Compare commits

..
Author SHA1 Message Date
renovate-bot 59a056aed1 chore(deps): update renovate/renovate docker tag to v44.132.4
renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (pull_request) Successful in 10s
ci / lint-prettier (pull_request) Successful in 13s
ci / build (pull_request) Skipped
ci / lint-compose (push) Successful in 9s
ci / lint-actionlint (push) Successful in 4s
ci / validate (push) Successful in 6s
ci / build (push) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 38s
ci / lint-actionlint (pull_request) Successful in 4s
ci / lint-shellcheck (pull_request) Successful in 7s
ci / lint-ruff (pull_request) Successful in 5s
ci / lint-yaml (pull_request) Successful in 8s
ci / lint-dockerfiles (pull_request) Successful in 6s
ci / validate (pull_request) Successful in 7s
ci / lint-shellcheck (push) Successful in 9s
ci / lint-prettier (push) Successful in 16s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 8s
ci / lint-dockerfiles (push) Successful in 5s
2026-10-03 16:19:59 +00:00
24 changed files with 64 additions and 747 deletions

No files matched your search

+1 -1
View File
@@ -81,7 +81,7 @@ jobs:
docker run --rm \ docker run --rm \
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \ -v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
-e RENOVATE_PLATFORM=gitea \ -e RENOVATE_PLATFORM=gitea \
-e RENOVATE_ENDPOINT=https://git.forust.xyz/api/v1 \ -e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \ -e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \ -e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \ -e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
+35 -7
View File
@@ -68,6 +68,35 @@ spec:
reloader.stakater.com/auto: "true" reloader.stakater.com/auto: "true"
spec: spec:
containers: containers:
- name: netbird
image: netbirdio/netbird:0.80.0
envFrom:
- configMapRef:
name: adguard-config
env:
- name: NB_SETUP_KEY
valueFrom:
secretKeyRef:
name: adguard-netbird-secrets
key: NB_SETUP_KEY
securityContext:
capabilities:
add:
- NET_ADMIN
- SYS_ADMIN
- SYS_RESOURCE
resources:
requests:
memory: "64Mi"
cpu: "50m"
limits:
memory: "256Mi"
cpu: "200m"
volumeMounts:
- name: netbird-state
mountPath: /var/lib/netbird
- name: dev-tun
mountPath: /dev/net/tun
- name: adguard - name: adguard
image: adguard/adguardhome:v0.107.79 image: adguard/adguardhome:v0.107.79
resources: resources:
@@ -84,13 +113,6 @@ spec:
name: dns name: dns
- containerPort: 853 - containerPort: 853
name: dot name: dot
readinessProbe:
tcpSocket:
port: dns
initialDelaySeconds: 5
periodSeconds: 5
successThreshold: 1
failureThreshold: 3
volumeMounts: volumeMounts:
- name: adguard-data - name: adguard-data
mountPath: /opt/adguardhome/work mountPath: /opt/adguardhome/work
@@ -102,6 +124,12 @@ spec:
mountPath: /certs mountPath: /certs
readOnly: true readOnly: true
volumes: volumes:
- name: netbird-state
emptyDir: {}
- name: dev-tun
hostPath:
path: /dev/net/tun
type: CharDevice
- name: adguard-data - name: adguard-data
persistentVolumeClaim: persistentVolumeClaim:
claimName: adguard-pvc claimName: adguard-pvc
+10
View File
@@ -0,0 +1,10 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: adguard-config
namespace: adguard
data:
NB_MANAGEMENT_URL: "https://nb.forust.xyz"
NB_HOSTNAME: "adguard"
NB_LOG_LEVEL: "info"
NB_DISABLE_DNS: "true"
@@ -0,0 +1,8 @@
apiVersion: v1
kind: Secret
metadata:
name: adguard-netbird-secrets
namespace: adguard
type: Opaque
stringData:
NB_SETUP_KEY: "REPLACE_ME"
+2 -5
View File
@@ -13,12 +13,9 @@ services:
- GITEA__database__PASSWD=gitea - GITEA__database__PASSWD=gitea
- GITEA__database__NAME=gitea - GITEA__database__NAME=gitea
# Server # Server
- GITEA__server__ROOT_URL=https://git.forust.xyz - GITEA__server__ROOT_URL=https://gitea.forust.xyz
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz - GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
