Compare commits
1 Commits
e5626b7b2d
..
vv
| Author | SHA1 | Date | |
|---|---|---|---|
| 1dec4de708 |
@@ -1,191 +0,0 @@
|
|||||||
# Инструкция: Анализ хранилища Kubernetes и настройка NFS
|
|
||||||
|
|
||||||
## Цель
|
|
||||||
Проанализировать текущую конфигурацию хранилища Kubernetes и подготовить план внедрения NFS StorageClass для сохранения данных при удалении namespace.
|
|
||||||
|
|
||||||
## 1. Собрать информацию о кластере
|
|
||||||
|
|
||||||
### 1.1. Версия Kubernetes и тип дистрибутива
|
|
||||||
```bash
|
|
||||||
kubectl version --short
|
|
||||||
# или
|
|
||||||
kubectl version
|
|
||||||
```
|
|
||||||
|
|
||||||
Определить, используется ли k3s, k8s, microk8s и т.д.:
|
|
||||||
```bash
|
|
||||||
# Проверить наличие k3s
|
|
||||||
which k3s
|
|
||||||
# Проверить процесс
|
|
||||||
ps aux | grep -E 'kube|k3s'
|
|
||||||
```
|
|
||||||
|
|
||||||
### 1.2. StorageClass
|
|
||||||
```bash
|
|
||||||
kubectl get storageclass -o wide
|
|
||||||
```
|
|
||||||
|
|
||||||
Запомнить:
|
|
||||||
- `PROVISIONER` — какой драйвер используется
|
|
||||||
- `RECLAIMPOLICY` — Delete или Retain
|
|
||||||
- Какой StorageClass помечен как `(default)`
|
|
||||||
|
|
||||||
### 1.3. Существующие PV и PVC
|
|
||||||
```bash
|
|
||||||
kubectl get pv -o wide
|
|
||||||
kubectl get pvc --all-namespaces
|
|
||||||
```
|
|
||||||
|
|
||||||
Посмотреть, какие PVC привязаны к каким PV, и какой reclaimPolicy у PV.
|
|
||||||
|
|
||||||
### 1.4. Нода и диски
|
|
||||||
```bash
|
|
||||||
# Список нод
|
|
||||||
kubectl get nodes -o wide
|
|
||||||
|
|
||||||
# На каждой ноде (через ssh или локально):
|
|
||||||
lsblk
|
|
||||||
df -h
|
|
||||||
cat /etc/fstab
|
|
||||||
```
|
|
||||||
|
|
||||||
Определить:
|
|
||||||
- Есть ли отдельный раздел/диск для данных
|
|
||||||
- Куда смонтированы разделы
|
|
||||||
- Сколько свободного места
|
|
||||||
- Есть ли монтирование NTFS-разделов (как `/media/forust/Programs`)
|
|
||||||
|
|
||||||
### 1.5. Где local-path хранит данные (для k3s)
|
|
||||||
```bash
|
|
||||||
ls -la /var/lib/rancher/k3s/storage/ 2>/dev/null
|
|
||||||
# или для microk8s
|
|
||||||
ls -la /var/snap/microk8s/common/ 2>/dev/null
|
|
||||||
```
|
|
||||||
|
|
||||||
## 2. Анализ: сохраняются ли данные при удалении namespace?
|
|
||||||
|
|
||||||
| Сценарий | Результат |
|
|
||||||
|---|---|
|
|
||||||
| `kubectl delete ns <ns>` | Все PVC в namespace удаляются |
|
|
||||||
| PVC → PV c `reclaimPolicy: Delete` | PV и данные удалены |
|
|
||||||
| PVC → PV c `reclaimPolicy: Retain` | PV остаётся (статус Released), данные целы |
|
|
||||||
|
|
||||||
**Вывод:** Если reclaimPolicy в StorageClass = `Delete`, то данные **пропадут**. Если `Retain` — сохранятся.
|
|
||||||
|
|
||||||
## 3. План внедрения NFS
|
|
||||||
|
|
||||||
### 3.1. Проверить, установлен ли NFS
|
|
||||||
```bash
|
|
||||||
which nfsstat exportfs mount.nfs
|
|
||||||
systemctl status nfs-server 2>/dev/null || systemctl status nfs-kernel-server 2>/dev/null
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3.2. Выбрать директорию для NFS-экспорта
|
|
||||||
|
|
||||||
Варианты (выбрать подходящий):
|
|
||||||
- `/var/lib/k8s-nfs/` — на корневом разделе
|
|
||||||
- `<путь к отдельному разделу>/k8s-nfs/` — если есть отдельный диск/раздел
|
|
||||||
- Не рекомендуется использовать NTFS-раздел (проблемы с правами и производительностью)
|
|
||||||
|
|
||||||
Требования:
|
|
||||||
- Файловая система: ext4 или xfs (не ntfs!)
|
|
||||||
- Достаточно свободного места
|
|
||||||
- Права: `755`, владелец root
|
|
||||||
|
|
||||||
### 3.3. Установить NFS-сервер
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# Debian/Ubuntu
|
|
||||||
apt update && apt install -y nfs-kernel-server
|
|
||||||
|
|
||||||
# RHEL/Fedora
|
|
||||||
dnf install -y nfs-utils
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3.4. Настроить экспорт
|
|
||||||
|
|
||||||
Создать директорию:
|
|
||||||
```bash
|
|
||||||
mkdir -p /var/lib/k8s-nfs
|
|
||||||
chmod 755 /var/lib/k8s-nfs
|
|
||||||
```
|
|
||||||
|
|
||||||
Добавить в `/etc/exports`:
|
|
||||||
```
|
|
||||||
/var/lib/k8s-nfs *(rw,sync,no_subtree_check,no_root_squash)
|
|
||||||
```
|
|
||||||
|
|
||||||
Применить:
|
|
||||||
```bash
|
|
||||||
exportfs -rav
|
|
||||||
```
|
|
||||||
|
|
||||||
Проверить:
|
|
||||||
```bash
|
|
||||||
showmount -e localhost
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3.5. Выбрать способ интеграции с Kubernetes
|
|
||||||
|
|
||||||
#### Вариант A: nfs-subdir-external-provisioner (проще)
|
|
||||||
```bash
|
|
||||||
helm repo add nfs-subdir-external-provisioner https://kubernetes-sigs.github.io/nfs-subdir-external-provisioner/
|
|
||||||
helm install nfs-provisioner nfs-subdir-external-provisioner/nfs-subdir-external-provisioner \
|
|
||||||
--namespace kube-system \
|
|
||||||
--set nfs.server=127.0.0.1 \
|
|
||||||
--set nfs.path=/var/lib/k8s-nfs \
|
|
||||||
--set storageClass.name=nfs \
|
|
||||||
--set storageClass.defaultClass=false \
|
|
||||||
--set storageClass.reclaimPolicy=Retain
|
|
||||||
```
|
|
||||||
|
|
||||||
#### Вариант B: NFS CSI Driver
|
|
||||||
```bash
|
|
||||||
helm repo add csi-driver-nfs https://raw.githubusercontent.com/kubernetes-csi/csi-driver-nfs/master/charts
|
|
||||||
helm install csi-driver-nfs csi-driver-nfs/csi-driver-nfs --namespace kube-system
|
|
||||||
```
|
|
||||||
|
|
||||||
После установки CSI драйвера создать StorageClass:
|
|
||||||
```yaml
|
|
||||||
apiVersion: storage.k8s.io/v1
|
|
||||||
kind: StorageClass
|
|
||||||
metadata:
|
|
||||||
name: nfs
|
|
||||||
provisioner: nfs.csi.k8s.io
|
|
||||||
parameters:
|
|
||||||
server: 127.0.0.1
|
|
||||||
share: /var/lib/k8s-nfs
|
|
||||||
reclaimPolicy: Retain
|
|
||||||
volumeBindingMode: Immediate
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3.6. Проверить результат
|
|
||||||
```bash
|
|
||||||
kubectl get storageclass
|
|
||||||
kubectl get pods -n kube-system | grep -E 'nfs|provisioner'
|
|
||||||
```
|
|
||||||
|
|
||||||
## 4. Итоговая конфигурация
|
|
||||||
|
|
||||||
После внедрения в кластере будет два StorageClass:
|
|
||||||
|
|
||||||
| Имя | Provisioner | ReclaimPolicy | Назначение |
|
|
||||||
|---|---|---|---|
|
|
||||||
| `local-path` (default) | rancher.io/local-path | Delete | Временные данные, stateless |
|
|
||||||
| `nfs` | nfs-subdir-external-provisioner или nfs.csi.k8s.io | Retain | Данные, которые нужно сохранять |
|
|
||||||
|
|
||||||
**Главное преимущество:** PVC c `storageClassName: nfs` при удалении namespace сохраняют данные на диске, так как NFS-провизор использует `reclaimPolicy: Retain` или файлы физически остаются в NFS-экспорте.
