Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
59a056aed1 |
No files matched your search
@@ -81,7 +81,7 @@ jobs:
|
|||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
|
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
|
||||||
-e RENOVATE_PLATFORM=gitea \
|
-e RENOVATE_PLATFORM=gitea \
|
||||||
-e RENOVATE_ENDPOINT=https://git.forust.xyz/api/v1 \
|
-e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \
|
||||||
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
|
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
|
||||||
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
|
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
|
||||||
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
|
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
|
||||||
|
|||||||
@@ -68,6 +68,35 @@ spec:
|
|||||||
reloader.stakater.com/auto: "true"
|
reloader.stakater.com/auto: "true"
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
|
- name: netbird
|
||||||
|
image: netbirdio/netbird:0.80.0
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: adguard-config
|
||||||
|
env:
|
||||||
|
- name: NB_SETUP_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: adguard-netbird-secrets
|
||||||
|
key: NB_SETUP_KEY
|
||||||
|
securityContext:
|
||||||
|
capabilities:
|
||||||
|
add:
|
||||||
|
- NET_ADMIN
|
||||||
|
- SYS_ADMIN
|
||||||
|
- SYS_RESOURCE
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "64Mi"
|
||||||
|
cpu: "50m"
|
||||||
|
limits:
|
||||||
|
memory: "256Mi"
|
||||||
|
cpu: "200m"
|
||||||
|
volumeMounts:
|
||||||
|
- name: netbird-state
|
||||||
|
mountPath: /var/lib/netbird
|
||||||
|
- name: dev-tun
|
||||||
|
mountPath: /dev/net/tun
|
||||||
- name: adguard
|
- name: adguard
|
||||||
image: adguard/adguardhome:v0.107.79
|
image: adguard/adguardhome:v0.107.79
|
||||||
resources:
|
resources:
|
||||||
@@ -84,13 +113,6 @@ spec:
|
|||||||
name: dns
|
name: dns
|
||||||
- containerPort: 853
|
- containerPort: 853
|
||||||
name: dot
|
name: dot
|
||||||
readinessProbe:
|
|
||||||
tcpSocket:
|
|
||||||
port: dns
|
|
||||||
initialDelaySeconds: 5
|
|
||||||
periodSeconds: 5
|
|
||||||
successThreshold: 1
|
|
||||||
failureThreshold: 3
|
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: adguard-data
|
- name: adguard-data
|
||||||
mountPath: /opt/adguardhome/work
|
mountPath: /opt/adguardhome/work
|
||||||
@@ -102,6 +124,12 @@ spec:
|
|||||||
mountPath: /certs
|
mountPath: /certs
|
||||||
readOnly: true
|
readOnly: true
|
||||||
volumes:
|
volumes:
|
||||||
|
- name: netbird-state
|
||||||
|
emptyDir: {}
|
||||||
|
- name: dev-tun
|
||||||
|
hostPath:
|
||||||
|
path: /dev/net/tun
|
||||||
|
type: CharDevice
|
||||||
- name: adguard-data
|
- name: adguard-data
|
||||||
persistentVolumeClaim:
|
persistentVolumeClaim:
|
||||||
claimName: adguard-pvc
|
claimName: adguard-pvc
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: adguard-config
|
||||||
|
namespace: adguard
|
||||||
|
data:
|
||||||
|
NB_MANAGEMENT_URL: "https://nb.forust.xyz"
|
||||||
|
NB_HOSTNAME: "adguard"
|
||||||
|
NB_LOG_LEVEL: "info"
|
||||||
|
NB_DISABLE_DNS: "true"
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: adguard-netbird-secrets
|
||||||
|
