch updates' (#76) from renovate/all-patch into main
ci / lint-compose (push) Successful in 8s
ci / lint-actionlint (push) Successful in 5s
ci / lint-shellcheck (push) Successful in 8s
ci / lint-prettier (push) Successful in 12s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 9s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 6s
renovate-ci / validate-renovate (push) Successful in 9s
ci / build (push) Successful in 17s
Reviewed-on: #76
2026-10-05 21:41:00 +00:00
renovate-bot 1add5b5cd7 chore(deps): update all patch updates 2026-10-05 21:41:00 +00:00
forust 34f10211ab Merge pull request 'chore(deps): update renovate/renovate docker tag to v44.136.0' (#79) from renovate/renovate-self-update into main
ci / lint-compose (push) Successful in 9s
ci / lint-actionlint (push) Successful in 5s
ci / lint-shellcheck (push) Successful in 7s
ci / lint-prettier (push) Successful in 13s
ci / lint-yaml (push) Successful in 10s
ci / validate (push) Successful in 7s
renovate-ci / validate-renovate (push) Successful in 9s
ci / lint-ruff (push) Successful in 6s
ci / lint-dockerfiles (push) Successful in 5s
ci / build (push) Successful in 18s
Reviewed-on: #79
2026-10-05 21:39:21 +00:00
renovate-bot 02447f2946 chore(deps): update renovate/renovate docker tag to v44.136.0
renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 11s
ci / lint-actionlint (push) Successful in 5s
ci / lint-shellcheck (push) Successful in 7s
ci / lint-ruff (push) Successful in 5s
ci / validate (push) Successful in 9s
ci / lint-prettier (push) Successful in 13s
ci / lint-yaml (push) Successful in 10s
ci / lint-dockerfiles (push) Successful in 5s
ci / build (push) Skipped
ci / lint-compose (pull_request) Successful in 8s
ci / lint-actionlint (pull_request) Successful in 6s
ci / lint-shellcheck (pull_request) Successful in 12s
ci / lint-prettier (pull_request) Successful in 14s
ci / lint-ruff (pull_request) Successful in 6s
ci / lint-yaml (pull_request) Successful in 9s
ci / lint-dockerfiles (pull_request) Successful in 5s
ci / validate (pull_request) Successful in 6s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 1m18s
2026-10-05 16:19:11 +00:00
forust 8799962b1c Revert "feat(adguard): add netbird sidecar"
ci / lint-dockerfiles (push) Successful in 5s
renovate-ci / validate-renovate (push) Successful in 9s
ci / lint-compose (push) Successful in 10s
ci / lint-actionlint (push) Successful in 5s
ci / lint-shellcheck (push) Successful in 8s
ci / lint-prettier (push) Successful in 15s
ci / lint-ruff (push) Successful in 7s
ci / lint-yaml (push) Successful in 10s
ci / validate (push) Successful in 6s
ci / build (push) Successful in 20s
This reverts commit 7a81b4ea8b.
2026-10-04 17:40:19 +02:00
forust fb80024fa2 feat(streaming): add bazarr for subtitles
renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 9s
ci / lint-actionlint (push) Successful in 5s
ci / lint-shellcheck (push) Successful in 7s
ci / lint-prettier (push) Successful in 15s
ci / lint-ruff (push) Successful in 7s
ci / validate (push) Successful in 6s
ci / build (push) Skipped
ci / lint-yaml (push) Successful in 11s
ci / lint-dockerfiles (push) Successful in 6s
2026-10-04 17:25:00 +02:00
forust 0f1a788874 Merge pull request 'feat(streaming): compose *arr streaming stack (k8s routing)' (#78) from feat/streaming-compose-test into main
ci / lint-compose (push) Successful in 8s
ci / lint-prettier (push) Successful in 14s
ci / lint-ruff (push) Successful in 6s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 8s
ci / lint-yaml (push) Successful in 9s
ci / lint-dockerfiles (push) Successful in 6s
ci / validate (push) Successful in 6s
renovate-ci / validate-renovate (push) Successful in 10s
ci / build (push) Successful in 54s
Reviewed-on: #78
2026-10-04 14:04:28 +00:00
forust 39df442e60 fix(streaming): trailing newline for yamllint
renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 8s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 6s
ci / lint-ruff (push) Successful in 6s
ci / lint-prettier (push) Successful in 15s
ci / lint-yaml (push) Successful in 10s
ci / lint-dockerfiles (push) Successful in 6s
ci / validate (push) Successful in 6s
ci / build (push) Skipped
ci / lint-compose (pull_request) Successful in 10s
ci / lint-actionlint (pull_request) Successful in 5s
ci / lint-shellcheck (pull_request) Successful in 8s
ci / lint-prettier (pull_request) Successful in 14s
ci / lint-ruff (pull_request) Successful in 5s
ci / lint-yaml (pull_request) Successful in 8s
ci / lint-dockerfiles (pull_request) Successful in 5s
ci / validate (pull_request) Successful in 6s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 8s
2026-10-04 16:03:40 +02:00
forust 62a451773e feat(streaming): compose *arr streaming stack (k8s routing)
renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 10s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 7s
ci / lint-prettier (push) Failing after 15s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Failing after 9s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 6s
ci / build (push) Skipped
ci / lint-compose (pull_request) Successful in 8s
ci / lint-actionlint (pull_request) Successful in 4s