- GITEA__server__SSH_PORT=2221 - GITEA__server__SSH_PORT=2221
# Pin 28.0 defaults explicitly (see k8s/config.yaml for rationale)
- GITEA__service__DISABLE_REGISTRATION=true
- GITEA__actions__RUN_RETENTION_DAYS=90
# Mailer # Mailer
- GITEA__mailer__ENABLED=true - GITEA__mailer__ENABLED=true
- GITEA__mailer__FROM=${SERVICE_EMAIL} - GITEA__mailer__FROM=${SERVICE_EMAIL}
@@ -37,7 +34,7 @@ services:
- "traefik.http.services.gitea.loadbalancer.server.port=3000" - "traefik.http.services.gitea.loadbalancer.server.port=3000"
# Prod Router # Prod Router
- "traefik.http.routers.gitea.rule=Host(`git.forust.xyz`) || Host(`gitea.forust.xyz`)" - "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
- "traefik.http.routers.gitea.entrypoints=websecure" - "traefik.http.routers.gitea.entrypoints=websecure"
- "traefik.http.routers.gitea.tls.certresolver" - "traefik.http.routers.gitea.tls.certresolver"
# Local Router # Local Router
+2 -5
View File
@@ -4,14 +4,11 @@ metadata:
name: gitea-config name: gitea-config
namespace: gitea namespace: gitea
data: data:
GITEA__server__ROOT_URL: "https://git.forust.xyz" GITEA__server__DOMAIN: "gitea.forust.xyz"
GITEA__server__ROOT_URL: "https://gitea.forust.xyz"
GITEA__server__SSH_DOMAIN: "gitssh.forust.xyz" GITEA__server__SSH_DOMAIN: "gitssh.forust.xyz"
GITEA__server__SSH_PORT: "2221" GITEA__server__SSH_PORT: "2221"
GITEA__service__DISABLE_REGISTRATION: "true"
GITEA__actions__RUN_RETENTION_DAYS: "90"
GITEA__database__DB_TYPE: "postgres" GITEA__database__DB_TYPE: "postgres"
GITEA__database__HOST: "postgres.database.svc.cluster.local:5432" GITEA__database__HOST: "postgres.database.svc.cluster.local:5432"
GITEA__database__NAME: "gitea" GITEA__database__NAME: "gitea"
+2 -2
View File
@@ -177,8 +177,8 @@ data:
# url: https://gitssh.forust.xyz # url: https://gitssh.forust.xyz
# - title: gcr.forust.xyz # - title: gcr.forust.xyz
# url: https://gcr.forust.xyz/v2/ # url: https://gcr.forust.xyz/v2/
- title: git.forust.xyz - title: gitea.forust.xyz
url: https://git.forust.xyz url: https://gitea.forust.xyz
- title: nextcloud.forust.xyz - title: nextcloud.forust.xyz
url: https://nextcloud.forust.xyz url: https://nextcloud.forust.xyz
- title: mc.forust.xyz - title: mc.forust.xyz
+1 -1
View File
@@ -174,7 +174,7 @@
<h2>./projects</h2> <h2>./projects</h2>
<ul class="repo-list"> <ul class="repo-list">
<li> <li>
<a href="https://git.forust.xyz/forust/gosleep" target="_blank">forust/gosleep</a> <a href="https://gitea.forust.xyz/forust/gosleep" target="_blank">forust/gosleep</a>
<span class="comment">// linux sleep timer written in rust (originally in go)</span> <span class="comment">// linux sleep timer written in rust (originally in go)</span>
</li> </li>
</ul> </ul>
+1 -1
View File
@@ -1,4 +1,4 @@
RENOVATE_ENDPOINT=https://git.forust.xyz/api/v1 RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1
RENOVATE_TOKEN= RENOVATE_TOKEN=
RENOVATE_REPOSITORIES=forust/homelab RENOVATE_REPOSITORIES=forust/homelab
LOG_LEVEL=info LOG_LEVEL=info
+1 -1
View File
@@ -19,7 +19,7 @@ spec:
restartPolicy: Never restartPolicy: Never
containers: containers:
- name: renovate - name: renovate
image: renovate/renovate:44.132.2 image: renovate/renovate:44.132.4
env: env:
- name: RENOVATE_PLATFORM - name: RENOVATE_PLATFORM
value: gitea value: gitea
+1 -1
View File
@@ -6,6 +6,6 @@ metadata:
type: Opaque type: Opaque
stringData: stringData:
RENOVATE_TOKEN: "" RENOVATE_TOKEN: ""
RENOVATE_ENDPOINT: "https://git.forust.xyz/api/v1" RENOVATE_ENDPOINT: "https://gitea.forust.xyz/api/v1"
RENOVATE_REPOSITORIES: "forust/homelab" RENOVATE_REPOSITORIES: "forust/homelab"
RENOVATE_GITHUB_COM_TOKEN: "" RENOVATE_GITHUB_COM_TOKEN: ""
-3
View File
@@ -1,3 +0,0 @@
PUID=1000
PGID=1000
TZ=Europe/Berlin
View File
Whitespace-only changes.
