Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d9e6a52cd5 |
No files matched your search
@@ -81,7 +81,7 @@ jobs:
|
||||
docker run --rm \
|
||||
-v "$PWD/renovate/renovate.json:/opt/renovate/renovate.json:ro" \
|
||||
-e RENOVATE_PLATFORM=gitea \
|
||||
-e RENOVATE_ENDPOINT=https://git.forust.xyz/api/v1 \
|
||||
-e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \
|
||||
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
|
||||
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
|
||||
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
|
||||
|
||||
@@ -68,6 +68,35 @@ spec:
|
||||
reloader.stakater.com/auto: "true"
|
||||
spec:
|
||||
containers:
|
||||
- name: netbird
|
||||
image: netbirdio/netbird:0.80.0
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: adguard-config
|
||||
env:
|
||||
- name: NB_SETUP_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: adguard-netbird-secrets
|
||||
key: NB_SETUP_KEY
|
||||
securityContext:
|
||||
capabilities:
|
||||
add:
|
||||
- NET_ADMIN
|
||||
- SYS_ADMIN
|
||||
- SYS_RESOURCE
|
||||
resources:
|
||||
requests:
|
||||
memory: "64Mi"
|
||||
cpu: "50m"
|
||||
limits:
|
||||
memory: "256Mi"
|
||||
cpu: "200m"
|
||||
volumeMounts:
|
||||
- name: netbird-state
|
||||
mountPath: /var/lib/netbird
|
||||
- name: dev-tun
|
||||
mountPath: /dev/net/tun
|
||||
- name: adguard
|
||||
image: adguard/adguardhome:v0.107.79
|
||||
resources:
|
||||
@@ -84,13 +113,6 @@ spec:
|
||||
name: dns
|
||||
- containerPort: 853
|
||||
name: dot
|
||||
readinessProbe:
|
||||
tcpSocket:
|
||||
port: dns
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 5
|
||||
successThreshold: 1
|
||||
failureThreshold: 3
|
||||
volumeMounts:
|
||||
- name: adguard-data
|
||||
mountPath: /opt/adguardhome/work
|
||||
@@ -102,6 +124,12 @@ spec:
|
||||
mountPath: /certs
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: netbird-state
|
||||
emptyDir: {}
|
||||
- name: dev-tun
|
||||
hostPath:
|
||||
path: /dev/net/tun
|
||||
type: CharDevice
|
||||
- name: adguard-data
|
||||
persistentVolumeClaim:
|
||||
claimName: adguard-pvc
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: adguard-config
|
||||
namespace: adguard
|
||||
data:
|
||||
NB_MANAGEMENT_URL: "https://nb.forust.xyz"
|
||||
NB_HOSTNAME: "adguard"
|
||||
NB_LOG_LEVEL: "info"
|
||||
NB_DISABLE_DNS: "true"
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: adguard-netbird-secrets
|
||||
namespace: adguard
|
||||
type: Opaque
|
||||
stringData:
|
||||
NB_SETUP_KEY: "REPLACE_ME"
|
||||
+2
-5
@@ -13,12 +13,9 @@ services:
|
||||
- GITEA__database__PASSWD=gitea
|
||||
- GITEA__database__NAME=gitea
|
||||
# Server
|
||||
- GITEA__server__ROOT_URL=https://git.forust.xyz
|
||||
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
||||
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
|
||||
- GITEA__server__SSH_PORT=2221
|
||||
# Pin 28.0 defaults explicitly (see k8s/config.yaml for rationale)
|
||||
- GITEA__service__DISABLE_REGISTRATION=true
|
||||
- GITEA__actions__RUN_RETENTION_DAYS=90
|
||||
# Mailer
|
||||
- GITEA__mailer__ENABLED=true
|
||||
- GITEA__mailer__FROM=${SERVICE_EMAIL}
|
||||
@@ -37,7 +34,7 @@ services:
|
||||
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.gitea.rule=Host(`git.forust.xyz`) || Host(`gitea.forust.xyz`)"
|
||||
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
||||
- "traefik.http.routers.gitea.entrypoints=websecure"
|
||||
- "traefik.http.routers.gitea.tls.certresolver"
|
||||
# Local Router
|
||||
|
||||
@@ -4,14 +4,11 @@ metadata:
|
||||
name: gitea-config
|
||||
namespace: gitea
|
||||
data:
|
||||
GITEA__server__ROOT_URL: "https://git.forust.xyz"
|
||||
GITEA__server__DOMAIN: "gitea.forust.xyz"
|
||||
GITEA__server__ROOT_URL: "https://gitea.forust.xyz"
