mirror of
https://github.com/auricom/home-cluster.git
synced 2025-10-02 16:51:52 +02:00
♻️ wallabag
This commit is contained in:
@@ -1,5 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
resources:
|
|
||||||
- helm-release.yaml
|
|
||||||
- volume.yaml
|
|
@@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: freshrss-config
|
|
||||||
namespace: data
|
|
||||||
labels:
|
|
||||||
kasten-io/backup: "true"
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
storageClassName: rook-ceph-block
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 1Gi
|
|
@@ -1,63 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
|
||||||
kind: HelmRelease
|
|
||||||
metadata:
|
|
||||||
name: &app joplin
|
|
||||||
namespace: data
|
|
||||||
spec:
|
|
||||||
interval: 15m
|
|
||||||
chart:
|
|
||||||
spec:
|
|
||||||
chart: kah-common-chart
|
|
||||||
version: 1.2.2
|
|
||||||
sourceRef:
|
|
||||||
kind: HelmRepository
|
|
||||||
name: k8s-at-home-charts
|
|
||||||
namespace: flux-system
|
|
||||||
interval: 15m
|
|
||||||
install:
|
|
||||||
createNamespace: true
|
|
||||||
remediation:
|
|
||||||
retries: 5
|
|
||||||
upgrade:
|
|
||||||
remediation:
|
|
||||||
retries: 5
|
|
||||||
values:
|
|
||||||
global:
|
|
||||||
nameOverride: *app
|
|
||||||
|
|
||||||
image:
|
|
||||||
repository: joplin/server
|
|
||||||
tag: 2.7.4-beta
|
|
||||||
|
|
||||||
env:
|
|
||||||
APP_BASE_URL: https://joplin.${SECRET_CLUSTER_DOMAIN}
|
|
||||||
APP_PORT: 22300
|
|
||||||
DB_CLIENT: pg
|
|
||||||
POSTGRES_HOST: postgres.${SECRET_DOMAIN}
|
|
||||||
POSTGRES_PORT: 5432
|
|
||||||
POSTGRES_DATABASE: joplin
|
|
||||||
POSTGRES_USER: joplin
|
|
||||||
POSTGRES_PASSWORD: ${SECRET_JOPLIN_DB_PASSWORD}
|
|
||||||
|
|
||||||
service:
|
|
||||||
main:
|
|
||||||
ports:
|
|
||||||
http:
|
|
||||||
port: 22300
|
|
||||||
|
|
||||||
ingress:
|
|
||||||
main:
|
|
||||||
enabled: true
|
|
||||||
ingressClassName: "nginx"
|
|
||||||
annotations:
|
|
||||||
external-dns.alpha.kubernetes.io/target: "services.${SECRET_DOMAIN}."
|
|
||||||
external-dns/is-public: "true"
|
|
||||||
hosts:
|
|
||||||
- host: &host "{{ .Release.Name }}.${SECRET_CLUSTER_DOMAIN}"
|
|
||||||
paths:
|
|
||||||
- path: /
|
|
||||||
pathType: Prefix
|
|
||||||
tls:
|
|
||||||
- hosts:
|
|
||||||
- *host
|
|
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
resources:
|
|
||||||
- helm-release.yaml
|
|
@@ -12,4 +12,3 @@ resources:
|
|||||||
- tandoor
|
- tandoor
|
||||||
- truecommand
|
- truecommand
|
||||||
- vikunja
|
- vikunja
|
||||||
- wallabag
|
|
||||||
|
@@ -1,94 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
|
||||||
kind: HelmRelease
|
|
||||||
metadata:
|
|
||||||
name: &app vaultwarden
|
|
||||||
namespace: data
|
|
||||||
spec:
|
|
||||||
interval: 15m
|
|
||||||
chart:
|
|
||||||
spec:
|
|
||||||
chart: kah-common-chart
|
|
||||||
version: 1.2.2
|
|
||||||
sourceRef:
|
|
||||||
kind: HelmRepository
|
|
||||||
name: k8s-at-home-charts
|
|
||||||
