--- # yaml-language-server: $schema=https://raw.githubusercontent.com/fluxcd-community/flux2-schemas/main/helmrelease-helm-v2beta1.json apiVersion: helm.toolkit.fluxcd.io/v2beta1 kind: HelmRelease metadata: name: &app bazarr namespace: default spec: interval: 30m chart: spec: chart: app-template version: 2.3.0 sourceRef: kind: HelmRepository name: bjw-s namespace: flux-system maxHistory: 2 install: createNamespace: true remediation: retries: 3 upgrade: cleanupOnFail: true remediation: retries: 3 uninstall: keepHistory: false dependsOn: - name: rook-ceph-cluster namespace: rook-ceph - name: volsync namespace: volsync values: defaultPodOptions: securityContext: runAsUser: 568 runAsGroup: 568 fsGroup: 568 fsGroupChangePolicy: OnRootMismatch controllers: main: type: statefulset annotations: reloader.stakater.com/auto: "true" initContainers: init-db: image: repository: ghcr.io/auricom/postgres-init tag: 15.5@sha256:a337602f0dc11ee0e7f819ede78fa1a13e40a52adad737353efe10ce265a4b36 pullPolicy: IfNotPresent envFrom: &envFrom - secretRef: name: atuin-secret containers: main: image: repository: ghcr.io/onedr0p/bazarr tag: 1.4.0@sha256:c81c4d9cbec093d5a999cfa3cd1af01d3f00d6292d6f5c33608510cef0ed83c7 env: TZ: "${TIMEZONE}" envFrom: *envFrom resources: requests: cpu: 23m memory: 204M limits: memory: 1Gi subcleaner: image: repository: registry.k8s.io/git-sync/git-sync tag: v4.1.0 pullPolicy: IfNotPresent args: - --repo=https://github.com/KBlixt/subcleaner - --branch=master - --wait=86400 # 1 day - --root=/add-ons statefulset: volumeClaimTemplates: - name: config accessMode: ReadWriteOnce size: 1Gi storageClass: rook-ceph-block globalMounts: - path: /config service: main: ports: http: port: 6767 ingress: main: enabled: true className: "nginx" annotations: nginx.ingress.kubernetes.io/auth-method: GET nginx.ingress.kubernetes.io/auth-url: http://authelia.default.svc.cluster.local.:8888/api/verify nginx.ingress.kubernetes.io/auth-signin: https://auth.${SECRET_CLUSTER_DOMAIN}?rm=$request_method nginx.ingress.kubernetes.io/auth-response-headers: Remote-User,Remote-Name,Remote-Groups,Remote-Email nginx.ingress.kubernetes.io/auth-snippet: proxy_set_header X-Forwarded-Method $request_method; hajimari.io/icon: mdi:subtitles-outline hosts: - host: &host "{{ .Release.Name }}.${SECRET_CLUSTER_DOMAIN}" paths: - path: / service: name: main port: http tls: - hosts: - *host persistence: add-ons: enabled: true type: emptyDir globalMounts: - path: /add-ons video: enabled: true type: nfs server: "${LOCAL_LAN_TRUENAS}" path: /mnt/storage/video globalMounts: - path: /mnt/storage/video scripts: enabled: true type: configMap name: bazarr-scripts # overriden by kustomizeconfig defaultMode: 0775 readOnly: true globalMounts: - path: /scripts