-162
View File
@@ -1,162 +0,0 @@
services:
jellyfin:
image: lscr.io/linuxserver/jellyfin:latest
container_name: jellyfin
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- jellyfin-cfg:/config
- movies:/media/movies
- tv:/media/tv
devices:
- /dev/dri:/dev/dri
ports:
- "18096:8096"
networks:
- streaming
qbittorrent:
image: lscr.io/linuxserver/qbittorrent:latest
container_name: qbittorrent
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
- WEBUI_PORT=8080
volumes:
- qbittorrent-cfg:/config
- downloads:/downloads
ports:
- "18180:8080"
- "6881:6881"
- "6881:6881/udp"
networks:
- streaming
sonarr:
image: lscr.io/linuxserver/sonarr:latest
container_name: sonarr
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- sonarr-cfg:/config
- downloads:/downloads
- tv:/tv
ports:
- "18989:8989"
networks:
- streaming
radarr:
image: lscr.io/linuxserver/radarr:latest
container_name: radarr
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- radarr-cfg:/config
- downloads:/downloads
- movies:/movies
ports:
- "17878:7878"
networks:
- streaming
prowlarr:
image: lscr.io/linuxserver/prowlarr:latest
container_name: prowlarr
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- prowlarr-cfg:/config
ports:
- "19696:9696"
networks:
- streaming
jellyseerr:
image: ghcr.io/seerr-team/seerr:latest
container_name: jellyseerr
init: true
restart: unless-stopped
environment:
- TZ=${TZ:-Europe/Berlin}
volumes:
- jellyseerr-cfg:/app/config
ports:
- "15055:5055"
networks:
- streaming
bazarr:
image: lscr.io/linuxserver/bazarr:latest
container_name: bazarr
restart: unless-stopped
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
- TZ=${TZ:-Europe/Berlin}
volumes:
- bazarr-cfg:/config
- movies:/movies
- tv:/tv
ports:
- "16767:6767"
networks:
- streaming
lampac:
image: ghcr.io/lampac-nextgen/lampac:latest
container_name: lampac
restart: unless-stopped
shm_size: 1024mb
# Restore persisted passwd/init.conf from seed volume before start,
# so config survives container recreation (upstream entrypoint is
# ENTRYPOINT ["dotnet", "Core.dll"], WORKDIR /lampac, USER lampac).
entrypoint:
[
"/bin/sh",
"-c",
"if [ -f /seed/passwd ] && [ ! -f /lampac/passwd ]; then cp /seed/passwd /lampac/passwd; fi; if [ -f /seed/init.conf ] && [ ! -f /lampac/init.conf ]; then cp /seed/init.conf /lampac/init.conf; fi; exec /usr/share/dotnet/dotnet Core.dll",
]
environment:
- TZ=${TZ:-Europe/Berlin}
volumes:
- lampac-seed:/seed
- lampac-cache:/lampac/cache
- lampac-db:/lampac/database
ports:
- "19118:9118"
networks:
- streaming
volumes:
jellyfin-cfg:
qbittorrent-cfg:
sonarr-cfg:
radarr-cfg:
prowlarr-cfg:
jellyseerr-cfg:
bazarr-cfg:
lampac-seed:
lampac-cache:
lampac-db:
downloads:
movies:
tv:
networks:
streaming:
name: streaming
View File
Whitespace-only changes.