|
||||
GITEA__server__SSH_DOMAIN: "gitssh.forust.xyz"
|
||||
GITEA__server__SSH_PORT: "2221"
|
||||
|
||||
GITEA__service__DISABLE_REGISTRATION: "true"
|
||||
|
||||
GITEA__actions__RUN_RETENTION_DAYS: "90"
|
||||
|
||||
GITEA__database__DB_TYPE: "postgres"
|
||||
GITEA__database__HOST: "postgres.database.svc.cluster.local:5432"
|
||||
GITEA__database__NAME: "gitea"
|
||||
|
||||
@@ -177,8 +177,8 @@ data:
|
||||
# url: https://gitssh.forust.xyz
|
||||
# - title: gcr.forust.xyz
|
||||
# url: https://gcr.forust.xyz/v2/
|
||||
- title: git.forust.xyz
|
||||
url: https://git.forust.xyz
|
||||
- title: gitea.forust.xyz
|
||||
url: https://gitea.forust.xyz
|
||||
- title: nextcloud.forust.xyz
|
||||
url: https://nextcloud.forust.xyz
|
||||
- title: mc.forust.xyz
|
||||
|
||||
@@ -69,7 +69,7 @@ spec:
|
||||
name: glance-config
|
||||
- name: glance-assets
|
||||
configMap:
|
||||
name: glance-assets
|
||||
name: glance-config
|
||||
- name: docker-socket
|
||||
hostPath:
|
||||
path: /var/run/docker.sock
|
||||
|
||||
@@ -1,4 +0,0 @@
|
||||
SECRET_ENCRYPTION_KEY="REPLACE_ME"
|
||||
TZ="Europe/Bratislava"
|
||||
PUID="1000"
|
||||
PGID="1000"
|
||||
@@ -1,38 +0,0 @@
|
||||
services:
|
||||
homarr:
|
||||
container_name: homarr
|
||||
image: ghcr.io/homarr-labs/homarr:v2.1.2
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./appdata:/appdata
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- ./kubeconfig:/app/config/kubeconfig:ro
|
||||
env_file: .env
|
||||
ports:
|
||||
- 80:7575
|
||||
- 81:3000
|
||||
environment:
|
||||
- TZ=${TZ:-Europe/Bratislava}
|
||||
- TURBO_TELEMETRY_DISABLED=1
|
||||
- KUBECONFIG=/app/config/kubeconfig
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.homarr.loadbalancer.server.port=7575"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.homarr.rule=Host(`homarr.forust.xyz`)"
|
||||
- "traefik.http.routers.homarr.entrypoints=websecure"
|
||||
- "traefik.http.routers.homarr.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.homarr-local.rule=Host(`homarr.workstation.internal`)"
|
||||
- "traefik.http.routers.homarr-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.homarr-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.homarr-dev.rule=Host(`homarr.gigaforust.internal`)"
|
||||
- "traefik.http.routers.homarr-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.homarr-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -1,28 +0,0 @@
|
||||
# apiVersion: cert-manager.io/v1
|
||||
# kind: Certificate
|
||||
# metadata:
|
||||
# name: home-prod-tls
|
||||
# namespace: homarr
|
||||
# spec:
|
||||
# secretName: home-prod-tls
|
||||
# dnsNames:
|
||||
# - home.forust.xyz
|
||||
# issuerRef:
|
||||
# name: letsencrypt-prod
|
||||
# kind: ClusterIssuer
|
||||
# ---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: homarr
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -1,9 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: homarr-config
|
||||
namespace: homarr
|
||||
data:
|
||||
TZ: "Europe/Bratislava"
|
||||
TURBO_TELEMETRY_DISABLED: "1"
|
||||
ENABLE_KUBERNETES: "true"
|
||||
@@ -1,81 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: homarr-service
|
||||
namespace: homarr
|
||||
spec:
|
||||
selector:
|
||||
app: homarr
|
||||
ports:
|
||||
- port: 7575
|
||||
targetPort: 7575
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: homarr-deployment
|
||||
namespace: homarr
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: homarr
|
||||
strategy:
|
||||
type: Recreate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: homarr
|
||||
spec:
|
||||
serviceAccountName: homarr
|
||||
containers:
|
||||
- name: homarr
|
||||
image: ghcr.io/homarr-labs/homarr:v2.1.2
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: homarr-config
