mirror of
https://github.com/auricom/home-cluster.git
synced 2025-09-28 04:53:44 +02:00
♻️ emqx
This commit is contained in:
@@ -3,56 +3,55 @@ apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
|||||||
kind: HelmRelease
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: emqx
|
name: emqx
|
||||||
namespace: home-automation
|
namespace: default
|
||||||
spec:
|
spec:
|
||||||
interval: 5m
|
interval: 15m
|
||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
# renovate: registryUrl=https://repos.emqx.io/charts
|
|
||||||
chart: emqx
|
chart: emqx
|
||||||
version: 5.0.3
|
version: 5.0.3
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: emqx-charts
|
name: emqx-charts
|
||||||
namespace: flux-system
|
namespace: flux-system
|
||||||
interval: 5m
|
install:
|
||||||
|
createNamespace: true
|
||||||
|
remediation:
|
||||||
|
retries: 5
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 5
|
||||||
values:
|
values:
|
||||||
image:
|
image:
|
||||||
repository: public.ecr.aws/emqx/emqx
|
repository: public.ecr.aws/emqx/emqx
|
||||||
|
|
||||||
replicaCount: 3
|
replicaCount: 3
|
||||||
recreatePods: true
|
recreatePods: true
|
||||||
|
|
||||||
emqxConfig:
|
emqxConfig:
|
||||||
EMQX_ALLOW_ANONYMOUS: "false"
|
EMQX_ALLOW_ANONYMOUS: "false"
|
||||||
EMQX_ADMIN_PASSWORD: "${SECRET_EMQX_ADMIN_PASSWORD}"
|
|
||||||
EMQX_AUTH__MNESIA__PASSWORD_HASH: plain
|
EMQX_AUTH__MNESIA__PASSWORD_HASH: plain
|
||||||
EMQX_AUTH__USER__1__USERNAME: "${SECRET_MQTT_USERNAME}"
|
EMQX_AUTH__USER__1__USERNAME: "${SECRET_MQTT_USERNAME}"
|
||||||
EMQX_AUTH__USER__1__PASSWORD: "${SECRET_MQTT_PASSWORD}"
|
EMQX_AUTH__USER__1__PASSWORD: "${SECRET_MQTT_PASSWORD}"
|
||||||
|
|
||||||
service:
|
service:
|
||||||
annotations:
|
|
||||||
prometheus.io/probe: "true"
|
|
||||||
prometheus.io/protocol: tcp
|
|
||||||
type: LoadBalancer
|
type: LoadBalancer
|
||||||
externalIPs:
|
externalIPs:
|
||||||
- ${CLUSTER_LB_EMQX}
|
- ${CLUSTER_LB_EMQX}
|
||||||
externalTrafficPolicy: Local
|
externalTrafficPolicy: Local
|
||||||
|
|
||||||
ingress:
|
ingress:
|
||||||
dashboard:
|
dashboard:
|
||||||
enabled: true
|
enabled: true
|
||||||
ingressClassName: nginx
|
ingressClassName: nginx
|
||||||
path: /
|
path: /
|
||||||
hosts:
|
hosts:
|
||||||
- &host "emqx.${SECRET_CLUSTER_DOMAIN}"
|
- &host "{{ .Release.Name }}.${SECRET_CLUSTER_DOMAIN}"
|
||||||
tls:
|
tls:
|
||||||
- hosts:
|
- hosts:
|
||||||
- *host
|
- *host
|
||||||
|
|
||||||
metrics:
|
metrics:
|
||||||
enabled: false
|
enabled: false
|
||||||
|
persistence:
|
||||||
|
enabled: true
|
||||||
|
storageClass: ceph-block
|
||||||
|
size: 100Mi
|
||||||
affinity:
|
affinity:
|
||||||
podAntiAffinity:
|
podAntiAffinity:
|
||||||
preferredDuringSchedulingIgnoredDuringExecution:
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
@@ -62,13 +61,16 @@ spec:
|
|||||||
matchExpressions:
|
matchExpressions:
|
||||||
- key: app.kubernetes.io/name