namespace: adguard
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
NB_SETUP_KEY: "REPLACE_ME"
|
||||||
+2
-5
@@ -13,12 +13,9 @@ services:
|
|||||||
- GITEA__database__PASSWD=gitea
|
- GITEA__database__PASSWD=gitea
|
||||||
- GITEA__database__NAME=gitea
|
- GITEA__database__NAME=gitea
|
||||||
# Server
|
# Server
|
||||||
- GITEA__server__ROOT_URL=https://git.forust.xyz
|
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
||||||
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
|
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
|
||||||
- GITEA__server__SSH_PORT=2221
|
- GITEA__server__SSH_PORT=2221
|
||||||
# Pin 28.0 defaults explicitly (see k8s/config.yaml for rationale)
|
|
||||||
- GITEA__service__DISABLE_REGISTRATION=true
|
|
||||||
- GITEA__actions__RUN_RETENTION_DAYS=90
|
|
||||||
# Mailer
|
# Mailer
|
||||||
- GITEA__mailer__ENABLED=true
|
- GITEA__mailer__ENABLED=true
|
||||||
- GITEA__mailer__FROM=${SERVICE_EMAIL}
|
- GITEA__mailer__FROM=${SERVICE_EMAIL}
|
||||||
@@ -37,7 +34,7 @@ services:
|
|||||||
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.gitea.rule=Host(`git.forust.xyz`) || Host(`gitea.forust.xyz`)"
|
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
||||||
- "traefik.http.routers.gitea.entrypoints=websecure"
|
- "traefik.http.routers.gitea.entrypoints=websecure"
|
||||||
- "traefik.http.routers.gitea.tls.certresolver"
|
- "traefik.http.routers.gitea.tls.certresolver"
|
||||||
# Local Router
|
# Local Router
|
||||||
|
|||||||
@@ -4,14 +4,11 @@ metadata:
|
|||||||
name: gitea-config
|
name: gitea-config
|
||||||
namespace: gitea
|
namespace: gitea
|
||||||
data:
|
data:
|
||||||
GITEA__server__ROOT_URL: "https://git.forust.xyz"
|
GITEA__server__DOMAIN: "gitea.forust.xyz"
|
||||||
|
GITEA__server__ROOT_URL: "https://gitea.forust.xyz"
|
||||||
GITEA__server__SSH_DOMAIN: "gitssh.forust.xyz"
|
GITEA__server__SSH_DOMAIN: "gitssh.forust.xyz"
|
||||||
GITEA__server__SSH_PORT: "2221"
|
GITEA__server__SSH_PORT: "2221"
|
||||||
|
|
||||||
GITEA__service__DISABLE_REGISTRATION: "true"
|
|
||||||
|
|
||||||
GITEA__actions__RUN_RETENTION_DAYS: "90"
|
|
||||||
|
|
||||||
GITEA__database__DB_TYPE: "postgres"
|
GITEA__database__DB_TYPE: "postgres"
|
||||||
GITEA__database__HOST: "postgres.database.svc.cluster.local:5432"
|
GITEA__database__HOST: "postgres.database.svc.cluster.local:5432"
|
||||||
GITEA__database__NAME: "gitea"
|
GITEA__database__NAME: "gitea"
|
||||||
|
|||||||
@@ -177,8 +177,8 @@ data:
|
|||||||
# url: https://gitssh.forust.xyz
|
# url: https://gitssh.forust.xyz
|
||||||
# - title: gcr.forust.xyz
|
# - title: gcr.forust.xyz
|
||||||
# url: https://gcr.forust.xyz/v2/
|
# url: https://gcr.forust.xyz/v2/
|
||||||
- title: git.forust.xyz
|
- title: gitea.forust.xyz
|
||||||
url: https://git.forust.xyz
|
url: https://gitea.forust.xyz
|
||||||
- title: nextcloud.forust.xyz
|
- title: nextcloud.forust.xyz
|
||||||
url: https://nextcloud.forust.xyz
|
url: https://nextcloud.forust.xyz
|
||||||
- title: mc.forust.xyz
|
- title: mc.forust.xyz
|
||||||
|
|||||||
@@ -174,7 +174,7 @@
|
|||||||
<h2>./projects</h2>
|
<h2>./projects</h2>
|
||||||
<ul class="repo-list">
|
<ul class="repo-list">
|
||||||
<li>
|
<li>
|
||||||
