forust
861d89d36a
ci(deploy): split runtime by k8s/active marker
...
services marked k8s/active are applied via kubectl; the rest via docker
compose. inactive services with k8s/ keep only routing manifests
(external Services, EndpointSlices, Ingresses) to reach docker backends.
headscale/nextcloud routing moved to k8s/routing/.
validations: compose config --quiet + kubectl apply --dry-run=client.
namespace manifests applied first. pull_policy:build stacks get
build+push before up so the registry image stays fresh.
2026-09-06 20:39:12 +02:00
forust
587611ca88
chore: remove empty middlewares blocks from k8s ingresses
2026-09-02 12:17:04 +02:00
forust
92aa731e44
deleted crowdsec stack from the repo. will figure something else
...
ci / lint-prettier (push) Successful in 18s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 6s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 6s
ci / build (push) Successful in 43s
Signed-off-by: mr-forust <vzlomdsisma@gmail.com >
2026-07-19 23:16:14 +02:00
forust
a128523c24
Fix CrowdSec middleware references in Traefik ingresses
2026-06-29 22:47:21 +02:00
forust
bacb2f4b9f
fix: correct Traefik rule syntax for local IngressRoutes
...
Move parentheses outside Host() calls so that || and && operators
are properly grouped in Traefik rule expressions.
2026-06-28 11:59:52 +02:00
forust
6363d050b0
Add YAML validation workflows
2026-06-21 21:27:31 +02:00
forust
1762962f32
chore(k8s): fix indentation in ingress manifests (3-space -> 2-space)
2026-06-19 12:03:02 +02:00
forust
d53b14b1de
chore: apply yaml lint fixes across compose files
...
- Fix trailing whitespace in compose files
- Add missing final newlines (EOF)
- Fix indentation in dockmon (3-space -> 2-space) and glance monitor.yml
- Align comments consistently
2026-06-19 11:57:14 +02:00
forust
0803f3efff
chore(k8s): returned to Host || Host standart instead of regexp.
...
Deploy to Server / deploy (push) Has been cancelled
Yaml lint (yamllint)
2026-06-18 21:02:40 +02:00
forust
b9b8474455
feat(k8s): protect all prod routers with crowdsec middleware
2026-06-17 01:50:33 +02:00
forust
85d35f86a7
feat: switch adguard dns to a dedicated metallb IP
2026-06-16 12:36:31 +02:00
forust
4ca3ccdad3
chore(k8s): router rewrite
...
- returned to Host matcher instead of Hostregexp
- switched dockercompose labels to letsencrypt
- renamed DoH route
2026-06-16 12:34:15 +02:00
forust
68c5eac164
chore: compact ingress rules with regex
2026-06-11 14:20:03 +02:00
forust
18d1e21690
fix(k8s): traefik log spam for non-existing local-tls secret, because of namespace isolation
2026-06-10 21:14:10 +02:00
forust
1ea669220b
chore(k8): adjusted system resources requests and limits based on manual monitoring
2026-06-10 19:37:16 +02:00
forust
7a3708f70c
lint: yaml spaces and tabs
2026-06-09 12:59:36 +02:00
forust
17b2dfdc2e
fix: gitea ssh tcp router, dns over tls adguard router
2026-06-08 14:20:28 +02:00
forust
b641e3bd94
fix: adguard cers mount name
2026-06-08 12:40:23 +02:00
forust
e19660fdf4
feat(k8s): standardize IngressRoutes — LE prod certs, prod→local→dev order, Traefik values fix
2026-06-08 12:27:55 +02:00
forust
36922a177c
feat(k8s): add K8s manifests for all homelab services
...
traefik, gitea, adguard, nextcloud, errorpages, homepages,
uptime-kuma, kener, checkmk, headscale, dockmon, metube,
downtify, portainer, netronome, userbot
Includes Helm values, deployments, services, ingress routes,
configmaps, secrets (placeholders), postgres statefulsets,
kustomize overlays, and Traefik dynamic configuration.
2026-06-08 10:54:03 +02:00
forust
d7a68237e5
chore: remove redundant or unnececary traefik labels
...
- traefik.docker.network= (defined by traefik cli)
- traefik.http.routers.<routername>.middlewares=security-headers@file" (applied globally by traefik cli)
2026-02-04 22:26:27 +01:00
forust
721348e67f
refactor: switch adguard data to named volume
2026-01-29 17:22:33 +01:00
forust
53b71a33ad
fix: correct adguard traefik devrule
2026-01-21 11:41:37 +01:00
forust
45ce789f58
chore: compose cleanup:
...
- Remove TZ envs
- +- unified compose structure
- Minify where possible
- Remove <service>.internal routers
- Remove service specifications where possible
Affected services:
- adguardhome
- authentik
- cfddns
- checkmk
- dockmon
- downtify
- gitea
- glance
- headscale
- homepages
- metube
- nextcloud
- penpot
- portainer
- termix
- traefik
- uptime-kuma
TODO: Move data from directory to volumes
2026-01-19 23:33:50 +01:00
forust
c048efd569
Merge branch 'main' of ssh://gitssh.forust.xyz:2221/forust/homelab into feat/tailscale
2026-01-01 01:45:57 +01:00
forust
9675eac2bf
feat: add DoT support on dns.forust.xyz
...
- Made adguard available on adguard. and dns. subdomain
- DoT and DoH implementation complete
2025-12-31 03:41:38 +01:00
forust
dc7fe64fbc
fix: clean up traefik configuration and add redirect middleware
2025-12-30 22:44:52 +01:00
forust
502810a12e
fix: update traefik router rules for DNS and adjust letsencrypt volume path
2025-12-30 17:20:13 +01:00
forust
c047cc291d
LE for DoH
2025-12-30 16:54:23 +01:00
forust
f2b951673c
fix: add traefik route for dns o https
2025-12-30 15:47:39 +01:00
forust
fb2f420520
refactor: update network refs form "traefik-proxy" to "proxy"
...
- To allow testing dev vers of other services
2025-12-30 14:14:24 +01:00
forust
5e4c60bb30
chore (security): port hardening, commented out non-critical ports
2025-12-14 02:42:46 +01:00
forust
a767107277
fix: refering to file-defined middlewares
2025-12-05 14:36:57 +01:00
forust
e68e37c285
refactor: use internal tld according to ICAAN
2025-12-05 04:30:51 +01:00
forust
fc6a11397b
refactor: move traefik configuration to docker-compose files via labels
2025-12-05 04:03:24 +01:00
forust
b51a1c7ee6
moved and renamed adguard, dockmon to their directories
...
+gitea rename
2025-11-15 12:54:56 +01:00