|
- key: app.kubernetes.io/name
|
||||||
operator: In
|
operator: In
|
||||||
values:
|
values: ["emqx"]
|
||||||
- emqx
|
|
||||||
topologyKey: kubernetes.io/hostname
|
topologyKey: kubernetes.io/hostname
|
||||||
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 100m
|
cpu: 100m
|
||||||
memory: 150Mi
|
memory: 150Mi
|
||||||
limits:
|
limits:
|
||||||
memory: 512Mi
|
memory: 512Mi
|
||||||
|
valuesFrom:
|
||||||
|
- targetPath: emqxConfig.EMQX_DASHBOARD__DEFAULT_PASSWORD
|
||||||
|
kind: Secret
|
||||||
|
name: emqx-config
|
||||||
|
valuesKey: admin_password
|
||||||
|
@@ -1,4 +1,5 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
|
- secret.sops.yaml
|
||||||
- helm-release.yaml
|
- helm-release.yaml
|
||||||
|
28
cluster/apps/home-automation/emqx/secret.sops.yaml
Normal file
28
cluster/apps/home-automation/emqx/secret.sops.yaml
Normal file
@@ -0,0 +1,28 @@
|
|||||||
|
kind: Secret
|
||||||
|
apiVersion: v1
|
||||||
|
type: Opaque
|
||||||
|
metadata:
|
||||||
|
name: emqx-config
|
||||||
|
namespace: default
|
||||||
|
stringData:
|
||||||
|
admin_password: ENC[AES256_GCM,data:5CgeNci9Mr9bhHLG/cl9yajr02CInvng,iv:tzU2NnmprFiVfnxgXP8y+o2wgwooaWVpvq6+fKodLC8=,tag:MkDFv5wOn4B6yWUMfivQGA==,type:str]
|
||||||
|
sops:
|
||||||
|
kms: []
|
||||||
|
gcp_kms: []
|
||||||
|
azure_kv: []
|
||||||
|
hc_vault: []
|
||||||
|
age:
|
||||||
|
- recipient: age1hhurqwmfvl9m3vh3hk8urulfzcdsrep2ax2neazqt435yhpamu3qj20asg
|
||||||
|
enc: |
|
||||||
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBvb3RQOTVNN0VzdElJSGRY
|
||||||
|
bytDQ045bnRMY2RGSmEvTE9jQkN4MTQrZUhnCnZ0TjF5ZTU2bWtJNzVGRXdqV0lP
|
||||||
|
RGtuaUVkZlluUjlsd0lvZ0ZuRE5ocEUKLS0tIGxsTjJpc0JEeUhxSjF6MU5mSlli
|
||||||
|
bXpSSjd3YU5hRXFKdnhVcTFKTzRqZzQKlFvt9rCRt+1EviAtZxaQVVwAEt300456
|
||||||
|
KDHW7U58DUO3TmzTG47/iLj7AxIgCQKUjgaU6FoiQ/DZLaVCloyWEA==
|
||||||
|
-----END AGE ENCRYPTED FILE-----
|
||||||
|
lastmodified: "2022-09-14T08:51:36Z"
|
||||||
|
mac: ENC[AES256_GCM,data:cwjeMMjPMPF2J0cc14XcQANFnhF59445engaEJAufIi8CH6rNvqzW/7fx6KqRIgeRMoNVInd5izn+rQKAvpLCFjsntpjvihE9AOIEsxHYkZ7S6wxzDtffeEDMKPq9ybemkRkqUUWdIve2jZaFtsY5hndEmuWq+euvr4G3fqXeU4=,iv:ldP/x68he76ObwJ8dFuWL6+y87yTLsmkoABKFmmxVQY=,tag:COn18dD88/Oa7hYp8/bjdg==,type:str]
|
||||||
|
pgp: []
|
||||||
|
encrypted_regex: ^(data|stringData)$
|
||||||
|
version: 3.7.3
|
@@ -19,7 +19,6 @@ stringData:
|
|||||||
SECRET_CLUSTER_OVH_CONSUMER_KEY: ENC[AES256_GCM,data:HwEaNSLEoON99KzgVLuDWxj8DPz1gz8tc3q/1hWJOvM=,iv:uTHCAT81Js9yQ/7iK90+elZzA0j6ia7AOWEufE1i/4k=,tag:D4tI50RyJz8o3n9hrrYz4Q==,type:str]
|
SECRET_CLUSTER_OVH_CONSUMER_KEY: ENC[AES256_GCM,data:HwEaNSLEoON99KzgVLuDWxj8DPz1gz8tc3q/1hWJOvM=,iv:uTHCAT81Js9yQ/7iK90+elZzA0j6ia7AOWEufE1i/4k=,tag:D4tI50RyJz8o3n9hrrYz4Q==,type:str]
|
||||||
SECRET_EMAIL_DOMAIN: ENC[AES256_GCM,data:tggMEXyLi03dAorm,iv:tXHmWmm9wUIOyGXbHUagS0gl4cEW588XSvBIoNsADFw=,tag:69X+WZoj6CiI6mUJT01DzQ==,type:str]
|