|
||||
- secretRef:
|
||||
name: homarr-secrets
|
||||
ports:
|
||||
- containerPort: 7575
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /
|
||||
port: 7575
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 10
|
||||
failureThreshold: 6
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /
|
||||
port: 7575
|
||||
initialDelaySeconds: 60
|
||||
periodSeconds: 30
|
||||
failureThreshold: 3
|
||||
volumeMounts:
|
||||
- name: homarr-data
|
||||
mountPath: /appdata
|
||||
resources:
|
||||
requests:
|
||||
cpu: "250m"
|
||||
memory: "350Mi"
|
||||
limits:
|
||||
cpu: "500m"
|
||||
memory: "700Mi"
|
||||
volumes:
|
||||
- name: homarr-data
|
||||
persistentVolumeClaim:
|
||||
claimName: homarr-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: homarr-pvc
|
||||
namespace: homarr
|
||||
spec:
|
||||
resources:
|
||||
requests:
|
||||
storage: 2Gi
|
||||
volumeMode: Filesystem
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
@@ -1,33 +0,0 @@
|
||||
# apiVersion: traefik.io/v1alpha1
|
||||
# kind: IngressRoute
|
||||
# metadata:
|
||||
# name: homarr-prod
|
||||
# namespace: homarr
|
||||
# spec:
|
||||
# entryPoints:
|
||||
# - websecure
|
||||
# routes:
|
||||
# - match: Host(`home.forust.xyz`)
|
||||
# kind: Rule
|
||||
# services:
|
||||
# - name: homarr-service
|
||||
# port: 7575
|
||||
# tls:
|
||||
# secretName: home-prod-tls
|
||||
# ---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: homarr-local
|
||||
namespace: homarr
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`home.workstation.internal`) || Host(`home.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: homarr-service
|
||||
port: 7575
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -1,4 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: homarr
|
||||
@@ -1,58 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: homarr
|
||||
namespace: homarr
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: homarr-readonly
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- endpoints
|
||||
- namespaces
|
||||
- nodes
|
||||
- configmaps
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["apps"]
|
||||
resources:
|
||||
- deployments
|
||||
- statefulsets
|
||||
- daemonsets
|
||||
- replicasets
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["networking.k8s.io"]
|
||||
resources:
|
||||
- ingresses
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["traefik.io"]
|
||||
resources:
|
||||
- ingressroutes
|
||||
- ingressroutetcps
|
||||
- ingressrouteudps
|
||||
- middlewares
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["metrics.k8s.io"]
|
||||
resources:
|
||||
- pods
|
||||
- nodes
|
||||
verbs: ["get", "list"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: homarr-readonly
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: homarr-readonly
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: homarr
|
||||
namespace: homarr
|
||||
@@ -1,9 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: homarr-secrets
|
||||
namespace: homarr
|
||||
type: Opaque
|
||||
stringData:
|
||||
# openssl rand -hex 32
|
||||
SECRET_ENCRYPTION_KEY: "REPLACE_ME"
|
||||
@@ -174,7 +174,7 @@
|
||||
<h2>./projects</h2>
|
||||
<ul class="repo-list">
|
||||
<li>
|
||||
<a href="https://git.forust.xyz/forust/gosleep" target="_blank">forust/gosleep</a>
|
||||
<a href="https://gitea.forust.xyz/forust/gosleep" target="_blank">forust/gosleep</a>
|
||||
<span class="comment">// linux sleep timer written in rust (originally in go)</span>
|
||||
</li>
|
||||
</ul>
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
n8n:
|
||||
image: docker.n8n.io/n8nio/n8n:2.42.3
|
||||
image: docker.n8n.io/n8nio/n8n:2.42.2
|
||||
container_name: n8n
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