<a href="https://git.forust.xyz/forust/gosleep" target="_blank">forust/gosleep</a>
|
<a href="https://gitea.forust.xyz/forust/gosleep" target="_blank">forust/gosleep</a>
|
||||||
<span class="comment">// linux sleep timer written in rust (originally in go)</span>
|
<span class="comment">// linux sleep timer written in rust (originally in go)</span>
|
||||||
</li>
|
</li>
|
||||||
</ul>
|
</ul>
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
RENOVATE_ENDPOINT=https://git.forust.xyz/api/v1
|
RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1
|
||||||
RENOVATE_TOKEN=
|
RENOVATE_TOKEN=
|
||||||
RENOVATE_REPOSITORIES=forust/homelab
|
RENOVATE_REPOSITORIES=forust/homelab
|
||||||
LOG_LEVEL=info
|
LOG_LEVEL=info
|
||||||
@@ -19,7 +19,7 @@ spec:
|
|||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
containers:
|
containers:
|
||||||
- name: renovate
|
- name: renovate
|
||||||
image: renovate/renovate:44.132.2
|
image: renovate/renovate:44.132.4
|
||||||
env:
|
env:
|
||||||
- name: RENOVATE_PLATFORM
|
- name: RENOVATE_PLATFORM
|
||||||
value: gitea
|
value: gitea
|
||||||
|
|||||||
@@ -6,6 +6,6 @@ metadata:
|
|||||||
type: Opaque
|
type: Opaque
|
||||||
stringData:
|
stringData:
|
||||||
RENOVATE_TOKEN: ""
|
RENOVATE_TOKEN: ""
|
||||||
RENOVATE_ENDPOINT: "https://git.forust.xyz/api/v1"
|
RENOVATE_ENDPOINT: "https://gitea.forust.xyz/api/v1"
|
||||||
RENOVATE_REPOSITORIES: "forust/homelab"
|
RENOVATE_REPOSITORIES: "forust/homelab"
|
||||||
RENOVATE_GITHUB_COM_TOKEN: ""
|
RENOVATE_GITHUB_COM_TOKEN: ""
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
PUID=1000
|
|
||||||
PGID=1000
|
|
||||||
TZ=Europe/Berlin
|
|
||||||
Whitespace-only changes.
@@ -1,162 +0,0 @@
|
|||||||
services:
|
|
||||||
jellyfin:
|
|
||||||
image: lscr.io/linuxserver/jellyfin:latest
|
|
||||||
container_name: jellyfin
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- PUID=${PUID:-1000}
|
|
||||||
- PGID=${PGID:-1000}
|
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
|
||||||
volumes:
|
|
||||||
- jellyfin-cfg:/config
|
|
||||||
- movies:/media/movies
|
|
||||||
- tv:/media/tv
|
|
||||||
devices:
|
|
||||||
- /dev/dri:/dev/dri
|
|
||||||
ports:
|
|
||||||
- "18096:8096"
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
|
|
||||||
qbittorrent:
|
|
||||||
image: lscr.io/linuxserver/qbittorrent:latest
|
|
||||||
container_name: qbittorrent
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- PUID=${PUID:-1000}
|
|
||||||
- PGID=${PGID:-1000}
|
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
|
||||||
- WEBUI_PORT=8080
|
|
||||||
volumes:
|
|
||||||
- qbittorrent-cfg:/config
|
|
||||||
- downloads:/downloads
|
|
||||||
ports:
|
|
||||||
- "18180:8080"
|
|
||||||
- "6881:6881"
|
|
||||||
- "6881:6881/udp"
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
|
|
||||||
sonarr:
|
|
||||||
image: lscr.io/linuxserver/sonarr:latest
|
|
||||||
container_name: sonarr
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- PUID=${PUID:-1000}
|
|
||||||
- PGID=${PGID:-1000}
|
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
|
||||||
volumes:
|
|
||||||
- sonarr-cfg:/config
|
|
||||||
- downloads:/downloads
|
|
||||||
- tv:/tv
|
|
||||||
ports:
|
|
||||||
- "18989:8989"