ci / lint-prettier (pull_request) Failing after 14s
ci / lint-ruff (pull_request) Successful in 5s
ci / lint-yaml (pull_request) Failing after 11s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 9s
ci / lint-shellcheck (pull_request) Successful in 7s
ci / lint-dockerfiles (pull_request) Successful in 5s
ci / validate (pull_request) Successful in 7s
2026-10-04 15:57:08 +02:00
forust f196099491 feat(adguard): add DNS readiness probe
ci / lint-compose (push) Successful in 8s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 8s
ci / lint-prettier (push) Successful in 15s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 10s
ci / lint-dockerfiles (push) Successful in 6s
ci / validate (push) Successful in 6s
renovate-ci / validate-renovate (push) Successful in 9s
ci / build (push) Successful in 33s
2026-10-03 22:39:25 +02:00
forust 66502b8279 fix(traefik): protect dashboard with security-chain 2026-10-03 22:39:25 +02:00
forust 9018c091fa feat(uptime-kuma): add ServiceMonitor, alerts and secrets example 2026-10-03 22:39:24 +02:00
forust 114608af2f fix(uptime-kuma): label service and name http port 2026-10-03 22:39:23 +02:00
forust 51a73fb213 chore(gitea): switch domain to git.forust.xyz (28.0.0 update) 2026-10-03 22:37:48 +02:00
44 changed files with 1076 additions and 115 deletions

No files matched your search

+1
View File
@@ -141,6 +141,7 @@ jobs:
export PATH="$tools_dir:$PATH" export PATH="$tools_dir:$PATH"
ruff check . ruff check .
ruff format --check . ruff format --check .
python3 -m unittest discover -s tests -v
lint-yaml: lint-yaml:
runs-on: [self-hosted, linux, arch, homelab] runs-on: [self-hosted, linux, arch, homelab]
+1 -1
View File
@@ -81,7 +81,7 @@ jobs:
docker run --rm \ docker run --rm \
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \ -v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
-e RENOVATE_PLATFORM=gitea \ -e RENOVATE_PLATFORM=gitea \
-e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \ -e RENOVATE_ENDPOINT=https://git.forust.xyz/api/v1 \
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \ -e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \ -e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \ -e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
+7 -35
View File
@@ -68,35 +68,6 @@ spec:
reloader.stakater.com/auto: "true" reloader.stakater.com/auto: "true"
spec: spec:
containers: containers:
- name: netbird
image: netbirdio/netbird:0.80.0
envFrom:
- configMapRef:
name: adguard-config
env:
- name: NB_SETUP_KEY
valueFrom:
secretKeyRef:
name: adguard-netbird-secrets
key: NB_SETUP_KEY
securityContext:
capabilities:
add:
- NET_ADMIN
- SYS_ADMIN
- SYS_RESOURCE
resources:
requests:
memory: "64Mi"
cpu: "50m"
limits:
memory: "256Mi"
cpu: "200m"
volumeMounts:
- name: netbird-state
mountPath: /var/lib/netbird
- name: dev-tun
mountPath: /dev/net/tun
- name: adguard - name: adguard
image: adguard/adguardhome:v0.107.79 image: adguard/adguardhome:v0.107.79
resources: resources:
@@ -113,6 +84,13 @@ spec:
name: dns name: dns
- containerPort: 853 - containerPort: 853
name: dot name: dot
readinessProbe:
tcpSocket:
port: dns
initialDelaySeconds: 5
periodSeconds: 5
successThreshold: 1
failureThreshold: 3
volumeMounts: volumeMounts:
- name: adguard-data - name: adguard-data
mountPath: /opt/adguardhome/work mountPath: /opt/adguardhome/work
@@ -124,12 +102,6 @@ spec:
mountPath: /certs mountPath: /certs
readOnly: true readOnly: true
volumes: volumes:
- name: netbird-state
emptyDir: {}
- name: dev-tun
hostPath:
path: /dev/net/tun
type: CharDevice
- name: adguard-data - name: adguard-data
persistentVolumeClaim: persistentVolumeClaim:
claimName: adguard-pvc claimName: adguard-pvc
-10
View File
@@ -1,10 +0,0 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: adguard-config
namespace: adguard
data:
NB_MANAGEMENT_URL: "https://nb.forust.xyz"
NB_HOSTNAME: "adguard"
NB_LOG_LEVEL: "info"
NB_DISABLE_DNS: "true"
@@ -1,8 +0,0 @@
apiVersion: v1
kind: Secret
metadata:
name: adguard-netbird-secrets
namespace: adguard
type: Opaque
stringData:
NB_SETUP_KEY: "REPLACE_ME"
+7 -6
View File
@@ -1,10 +1,11 @@
EDU_LOGIN=your_edu_login_here KEEPER_LOGIN=your_edu_login_here
EDU_PASSWORD=your_edu_password_here KEEPER_PASSWORD=your_edu_password_here
EDU_URL_LOGIN=https://edu.edu.vn.ua/user/login EDU_URL_BASE=https://edu.edu.vn.ua
EDU_URL_VERIFY=https://edu.edu.vn.ua/course/userlist EDU_URL_LOGIN=/user/login
PHPSESSID_INTERVAL=10 EDU_URL_COURSES=/course/userlist
KEEPER_INTERVAL=10
USER_AGENT="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36" USER_AGENT="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36"
WEBINAR_URL=https://edu.edu.vn.ua/webinar/useractive EDU_URL_WEBINAR=/webinar/useractive
WEBINAR_CHECK_INTERVAL=60 WEBINAR_CHECK_INTERVAL=60
REDIS_HOST=redis REDIS_HOST=redis
REDIS_PORT=6379 REDIS_PORT=6379
+29 -40
View File
@@ -48,17 +48,43 @@ def touch_success_file():
logger.error(f'Failed to touch success file: {e}') logger.error(f'Failed to touch success file: {e}')
def refresh_session(session, redis_client):
"""Publish a verified cookie with a lifetime tied to the refresh interval."""