|
||||
+1
-1
@@ -29,7 +29,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: n8n
|
||||
image: docker.n8n.io/n8nio/n8n:2.42.3
|
||||
image: docker.n8n.io/n8nio/n8n:2.42.2
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: n8n-config
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
RENOVATE_ENDPOINT=https://git.forust.xyz/api/v1
|
||||
RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1
|
||||
RENOVATE_TOKEN=
|
||||
RENOVATE_REPOSITORIES=forust/homelab
|
||||
LOG_LEVEL=info
|
||||
@@ -218,34 +218,6 @@ data:
|
||||
"matchUpdateTypes": ["patch"],
|
||||
"groupName": "all patch updates",
|
||||
"groupSlug": "all-patch"
|
||||
},
|
||||
{
|
||||
"description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.",
|
||||
"matchDatasources": ["docker"],
|
||||
"matchPackageNames": ["python"],
|
||||
"groupName": "python base image",
|
||||
"groupSlug": "python",
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
"description": "Rolling/floating tags (streaming stack, nextcloud beta, kubectl latest) - never automerge, every bump is a manual review. Placed last so automerge:false wins over the shared digest/patch rule.",
|
||||
"matchDatasources": ["docker"],
|
||||
"matchPackageNames": [
|
||||
"lscr.io/linuxserver/jellyfin",
|
||||
"lscr.io/linuxserver/qbittorrent",
|
||||
"lscr.io/linuxserver/sonarr",
|
||||
"lscr.io/linuxserver/radarr",
|
||||
"lscr.io/linuxserver/prowlarr",
|
||||
"lscr.io/linuxserver/bazarr",
|
||||
"ghcr.io/seerr-team/seerr",
|
||||
"fallenbagel/jellyseerr",
|
||||
"ghcr.io/lampac-nextgen/lampac",
|
||||
"ghcr.io/nextcloud-releases/all-in-one",
|
||||
"alpine/kubectl"
|
||||
],
|
||||
"groupName": "floating images - manual",
|
||||
"groupSlug": "floating-manual",
|
||||
"automerge": false
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -19,7 +19,7 @@ spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: renovate
|
||||
image: renovate/renovate:44.136.0
|
||||
image: renovate/renovate:44.132.5
|
||||
env:
|
||||
- name: RENOVATE_PLATFORM
|
||||
value: gitea
|
||||
|
||||
@@ -6,6 +6,6 @@ metadata:
|
||||
type: Opaque
|
||||
stringData:
|
||||
RENOVATE_TOKEN: ""
|
||||
RENOVATE_ENDPOINT: "https://git.forust.xyz/api/v1"
|
||||
RENOVATE_ENDPOINT: "https://gitea.forust.xyz/api/v1"
|
||||
RENOVATE_REPOSITORIES: "forust/homelab"
|
||||
RENOVATE_GITHUB_COM_TOKEN: ""
|
||||
@@ -207,34 +207,6 @@
|
||||
"matchUpdateTypes": ["patch"],
|
||||
"groupName": "all patch updates",
|
||||
"groupSlug": "all-patch"
|
||||
},
|
||||
{
|
||||
"description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.",
|
||||
"matchDatasources": ["docker"],
|
||||
"matchPackageNames": ["python"],
|
||||
"groupName": "python base image",
|
||||
"groupSlug": "python",
|
||||
"automerge": false
|
||||
},
|
||||
{
|
||||
"description": "Rolling/floating tags (streaming stack, nextcloud beta, kubectl latest) - never automerge, every bump is a manual review. Placed last so automerge:false wins over the shared digest/patch rule.",
|
||||
"matchDatasources": ["docker"],
|
||||
"matchPackageNames": [
|
||||
"lscr.io/linuxserver/jellyfin",
|
||||
"lscr.io/linuxserver/qbittorrent",
|
||||
"lscr.io/linuxserver/sonarr",
|
||||
"lscr.io/linuxserver/radarr",
|
||||
"lscr.io/linuxserver/prowlarr",
|
||||
"lscr.io/linuxserver/bazarr",
|
||||
"ghcr.io/seerr-team/seerr",
|
||||
"fallenbagel/jellyseerr",
|
||||
"ghcr.io/lampac-nextgen/lampac",
|
||||
"ghcr.io/nextcloud-releases/all-in-one",
|
||||
"alpine/kubectl"
|
||||
],
|
||||
"groupName": "floating images - manual",
|
||||
"groupSlug": "floating-manual",
|
||||
"automerge": false
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -1,3 +0,0 @@
|
||||
PUID=1000
|
||||
PGID=1000
|
||||
TZ=Europe/Berlin
|
||||
Whitespace-only changes.