namespace: flux-system
|
|
||||||
interval: 15m
|
|
||||||
install:
|
|
||||||
createNamespace: true
|
|
||||||
remediation:
|
|
||||||
retries: 5
|
|
||||||
upgrade:
|
|
||||||
remediation:
|
|
||||||
retries: 5
|
|
||||||
values:
|
|
||||||
global:
|
|
||||||
nameOverride: *app
|
|
||||||
|
|
||||||
image:
|
|
||||||
repository: ghcr.io/k8s-at-home/vaultwarden
|
|
||||||
tag: v1.25.2
|
|
||||||
|
|
||||||
strategy:
|
|
||||||
type: Recreate
|
|
||||||
|
|
||||||
env:
|
|
||||||
DATA_FOLDER: "data"
|
|
||||||
ICON_CACHE_FOLDER: "data/icon_cache"
|
|
||||||
ATTACHMENTS_FOLDER: "data/attachments"
|
|
||||||
DOMAIN: "https://vaultwarden.${SECRET_CLUSTER_DOMAIN}"
|
|
||||||
ADMIN_TOKEN: ${SECRET_VAULTWARDEN_ADMIN_TOKEN}
|
|
||||||
DATABASE_URL: ${SECRET_VAULTWARDEN_DB_URL}
|
|
||||||
TZ: "${TIMEZONE}"
|
|
||||||
SIGNUPS_ALLOWED: "false"
|
|
||||||
WEBSOCKET_ENABLED: "true"
|
|
||||||
WEBSOCKET_ADDRESS: 0.0.0.0
|
|
||||||
WEBSOCKET_PORT: 3012
|
|
||||||
SMTP_HOST: smtp-relay.default.svc.cluster.local
|
|
||||||
SMTP_FROM: vaultwarden@${SECRET_DOMAIN}
|
|
||||||
SMTP_FROM_NAME: vaultwarden
|
|
||||||
SMTP_PORT: 2525
|
|
||||||
|
|
||||||
service:
|
|
||||||
main:
|
|
||||||
ports:
|
|
||||||
http:
|
|
||||||
port: 80
|
|
||||||
websocket:
|
|
||||||
enabled: true
|
|
||||||
port: 3012
|
|
||||||
|
|
||||||
persistence:
|
|
||||||
data:
|
|
||||||
enabled: true
|
|
||||||
existingClaim: vaultwarden-data
|
|
||||||
mountPath: /data
|
|
||||||
|
|
||||||
ingress:
|
|
||||||
main:
|
|
||||||
enabled: true
|
|
||||||
ingressClassName: "nginx"
|
|
||||||
annotations:
|
|
||||||
external-dns.alpha.kubernetes.io/target: "services.${SECRET_DOMAIN}."
|
|
||||||
external-dns/is-public: "true"
|
|
||||||
hosts:
|
|
||||||
- host: &host "{{ .Release.Name }}.${SECRET_CLUSTER_DOMAIN}"
|
|
||||||
paths:
|
|
||||||
- path: /
|
|
||||||
pathType: Prefix
|
|
||||||
- path: /notifications/hub
|
|
||||||
pathType: Prefix
|
|
||||||
- path: /notifications/hub/negotiate
|
|
||||||
pathType: Prefix
|
|
||||||
service:
|
|
||||||
port: 3012
|
|
||||||
tls:
|
|
||||||
- hosts:
|
|
||||||
- *host
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 100m
|
|
||||||
memory: 100Mi
|
|
||||||
limits:
|
|
||||||
memory: 2Gi
|
|
@@ -1,5 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
resources:
|
|
||||||
- helm-release.yaml
|
|
||||||
- volume.yaml
|
|
@@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: vaultwarden-data
|
|
||||||
namespace: data
|
|
||||||
labels:
|
|
||||||
kasten-io/backup: "true"
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
storageClassName: rook-ceph-block
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 1Gi
|
|
@@ -1,72 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
|
||||||
kind: HelmRelease
|
|
||||||
metadata:
|
|
||||||
name: &app whoogle
|
|
||||||
namespace: data
|
|
||||||
spec:
|
|
||||||
interval: 5m
|
|
||||||
chart:
|
|
||||||
spec:
|
|
||||||
chart: kah-common-chart
|
|
||||||
version: 1.2.2
|