SECRET_EMAIL_DOMAIN: ENC[AES256_GCM,data:tggMEXyLi03dAorm,iv:tXHmWmm9wUIOyGXbHUagS0gl4cEW588XSvBIoNsADFw=,tag:69X+WZoj6CiI6mUJT01DzQ==,type:str]
|
||||||
SECRET_EMAIL_SMTP_USERNAME: ENC[AES256_GCM,data:U8UiC6SdBbX9JbpRglyXfofDzYf+LNY=,iv:BLqn6nWm+il2yxWBJgpjlLKp5/eVh8L9qSEfM9LzUEo=,tag:1+afhSVYeHTvzzBiTxP7Ew==,type:str]
|
SECRET_EMAIL_SMTP_USERNAME: ENC[AES256_GCM,data:U8UiC6SdBbX9JbpRglyXfofDzYf+LNY=,iv:BLqn6nWm+il2yxWBJgpjlLKp5/eVh8L9qSEfM9LzUEo=,tag:1+afhSVYeHTvzzBiTxP7Ew==,type:str]
|
||||||
SECRET_EMQX_ADMIN_PASSWORD: ENC[AES256_GCM,data:1TU2rUWjqHTX4a7P4L9cZSHUoO/OxrYS,iv:QUpEZs2nDNREOt915MSwMMVXAscC1rszIPRp4F/Slig=,tag:DN91F66rvha5TjMB/ZHGFQ==,type:str]
|
|
||||||
SECRET_GITEA_ADMIN_EMAIL: ENC[AES256_GCM,data:IJiZAgExGAUcYW1L8jW0m2zr+hZL,iv:T+T9AM5wYqNoWKlDVDpsmxf4gvYSsLHwSoxxFAZfiuU=,tag:QeL6xFPsgxgBjMb79zrWZw==,type:str]
|
SECRET_GITEA_ADMIN_EMAIL: ENC[AES256_GCM,data:IJiZAgExGAUcYW1L8jW0m2zr+hZL,iv:T+T9AM5wYqNoWKlDVDpsmxf4gvYSsLHwSoxxFAZfiuU=,tag:QeL6xFPsgxgBjMb79zrWZw==,type:str]
|
||||||
SECRET_GITEA_ADMIN_PASSWORD: ENC[AES256_GCM,data:w1BcZzMeLqEMVFdX94c=,iv:bc4IaH9YXvRQTW38Rb1tySKx9/1npWtqI2DtS0y/p3w=,tag:X3hyHEhbGNJcYaH2yWMQNQ==,type:str]
|
SECRET_GITEA_ADMIN_PASSWORD: ENC[AES256_GCM,data:w1BcZzMeLqEMVFdX94c=,iv:bc4IaH9YXvRQTW38Rb1tySKx9/1npWtqI2DtS0y/p3w=,tag:X3hyHEhbGNJcYaH2yWMQNQ==,type:str]
|
||||||
SECRET_GITEA_API_TOKEN: ENC[AES256_GCM,data:Xsk9tJLyy6LaoGdIhIQ0rrbu4qREg5fKWJ0KDp7f4qPme7Q1Iha7YA==,iv:uHcaLAaQ/l737UMTzjX3okEAba7gxrowMDu/GO98FnM=,tag:4rKcU+z1sqnDcZoZ+9Zqxg==,type:str]
|
SECRET_GITEA_API_TOKEN: ENC[AES256_GCM,data:Xsk9tJLyy6LaoGdIhIQ0rrbu4qREg5fKWJ0KDp7f4qPme7Q1Iha7YA==,iv:uHcaLAaQ/l737UMTzjX3okEAba7gxrowMDu/GO98FnM=,tag:4rKcU+z1sqnDcZoZ+9Zqxg==,type:str]
|
||||||
@@ -79,8 +78,8 @@ sops:
|
|||||||
WG82VkdBMlNnRzBySFQzMk41cEtXSlEKBqOmq9UpO61C85+pj0ibdT31y4pmFsbm
|
WG82VkdBMlNnRzBySFQzMk41cEtXSlEKBqOmq9UpO61C85+pj0ibdT31y4pmFsbm
|
||||||
pTi4N0vv81kcf4ilqBU5h1gudNCb42Q2iL0eGNR4e3JzH4iaNsvnEg==
|
pTi4N0vv81kcf4ilqBU5h1gudNCb42Q2iL0eGNR4e3JzH4iaNsvnEg==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
lastmodified: "2022-09-13T22:56:56Z"
|
lastmodified: "2022-09-14T08:46:49Z"
|
||||||
mac: ENC[AES256_GCM,data:lLQYL2TJ4KxZhviBd3Co2WGQPy09kyZF5a0oMR2QGud8JPqbSUzxNspu4n1cxJRuF7PAfsb3FWoeal/DmjTP06grqj1RNwSpNQfCBKb6bi1/9MONkA1PKUf1fzoZK+s8h8nTK0nknm6nMk/sSJg+Sgz/Zuy8rt/CuJgYEVVGb8w=,iv:VP5rnNNBZjGkTXOQfXcV8zLKcf9sjVwTJ+44K8Rmdgw=,tag:zukSR3nXrWiDlo67EKgsPg==,type:str]
|
mac: ENC[AES256_GCM,data:V937qTqC7tg+sR7RbR1MSZCnXzfT1Xwzq0XTjJKh8rJEYHx8MHHgw70Tjz1aFfDGBvFn2Cokom27lTZTU+zsEwj6Mz+ulf8WNDlQpmScz24kwHHEPJAJExs1RmL2QiXn3G9YqCHXrJDEzPrbYQn2Kf4QtM1ED36UJrpxSufHTJg=,iv:rUfXzDTGOnpg7PA3Z3JGl3AW9s9vUDScTo970pPsEG8=,tag:C5CK17hIuIZbLJoiXbn/iA==,type:str]
|
||||||
pgp: []
|
pgp: []
|
||||||
encrypted_regex: ^(data|stringData)$
|
encrypted_regex: ^(data|stringData)$
|
||||||
version: 3.7.3
|
version: 3.7.3
|
||||||
|
Reference in New Issue
Block a user