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
|
|
||||||
radarr:
|
|
||||||
image: lscr.io/linuxserver/radarr:latest
|
|
||||||
container_name: radarr
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- PUID=${PUID:-1000}
|
|
||||||
- PGID=${PGID:-1000}
|
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
|
||||||
volumes:
|
|
||||||
- radarr-cfg:/config
|
|
||||||
- downloads:/downloads
|
|
||||||
- movies:/movies
|
|
||||||
ports:
|
|
||||||
- "17878:7878"
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
|
|
||||||
prowlarr:
|
|
||||||
image: lscr.io/linuxserver/prowlarr:latest
|
|
||||||
container_name: prowlarr
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- PUID=${PUID:-1000}
|
|
||||||
- PGID=${PGID:-1000}
|
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
|
||||||
volumes:
|
|
||||||
- prowlarr-cfg:/config
|
|
||||||
ports:
|
|
||||||
- "19696:9696"
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
|
|
||||||
jellyseerr:
|
|
||||||
image: ghcr.io/seerr-team/seerr:latest
|
|
||||||
container_name: jellyseerr
|
|
||||||
init: true
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
|
||||||
volumes:
|
|
||||||
- jellyseerr-cfg:/app/config
|
|
||||||
ports:
|
|
||||||
- "15055:5055"
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
|
|
||||||
bazarr:
|
|
||||||
image: lscr.io/linuxserver/bazarr:latest
|
|
||||||
container_name: bazarr
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- PUID=${PUID:-1000}
|
|
||||||
- PGID=${PGID:-1000}
|
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
|
||||||
volumes:
|
|
||||||
- bazarr-cfg:/config
|
|
||||||
- movies:/movies
|
|
||||||
- tv:/tv
|
|
||||||
ports:
|
|
||||||
- "16767:6767"
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
|
|
||||||
lampac:
|
|
||||||
image: ghcr.io/lampac-nextgen/lampac:latest
|
|
||||||
container_name: lampac
|
|
||||||
restart: unless-stopped
|
|
||||||
shm_size: 1024mb
|
|
||||||
# Restore persisted passwd/init.conf from seed volume before start,
|
|
||||||
# so config survives container recreation (upstream entrypoint is
|
|
||||||
# ENTRYPOINT ["dotnet", "Core.dll"], WORKDIR /lampac, USER lampac).
|
|
||||||
entrypoint:
|
|
||||||
[
|
|
||||||
"/bin/sh",
|
|
||||||
"-c",
|
|
||||||
"if [ -f /seed/passwd ] && [ ! -f /lampac/passwd ]; then cp /seed/passwd /lampac/passwd; fi; if [ -f /seed/init.conf ] && [ ! -f /lampac/init.conf ]; then cp /seed/init.conf /lampac/init.conf; fi; exec /usr/share/dotnet/dotnet Core.dll",
|
|
||||||
]
|
|
||||||
environment:
|
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
|
||||||
volumes:
|
|
||||||
- lampac-seed:/seed
|
|
||||||
- lampac-cache:/lampac/cache
|
|
||||||
- lampac-db:/lampac/database
|
|
||||||
ports:
|
|
||||||
- "19118:9118"
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
jellyfin-cfg:
|
|
||||||
qbittorrent-cfg:
|
|
||||||
sonarr-cfg:
|
|
||||||
radarr-cfg:
|
|
||||||
prowlarr-cfg:
|
|
||||||
jellyseerr-cfg:
|
|
||||||
bazarr-cfg:
|
|
||||||
lampac-seed:
|
|
||||||
lampac-cache:
|
|
||||||
lampac-db:
|
|
||||||
downloads:
|
|
||||||
movies:
|
|
||||||
tv:
|
|
||||||
|
|
||||||
networks:
|
|
||||||
streaming:
|
|
||||||
name: streaming
|
|
||||||
Whitespace-only changes.