|
|
||||||
|
|
||||||
## 5. Ответы на частые вопросы
|
|
||||||
|
|
||||||
**В:** Не упадёт ли local-path при установке NFS?
|
|
||||||
**О:** Нет, они независимы. local-path продолжает работать как обычно.
|
|
||||||
|
|
||||||
**В:** Данные NFS и local-path будут на одном диске?
|
|
||||||
**О:** Да, можно настроить оба на одном разделе, в разных каталогах.
|
|
||||||
|
|
||||||
**В:** Что если у меня несколько нод?
|
|
||||||
**О:** NFS сервер нужно поднять на одной ноде, а с других нод должна быть доступна шари. Для multi-node лучше использовать отдельный сервер или distributed storage (Longhorn, Rook/Ceph).
|
|
||||||
|
|
||||||
**В:** Можно ли использовать существующий NTFS-раздел для NFS?
|
|
||||||
**О:** Не рекомендуется — NTFS не поддерживает права Linux (no_root_squash не сработает корректно), возможны проблемы с блокировками и производительностью.
|
|
||||||
@@ -1,24 +0,0 @@
|
|||||||
root = true
|
|
||||||
|
|
||||||
[*]
|
|
||||||
indent_style = space
|
|
||||||
indent_size = 2
|
|
||||||
end_of_line = lf
|
|
||||||
charset = utf-8
|
|
||||||
trim_trailing_whitespace = true
|
|
||||||
insert_final_newline = true
|
|
||||||
|
|
||||||
[*.{yml,yaml}]
|
|
||||||
indent_size = 2
|
|
||||||
|
|
||||||
[*.{json,jsonc}]
|
|
||||||
indent_size = 2
|
|
||||||
|
|
||||||
[*.md]
|
|
||||||
trim_trailing_whitespace = false
|
|
||||||
|
|
||||||
[*.py]
|
|
||||||
indent_size = 4
|
|
||||||
|
|
||||||
[{Makefile,makefile}]
|
|
||||||
indent_style = tab
|
|
||||||
@@ -1,359 +0,0 @@
|
|||||||
name: ci
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- "**"
|
|
||||||
pull_request:
|
|
||||||
workflow_dispatch:
|
|
||||||
|
|
||||||
env:
|
|
||||||
REGISTRY: gcr.forust.xyz
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
lint-prettier:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Check formatting with Prettier
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
mapfile -t prettier_files < <(
|
|
||||||
git ls-files \
|
|
||||||
| grep -E '\.(md|json|ya?ml|html|css)$' \
|
|
||||||
| grep -Ev '^(\.docs/|\.zed/|errorpages/html/|homepages/(forust_files|xdfnx_files)/)'
|
|
||||||
)
|
|
||||||
|
|
||||||
if [ "${#prettier_files[@]}" -eq 0 ]; then
|
|
||||||
echo "No Prettier-managed files found."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
node:22-alpine \
|
|
||||||
sh -lc 'npx --yes prettier@3 --check --ignore-unknown "$@"' sh "${prettier_files[@]}"
|
|
||||||
|
|
||||||
lint-ruff:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Lint Python with Ruff
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
ghcr.io/astral-sh/ruff:latest \
|
|
||||||
check .
|
|
||||||
|
|
||||||
lint-yaml:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Lint YAML syntax
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
cytopia/yamllint:latest \
|
|
||||||
-c .yamllint .
|
|
||||||
|
|
||||||
lint-dockerfiles:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Lint Dockerfiles
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
mapfile -t dockerfiles < <(
|
|
||||||
git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*'
|
|
||||||
)
|
|
||||||
|
|
||||||
if [ "${#dockerfiles[@]}" -eq 0 ]; then
|
|
||||||
echo "No Dockerfiles found."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
--entrypoint hadolint \
|
|
||||||
hadolint/hadolint:latest-debian \
|
|
||||||
-c .hadolint.yaml "${dockerfiles[@]}"
|
|
||||||
|
|
||||||
validate:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Validate Kubernetes manifests
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
mapfile -t manifests < <(
|
|
||||||
git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \
|
|
||||||
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'
|
|
||||||
)
|
|
||||||
|
|
||||||
if [ "${#manifests[@]}" -eq 0 ]; then
|
|
||||||
echo "No Kubernetes manifests found."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
ghcr.io/yannh/kubeconform:latest \
|
|
||||||
-strict \
|
|
||||||
-ignore-missing-schemas \
|
|
||||||
-summary \
|
|
||||||
"${manifests[@]}"
|
|
||||||
|
|
||||||
build:
|
|
||||||
needs: [lint-prettier, lint-ruff, lint-yaml, lint-dockerfiles, validate]
|
|
||||||
if: github.event_name != 'pull_request' && (github.ref_name == 'main' || github.ref_name == 'dev')
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
outputs:
|
|
||||||
services: ${{ steps.services.outputs.services }}
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
|
|
||||||
- name: Detect changed docker-built services
|
|
||||||
id: services
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
base="${{ github.event.before }}"
|
|
||||||
if [ -z "$base" ] || [ "$base" = "0000000000000000000000000000000000000000" ]; then
|
|
||||||
base="$(git rev-list --max-parents=0 HEAD)"
|
|
||||||
fi
|
|
||||||
|
|
||||||
mapfile -t changed_files < <(git diff --name-only "$base" "${GITHUB_SHA}")
|
|
||||||
|
|
||||||
services=()
|
|
||||||
|
|
||||||
add_service() {
|
|
||||||
local name="$1"
|
|
||||||
local seen=0
|
|
||||||
for existing in "${services[@]}"; do
|
|
||||||
if [ "$existing" = "$name" ]; then
|
|
||||||
seen=1
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
if [ "$seen" -eq 0 ]; then
|
|
||||||
services+=("$name")
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
for file in "${changed_files[@]}"; do
|
|
||||||
case "$file" in
|
|
||||||
dtek_notif/*)
|
|
||||||
add_service dtek_notif
|
|
||||||
;;
|
|
||||||
errorpages/*)
|
|
||||||
add_service errorpages
|
|
||||||
;;
|
|
||||||
userbot/*)
|
|
||||||
add_service userbot
|
|
||||||
;;
|
|
||||||
homepages/*)
|
|
||||||
add_service homepages
|
|
||||||
;;
|
|
||||||
edu_master/phpsessid-bot/*|edu_master/webinar-checker/*|edu_master/compose.yaml)
|
|
||||||
add_service edu_master
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
if [ "${#services[@]}" -eq 0 ]; then
|
|
||||||
echo "No docker-built services changed."