@@ -1,133 +0,0 @@
|
||||
services:
|
||||
jellyfin:
|
||||
image: lscr.io/linuxserver/jellyfin:version-12.1ubu2604
|
||||
container_name: jellyfin
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- PUID=${PUID:-1000}
|
||||
- PGID=${PGID:-1000}
|
||||
- TZ=${TZ:-Europe/Berlin}
|
||||
volumes:
|
||||
- jellyfin-cfg:/config
|
||||
- movies:/media/movies
|
||||
- tv:/media/tv
|
||||
devices:
|
||||
- /dev/dri:/dev/dri
|
||||
ports:
|
||||
- "18096:8096"
|
||||
networks:
|
||||
- streaming
|
||||
|
||||
qbittorrent:
|
||||
image: lscr.io/linuxserver/qbittorrent:5.2.4
|
||||
container_name: qbittorrent
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- PUID=${PUID:-1000}
|
||||
- PGID=${PGID:-1000}
|
||||
- TZ=${TZ:-Europe/Berlin}
|
||||
- WEBUI_PORT=8080
|
||||
volumes:
|
||||
- qbittorrent-cfg:/config
|
||||
- downloads:/downloads
|
||||
ports:
|
||||
- "18180:8080"
|
||||
- "6881:6881"
|
||||
- "6881:6881/udp"
|
||||
networks:
|
||||
- streaming
|
||||
|
||||
sonarr:
|
||||
image: lscr.io/linuxserver/sonarr:4.0.20
|
||||
container_name: sonarr
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- PUID=${PUID:-1000}
|
||||
- PGID=${PGID:-1000}
|
||||
- TZ=${TZ:-Europe/Berlin}
|
||||
volumes:
|
||||
- sonarr-cfg:/config
|
||||
- downloads:/downloads
|
||||
- tv:/tv
|
||||
ports:
|
||||
- "18989:8989"
|
||||
networks:
|
||||
- streaming
|
||||
|
||||
radarr:
|
||||
image: lscr.io/linuxserver/radarr:6.4.4
|
||||
container_name: radarr
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- PUID=${PUID:-1000}
|
||||
- PGID=${PGID:-1000}
|
||||
- TZ=${TZ:-Europe/Berlin}
|
||||
volumes:
|
||||
- radarr-cfg:/config
|
||||
- downloads:/downloads
|
||||
- movies:/movies
|
||||
ports:
|
||||
- "17878:7878"
|
||||
networks:
|
||||
- streaming
|
||||
|
||||
prowlarr:
|
||||
image: lscr.io/linuxserver/prowlarr:2.6.5
|
||||
container_name: prowlarr
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- PUID=${PUID:-1000}
|
||||
- PGID=${PGID:-1000}
|
||||
- TZ=${TZ:-Europe/Berlin}
|
||||
volumes:
|
||||
- prowlarr-cfg:/config
|
||||
ports:
|
||||
- "19696:9696"
|
||||
networks:
|
||||
- streaming
|
||||
|
||||
jellyseerr:
|
||||
image: fallenbagel/jellyseerr:latest
|
||||
container_name: jellyseerr
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- TZ=${TZ:-Europe/Berlin}
|
||||
volumes:
|
||||
- jellyseerr-cfg:/app/config
|
||||
ports:
|
||||
- "15055:5055"
|
||||
networks:
|
||||
- streaming
|
||||
|
||||
bazarr:
|
||||
image: lscr.io/linuxserver/bazarr:1.6.2
|
||||
container_name: bazarr
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- PUID=${PUID:-1000}
|
||||
- PGID=${PGID:-1000}
|
||||
- TZ=${TZ:-Europe/Berlin}
|
||||
volumes:
|
||||
- bazarr-cfg:/config
|
||||
- movies:/movies
|
||||
- tv:/tv
|
||||
ports:
|
||||
- "16767:6767"
|
||||
networks:
|
||||
- streaming
|
||||
|
||||
volumes:
|
||||
jellyfin-cfg:
|
||||
qbittorrent-cfg:
|
||||
sonarr-cfg:
|
||||
radarr-cfg:
|
||||
prowlarr-cfg:
|
||||
jellyseerr-cfg:
|
||||
bazarr-cfg:
|
||||
downloads:
|
||||
movies:
|
||||
tv:
|
||||
|
||||
networks:
|
||||
streaming:
|
||||
name: streaming
|
||||
Whitespace-only changes.