|
||||||
sourceRef:
|
|
||||||
kind: HelmRepository
|
|
||||||
name: k8s-at-home-charts
|
|
||||||
namespace: flux-system
|
|
||||||
interval: 5m
|
|
||||||
install:
|
|
||||||
createNamespace: true
|
|
||||||
values:
|
|
||||||
fullnameOverride: *app
|
|
||||||
controller:
|
|
||||||
replicas: 2
|
|
||||||
strategy: RollingUpdate
|
|
||||||
image:
|
|
||||||
repository: docker.io/benbusby/whoogle-search
|
|
||||||
tag: 0.7.4
|
|
||||||
env:
|
|
||||||
WHOOGLE_ALT_TW: farside.link/nitter
|
|
||||||
WHOOGLE_ALT_YT: farside.link/invidious
|
|
||||||
WHOOGLE_ALT_IG: imginn.com
|
|
||||||
WHOOGLE_ALT_RD: farside.link/libreddit
|
|
||||||
WHOOGLE_ALT_MD: farside.link/scribe
|
|
||||||
WHOOGLE_ALT_TL: farside.link/lingva
|
|
||||||
WHOOGLE_ALT_IMG: farside.link/rimgo
|
|
||||||
WHOOGLE_CONFIG_ALTS: 1
|
|
||||||
WHOOGLE_CONFIG_COUNTRY: FR
|
|
||||||
WHOOGLE_CONFIG_THEME: system
|
|
||||||
WHOOGLE_CONFIG_URL: https://whoogle.${SECRET_CLUSTER_DOMAIN}/
|
|
||||||
service:
|
|
||||||
main:
|
|
||||||
ports:
|
|
||||||
http:
|
|
||||||
port: 5000
|
|
||||||
ingress:
|
|
||||||
main:
|
|
||||||
enabled: true
|
|
||||||
ingressClassName: "nginx"
|
|
||||||
annotations:
|
|
||||||
external-dns.alpha.kubernetes.io/target: "services.${SECRET_DOMAIN}."
|
|
||||||
external-dns/is-public: "true"
|
|
||||||
hosts:
|
|
||||||
- host: &host "whoogle.${SECRET_CLUSTER_DOMAIN}"
|
|
||||||
paths:
|
|
||||||
- path: /
|
|
||||||
pathType: Prefix
|
|
||||||
tls:
|
|
||||||
- hosts:
|
|
||||||
- *host
|
|
||||||
topologySpreadConstraints:
|
|
||||||
- maxSkew: 1
|
|
||||||
topologyKey: kubernetes.io/hostname
|
|
||||||
whenUnsatisfiable: DoNotSchedule
|
|
||||||
labelSelector:
|
|
||||||
matchLabels:
|
|
||||||
app.kubernetes.io/name: *app
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 10m
|
|
||||||
memory: 50Mi
|
|
||||||
limits:
|
|
||||||
memory: 250Mi
|
|
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
resources:
|
|
||||||
- helm-release.yaml
|
|
@@ -8,4 +8,5 @@ resources:
|
|||||||
- music-transcode
|
- music-transcode
|
||||||
- theme-park
|
- theme-park
|
||||||
- vaultwarden
|
- vaultwarden
|
||||||
|
- wallabag
|
||||||
- whoogle
|
- whoogle
|
||||||
|
@@ -2,19 +2,18 @@
|
|||||||
apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
||||||
kind: HelmRelease
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: &app freshrss
|
name: &app wallabag
|
||||||
namespace: data
|
namespace: default
|
||||||
spec:
|
spec:
|
||||||
interval: 15m
|
interval: 15m
|
||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: kah-common-chart
|
chart: app-template
|
||||||
version: 1.2.2
|
version: 0.1.1
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: k8s-at-home-charts
|
name: bjw-s-charts
|
||||||
namespace: flux-system
|
namespace: flux-system
|
||||||
interval: 15m
|
|
||||||
install:
|
install:
|
||||||
createNamespace: true
|
createNamespace: true
|
||||||
remediation:
|
remediation:
|
||||||
@@ -22,35 +21,33 @@ spec:
|
