--- # yaml-language-server: $schema=https://raw.githubusercontent.com/bjw-s/helm-charts/main/charts/other/app-template/schemas/helmrelease-helm-v2beta2.schema.json apiVersion: helm.toolkit.fluxcd.io/v2beta2 kind: HelmRelease metadata: name: &app sabnzbd namespace: default spec: interval: 30m chart: spec: chart: app-template version: 3.1.0 sourceRef: kind: HelmRepository name: bjw-s namespace: flux-system maxHistory: 2 install: createNamespace: true remediation: retries: 3 upgrade: cleanupOnFail: true remediation: strategy: rollback retries: 3 uninstall: keepHistory: false dependsOn: - name: rook-ceph-cluster namespace: rook-ceph - name: volsync namespace: volsync values: defaultPodOptions: securityContext: runAsUser: 568 runAsGroup: 568 fsGroup: 568 fsGroupChangePolicy: OnRootMismatch controllers: sabnzbd: annotations: reloader.stakater.com/auto: "true" containers: app: image: repository: ghcr.io/onedr0p/sabnzbd tag: 4.3.0@sha256:5fdbb4feed00e55ac97f99c21c71a5d56a9ede4a2eae7586f160bdd01a47a350 env: TZ: "${TIMEZONE}" SABNZBD__PORT: &port 8080 SABNZBD__HOST_WHITELIST_ENTRIES: >- sabnzbd, sabnzbd.default, sabnzbd.default.svc, sabnzbd.default.svc.cluster, sabnzbd.default.svc.cluster.local, sabnzbd.${SECRET_CLUSTER_DOMAIN} envFrom: - secretRef: name: sabnzbd-secret probes: liveness: &probes enabled: true custom: true spec: httpGet: path: /api?mode=version port: *port initialDelaySeconds: 0 periodSeconds: 10 timeoutSeconds: 1 failureThreshold: 3 readiness: *probes startup: enabled: false resources: requests: cpu: 10m memory: 250Mi limits: memory: 8000Mi service: app: controller: *app ports: http: port: *port ingress: app: enabled: true className: nginx annotations: nginx.ingress.kubernetes.io/auth-method: GET nginx.ingress.kubernetes.io/auth-url: http://authelia.default.svc.cluster.local.:8888/api/verify nginx.ingress.kubernetes.io/auth-signin: https://auth.${SECRET_CLUSTER_DOMAIN}?rm=$request_method nginx.ingress.kubernetes.io/auth-response-headers: Remote-User,Remote-Name,Remote-Groups,Remote-Email nginx.ingress.kubernetes.io/auth-snippet: proxy_set_header X-Forwarded-Method $request_method; hajimari.io/icon: mdi:download hosts: - host: &host "{{ .Release.Name }}.${SECRET_CLUSTER_DOMAIN}" paths: - path: / service: identifier: app port: http tls: - hosts: - *host persistence: config: enabled: true existingClaim: *app globalMounts: - path: /config downloads: type: nfs server: 192.168.9.10 path: /mnt/storage/downloads globalMounts: - path: /mnt/storage/downloads music-usenet: type: nfs server: 192.168.9.10 path: /mnt/storage/music/.usenet globalMounts: - path: /mnt/storage/music/.usenet video-usenet: type: nfs server: 192.168.9.10 path: /mnt/storage/video/.usenet globalMounts: - path: /mnt/storage/video/.usenet