Compare commits
279
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6bd183ba73 | ||
|
|
aeefdd8560 | ||
|
|
c10d344fd7 | ||
|
|
6e5f80611b | ||
|
|
5cf0c90258 | ||
|
|
90a452a253 | ||
|
|
a9eabfba02 | ||
|
|
46c7e99b1d | ||
|
|
8b2cf29771 | ||
|
|
7b7fc3bcb0 | ||
|
|
bc1e69ebe0 | ||
|
|
f29bb3d580 | ||
|
|
1f7166026b | ||
|
|
1cbdfc1d6f | ||
|
|
6be3769288 | ||
|
|
ef325cd3b1 | ||
|
|
aa81f1bf8a | ||
|
|
93d768e988 | ||
|
|
a8f7c79934 | ||
|
|
c42bf14c9a | ||
|
|
1e8479b853 | ||
|
|
c139d700f1 | ||
|
|
67b9996911 | ||
|
|
4e9ee567ca | ||
|
|
4863e13596 | ||
|
|
9c4580a522 | ||
|
|
4e3ad00202 | ||
|
|
86ac43567d | ||
|
|
35bf980bda | ||
|
|
51677ae184 | ||
|
|
c9e6fc0e2b | ||
|
|
ab386fc436 | ||
|
|
7e17ae638a | ||
|
|
872d9695c3 | ||
|
|
69e7df6a63 | ||
|
|
98aceef192 | ||
|
|
dfd9cc6fbf | ||
|
|
40e7499e7c | ||
|
|
7f0bd5f609 | ||
|
|
043923fc64 | ||
|
|
f0f8a35b0f | ||
|
|
f5f389b440 | ||
|
|
7cca330438 | ||
|
|
5936de3e56 | ||
|
|
c98ea8b957 | ||
|
|
34c33697bb | ||
|
|
92bd920113 | ||
|
|
8007f82d52 | ||
|
|
60b9766449 | ||
|
|
0ebb7264bc | ||
|
|
ce21c60eba | ||
|
|
53638f831d | ||
|
|
4953da2dd7 | ||
|
|
4ac65f743c | ||
|
|
8f2e9d66c8 | ||
|
|
c7d42fb90a | ||
|
|
003b1e5dca | ||
|
|
b3463705c3 | ||
|
|
52e1f50a80 | ||
|
|
cdc2f10fe8 | ||
|
|
89fbdef10e | ||
|
|
ac795feeed | ||
|
|
3af5ecd07f | ||
|
|
82949613db | ||
|
|
47d788ca13 | ||
|
|
77be606912 | ||
|
|
4eab6a43c8 | ||
|
|
6c24d4fb17 | ||
|
|
e36595a045 | ||
|
|
e07537ff8b | ||
|
|
303eaaa71b | ||
|
|
1e66b5f344 | ||
|
|
d638a2c1f9 | ||
|
|
b8512c6033 | ||
|
|
3e057ea18d | ||
|
|
77113fb629 | ||
|
|
a3a0ab92b7 | ||
|
|
68fb5eb45e | ||
|
|
1c58c78892 | ||
|
|
82124017c0 | ||
|
|
e502f46f43 | ||
|
|
a4f8218b5e | ||
|
|
d162a50bba | ||
|
|
9ca8514a0a | ||
|
|
6fa809a8d2 | ||
|
|
c6d8df2317 | ||
|
|
c28d7323b3 | ||
|
|
25f547ff78 | ||
|
|
50911b4ec1 | ||
|
|
663675f9a0 | ||
|
|
8b28bd24ff | ||
|
|
b5d6f75330 | ||
|
|
f5b5ecaafa | ||
|
|
7799b676ca | ||
|
|
24d3686f60 | ||
|
|
b8b3bba264 | ||
|
|
abfbc04067 | ||
|
|
23ed72826a | ||
|
|
7288058df6 | ||
|
|
6715f9e9af | ||
|
|
ccec1102ef | ||
|
|
360a6fc5dc | ||
|
|
9a806724af | ||
|
|
ed1ddaad5d | ||
|
|
726b3ee544 | ||
|
|
13309b26e0 | ||
|
|
eddc256bed | ||
|
|
52f821cbba | ||
|
|
0dbc2fff13 | ||
|
|
91ec83bc1c | ||
|
|
9fec1dae39 | ||
|
|
e5626b7b2d | ||
|
|
8fb12a2176 | ||
|
|
fe0c7067b6 | ||
|
|
d0f0843774 | ||
|
|
81a5b207ac | ||
|
|
e3d5970ae3 | ||
|
|
85f05c26cb | ||
|
|
68630eb773 | ||
|
|
dad9cf2104 | ||
|
|
60886e8be2 | ||
|
|
4528321225 | ||
|
|
b246a3dea1 | ||
|
|
4c59a2d2fe | ||
|
|
fcc7b0d611 | ||
|
|
9633fe3a10 | ||
|
|
d9f1c8325a | ||
|
|
861d89d36a | ||
|
|
71cddd6a91 | ||
|
|
30e6f05584 | ||
|
|
bc8d74fd28 | ||
|
|
d2d4efb0d7 | ||
|
|
b752bf88bd | ||
|
|
587611ca88 | ||
|
|
ace23ad1f9 | ||
|
|
92aa731e44 | ||
|
|
87ca3fd40c
|
||
|
|
82bcd30ed8
|
||
|
|
620262d98c | ||
|
|
831f3a46b0 | ||
|
|
f7902e74e8
|
||
|
|
eb8d1b361e
|
||
|
|
6e2cafb206
|
||
|
|
67b0c0824f
|
||
|
|
8e72e0a920
|
||
|
|
73a1132beb | ||
|
|
a128523c24 | ||
|
|
ee881acd0e | ||
|
|
bacb2f4b9f | ||
|
|
91211e7b78 | ||
|
|
9b3a7aadb4
|
||
|
|
b123621ead
|
||
|
|
a2df8504f5
|
||
|
|
fb43306571
|
||
|
|
f424d91405
|
||
|
|
88a8f2987f
|
||
|
|
17027b232b
|
||
|
|
6ecbbb39b4
|
||
|
|
175cbc8860
|
||
|
|
6363d050b0
|
||
|
|
c855764bc6
|
||
|
|
7d92b85e21
|
||
|
|
9364392bc0 | ||
|
|
4355f451d4 | ||
|
|
3eaef5dc90 | ||
|
|
69ffd3682e | ||
|
|
1930600c40 | ||
|
|
d74a705d53
|
||
|
|
3c383db9a7
|
||
|
|
7fb0a0e179 | ||
|
|
227e5fda27
|
||
|
|
20bce5b31c | ||
|
|
70d7855f06
|
||
|
|
c905bbd039 | ||
|
|
fc83176522
|
||
|
|
7ba6bc44f2 | ||
|
|
0506aaaac8
|
||
|
|
bd9724da69
|
||
|
|
3bad433f1a
|
||
|
|
2bd7a5176f
|
||
|
|
a9ff01261b
|
||
|
|
95cec59263 | ||
|
|
1362ebc3c2
|
||
|
|
2de6131ba7
|
||
|
|
1762962f32
|
||
|
|
7fb9e46c05
|
||
|
|
b33488342a
|
||
|
|
d53b14b1de
|
||
|
|
a6a6d933da
|
||
|
|
0803f3efff | ||
|
|
ec0420962b | ||
|
|
b407202e53 | ||
|
|
b9b8474455 | ||
|
|
76853637bc | ||
|
|
dac3777fc4 | ||
|
|
bb5a3697f2 | ||
|
|
e73aacb900 | ||
|
|
ea483da645 | ||
|
|
85d35f86a7 | ||
|
|
3d03ab1ea4 | ||
|
|
4ca3ccdad3 | ||
|
|
10e26cda72 | ||
|
|
c648dfd147 | ||
|
|
2f97821dc6 | ||
|
|
3d78b90f3a | ||
|
|
3dc8228e22 | ||
|
|
93171ad8e6 | ||
|
|
dca7ad0902 | ||
|
|
26d10f4e71 | ||
|
|
68c5eac164 | ||
|
|
30f0f05150 | ||
|
|
a97560eaf3 | ||
|
|
2dce972be2 | ||
|
|
c2ad1122e5 | ||
|
|
4c356924e7 | ||
|
|
51777f904f | ||
|
|
37550da086 | ||
|
|
12d59cb6f9 | ||
|
|
714d4896c6 | ||
|
|
e369875117 | ||
|
|
31e61a9513 | ||
|
|
9b21f8056c | ||
|
|
4623fbd8bd | ||
|
|
18d1e21690 | ||
|
|
20b8c93275 | ||
|
|
5f88ecf02b | ||
|
|
0093e5ac52 | ||
|
|
bb821e138a | ||
|
|
1ea669220b | ||
|
|
f068a3e6a0 | ||
|
|
b7854447af | ||
|
|
7a3708f70c | ||
|
|
01ae2dd5cf | ||
|
|
82595804bf | ||
|
|
31b3c5bc31 | ||
|
|
1cdbfb2d7b | ||
|
|
6232b77026 | ||
|
|
22ffd779cc | ||
|
|
d85b3f02f5 | ||
|
|
17b2dfdc2e | ||
|
|
b641e3bd94 | ||
|
|
e19660fdf4 | ||
|
|
36922a177c
|
||
|
|
f3d04e935c
|
||
|
|
e5797e60b7 | ||
|
|
444bb97f8e | ||
|
|
0c5cf29f83
|
||
|
|
4f01cdac31 | ||
|
|
43c38767a1
|
||
|
|
cb40b10ecf | ||
|
|
a68c01a68f | ||
|
|
bdcdb1cb3d | ||
|
|
fe2b80b51f | ||
|
|
b8d5bc747d | ||
|
|
6f77b7d845
|
||
|
|
ea286e117d | ||
|
|
6a050669e8 | ||
|
|
b9c11b8eab | ||
|
|
6dac841b2c | ||
|
|
bed58c84ef | ||
|
|
526a2b617a | ||
|
|
56e5d79e3e | ||
|
|
1e08391e0e | ||
|
|
cd0ce06246 | ||
|
|
0a31601b77 | ||
|
|
e9a9271d2f | ||
|
|
25eb89c902 | ||
|
|
d988b0f7db | ||
|
|
e873f37159 | ||
|
|
8362f45bdc | ||
|
|
a699ceb935 | ||
|
|
ce66a546f1 | ||
|
|
a30bda4940 | ||
|
|
b722467991 | ||
|
|
5f8fd05266 | ||
|
|
1c7afe5bb3 | ||
|
|
4ff80c07b0 | ||
|
|
3a5652daa7 | ||
|
|
4e18cd0eb3 |
No files matched your search
@@ -0,0 +1,191 @@
|
||||
# Инструкция: Анализ хранилища Kubernetes и настройка NFS
|
||||
|
||||
## Цель
|
||||
Проанализировать текущую конфигурацию хранилища Kubernetes и подготовить план внедрения NFS StorageClass для сохранения данных при удалении namespace.
|
||||
|
||||
## 1. Собрать информацию о кластере
|
||||
|
||||
### 1.1. Версия Kubernetes и тип дистрибутива
|
||||
```bash
|
||||
kubectl version --short
|
||||
# или
|
||||
kubectl version
|
||||
```
|
||||
|
||||
Определить, используется ли k3s, k8s, microk8s и т.д.:
|
||||
```bash
|
||||
# Проверить наличие k3s
|
||||
which k3s
|
||||
# Проверить процесс
|
||||
ps aux | grep -E 'kube|k3s'
|
||||
```
|
||||
|
||||
### 1.2. StorageClass
|
||||
```bash
|
||||
kubectl get storageclass -o wide
|
||||
```
|
||||
|
||||
Запомнить:
|
||||
- `PROVISIONER` — какой драйвер используется
|
||||
- `RECLAIMPOLICY` — Delete или Retain
|
||||
- Какой StorageClass помечен как `(default)`
|
||||
|
||||
### 1.3. Существующие PV и PVC
|
||||
```bash
|
||||
kubectl get pv -o wide
|
||||
kubectl get pvc --all-namespaces
|
||||
```
|
||||
|
||||
Посмотреть, какие PVC привязаны к каким PV, и какой reclaimPolicy у PV.
|
||||
|
||||
### 1.4. Нода и диски
|
||||
```bash
|
||||
# Список нод
|
||||
kubectl get nodes -o wide
|
||||
|
||||
# На каждой ноде (через ssh или локально):
|
||||
lsblk
|
||||
df -h
|
||||
cat /etc/fstab
|
||||
```
|
||||
|
||||
Определить:
|
||||
- Есть ли отдельный раздел/диск для данных
|
||||
- Куда смонтированы разделы
|
||||
- Сколько свободного места
|
||||
- Есть ли монтирование NTFS-разделов (как `/media/forust/Programs`)
|
||||
|
||||
### 1.5. Где local-path хранит данные (для k3s)
|
||||
```bash
|
||||
ls -la /var/lib/rancher/k3s/storage/ 2>/dev/null
|
||||
# или для microk8s
|
||||
ls -la /var/snap/microk8s/common/ 2>/dev/null
|
||||
```
|
||||
|
||||
## 2. Анализ: сохраняются ли данные при удалении namespace?
|
||||
|
||||
| Сценарий | Результат |
|
||||
|---|---|
|
||||
| `kubectl delete ns <ns>` | Все PVC в namespace удаляются |
|
||||
| PVC → PV c `reclaimPolicy: Delete` | PV и данные удалены |
|
||||
| PVC → PV c `reclaimPolicy: Retain` | PV остаётся (статус Released), данные целы |
|
||||
|
||||
**Вывод:** Если reclaimPolicy в StorageClass = `Delete`, то данные **пропадут**. Если `Retain` — сохранятся.
|
||||
|
||||
## 3. План внедрения NFS
|
||||
|
||||
### 3.1. Проверить, установлен ли NFS
|
||||
```bash
|
||||
which nfsstat exportfs mount.nfs
|
||||
systemctl status nfs-server 2>/dev/null || systemctl status nfs-kernel-server 2>/dev/null
|
||||
```
|
||||
|
||||
### 3.2. Выбрать директорию для NFS-экспорта
|
||||
|
||||
Варианты (выбрать подходящий):
|
||||
- `/var/lib/k8s-nfs/` — на корневом разделе
|
||||
- `<путь к отдельному разделу>/k8s-nfs/` — если есть отдельный диск/раздел
|
||||
- Не рекомендуется использовать NTFS-раздел (проблемы с правами и производительностью)
|
||||
|
||||
Требования:
|
||||
- Файловая система: ext4 или xfs (не ntfs!)
|
||||
- Достаточно свободного места
|
||||
- Права: `755`, владелец root
|
||||
|
||||
### 3.3. Установить NFS-сервер
|
||||
|
||||
```bash
|
||||
# Debian/Ubuntu
|
||||
apt update && apt install -y nfs-kernel-server
|
||||
|
||||
# RHEL/Fedora
|
||||
dnf install -y nfs-utils
|
||||
```
|
||||
|
||||
### 3.4. Настроить экспорт
|
||||
|
||||
Создать директорию:
|
||||
```bash
|
||||
mkdir -p /var/lib/k8s-nfs
|
||||
chmod 755 /var/lib/k8s-nfs
|
||||
```
|
||||
|
||||
Добавить в `/etc/exports`:
|
||||
```
|
||||
/var/lib/k8s-nfs *(rw,sync,no_subtree_check,no_root_squash)
|
||||
```
|
||||
|
||||
Применить:
|
||||
```bash
|
||||
exportfs -rav
|
||||
```
|
||||
|
||||
Проверить:
|
||||
```bash
|
||||
showmount -e localhost
|
||||
```
|
||||
|
||||
### 3.5. Выбрать способ интеграции с Kubernetes
|
||||
|
||||
#### Вариант A: nfs-subdir-external-provisioner (проще)
|
||||
```bash
|
||||
helm repo add nfs-subdir-external-provisioner https://kubernetes-sigs.github.io/nfs-subdir-external-provisioner/
|
||||
helm install nfs-provisioner nfs-subdir-external-provisioner/nfs-subdir-external-provisioner \
|
||||
--namespace kube-system \
|
||||
--set nfs.server=127.0.0.1 \
|
||||
--set nfs.path=/var/lib/k8s-nfs \
|
||||
--set storageClass.name=nfs \
|
||||
--set storageClass.defaultClass=false \
|
||||
--set storageClass.reclaimPolicy=Retain
|
||||
```
|
||||
|
||||
#### Вариант B: NFS CSI Driver
|
||||
```bash
|
||||
helm repo add csi-driver-nfs https://raw.githubusercontent.com/kubernetes-csi/csi-driver-nfs/master/charts
|
||||
helm install csi-driver-nfs csi-driver-nfs/csi-driver-nfs --namespace kube-system
|
||||
```
|
||||
|
||||
После установки CSI драйвера создать StorageClass:
|
||||
```yaml
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: StorageClass
|
||||
metadata:
|
||||
name: nfs
|
||||
provisioner: nfs.csi.k8s.io
|
||||
parameters:
|
||||
server: 127.0.0.1
|
||||
share: /var/lib/k8s-nfs
|
||||
reclaimPolicy: Retain
|
||||
volumeBindingMode: Immediate
|
||||
```
|
||||
|
||||
### 3.6. Проверить результат
|
||||
```bash
|
||||
kubectl get storageclass
|
||||
kubectl get pods -n kube-system | grep -E 'nfs|provisioner'
|
||||
```
|
||||
|
||||
## 4. Итоговая конфигурация
|
||||
|
||||
После внедрения в кластере будет два StorageClass:
|
||||
|
||||
| Имя | Provisioner | ReclaimPolicy | Назначение |
|
||||
|---|---|---|---|
|
||||
| `local-path` (default) | rancher.io/local-path | Delete | Временные данные, stateless |
|
||||
| `nfs` | nfs-subdir-external-provisioner или nfs.csi.k8s.io | Retain | Данные, которые нужно сохранять |
|
||||
|
||||
**Главное преимущество:** PVC c `storageClassName: nfs` при удалении namespace сохраняют данные на диске, так как NFS-провизор использует `reclaimPolicy: Retain` или файлы физически остаются в NFS-экспорте.