|
|
||||||
echo "services=" >> "$GITHUB_OUTPUT"
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
printf '%s\n' "${services[@]}" | tee /tmp/services.txt
|
|
||||||
echo "services=$(paste -sd, /tmp/services.txt)" >> "$GITHUB_OUTPUT"
|
|
||||||
|
|
||||||
- name: Log in to registry
|
|
||||||
if: steps.services.outputs.services != ''
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login "${REGISTRY}" \
|
|
||||||
-u "${{ secrets.REGISTRY_USERNAME }}" \
|
|
||||||
--password-stdin
|
|
||||||
|
|
||||||
- name: Build and push changed images
|
|
||||||
if: steps.services.outputs.services != ''
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
IFS=, read -r -a services <<< "${{ steps.services.outputs.services }}"
|
|
||||||
|
|
||||||
for service in "${services[@]}"; do
|
|
||||||
case "$service" in
|
|
||||||
dtek_notif)
|
|
||||||
image="${REGISTRY}/forust/dtek-notif"
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" dtek_notif
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
errorpages)
|
|
||||||
image="${REGISTRY}/forust/error-pages"
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" errorpages
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
userbot)
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
for target in runtime panel; do
|
|
||||||
case "$target" in
|
|
||||||
runtime)
|
|
||||||
context="userbot"
|
|
||||||
image="${REGISTRY}/forust/userbot"
|
|
||||||
;;
|
|
||||||
panel)
|
|
||||||
context="userbot/panel"
|
|
||||||
image="${REGISTRY}/forust/userbot-panel"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" "$context"
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
homepages)
|
|
||||||
for service in forust xdfnx; do
|
|
||||||
case "$service" in
|
|
||||||
forust)
|
|
||||||
image="${REGISTRY}/forust/forust-homepage"
|
|
||||||
;;
|
|
||||||
xdfnx)
|
|
||||||
image="${REGISTRY}/forust/xdfnx-homepage"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" -f "homepages/Dockerfile.${service}" homepages
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
edu_master)
|
|
||||||
for service in session-keeper webinar-checker; do
|
|
||||||
case "$service" in
|
|
||||||
session-keeper)
|
|
||||||
context="edu_master/phpsessid-bot"
|
|
||||||
image="${REGISTRY}/forust/session-keeper"
|
|
||||||
;;
|
|
||||||
webinar-checker)
|
|
||||||
context="edu_master/webinar-checker"
|
|
||||||
image="${REGISTRY}/forust/webinar-checker"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" "$context"
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
deploy-userbot-panel:
|
|
||||||
needs: build
|
|
||||||
if: github.ref_name == 'main' && contains(needs.build.outputs.services, 'userbot')
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab, prod]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Apply and roll out userbot panel
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
kubectl apply -f userbot/k8s/base/panel.yaml
|
|
||||||
kubectl get secret userbot-common-secrets -n default -o json \
|
|
||||||
| jq 'del(.metadata.annotations,.metadata.creationTimestamp,.metadata.resourceVersion,.metadata.uid,.metadata.managedFields) | .metadata.namespace = "userbot"' \
|
|
||||||
| kubectl apply -f -
|
|
||||||
# Keep legacy deployments (forust/anna) in sync with manifests; they have no replicas field, so apply leaves scaling to the user manager only.
|
|
||||||
kubectl apply -f userbot/k8s/base/userbots.yaml
|
|
||||||
kubectl rollout restart deployment/userbot-panel -n userbot
|
|
||||||
kubectl rollout status deployment/userbot-panel -n userbot --timeout=180s
|
|
||||||
@@ -1,155 +0,0 @@
|
|||||||
name: deploy
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
workflow_dispatch:
|
|
||||||
|
|
||||||
concurrency:
|
|
||||||
group: deploy-main
|
|
||||||
cancel-in-progress: false
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
redeploy:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab, prod]
|
|
||||||
steps:
|
|
||||||
- name: Redeploy workstation
|
|
||||||
shell: bash
|
|
||||||
env:
|
|
||||||
DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }}
|
|
||||||
DEPLOY_PORT: ${{ secrets.DEPLOY_PORT }}
|
|
||||||
DEPLOY_USER: ${{ secrets.DEPLOY_USER }}
|
|
||||||
DEPLOY_PATH: ${{ secrets.DEPLOY_PATH }}
|
|
||||||
DEPLOY_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
|
|
||||||
# Set APPLY_PRUNE=true to enable kubectl apply --prune. Requires every
|
|
||||||
# manifest to carry label app.kubernetes.io/managed-by=homelab-deploy,
|
|
||||||
# otherwise previously applied resources get deleted on the next run.
|
|
||||||
APPLY_PRUNE: ${{ vars.APPLY_PRUNE }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
: "${DEPLOY_HOST:?missing DEPLOY_HOST}"
|
|
||||||
: "${DEPLOY_USER:?missing DEPLOY_USER}"
|
|
||||||
: "${DEPLOY_KEY:?missing DEPLOY_SSH_KEY}"
|
|
||||||
|
|
||||||
deploy_port="${DEPLOY_PORT:-22}"
|
|
||||||
deploy_path="${DEPLOY_PATH:-/srv/homelab}"
|
|
||||||
|
|
||||||
ssh_key="$RUNNER_TEMP/deploy_key"
|
|
||||||
mkdir -p "$RUNNER_TEMP"
|
|
||||||
printf '%s\n' "$DEPLOY_KEY" > "$ssh_key"
|
|
||||||
chmod 600 "$ssh_key"
|
|
||||||
|
|
||||||
ssh_opts=(
|
|
||||||
-i "$ssh_key"
|
|
||||||
-p "$deploy_port"
|
|
||||||
-o BatchMode=yes
|
|
||||||
-o StrictHostKeyChecking=accept-new
|
|
||||||
)
|
|
||||||
|
|
||||||
ssh "${ssh_opts[@]}" "${DEPLOY_USER}@${DEPLOY_HOST}" \
|
|
||||||
"DEPLOY_PATH=$(printf '%q' \"$deploy_path\") APPLY_PRUNE=$(printf '%q' \"${APPLY_PRUNE:-false}\") bash -se" <<'EOF'
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
repo="${DEPLOY_PATH:-/srv/homelab}"
|
|
||||||
|
|
||||||
if [ ! -d "$repo/.git" ]; then
|
|
||||||
echo "Repository not found at $repo"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