@@ -1,4 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: streaming
|
||||
@@ -1,93 +0,0 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: streaming
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
# ---
|
||||
# apiVersion: cert-manager.io/v1
|
||||
# kind: Certificate
|
||||
# metadata:
|
||||
# name: jellyfin-prod-tls
|
||||
# namespace: streaming
|
||||
# spec:
|
||||
# secretName: jellyfin-prod-tls
|
||||
# dnsNames:
|
||||
# - jellyfin.forust.xyz
|
||||
# issuerRef:
|
||||
# name: letsencrypt-prod
|
||||
# kind: ClusterIssuer
|
||||
# ---
|
||||
# apiVersion: cert-manager.io/v1
|
||||
# kind: Certificate
|
||||
# metadata:
|
||||
# name: qbittorrent-prod-tls
|
||||
# namespace: streaming
|
||||
# spec:
|
||||
# secretName: qbittorrent-prod-tls
|
||||
# dnsNames:
|
||||
# - qbittorrent.forust.xyz
|
||||
# issuerRef:
|
||||
# name: letsencrypt-prod
|
||||
# kind: ClusterIssuer
|
||||
# ---
|
||||
# apiVersion: cert-manager.io/v1
|
||||
# kind: Certificate
|
||||
# metadata:
|
||||
# name: sonarr-prod-tls
|
||||
# namespace: streaming
|
||||
# spec:
|
||||
# secretName: sonarr-prod-tls
|
||||
# dnsNames:
|
||||
# - sonarr.forust.xyz
|
||||
# issuerRef:
|
||||
# name: letsencrypt-prod
|
||||
# kind: ClusterIssuer
|
||||
# ---
|
||||
# apiVersion: cert-manager.io/v1
|
||||
# kind: Certificate
|
||||
# metadata:
|
||||
# name: radarr-prod-tls
|
||||
# namespace: streaming
|
||||
# spec:
|
||||
# secretName: radarr-prod-tls
|
||||
# dnsNames:
|
||||
# - radarr.forust.xyz
|
||||
# issuerRef:
|
||||
# name: letsencrypt-prod
|
||||
# kind: ClusterIssuer
|
||||
# ---
|
||||
# apiVersion: cert-manager.io/v1
|
||||
# kind: Certificate
|
||||
# metadata:
|
||||
# name: prowlarr-prod-tls
|
||||
# namespace: streaming
|
||||
# spec:
|
||||
# secretName: prowlarr-prod-tls
|
||||
# dnsNames:
|
||||
# - prowlarr.forust.xyz
|
||||
# issuerRef:
|
||||
# name: letsencrypt-prod
|
||||
# kind: ClusterIssuer
|
||||
# ---
|
||||
# apiVersion: cert-manager.io/v1
|
||||
# kind: Certificate
|
||||
# metadata:
|
||||
# name: jellyseerr-prod-tls
|
||||
# namespace: streaming
|
||||
# spec:
|
||||
# secretName: jellyseerr-prod-tls
|
||||
# dnsNames:
|
||||
# - jellyseerr.forust.xyz
|
||||
# issuerRef:
|
||||
# name: letsencrypt-prod
|
||||
# kind: ClusterIssuer
|
||||
@@ -1,188 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: jellyfin
|
||||
namespace: streaming
|
||||
spec:
|
||||
ports:
|
||||
- port: 18096
|
||||
targetPort: 18096
|
||||
---
|
||||
apiVersion: discovery.k8s.io/v1
|
||||
kind: EndpointSlice
|
||||
metadata:
|
||||
name: jellyfin
|
||||
namespace: streaming
|
||||
labels:
|
||||
kubernetes.io/service-name: jellyfin
|
||||
addressType: IPv4
|
||||
ports:
|
||||
- port: 18096
|
||||
protocol: TCP
|
||||
endpoints:
|
||||
- addresses:
|
||||
- "192.168.88.100"
|
||||
conditions:
|
||||
ready: true
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: qbittorrent
|
||||
namespace: streaming
|
||||
spec:
|
||||
ports:
|
||||
- port: 18180
|
||||
targetPort: 18180
|
||||
---
|
||||
apiVersion: discovery.k8s.io/v1
|
||||
kind: EndpointSlice
|
||||
metadata:
|
||||
name: qbittorrent
|
||||
namespace: streaming
|
||||
labels:
|
||||
kubernetes.io/service-name: qbittorrent
|
||||
addressType: IPv4
|
||||
ports:
|
||||
- port: 18180
|
||||
protocol: TCP
|
||||
endpoints:
|
||||
- addresses:
|
||||
- "192.168.88.100"
|
||||
conditions:
|
||||
ready: true
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: sonarr
|
||||
namespace: streaming
|
||||
spec:
|
||||
ports:
|
||||
- port: 18989
|
||||
targetPort: 18989
|
||||
---
|
||||
apiVersion: discovery.k8s.io/v1
|
||||
kind: EndpointSlice
|
||||
metadata:
|
||||
name: sonarr
|
||||
namespace: streaming
|
||||
labels:
|
||||
kubernetes.io/service-name: sonarr
|
||||
addressType: IPv4
|
||||
ports:
|
||||
- port: 18989
|
||||
protocol: TCP