|
||||
|
||||
## 5. Ответы на частые вопросы
|
||||
|
||||
**В:** Не упадёт ли local-path при установке NFS?
|
||||
**О:** Нет, они независимы. local-path продолжает работать как обычно.
|
||||
|
||||
**В:** Данные NFS и local-path будут на одном диске?
|
||||
**О:** Да, можно настроить оба на одном разделе, в разных каталогах.
|
||||
|
||||
**В:** Что если у меня несколько нод?
|
||||
**О:** NFS сервер нужно поднять на одной ноде, а с других нод должна быть доступна шари. Для multi-node лучше использовать отдельный сервер или distributed storage (Longhorn, Rook/Ceph).
|
||||
|
||||
**В:** Можно ли использовать существующий NTFS-раздел для NFS?
|
||||
**О:** Не рекомендуется — NTFS не поддерживает права Linux (no_root_squash не сработает корректно), возможны проблемы с блокировками и производительностью.
|
||||
@@ -0,0 +1,24 @@
|
||||
root = true
|
||||
|
||||
[*]
|
||||
indent_style = space
|
||||
indent_size = 2
|
||||
end_of_line = lf
|
||||
charset = utf-8
|
||||
trim_trailing_whitespace = true
|
||||
insert_final_newline = true
|
||||
|
||||
[*.{yml,yaml}]
|
||||
indent_size = 2
|
||||
|
||||
[*.{json,jsonc}]
|
||||
indent_size = 2
|
||||
|
||||
[*.md]
|
||||
trim_trailing_whitespace = false
|
||||
|
||||
[*.py]
|
||||
indent_size = 4
|
||||
|
||||
[{Makefile,makefile}]
|
||||
indent_style = tab
|
||||
@@ -0,0 +1,349 @@
|
||||
name: ci
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- "**"
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: ci-${{ github.ref }}
|
||||
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
|
||||
|
||||
env:
|
||||
REGISTRY: gcr.forust.xyz
|
||||
|
||||
jobs:
|
||||
lint-prettier:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Check formatting with Prettier
|
||||
shell: bash
|
||||
run: |
|
||||
mapfile -t prettier_files < <(
|
||||
git ls-files \
|
||||
| grep -E '\.(md|json|ya?ml|html|css)$' \
|
||||
| grep -Ev '^(\.docs/|\.zed/|errorpages/html/|homepages/(forust_files|xdfnx_files)/)'
|
||||
)
|
||||
|
||||
if [ "${#prettier_files[@]}" -eq 0 ]; then
|
||||
echo "No Prettier-managed files found."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
prettier --check --ignore-unknown "${prettier_files[@]}"
|
||||
|
||||
lint-ruff:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Lint Python with Ruff
|
||||
shell: bash
|
||||
run: |
|
||||
ruff check .
|
||||
|
||||
lint-yaml:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Lint YAML syntax
|
||||
shell: bash
|
||||
run: |
|
||||
mapfile -t yaml_files < <(
|
||||
git ls-files '*.yaml' '*.yml' \
|
||||
':!node_modules/**' \
|
||||
':!**/.venv/**'
|
||||
)
|
||||
|
||||
if [ "${#yaml_files[@]}" -eq 0 ]; then
|
||||
echo "No YAML files found."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
yamllint -c .yamllint "${yaml_files[@]}"
|
||||
|
||||
lint-dockerfiles:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Lint Dockerfiles
|
||||
shell: bash
|
||||
run: |
|
||||
mapfile -t dockerfiles < <(
|
||||
git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*'
|
||||
)
|
||||
|
||||
if [ "${#dockerfiles[@]}" -eq 0 ]; then
|
||||
echo "No Dockerfiles found."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
hadolint -c .hadolint.yaml "${dockerfiles[@]}"
|
||||
|
||||
validate:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Validate Kubernetes manifests
|
||||
shell: bash
|
||||
run: |
|
||||
mapfile -t manifests < <(
|
||||
git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \
|
||||
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'
|
||||
)
|
||||
|
||||
if [ "${#manifests[@]}" -eq 0 ]; then
|
||||
echo "No Kubernetes manifests found."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
kubeconform \
|
||||
-strict \
|
||||
-ignore-missing-schemas \
|
||||
-summary \
|
||||
"${manifests[@]}"
|
||||
|
||||
build:
|
||||
needs: [lint-prettier, lint-ruff, lint-yaml, lint-dockerfiles, validate]
|
||||
if: github.event_name != 'pull_request' && (github.ref_name == 'main' || github.ref_name == 'dev')
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
outputs:
|
||||
services: ${{ steps.services.outputs.services }}
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Detect changed docker-built services
|
||||
id: services
|
||||
shell: bash
|
||||
run: |
|
||||
base="${{ github.event.before }}"
|
||||
if [ -z "$base" ] || [ "$base" = "0000000000000000000000000000000000000000" ]; then
|
||||
base="$(git rev-list --max-parents=0 HEAD)"
|
||||
fi
|
||||
|
||||
mapfile -t changed_files < <(git diff --name-only "$base" "${GITHUB_SHA}")
|
||||
|
||||
services=()
|
||||
|
||||
add_service() {
|
||||
local name="$1"
|
||||
local seen=0
|
||||
for existing in "${services[@]}"; do
|
||||
if [ "$existing" = "$name" ]; then
|
||||
seen=1
|
||||
break
|
||||
fi
|
||||
done
|
||||
if [ "$seen" -eq 0 ]; then
|
||||
services+=("$name")
|
||||
fi
|
||||
}
|
||||
|
||||
for file in "${changed_files[@]}"; do
|
||||
case "$file" in
|
||||
dtek_notif/*)
|
||||
add_service dtek_notif
|
||||
;;
|
||||
errorpages/*)
|
||||
add_service errorpages
|
||||
;;
|
||||
userbot/*)
|
||||
add_service userbot
|
||||
;;
|
||||
homepages/*)
|
||||
add_service homepages
|
||||
;;
|
||||
edu_master/phpsessid-bot/*|edu_master/webinar-checker/*|edu_master/compose.yaml)
|
||||
add_service edu_master
|
||||
;;
|
||||
esac
|
||||
done
|
||||
|
||||
if [ "${#services[@]}" -eq 0 ]; then
|
||||
echo "No docker-built services changed."
|
||||
echo "services=" >> "$GITHUB_OUTPUT"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
printf '%s\n' "${services[@]}" | tee /tmp/services.txt
|
||||
echo "services=$(paste -sd, /tmp/services.txt)" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Log in to registry
|
||||
if: steps.services.outputs.services != ''
|
||||
shell: bash
|
||||
run: |
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login "${REGISTRY}" \
|
||||
-u "${{ secrets.REGISTRY_USERNAME }}" \
|
||||
--password-stdin
|
||||
|
||||
- name: Build and push changed images
|
||||
if: steps.services.outputs.services != ''
|
||||
shell: bash
|
||||
run: |
|
||||
IFS=, read -r -a services <<< "${{ steps.services.outputs.services }}"
|
||||
|
||||
for service in "${services[@]}"; do
|
||||
case "$service" in
|
||||
dtek_notif)
|
||||
image="${REGISTRY}/forust/dtek-notif"
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" dtek_notif
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
;;
|
||||
errorpages)
|
||||
image="${REGISTRY}/forust/error-pages"
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" errorpages
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
;;
|
||||
userbot)
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
for target in runtime panel; do
|
||||
case "$target" in
|
||||
runtime)
|
||||
context="userbot"
|
||||
image="${REGISTRY}/forust/userbot"
|
||||
;;
|
||||
panel)
|
||||
context="userbot/panel"
|
||||
image="${REGISTRY}/forust/userbot-panel"
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" "$context"
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
done
|
||||
;;
|
||||
homepages)
|
||||
for service in forust xdfnx; do
|
||||
case "$service" in
|
||||
forust)
|
||||
image="${REGISTRY}/forust/forust-homepage"
|
||||
;;
|
||||
xdfnx)
|
||||
image="${REGISTRY}/forust/xdfnx-homepage"
|
||||
;;
|
||||
esac
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" -f "homepages/Dockerfile.${service}" homepages
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
done
|
||||
;;
|
||||
edu_master)
|
||||
for service in session-keeper webinar-checker; do
|
||||
case "$service" in
|
||||
session-keeper)
|
||||
context="edu_master/phpsessid-bot"
|
||||
image="${REGISTRY}/forust/session-keeper"
|
||||
;;
|
||||
webinar-checker)
|
||||
context="edu_master/webinar-checker"
|
||||
image="${REGISTRY}/forust/webinar-checker"
|
||||
;;
|
||||
esac
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" "$context"
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
done
|
||||
;;
|
||||
esac
|
||||
done
|
||||
@@ -0,0 +1,307 @@
|
||||
name: deploy
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: deploy-main
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
redeploy:
|
||||
runs-on: [self-hosted, linux, arch, homelab, prod]
|
||||
steps:
|
||||
- name: Redeploy workstation
|
||||
shell: bash
|
||||
env:
|
||||
DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }}
|
||||
DEPLOY_PORT: ${{ secrets.DEPLOY_PORT }}
|
||||
DEPLOY_USER: ${{ secrets.DEPLOY_USER }}
|
||||
DEPLOY_PATH: ${{ secrets.DEPLOY_PATH }}
|
||||
DEPLOY_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
|
||||
APPLY_PRUNE: ${{ vars.APPLY_PRUNE }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
: "${DEPLOY_HOST:?missing DEPLOY_HOST}"
|
||||
: "${DEPLOY_USER:?missing DEPLOY_USER}"
|
||||
: "${DEPLOY_KEY:?missing DEPLOY_SSH_KEY}"
|
||||
|
||||
deploy_port="${DEPLOY_PORT:-22}"
|
||||
deploy_path="${DEPLOY_PATH:-/srv/homelab}"
|
||||
|
||||
ssh_key="$RUNNER_TEMP/deploy_key"
|
||||
mkdir -p "$RUNNER_TEMP"
|
||||
printf '%s\n' "$DEPLOY_KEY" > "$ssh_key"
|
||||
chmod 600 "$ssh_key"
|
||||
|
||||
ssh_opts=(
|
||||
-i "$ssh_key"
|
||||
-p "$deploy_port"
|
||||
-o BatchMode=yes
|
||||
-o StrictHostKeyChecking=accept-new
|
||||
)
|
||||
|
||||
ssh "${ssh_opts[@]}" "${DEPLOY_USER}@${DEPLOY_HOST}" \
|
||||
"DEPLOY_PATH=$(printf '%q' \"$deploy_path\") APPLY_PRUNE=$(printf '%q' \"${APPLY_PRUNE:-false}\") bash -se" <<'EOF'
|
||||
set -euo pipefail
|
||||
|
||||
repo="${DEPLOY_PATH:-/srv/homelab}"
|
||||
|
||||
if [ ! -d "$repo/.git" ]; then
|
||||
echo "Repository not found at $repo"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
git -C "$repo" fetch origin main
|
||||
|
||||
echo "== Workstation state =="
|
||||
echo " local: $(git -C "$repo" rev-parse --short HEAD)"
|
||||
echo " remote: $(git -C "$repo" rev-parse --short origin/main)"
|
||||
|
||||
if [ -n "$(git -C "$repo" status --porcelain --untracked-files=no)" ]; then
|
||||
echo "ERROR: workstation has local tracked modifications, refusing reset:"
|
||||
git -C "$repo" status --porcelain --untracked-files=no
|
||||
git -C "$repo" diff --stat
|
||||
exit 1
|
||||
fi
|
||||
|
||||
git -C "$repo" reset --hard origin/main
|
||||
cd "$repo"
|
||||
|
||||
is_disabled() {
|
||||
local target="$1"
|
||||
if [ -f "$target" ]; then
|
||||
target="$(dirname "$target")"
|
||||
fi
|
||||
while true; do
|
||||
if [ -f "$target/DISABLED" ]; then
|
||||
return 0
|
||||
fi
|
||||
if [ "$target" = "$repo" ]; then
|
||||
break
|
||||
fi
|
||||
target="$(dirname "$target")"
|
||||
case "$target" in
|
||||
"$repo"/*) ;;
|
||||
*) break ;;
|
||||
esac
|
||||
done
|
||||
return 1
|
||||
}
|
||||
|
||||
collect_k8s() {
|
||||
git ls-files -- "$1" \
|
||||
| grep -E '\.ya?ml$' \
|
||||
| grep -Ev '/routing/|/overlays/' \
|
||||
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$' \
|
||||
| grep -Ev '(^|/)[^/]*secret[^/]*\.ya?ml$' \
|
||||
| sort
|
||||
}
|
||||
|
||||
collect_k8s_inactive() {
|
||||
collect_k8s "$1" \
|
||||
| grep -E '(^|/)namespace\.ya?ml$|/routing/'
|
||||
}
|
||||
|
||||
kustomize_overlay() {
|
||||
if [ -f "$1/overlays/prod/kustomization.yaml" ]; then
|
||||
echo "$1/overlays/prod"
|
||||
elif [ -f "$1/base/kustomization.yaml" ]; then
|
||||
echo "$1/base"
|
||||
fi
|
||||
}
|
||||
|
||||
mapfile -t k8s_dirs < <(
|
||||
git ls-files '*.yaml' '*.yml' \
|
||||
| grep -E '(^|/)k8s/' \
|
||||
| sed -E 's#((^|.*/)k8s)/.*#\1#' \
|
||||
| sort -u
|
||||
)
|
||||
|
||||
k8s_manifests=()
|
||||
kustomize_apps=()
|
||||
for kd_rel in "${k8s_dirs[@]}"; do
|
||||
kd="$repo/$kd_rel"
|
||||
if is_disabled "$kd"; then
|
||||
echo "skip (DISABLED): $kd_rel"
|
||||
continue
|
||||
fi
|
||||
if [ -f "$kd/active" ]; then
|
||||
overlay="$(kustomize_overlay "$kd" || true)"
|
||||
if [ -n "${overlay:-}" ]; then
|
||||
echo "kustomize app: ${overlay#$repo/}"
|
||||
kustomize_apps+=("$overlay")
|
||||
else
|
||||
while IFS= read -r f; do
|
||||
[ -n "$f" ] && k8s_manifests+=("$repo/$f")
|
||||
done < <(collect_k8s "$kd_rel" || true)
|
||||
fi
|
||||
else
|
||||
while IFS= read -r f; do
|
||||
[ -n "$f" ] && k8s_manifests+=("$repo/$f")
|
||||
done < <(collect_k8s_inactive "$kd_rel" || true)
|
||||
fi
|
||||
done
|
||||
|
||||
mapfile -t compose_rel < <(
|
||||
git ls-files '*/compose.yaml' '*/compose.yml' compose.yaml compose.yml | sort
|
||||
)
|
||||
|
||||
compose_stacks=()
|
||||
for cf_rel in "${compose_rel[@]}"; do
|
||||
cf="$repo/$cf_rel"
|
||||
if is_disabled "$cf"; then
|
||||
echo "skip (DISABLED): $cf_rel"
|
||||
continue
|
||||
fi
|
||||
if [ -f "$(dirname "$cf")/k8s/active" ]; then
|
||||
echo "skip (k8s-managed): $cf_rel"
|
||||
continue
|
||||
fi
|
||||
compose_stacks+=("$cf")
|
||||
done
|
||||
|
||||
echo "== Validate compose stacks =="
|
||||
for cf in "${compose_stacks[@]}"; do
|
||||
echo " config: $cf"
|
||||
docker compose -f "$cf" config --quiet
|
||||
done
|
||||
|
||||
echo "== Validate k8s manifests (kubectl dry-run=client) =="
|
||||
for m in "${k8s_manifests[@]}"; do
|
||||
echo " apply --dry-run=client $m"
|
||||
kubectl apply --dry-run=client -f "$m" >/dev/null
|
||||
done
|
||||
for k in "${kustomize_apps[@]}"; do
|
||||
echo " apply -k --dry-run=client $k"
|
||||
kubectl apply -k "$k" --dry-run=client >/dev/null
|
||||
done
|
||||
|
||||
echo "== Validate k8s manifests (kubectl dry-run=server) =="
|
||||
for m in "${k8s_manifests[@]}"; do
|
||||
echo " apply --dry-run=server $m"
|
||||
kubectl apply --dry-run=server -f "$m" >/dev/null
|
||||
done
|
||||
for k in "${kustomize_apps[@]}"; do
|
||||
echo " apply -k --dry-run=server $k"
|
||||
kubectl apply -k "$k" --dry-run=server >/dev/null
|
||||
done
|
||||
|
||||
echo "== Checking referenced Secrets exist =="
|
||||
echo " (deploy never applies *secret*.yaml; create missing ones from the laptop)"
|
||||
ref_secrets=()
|
||||
if [ "${#k8s_manifests[@]}" -gt 0 ]; then
|
||||
while IFS= read -r s; do
|
||||
[ -n "$s" ] && ref_secrets+=("$s")
|
||||
done < <(
|
||||
{
|
||||
grep -h -A1 -E 'secretRef:|secretKeyRef:' "${k8s_manifests[@]}" 2>/dev/null || true
|
||||
grep -h -E 'secretName:' "${k8s_manifests[@]}" 2>/dev/null || true
|
||||
} | grep -E 'name:' | sed -E 's/.*name:[[:space:]]*//' | tr -d '"'"'"' "'"'" | sed -E 's/[[:space:]]*#.*//' | awk 'NF' | sort -u || true
|
||||
)
|
||||
fi
|
||||
missing_secrets=()
|
||||
all_secrets="$(kubectl get secrets -A --no-headers -o custom-columns=:metadata.name 2>/dev/null || true)"
|
||||
for s in "${ref_secrets[@]}"; do
|
||||
if printf '%s\n' "$all_secrets" | grep -qx "$s"; then
|
||||
echo " ok: $s"
|
||||
else
|
||||
echo " MISSING: $s"
|
||||
missing_secrets+=("$s")
|
||||
fi
|
||||
done
|
||||
if [ "${#missing_secrets[@]}" -gt 0 ]; then
|
||||
echo "ERROR: ${#missing_secrets[@]} referenced Secret(s) not found in the cluster:"
|
||||
printf ' - %s\n' "${missing_secrets[@]}"
|
||||
echo "Create them manually from the laptop, e.g.:"
|
||||
echo " kubectl apply -f SERVICE/k8s/secrets.yaml # see SERVICE/k8s/secrets.yaml.example"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "== Applying Kubernetes manifests =="
|
||||
ns_files=()
|
||||
other_files=()
|
||||
for m in "${k8s_manifests[@]}"; do
|
||||
case "$m" in
|
||||
*/namespace.y?ml) ns_files+=("$m") ;;
|
||||
*) other_files+=("$m") ;;
|
||||
esac
|
||||
done
|
||||
|
||||
prune_opts=()
|
||||
if [ "${APPLY_PRUNE:-false}" = "true" ]; then
|
||||
prune_opts=(--prune -l app.kubernetes.io/managed-by=homelab-deploy)
|
||||
fi
|
||||
|
||||
if [ "${#ns_files[@]}" -gt 0 ]; then
|
||||
echo " namespaces first: ${ns_files[*]}"
|
||||
kubectl apply -f "${ns_files[@]}"
|
||||
fi
|
||||
if [ -f "$repo/prometheus-stack/k8s/active" ] && ! is_disabled "$repo/prometheus-stack/k8s"; then
|
||||
if [ ! -f "$repo/prometheus-stack/k8s/grafana-values.yaml" ]; then
|
||||
echo "ERROR: prometheus-stack/k8s/grafana-values.yaml (gitignored) missing on workstation, restore it first."