login_response = session.post(
URL_LOGIN, data={'login': LOGIN, 'password': PASSWORD}, allow_redirects=True, timeout=(10, 30)
)
login_response.raise_for_status()
verify_response = session.get(URL_VERIFY, allow_redirects=False, timeout=(10, 30))
if verify_response.status_code != 200:
logger.warning('Session verification failed (HTTP %s)', verify_response.status_code)
return False
phpsessid = session.cookies.get('PHPSESSID')
if not phpsessid:
logger.warning('Verified response did not provide a PHPSESSID cookie')
return False
redis_client.set('EDU_PHPSESSID', phpsessid, ex=INTERVAL * 120)
touch_success_file()
logger.info('Verified session saved to Redis')
return True
def main(): def main():
if not LOGIN or not PASSWORD:
raise ValueError('KEEPER_LOGIN and KEEPER_PASSWORD must be set')
if INTERVAL <= 0:
raise ValueError('KEEPER_INTERVAL must be a positive number of minutes')
logger.info('Starting Session Keeper Bot') logger.info('Starting Session Keeper Bot')
# Connect to Redis # Connect to Redis
try: try:
redis_client = redis.Redis(host=REDIS_HOST, port=REDIS_PORT, decode_responses=True) redis_client = redis.Redis(
host=REDIS_HOST, port=REDIS_PORT, decode_responses=True, socket_connect_timeout=5, socket_timeout=5
)
redis_client.ping() redis_client.ping()
logger.info(f'Connected to Redis at {REDIS_HOST}:{REDIS_PORT}') logger.info(f'Connected to Redis at {REDIS_HOST}:{REDIS_PORT}')
except Exception as e: except Exception as e:
logger.error(f'Failed to connect to Redis: {e}') logger.error(f'Failed to connect to Redis: {e}')
return raise
session = requests.Session() session = requests.Session()
@@ -83,44 +109,7 @@ def main():
while True: while True:
try: try:
logger.info('Attempting login...') refresh_session(session, redis_client)
# Login payload
payload = {'login': LOGIN, 'password': PASSWORD}
# Perform Login
# Note: The user request shows a POST to /user/login with form data
# We need to make sure we handle the PHPSESSID correctly.
# If we already have a PHPSESSID, requests will send it.
login_response = session.post(URL_LOGIN, data=payload, allow_redirects=True)
logger.info(f'Login Response Status: {login_response.status_code}')
logger.info(f'Cookies after login: {session.cookies.get_dict()}')
# Verify Session
logger.info('Verifying session...')
verify_response = session.get(URL_VERIFY, allow_redirects=False)
logger.info(f'Verify Response Status: {verify_response.status_code}')
if verify_response.status_code == 200:
logger.info('Session verification SUCCESS (200 OK).')
touch_success_file()
# Save PHPSESSID to Redis
phpsessid = session.cookies.get('PHPSESSID')
if phpsessid:
try:
redis_client.set('EDU_PHPSESSID', phpsessid)
logger.info(f'Saved PHPSESSID to Redis: {phpsessid}')
except Exception as e:
logger.error(f'Failed to save PHPSESSID to Redis: {e}')
elif verify_response.status_code == 302:
logger.warning('Session verification FAILED (302 Redirect). Session might be invalid.')