|
||||
endpoints:
|
||||
- addresses:
|
||||
- "192.168.88.100"
|
||||
conditions:
|
||||
ready: true
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: radarr
|
||||
namespace: streaming
|
||||
spec:
|
||||
ports:
|
||||
- port: 17878
|
||||
targetPort: 17878
|
||||
---
|
||||
apiVersion: discovery.k8s.io/v1
|
||||
kind: EndpointSlice
|
||||
metadata:
|
||||
name: radarr
|
||||
namespace: streaming
|
||||
labels:
|
||||
kubernetes.io/service-name: radarr
|
||||
addressType: IPv4
|
||||
ports:
|
||||
- port: 17878
|
||||
protocol: TCP
|
||||
endpoints:
|
||||
- addresses:
|
||||
- "192.168.88.100"
|
||||
conditions:
|
||||
ready: true
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: prowlarr
|
||||
namespace: streaming
|
||||
spec:
|
||||
ports:
|
||||
- port: 19696
|
||||
targetPort: 19696
|
||||
---
|
||||
apiVersion: discovery.k8s.io/v1
|
||||
kind: EndpointSlice
|
||||
metadata:
|
||||
name: prowlarr
|
||||
namespace: streaming
|
||||
labels:
|
||||
kubernetes.io/service-name: prowlarr
|
||||
addressType: IPv4
|
||||
ports:
|
||||
- port: 19696
|
||||
protocol: TCP
|
||||
endpoints:
|
||||
- addresses:
|
||||
- "192.168.88.100"
|
||||
conditions:
|
||||
ready: true
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: jellyseerr
|
||||
namespace: streaming
|
||||
spec:
|
||||
ports:
|
||||
- port: 15055
|
||||
targetPort: 15055
|
||||
---
|
||||
apiVersion: discovery.k8s.io/v1
|
||||
kind: EndpointSlice
|
||||
metadata:
|
||||
name: jellyseerr
|
||||
namespace: streaming
|
||||
labels:
|
||||
kubernetes.io/service-name: jellyseerr
|
||||
addressType: IPv4
|
||||
ports:
|
||||
- port: 15055
|
||||
protocol: TCP
|
||||
endpoints:
|
||||
- addresses:
|
||||
- "192.168.88.100"
|
||||
conditions:
|
||||
ready: true
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: bazarr
|
||||
namespace: streaming
|
||||
spec:
|
||||
ports:
|
||||
- port: 16767
|
||||
targetPort: 16767
|
||||
---
|
||||
apiVersion: discovery.k8s.io/v1
|
||||
kind: EndpointSlice
|
||||
metadata:
|
||||
name: bazarr
|
||||
namespace: streaming
|
||||
labels:
|
||||
kubernetes.io/service-name: bazarr
|
||||
addressType: IPv4
|
||||
ports:
|
||||
- port: 16767
|
||||
protocol: TCP
|
||||
endpoints:
|
||||
- addresses:
|
||||
- "192.168.88.100"
|
||||
conditions:
|
||||
ready: true
|
||||
@@ -1,118 +0,0 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: jellyfin-local
|
||||
namespace: streaming
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`jellyfin.workstation.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: jellyfin
|
||||
port: 18096
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: qbittorrent-local
|
||||
namespace: streaming
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`qbittorrent.workstation.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: qbittorrent
|
||||
port: 18180
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: sonarr-local
|
||||
namespace: streaming
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`sonarr.workstation.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: sonarr
|
||||
port: 18989
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: radarr-local
|
||||
namespace: streaming
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`radarr.workstation.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: radarr
|
||||
port: 17878
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: prowlarr-local
|
||||
namespace: streaming
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`prowlarr.workstation.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: prowlarr
|
||||
port: 19696
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: jellyseerr-local
|
||||
namespace: streaming
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`jellyseerr.workstation.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: jellyseerr
|
||||