-4
View File
@@ -1,4 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: streaming
-93
View File
@@ -1,93 +0,0 @@
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: internal-wildcard-tls
namespace: streaming
spec:
secretName: internal-wildcard-tls
dnsNames:
- "*.workstation.internal"
- "*.gigaforust.internal"
- workstation.internal
- gigaforust.internal
issuerRef:
name: internal-ca
kind: ClusterIssuer
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: jelly-prod-tls
namespace: streaming
spec:
secretName: jelly-prod-tls
dnsNames:
- jelly.forust.xyz
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: seerr-prod-tls
namespace: streaming
spec:
secretName: seerr-prod-tls
dnsNames:
- seerr.forust.xyz
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: qbittorrent-prod-tls
# namespace: streaming
# spec:
# secretName: qbittorrent-prod-tls
# dnsNames:
# - qbittorrent.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: sonarr-prod-tls
# namespace: streaming
# spec:
# secretName: sonarr-prod-tls
# dnsNames:
# - sonarr.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: radarr-prod-tls
# namespace: streaming
# spec:
# secretName: radarr-prod-tls
# dnsNames:
# - radarr.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
# ---
# apiVersion: cert-manager.io/v1
# kind: Certificate
# metadata:
# name: prowlarr-prod-tls
# namespace: streaming
# spec:
# secretName: prowlarr-prod-tls
# dnsNames:
# - prowlarr.forust.xyz
# issuerRef:
# name: letsencrypt-prod
# kind: ClusterIssuer
-215
View File
@@ -1,215 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: jellyfin
namespace: streaming
spec:
ports:
- port: 18096
targetPort: 18096
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: jellyfin
namespace: streaming
labels:
kubernetes.io/service-name: jellyfin
addressType: IPv4
ports:
- port: 18096
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: qbittorrent
namespace: streaming
spec:
ports:
- port: 18180
targetPort: 18180
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: qbittorrent
namespace: streaming
labels:
kubernetes.io/service-name: qbittorrent
addressType: IPv4
ports:
- port: 18180
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: sonarr
namespace: streaming
spec:
ports:
- port: 18989
targetPort: 18989
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: sonarr
namespace: streaming
labels:
kubernetes.io/service-name: sonarr
addressType: IPv4
ports:
- port: 18989
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: radarr
namespace: streaming
spec:
ports:
- port: 17878
targetPort: 17878
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: radarr
namespace: streaming
labels:
kubernetes.io/service-name: radarr
addressType: IPv4
ports:
- port: 17878
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: prowlarr
namespace: streaming
spec:
ports:
- port: 19696
targetPort: 19696
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: prowlarr
namespace: streaming
labels:
kubernetes.io/service-name: prowlarr
addressType: IPv4
ports:
- port: 19696
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: jellyseerr
namespace: streaming
spec:
ports:
- port: 15055
targetPort: 15055
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: jellyseerr
namespace: streaming
labels:
kubernetes.io/service-name: jellyseerr
addressType: IPv4
ports:
- port: 15055
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: bazarr
namespace: streaming
spec:
ports:
- port: 16767
targetPort: 16767
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: bazarr
namespace: streaming
labels:
kubernetes.io/service-name: bazarr
addressType: IPv4
ports:
- port: 16767
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
---
apiVersion: v1
kind: Service
metadata:
name: lampac
namespace: streaming
spec:
ports:
- port: 19118
targetPort: 19118
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: lampac
namespace: streaming
labels:
kubernetes.io/service-name: lampac
addressType: IPv4
ports:
- port: 19118
protocol: TCP
endpoints:
- addresses:
- "192.168.88.100"
conditions:
ready: true
-169
View File
@@ -1,169 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: jellyfin-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`jellyfin.workstation.internal`)
kind: Rule
services:
- name: jellyfin
port: 18096
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: qbittorrent-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`qbittorrent.workstation.internal`)