git -C "$repo" fetch origin main
|
|
||||||
git -C "$repo" reset --hard origin/main
|
|
||||||
|
|
||||||
# Runtime selection: a service is k8s-managed when $SERVICE/k8s/active
|
|
||||||
# exists. Otherwise it is compose-managed, and only k8s/routing/*
|
|
||||||
# manifests (external Services / EndpointSlices / ServersTransport /
|
|
||||||
# Ingresses that route to docker backends) are applied.
|
|
||||||
# migrate: touch SERVICE/k8s/active (+ move routing files up)
|
|
||||||
# rollback: rm SERVICE/k8s/active
|
|
||||||
collect_k8s() {
|
|
||||||
find "$1" -type f \( -name '*.yaml' -o -name '*.yml' \) \
|
|
||||||
! -path '*/routing/*' ! -path '*/overlays/*' \
|
|
||||||
! -name 'kustomization.y*ml' ! -name '*.example.y*ml' \
|
|
||||||
! -name '*values.y*ml' ! -name 'patch-*.y*ml' \
|
|
||||||
| sort
|
|
||||||
}
|
|
||||||
|
|
||||||
collect_k8s_inactive() {
|
|
||||||
find "$1" -type f \( -name '*.yaml' -o -name '*.yml' \) \
|
|
||||||
\( -name 'namespace.y*ml' -o -path '*/routing/*' \) \
|
|
||||||
! -path '*/overlays/*' ! -name '*.example.y*ml' \
|
|
||||||
| sort
|
|
||||||
}
|
|
||||||
|
|
||||||
mapfile -t compose_stacks < <(
|
|
||||||
find "$repo" -type f \( -name 'compose.yaml' -o -name 'compose.yml' \) | sort
|
|
||||||
)
|
|
||||||
|
|
||||||
mapfile -t k8s_manifests < <(
|
|
||||||
for kd in $(find "$repo" -type d -name k8s ! -path '*/.git/*' | sort); do
|
|
||||||
if [ -f "$kd/active" ]; then
|
|
||||||
collect_k8s "$kd"
|
|
||||||
else
|
|
||||||
collect_k8s_inactive "$kd"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
)
|
|
||||||
|
|
||||||
echo "== Validate compose stacks =="
|
|
||||||
for cf in "${compose_stacks[@]}"; do
|
|
||||||
dir=$(dirname "$cf")
|
|
||||||
if [ -f "$dir/k8s/active" ]; then
|
|
||||||
echo " skip (k8s-managed): $dir"
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
echo " config: $cf"
|
|
||||||
docker compose -f "$cf" config --quiet
|
|
||||||
done
|
|
||||||
|
|
||||||
echo "== Validate k8s manifests (kubectl dry-run) =="
|
|
||||||
for m in "${k8s_manifests[@]}"; do
|
|
||||||
echo " apply --dry-run=client $m"
|
|
||||||
kubectl apply --dry-run=client -f "$m" >/dev/null
|
|
||||||
done
|
|
||||||
|
|
||||||
echo "== Applying Kubernetes manifests =="
|
|
||||||
ns_files=()
|
|
||||||
other_files=()
|
|
||||||
for m in "${k8s_manifests[@]}"; do
|
|
||||||
case "$m" in
|
|
||||||
*/namespace.y?ml) ns_files+=("$m") ;;
|
|
||||||
*) other_files+=("$m") ;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
prune_opts=()
|
|
||||||
if [ "${APPLY_PRUNE:-false}" = "true" ]; then
|
|
||||||
prune_opts=(--prune -l app.kubernetes.io/managed-by=homelab-deploy)
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ "${#ns_files[@]}" -gt 0 ]; then
|
|
||||||
echo " namespaces first: ${ns_files[*]}"
|
|
||||||
kubectl apply -f "${ns_files[@]}"
|
|
||||||
fi
|
|
||||||
if [ "${#other_files[@]}" -gt 0 ]; then
|
|
||||||
echo " resources: ${other_files[*]}"
|
|
||||||
kubectl apply "${prune_opts[@]}" -f "${other_files[@]}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "== Redeploying docker compose stacks =="
|
|
||||||
for cf in "${compose_stacks[@]}"; do
|
|
||||||
dir=$(dirname "$cf")
|
|
||||||
if [ -f "$dir/k8s/active" ]; then
|
|
||||||
echo " skip (k8s-managed): $dir"
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
echo " compose: $dir"
|
|
||||||
if grep -Eq '^\s+pull_policy:\s*build\b' "$cf"; then
|
|
||||||
docker compose -f "$cf" build
|
|
||||||
docker compose -f "$cf" push
|
|
||||||
fi
|
|
||||||
docker compose -f "$cf" up -d --pull always --remove-orphans
|
|
||||||
done
|
|
||||||
EOF
|
|
||||||
@@ -1,359 +0,0 @@
|
|||||||
name: ci
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- "**"
|
|
||||||
pull_request:
|
|
||||||
workflow_dispatch:
|
|
||||||
|
|
||||||
env:
|
|
||||||
REGISTRY: gcr.forust.xyz
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
lint-prettier:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Check formatting with Prettier
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
mapfile -t prettier_files < <(
|
|
||||||
git ls-files \
|
|
||||||
| grep -E '\.(md|json|ya?ml|html|css)$' \
|
|
||||||
| grep -Ev '^(\.docs/|\.zed/|errorpages/html/|homepages/(forust_files|xdfnx_files)/)'
|
|
||||||
)
|
|
||||||
|
|
||||||
if [ "${#prettier_files[@]}" -eq 0 ]; then
|
|
||||||
echo "No Prettier-managed files found."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
node:22-alpine \
|
|
||||||
sh -lc 'npx --yes prettier@3 --check --ignore-unknown "$@"' sh "${prettier_files[@]}"
|
|
||||||
|
|
||||||
lint-ruff:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Lint Python with Ruff
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
ghcr.io/astral-sh/ruff:latest \
|
|
||||||
check .
|
|
||||||
|
|
||||||
lint-yaml:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Lint YAML syntax
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
cytopia/yamllint:latest \
|
|
||||||
-c .yamllint .
|
|
||||||
|
|
||||||
lint-dockerfiles:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Lint Dockerfiles
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
mapfile -t dockerfiles < <(
|
|
||||||
git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*'
|
|
||||||
)
|
|
||||||
|
|
||||||
if [ "${#dockerfiles[@]}" -eq 0 ]; then
|
|
||||||
echo "No Dockerfiles found."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
--entrypoint hadolint \
|
|
||||||
hadolint/hadolint:latest-debian \
|
|
||||||
-c .hadolint.yaml "${dockerfiles[@]}"
|
|
||||||
|
|
||||||
validate:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Validate Kubernetes manifests
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
mapfile -t manifests < <(
|
|
||||||
git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \
|
|
||||||
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'
|
|
||||||
)
|
|
||||||
|
|
||||||
if [ "${#manifests[@]}" -eq 0 ]; then
|
|
||||||
echo "No Kubernetes manifests found."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker run --rm \
|
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
ghcr.io/yannh/kubeconform:latest \
|
|
||||||
-strict \
|
|
||||||
-ignore-missing-schemas \
|
|
||||||
-summary \
|
|
||||||
"${manifests[@]}"
|
|
||||||
|
|
||||||
build:
|
|
||||||
needs: [lint-prettier, lint-ruff, lint-yaml, lint-dockerfiles, validate]
|
|
||||||
if: github.event_name != 'pull_request' && (github.ref_name == 'main' || github.ref_name == 'dev')
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
|
||||||
outputs:
|
|
||||||
services: ${{ steps.services.outputs.services }}
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
|
|
||||||
- name: Detect changed docker-built services
|
|
||||||
id: services
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
base="${{ github.event.before }}"
|
|
||||||
if [ -z "$base" ] || [ "$base" = "0000000000000000000000000000000000000000" ]; then
|
|
||||||
base="$(git rev-list --max-parents=0 HEAD)"
|
|
||||||
fi
|
|
||||||
|
|
||||||
mapfile -t changed_files < <(git diff --name-only "$base" "${GITHUB_SHA}")
|
|
||||||
|
|
||||||
services=()
|
|
||||||
|
|
||||||
add_service() {
|
|
||||||
local name="$1"
|
|
||||||
local seen=0
|
|
||||||
for existing in "${services[@]}"; do
|
|
||||||
if [ "$existing" = "$name" ]; then
|
|
||||||
seen=1
|
|
||||||
break
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
if [ "$seen" -eq 0 ]; then
|
|
||||||
services+=("$name")
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
for file in "${changed_files[@]}"; do
|
|
||||||
case "$file" in
|
|
||||||
dtek_notif/*)
|
|
||||||
add_service dtek_notif
|
|
||||||
;;
|
|
||||||
errorpages/*)
|
|
||||||
add_service errorpages
|
|
||||||
;;
|
|
||||||
userbot/*)
|
|
||||||
add_service userbot
|
|
||||||
;;
|
|
||||||
homepages/*)
|
|
||||||
add_service homepages
|
|
||||||
;;
|
|
||||||
edu_master/phpsessid-bot/*|edu_master/webinar-checker/*|edu_master/compose.yaml)
|
|
||||||
add_service edu_master
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
if [ "${#services[@]}" -eq 0 ]; then
|
|
||||||
echo "No docker-built services changed."