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: streaming
|
|
||||||
@@ -1,93 +0,0 @@
|
|||||||
apiVersion: cert-manager.io/v1
|
|
||||||
kind: Certificate
|
|
||||||
metadata:
|
|
||||||
name: internal-wildcard-tls
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
dnsNames:
|
|
||||||
- "*.workstation.internal"
|
|
||||||
- "*.gigaforust.internal"
|
|
||||||
- workstation.internal
|
|
||||||
- gigaforust.internal
|
|
||||||
issuerRef:
|
|
||||||
name: internal-ca
|
|
||||||
kind: ClusterIssuer
|
|
||||||
---
|
|
||||||
apiVersion: cert-manager.io/v1
|
|
||||||
kind: Certificate
|
|
||||||
metadata:
|
|
||||||
name: jelly-prod-tls
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
secretName: jelly-prod-tls
|
|
||||||
dnsNames:
|
|
||||||
- jelly.forust.xyz
|
|
||||||
issuerRef:
|
|
||||||
name: letsencrypt-prod
|
|
||||||
kind: ClusterIssuer
|
|
||||||
---
|
|
||||||
apiVersion: cert-manager.io/v1
|
|
||||||
kind: Certificate
|
|
||||||
metadata:
|
|
||||||
name: seerr-prod-tls
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
secretName: seerr-prod-tls
|
|
||||||
dnsNames:
|
|
||||||
- seerr.forust.xyz
|
|
||||||
issuerRef:
|
|
||||||
name: letsencrypt-prod
|
|
||||||
kind: ClusterIssuer
|
|
||||||
# ---
|
|
||||||
# apiVersion: cert-manager.io/v1
|
|
||||||
# kind: Certificate
|
|
||||||
# metadata:
|
|
||||||
# name: qbittorrent-prod-tls
|
|
||||||
# namespace: streaming
|
|
||||||
# spec:
|
|
||||||
# secretName: qbittorrent-prod-tls
|
|
||||||
# dnsNames:
|
|
||||||
# - qbittorrent.forust.xyz
|
|
||||||
# issuerRef:
|
|
||||||
# name: letsencrypt-prod
|
|
||||||
# kind: ClusterIssuer
|
|
||||||
# ---
|
|
||||||
# apiVersion: cert-manager.io/v1
|
|
||||||
# kind: Certificate
|
|
||||||
# metadata:
|
|
||||||
# name: sonarr-prod-tls
|
|
||||||
# namespace: streaming
|
|
||||||
# spec:
|
|
||||||
# secretName: sonarr-prod-tls
|
|
||||||
# dnsNames:
|
|
||||||
# - sonarr.forust.xyz
|
|
||||||
# issuerRef:
|
|
||||||
# name: letsencrypt-prod
|
|
||||||
# kind: ClusterIssuer
|
|
||||||
# ---
|
|
||||||
# apiVersion: cert-manager.io/v1
|
|
||||||
# kind: Certificate
|
|
||||||
# metadata:
|
|
||||||
# name: radarr-prod-tls
|
|
||||||
# namespace: streaming
|
|
||||||
# spec:
|
|
||||||
# secretName: radarr-prod-tls
|
|
||||||
# dnsNames:
|
|
||||||
# - radarr.forust.xyz
|
|
||||||
# issuerRef:
|
|
||||||
# name: letsencrypt-prod
|
|
||||||
# kind: ClusterIssuer
|
|
||||||
# ---
|
|
||||||
# apiVersion: cert-manager.io/v1
|
|
||||||
# kind: Certificate
|
|
||||||
# metadata:
|
|
||||||
# name: prowlarr-prod-tls
|
|
||||||
# namespace: streaming
|
|
||||||
# spec:
|
|
||||||
# secretName: prowlarr-prod-tls
|
|
||||||
# dnsNames:
|
|
||||||
# - prowlarr.forust.xyz
|
|
||||||
# issuerRef:
|
|
||||||
# name: letsencrypt-prod
|
|
||||||
# kind: ClusterIssuer
|
|
||||||
@@ -1,215 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: jellyfin
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: 18096
|
|
||||||
targetPort: 18096
|
|
||||||
---
|
|
||||||
apiVersion: discovery.k8s.io/v1
|
|
||||||
kind: EndpointSlice
|
|
||||||
metadata:
|
|
||||||
name: jellyfin
|
|
||||||
namespace: streaming
|
|
||||||
labels:
|
|
||||||
kubernetes.io/service-name: jellyfin
|
|
||||||
addressType: IPv4
|
|
||||||
ports:
|
|
||||||
- port: 18096
|
|
||||||
protocol: TCP
|
|
||||||
endpoints:
|
|
||||||
- addresses:
|
|
||||||
- "192.168.88.100"
|
|
||||||
conditions:
|
|
||||||
ready: true
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: qbittorrent
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: 18180
|
|
||||||
targetPort: 18180
|
|
||||||
---
|
|
||||||
apiVersion: discovery.k8s.io/v1
|
|
||||||
kind: EndpointSlice
|
|
||||||
metadata:
|
|
||||||
name: qbittorrent
|
|
||||||
namespace: streaming
|
|
||||||
labels:
|
|