|
||||
exit 1
|
||||
fi
|
||||
echo "== Upgrading kube-prometheus-stack =="
|
||||
helm upgrade --install prometheus-stack prometheus-community/kube-prometheus-stack \
|
||||
--namespace prometheus \
|
||||
--version 86.2.3 \
|
||||
--values "$repo/prometheus-stack/k8s/grafana-values.yaml" \
|
||||
--wait --timeout 10m
|
||||
fi
|
||||
if [ -f "$repo/loki/k8s/active" ] && ! is_disabled "$repo/loki/k8s"; then
|
||||
echo "== Upgrading loki/alloy =="
|
||||
helm repo add grafana https://grafana.github.io/helm-charts >/dev/null 2>&1 || true
|
||||
helm repo update grafana >/dev/null 2>&1 || true
|
||||
helm upgrade --install loki grafana/loki \
|
||||
--version 7.3.0 \
|
||||
--namespace prometheus \
|
||||
--values "$repo/loki/k8s/loki-values.yaml" \
|
||||
--wait --timeout 10m
|
||||
helm upgrade --install alloy grafana/alloy \
|
||||
--version 1.12.1 \
|
||||
--namespace prometheus \
|
||||
--values "$repo/loki/k8s/alloy-values.yaml" \
|
||||
--wait --timeout 10m
|
||||
fi
|
||||
|
||||
if [ "${#other_files[@]}" -gt 0 ]; then
|
||||
echo " resources: ${other_files[*]}"
|
||||
kubectl apply "${prune_opts[@]}" -f "${other_files[@]}"
|
||||
fi
|
||||
|
||||
for k in "${kustomize_apps[@]}"; do
|
||||
echo "== Applying kustomize app: ${k#$repo/} =="
|
||||
kubectl apply -k "$k"
|
||||
done
|
||||
|
||||
if [ -f "$repo/userbot/k8s/active" ] && ! is_disabled "$repo/userbot"; then
|
||||
echo "== userbot panel hook =="
|
||||
if kubectl get secret userbot-common-secrets -n userbot >/dev/null 2>&1; then
|
||||
echo " userbot-common-secrets already present in userbot ns, not touching"
|
||||
elif kubectl get secret userbot-common-secrets -n default >/dev/null 2>&1; then
|
||||
echo " bootstrapping userbot-common-secrets into userbot ns"
|
||||
kubectl get secret userbot-common-secrets -n default -o json \
|
||||
| jq 'del(.metadata.annotations,.metadata.creationTimestamp,.metadata.resourceVersion,.metadata.uid,.metadata.managedFields) | .metadata.namespace = "userbot"' \
|
||||
| kubectl apply -f -
|
||||
else
|
||||
echo " WARNING: userbot-common-secrets missing in both default and userbot ns; create it manually from the laptop"
|
||||
fi
|
||||
kubectl rollout restart deployment/userbot-panel -n userbot
|
||||
kubectl rollout status deployment/userbot-panel -n userbot --timeout=180s
|
||||
fi
|
||||
|
||||
echo "== Redeploying docker compose stacks =="
|
||||
for cf in "${compose_stacks[@]}"; do
|
||||
echo " compose: $cf"
|
||||
if grep -Eq '^\s+pull_policy:\s*build\b' "$cf"; then
|
||||
docker compose -f "$cf" build
|
||||
docker compose -f "$cf" push
|
||||
fi
|
||||
docker compose -f "$cf" up -d --pull always --remove-orphans
|
||||
done
|
||||
EOF
|
||||
@@ -1,39 +0,0 @@
|
||||
name: Deploy to Server
|
||||
run-name: Deploying to ${{ runner.os}} server on ${{ gitea.ref }}
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- ci/gitea-actions
|
||||
jobs:
|
||||
deploy:
|
||||
runs-on: prod
|
||||
steps:
|
||||
- name: Fetch and Diff Analysis
|
||||
id: diff
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
git fetch origin main
|
||||
CHANGES=$(git diff --name-only HEAD origin/main | cut -d/ -f1 | sort -u | tr '\n' ' ')
|
||||
echo "dirs=$CHANGES" >> $GITHUB_OUTPUT
|
||||
echo "Changed dirs: $CHANGES"
|
||||
|
||||
- name: Sync Server Files
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
git reset --hard origin/main
|
||||
echo "Server files synced with origin/main"
|
||||
|
||||
- name: Deploy Services
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
for dir in ${{ steps.diff.outputs.dirs }}; do
|
||||
if [ -d "$dir" ] && ([ -f "$dir/compose.yaml" ] || [ -f "$dir/docker-compose.yaml" ]); then
|
||||
echo ">>> Deploying $dir"
|
||||
cd "$dir"
|
||||
DOCKER_BUILDKIT=1 BUILDKIT_PROGRESS=plain docker compose up -d --build --no-color
|
||||
cd ..
|
||||
else
|
||||
echo ">>> Skipping $dir: no compose file found"
|
||||
fi
|
||||
done
|
||||
@@ -0,0 +1,52 @@
|
||||
name: renovate-ci
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
validate-renovate:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Validate Renovate Compose draft
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
trap 'rm -f renovate/.env' EXIT
|
||||
printf '%s\n' \
|
||||
'RENOVATE_ENDPOINT=https://gitea.example/api/v1' \
|
||||
'RENOVATE_TOKEN=test-token' \
|
||||
'RENOVATE_REPOSITORIES=forust/homelab' \
|
||||
> renovate/.env
|
||||
docker compose -f renovate/renovate-compose.yaml config --quiet
|
||||
|
||||
- name: Validate Kubernetes manifests
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
docker run --rm \
|
||||
-v "$PWD:/work" \
|
||||
-w /work \
|
||||
ghcr.io/yannh/kubeconform:latest \
|
||||
-strict \
|
||||
-ignore-missing-schemas \
|
||||
-summary \
|
||||
renovate/k8s/namespace.yaml \
|
||||
renovate/k8s/configmap.yaml \
|
||||
renovate/k8s/cronjob.yaml
|
||||
|
||||
- name: Validate Renovate repository config
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
docker run --rm \
|
||||
-v "$PWD:/work" \
|
||||
-w /work \
|
||||
renovate/renovate:44.103.0 \
|
||||
renovate-config-validator renovate.json
|
||||
@@ -0,0 +1,69 @@
|
||||
name: renovate-run
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
repositories:
|
||||
description: "Repositories to scan (comma-separated)"
|
||||
required: false
|
||||
default: "forust/homelab"
|
||||
log_level:
|
||||
description: "Renovate log level"
|
||||
required: false
|
||||
default: "info"
|
||||
type: choice
|
||||
options:
|
||||
- info
|
||||
- debug
|
||||
dry_run:
|
||||
description: "Plan only, do not open or update PRs"
|
||||
required: false
|
||||
default: false
|
||||
type: boolean
|
||||
|
||||
concurrency:
|
||||
group: renovate-run
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
run-renovate:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Validate Renovate config
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
docker run --rm \
|
||||
-v "$PWD/renovate/config.js:/opt/renovate/config.js:ro" \
|
||||
-e RENOVATE_CONFIG_FILE=/opt/renovate/config.js \
|
||||
renovate/renovate:44.103.0 \
|
||||
renovate-config-validator
|
||||
|
||||
- name: Run Renovate
|
||||
shell: bash
|
||||
env:
|
||||
RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}
|
||||
RENOVATE_GITHUB_COM_TOKEN: ${{ secrets.RENOVATE_GITHUB_COM_TOKEN }}
|
||||
RENOVATE_REPOSITORIES: ${{ inputs.repositories }}
|
||||
RENOVATE_DRY_RUN: ${{ inputs.dry_run && 'full' || '' }}
|
||||
LOG_LEVEL: ${{ inputs.log_level }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
: "${RENOVATE_TOKEN:?missing RENOVATE_TOKEN secret — add a renovate-bot PAT in repo/org Actions secrets}"
|
||||
|
||||
docker run --rm \
|
||||
-v "$PWD/renovate/config.js:/opt/renovate/config.js:ro" \
|
||||
-e RENOVATE_PLATFORM=gitea \
|
||||
-e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \
|
||||
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
|
||||
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
|
||||
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
|
||||
-e RENOVATE_DRY_RUN="${RENOVATE_DRY_RUN:-}" \
|
||||
-e RENOVATE_CONFIG_FILE=/opt/renovate/config.js \
|
||||
-e RENOVATE_BASE_DIR=/tmp/renovate \
|
||||
-e LOG_LEVEL="${LOG_LEVEL:-info}" \
|
||||
renovate/renovate:44.103.0
|
||||
@@ -1,41 +0,0 @@
|
||||
## BINARY MODE, USE WITH THE GITHUB RUNNER BINARY INSTALLED ON THE SERVER
|
||||
|
||||
name: Deploy to Server
|
||||
run-name: Deploying onto server on ${{ github.ref }}
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- ci/actions
|
||||
jobs:
|
||||
deploy:
|
||||
runs-on: [prod, self-hosted]
|
||||
steps:
|
||||
- name: Fetch and Diff Analysis
|
||||
id: diff
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
git fetch origin main
|
||||
CHANGES=$(git diff --name-only HEAD origin/main | cut -d/ -f1 | sort -u | tr '\n' ' ')
|
||||
echo "dirs=$CHANGES" >> $GITHUB_OUTPUT
|
||||
echo "Changed dirs: $CHANGES"
|
||||
|
||||
- name: Sync Server Files
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
git reset --hard origin/main
|
||||
echo "Server files synced with origin/main"
|
||||
|
||||
- name: Deploy Services
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
for dir in ${{ steps.diff.outputs.dirs }}; do
|
||||
if [ -d "$dir" ] && ([ -f "$dir/compose.yaml" ] || [ -f "$dir/docker-compose.yaml" ]); then
|
||||
echo ">>> Deploying $dir"
|
||||
cd "$dir"
|
||||
DOCKER_BUILDKIT=1 BUILDKIT_PROGRESS=plain docker compose up -d --build --no-color
|
||||
cd ..
|
||||
else
|
||||
echo ">>> Skipping $dir: no compose file found"
|
||||
fi
|
||||
done
|
||||
+20
-6
@@ -5,7 +5,7 @@ sync.ffs_lock
|
||||
# Copyparty
|
||||
*.hist/
|
||||
|
||||
# Volumes and data directories
|
||||
# Volumes, configs and data directories
|
||||
gitea/gitea-db/
|
||||
gitea/gitea-data/*
|
||||
n8n/n8n-data/*
|
||||
@@ -21,6 +21,7 @@ checkmk/checkmk/*
|
||||
downtify/Downtify_downloads
|
||||
headscale/config/*
|
||||
headscale/data/*
|
||||
searxng/core-config/*
|
||||
|
||||
# Steaming services files
|
||||
streaming/jellyfin/*
|
||||
@@ -31,7 +32,7 @@ streaming/data/*
|
||||
streaming/qbittorrent/*
|
||||
streaming/prowlarr/*
|
||||
|
||||
# Homepage
|
||||
# Homepage
|
||||
homepages/forust_files/.well-known/*
|
||||
|
||||
# Traefik files
|
||||
@@ -39,18 +40,20 @@ traefik/letsencrypt/acme.json
|
||||
traefik/dynamic/fileservers.yml
|
||||
traefik/dynamic/*.local.y*ml.*
|
||||
traefik/dynamic/*.external.y*ml
|
||||
|
||||
traefik/k8s/fileservers.y*ml
|
||||
traefik/k8s/aliasHeadersStrategy.md
|
||||
|
||||
traefik/logs/*
|
||||
|
||||
# SSL Certificates
|
||||
adguardhome/certs/*
|
||||
traefik/certs/*
|
||||
certs/
|
||||
|
||||
# Monitoring
|
||||
monitoring/prometheus.yml
|
||||
|
||||
# Python
|
||||
# Python
|
||||
.python-version
|
||||
venv/
|
||||
pyc
|
||||
@@ -91,9 +94,20 @@ replacements.txt
|
||||
edu_master/temp/
|
||||
temp/*
|
||||
|
||||
# Environment
|
||||
# Environment
|
||||
.env
|
||||
.env.anna
|
||||
.env.forust
|
||||
.env.*
|
||||
!*example
|
||||
!*example
|
||||
|
||||
# kubernetes
|
||||
*/k8s/*secret*
|
||||
!*/k8s/*secret*.example
|
||||
**/k8s/*secret*
|
||||
!**/k8s/*secret*.example
|
||||
# Local-only tweaks, not for upstream
|
||||
prometheus-stack/k8s/grafana-values.yaml
|
||||
traefik/k8s/local-tls.yaml
|
||||
converters/k8s/config.yaml
|
||||
convertx/k8s/config.yaml
|
||||
@@ -0,0 +1,10 @@
|
||||
ignored:
|
||||
- DL3008
|
||||
- DL3042
|
||||
- DL3018
|
||||
- DL3059
|
||||
trustedRegistries:
|
||||
- docker.io
|
||||
- ghcr.io
|
||||
- quay.io
|
||||
- gcr.forust.xyz
|
||||
@@ -0,0 +1,8 @@
|
||||
{
|
||||
"default": true,
|
||||
"MD013": false,
|
||||
"MD024": false,
|
||||
"MD033": false,
|
||||
"MD041": false,
|
||||
"MD046": false
|
||||
}
|
||||
@@ -0,0 +1,7 @@
|
||||
bracketSameLine: true
|
||||
htmlWhitespaceSensitivity: css
|
||||
printWidth: 120
|
||||
tabWidth: 2
|
||||
trailingComma: all
|
||||
proseWrap: preserve
|
||||
endOfLine: lf
|
||||
@@ -0,0 +1,22 @@
|
||||
extends: default
|
||||
|
||||
rules:
|
||||
comments:
|
||||
min-spaces-from-content: 1
|
||||
comments-indentation: false
|
||||
document-start: disable
|
||||
line-length: disable
|
||||
braces:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 1
|
||||
brackets:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 1
|
||||
indentation:
|
||||
spaces: 2
|
||||
indent-sequences: consistent
|
||||
truthy:
|
||||
allowed-values:
|
||||
- "true"
|
||||
- "false"
|
||||
- "on"
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"tab_size": 2,
|
||||
"soft_wrap": "prefer_line",
|
||||
"preferred_line_length": 120,
|
||||
"format_on_save": "on",
|
||||
"languages": {
|
||||
"YAML": {
|
||||
"tab_size": 2,
|
||||
"hard_tabs": false,
|
||||
"format_on_save": "on",
|
||||
"formatter": {
|
||||
"language_server": { "name": "yaml-language-server" },
|
||||
},
|
||||
},
|
||||
"Python": {
|
||||
"tab_size": 4,
|
||||
"format_on_save": "on",
|
||||
"language_servers": ["pyright", "ruff"],
|
||||
"formatter": {
|
||||
"language_server": { "name": "ruff" },
|
||||
},
|
||||
},
|
||||
},
|
||||
"lsp": {
|
||||
"yaml-language-server": {
|
||||
"settings": {
|
||||
"yaml": {
|
||||
"schemas": {
|
||||
"kubernetes": ["**/k8s/*.yaml", "**/k8s/*.yml"],
|
||||
},
|
||||
"validate": true,
|
||||
"completion": true,
|
||||
"format": {
|
||||
"enable": true,
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
adguard:
|
||||
image: adguard/adguardhome:latest
|
||||
image: adguard/adguardhome:v0.107.79
|
||||
container_name: adguardhome
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
@@ -17,11 +17,11 @@ services:
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
||||
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
||||
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard.tls=true"
|
||||
- "traefik.http.routers.adguard.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)"
|
||||
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
||||
@@ -31,10 +31,10 @@ services:
|
||||
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard-dev.tls=true"
|
||||
# DoH Router
|
||||
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
|
||||
- "traefik.http.routers.dns.entrypoints=websecure"
|
||||
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
|
||||
|
||||
- "traefik.http.routers.dns-over-https.rule=(Host(`dns.forust.xyz` || Host(`adguard.forust.xyz`)) && PathPrefix(`/dns-query`))"
|
||||
- "traefik.http.routers.dns-over-https.entrypoints=websecure"
|
||||
- "traefik.http.routers.dns-over-https.tls.certresolver=letsencrypt"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=adguard
|
||||
- glance.url=https://adguard.forust.xyz/
|
||||
|
||||
Whitespace-only changes.