|
|
||||||
echo "services=" >> "$GITHUB_OUTPUT"
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
printf '%s\n' "${services[@]}" | tee /tmp/services.txt
|
|
||||||
echo "services=$(paste -sd, /tmp/services.txt)" >> "$GITHUB_OUTPUT"
|
|
||||||
|
|
||||||
- name: Log in to registry
|
|
||||||
if: steps.services.outputs.services != ''
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login "${REGISTRY}" \
|
|
||||||
-u "${{ secrets.REGISTRY_USERNAME }}" \
|
|
||||||
--password-stdin
|
|
||||||
|
|
||||||
- name: Build and push changed images
|
|
||||||
if: steps.services.outputs.services != ''
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
IFS=, read -r -a services <<< "${{ steps.services.outputs.services }}"
|
|
||||||
|
|
||||||
for service in "${services[@]}"; do
|
|
||||||
case "$service" in
|
|
||||||
dtek_notif)
|
|
||||||
image="${REGISTRY}/forust/dtek-notif"
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" dtek_notif
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
errorpages)
|
|
||||||
image="${REGISTRY}/forust/error-pages"
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" errorpages
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
userbot)
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
for target in runtime panel; do
|
|
||||||
case "$target" in
|
|
||||||
runtime)
|
|
||||||
context="userbot"
|
|
||||||
image="${REGISTRY}/forust/userbot"
|
|
||||||
;;
|
|
||||||
panel)
|
|
||||||
context="userbot/panel"
|
|
||||||
image="${REGISTRY}/forust/userbot-panel"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" "$context"
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
homepages)
|
|
||||||
for service in forust xdfnx; do
|
|
||||||
case "$service" in
|
|
||||||
forust)
|
|
||||||
image="${REGISTRY}/forust/forust-homepage"
|
|
||||||
;;
|
|
||||||
xdfnx)
|
|
||||||
image="${REGISTRY}/forust/xdfnx-homepage"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" -f "homepages/Dockerfile.${service}" homepages
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
edu_master)
|
|
||||||
for service in session-keeper webinar-checker; do
|
|
||||||
case "$service" in
|
|
||||||
session-keeper)
|
|
||||||
context="edu_master/phpsessid-bot"
|
|
||||||
image="${REGISTRY}/forust/session-keeper"
|
|
||||||
;;
|
|
||||||
webinar-checker)
|
|
||||||
context="edu_master/webinar-checker"
|
|
||||||
image="${REGISTRY}/forust/webinar-checker"
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
tags=("latest")
|
|
||||||
case "${GITHUB_REF_NAME}" in
|
|
||||||
main)
|
|
||||||
tags+=("main" "prod")
|
|
||||||
;;
|
|
||||||
dev)
|
|
||||||
tags+=("dev")
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
build_args=()
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
build_args+=(-t "${image}:${tag}")
|
|
||||||
done
|
|
||||||
docker build "${build_args[@]}" "$context"
|
|
||||||
for tag in "${tags[@]}"; do
|
|
||||||
docker push "${image}:${tag}"
|
|
||||||
done
|
|
||||||
done
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
deploy-userbot-panel:
|
|
||||||
needs: build
|
|
||||||
if: github.ref_name == 'main' && contains(needs.build.outputs.services, 'userbot')
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab, prod]
|
|
||||||
steps:
|
|
||||||
- name: Checkout repository
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Apply and roll out userbot panel
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
kubectl apply -f userbot/k8s/base/panel.yaml
|
|
||||||
kubectl get secret userbot-common-secrets -n default -o json \
|
|
||||||
| jq 'del(.metadata.annotations,.metadata.creationTimestamp,.metadata.resourceVersion,.metadata.uid,.metadata.managedFields) | .metadata.namespace = "userbot"' \
|
|
||||||
| kubectl apply -f -
|
|
||||||
# Keep legacy deployments (forust/anna) in sync with manifests; they have no replicas field, so apply leaves scaling to the user manager only.
|
|
||||||
kubectl apply -f userbot/k8s/base/userbots.yaml
|
|
||||||
kubectl rollout restart deployment/userbot-panel -n userbot
|
|
||||||
kubectl rollout status deployment/userbot-panel -n userbot --timeout=180s
|
|
||||||
@@ -1,155 +0,0 @@
|
|||||||
name: deploy
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
workflow_dispatch:
|
|
||||||
|
|
||||||
concurrency:
|
|
||||||
group: deploy-main
|
|
||||||
cancel-in-progress: false
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
redeploy:
|
|
||||||
runs-on: [self-hosted, linux, arch, homelab, prod]
|
|
||||||
steps:
|
|
||||||
- name: Redeploy workstation
|
|
||||||
shell: bash
|
|
||||||
env:
|
|
||||||
DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }}
|
|
||||||
DEPLOY_PORT: ${{ secrets.DEPLOY_PORT }}
|
|
||||||
DEPLOY_USER: ${{ secrets.DEPLOY_USER }}
|
|
||||||
DEPLOY_PATH: ${{ secrets.DEPLOY_PATH }}
|
|
||||||
DEPLOY_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
|
|
||||||
# Set APPLY_PRUNE=true to enable kubectl apply --prune. Requires every
|
|
||||||
# manifest to carry label app.kubernetes.io/managed-by=homelab-deploy,
|
|
||||||
# otherwise previously applied resources get deleted on the next run.
|
|
||||||
APPLY_PRUNE: ${{ vars.APPLY_PRUNE }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
: "${DEPLOY_HOST:?missing DEPLOY_HOST}"
|
|
||||||
: "${DEPLOY_USER:?missing DEPLOY_USER}"
|
|
||||||
: "${DEPLOY_KEY:?missing DEPLOY_SSH_KEY}"
|
|
||||||
|
|
||||||
deploy_port="${DEPLOY_PORT:-22}"
|
|
||||||
deploy_path="${DEPLOY_PATH:-/srv/homelab}"
|
|
||||||
|
|
||||||
ssh_key="$RUNNER_TEMP/deploy_key"
|
|
||||||
mkdir -p "$RUNNER_TEMP"
|
|
||||||
printf '%s\n' "$DEPLOY_KEY" > "$ssh_key"
|
|
||||||
chmod 600 "$ssh_key"
|
|
||||||
|
|
||||||
ssh_opts=(
|
|
||||||
-i "$ssh_key"
|
|
||||||
-p "$deploy_port"
|
|
||||||
-o BatchMode=yes
|
|
||||||
-o StrictHostKeyChecking=accept-new
|
|
||||||
)
|
|
||||||
|
|
||||||
ssh "${ssh_opts[@]}" "${DEPLOY_USER}@${DEPLOY_HOST}" \
|
|
||||||
"DEPLOY_PATH=$(printf '%q' \"$deploy_path\") APPLY_PRUNE=$(printf '%q' \"${APPLY_PRUNE:-false}\") bash -se" <<'EOF'
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
repo="${DEPLOY_PATH:-/srv/homelab}"
|
|
||||||
|
|
||||||
if [ ! -d "$repo/.git" ]; then
|
|
||||||
echo "Repository not found at $repo"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