|||||||
upgrade:
|
upgrade:
|
||||||
remediation:
|
remediation:
|
||||||
retries: 5
|
retries: 5
|
||||||
|
dependsOn:
|
||||||
|
- name: postgres
|
||||||
|
namespace: default
|
||||||
|
- name: redis
|
||||||
|
namespace: default
|
||||||
values:
|
values:
|
||||||
global:
|
controller:
|
||||||
nameOverride: *app
|
replicas: 1
|
||||||
|
strategy: RollingUpdate
|
||||||
image:
|
image:
|
||||||
repository: freshrss/freshrss
|
repository: wallabag/wallabag
|
||||||
tag: 1.20.0
|
tag: 2.5.1
|
||||||
|
envFrom:
|
||||||
|
- secretRef:
|
||||||
|
name: *app
|
||||||
|
enableServiceLinks: false
|
||||||
service:
|
service:
|
||||||
main:
|
main:
|
||||||
ports:
|
ports:
|
||||||
http:
|
http:
|
||||||
port: 80
|
port: 80
|
||||||
|
|
||||||
env:
|
|
||||||
TZ: ${TIMEZONE}
|
|
||||||
CRON_MIN: "18,48"
|
|
||||||
DOMAIN: "https://freshrss.${SECRET_CLUSTER_DOMAIN}/"
|
|
||||||
|
|
||||||
persistence:
|
|
||||||
config:
|
|
||||||
enabled: true
|
|
||||||
existingClaim: freshrss-config
|
|
||||||
mountPath: /var/www/FreshRSS/data
|
|
||||||
|
|
||||||
ingress:
|
ingress:
|
||||||
main:
|
main:
|
||||||
enabled: true
|
enabled: true
|
||||||
ingressClassName: "nginx"
|
ingressClassName: "nginx"
|
||||||
|
annotations:
|
||||||
|
external-dns.home.arpa/enabled: "true"
|
||||||
hosts:
|
hosts:
|
||||||
- host: &host "{{ .Release.Name }}.${SECRET_CLUSTER_DOMAIN}"
|
- host: &host "{{ .Release.Name }}.${SECRET_CLUSTER_DOMAIN}"
|
||||||
paths:
|
paths:
|
||||||
@@ -59,8 +56,17 @@ spec:
|
|||||||
tls:
|
tls:
|
||||||
- hosts:
|
- hosts:
|
||||||
- *host
|
- *host
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 0
|
||||||
|
persistence:
|
||||||
|
images:
|
||||||
|
enabled: true
|
||||||
|
existingClaim: wallabag-images
|
||||||
|
podAnnotations:
|
||||||
|
secret.reloader.stakater.com/reload: *app
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 50m
|
cpu: 100m
|
||||||
memory: 256Mi
|
memory: 250Mi
|
||||||
|
limits:
|
||||||
|
memory: 100Gi
|
10
cluster/apps/web-tools/wallabag/kustomization.yaml
Normal file
10
cluster/apps/web-tools/wallabag/kustomization.yaml
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: default
|
||||||
|
resources:
|
||||||
|
- secret.sops.yaml
|
||||||
|
- helm-release.yaml
|
||||||
|
patchesStrategicMerge:
|
||||||
|
- patches/env.yaml
|
||||||
|
- patches/postgres.yaml
|
19
cluster/apps/web-tools/wallabag/patches/env.yaml
Normal file
19
cluster/apps/web-tools/wallabag/patches/env.yaml
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: wallabag
|
||||||
|
namespace: default
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
env:
|
||||||
|
SYMFONY__ENV__DATABASE_DRIVER: pdo_pgsql
|
||||||
|
SYMFONY__ENV__DATABASE_HOST: postgres-rw.default.svc.cluster.local
|
||||||
|
SYMFONY__ENV__DATABASE_PORT: 5432
|
||||||
|
SYMFONY__ENV__DATABASE_NAME: wallabag
|
||||||
|
SYMFONY__ENV__REDIS_HOST: redis.default.svc.cluster.local
|
||||||
|
SYMFONY__ENV__DOMAIN_NAME: https://wallabag.${SECRET_CLUSTER_DOMAIN}