||||||
kubernetes.io/service-name: qbittorrent
|
|
||||||
addressType: IPv4
|
|
||||||
ports:
|
|
||||||
- port: 18180
|
|
||||||
protocol: TCP
|
|
||||||
endpoints:
|
|
||||||
- addresses:
|
|
||||||
- "192.168.88.100"
|
|
||||||
conditions:
|
|
||||||
ready: true
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: sonarr
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: 18989
|
|
||||||
targetPort: 18989
|
|
||||||
---
|
|
||||||
apiVersion: discovery.k8s.io/v1
|
|
||||||
kind: EndpointSlice
|
|
||||||
metadata:
|
|
||||||
name: sonarr
|
|
||||||
namespace: streaming
|
|
||||||
labels:
|
|
||||||
kubernetes.io/service-name: sonarr
|
|
||||||
addressType: IPv4
|
|
||||||
ports:
|
|
||||||
- port: 18989
|
|
||||||
protocol: TCP
|
|
||||||
endpoints:
|
|
||||||
- addresses:
|
|
||||||
- "192.168.88.100"
|
|
||||||
conditions:
|
|
||||||
ready: true
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: radarr
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: 17878
|
|
||||||
targetPort: 17878
|
|
||||||
---
|
|
||||||
apiVersion: discovery.k8s.io/v1
|
|
||||||
kind: EndpointSlice
|
|
||||||
metadata:
|
|
||||||
name: radarr
|
|
||||||
namespace: streaming
|
|
||||||
labels:
|
|
||||||
kubernetes.io/service-name: radarr
|
|
||||||
addressType: IPv4
|
|
||||||
ports:
|
|
||||||
- port: 17878
|
|
||||||
protocol: TCP
|
|
||||||
endpoints:
|
|
||||||
- addresses:
|
|
||||||
- "192.168.88.100"
|
|
||||||
conditions:
|
|
||||||
ready: true
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: prowlarr
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: 19696
|
|
||||||
targetPort: 19696
|
|
||||||
---
|
|
||||||
apiVersion: discovery.k8s.io/v1
|
|
||||||
kind: EndpointSlice
|
|
||||||
metadata:
|
|
||||||
name: prowlarr
|
|
||||||
namespace: streaming
|
|
||||||
labels:
|
|
||||||
kubernetes.io/service-name: prowlarr
|
|
||||||
addressType: IPv4
|
|
||||||
ports:
|
|
||||||
- port: 19696
|
|
||||||
protocol: TCP
|
|
||||||
endpoints:
|
|
||||||
- addresses:
|
|
||||||
- "192.168.88.100"
|
|
||||||
conditions:
|
|
||||||
ready: true
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: jellyseerr
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: 15055
|
|
||||||
targetPort: 15055
|
|
||||||
---
|
|
||||||
apiVersion: discovery.k8s.io/v1
|
|
||||||
kind: EndpointSlice
|
|
||||||
metadata:
|
|
||||||
name: jellyseerr
|
|
||||||
namespace: streaming
|
|
||||||
labels:
|
|
||||||
kubernetes.io/service-name: jellyseerr
|
|
||||||
addressType: IPv4
|
|
||||||
ports:
|
|
||||||
- port: 15055
|
|
||||||
protocol: TCP
|
|
||||||
endpoints:
|
|
||||||
- addresses:
|
|
||||||
- "192.168.88.100"
|
|
||||||
conditions:
|
|
||||||
ready: true
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: bazarr
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: 16767
|
|
||||||
targetPort: 16767
|
|
||||||
---
|
|
||||||
apiVersion: discovery.k8s.io/v1
|
|
||||||
kind: EndpointSlice
|
|
||||||
metadata:
|
|
||||||
name: bazarr
|
|
||||||
namespace: streaming
|
|
||||||
labels:
|
|
||||||
kubernetes.io/service-name: bazarr
|
|
||||||
addressType: IPv4
|
|
||||||
ports:
|
|
||||||
- port: 16767
|
|
||||||
protocol: TCP
|
|
||||||
endpoints:
|
|
||||||
- addresses:
|
|
||||||
- "192.168.88.100"
|
|
||||||
conditions:
|
|
||||||
ready: true
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: lampac
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: 19118
|
|
||||||
targetPort: 19118
|
|
||||||
---
|
|
||||||
apiVersion: discovery.k8s.io/v1
|
|
||||||
kind: EndpointSlice
|
|
||||||
metadata:
|
|
||||||
name: lampac
|
|
||||||
namespace: streaming
|
|
||||||
labels:
|
|
||||||
kubernetes.io/service-name: lampac
|
|
||||||
addressType: IPv4
|
|
||||||
ports:
|
|
||||||
- port: 19118
|
|
||||||
protocol: TCP
|
|
||||||
endpoints:
|
|