git -C "$repo" fetch origin main
|
|
||||||
git -C "$repo" reset --hard origin/main
|
|
||||||
|
|
||||||
# Runtime selection: a service is k8s-managed when $SERVICE/k8s/active
|
|
||||||
# exists. Otherwise it is compose-managed, and only k8s/routing/*
|
|
||||||
# manifests (external Services / EndpointSlices / ServersTransport /
|
|
||||||
# Ingresses that route to docker backends) are applied.
|
|
||||||
# migrate: touch SERVICE/k8s/active (+ move routing files up)
|
|
||||||
# rollback: rm SERVICE/k8s/active
|
|
||||||
collect_k8s() {
|
|
||||||
find "$1" -type f \( -name '*.yaml' -o -name '*.yml' \) \
|
|
||||||
! -path '*/routing/*' ! -path '*/overlays/*' \
|
|
||||||
! -name 'kustomization.y*ml' ! -name '*.example.y*ml' \
|
|
||||||
! -name '*values.y*ml' ! -name 'patch-*.y*ml' \
|
|
||||||
| sort
|
|
||||||
}
|
|
||||||
|
|
||||||
collect_k8s_inactive() {
|
|
||||||
find "$1" -type f \( -name '*.yaml' -o -name '*.yml' \) \
|
|
||||||
\( -name 'namespace.y*ml' -o -path '*/routing/*' \) \
|
|
||||||
! -path '*/overlays/*' ! -name '*.example.y*ml' \
|
|
||||||
| sort
|
|
||||||
}
|
|
||||||
|
|
||||||
mapfile -t compose_stacks < <(
|
|
||||||
find "$repo" -type f \( -name 'compose.yaml' -o -name 'compose.yml' \) | sort
|
|
||||||
)
|
|
||||||
|
|
||||||
mapfile -t k8s_manifests < <(
|
|
||||||
for kd in $(find "$repo" -type d -name k8s ! -path '*/.git/*' | sort); do
|
|
||||||
if [ -f "$kd/active" ]; then
|
|
||||||
collect_k8s "$kd"
|
|
||||||
else
|
|
||||||
collect_k8s_inactive "$kd"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
)
|
|
||||||
|
|
||||||
echo "== Validate compose stacks =="
|
|
||||||
for cf in "${compose_stacks[@]}"; do
|
|
||||||
dir=$(dirname "$cf")
|
|
||||||
if [ -f "$dir/k8s/active" ]; then
|
|
||||||
echo " skip (k8s-managed): $dir"
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
echo " config: $cf"
|
|
||||||
docker compose -f "$cf" config --quiet
|
|
||||||
done
|
|
||||||
|
|
||||||
echo "== Validate k8s manifests (kubectl dry-run) =="
|
|
||||||
for m in "${k8s_manifests[@]}"; do
|
|
||||||
echo " apply --dry-run=client $m"
|
|
||||||
kubectl apply --dry-run=client -f "$m" >/dev/null
|
|
||||||
done
|
|
||||||
|
|
||||||
echo "== Applying Kubernetes manifests =="
|
|
||||||
ns_files=()
|
|
||||||
other_files=()
|
|
||||||
for m in "${k8s_manifests[@]}"; do
|
|
||||||
case "$m" in
|
|
||||||
*/namespace.y?ml) ns_files+=("$m") ;;
|
|
||||||
*) other_files+=("$m") ;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
prune_opts=()
|
|
||||||
if [ "${APPLY_PRUNE:-false}" = "true" ]; then
|
|
||||||
prune_opts=(--prune -l app.kubernetes.io/managed-by=homelab-deploy)
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ "${#ns_files[@]}" -gt 0 ]; then
|
|
||||||
echo " namespaces first: ${ns_files[*]}"
|
|
||||||
kubectl apply -f "${ns_files[@]}"
|
|
||||||
fi
|
|
||||||
if [ "${#other_files[@]}" -gt 0 ]; then
|
|
||||||
echo " resources: ${other_files[*]}"
|
|
||||||
kubectl apply "${prune_opts[@]}" -f "${other_files[@]}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "== Redeploying docker compose stacks =="
|
|
||||||
for cf in "${compose_stacks[@]}"; do
|
|
||||||
dir=$(dirname "$cf")
|
|
||||||
if [ -f "$dir/k8s/active" ]; then
|
|
||||||
echo " skip (k8s-managed): $dir"
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
echo " compose: $dir"
|
|
||||||
if grep -Eq '^\s+pull_policy:\s*build\b' "$cf"; then
|
|
||||||
docker compose -f "$cf" build
|
|
||||||
docker compose -f "$cf" push
|
|
||||||
fi
|
|
||||||
docker compose -f "$cf" up -d --pull always --remove-orphans
|
|
||||||
done
|
|
||||||
EOF
|
|
||||||
+10
-35
@@ -2,15 +2,19 @@
|
|||||||
sync.ffs_lock
|
sync.ffs_lock
|
||||||
.sync.ffs_db
|
.sync.ffs_db
|
||||||
|
|
||||||
# Copyparty
|
# Environment
|
||||||
*.hist/
|
.env
|
||||||
|
.env.anna
|
||||||
|
.env.forust
|
||||||
|
.env.*
|
||||||
|
!.env.*example
|
||||||
|
|
||||||
# Volumes, configs and data directories
|
# Volumes and data directories
|
||||||
gitea/gitea-db/
|
gitea/gitea-db/
|
||||||
gitea/gitea-data/*
|
gitea/gitea-data/*
|
||||||
n8n/n8n-data/*
|
n8n/n8n-data/*
|
||||||
n8n/n8n-node-data/*
|
n8n/n8n-node-data/*
|
||||||
adguardhome/conf/*
|
adguardhome/data/*
|
||||||
dockmon/data/*
|
dockmon/data/*
|
||||||
portainer/portainer_data/*
|
portainer/portainer_data/*
|
||||||
metube/MeTube_downloads
|
metube/MeTube_downloads
|
||||||
@@ -18,10 +22,6 @@ uptime-kuma/data/
|
|||||||
termix/termix-data/*
|
termix/termix-data/*
|
||||||
cfddns/config.json
|
cfddns/config.json
|
||||||
checkmk/checkmk/*
|
checkmk/checkmk/*
|
||||||
downtify/Downtify_downloads
|
|
||||||
headscale/config/*
|
|
||||||
headscale/data/*
|
|
||||||
searxng/core-config/*
|
|
||||||
|
|
||||||
# Steaming services files
|
# Steaming services files
|
||||||
streaming/jellyfin/*
|
streaming/jellyfin/*
|
||||||
@@ -33,21 +33,13 @@ streaming/qbittorrent/*
|
|||||||
streaming/prowlarr/*
|
streaming/prowlarr/*
|
||||||
|
|
||||||
# Homepage
|
# Homepage
|
||||||
homepages/forust_files/.well-known/*
|
homepages/forust_files/assets/images/team/*
|
||||||
|
|
||||||
|
|
||||||
# Traefik files
|
# Traefik files
|
||||||
traefik/letsencrypt/acme.json
|
traefik/letsencrypt/acme.json
|
||||||
traefik/dynamic/fileservers.yml
|
|
||||||
traefik/dynamic/*.local.y*ml.*
|
|
||||||
traefik/dynamic/*.external.y*ml
|
|
||||||
traefik/k8s/fileservers.y*ml
|
|
||||||
|
|
||||||
traefik/logs/*
|
traefik/logs/*
|
||||||
|
|
||||||
# SSL Certificates
|
|
||||||
adguardhome/certs/*
|
|
||||||
traefik/certs/*
|
traefik/certs/*
|
||||||
certs/
|
|
||||||
|
|
||||||
# Monitoring
|
# Monitoring
|
||||||
monitoring/prometheus.yml
|
monitoring/prometheus.yml
|
||||||
@@ -82,8 +74,6 @@ replacements.txt
|
|||||||
|
|
||||||
# Git
|
# Git
|
||||||
.gitattributes
|
.gitattributes
|
||||||
# Gitea/github Runners
|
|
||||||
.runner
|
|
||||||
|
|
||||||
# Misc
|
# Misc
|
||||||
.DS_Store
|
.DS_Store
|
||||||
@@ -91,18 +81,3 @@ replacements.txt
|
|||||||
|
|
||||||
# Temp files
|
# Temp files
|
||||||
edu_master/temp/
|
edu_master/temp/
|
||||||
temp/*
|
|
||||||
|
|
||||||
# Environment
|
|
||||||
.env
|
|
||||||
.env.anna
|
|
||||||
.env.forust
|
|
||||||