else:
logger.warning(f'Session verification returned unexpected status: {verify_response.status_code}')
except Exception as e: except Exception as e:
logger.error(f'An error occurred: {e}') logger.error(f'An error occurred: {e}')
+5 -2
View File
@@ -13,9 +13,12 @@ services:
- GITEA__database__PASSWD=gitea - GITEA__database__PASSWD=gitea
- GITEA__database__NAME=gitea - GITEA__database__NAME=gitea
# Server # Server
- GITEA__server__ROOT_URL=https://gitea.forust.xyz - GITEA__server__ROOT_URL=https://git.forust.xyz
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz - GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
- GITEA__server__SSH_PORT=2221 - GITEA__server__SSH_PORT=2221
# Pin 28.0 defaults explicitly (see k8s/config.yaml for rationale)
- GITEA__service__DISABLE_REGISTRATION=true
- GITEA__actions__RUN_RETENTION_DAYS=90
# Mailer # Mailer
- GITEA__mailer__ENABLED=true - GITEA__mailer__ENABLED=true
- GITEA__mailer__FROM=${SERVICE_EMAIL} - GITEA__mailer__FROM=${SERVICE_EMAIL}
@@ -34,7 +37,7 @@ services:
- "traefik.http.services.gitea.loadbalancer.server.port=3000" - "traefik.http.services.gitea.loadbalancer.server.port=3000"
# Prod Router # Prod Router
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)" - "traefik.http.routers.gitea.rule=Host(`git.forust.xyz`) || Host(`gitea.forust.xyz`)"
- "traefik.http.routers.gitea.entrypoints=websecure" - "traefik.http.routers.gitea.entrypoints=websecure"
- "traefik.http.routers.gitea.tls.certresolver" - "traefik.http.routers.gitea.tls.certresolver"
# Local Router # Local Router
+5 -2
View File
@@ -4,11 +4,14 @@ metadata:
name: gitea-config name: gitea-config
namespace: gitea namespace: gitea
data: data:
GITEA__server__DOMAIN: "gitea.forust.xyz" GITEA__server__ROOT_URL: "https://git.forust.xyz"
GITEA__server__ROOT_URL: "https://gitea.forust.xyz"
GITEA__server__SSH_DOMAIN: "gitssh.forust.xyz" GITEA__server__SSH_DOMAIN: "gitssh.forust.xyz"
GITEA__server__SSH_PORT: "2221" GITEA__server__SSH_PORT: "2221"
GITEA__service__DISABLE_REGISTRATION: "true"
GITEA__actions__RUN_RETENTION_DAYS: "90"
GITEA__database__DB_TYPE: "postgres" GITEA__database__DB_TYPE: "postgres"
GITEA__database__HOST: "postgres.database.svc.cluster.local:5432" GITEA__database__HOST: "postgres.database.svc.cluster.local:5432"
GITEA__database__NAME: "gitea" GITEA__database__NAME: "gitea"
+2 -2
View File
@@ -177,8 +177,8 @@ data:
# url: https://gitssh.forust.xyz # url: https://gitssh.forust.xyz
# - title: gcr.forust.xyz # - title: gcr.forust.xyz
# url: https://gcr.forust.xyz/v2/ # url: https://gcr.forust.xyz/v2/
- title: gitea.forust.xyz - title: git.forust.xyz
url: https://gitea.forust.xyz url: https://git.forust.xyz
- title: nextcloud.forust.xyz - title: nextcloud.forust.xyz
url: https://nextcloud.forust.xyz url: https://nextcloud.forust.xyz
- title: mc.forust.xyz - title: mc.forust.xyz
+4
View File
@@ -0,0 +1,4 @@
SECRET_ENCRYPTION_KEY="REPLACE_ME"
TZ="Europe/Bratislava"
PUID="1000"
PGID="1000"
+38
View File
@@ -0,0 +1,38 @@
services:
homarr:
container_name: homarr
image: ghcr.io/homarr-labs/homarr:v2.1.2
restart: unless-stopped
volumes:
- ./appdata:/appdata
- /var/run/docker.sock:/var/run/docker.sock:ro
- ./kubeconfig:/app/config/kubeconfig:ro
env_file: .env
ports:
- 80:7575
- 81:3000
environment:
- TZ=${TZ:-Europe/Bratislava}
- TURBO_TELEMETRY_DISABLED=1
- KUBECONFIG=/app/config/kubeconfig
labels:
- "traefik.enable=true"
- "traefik.http.services.homarr.loadbalancer.server.port=7575"
# Prod Router
- "traefik.http.routers.homarr.rule=Host(`homarr.forust.xyz`)"
- "traefik.http.routers.homarr.entrypoints=websecure"
- "traefik.http.routers.homarr.tls.certresolver=letsencrypt"
# Local Router
- "traefik.http.routers.homarr-local.rule=Host(`homarr.workstation.internal`)"
- "traefik.http.routers.homarr-local.entrypoints=websecure"
- "traefik.http.routers.homarr-local.tls=true"
# Dev Router
- "traefik.http.routers.homarr-dev.rule=Host(`homarr.gigaforust.internal`)"
- "traefik.http.routers.homarr-dev.entrypoints=websecure"
- "traefik.http.routers.homarr-dev.tls=true"
networks:
- proxy
networks:
proxy:
external: true
+28
View File
@@ -0,0 +1,28 @@
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: home-prod-tls
# namespace: homarr
# spec:
# secretName: home-prod-tls
# dnsNames:
# - home.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
# ---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: internal-wildcard-tls
namespace: homarr
spec:
secretName: internal-wildcard-tls
dnsNames:
- "*.workstation.internal"
- "*.gigaforust.internal"
- workstation.internal
- gigaforust.internal
issuerRef:
name: internal-ca
kind: ClusterIssuer
+9
View File
@@ -0,0 +1,9 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: homarr-config