port: 15055
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: bazarr-local
|
||||
namespace: streaming
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`bazarr.workstation.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: bazarr
|
||||
port: 16767
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
termix:
|
||||
image: ghcr.io/lukegus/termix:2.9.1
|
||||
image: ghcr.io/lukegus/termix:2.9.0
|
||||
container_name: termix
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
|
||||
@@ -29,7 +29,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: termix
|
||||
image: ghcr.io/lukegus/termix:2.9.1
|
||||
image: ghcr.io/lukegus/termix:2.9.0
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: termix-config
|
||||
|
||||
@@ -10,8 +10,6 @@ spec:
|
||||
routes:
|
||||
- match: Host(`traefik.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: security-chain@file
|
||||
services:
|
||||
- name: api@internal
|
||||
kind: TraefikService
|
||||
|
||||
@@ -94,7 +94,7 @@ ports:
|
||||
exposedPort: 8080
|
||||
protocol: TCP
|
||||
expose:
|
||||
default: true
|
||||
default: false
|
||||
http:
|
||||
aliasHeadersStrategy: delete
|
||||
ssh:
|
||||
|
||||
@@ -1,40 +0,0 @@
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: PrometheusRule
|
||||
metadata:
|
||||
name: uptime-kuma
|
||||
namespace: uptime-kuma
|
||||
labels:
|
||||
release: prometheus-stack
|
||||
spec:
|
||||
groups:
|
||||
- name: uptime_kuma.monitors
|
||||
rules:
|
||||
- alert: KumaMonitorDown
|
||||
expr: |
|
||||
monitor_status{monitor_type!="group"} == 0
|
||||
for: 5m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Uptime Kuma monitor down: {{ $labels.monitor_name }}"
|
||||
description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) is down for 5m. Check Uptime Kuma (https://uptime.forust.xyz) and the target service."
|
||||
|
||||
- alert: KumaScrapeDown
|
||||
expr: |
|
||||
absent(monitor_status) == 1
|
||||
for: 10m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Uptime Kuma metrics missing"
|
||||
description: "uptime-kuma: no monitor_status series for 10m. Pod may be down, the uk1_ API key may have been rotated without updating uptime-kuma-secrets, or ServiceMonitor/Service broken. All Kuma monitors are unobserved."
|
||||
|
||||
- alert: KumaCertExpiring
|
||||
expr: |
|
||||
monitor_cert_days_remaining < 14
|
||||
for: 1h
|
||||
labels:
|
||||
severity: warning
|
||||
annotations:
|
||||
summary: "TLS cert expiring: {{ $labels.monitor_name }} ({{ $value }}d left)"
|
||||
description: "Uptime Kuma monitor {{ $labels.monitor_name }} ({{ $labels.monitor_url }}) reports a TLS certificate with {{ $value }} days remaining. Check cert-manager Certificate for this host."
|
||||
@@ -1,9 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: uptime-kuma-secrets
|
||||
namespace: uptime-kuma
|
||||
type: Opaque
|
||||
stringData:
|
||||
metrics-username: "uptime-kuma"
|
||||
metrics-password: "REPLACE_ME"
|
||||
@@ -1,23 +0,0 @@
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: uptime-kuma
|
||||
namespace: uptime-kuma
|
||||
labels:
|
||||
release: prometheus-stack
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: uptime-kuma
|
||||
endpoints:
|
||||
- port: http
|
||||
path: /metrics
|
||||
interval: 60s
|
||||
scrapeTimeout: 15s
|
||||
basicAuth:
|
||||
username:
|
||||
name: uptime-kuma-secrets
|
||||
key: metrics-username
|
||||
password:
|
||||
name: uptime-kuma-secrets
|
||||
key: metrics-password
|
||||
@@ -3,14 +3,11 @@ kind: Service
|
||||
metadata:
|
||||
name: uptime-kuma-service
|
||||
namespace: uptime-kuma
|
||||
labels:
|
||||
app: uptime-kuma
|
||||
spec:
|
||||
selector:
|
||||
app: uptime-kuma
|
||||
ports:
|
||||
- port: 3001
|
||||
name: http
|
||||
targetPort: 3001
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
|
||||
Reference in new issue
Block a user