@@ -0,0 +1,118 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: adguard-lb-service
|
||||
namespace: adguard
|
||||
annotations:
|
||||
metallb.io/loadBalancerIPs: "192.168.80.3"
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
externalTrafficPolicy: Local
|
||||
selector:
|
||||
app: adguard
|
||||
ports:
|
||||
- name: dns-udp
|
||||
port: 53
|
||||
targetPort: 53
|
||||
protocol: UDP
|
||||
- name: dns-tcp
|
||||
port: 53
|
||||
targetPort: 53
|
||||
protocol: TCP
|
||||
- name: dot
|
||||
port: 853
|
||||
targetPort: 853
|
||||
protocol: TCP
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: adguard-service
|
||||
namespace: adguard
|
||||
spec:
|
||||
selector:
|
||||
app: adguard
|
||||
ports:
|
||||
- port: 3000
|
||||
name: webui
|
||||
targetPort: 3000
|
||||
- port: 53
|
||||
name: dns
|
||||
targetPort: 53
|
||||
protocol: UDP
|
||||
- port: 53
|
||||
name: dns-tcp
|
||||
targetPort: 53
|
||||
protocol: TCP
|
||||
- port: 853
|
||||
name: dot
|
||||
targetPort: 853
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: adguard-deployment
|
||||
namespace: adguard
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: adguard
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: adguard
|
||||
annotations:
|
||||
reloader.stakater.com/auto: "true"
|
||||
spec:
|
||||
containers:
|
||||
- name: adguard
|
||||
image: adguard/adguardhome:v0.107.79
|
||||
resources:
|
||||
limits:
|
||||
memory: "1.5Gi"
|
||||
cpu: "300m"
|
||||
requests:
|
||||
memory: "500Mi"
|
||||
cpu: "50m"
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
name: webui
|
||||
- containerPort: 53
|
||||
name: dns
|
||||
- containerPort: 853
|
||||
name: dot
|
||||
volumeMounts:
|
||||
- name: adguard-data
|
||||
mountPath: /opt/adguardhome/work
|
||||
subPath: work
|
||||
- name: adguard-data
|
||||
mountPath: /opt/adguardhome/conf
|
||||
subPath: conf
|
||||
- name: adguard-certs
|
||||
mountPath: /certs
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: adguard-data
|
||||
persistentVolumeClaim:
|
||||
claimName: adguard-pvc
|
||||
- name: adguard-certs
|
||||
secret:
|
||||
secretName: adguard-certs
|
||||
items:
|
||||
- key: tls.crt
|
||||
path: fullchain.pem
|
||||
- key: tls.key
|
||||
path: privkey.pem
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: adguard-pvc
|
||||
namespace: adguard
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 2Gi
|
||||
@@ -0,0 +1,12 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: adguard-certs
|
||||
namespace: adguard
|
||||
spec:
|
||||
secretName: adguard-certs
|
||||
dnsNames:
|
||||
- dns.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,46 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: adguard-prod
|
||||
namespace: adguard
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`dns.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
services:
|
||||
- name: adguard-service
|
||||
port: 3000
|
||||
- match: (Host(`dns.forust.xyz`)) && PathPrefix(`/dns-query`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: adguard-service
|
||||
port: 3000
|
||||
tls:
|
||||
secretName: adguard-certs
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: adguard-local
|
||||
namespace: adguard
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`) || Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: adguard-service
|
||||
port: 3000
|
||||
- match: (Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`) || Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)) && PathPrefix(`/dns-query`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: adguard-service
|
||||
port: 3000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,15 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: adguard
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: adguard
|
||||
@@ -0,0 +1,10 @@
|
||||
kubectl apply -f k8s/namespace.yaml && \
|
||||
kubectl create secret tls adguard-certs -n adguard \
|
||||
--cert=certs/fullchain.pem \
|
||||
--key=certs/privkey.pem --dry-run=client -o yaml > \
|
||||
k8s/secrets.yaml
|
||||
|
||||
# OR WITH NO FILE CREATION:
|
||||
kubectl create secret tls adguard-certs -n adguard \
|
||||
--cert=certs/fullchain.pem --key=certs/privkey.pem \
|
||||
--save-config
|
||||
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
postgresql:
|
||||
image: docker.io/library/postgres:15-alpine
|
||||
image: docker.io/library/postgres:15.19-alpine
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- .env
|
||||
@@ -47,7 +47,7 @@ services:
|
||||
# Prod Router
|
||||
- "traefik.http.routers.authentik-server.rule=Host(`auth.forust.xyz`)"
|
||||
- "traefik.http.routers.authentik-server.entrypoints=websecure"
|
||||
- "traefik.http.routers.authentik-server.tls=true"
|
||||
- "traefik.http.routers.authentik-server.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`)"
|
||||
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
||||
|
||||
Whitespace-only changes.
@@ -0,0 +1,93 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: authentik-server-service
|
||||
namespace: authentik
|
||||
spec:
|
||||
type: ClusterIP
|
||||
selector:
|
||||
app: authentik-server
|
||||
ports:
|
||||
- port: 9000
|
||||
targetPort: 9000
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: authentik-worker-service
|
||||
namespace: authentik
|
||||
spec:
|
||||
type: ClusterIP
|
||||
selector:
|
||||
app: authentik-worker
|
||||
ports:
|
||||
- port: 9000
|
||||
targetPort: 9000
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: authentik-server-deployment
|
||||
namespace: authentik
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: authentik-server
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: authentik-server
|
||||
spec:
|
||||
containers:
|
||||
- name: authentik-server
|
||||
image: ghcr.io/goauthentik/server:2026.8.3
|
||||
args: ["server"]
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: authentik-config
|
||||
- secretRef:
|
||||
name: authentik-secrets
|
||||
ports:
|
||||
- containerPort: 9000
|
||||
resources:
|
||||
requests:
|
||||
memory: "700Mi"
|
||||
cpu: "300m"
|
||||
limits:
|
||||
memory: "1.5Gi"
|
||||
cpu: "1000m"
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: authentik-worker-deployment
|
||||
namespace: authentik
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: authentik-worker
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: authentik-worker
|
||||
spec:
|
||||
containers:
|
||||
- name: authentik-worker
|
||||
image: ghcr.io/goauthentik/server:2026.8.3
|
||||
args: ["worker"]
|
||||
securityContext:
|
||||
runAsUser: 0
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: authentik-config
|
||||
- secretRef:
|
||||
name: authentik-secrets
|
||||
resources:
|
||||
requests:
|
||||
memory: "512Mi"
|
||||
cpu: "300m"
|
||||
limits:
|
||||
memory: "1Gi"
|
||||
cpu: "700m"
|
||||
@@ -0,0 +1,28 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: authentik-prod-tls
|
||||
namespace: authentik
|
||||
spec:
|
||||
secretName: authentik-prod-tls
|
||||
dnsNames:
|
||||
- auth.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: authentik
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,11 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: authentik-config
|
||||
namespace: authentik
|
||||
data:
|
||||
AUTHENTIK_IMAGE: ghcr.io/goauthentik/server
|
||||
AUTHENTIK_TAG: "2025.10.2"
|
||||
AUTHENTIK_POSTGRESQL__HOST: postgres.database.svc.cluster.local
|
||||
AUTHENTIK_POSTGRESQL__NAME: authentik
|
||||
AUTHENTIK_ERROR_REPORTING__ENABLED: "true"
|
||||
@@ -0,0 +1,36 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: authentik-prod
|
||||
namespace: authentik
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`auth.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
services:
|
||||
- name: authentik-server-service
|
||||
port: 9000
|
||||
tls:
|
||||
secretName: authentik-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: authentik-local
|
||||
namespace: authentik
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`auth.workstation.internal`) || Host(`auth.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: authentik-server-service
|
||||
port: 9000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: authentik
|
||||
@@ -0,0 +1,11 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: authentik-secrets
|
||||
namespace: authentik
|
||||
type: Opaque
|
||||
stringData:
|
||||
AUTHENTIK_SECRET_KEY: ""
|
||||
AUTHENTIK_POSTGRESQL__PASSWORD: ""
|
||||
AUTHENTIK_POSTGRESQL__USER: authentik
|
||||
AUTHENTIK_BOOTSTRAP_PASSWORD: authentik
|
||||
@@ -0,0 +1,9 @@
|
||||
crds:
|
||||
enabled: true
|
||||
prometheus:
|
||||
servicemonitor:
|
||||
enabled: true
|
||||
interval: 60s
|
||||
scrapeTimeout: 30s
|
||||
labels:
|
||||
release: prometheus-stack
|
||||
@@ -0,0 +1,29 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: letsencrypt-staging
|
||||
spec:
|
||||
acme:
|
||||
email: bobrovod@national.shitposting.agency
|
||||
server: https://acme-staging-v02.api.letsencrypt.org/directory
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-staging-account-key
|
||||
solvers:
|
||||
- http01:
|
||||
ingress:
|
||||
class: traefik
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: letsencrypt-prod
|
||||
spec:
|
||||
acme:
|
||||
email: bobrovod@national.shitposting.agency
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-prod-account-key
|
||||
solvers:
|
||||
- http01:
|
||||
ingress:
|
||||
class: traefik
|
||||
@@ -0,0 +1,30 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIFFjCCAv6gAwIBAgIUetKpTfEDOn2985FFMu6G26itT+wwDQYJKoZIhvcNAQEN
|
||||
BQAwIzEhMB8GA1UEAxMYaG9tZWxhYiBpbnRlcm5hbCByb290IENBMB4XDTI2MDky
|
||||
MzEyNDA0N1oXDTM2MDkyMDEyNDA0N1owIzEhMB8GA1UEAxMYaG9tZWxhYiBpbnRl
|
||||
cm5hbCByb290IENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAvmNP
|
||||
ZCOoD8NtNuYJKVXBlTPjX7D7sJCSK5neH7ZbYV5+lmUlEErY8Mik7j37V5k5NfpF
|
||||
Ig85pOjP7RckTPz5V6ek3yaN40s4AL053sN5ZPauDVYjalaEHTgj5sEMqlLACQWI
|
||||
yZmJOZspZykae8dIpQnqCoFpRT4FurJ78v4a0ylnFVLMQn/lyCHedwTjkEdtYWYr
|
||||
ccJy8vQwqkzs/rWvEH1lDqZhennLOrmcCjfonG7D/pruMn4z+6E28p4+ejkRrI6x
|
||||
luak3KnpT1XMeHtgU21hiRGaMDBchHMFgAhnY1qosymKenXvfTZItwgjZbwa1hJI
|
||||
GAiDm+jQDKMjzRZ3rH6Xfc0auUcykNz73PpNu1NGm78nndXwCXcXn1LFKNQJ+r1U
|
||||
sJiyAmUZmXVn4aM4OMf2F38k7wTYIKg7nRGaUkNeKDlNkjA4HvgWw+jwO1KmdHQ/
|
||||
mOem1rosDWHRK01wg+Gga9mQCnhNhxglg3t/UeSic6uOaRsvaz4qkzHq8MbCujVz
|
||||
DpKQjqdikYOAXZOs4KlBLWrS7NaK4NzfSD02pBUErh54ruJfY/bWz9KyXzBD/lQZ
|
||||
VUTKyvUVB0bkVHEdf1jJmX3H4IZRQSF5JPqOBotW6bJI5fEGNBvj9Zxy4nm2WWGz
|
||||
yyP3uWsQz8U/Wdx9nXZLHInTZBsvgLYtKUAWA30CAwEAAaNCMEAwDgYDVR0PAQH/
|
||||
BAQDAgKkMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEkKm2rxPaK6+O9WD80z
|
||||
BLC6F9QsMA0GCSqGSIb3DQEBDQUAA4ICAQAnFyHz97Umf5VIu+dKTJid7C73VugJ
|
||||
TIar/xJBs/4CxP+znBxhJjXygRoyIfzoVGWcB2ZSL//vL78Qlts79K/Imc9a4RFF
|
||||
wMvCxsRXAEQ4TpeWi3ophPNcs4rhsP+gQKQFtnyKP9519bqpfxp0bTqwOV2o18fn
|
||||
za7rlQViiEnNV58j7CVoM9+mJvVVfBEX1Km+GyJL9GadzbIQ7FxClVJZefCbft93
|
||||
zHVk9gDOw8ys1XGSR2OUCyCLinXO6mqS16CmBb2MAKXq/YyH7E0N8iotAPGtfA8V
|
||||
M/0ddy947rY0xCrtECfWwvGQpJS7NRv/Z9b2jCfXrI5LXmL2nfQRg0y9GE4Vjwr+
|
||||
WxtGU5jOeFt0jQ+xRzcgG0Op+qK3x55l5LSo2hOcOVYbiHxcHEJFgwNi1ADeBFwb
|
||||
q/HdysfURSOghqjIpMMAUabBp+DBUg2EUF7pIaUqbdqExFYcr9EYisEMiNsmKmN+
|
||||
8ZbcOeerFKDQj+t/R0bFXa7UBn2UWsjI8zlR74aa2kLDXwtyz/XlO/FlYm66eBFo
|
||||
2/eYUSeU+S4ej+wUAs/dvjF7f190/DUQGuwOTlLTahqWDztmhCk7qzbECu56CwKT
|
||||
E5Ect2P72UleYwdblkVOVd352AmiwEzdOaziIRrPh8uenEknH6JBYPO3mjk7cCg+
|
||||
GPGcNIBctjdXhg==
|
||||
-----END CERTIFICATE-----
|
||||
@@ -0,0 +1,33 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: selfsigned
|
||||
spec:
|
||||
selfSigned: {}
|
||||
---
|
||||
# Homelab internal root CA (10y). Install the .crt on clients (see below).
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-ca-root
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
isCA: true
|
||||
commonName: homelab internal root CA
|
||||
duration: 87600h
|
||||
renewBefore: 7200h
|
||||
secretName: internal-ca-root
|
||||
privateKey:
|
||||
algorithm: RSA
|
||||
size: 4096
|
||||
issuerRef:
|
||||
name: selfsigned
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: internal-ca
|
||||
spec:
|
||||
ca:
|
||||
secretName: internal-ca-root
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: cert-manager
|
||||
@@ -0,0 +1,15 @@
|
||||
CLOUDFLARE_API_TOKEN=YOUR_CLOUDFLARE_API_TOKEN
|
||||
DOMAINS=example.com,dns.example.com,mc.example.com,auth.example.com,ssh.example.com
|
||||
IP4_DOMAINS=
|
||||
IP6_DOMAINS=
|
||||
IP4_PROVIDER=cloudflare.trace
|
||||
IP6_PROVIDER=none # change if you want to update AAAA
|
||||
UPDATE_CRON=@every 5m
|
||||
UPDATE_ON_START=true
|
||||
DELETE_ON_STOP=false
|
||||
DELETE_ON_FAILURE=true
|
||||
TTL=1
|
||||
PROXIED=!is(dns.example.com) && !is(mc.example.com) && !is(ssh.example.com)
|
||||
EMOJI=true
|
||||
UPTIMEKUMA=https://uptime-kuma.example.com/api/push/AsaSDFGFkfklaFALSKffkfFKfkfkfkFK?status=up&msg=OK&ping=
|
||||
REJECT_CLOUDFLARE_IPS=true
|
||||
+23
-6
@@ -1,13 +1,30 @@
|
||||
services:
|
||||
cloudflare-ddns:
|
||||
image: timothyjmiller/cloudflare-ddns:latest
|
||||
image: timothyjmiller/cloudflare-ddns:2.2.0
|
||||
container_name: cloudflare-ddns
|
||||
restart: unless-stopped
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
network_mode: 'host'
|
||||
network_mode: "host"
|
||||
# https://github.com/timothymiller/cloudflare-ddns#-quick-start
|
||||
environment:
|
||||
- PUID=1000
|
||||
- PGID=1000
|
||||
volumes:
|
||||
- ./config.json:/config.json
|
||||
- CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN:?Cloudflare API token is required}
|
||||
- DOMAINS=${DOMAINS:-}
|
||||
- IP4_DOMAINS=${IP4_DOMAINS:-}
|
||||
- IP6_DOMAINS=${IP6_DOMAINS:-}
|
||||
- IP4_PROVIDER=${IP4_PROVIDER:-cloudflare.trace}
|
||||
- IP6_PROVIDER=${IP6_PROVIDER:-none}
|
||||
- UPDATE_CRON=${UPDATE_CRON:-@every 5m}
|
||||
- UPDATE_ON_START=${UPDATE_ON_START:-true}
|
||||
- DELETE_ON_STOP=${DELETE_ON_STOP:-false}
|
||||
- DELETE_ON_FAILURE=${DELETE_ON_FAILURE:-true}
|
||||
- TTL=${TTL:-1} # 1=auto
|
||||
# to proxy only "dns.example.com" and "wfs.example.com" use "!is(dns.domain.com) && !is (wfs.domain.com)"
|
||||
- PROXIED=${PROXIED:-true}
|
||||
- EMOJI=${EMOJI:-true}
|
||||
- UPTIMEKUMA=${UPTIMEKUMA:-}
|
||||
- HEALTHCHECKS=${HEALTHCHECKS:-}
|
||||
- REJECT_CLOUDFLARE_IPS=${REJECT_CLOUDFLARE_IPS:-true}
|
||||
# volumes:
|
||||
# Prefer using environment variables for configuration, config.json legacy support
|
||||
# - ./config.json:/config.json
|
||||
@@ -7,7 +7,7 @@
|
||||
"api_key": {
|
||||
"api_key": "api_key_here",
|
||||
"account_email": "your_email_here"
|
||||
}
|
||||
},
|
||||
"zone_id": "your_zone-id",
|
||||
"subdomains": [
|
||||
{ "name": "", "proxied": true },
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
secret.yaml
|
||||
Whitespace-only changes.