namespace: homarr
data:
TZ: "Europe/Bratislava"
TURBO_TELEMETRY_DISABLED: "1"
ENABLE_KUBERNETES: "true"
+81
View File
@@ -0,0 +1,81 @@
apiVersion: v1
kind: Service
metadata:
name: homarr-service
namespace: homarr
spec:
selector:
app: homarr
ports:
- port: 7575
targetPort: 7575
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: homarr-deployment
namespace: homarr
spec:
replicas: 1
selector:
matchLabels:
app: homarr
strategy:
type: Recreate
template:
metadata:
labels:
app: homarr
spec:
serviceAccountName: homarr
containers:
- name: homarr
image: ghcr.io/homarr-labs/homarr:v2.1.2
envFrom:
- configMapRef:
name: homarr-config
- secretRef:
name: homarr-secrets
ports:
- containerPort: 7575
readinessProbe:
httpGet:
path: /
port: 7575
initialDelaySeconds: 30
periodSeconds: 10
failureThreshold: 6
livenessProbe:
httpGet:
path: /
port: 7575
initialDelaySeconds: 60
periodSeconds: 30
failureThreshold: 3
volumeMounts:
- name: homarr-data
mountPath: /appdata
resources:
requests:
cpu: "250m"
memory: "350Mi"
limits:
cpu: "500m"
memory: "700Mi"
volumes:
- name: homarr-data
persistentVolumeClaim:
claimName: homarr-pvc
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: homarr-pvc
namespace: homarr
spec:
resources:
requests:
storage: 2Gi
volumeMode: Filesystem
accessModes:
- ReadWriteOnce
+33
View File
@@ -0,0 +1,33 @@
# apiVersion: traefik.io/v1alpha1
# kind: IngressRoute
# metadata:
# name: homarr-prod
# namespace: homarr
# spec:
# entryPoints:
# - websecure
# routes:
# - match: Host(`home.forust.xyz`)
# kind: Rule
# services:
# - name: homarr-service
# port: 7575
# tls:
# secretName: home-prod-tls
# ---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: homarr-local
namespace: homarr
spec:
entryPoints:
- websecure
routes:
- match: Host(`home.workstation.internal`) || Host(`home.gigaforust.internal`)
kind: Rule
services:
- name: homarr-service
port: 7575
tls:
secretName: internal-wildcard-tls
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: homarr
+58
View File
@@ -0,0 +1,58 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: homarr
namespace: homarr
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: homarr-readonly
rules:
- apiGroups: [""]
resources:
- pods
- services
- endpoints
- namespaces
- nodes
- configmaps
- persistentvolumeclaims
- events
verbs: ["get", "list", "watch"]
- apiGroups: ["apps"]
resources:
- deployments
- statefulsets
- daemonsets
- replicasets
verbs: ["get", "list", "watch"]
- apiGroups: ["networking.k8s.io"]
resources:
- ingresses
verbs: ["get", "list", "watch"]
- apiGroups: ["traefik.io"]
resources:
- ingressroutes
- ingressroutetcps
- ingressrouteudps
- middlewares
verbs: ["get", "list", "watch"]
- apiGroups: ["metrics.k8s.io"]
resources:
- pods
- nodes
verbs: ["get", "list"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: homarr-readonly
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: homarr-readonly
subjects:
- kind: ServiceAccount
name: homarr
namespace: homarr
+9
View File
@@ -0,0 +1,9 @@
apiVersion: v1
kind: Secret
metadata:
name: homarr-secrets
namespace: homarr
type: Opaque
stringData:
# openssl rand -hex 32
SECRET_ENCRYPTION_KEY: "REPLACE_ME"
+1 -1
View File
@@ -174,7 +174,7 @@
<h2>./projects</h2> <h2>./projects</h2>
<ul class="repo-list"> <ul class="repo-list">
<li> <li>
<a href="https://gitea.forust.xyz/forust/gosleep" target="_blank">forust/gosleep</a> <a href="https://git.forust.xyz/forust/gosleep" target="_blank">forust/gosleep</a>
<span class="comment">// linux sleep timer written in rust (originally in go)</span> <span class="comment">// linux sleep timer written in rust (originally in go)</span>
</li> </li>
</ul> </ul>
+1 -1
View File
@@ -1,6 +1,6 @@
services: services:
n8n: n8n:
image: docker.n8n.io/n8nio/n8n:2.42.2 image: docker.n8n.io/n8nio/n8n:2.42.3
container_name: n8n container_name: n8n
restart: unless-stopped restart: unless-stopped
environment: environment:
+1 -1
View File
@@ -29,7 +29,7 @@ spec:
spec: spec:
containers: containers:
- name: n8n - name: n8n
image: docker.n8n.io/n8nio/n8n:2.42.2 image: docker.n8n.io/n8nio/n8n:2.42.3
envFrom: envFrom:
- configMapRef: - configMapRef:
name: n8n-config name: n8n-config
+1 -1
View File
@@ -1,4 +1,4 @@
RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 RENOVATE_ENDPOINT=https://git.forust.xyz/api/v1
RENOVATE_TOKEN= RENOVATE_TOKEN=
RENOVATE_REPOSITORIES=forust/homelab RENOVATE_REPOSITORIES=forust/homelab
LOG_LEVEL=info LOG_LEVEL=info
+28
View File
@@ -218,6 +218,34 @@ data:
"matchUpdateTypes": ["patch"], "matchUpdateTypes": ["patch"],
"groupName": "all patch updates", "groupName": "all patch updates",
"groupSlug": "all-patch" "groupSlug": "all-patch"
},
{