kind: Rule
services:
- name: qbittorrent
port: 18180
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: sonarr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`sonarr.workstation.internal`)
kind: Rule
services:
- name: sonarr
port: 18989
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: radarr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`radarr.workstation.internal`)
kind: Rule
services:
- name: radarr
port: 17878
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: prowlarr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`prowlarr.workstation.internal`)
kind: Rule
services:
- name: prowlarr
port: 19696
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: jellyseerr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`jellyseerr.workstation.internal`)
kind: Rule
services:
- name: jellyseerr
port: 15055
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: bazarr-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`bazarr.workstation.internal`)
kind: Rule
services:
- name: bazarr
port: 16767
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: lampac-local
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`lampac.workstation.internal`)
kind: Rule
services:
- name: lampac
port: 19118
tls:
secretName: internal-wildcard-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: jellyfin-prod
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`jelly.forust.xyz`)
kind: Rule
services:
- name: jellyfin
port: 18096
tls:
secretName: jelly-prod-tls
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: seerr-prod
namespace: streaming
spec:
entryPoints:
- websecure
routes:
- match: Host(`seerr.forust.xyz`)
kind: Rule
services:
- name: jellyseerr
port: 15055
tls:
secretName: seerr-prod-tls
-2
View File
@@ -10,8 +10,6 @@ spec:
routes: routes:
- match: Host(`traefik.forust.xyz`) - match: Host(`traefik.forust.xyz`)
kind: Rule kind: Rule
middlewares:
- name: security-chain@file
services: services:
- name: api@internal - name: api@internal
kind: TraefikService kind: TraefikService
-40
View File
@@ -1,40 +0,0 @@
apiVersion: monitoring.coreos.com/v1
kind: PrometheusRule
metadata:
name: uptime-kuma
namespace: uptime-kuma
labels:
release: prometheus-stack
spec:
groups:
- name: uptime_kuma.monitors
rules:
- alert: KumaMonitorDown
expr: |
monitor_status{monitor_type!="group"} == 0
for: 5m
labels:
severity: critical
annotations:
summary: "Uptime Kuma monitor down: {{ $labels.monitor_name }}"
description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) is down for 5m. Check Uptime Kuma (https://uptime.forust.xyz) and the target service."
- alert: KumaScrapeDown
expr: |
absent(monitor_status) == 1
for: 10m
labels:
severity: critical
annotations:
summary: "Uptime Kuma metrics missing"
description: "uptime-kuma: no monitor_status series for 10m. Pod may be down, the uk1_ API key may have been rotated without updating uptime-kuma-secrets, or ServiceMonitor/Service broken. All Kuma monitors are unobserved."
- alert: KumaCertExpiring
expr: |
monitor_cert_days_remaining < 14
for: 1h
labels:
severity: warning
annotations:
summary: "TLS cert expiring: {{ $labels.monitor_name }} ({{ $value }}d left)"
description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) reports a TLS certificate with {{ $value }} days remaining. Check cert-manager Certificate for this host."
-9
View File
@@ -1,9 +0,0 @@
apiVersion: v1
kind: Secret
metadata:
name: uptime-kuma-secrets
namespace: uptime-kuma
type: Opaque
stringData:
metrics-username: "uptime-kuma"
metrics-password: "REPLACE_ME"
-23
View File
@@ -1,23 +0,0 @@
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
name: uptime-kuma
namespace: uptime-kuma
labels:
release: prometheus-stack
spec:
selector:
matchLabels:
app: uptime-kuma
endpoints:
- port: http
path: /metrics
interval: 60s
scrapeTimeout: 15s
basicAuth:
username:
name: uptime-kuma-secrets
key: metrics-username
password:
name: uptime-kuma-secrets
key: metrics-password
-3
View File
@@ -3,14 +3,11 @@ kind: Service
metadata: metadata:
name: uptime-kuma-service name: uptime-kuma-service
namespace: uptime-kuma namespace: uptime-kuma
labels:
app: uptime-kuma
spec: spec:
selector: selector:
app: uptime-kuma app: uptime-kuma
ports: ports:
- port: 3001 - port: 3001
name: http
targetPort: 3001 targetPort: 3001
--- ---
apiVersion: apps/v1 apiVersion: apps/v1