@@ -0,0 +1,32 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: cfddns
|
||||
labels:
|
||||
app: cfddns
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: cfddns
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: cfddns
|
||||
spec:
|
||||
hostNetwork: true
|
||||
dnsPolicy: ClusterFirstWithHostNet
|
||||
containers:
|
||||
- name: cloudflare-ddns
|
||||
image: timothyjmiller/cloudflare-ddns:2.2.0
|
||||
imagePullPolicy: Always
|
||||
resources:
|
||||
requests:
|
||||
memory: "20Mi"
|
||||
cpu: "30m"
|
||||
limits:
|
||||
memory: "64Mi"
|
||||
cpu: "50m"
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: cfddns-secrets
|
||||
@@ -0,0 +1,18 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: cfddns-secrets
|
||||
type: Opaque
|
||||
stringData:
|
||||
CLOUDFLARE_API_TOKEN: your_token
|
||||
DOMAINS: "example.com,www.example.com"
|
||||
IP4_PROVIDER: cloudflare.trace
|
||||
IP6_PROVIDER: none
|
||||
UPDATE_CRON: "@every 5m"
|
||||
UPDATE_ON_START: "true"
|
||||
DELETE_ON_STOP: "false"
|
||||
DELETE_ON_FAILURE: "true"
|
||||
TTL: "1"
|
||||
PROXIED: "true"
|
||||
EMOJI: "true"
|
||||
REJECT_CLOUDFLARE_IPS: "true"
|
||||
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
checkmk:
|
||||
image: "checkmk/check-mk-raw:2.4.0-latest"
|
||||
image: "checkmk/check-mk-raw:2.4.0-2026.09.14"
|
||||
container_name: "checkmk"
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
@@ -21,7 +21,7 @@ services:
|
||||
# Prod Router
|
||||
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
||||
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk.tls=true"
|
||||
- "traefik.http.routers.checkmk.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)"
|
||||
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
||||
|
||||
Whitespace-only changes.
@@ -0,0 +1,28 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: checkmk-prod-tls
|
||||
namespace: checkmk
|
||||
spec:
|
||||
secretName: checkmk-prod-tls
|
||||
dnsNames:
|
||||
- cmk.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: checkmk
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,75 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: checkmk-service
|
||||
namespace: checkmk
|
||||
spec:
|
||||
selector:
|
||||
app: checkmk
|
||||
ports:
|
||||
- name: web
|
||||
port: 5000
|
||||
targetPort: 5000
|
||||
- name: agent-receiver
|
||||
port: 8000
|
||||
targetPort: 8000
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: checkmk-deployment
|
||||
namespace: checkmk
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: checkmk
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: checkmk
|
||||
spec:
|
||||
containers:
|
||||
- name: checkmk
|
||||
image: checkmk/check-mk-raw:2.4.0-2026.09.14
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: checkmk-secrets
|
||||
- configMapRef:
|
||||
name: checkmk-config
|
||||
ports:
|
||||
- name: web
|
||||
containerPort: 5000
|
||||
- name: agent-receiver
|
||||
containerPort: 8000
|
||||
volumeMounts:
|
||||
- name: sites
|
||||
mountPath: /omd/sites
|
||||
- name: tmp
|
||||
mountPath: /opt/omd/sites/cmk/tmp
|
||||
resources:
|
||||
requests:
|
||||
memory: "2Gi"
|
||||
cpu: "600m"
|
||||
limits:
|
||||
memory: "5Gi"
|
||||
cpu: "4"
|
||||
volumes:
|
||||
- name: sites
|
||||
persistentVolumeClaim:
|
||||
claimName: checkmk-sites-pvc
|
||||
- name: tmp
|
||||
emptyDir:
|
||||
medium: Memory
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: checkmk-sites-pvc
|
||||
namespace: checkmk
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 5Gi
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: checkmk-config
|
||||
namespace: checkmk
|
||||
data:
|
||||
TZ: Europe/Bratislava
|
||||
CMK_SITE_ID: cmk
|
||||
@@ -0,0 +1,52 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: checkmk-prod
|
||||
namespace: checkmk
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`cmk.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
services:
|
||||
- name: checkmk-service
|
||||
port: 5000
|
||||
tls:
|
||||
secretName: checkmk-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRouteTCP
|
||||
metadata:
|
||||
name: checkmk-agent-receiver
|
||||
namespace: checkmk
|
||||
spec:
|
||||
entryPoints:
|
||||
- checkmk-agent
|
||||
routes:
|
||||
- match: HostSNI(`*`)
|
||||
services:
|
||||
- name: checkmk-service
|
||||
port: 8000
|
||||
tls:
|
||||
passthrough: true
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: checkmk-local
|
||||
namespace: checkmk
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`cmk.workstation.internal`) || Host(`cmk.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: checkmk-service
|
||||
port: 5000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: checkmk
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: checkmk-secrets
|
||||
namespace: checkmk
|
||||
type: Opaque
|
||||
stringData:
|
||||
CMK_PASSWORD: "password"
|
||||
@@ -0,0 +1 @@
|
||||
secret.yaml
|
||||
Whitespace-only changes.
@@ -0,0 +1,37 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: cloudflared
|
||||
labels:
|
||||
app: cloudflared
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: cloudflared
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: cloudflared
|
||||
spec:
|
||||
containers:
|
||||
- name: cloudflared
|
||||
image: cloudflare/cloudflared:2026.9.1
|
||||
imagePullPolicy: IfNotPresent
|
||||
args:
|
||||
- tunnel
|
||||
- --no-autoupdate
|
||||
- run
|
||||
env:
|
||||
- name: TUNNEL_TOKEN
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: cloudflared-secrets
|
||||
key: TUNNEL_TOKEN
|
||||
resources:
|
||||
requests:
|
||||
memory: "32Mi"
|
||||
cpu: "30m"
|
||||
limits:
|
||||
memory: "128Mi"
|
||||
cpu: "200m"
|
||||
@@ -0,0 +1,7 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: cloudflared-secrets
|
||||
type: Opaque
|
||||
stringData:
|
||||
TUNNEL_TOKEN: your_tunnel_token_here
|
||||
@@ -0,0 +1,9 @@
|
||||
ACCOUNT_REGISTRATION=false
|
||||
HTTP_ALLOWED=false
|
||||
ALLOW_UNAUTHENTICAED=false
|
||||
AUTO_DELETE_EVERY_N_HOURS=24
|
||||
WEBROOT=/convert
|
||||
HIDE_HISTORY=false
|
||||
LANGUAGE=en
|
||||
UNAUTHED_USER_SHARING=false
|
||||
MAX_CONVERT_PROCESS=0
|
||||
@@ -0,0 +1,70 @@
|
||||
services:
|
||||
convertx:
|
||||
container_name: convertx
|
||||
image: ghcr.io/c4illin/convertx:v0.18.0
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "9992:3000"
|
||||
# https://github.com/C4illin/ConvertX#environment-variables
|
||||
environment:
|
||||
- JWT_SECRET=$(JWT_SECRET)
|
||||
- ACCOUNT_REGISTRATION=$(ACCOUNT_REGISTRATION:-false)
|
||||
- HTTP_ALLOWED=$(HTTP_ALLOWED:-false)
|
||||
- ALLOW_UNAUTHENTICATED=$(ALLOW_UNAUTHENTICATED:-false)
|
||||
- AUTO_DELETE_EVERY_N_HOURS=$(AUTO_DELETE_EVERY_N_HOURS:-24)
|
||||
- WEBROOT=$(WEBROOT)
|
||||
- HIDE_HISTORY=$(HIDE_HISTORY:-false)
|
||||
- LANGUAGE=$(LANGUAGE:-en)
|
||||
- UNAUTHENTICATED_USER_SHARING=$(UNAUTHENTICATED_USER_SHARING:-false)
|
||||
- MAX_CONVERT_PROCESS=$(MAX_CONVERT_PROCESS:-0)
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.convertx.loadbalancer.server.port=3000"
|
||||
# Prod Router
|
||||
- "traefik.http.routers.convertx.rule=(Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/convert`)"
|
||||
- "traefik.http.routers.convertx.entrypoints=websecure"
|
||||
- "traefik.http.routers.convertx.priority=50"
|
||||
- "traefik.http.routers.convertx.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.convertx-local.rule=Host(`workstation.internal`) && PathPrefix(`/convert`)"
|
||||
- "traefik.http.routers.convertx-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.convertx-local.priority=50"
|
||||
- "traefik.http.routers.convertx-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.convertx-dev.rule=Host(`gigaforust.internal`) && PathPrefix(`/convert`)"
|
||||
- "traefik.http.routers.convertx-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.convertx-dev.priority=50"
|
||||
- "traefik.http.routers.convertx-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
- data:/app/data
|
||||
|
||||
bentopdf:
|
||||
container_name: bentopdf
|
||||
image: bentopdf/bentopdf@sha256:4eb4ec8f5030faf87c29a73d3d5a2781f28a597cf440c3ab111eb96aee550871
|
||||
restart: unless-stopped
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.bentopdf.loadbalancer.server.port=8080"
|
||||
|
||||
# Prod router
|
||||
- "traefik.http.routers.bentopdf.rule=Host(`pdf.forust.xyz`)"
|
||||
- "traefik.http.routers.bentopdf.entrypoints=websecure"
|
||||
- "traefik.http.routers.bentopdf.tls.certresolver=letsencrypt"
|
||||
- "traefik.http.routers.bentopdf.tls=true"
|
||||
# Local router
|
||||
- "traefik.http.routers.bentopdf-local.rule=Host(`pdf.wokstation.internal`)"
|
||||
- "traefik.http.routers.bentopdf-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.bentopdf-local.tls=true"
|
||||
# Dev router
|
||||
- "traefik.http.routers.bentopdf-dev.rule=Host(`pdf.gigaforust.internal`)"
|
||||
- "traefik.http.routers.bentopdf-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.bentopdf-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
volumes:
|
||||
data:
|
||||
Whitespace-only changes.
@@ -0,0 +1,42 @@
|
||||
kind: Service
|
||||
apiVersion: v1
|
||||
metadata:
|
||||
name: bentopdf-service
|
||||
namespace: converters
|
||||
spec:
|
||||
selector:
|
||||
app: bentopdf
|
||||
ports:
|
||||
- port: 8080
|
||||
targetPort: 8080
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: bentopdf-deployment
|
||||
namespace: converters
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: bentopdf
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: bentopdf
|
||||
spec:
|
||||
containers:
|
||||
- image: bentopdf/bentopdf@sha256:4eb4ec8f5030faf87c29a73d3d5a2781f28a597cf440c3ab111eb96aee550871
|
||||
imagePullPolicy: Always
|
||||
name: bentopdf
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
resources:
|
||||
requests:
|
||||
memory: "50Mi"
|
||||
cpu: "50m"
|
||||
ephemeral-storage: "100Mi"
|
||||
limits:
|
||||
memory: "700Mi"
|
||||
cpu: "700m"
|
||||
ephemeral-storage: "5Gi"
|
||||
@@ -0,0 +1,42 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: convertx-prod-tls
|
||||
namespace: converters
|
||||
spec:
|
||||
secretName: convertx-prod-tls
|
||||
dnsNames:
|
||||
- forust.xyz
|
||||
- www.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: bentopdf-prod-tls
|
||||
namespace: converters
|
||||
spec:
|
||||
secretName: bentopdf-prod-tls
|
||||
dnsNames:
|
||||
- pdf.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: converters
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,16 @@
|
||||
# test manifest with docker and k8s config keys mismatch
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: convertx-config
|
||||
namespace: converters
|
||||
data:
|
||||
ACCOUNT_REGISTRATION: "false"
|
||||
HTTP_ALLOWED: "false"
|
||||
ALLOW_UNAUTHENTICAED: "false"
|
||||
AUTO_DELETE_EVERY_N_HOURS: "24"
|
||||
WEBROOT: "/convert"
|
||||
HIDE_HISTORY: "false"
|
||||
LANGUAGE: "en"
|
||||
UNAUTHED_USER_SHARING: "false"
|
||||
MAX_CONVERT_PROCESS: "0"
|
||||
@@ -0,0 +1,63 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: convertx-service
|
||||
namespace: converters
|
||||
spec:
|
||||
selector:
|
||||
app: convertx
|
||||
ports:
|
||||
- port: 3000
|
||||
targetPort: 3000
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: convertx-deployment
|
||||
namespace: converters
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: convertx
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: convertx
|
||||
spec:
|
||||
containers:
|
||||
- image: ghcr.io/c4illin/convertx:v0.18.0
|
||||
name: convertx
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: convertx-config
|
||||
- secretRef:
|
||||
name: convertx-secrets
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
volumeMounts:
|
||||
- mountPath: /data
|
||||
name: data
|
||||
resources:
|
||||
requests:
|
||||
memory: "250Mi"
|
||||
cpu: "100m"
|
||||
limits:
|
||||
cpu: "1500m"
|
||||
memory: "1.5Gi"
|
||||
volumes:
|
||||
- name: data
|
||||
persistentVolumeClaim:
|
||||
claimName: convertx-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: convertx-pvc
|
||||
namespace: converters
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 2Gi
|
||||
@@ -0,0 +1,70 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: convertx-prod
|
||||
namespace: converters
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: (Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/convert`)
|
||||
kind: Rule
|
||||
priority: 50
|
||||
services:
|
||||
- name: convertx-service
|
||||
port: 3000
|
||||
tls:
|
||||
secretName: convertx-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: convertx-local
|
||||
namespace: converters
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: (Host(`workstation.internal`) || Host(`gigaforust.internal`)) && PathPrefix(`/convert`)
|
||||
kind: Rule
|
||||
priority: 50
|
||||
services:
|
||||
- name: convertx-service
|
||||
port: 3000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: bentopdf-prod
|
||||
namespace: converters
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`pdf.forust.xyz`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: bentopdf-service
|
||||
port: 8080
|
||||
tls:
|
||||
secretName: bentopdf-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: bentopdf-local
|
||||
namespace: converters
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`pdf.workstation.internal`) || Host(`pdf.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: bentopdf-service
|
||||
port: 8080
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: converters
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: convertx-secrets
|
||||
namespace: converters
|
||||
type: Opaque
|
||||
stringData:
|
||||
jwt-secret: ""
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: Middleware
|
||||
metadata:
|
||||
name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
spec:
|
||||
plugin:
|
||||
crowdsec-bouncer:
|
||||
enabled: true
|
||||
LogLevel: INFO
|
||||
CrowdsecMode: live
|
||||
CrowdsecLapiScheme: http
|
||||
CrowdsecLapiHost: crowdsec-service.crowdsec.svc.cluster.local:8080
|
||||
CrowdsecLapiKeyFile: "/etc/traefik/secrets/traefik-api-key"
|
||||
@@ -0,0 +1,102 @@
|
||||
container_runtime: containerd
|
||||
|
||||
agent:
|
||||
acquisition: []
|
||||
additionalAcquisition:
|
||||
- labels:
|
||||
type: traefik
|
||||
limit: 1000
|
||||
query: |
|
||||
{namespace="traefik"}
|
||||
source: loki
|
||||
url: http://loki.prometheus.svc.cluster.local:3100/
|
||||
wait_for_ready: 30s
|
||||
env:
|
||||
- name: COLLECTIONS
|
||||
value: crowdsecurity/traefik crowdsecurity/base-http-scenarios
|
||||
- name: DISABLE_COLLECTIONS
|
||||
value: crowdsecurity/sshd
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
additionalLabels:
|
||||
release: prometheus-stack
|
||||
enabled: true
|
||||
# Static machine identity: agent pods mount pre-created LAPI credentials
|
||||
# (Secret crowdsec-agent-credentials, key local_api_credentials.yaml)
|
||||
# at the exact path the agent entrypoint expects. Together with the
|
||||
# patched register-init (enforced by janitor-cronjob.yaml) the agent
|
||||
# never calls `cscli lapi register` in steady state, so pod names,
|
||||
# restarts and reboots can no longer break it.
|
||||
extraVolumes:
|
||||
- name: static-creds
|
||||
secret:
|
||||
secretName: crowdsec-agent-credentials
|
||||
items:
|
||||
- key: local_api_credentials.yaml
|
||||
path: local_api_credentials.yaml
|
||||
extraVolumeMounts:
|
||||
- name: static-creds
|
||||
mountPath: /tmp_config/local_api_credentials.yaml
|
||||
subPath: local_api_credentials.yaml
|
||||
readOnly: true
|
||||
resources:
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 500Mi
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 100Mi
|
||||
|
||||
config:
|
||||
parsers:
|
||||
s02-enrich:
|
||||
mobile-whitelist.yaml: |
|
||||
name: forust/mobile-whitelist
|
||||
description: "Whitelist SWAN/4ka mobile network"
|
||||
whitelist:
|
||||
reason: "Mobile IP whitelist"
|
||||
cidr:
|
||||
- "84.245.64.0/18"
|
||||
|
||||
postoverflows:
|
||||
s01-whitelist:
|
||||
home-dynamic-ip.yaml: |
|
||||
name: forust/home-dynamic-ip
|
||||
description: "Whitelist home dynamic IP"
|
||||
whitelist:
|
||||
reason: "Home dynamic IP"
|
||||
expression:
|
||||
- evt.Overflow.Alert.Source.IP in LookupHost("ddns.forust.xyz")
|
||||
|
||||
lapi:
|
||||
env:
|
||||
- name: COLLECTIONS
|
||||
value: crowdsecurity/traefik crowdsecurity/base-http-scenarios
|
||||
- name: DISABLE_COLLECTIONS
|
||||
value: crowdsecurity/linux crowdsecurity/sshd
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
additionalLabels:
|
||||
release: prometheus-stack
|
||||
enabled: true
|
||||
persistentVolume:
|
||||
config:
|
||||
enabled: true
|
||||
size: 100Mi
|
||||
storageClassName: local-path-retain
|
||||
data:
|
||||
enabled: true
|
||||
size: 1Gi
|
||||
storageClassName: local-path-retain
|
||||
resources:
|
||||
limits:
|
||||
cpu: 400m
|
||||
memory: 500Mi
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 150Mi
|
||||
service:
|
||||
type: ClusterIP
|
||||
storeLAPICscliCredentialsInSecret: true
|
||||
@@ -0,0 +1,32 @@
|
||||
apiVersion: v1
|
||||
data:
|
||||
crowdsec-overview.json: "{\n \"__inputs\": [\n {\n \"name\": \"DS_PROMETHEUS\",\n \"label\": \"Prometheus\",\n \"description\": \"\",\n \"type\": \"datasource\",\n \"pluginId\": \"prometheus\",\n \"pluginName\": \"Prometheus\"\n }\n ],\n \"__requires\": [\n {\n \"type\": \"grafana\",\n \"id\": \"grafana\",\n \"name\": \"Grafana\",\n \"version\": \"8.1.2\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"graph\",\n \"name\": \"Graph (old)\",\n \"version\": \"\"\n },\n {\n \"type\": \"datasource\",\n \"id\": \"prometheus\",\n \"name\": \"Prometheus\",\n \"version\": \"1.0.0\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"stat\",\n \"name\": \"Stat\",\n \"version\": \"\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"timeseries\",\n \"name\": \"Time series\",\n \"version\": \"\"\n }\n ],\n \"annotations\": {\n \"list\": [\n {\n \"builtIn\": 1,\n \"datasource\": \"-- Grafana --\",\n \"enable\": true,\n \"hide\": true,\n \"iconColor\": \"rgba(0, 211, 255, 1)\",\n \"name\": \"Annotations & Alerts\",\n \"target\": {\n \"limit\": 100,\n \"matchAny\": false,\n \"tags\": [],\n \"type\": \"dashboard\"\n },\n \"type\": \"dashboard\"\n }\n ]\n },\n \"editable\": true,\n \"gnetId\": null,\n \"graphTooltip\": 0,\n \"id\": null,\n \"links\": [],\n \"panels\": [\n {\n \"collapsed\": false,\n \"datasource\": null,\n \"gridPos\": {\n \"h\": 1,\n \"w\": 24,\n \"x\": 0,\n \"y\": 0\n },\n \"id\": 24,\n \"panels\": [],\n \"title\": \"Summary\",\n \"type\": \"row\"\n },\n {\n \"cacheTimeout\": null,\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"color\": {\n \"mode\": \"thresholds\"\n },\n \"mappings\": [\n {\n \"options\": {\n \"match\": \"null\",\n \"result\": {\n \"text\": \"N/A\"\n }\n },\n \"type\": \"special\"\n }\n ],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"#E02F44\",\n \"value\": null\n },\n {\n \"color\": \"#E02F44\",\n \"value\": 10\n },\n {\n \"color\": \"#299c46\",\n \"value\": 10\n }\n ]\n },\n \"unit\": \"none\"\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 8,\n \"w\": 6,\n \"x\": 0,\n \"y\": 1\n },\n \"id\": 2,\n \"interval\": null,\n \"links\": [],\n \"maxDataPoints\": 100,\n \"options\": {\n \"colorMode\": \"background\",\n \"graphMode\": \"none\",\n \"justifyMode\": \"auto\",\n \"orientation\": \"horizontal\",\n \"reduceOptions\": {\n \"calcs\": [\n \"lastNotNull\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\n \"text\": {},\n \"textMode\": \"auto\"\n },\n \"pluginVersion\": \"8.1.2\",\n \"targets\": [\n {\n \"exemplar\": true,\n \"expr\": \"count(cs_info)\",\n \"interval\": \"\",\n \"legendFormat\": \"\",\n \"refId\": \"A\"\n }\n ],\n \"timeFrom\": null,\n \"timeShift\": null,\n \"title\": \"Running Crowdsec\",\n \"transparent\": true,\n \"type\": \"stat\"\n },\n {\n \"aliasColors\": {},\n \"bars\": false,\n \"dashLength\": 10,\n \"dashes\": false,\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"decimals\": 1,\n \"fieldConfig\": {\n \"defaults\": {\n \"links\": []\n },\n \"overrides\": []\n },\n \"fill\": 1,\n \"fillGradient\": 0,\n \"gridPos\": {\n \"h\": 8,\n \"w\": 18,\n \"x\": 6,\n \"y\": 1\n },\n \"hiddenSeries\": false,\n \"id\": 8,\n \"legend\": {\n \"alignAsTable\": true,\n \"avg\": false,\n \"current\": false,\n \"max\": false,\n \"min\": false,\n \"rightSide\": true,\n \"show\": true,\n \"sort\": \"total\",\n \"sortDesc\": true,\n \"total\": true,\n \"values\": true\n },\n \"lines\": true,\n \"linewidth\": 1,\n \"nullPointMode\": \"null\",\n \"options\": {\n \"alertThreshold\": true\n },\n \"percentage\": false,\n \"pluginVersion\": \"8.1.2\",\n \"pointradius\": 2,\n \"points\": false,\n \"renLine truncated
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/managed-by: manual
|
||||
grafana_dashboard: "1"
|
||||
name: crowdsec-crowdsec-overview
|
||||
namespace: prometheus
|
||||
---
|
||||
apiVersion: v1
|
||||
data:
|
||||
crowdsec-lapi-metrics.json: "{\n \"__inputs\": [\n {\n \"name\": \"DS_PROMETHEUS\",\n \"label\": \"Prometheus\",\n \"description\": \"\",\n \"type\": \"datasource\",\n \"pluginId\": \"prometheus\",\n \"pluginName\": \"Prometheus\"\n }\n ],\n \"__requires\": [\n {\n \"type\": \"panel\",\n \"id\": \"bargauge\",\n \"name\": \"Bar gauge\",\n \"version\": \"\"\n },\n {\n \"type\": \"grafana\",\n \"id\": \"grafana\",\n \"name\": \"Grafana\",\n \"version\": \"8.1.2\"\n },\n {\n \"type\": \"datasource\",\n \"id\": \"prometheus\",\n \"name\": \"Prometheus\",\n \"version\": \"1.0.0\"\n }\n ],\n \"annotations\": {\n \"list\": [\n {\n \"builtIn\": 1,\n \"datasource\": \"-- Grafana --\",\n \"enable\": true,\n \"hide\": true,\n \"iconColor\": \"rgba(0, 211, 255, 1)\",\n \"name\": \"Annotations & Alerts\",\n \"target\": {\n \"limit\": 100,\n \"matchAny\": false,\n \"tags\": [],\n \"type\": \"dashboard\"\n },\n \"type\": \"dashboard\"\n }\n ]\n },\n \"editable\": true,\n \"gnetId\": null,\n \"graphTooltip\": 0,\n \"id\": null,\n \"iteration\": 1655915193937,\n \"links\": [],\n \"panels\": [\n {\n \"collapsed\": false,\n \"datasource\": null,\n \"gridPos\": {\n \"h\": 1,\n \"w\": 24,\n \"x\": 0,\n \"y\": 0\n },\n \"id\": 10,\n \"panels\": [],\n \"title\": \"Agents\",\n \"type\": \"row\"\n },\n {\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"color\": {\n \"mode\": \"thresholds\"\n },\n \"mappings\": [],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"green\",\n \"value\": null\n },\n {\n \"color\": \"red\",\n \"value\": 80\n }\n ]\n }\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 8,\n \"w\": 12,\n \"x\": 0,\n \"y\": 1\n },\n \"id\": 2,\n \"options\": {\n \"displayMode\": \"gradient\",\n \"orientation\": \"vertical\",\n \"reduceOptions\": {\n \"calcs\": [\n \"lastNotNull\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\n \"showUnfilled\": false,\n \"text\": {}\n },\n \"pluginVersion\": \"8.1.2\",\n \"repeat\": \"query0\",\n \"repeatDirection\": \"h\",\n \"targets\": [\n {\n \"exemplar\": false,\n \"expr\": \"sum(rate(cs_lapi_request_duration_seconds_bucket{endpoint=\\\"/v1/watchers/login\\\", instance=\\\"$lapi\\\"}[$__rate_interval])) by (le)\",\n \"format\": \"heatmap\",\n \"interval\": \"\",\n \"legendFormat\": \"{{le}}\",\n \"refId\": \"A\"\n }\n ],\n \"title\": \"Agents Login\",\n \"type\": \"heatmap\"\n },\n {\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"color\": {\n \"mode\": \"thresholds\"\n },\n \"mappings\": [],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"green\",\n \"value\": null\n }\n ]\n },\n \"unit\": \"none\"\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 8,\n \"w\": 12,\n \"x\": 12,\n \"y\": 1\n },\n \"id\": 6,\n \"options\": {\n \"displayMode\": \"gradient\",\n \"orientation\": \"auto\",\n \"reduceOptions\": {\n \"calcs\": [\n \"lastNotNull\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\n \"showUnfilled\": false,\n \"text\": {}\n },\n \"pluginVersion\": \"8.1.2\",\n \"targets\": [\n {\n \"exemplar\": true,\n \"expr\": \"sum(rate(cs_lapi_request_duration_seconds_bucket{endpoint=\\\"/v1/watchers/login\\\"}[$__rate_interval])) by (le)\",\n \"format\": \"heatmap\",\n \"interval\": \"\",\n \"legendFormat\": \"{{le}}\",\n \"refId\": \"A\"\n }\n ],\n \"title\": \"Heartbeat\",\n \"type\": \"heatmap\"\n },\n {\n \"collapsed\": false,\n \"datasource\": null,\n \"gridPos\": {\n \"h\": 1,\n \"w\": 24,\n \"x\": 0,\n \"y\": 9\n },\n \"id\": 12,\n \"panels\": [],\n \"title\": \"Decisions\",\n \"type\": \"row\"\n },\n {\n \"datasource\": \"${DS_PROMETHEUS}\",\n Line truncated
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/managed-by: manual
|
||||
grafana_dashboard: "1"
|
||||
name: crowdsec-crowdsec-lapi-metrics
|
||||
namespace: prometheus
|
||||
---
|
||||
apiVersion: v1
|
||||
data:
|
||||
crowdsec-insight.json: "{\n \"__inputs\": [\n {\n \"name\": \"DS_PROMETHEUS\",\n \"label\": \"Prometheus\",\n \"description\": \"\",\n \"type\": \"datasource\",\n \"pluginId\": \"prometheus\",\n \"pluginName\": \"Prometheus\"\n }\n ],\n \"__requires\": [\n {\n \"type\": \"panel\",\n \"id\": \"bargauge\",\n \"name\": \"Bar gauge\",\n \"version\": \"\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"gauge\",\n \"name\": \"Gauge\",\n \"version\": \"\"\n },\n {\n \"type\": \"grafana\",\n \"id\": \"grafana\",\n \"name\": \"Grafana\",\n \"version\": \"8.1.2\"\n },\n {\n \"type\": \"datasource\",\n \"id\": \"prometheus\",\n \"name\": \"Prometheus\",\n \"version\": \"1.0.0\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"stat\",\n \"name\": \"Stat\",\n \"version\": \"\"\n }\n ],\n \"annotations\": {\n \"list\": [\n {\n \"builtIn\": 1,\n \"datasource\": \"-- Grafana --\",\n \"enable\": true,\n \"hide\": true,\n \"iconColor\": \"rgba(0, 211, 255, 1)\",\n \"name\": \"Annotations & Alerts\",\n \"target\": {\n \"limit\": 100,\n \"matchAny\": false,\n \"tags\": [],\n \"type\": \"dashboard\"\n },\n \"type\": \"dashboard\"\n }\n ]\n },\n \"editable\": true,\n \"gnetId\": null,\n \"graphTooltip\": 0,\n \"id\": null,\n \"iteration\": 1655915159751,\n \"links\": [],\n \"panels\": [\n {\n \"collapsed\": true,\n \"datasource\": null,\n \"gridPos\": {\n \"h\": 1,\n \"w\": 24,\n \"x\": 0,\n \"y\": 0\n },\n \"id\": 22,\n \"panels\": [\n {\n \"cacheTimeout\": null,\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"color\": {\n \"mode\": \"thresholds\"\n },\n \"mappings\": [\n {\n \"options\": {\n \"match\": \"null\",\n \"result\": {\n \"text\": \"N/A\"\n }\n },\n \"type\": \"special\"\n }\n ],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"green\",\n \"value\": null\n },\n {\n \"color\": \"red\",\n \"value\": 80\n }\n ]\n },\n \"unit\": \"dateTimeAsIso\"\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 9,\n \"w\": 5,\n \"x\": 2,\n \"y\": 1\n },\n \"id\": 2,\n \"interval\": null,\n \"links\": [],\n \"maxDataPoints\": 100,\n \"options\": {\n \"colorMode\": \"none\",\n \"graphMode\": \"none\",\n \"justifyMode\": \"auto\",\n \"orientation\": \"horizontal\",\n \"reduceOptions\": {\n \"calcs\": [\n \"lastNotNull\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\n \"text\": {},\n \"textMode\": \"auto\"\n },\n \"pluginVersion\": \"8.1.2\",\n \"targets\": [\n {\n \"exemplar\": true,\n \"expr\": \"(process_start_time_seconds{instance=\\\"$instance\\\"})*1000\",\n \"interval\": \"\",\n \"legendFormat\": \"{{instance}}\",\n \"refId\": \"A\"\n }\n ],\n \"timeFrom\": null,\n \"timeShift\": null,\n \"title\": \"Up since\",\n \"type\": \"stat\"\n },\n {\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"displayName\": \"\",\n \"mappings\": [],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"green\",\n \"value\": null\n }\n ]\n },\n \"unit\": \"decbytes\"\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 9,\n \"w\": 5,\n \"x\": 7,\n \"y\": 1\n },\n \"id\": 4,\n \"options\": {\n \"orientation\": \"auto\",\n \"reduceOptions\": {\n \"calcs\": [\n \"mean\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\Line truncated
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/managed-by: manual
|
||||
grafana_dashboard: "1"