"description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.",
"matchDatasources": ["docker"],
"matchPackageNames": ["python"],
"groupName": "python base image",
"groupSlug": "python",
"automerge": false
},
{
"description": "Rolling/floating tags (streaming stack, nextcloud beta, kubectl latest) - never automerge, every bump is a manual review. Placed last so automerge:false wins over the shared digest/patch rule.",
"matchDatasources": ["docker"],
"matchPackageNames": [
"lscr.io/linuxserver/jellyfin",
"lscr.io/linuxserver/qbittorrent",
"lscr.io/linuxserver/sonarr",
"lscr.io/linuxserver/radarr",
"lscr.io/linuxserver/prowlarr",
"lscr.io/linuxserver/bazarr",
"ghcr.io/seerr-team/seerr",
"fallenbagel/jellyseerr",
"ghcr.io/lampac-nextgen/lampac",
"ghcr.io/nextcloud-releases/all-in-one",
"alpine/kubectl"
],
"groupName": "floating images - manual",
"groupSlug": "floating-manual",
"automerge": false
} }
] ]
} }
+1 -1
View File
@@ -19,7 +19,7 @@ spec:
restartPolicy: Never restartPolicy: Never
containers: containers:
- name: renovate - name: renovate
image: renovate/renovate:44.132.5 image: renovate/renovate:44.136.0
env: env:
- name: RENOVATE_PLATFORM - name: RENOVATE_PLATFORM
value: gitea value: gitea
+1 -1
View File
@@ -6,6 +6,6 @@ metadata:
type: Opaque type: Opaque
stringData: stringData:
RENOVATE_TOKEN: "" RENOVATE_TOKEN: ""
RENOVATE_ENDPOINT: "https://gitea.forust.xyz/api/v1" RENOVATE_ENDPOINT: "https://git.forust.xyz/api/v1"
RENOVATE_REPOSITORIES: "forust/homelab" RENOVATE_REPOSITORIES: "forust/homelab"
RENOVATE_GITHUB_COM_TOKEN: "" RENOVATE_GITHUB_COM_TOKEN: ""
+28
View File
@@ -207,6 +207,34 @@
"matchUpdateTypes": ["patch"], "matchUpdateTypes": ["patch"],
"groupName": "all patch updates", "groupName": "all patch updates",
"groupSlug": "all-patch" "groupSlug": "all-patch"
},
{
"description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.",
"matchDatasources": ["docker"],
"matchPackageNames": ["python"],
"groupName": "python base image",
"groupSlug": "python",
"automerge": false
},
{
"description": "Rolling/floating tags (streaming stack, nextcloud beta, kubectl latest) - never automerge, every bump is a manual review. Placed last so automerge:false wins over the shared digest/patch rule.",
"matchDatasources": ["docker"],
"matchPackageNames": [
"lscr.io/linuxserver/jellyfin",
"lscr.io/linuxserver/qbittorrent",
"lscr.io/linuxserver/sonarr",
"lscr.io/linuxserver/radarr",
"lscr.io/linuxserver/prowlarr",
"lscr.io/linuxserver/bazarr",
"ghcr.io/seerr-team/seerr",
"fallenbagel/jellyseerr",
"ghcr.io/lampac-nextgen/lampac",
"ghcr.io/nextcloud-releases/all-in-one",
"alpine/kubectl"
],
"groupName": "floating images - manual",
"groupSlug": "floating-manual",
"automerge": false
} }
] ]
} }
+3
View File
@@ -0,0 +1,3 @@
PUID=1000
PGID=1000
TZ=Europe/Berlin
View File
Whitespace-only changes.
+133
View File
@@ -0,0 +1,133 @@
services:
jellyfin:
image: lscr.io/linuxserver/jellyfin:version-12.1ubu2604
container_name: jellyfin
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- jellyfin-cfg:/config
- movies:/media/movies
- tv:/media/tv
devices:
- /dev/dri:/dev/dri
ports:
- "18096:8096"
networks:
- streaming
qbittorrent:
image: lscr.io/linuxserver/qbittorrent:5.2.4
container_name: qbittorrent
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
- WEBUI_PORT=8080
volumes:
- qbittorrent-cfg:/config
- downloads:/downloads
ports:
- "18180:8080"
- "6881:6881"
- "6881:6881/udp"
networks:
- streaming
sonarr:
image: lscr.io/linuxserver/sonarr:4.0.20
container_name: sonarr
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- sonarr-cfg:/config
- downloads:/downloads
- tv:/tv
ports:
- "18989:8989"
networks:
- streaming
radarr:
image: lscr.io/linuxserver/radarr:6.4.4
container_name: radarr
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- radarr-cfg:/config
- downloads:/downloads
- movies:/movies
ports:
- "17878:7878"
networks:
- streaming
prowlarr:
image: lscr.io/linuxserver/prowlarr:2.6.5
container_name: prowlarr
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- prowlarr-cfg:/config
ports:
- "19696:9696"
networks:
- streaming
jellyseerr:
image: fallenbagel/jellyseerr:latest
container_name: jellyseerr
restart: unless-stopped
environment:
- TZ=${TZ:-Europe/Berlin}
volumes:
- jellyseerr-cfg:/app/config
ports:
- "15055:5055"
networks:
- streaming
bazarr:
image: lscr.io/linuxserver/bazarr:1.6.2
container_name: bazarr
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- bazarr-cfg:/config
- movies:/movies
- tv:/tv
ports:
- "16767:6767"
networks:
- streaming
volumes:
jellyfin-cfg:
qbittorrent-cfg:
sonarr-cfg:
radarr-cfg:
prowlarr-cfg:
jellyseerr-cfg:
bazarr-cfg:
downloads:
movies:
tv:
networks:
streaming:
name: streaming
View File
Whitespace-only changes.