.env.*
|
|
||||||
!*example
|
|
||||||
|
|
||||||
# kubernetes
|
|
||||||
*/k8s/*secret*
|
|
||||||
!*/k8s/*secret*.example
|
|
||||||
traefik/k8s/local-tls.yaml
|
|
||||||
converters/k8s/config.yaml
|
|
||||||
convertx/k8s/config.yaml
|
|
||||||
|
|||||||
@@ -1,10 +0,0 @@
|
|||||||
ignored:
|
|
||||||
- DL3008
|
|
||||||
- DL3042
|
|
||||||
- DL3018
|
|
||||||
- DL3059
|
|
||||||
trustedRegistries:
|
|
||||||
- docker.io
|
|
||||||
- ghcr.io
|
|
||||||
- quay.io
|
|
||||||
- gcr.forust.xyz
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
{
|
|
||||||
"default": true,
|
|
||||||
"MD013": false,
|
|
||||||
"MD024": false,
|
|
||||||
"MD033": false,
|
|
||||||
"MD041": false,
|
|
||||||
"MD046": false
|
|
||||||
}
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
bracketSameLine: true
|
|
||||||
htmlWhitespaceSensitivity: css
|
|
||||||
printWidth: 120
|
|
||||||
tabWidth: 2
|
|
||||||
trailingComma: all
|
|
||||||
proseWrap: preserve
|
|
||||||
endOfLine: lf
|
|
||||||
@@ -1,22 +0,0 @@
|
|||||||
extends: default
|
|
||||||
|
|
||||||
rules:
|
|
||||||
comments:
|
|
||||||
min-spaces-from-content: 1
|
|
||||||
comments-indentation: false
|
|
||||||
document-start: disable
|
|
||||||
line-length: disable
|
|
||||||
braces:
|
|
||||||
min-spaces-inside: 0
|
|
||||||
max-spaces-inside: 1
|
|
||||||
brackets:
|
|
||||||
min-spaces-inside: 0
|
|
||||||
max-spaces-inside: 1
|
|
||||||
indentation:
|
|
||||||
spaces: 2
|
|
||||||
indent-sequences: consistent
|
|
||||||
truthy:
|
|
||||||
allowed-values:
|
|
||||||
- "true"
|
|
||||||
- "false"
|
|
||||||
- "on"
|
|
||||||
@@ -1,40 +0,0 @@
|
|||||||
{
|
|
||||||
"tab_size": 2,
|
|
||||||
"soft_wrap": "prefer_line",
|
|
||||||
"preferred_line_length": 120,
|
|
||||||
"format_on_save": "on",
|
|
||||||
"languages": {
|
|
||||||
"YAML": {
|
|
||||||
"tab_size": 2,
|
|
||||||
"hard_tabs": false,
|
|
||||||
"format_on_save": "on",
|
|
||||||
"formatter": {
|
|
||||||
"language_server": { "name": "yaml-language-server" },
|
|
||||||
},
|
|
||||||
},
|
|
||||||
"Python": {
|
|
||||||
"tab_size": 4,
|
|
||||||
"format_on_save": "on",
|
|
||||||
"language_servers": ["pyright", "ruff"],
|
|
||||||
"formatter": {
|
|
||||||
"language_server": { "name": "ruff" },
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
"lsp": {
|
|
||||||
"yaml-language-server": {
|
|
||||||
"settings": {
|
|
||||||
"yaml": {
|
|
||||||
"schemas": {
|
|
||||||
"kubernetes": ["**/k8s/*.yaml", "**/k8s/*.yml"],
|
|
||||||
},
|
|
||||||
"validate": true,
|
|
||||||
"completion": true,
|
|
||||||
"format": {
|
|
||||||
"enable": true,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
+28
-26
@@ -3,46 +3,48 @@ services:
|
|||||||
image: adguard/adguardhome:latest
|
image: adguard/adguardhome:latest
|
||||||
container_name: adguardhome
|
container_name: adguardhome
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
- TZ=${TZ}
|
||||||
ports:
|
ports:
|
||||||
- "53:53/tcp"
|
- "53:53/tcp"
|
||||||
- "53:53/udp"
|
- "53:53/udp"
|
||||||
- "853:853/tcp" # DNS over TLS
|
|
||||||
# - "67:67/udp" # DHCP
|
# - "67:67/udp" # DHCP
|
||||||
# - "68:68/tcp" # DHCP
|
# - "68:68/tcp" # DHCP
|
||||||
# - "3000:3000/tcp"
|
- "3000:3000/tcp"
|
||||||
volumes:
|
volumes:
|
||||||
- data:/opt/adguardhome/work
|
- ./data/work:/opt/adguardhome/work
|
||||||
- ./conf:/opt/adguardhome/conf
|
- ./data/conf:/opt/adguardhome/conf
|
||||||
- ./certs:/certs:ro
|
networks:
|
||||||
|
- traefik-proxy
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
- "traefik.docker.network=traefik-proxy"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
- "traefik.http.routers.adguard.rule=Host(`adguard.forust.xyz`)"
|
||||||
- "traefik.http.routers.adguard.entrypoints=websecure"
|
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||||
- "traefik.http.routers.adguard.tls.certresolver=letsencrypt"
|
- "traefik.http.routers.adguard.middlewares=security-headers@file"
|
||||||
# Local Router
|
- "traefik.http.routers.adguard.service=adguard"
|
||||||
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)"
|
- "traefik.http.routers.adguard.tls=true"
|
||||||
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
||||||
- "traefik.http.routers.adguard-local.tls=true"
|
|
||||||
# Dev Router
|
# Local Router
|
||||||
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)"
|
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`adguard.internal`)"
|
||||||
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.adguard-dev.tls=true"
|
- "traefik.http.routers.adguard-local.middlewares=security-headers@file"
|
||||||
# DoH Router
|
- "traefik.http.routers.adguard-local.service=adguard"
|
||||||
- "traefik.http.routers.dns-over-https.rule=(Host(`dns.forust.xyz` || Host(`adguard.forust.xyz`)) && PathPrefix(`/dns-query`))"
|
- "traefik.http.routers.adguard-local.tls=true"
|
||||||
- "traefik.http.routers.dns-over-https.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.dns-over-https.tls.certresolver=letsencrypt"
|
# Dev Router
|
||||||
|
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.adguard-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.adguard-dev.service=adguard"
|
||||||
|
- "traefik.http.routers.adguard-dev.tls=true"
|
||||||
|
|
||||||
# Glance Metadata
|
|
||||||
- glance.name=adguard
|
- glance.name=adguard
|
||||||
- glance.url=https://adguard.forust.xyz/
|
- glance.url=https://adguard.forust.xyz/
|
||||||
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
traefik-proxy:
|
||||||
volumes:
|
|
||||||
data:
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1,116 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: adguard-lb-service
|
|
||||||
namespace: adguard
|
|
||||||
annotations:
|
|
||||||
metallb.io/loadBalancerIPs: "192.168.80.3"
|
|
||||||
spec:
|
|
||||||
type: LoadBalancer
|
|
||||||
externalTrafficPolicy: Local
|
|
||||||
selector:
|
|
||||||
app: adguard
|
|
||||||
ports:
|
|
||||||
- name: dns-udp
|
|
||||||
port: 53
|
|
||||||
targetPort: 53
|
|
||||||
protocol: UDP
|
|
||||||
- name: dns-tcp
|
|
||||||
port: 53
|
|
||||||
targetPort: 53
|
|
||||||
protocol: TCP
|
|
||||||
- name: dot
|
|
||||||
port: 853
|
|
||||||
targetPort: 853
|
|
||||||