|
||||
name: crowdsec-crowdsec-insight
|
||||
namespace: prometheus
|
||||
@@ -0,0 +1,195 @@
|
||||
# CrowdSec self-healing: static machine identity + enforcement loops.
|
||||
#
|
||||
# Problem it fixes: the chart's agent init container runs
|
||||
# `cscli lapi register --machine "$POD_NAME" ...`
|
||||
# unconditionally. Credentials live in an emptyDir, the machine row lives
|
||||
# in LAPI's persistent DB. Any init re-run for an already-known pod name
|
||||
# (kubelet restart, node reboot) dies with
|
||||
# 403 Forbidden: user '<pod>' already exist
|
||||
# and the DaemonSet pod sticks in Init forever. Every DS restart also
|
||||
# leaves an orphan machine row that is never cleaned.
|
||||
#
|
||||
# Design (name-independent):
|
||||
# * Agent identity is a STATIC machine `crowdsec-agent-workstation`
|
||||
# whose password lives in Secret `crowdsec-agent-credentials`
|
||||
# (created once, manually - like all other secrets in this repo).
|
||||
# The secret is mounted into agent pods at
|
||||
# /tmp_config/local_api_credentials.yaml (see extraVolumeMounts in
|
||||
# crowdsec-values.yaml), which is exactly the path the agent's main
|
||||
# container copies into place at startup.
|
||||
# * The DS init command is patched (strategic merge, by container name)
|
||||
# to SKIP registration when that file exists, keeping the legacy
|
||||
# register path only as fallback. Detection marker in the patched
|
||||
# command: `[ -s /tmp_config`.
|
||||
# * This CronJob enforces the desired state hourly, so recovery is
|
||||
# automatic even after `helm upgrade` reverts the DS patch or the
|
||||
# LAPI database is wiped:
|
||||
# 1. patch DS init if it still has the unconditional register
|
||||
# (no-op otherwise - no restart churn);
|
||||
# 2. prune machines with no heartbeat for 2h (orphan hygiene);
|
||||
# 3. ensure the static machine exists, recreating it with the
|
||||
# Secret password if missing (agent retry loops reconnect
|
||||
# on their own - same name + same password);
|
||||
# 4. prune bouncer entries idle for 30d.
|
||||
#
|
||||
# Manual apply (crowdsec/k8s is NOT managed by deploy.yaml):
|
||||
# kubectl apply -f crowdsec/k8s/janitor-cronjob.yaml
|
||||
# Force a run:
|
||||
# kubectl create job -n crowdsec --from=cronjob/crowdsec-janitor janitor-now
|
||||
#
|
||||
# Helm upgrades: the janitor's strategic patch puts the DS field under
|
||||
# the `kubectl-patch` field manager, so a plain `helm upgrade` FAILS
|
||||
# with an SSA conflict on initContainers[].command. Procedure:
|
||||
# 1. revert init to chart state (kills the conflict):
|
||||
# helm template crowdsec crowdsec/crowdsec --version <ver> \
|
||||
# -n crowdsec -f crowdsec/k8s/crowdsec-values.yaml > /tmp/r.yaml
|
||||
# python3 -c "import yaml,json; ..." # build revert patch from
|
||||
# the rendered DaemonSet init command, then
|
||||
# kubectl patch ds crowdsec-agent -n crowdsec \
|
||||
# --type strategic -p "\$(cat /tmp/revert_patch.json)"
|
||||
# 2. helm upgrade --install crowdsec ... (no --force needed)
|
||||
# 3. janitor-now right away (upgrade reverts init; new pods would
|
||||
# sit in Init until the next hourly run otherwise).
|
||||
#
|
||||
# One-time bootstrap (order matters):
|
||||
# 1. Create Secret + static machine (see commands in chat).
|
||||
# 2. Apply this file, trigger janitor-now, wait for agent 1/1.
|
||||
# 3. One-time orphan cleanup:
|
||||
# kubectl exec -n crowdsec deploy/crowdsec-lapi -- \
|
||||
# cscli machines prune --duration 1h --force
|
||||
# 4. Only then `helm upgrade` crowdsec with the extraVolumes values.
|
||||
# Upgrade reverts the DS patch; trigger janitor-now right after it
|
||||
# (otherwise new pods sit in Init until the next hourly run, then
|
||||
# self-heal anyway).
|
||||
#
|
||||
# Password rotation: update the Secret, delete the machine
|
||||
# (`cscli machines delete crowdsec-agent-workstation`), trigger
|
||||
# janitor-now (recreates it), then `kubectl rollout restart
|
||||
# ds/crowdsec-agent -n crowdsec` (agent reads the file at startup only).
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["pods"]
|
||||
verbs: ["get", "list"]
|
||||
- apiGroups: [""]
|
||||
resources: ["pods/exec"]
|
||||
verbs: ["create"]
|
||||
- apiGroups: ["apps"]
|
||||
resources: ["daemonsets"]
|
||||
verbs: ["get", "patch"]
|
||||
# `kubectl exec deploy/<name>` resolves deploy -> replicaset -> pod,
|
||||
# which needs read access to these (exec itself is pods/exec above).
|
||||
- apiGroups: ["apps"]
|
||||
resources: ["deployments", "replicasets"]
|
||||
verbs: ["get", "list"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
roleRef:
|
||||
kind: Role
|
||||
name: crowdsec-janitor
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
---
|
||||
apiVersion: batch/v1
|
||||
kind: CronJob
|
||||
metadata:
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
spec:
|
||||
schedule: "17 * * * *"
|
||||
concurrencyPolicy: Forbid
|
||||
successfulJobsHistoryLimit: 3
|
||||
failedJobsHistoryLimit: 3
|
||||
jobTemplate:
|
||||
spec:
|
||||
activeDeadlineSeconds: 300
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
spec:
|
||||
serviceAccountName: crowdsec-janitor
|
||||
restartPolicy: OnFailure
|
||||
containers:
|
||||
- name: janitor
|
||||
# Same image the chart itself uses for registration jobs;
|
||||
# IfNotPresent so it works while the node is offline
|
||||
# (layer cached from the chart install).
|
||||
image: alpine/kubectl:latest
|
||||
imagePullPolicy: IfNotPresent
|
||||
env:
|
||||
- name: AGENT_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: crowdsec-agent-credentials
|
||||
key: password
|
||||
command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- |
|
||||
set -eu
|
||||
LAPI_EXEC="kubectl exec -n crowdsec deploy/crowdsec-lapi --"
|
||||
echo "== 1. enforce patched agent init =="
|
||||
CUR=$(kubectl get ds crowdsec-agent -n crowdsec \
|
||||
-o jsonpath='{.spec.template.spec.initContainers[0].command[2]}')
|
||||
case "$CUR" in
|
||||
*'-s /tmp_config'*)
|
||||
echo "init already patched"
|
||||
;;
|
||||
*)
|
||||
echo "patching init"
|
||||
WAIT='until nc "$LAPI_HOST" "$LAPI_PORT" -z'
|
||||
WAIT="$WAIT; do echo waiting for lapi to start; sleep 5; done"
|
||||
LINK='ln -s /staging/etc/crowdsec /etc/crowdsec'
|
||||
REG='cscli lapi register --machine "$USERNAME"'
|
||||
REG="$REG -u \"\$LAPI_URL\" --token \"\$REGISTRATION_TOKEN\""
|
||||
CREDS=/tmp_config/local_api_credentials.yaml
|
||||
CMD="$WAIT; $LINK; [ -s $CREDS ] || {"
|
||||
CMD="$CMD $REG && cp"
|
||||
CMD="$CMD /etc/crowdsec/local_api_credentials.yaml $CREDS; }"
|
||||
ESC=$(printf '%s' "$CMD" | sed 's/"/\\"/g')
|
||||
PATCH='{"spec":{"template":{"spec":{"initContainers":'
|
||||
PATCH=$PATCH'[{"name":"wait-for-lapi-and-register",'
|
||||
PATCH=$PATCH'"command":["sh","-c","'$ESC'"]}]}}}}'
|
||||
kubectl patch ds crowdsec-agent -n crowdsec \
|
||||
--type strategic -p "$PATCH"
|
||||
;;
|
||||
esac
|
||||
echo "== 2. prune orphan machines (no heartbeat for 2h) =="
|
||||
$LAPI_EXEC cscli machines prune --duration 2h --force
|
||||
echo "== 3. ensure static machine exists =="
|
||||
if $LAPI_EXEC cscli machines inspect \
|
||||
crowdsec-agent-workstation >/dev/null 2>&1; then
|
||||
echo "static machine present"
|
||||
else
|
||||
echo "recreating static machine"
|
||||
$LAPI_EXEC cscli machines add crowdsec-agent-workstation \
|
||||
--password "$AGENT_PASSWORD" --force
|
||||
fi
|
||||
echo "== 4. prune stale bouncers (no pull for 30d) =="
|
||||
$LAPI_EXEC cscli bouncers prune -d 720h --force
|
||||
@@ -0,0 +1,6 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
@@ -0,0 +1,34 @@
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: crowdsec-lapi
|
||||
namespace: crowdsec
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels:
|
||||
k8s-app: crowdsec
|
||||
type: lapi
|
||||
policyTypes:
|
||||
- Ingress
|
||||
ingress:
|
||||
- from:
|
||||
- namespaceSelector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: traefik
|
||||
podSelector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: traefik
|
||||
- podSelector:
|
||||
matchLabels:
|
||||
k8s-app: crowdsec
|
||||
type: agent
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 8080
|
||||
- from:
|
||||
- namespaceSelector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: prometheus
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 6060
|
||||
+41
-41
@@ -1,46 +1,46 @@
|
||||
services:
|
||||
dockmon:
|
||||
image: darthnorse/dockmon:latest
|
||||
container_name: dockmon
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - 8000:443
|
||||
volumes:
|
||||
- data:/app/data
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
healthcheck:
|
||||
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||
dockmon:
|
||||
image: darthnorse/dockmon:2.4.5
|
||||
container_name: dockmon
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - 8000:443
|
||||
volumes:
|
||||
- data:/app/data
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-k", "-f", "https://localhost:443/health"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.dockmon.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
|
||||
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||
# Prod Router
|
||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.dockmon.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
|
||||
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=dockmon
|
||||
- glance.url=https://dockmon.forust.xyz/
|
||||
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
||||
networks:
|
||||
- proxy
|
||||
# Glance Metadata
|
||||
- glance.name=dockmon
|
||||
- glance.url=https://dockmon.forust.xyz/
|
||||
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
data:
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
proxy:
|
||||
external: true
|
||||
Whitespace-only changes.
@@ -0,0 +1,28 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: dockmon-prod-tls
|
||||
namespace: dockmon
|
||||
spec:
|
||||
secretName: dockmon-prod-tls
|
||||
dnsNames:
|
||||
- dockmon.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: dockmon
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,68 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: dockmon-service
|
||||
namespace: dockmon
|
||||
spec:
|
||||
clusterIP: None
|
||||
selector:
|
||||
app: dockmon
|
||||
ports:
|
||||
- port: 443
|
||||
targetPort: 443
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: dockmon-statefulset
|
||||
namespace: dockmon
|
||||
spec:
|
||||
serviceName: dockmon-service
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: dockmon
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: dockmon
|
||||
spec:
|
||||
containers:
|
||||
- name: dockmon
|
||||
image: darthnorse/dockmon:2.4.5
|
||||
ports:
|
||||
- containerPort: 443
|
||||
volumeMounts:
|
||||
- name: data
|
||||
mountPath: /app/data
|
||||
- name: docker-sock
|
||||
mountPath: /var/run/docker.sock
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /health
|
||||
port: 443
|
||||
scheme: HTTPS
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 10
|
||||
failureThreshold: 3
|
||||
resources:
|
||||
requests:
|
||||
memory: "512Mi"
|
||||
cpu: "200m"
|
||||
limits:
|
||||
memory: "1.5Gi"
|
||||
cpu: "700m "
|
||||
volumes:
|
||||
- name: docker-sock
|
||||
hostPath:
|
||||
path: /var/run/docker.sock
|
||||
type: Socket
|
||||
volumeClaimTemplates:
|
||||
- metadata:
|
||||
name: data
|
||||
spec:
|
||||
accessModes: ["ReadWriteOnce"]
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
@@ -0,0 +1,47 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: ServersTransport
|
||||
metadata:
|
||||
name: dockmon-transport
|
||||
namespace: dockmon
|
||||
spec:
|
||||
insecureSkipVerify: true
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: dockmon-prod
|
||||
namespace: dockmon
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`dockmon.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
- name: security-headers@file
|
||||
services:
|
||||
- name: dockmon-service
|
||||
port: 443
|
||||
serversTransport: dockmon-transport
|
||||
tls:
|
||||
secretName: dockmon-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: dockmon-local
|
||||
namespace: dockmon
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`dockmon.workstation.internal`) || Host(`dockmon.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: dockmon-service
|
||||
port: 443
|
||||
serversTransport: dockmon-transport
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: dockmon
|
||||
@@ -1,7 +1,7 @@
|
||||
services:
|
||||
downtify:
|
||||
container_name: downtify
|
||||
image: ghcr.io/henriquesebastiao/downtify:latest
|
||||
image: ghcr.io/henriquesebastiao/downtify:3.1.0
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - '7077:8000'
|
||||
@@ -11,11 +11,11 @@ services:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.downtify.loadbalancer.server.port=8000"
|
||||
|
||||
# Prod Router
|
||||
# Prod Router
|
||||
- "traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)"
|
||||
- "traefik.http.routers.downtify.entrypoints=websecure"
|
||||
- "traefik.http.routers.downtify.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.downtify.tls=true"
|
||||
- "traefik.http.routers.downtify.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`)"
|
||||
- "traefik.http.routers.downtify-local.entrypoints=websecure"
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: downtify-service
|
||||
namespace: downtify
|
||||
spec:
|
||||
selector:
|
||||
app: downtify
|
||||
ports:
|
||||
- port: 8000
|
||||
targetPort: 8000
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: downtify-deployment
|
||||
namespace: downtify
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: downtify
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: downtify
|
||||
spec:
|
||||
containers:
|
||||
- name: downtify
|
||||
image: ghcr.io/henriquesebastiao/downtify:3.1.0
|
||||
ports:
|
||||
- containerPort: 8000
|
||||
volumeMounts:
|
||||
- name: downloads
|
||||
mountPath: /downloads
|
||||
resources:
|
||||
requests:
|
||||
memory: "128Mi"
|
||||
cpu: "200m"
|
||||
limits:
|
||||
memory: "1Gi"
|
||||
cpu: "1"
|
||||
volumes:
|
||||
- name: downloads
|
||||
persistentVolumeClaim:
|
||||
claimName: downtify-downloads-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: downtify-downloads-pvc
|
||||
namespace: downtify
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 10Gi
|
||||
@@ -0,0 +1,37 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: downtify-prod
|
||||
namespace: downtify
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`downtify.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
- name: security-chain@file
|
||||
services:
|
||||
- name: downtify-service
|
||||
port: 8000
|
||||
tls:
|
||||
secretName: downtify-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: downtify-local
|
||||
namespace: downtify
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`downtify.workstation.internal`) || Host(`downtify.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: downtify-service
|
||||
port: 8000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: downtify
|
||||
@@ -3,12 +3,13 @@ services:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
image: gcr.forust.xyz/forust/dtek-notif:latest
|
||||
pull_policy: build
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- TZ=Europe/Kyiv
|
||||
|
||||
dns:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
networks:
|
||||
- default
|
||||
- default
|
||||
+388
-418
File diff suppressed because it is too large.
Load diff
@@ -9,5 +9,6 @@ WEBINAR_CHECK_INTERVAL=60
|
||||
REDIS_HOST=redis
|
||||
REDIS_PORT=6379
|
||||
PLAYWRIGHT_WS=ws://playwright-service:3000/ws
|
||||
TZ=Europe/Kyiv
|
||||
WEBINAR_TELEGRAM_TOKEN=your_telegram_bot_token_here
|
||||
WEBINAR_ADMIN_ID=123456789
|
||||
@@ -0,0 +1 @@
|
||||
1.56.0
|
||||
@@ -1,11 +1,11 @@
|
||||
services:
|
||||
redis:
|
||||
image: redis:alpine
|
||||
image: redis:8.10.1-alpine
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- redis-data:/data
|
||||
healthcheck:
|
||||
test: [ "CMD", "redis-cli", "ping" ]
|
||||
test: ["CMD", "redis-cli", "ping"]
|
||||
interval: 5s
|
||||
timeout: 3s
|
||||
retries: 5
|
||||
@@ -17,13 +17,15 @@ services:
|
||||
|
||||
session-keeper:
|
||||
build: ./phpsessid-bot
|
||||
image: gcr.forust.xyz/forust/session-keeper:latest
|
||||
pull_policy: build
|
||||
env_file: .env
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
redis:
|
||||
condition: service_healthy
|
||||
healthcheck:
|
||||
test: [ "CMD-SHELL", "redis-cli -h redis EXISTS EDU_PHPSESSID | grep -q 1" ]
|
||||
test: ["CMD-SHELL", "redis-cli -h redis EXISTS EDU_PHPSESSID | grep -q 1"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
retries: 10
|
||||
@@ -31,6 +33,8 @@ services:
|
||||
|
||||
webinar-checker:
|
||||
build: ./webinar-checker
|
||||
image: gcr.forust.xyz/forust/webinar-checker:latest
|
||||
pull_policy: build
|
||||
env_file: .env
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
|
||||
Whitespace-only changes.
@@ -0,0 +1,77 @@
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: PrometheusRule
|
||||
metadata:
|
||||
name: edu-master-webinar
|
||||
namespace: edu-master
|
||||
labels:
|
||||
release: prometheus-stack
|
||||
spec:
|
||||
groups:
|
||||
- name: edu_master.webinar
|
||||
rules:
|
||||
# No successful webinar check for 5m (~2-3 missed 2-min checks).
|
||||
# Catches: playwright hangs/timeouts, version skew, site changes, hung job.
|
||||
- alert: WebinarCheckerNoSuccessfulCheck
|
||||
expr: |
|
||||
(time() - webinar_check_last_success_timestamp_seconds > 300)
|
||||
and (webinar_check_last_run_timestamp_seconds > 0)
|
||||
for: 2m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Webinar checker has no successful check for 5m"
|
||||
description: "edu-master/webinar-checker: last successful webinar check was {{ $value | humanizeDuration }} ago. Checks are failing or hanging (see consecutive failures alert). Notifications about new webinars are NOT being sent."
|
||||
|
||||
# Fast path: 3 consecutive failures (~6+ min at 2-min interval).
|
||||
- alert: WebinarCheckerConsecutiveFailures
|
||||
expr: |
|
||||
webinar_check_consecutive_failures >= 3
|
||||
for: 5m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Webinar checker failing consecutively"
|
||||
description: 'edu-master/webinar-checker: {{ $value }} consecutive webinar check failures (timeout / playwright error / page error). Check pod logs (Loki: {namespace="edu-master", container="webinar-checker"}).'
|
||||
|
||||
# Metrics endpoint not scraped for 10m: pod down, metrics server dead, or ServiceMonitor broken.
|
||||
- alert: WebinarCheckerScrapeDown
|
||||
expr: |
|
||||
absent(webinar_check_last_run_timestamp_seconds) == 1
|
||||
for: 10m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Webinar checker metrics missing"
|
||||
description: "edu-master/webinar-checker: no metrics series for 10m. Pod may be down, metrics server dead, or ServiceMonitor/Service broken. Webinar checks are unobserved."
|
||||
|
||||
# EDU session lost: session-keeper down or credentials expired. Without PHPSESSID every check is skipped.
|
||||
- alert: EduPhpsessidMissing
|
||||
expr: |
|
||||
edu_phpsessid_present == 0
|
||||
for: 10m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "EDU_PHPSESSID missing"
|
||||
description: "edu-master: EDU_PHPSESSID absent from redis for 10m. Webinar/diari/schedule checks are all skipped. Check session-keeper logs and EDU credentials."
|
||||
|
||||
# Hard deps: checker and playwright deployments unavailable.
|
||||
- alert: WebinarCheckerDeploymentDown
|
||||
expr: |
|
||||
kube_deployment_status_replicas_unavailable{deployment="webinar-checker", namespace="edu-master"} > 0
|
||||
for: 10m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Webinar checker deployment unavailable"
|
||||
description: "edu-master/webinar-checker deployment has {{ $value }} unavailable replica(s) for 10m."
|
||||
|
||||
- alert: PlaywrightServiceDown
|
||||
expr: |
|
||||
kube_deployment_status_replicas_unavailable{deployment="playwright-service", namespace="edu-master"} > 0
|
||||
for: 10m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Playwright service unavailable"
|
||||
description: "edu-master/playwright-service deployment has {{ $value }} unavailable replica(s) for 10m. All webinar/diari/schedule checks fail without it."