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: streaming
+93
View File
@@ -0,0 +1,93 @@
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: internal-wildcard-tls
namespace: streaming
spec:
secretName: internal-wildcard-tls
dnsNames:
- "*.workstation.internal"
- "*.gigaforust.internal"
- workstation.internal
- gigaforust.internal
issuerRef:
name: internal-ca
kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: jellyfin-prod-tls
# namespace: streaming
# spec:
# secretName: jellyfin-prod-tls
# dnsNames:
# - jellyfin.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: qbittorrent-prod-tls
# namespace: streaming
# spec:
# secretName: qbittorrent-prod-tls
# dnsNames:
# - qbittorrent.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: sonarr-prod-tls
# namespace: streaming
# spec:
# secretName: sonarr-prod-tls
# dnsNames:
# - sonarr.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: radarr-prod-tls
# namespace: streaming
# spec:
# secretName: radarr-prod-tls
# dnsNames:
# - radarr.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: prowlarr-prod-tls
# namespace: streaming
# spec:
# secretName: prowlarr-prod-tls
# dnsNames:
# - prowlarr.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: jellyseerr-prod-tls
# namespace: streaming
# spec:
# secretName: jellyseerr-prod-tls
# dnsNames:
# - jellyseerr.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
+188
View File
@@ -0,0 +1,188 @@
apiVersion: v1
kind: Service
metadata:
name: jellyfin
namespace: streaming
spec:
ports:
- port: 18096
targetPort: 18096
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: jellyfin
namespace: streaming
labels:
kubernetes.io/service-name: jellyfin
addressType: IPv4
ports:
- port: 18096
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: qbittorrent
namespace: streaming
spec:
ports:
- port: 18180
targetPort: 18180
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: qbittorrent
namespace: streaming
labels:
kubernetes.io/service-name: qbittorrent
addressType: IPv4
ports:
- port: 18180
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: sonarr
namespace: streaming
spec:
ports:
- port: 18989
targetPort: 18989
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: sonarr
namespace: streaming
labels:
kubernetes.io/service-name: sonarr
addressType: IPv4
ports:
- port: 18989
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: radarr
namespace: streaming
spec:
ports:
- port: 17878
targetPort: 17878
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: radarr
namespace: streaming
labels:
kubernetes.io/service-name: radarr
addressType: IPv4
ports:
- port: 17878
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: prowlarr
namespace: streaming
spec:
ports:
- port: 19696
targetPort: 19696
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: prowlarr
namespace: streaming
labels:
kubernetes.io/service-name: prowlarr
addressType: IPv4
ports:
- port: 19696
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: jellyseerr
namespace: streaming
spec:
ports:
- port: 15055
targetPort: 15055
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: jellyseerr
namespace: streaming
labels:
kubernetes.io/service-name: jellyseerr
addressType: IPv4
ports:
- port: 15055
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: bazarr
namespace: streaming
spec:
ports:
- port: 16767
targetPort: 16767
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: bazarr
namespace: streaming
labels:
kubernetes.io/service-name: bazarr
addressType: IPv4
ports:
- port: 16767
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
+118
View File
@@ -0,0 +1,118 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: jellyfin-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`jellyfin.workstation.internal`)
kind: Rule
services:
- name: jellyfin
port: 18096
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: qbittorrent-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`qbittorrent.workstation.internal`)
kind: Rule
services:
- name: qbittorrent
port: 18180
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: sonarr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`sonarr.workstation.internal`)
kind: Rule
services:
- name: sonarr
port: 18989
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: radarr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`radarr.workstation.internal`)
kind: Rule
services:
- name: radarr
port: 17878
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: prowlarr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`prowlarr.workstation.internal`)
kind: Rule
services:
- name: prowlarr
port: 19696
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: jellyseerr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`jellyseerr.workstation.internal`)
kind: Rule
services:
- name: jellyseerr
port: 15055
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: bazarr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`bazarr.workstation.internal`)
kind: Rule
services:
- name: bazarr
port: 16767
tls:
secretName: internal-wildcard-tls
+1 -1
View File
@@ -1,6 +1,6 @@
services: services:
termix: termix:
image: ghcr.io/lukegus/termix:2.9.0 image: ghcr.io/lukegus/termix:2.9.1
container_name: termix container_name: termix
restart: unless-stopped restart: unless-stopped
# ports: # ports:
+1 -1
View File
@@ -29,7 +29,7 @@ spec:
spec: spec:
containers: containers:
- name: termix - name: termix
image: ghcr.io/lukegus/termix:2.9.0 image: ghcr.io/lukegus/termix:2.9.1
envFrom: envFrom:
- configMapRef: - configMapRef:
name: termix-config name: termix-config
+74
View File
@@ -0,0 +1,74 @@
"""Session publication checks without Redis, the EDU website, or credentials."""