||||||
- addresses:
|
|
||||||
- "192.168.88.100"
|
|
||||||
conditions:
|
|
||||||
ready: true
|
|
||||||
@@ -1,169 +0,0 @@
|
|||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: jellyfin-local
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`jellyfin.workstation.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: jellyfin
|
|
||||||
port: 18096
|
|
||||||
tls:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: qbittorrent-local
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`qbittorrent.workstation.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: qbittorrent
|
|
||||||
port: 18180
|
|
||||||
tls:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: sonarr-local
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`sonarr.workstation.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: sonarr
|
|
||||||
port: 18989
|
|
||||||
tls:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: radarr-local
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`radarr.workstation.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: radarr
|
|
||||||
port: 17878
|
|
||||||
tls:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: prowlarr-local
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`prowlarr.workstation.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: prowlarr
|
|
||||||
port: 19696
|
|
||||||
tls:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: jellyseerr-local
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`jellyseerr.workstation.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: jellyseerr
|
|
||||||
port: 15055
|
|
||||||
tls:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: bazarr-local
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`bazarr.workstation.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: bazarr
|
|
||||||
port: 16767
|
|
||||||
tls:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: lampac-local
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`lampac.workstation.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: lampac
|
|
||||||
port: 19118
|
|
||||||
tls:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: jellyfin-prod
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`jelly.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: jellyfin
|
|
||||||
port: 18096
|
|
||||||
tls:
|
|
||||||
secretName: jelly-prod-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: seerr-prod
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`seerr.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: jellyseerr
|
|
||||||
port: 15055
|
|
||||||
tls:
|
|
||||||
secretName: seerr-prod-tls
|
|
||||||
@@ -10,8 +10,6 @@ spec:
|
|||||||
routes:
|
routes:
|
||||||
- match: Host(`traefik.forust.xyz`)
|
- match: Host(`traefik.forust.xyz`)
|
||||||
kind: Rule
|
kind: Rule
|
||||||
middlewares:
|
|
||||||
- name: security-chain@file
|
|
||||||
services:
|
services:
|
||||||
- name: api@internal
|
- name: api@internal
|
||||||
kind: TraefikService
|
kind: TraefikService
|
||||||
|
|||||||
@@ -1,40 +0,0 @@
|
|||||||
apiVersion: monitoring.coreos.com/v1
|
|
||||||
kind: PrometheusRule
|
|
||||||
metadata:
|
|
||||||
name: uptime-kuma
|
|
||||||
namespace: uptime-kuma
|
|
||||||
labels:
|
|
||||||
release: prometheus-stack
|
|
||||||
spec:
|
|
||||||
groups:
|
|
||||||
- name: uptime_kuma.monitors
|
|
||||||
rules:
|
|
||||||
- alert: KumaMonitorDown
|
|
||||||
expr: |
|
|
||||||
monitor_status{monitor_type!="group"} == 0
|
|
||||||
for: 5m
|
|
||||||
labels:
|
|
||||||
severity: critical
|
|
||||||
annotations:
|
|
||||||
summary: "Uptime Kuma monitor down: {{ $labels.monitor_name }}"
|
|
||||||
description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) is down for 5m. Check Uptime Kuma (https://uptime.forust.xyz) and the target service."