|
||||||
|
SYMFONY__ENV__SERVER_NAME: Wallabag
|
||||||
|
SYMFONY__ENV__FOSUSER_REGISTRATION: "false"
|
||||||
|
SYMFONY__ENV__FOSUSER_CONFIRMATION: "false"
|
||||||
|
POPULATE_DATABASE: "false"
|
31
cluster/apps/web-tools/wallabag/patches/postgres.yaml
Normal file
31
cluster/apps/web-tools/wallabag/patches/postgres.yaml
Normal file
@@ -0,0 +1,31 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: wallabag
|
||||||
|
namespace: default
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
initContainers:
|
||||||
|
init-db:
|
||||||
|
image: ghcr.io/onedr0p/postgres-initdb:14.5
|
||||||
|
env:
|
||||||
|
- name: POSTGRES_HOST
|
||||||
|
value: postgres-rw.default.svc.cluster.local
|
||||||
|
- name: POSTGRES_DB
|
||||||
|
value: wallabag
|
||||||
|
- name: POSTGRES_SUPER_PASS
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: postgres-superuser
|
||||||
|
key: password
|
||||||
|
- name: POSTGRES_USER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: wallabag
|
||||||
|
key: SYMFONY__ENV__DATABASE_USER
|
||||||
|
- name: POSTGRES_PASS
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: wallabag
|
||||||
|
key: SYMFONY__ENV__DATABASE_PASSWORD
|
30
cluster/apps/web-tools/wallabag/secret.sops.yaml
Normal file
30
cluster/apps/web-tools/wallabag/secret.sops.yaml
Normal file
@@ -0,0 +1,30 @@
|
|||||||
|
# yamllint disable
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: wallabag
|
||||||
|
namespace: default
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
SYMFONY__ENV__DATABASE_USER: ENC[AES256_GCM,data:h8pfT3ZnClc=,iv:2zW23/OmEWJJIf1NFJKqnVBenNsB+NA4qchYNLzuiJ4=,tag:JCl+8+z2tCByWzEomYsiCQ==,type:str]
|
||||||
|
SYMFONY__ENV__DATABASE_PASSWORD: ENC[AES256_GCM,data:1fIzVV2zPYBs/NUimG8=,iv:4LiY6LJtmV7UHlvw+GQn0HmISm3WL11y382gkPl+aCQ=,tag:CCL/dmqz2JolNe7H8ybDVg==,type:str]
|
||||||
|
sops:
|
||||||
|
kms: []
|
||||||
|
gcp_kms: []
|
||||||
|
azure_kv: []
|
||||||
|
hc_vault: []
|
||||||
|
age:
|
||||||
|
- recipient: age1hhurqwmfvl9m3vh3hk8urulfzcdsrep2ax2neazqt435yhpamu3qj20asg
|
||||||
|
enc: |
|
||||||
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB4TWU5YTlFY3FPQWhnZ2I2
|
||||||
|
akxnZ2xIRVNFZTdOWmg0dFhxTUNoZEFIM1cwCit5WnduNlQ1MkF2aytCVldMeVlC
|
||||||
|
Yk5QNWRQRllOT3ZTL3VGcjJNK1VqeUkKLS0tIFMyWHNFd29nc2tMektxclJkK0pT
|
||||||
|
Ny9OQ0l4ZXMrdW40NmRsbzgvZ0w5V3cKqTGvN5zk2TPgtxoVfwI7Wsz4N+lC9+Kq
|
||||||
|
DCXTgTU/QXm9dvo4ErPPzeWFqdk4JchExhvSJV2JfM32O+3z+EGhNg==
|
||||||
|
-----END AGE ENCRYPTED FILE-----
|
||||||
|
lastmodified: "2022-09-16T09:15:34Z"
|
||||||
|
mac: ENC[AES256_GCM,data:RQzfap7GaeaS0dnZs0wdzPsNT4T1Wsz0ovSO1d766U/w9FlfU2nLfmVCHjKdmhCDq99gxazA5mKzaE1sUPtRrtO1td80G4KTe7jm8DDOLMQOQXgo+QN+W6hJ398uCfkrobtaQFE3YCa9sGyON5Rq2jubQ3+WyvZv/gV1oIvCVAU=,iv:o/wxk2bB97j9wcKqM3/T4kCYWrrKSGlIqgFhvTo9H9E=,tag:0VKKqxudYaNBDjGUm9O/ww==,type:str]
|
||||||
|
pgp: []
|
||||||
|
encrypted_regex: ^(data|stringData)$
|
||||||
|
version: 3.7.3
|
Reference in New Issue
Block a user