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: edu-master
|
||||
@@ -0,0 +1,58 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: playwright-service
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-playwright
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-playwright
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: edu-master-playwright
|
||||
spec:
|
||||
containers:
|
||||
- name: playwright
|
||||
# renovate: datasource=docker depName=mcr.microsoft.com/playwright versioning=docker
|
||||
image: mcr.microsoft.com/playwright:v1.56.0-jammy
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- npx
|
||||
- -y
|
||||
- playwright@1.56.0
|
||||
- run-server
|
||||
- --port
|
||||
- "3000"
|
||||
- --path
|
||||
- /ws
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
readinessProbe:
|
||||
tcpSocket:
|
||||
port: 3000
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 3
|
||||
livenessProbe:
|
||||
tcpSocket:
|
||||
port: 3000
|
||||
initialDelaySeconds: 15
|
||||
periodSeconds: 20
|
||||
timeoutSeconds: 3
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: playwright-service
|
||||
namespace: edu-master
|
||||
spec:
|
||||
selector:
|
||||
app: edu-master-playwright
|
||||
ports:
|
||||
- name: ws
|
||||
port: 3000
|
||||
targetPort: 3000
|
||||
@@ -0,0 +1,75 @@
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: redis
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-redis
|
||||
spec:
|
||||
serviceName: redis
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-redis
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: edu-master-redis
|
||||
spec:
|
||||
containers:
|
||||
- name: redis
|
||||
image: redis:8.10.1-alpine
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 6379
|
||||
volumeMounts:
|
||||
- name: redis-data
|
||||
mountPath: /data
|
||||
resources:
|
||||
requests:
|
||||
cpu: 25m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
cpu: 250m
|
||||
memory: 256Mi
|
||||
readinessProbe:
|
||||
exec:
|
||||
command: ["redis-cli", "ping"]
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 5
|
||||
timeoutSeconds: 3
|
||||
livenessProbe:
|
||||
exec:
|
||||
command: ["redis-cli", "ping"]
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 3
|
||||
volumes:
|
||||
- name: redis-data
|
||||
persistentVolumeClaim:
|
||||
claimName: redis-data-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: redis-data-pvc
|
||||
namespace: edu-master
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: redis
|
||||
namespace: edu-master
|
||||
spec:
|
||||
selector:
|
||||
app: edu-master-redis
|
||||
ports:
|
||||
- name: redis
|
||||
port: 6379
|
||||
targetPort: 6379
|
||||
@@ -0,0 +1,50 @@
|
||||
# One-time Job to migrate redis state from docker compose to k8s (maintenance window).
|
||||
# The .example file is not applied by the deploy pipeline (mask *.example.yaml).
|
||||
#
|
||||
# Runbook:
|
||||
# 1. docker compose -f <repo>/edu_master/compose.yaml stop # SIGTERM -> redis will flush dump.rdb
|
||||
# 2. docker run --rm -v edu_master_redis-data:/data \
|
||||
# -v /tmp/edu-master-backup:/backup \
|
||||
# redis:alpine sh -c "cp /data/dump.rdb /backup/ && ls -la /backup"
|
||||
# 3. kubectl apply -f edu_master/k8s/namespace.yaml
|
||||
# 4. kubectl apply -f <only the PVC from redis.yaml> # seed must come BEFORE redis pod starts
|
||||
# 5. kubectl apply -f edu_master/k8s/restore-seed-job.yaml.example
|
||||
# kubectl wait --for=condition=complete job/redis-restore-seed -n edu-master --timeout=120s
|
||||
# 6. kubectl delete job redis-restore-seed -n edu-master
|
||||
# 7. kubectl apply -f edu_master/k8s/ -R # apply remaining manifests
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: redis-restore-seed
|
||||
namespace: edu-master
|
||||
spec:
|
||||
backoffLimit: 2
|
||||
ttlSecondsAfterFinished: 3600
|
||||
template:
|
||||
spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: seed
|
||||
image: redis:alpine
|
||||
command:
|
||||
- /bin/sh
|
||||
- -ec
|
||||
- |
|
||||
ls -la /backup
|
||||
cp /backup/dump.rdb /data/dump.rdb
|
||||
chmod 644 /data/dump.rdb
|
||||
ls -la /data
|
||||
volumeMounts:
|
||||
- name: redis-data
|
||||
mountPath: /data
|
||||
- name: backup
|
||||
mountPath: /backup
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: redis-data
|
||||
persistentVolumeClaim:
|
||||
claimName: redis-data-pvc
|
||||
- name: backup
|
||||
hostPath:
|
||||
path: /tmp/edu-master-backup
|
||||
type: DirectoryOrCreate
|
||||
@@ -0,0 +1,29 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: edu-master-secrets
|
||||
namespace: edu-master
|
||||
type: Opaque
|
||||
stringData:
|
||||
# Session keeper credentials
|
||||
KEEPER_LOGIN: ""
|
||||
KEEPER_PASSWORD: ""
|
||||
KEEPER_INTERVAL: "10"
|
||||
# EDU links
|
||||
EDU_URL_BASE: "https://edu.edu.vn.ua"
|
||||
EDU_URL_LOGIN: "/user/login"
|
||||
EDU_URL_COURSES: "/course/userlist"
|
||||
EDU_URL_WEBINAR: "/webinar/useractive"
|
||||
# Playwright
|
||||
USER_AGENT: ""
|
||||
PLAYWRIGHT_WS: "ws://playwright-service:3000/ws"
|
||||
# Webinar-checker
|
||||
WEBINAR_TELEGRAM_TOKEN: ""
|
||||
WEBINAR_ADMIN_ID: ""
|
||||
WEBINAR_CHECK_INTERVAL: "60"
|
||||
# Prometheus metrics endpoint (scraped via ServiceMonitor, alerts in k8s/alerts.yaml)
|
||||
METRICS_PORT: "8000"
|
||||
# Database
|
||||
REDIS_HOST: "redis"
|
||||
REDIS_PORT: "6379"
|
||||
TZ: "Europe/Kyiv"
|
||||
@@ -0,0 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: webinar-checker
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-webinar-checker
|
||||
spec:
|
||||
selector:
|
||||
app: edu-master-webinar-checker
|
||||
ports:
|
||||
- name: metrics
|
||||
port: 8000
|
||||
targetPort: metrics
|
||||
protocol: TCP
|
||||
@@ -0,0 +1,16 @@
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: webinar-checker
|
||||
namespace: edu-master
|
||||
labels:
|
||||
release: prometheus-stack
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-webinar-checker
|
||||
endpoints:
|
||||
- port: metrics
|
||||
path: /metrics
|
||||
interval: 30s
|
||||
scrapeTimeout: 10s
|
||||
@@ -0,0 +1,52 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: session-keeper
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-session-keeper
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-session-keeper
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: edu-master-session-keeper
|
||||
spec:
|
||||
initContainers:
|
||||
- name: wait-redis
|
||||
image: redis:8.10.1-alpine
|
||||
command:
|
||||
- /bin/sh
|
||||
- -ec
|
||||
- |
|
||||
i=0
|
||||
until redis-cli -h redis ping | grep -q PONG; do
|
||||
i=$((i+1))
|
||||
[ "$i" -ge 300 ] && echo "TIMEOUT: redis not ready" && exit 1
|
||||
sleep 2
|
||||
done
|
||||
echo "redis is ready"
|
||||
containers:
|
||||
- name: session-keeper
|
||||
image: gcr.forust.xyz/forust/session-keeper:latest
|
||||
imagePullPolicy: Always
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: edu-master-secrets
|
||||
resources:
|
||||
requests:
|
||||
cpu: 25m
|
||||
memory: 96Mi
|
||||
limits:
|
||||
cpu: 250m
|
||||
memory: 256Mi
|
||||
readinessProbe:
|
||||
exec:
|
||||
command: ["/bin/sh", "-ec", "redis-cli -h redis EXISTS EDU_PHPSESSID | grep -q 1"]
|
||||
initialDelaySeconds: 15
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 10
|
||||
@@ -0,0 +1,66 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: webinar-checker
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-webinar-checker
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-webinar-checker
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: edu-master-webinar-checker
|
||||
spec:
|
||||
# Enforces dependency order like compose depends_on:
|
||||
# redis healthy -> session-keeper healthy (EXISTS EDU_PHPSESSID) -> playwright started
|
||||
initContainers:
|
||||
- name: wait-deps
|
||||
image: redis:8.10.1-alpine
|
||||
command:
|
||||
- /bin/sh
|
||||
- -ec
|
||||
- |
|
||||
i=0
|
||||
until redis-cli -h redis ping | grep -q PONG; do
|
||||
i=$((i+1))
|
||||
[ "$i" -ge 300 ] && echo "TIMEOUT: redis not ready" && exit 1
|
||||
sleep 2
|
||||
done
|
||||
echo "redis ok"
|
||||
until [ "$(redis-cli -h redis EXISTS EDU_PHPSESSID)" = "1" ]; do
|
||||
i=$((i+1))
|
||||
[ "$i" -ge 300 ] && echo "TIMEOUT: no PHPSESSID (session-keeper down?)" && exit 1
|
||||
sleep 2
|
||||
done
|
||||
echo "PHPSESSID ok"
|
||||
until nc -z playwright-service 3000; do
|
||||
i=$((i+1))
|
||||
[ "$i" -ge 300 ] && echo "TIMEOUT: playwright-service not reachable" && exit 1
|
||||
sleep 2
|
||||
done
|
||||
echo "playwright ok"
|
||||
containers:
|
||||
- name: webinar-checker
|
||||
image: gcr.forust.xyz/forust/webinar-checker:latest
|
||||
imagePullPolicy: Always
|
||||
ports:
|
||||
- name: metrics
|
||||
containerPort: 8000
|
||||
protocol: TCP
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: edu-master-secrets
|
||||
env:
|
||||
- name: TZ
|
||||
value: "Europe/Kyiv"
|
||||
resources:
|
||||
requests:
|
||||
cpu: "50m"
|
||||
memory: "128Mi"
|
||||
limits:
|
||||
cpu: "600m"
|
||||
memory: "512Mi"
|
||||
@@ -3,10 +3,10 @@ FROM python:3.11-slim
|
||||
WORKDIR /app
|
||||
|
||||
# Install system dependencies
|
||||
RUN apt-get update && apt-get install -y redis-tools && rm -rf /var/lib/apt/lists/*
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends redis-tools && rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Install dependencies
|
||||
RUN pip install requests redis
|
||||
RUN pip install --no-cache-dir requests==2.32.3 redis==5.2.1
|
||||
|
||||
# Copy application code
|
||||
COPY . .
|
||||
|
||||
@@ -1,17 +1,16 @@
|
||||
import logging
|
||||
import os
|
||||
import time
|
||||
import requests
|
||||
import logging
|
||||
import redis
|
||||
from datetime import datetime
|
||||
|
||||
import redis
|
||||
import requests
|
||||
|
||||
# Configure logging
|
||||
logging.basicConfig(
|
||||
level=logging.INFO,
|
||||
format='%(asctime)s - %(levelname)s - %(message)s'
|
||||
)
|
||||
logging.basicConfig(level=logging.INFO, format='%(asctime)s - %(levelname)s - %(message)s')
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
# Load configuration (adapted to .env keys)
|
||||
def _env(key, default=None):
|
||||
v = os.getenv(key, default)
|
||||
@@ -19,21 +18,26 @@ def _env(key, default=None):
|
||||
return v[1:-1]
|
||||
return v
|
||||
|
||||
|
||||
LOGIN = _env('KEEPER_LOGIN')
|
||||
PASSWORD = _env('KEEPER_PASSWORD')
|
||||
|
||||
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
|
||||
EDU_LOGIN_PATH = _env('EDU_URL_LOGIN', '/user/login')
|
||||
EDU_COURSES_PATH = _env('EDU_URL_COURSES', '/course/userlist')
|
||||
URL_LOGIN = f"{EDU_BASE.rstrip('/')}/{EDU_LOGIN_PATH.lstrip('/')}"
|
||||
URL_VERIFY = f"{EDU_BASE.rstrip('/')}/{EDU_COURSES_PATH.lstrip('/')}"
|
||||
URL_LOGIN = f'{EDU_BASE.rstrip("/")}/{EDU_LOGIN_PATH.lstrip("/")}'
|
||||
URL_VERIFY = f'{EDU_BASE.rstrip("/")}/{EDU_COURSES_PATH.lstrip("/")}'
|
||||
|
||||
INTERVAL = int(_env('KEEPER_INTERVAL', 10))
|
||||
USER_AGENT = _env('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||
USER_AGENT = _env(
|
||||
'USER_AGENT',
|
||||
'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36',
|
||||
)
|
||||
REDIS_HOST = _env('REDIS_HOST', 'redis')
|
||||
REDIS_PORT = int(_env('REDIS_PORT', 6379))
|
||||
|
||||
SUCCESS_FILE = '/tmp/last_success'
|
||||
SUCCESS_FILE = '/tmp/last_success' # noqa: S108
|
||||
|
||||
|
||||
def touch_success_file():
|
||||
"""Updates the timestamp of the success file for healthchecks."""
|
||||
@@ -41,22 +45,23 @@ def touch_success_file():
|
||||
with open(SUCCESS_FILE, 'w') as f:
|
||||
f.write(str(datetime.now().timestamp()))
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to touch success file: {e}")
|
||||
logger.error(f'Failed to touch success file: {e}')
|
||||
|
||||
|
||||
def main():
|
||||
logger.info("Starting Session Keeper Bot")
|
||||
|
||||
logger.info('Starting Session Keeper Bot')
|
||||
|
||||
# Connect to Redis
|
||||
try:
|
||||
redis_client = redis.Redis(host=REDIS_HOST, port=REDIS_PORT, decode_responses=True)
|
||||
redis_client.ping()
|
||||
logger.info(f"Connected to Redis at {REDIS_HOST}:{REDIS_PORT}")
|
||||
logger.info(f'Connected to Redis at {REDIS_HOST}:{REDIS_PORT}')
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to connect to Redis: {e}")
|
||||
logger.error(f'Failed to connect to Redis: {e}')
|
||||
return
|
||||
|
||||
|
||||
session = requests.Session()
|
||||
|
||||
|
||||
# Set headers
|
||||
headers = {
|
||||
'User-Agent': USER_AGENT,
|
||||
@@ -72,58 +77,56 @@ def main():
|
||||
'Sec-Ch-Ua-Mobile': '?0',
|
||||
'Sec-Ch-Ua-Platform': '"Linux"',
|
||||
'Accept-Encoding': 'gzip, deflate, br',
|
||||
'Priority': 'u=0, i'
|
||||
'Priority': 'u=0, i',
|
||||
}
|
||||
session.headers.update(headers)
|
||||
|
||||
while True:
|
||||
try:
|
||||
logger.info("Attempting login...")
|
||||
|
||||
logger.info('Attempting login...')
|
||||
|
||||
# Login payload
|
||||
payload = {
|
||||
'login': LOGIN,
|
||||
'password': PASSWORD
|
||||
}
|
||||
|
||||
payload = {'login': LOGIN, 'password': PASSWORD}
|
||||
|
||||
# Perform Login
|
||||
# Note: The user request shows a POST to /user/login with form data
|
||||
# We need to make sure we handle the PHPSESSID correctly.
|
||||
# If we already have a PHPSESSID, requests will send it.
|
||||
|
||||
|
||||
login_response = session.post(URL_LOGIN, data=payload, allow_redirects=True)
|
||||
|
||||
logger.info(f"Login Response Status: {login_response.status_code}")
|
||||
logger.info(f"Cookies after login: {session.cookies.get_dict()}")
|
||||
|
||||
logger.info(f'Login Response Status: {login_response.status_code}')
|
||||
logger.info(f'Cookies after login: {session.cookies.get_dict()}')
|
||||
|
||||
# Verify Session
|
||||
logger.info("Verifying session...")
|
||||
logger.info('Verifying session...')
|
||||
verify_response = session.get(URL_VERIFY, allow_redirects=False)
|
||||
|
||||
logger.info(f"Verify Response Status: {verify_response.status_code}")
|
||||
|
||||
|
||||
logger.info(f'Verify Response Status: {verify_response.status_code}')
|
||||
|
||||
if verify_response.status_code == 200:
|
||||
logger.info("Session verification SUCCESS (200 OK).")
|
||||
logger.info('Session verification SUCCESS (200 OK).')
|
||||
touch_success_file()
|
||||
|
||||
|
||||
# Save PHPSESSID to Redis
|
||||
phpsessid = session.cookies.get('PHPSESSID')
|
||||
if phpsessid:
|
||||
try:
|
||||
redis_client.set('EDU_PHPSESSID', phpsessid)
|
||||
logger.info(f"Saved PHPSESSID to Redis: {phpsessid}")
|
||||
logger.info(f'Saved PHPSESSID to Redis: {phpsessid}')
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to save PHPSESSID to Redis: {e}")
|
||||
logger.error(f'Failed to save PHPSESSID to Redis: {e}')
|
||||
elif verify_response.status_code == 302:
|
||||
logger.warning("Session verification FAILED (302 Redirect). Session might be invalid.")
|
||||
logger.warning('Session verification FAILED (302 Redirect). Session might be invalid.')
|
||||
else:
|
||||
logger.warning(f"Session verification returned unexpected status: {verify_response.status_code}")
|
||||
logger.warning(f'Session verification returned unexpected status: {verify_response.status_code}')
|
||||
|
||||
except Exception as e:
|
||||
logger.error(f"An error occurred: {e}")
|
||||
logger.error(f'An error occurred: {e}')
|
||||
|
||||
logger.info(f"Sleeping for {INTERVAL} minutes...")
|
||||
logger.info(f'Sleeping for {INTERVAL} minutes...')
|
||||
time.sleep(INTERVAL * 60)
|
||||
|
||||
if __name__ == "__main__":
|
||||
|
||||
if __name__ == '__main__':
|
||||
main()
|
||||
@@ -2,8 +2,11 @@ FROM python:3.11-slim
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Install dependencies
|
||||
RUN pip install --upgrade pip && pip install playwright==1.56.0 redis requests "python-telegram-bot[job-queue]"
|
||||
# renovate: datasource=pypi depName=playwright versioning=pep440
|
||||
ARG PLAYWRIGHT_VERSION=1.56.0
|
||||
|
||||
# Install dependencies - PLAYWRIGHT_VERSION is single-source, renovate updates ARG above and all other places via regexManagers
|
||||
RUN pip install --no-cache-dir pip==25.0.1 && pip install --no-cache-dir playwright==${PLAYWRIGHT_VERSION} redis==5.2.1 requests==2.32.3 "python-telegram-bot[job-queue]==21.10"
|
||||
|
||||
COPY checker.py .
|
||||
|
||||
|
||||
+1491
-335
File diff suppressed because it is too large.
Load diff
Loaded 100 of 429 files, more files were not shown because too many files have changed in this diff.
Show more
Reference in new issue
Block a user