|
|
||||||
|
|
||||||
- alert: KumaScrapeDown
|
|
||||||
expr: |
|
|
||||||
absent(monitor_status) == 1
|
|
||||||
for: 10m
|
|
||||||
labels:
|
|
||||||
severity: critical
|
|
||||||
annotations:
|
|
||||||
summary: "Uptime Kuma metrics missing"
|
|
||||||
description: "uptime-kuma: no monitor_status series for 10m. Pod may be down, the uk1_ API key may have been rotated without updating uptime-kuma-secrets, or ServiceMonitor/Service broken. All Kuma monitors are unobserved."
|
|
||||||
|
|
||||||
- alert: KumaCertExpiring
|
|
||||||
expr: |
|
|
||||||
monitor_cert_days_remaining < 14
|
|
||||||
for: 1h
|
|
||||||
labels:
|
|
||||||
severity: warning
|
|
||||||
annotations:
|
|
||||||
summary: "TLS cert expiring: {{ $labels.monitor_name }} ({{ $value }}d left)"
|
|
||||||
description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) reports a TLS certificate with {{ $value }} days remaining. Check cert-manager Certificate for this host."
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: uptime-kuma-secrets
|
|
||||||
namespace: uptime-kuma
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
metrics-username: "uptime-kuma"
|
|
||||||
metrics-password: "REPLACE_ME"
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
apiVersion: monitoring.coreos.com/v1
|
|
||||||
kind: ServiceMonitor
|
|
||||||
metadata:
|
|
||||||
name: uptime-kuma
|
|
||||||
namespace: uptime-kuma
|
|
||||||
labels:
|
|
||||||
release: prometheus-stack
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: uptime-kuma
|
|
||||||
endpoints:
|
|
||||||
- port: http
|
|
||||||
path: /metrics
|
|
||||||
interval: 60s
|
|
||||||
scrapeTimeout: 15s
|
|
||||||
basicAuth:
|
|
||||||
username:
|
|
||||||
name: uptime-kuma-secrets
|
|
||||||
key: metrics-username
|
|
||||||
password:
|
|
||||||
name: uptime-kuma-secrets
|
|
||||||
key: metrics-password
|
|
||||||
@@ -3,14 +3,11 @@ kind: Service
|
|||||||
metadata:
|
metadata:
|
||||||
name: uptime-kuma-service
|
name: uptime-kuma-service
|
||||||
namespace: uptime-kuma
|
namespace: uptime-kuma
|
||||||
labels:
|
|
||||||
app: uptime-kuma
|
|
||||||
spec:
|
spec:
|
||||||
selector:
|
selector:
|
||||||
app: uptime-kuma
|
app: uptime-kuma
|
||||||
ports:
|
ports:
|
||||||
- port: 3001
|
- port: 3001
|
||||||
name: http
|
|
||||||
targetPort: 3001
|
targetPort: 3001
|
||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
|
|||||||
Reference in new issue
Block a user