import importlib.util
import sys
import unittest
from pathlib import Path
from unittest.mock import Mock, patch
SCRIPT = Path(__file__).resolve().parents[1] / 'edu_master/phpsessid-bot/bot.py'
spec = importlib.util.spec_from_file_location('session_keeper', SCRIPT)
bot = importlib.util.module_from_spec(spec)
with patch.dict(sys.modules, {'redis': Mock(), 'requests': Mock()}):
spec.loader.exec_module(bot)
class SessionKeeperTests(unittest.TestCase):
def setUp(self):
self.session = Mock()
self.session.get.return_value.status_code = 200
self.session.cookies.get.return_value = 'test-cookie'
self.redis = Mock()
self.touch = patch.object(bot, 'touch_success_file').start()
self.addCleanup(patch.stopall)
def test_verified_cookie_expires_and_is_not_logged(self):
with self.assertLogs(bot.logger, level='INFO') as logs:
self.assertTrue(bot.refresh_session(self.session, self.redis))
self.redis.set.assert_called_once_with('EDU_PHPSESSID', 'test-cookie', ex=bot.INTERVAL * 120)
self.touch.assert_called_once()
self.assertNotIn('test-cookie', '\n'.join(logs.output))
self.assertEqual(self.session.post.call_args.kwargs['timeout'], (10, 30))
self.assertEqual(self.session.get.call_args.kwargs['timeout'], (10, 30))
def test_redirect_does_not_publish(self):
self.session.get.return_value.status_code = 302
self.assertFalse(bot.refresh_session(self.session, self.redis))
self.redis.set.assert_not_called()
self.touch.assert_not_called()
def test_missing_cookie_does_not_mark_success(self):
self.session.cookies.get.return_value = None
self.assertFalse(bot.refresh_session(self.session, self.redis))
self.redis.set.assert_not_called()
self.touch.assert_not_called()
def test_redis_failure_does_not_mark_success(self):
self.redis.set.side_effect = OSError('redis unavailable')
with self.assertRaises(OSError):
bot.refresh_session(self.session, self.redis)
self.touch.assert_not_called()
def test_http_timeout_does_not_publish(self):
self.session.post.side_effect = TimeoutError('EDU unavailable')
with self.assertRaises(TimeoutError):
bot.refresh_session(self.session, self.redis)
self.redis.set.assert_not_called()
self.touch.assert_not_called()
def test_missing_credentials_fail_before_network_access(self):
with patch.object(bot, 'LOGIN', None), self.assertRaises(ValueError):
bot.main()
def test_nonpositive_interval_fails_before_network_access(self):
with (
patch.object(bot, 'LOGIN', 'test'),
patch.object(bot, 'PASSWORD', 'test'),
patch.object(bot, 'INTERVAL', 0),
self.assertRaises(ValueError),
):
bot.main()
if __name__ == '__main__':
unittest.main()
+2
View File
@@ -10,6 +10,8 @@ spec:
routes: routes:
- match: Host(`traefik.forust.xyz`) - match: Host(`traefik.forust.xyz`)
kind: Rule kind: Rule
middlewares:
- name: security-chain@file
services: services:
- name: api@internal - name: api@internal
kind: TraefikService kind: TraefikService
+1 -1
View File
@@ -94,7 +94,7 @@ ports:
exposedPort: 8080 exposedPort: 8080
protocol: TCP protocol: TCP
expose: expose:
default: false default: true
http: http:
aliasHeadersStrategy: delete aliasHeadersStrategy: delete
ssh: ssh:
+40
View File
@@ -0,0 +1,40 @@
apiVersion: monitoring.coreos.com/v1
kind: PrometheusRule
metadata:
name: uptime-kuma
namespace: uptime-kuma
labels:
release: prometheus-stack
spec:
groups:
- name: uptime_kuma.monitors
rules:
- alert: KumaMonitorDown
expr: |
monitor_status{monitor_type!="group"} == 0
for: 5m
labels:
severity: critical
annotations:
summary: "Uptime Kuma monitor down: {{ $labels.monitor_name }}"
description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) is down for 5m. Check Uptime Kuma (https://uptime.forust.xyz) and the target service."
- alert: KumaScrapeDown
expr: |
absent(monitor_status) == 1
for: 10m
labels:
severity: critical
annotations:
summary: "Uptime Kuma metrics missing"
description: "uptime-kuma: no monitor_status series for 10m. Pod may be down, the uk1_ API key may have been rotated without updating uptime-kuma-secrets, or ServiceMonitor/Service broken. All Kuma monitors are unobserved."
- alert: KumaCertExpiring
expr: |
monitor_cert_days_remaining < 14
for: 1h
labels:
severity: warning
annotations:
summary: "TLS cert expiring: {{ $labels.monitor_name }} ({{ $value }}d left)"
description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) reports a TLS certificate with {{ $value }} days remaining. Check cert-manager Certificate for this host."
+9
View File
@@ -0,0 +1,9 @@
apiVersion: v1
kind: Secret
metadata:
name: uptime-kuma-secrets
namespace: uptime-kuma
type: Opaque
stringData:
metrics-username: "uptime-kuma"
metrics-password: "REPLACE_ME"
+23
View File
@@ -0,0 +1,23 @@
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
name: uptime-kuma
namespace: uptime-kuma
labels:
release: prometheus-stack
spec:
selector:
matchLabels:
app: uptime-kuma
endpoints:
- port: http
path: /metrics
interval: 60s
scrapeTimeout: 15s
basicAuth:
username:
name: uptime-kuma-secrets
key: metrics-username
password:
name: uptime-kuma-secrets
key: metrics-password
+3
View File
@@ -3,11 +3,14 @@ kind: Service
metadata: metadata:
name: uptime-kuma-service name: uptime-kuma-service
namespace: uptime-kuma namespace: uptime-kuma
labels:
app: uptime-kuma
spec: spec:
selector: selector:
app: uptime-kuma app: uptime-kuma
ports: ports:
- port: 3001 - port: 3001
name: http
targetPort: 3001 targetPort: 3001
--- ---
apiVersion: apps/v1 apiVersion: apps/v1