protocol: TCP
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: adguard-service
|
|
||||||
namespace: adguard
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: adguard
|
|
||||||
ports:
|
|
||||||
- port: 3000
|
|
||||||
name: webui
|
|
||||||
targetPort: 3000
|
|
||||||
- port: 53
|
|
||||||
name: dns
|
|
||||||
targetPort: 53
|
|
||||||
protocol: UDP
|
|
||||||
- port: 53
|
|
||||||
name: dns-tcp
|
|
||||||
targetPort: 53
|
|
||||||
protocol: TCP
|
|
||||||
- port: 853
|
|
||||||
name: dot
|
|
||||||
targetPort: 853
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: adguard-deployment
|
|
||||||
namespace: adguard
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: adguard
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: adguard
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: adguard
|
|
||||||
image: adguard/adguardhome:latest
|
|
||||||
resources:
|
|
||||||
limits:
|
|
||||||
memory: "1.5Gi"
|
|
||||||
cpu: "300m"
|
|
||||||
requests:
|
|
||||||
memory: "500Mi"
|
|
||||||
cpu: "50m"
|
|
||||||
ports:
|
|
||||||
- containerPort: 3000
|
|
||||||
name: webui
|
|
||||||
- containerPort: 53
|
|
||||||
name: dns
|
|
||||||
- containerPort: 853
|
|
||||||
name: dot
|
|
||||||
volumeMounts:
|
|
||||||
- name: adguard-data
|
|
||||||
mountPath: /opt/adguardhome/work
|
|
||||||
subPath: work
|
|
||||||
- name: adguard-data
|
|
||||||
mountPath: /opt/adguardhome/conf
|
|
||||||
subPath: conf
|
|
||||||
- name: adguard-certs
|
|
||||||
mountPath: /certs
|
|
||||||
readOnly: true
|
|
||||||
volumes:
|
|
||||||
- name: adguard-data
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: adguard-pvc
|
|
||||||
- name: adguard-certs
|
|
||||||
secret:
|
|
||||||
secretName: adguard-certs
|
|
||||||
items:
|
|
||||||
- key: tls.crt
|
|
||||||
path: fullchain.pem
|
|
||||||
- key: tls.key
|
|
||||||
path: privkey.pem
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: adguard-pvc
|
|
||||||
namespace: adguard
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 2Gi
|
|
||||||
@@ -1,41 +0,0 @@
|
|||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: adguard-prod
|
|
||||||
namespace: adguard
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`adguard.forust.xyz`) || Host(`dns.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: adguard-service
|
|
||||||
port: 3000
|
|
||||||
- match: (Host(`adguard.forust.xyz`) || Host(`dns.forust.xyz`)) && PathPrefix(`/dns-query`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: adguard-service
|
|
||||||
port: 3000
|
|
||||||
tls:
|
|
||||||
certResolver: letsencrypt
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: adguard-local
|
|
||||||
namespace: adguard
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`) || Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: adguard-service
|
|
||||||
port: 3000
|
|
||||||
- match: (Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`) || Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)) && PathPrefix(`/dns-query`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: adguard-service
|
|
||||||
port: 3000
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: adguard
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
kubectl apply -f k8s/namespace.yaml && \
|
|
||||||
kubectl create secret tls adguard-certs -n adguard \
|
|
||||||
--cert=certs/fullchain.pem \
|
|
||||||
--key=certs/privkey.pem --dry-run=client -o yaml > \
|
|
||||||
k8s/secrets.yaml
|
|
||||||
|
|
||||||
# OR WITH NO FILE CREATION:
|
|
||||||
kubectl create secret tls adguard-certs -n adguard \
|
|
||||||
--cert=certs/fullchain.pem --key=certs/privkey.pem \
|
|
||||||
--save-config
|
|
||||||
+21
-10
@@ -26,9 +26,9 @@ services:
|
|||||||
command: server
|
command: server
|
||||||
container_name: authentik-server
|
container_name: authentik-server
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
# ports:
|
ports:
|
||||||
# - ${PORT_HTTP:-9000}:9000
|
- ${PORT_HTTP:-9000}:9000
|
||||||
# - ${PORT_HTTPS:-9443}:9443
|
- ${PORT_HTTPS:-9443}:9443
|
||||||
env_file:
|
env_file:
|
||||||
- .env
|
- .env
|
||||||
environment:
|
environment:
|
||||||
@@ -37,28 +37,39 @@ services:
|
|||||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||||
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||||
volumes:
|
|
||||||
- ./media:/media
|
|
||||||
- ./custom-templates:/templates
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=traefik-proxy"
|
||||||
|
# Services
|
||||||
|
# - "traefik.http.services.authentik-server.loadbalancer.server.port=9443"
|
||||||
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.authentik-server.rule=Host(`auth.forust.xyz`)"
|
- "traefik.http.routers.authentik-server.rule=Host(`auth.forust.xyz`)"
|
||||||
- "traefik.http.routers.authentik-server.entrypoints=websecure"
|
- "traefik.http.routers.authentik-server.entrypoints=websecure"
|
||||||
- "traefik.http.routers.authentik-server.tls.certresolver=letsencrypt"
|
- "traefik.http.routers.authentik-server.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server.service=authentik-server"
|
||||||
|
- "traefik.http.routers.authentik-server.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`)"
|
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`) || Host(`auth-dashboard.internal`)"
|
||||||
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.authentik-server-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server-local.service=authentik-server"
|
||||||
- "traefik.http.routers.authentik-server-local.tls=true"
|
- "traefik.http.routers.authentik-server-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server-dev.service=authentik-server"
|
||||||
- "traefik.http.routers.authentik-server-dev.tls=true"
|
- "traefik.http.routers.authentik-server-dev.tls=true"
|
||||||
|
volumes:
|
||||||
|
- ./media:/media
|
||||||
|
- ./custom-templates:/templates
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- traefik-proxy
|
||||||
- authentik
|
- authentik
|
||||||
depends_on:
|
depends_on:
|
||||||
postgresql:
|
postgresql:
|
||||||
@@ -91,5 +102,5 @@ volumes:
|
|||||||
driver: local
|
driver: local
|
||||||
networks:
|
networks:
|
||||||
authentik:
|
authentik:
|
||||||
proxy:
|
traefik-proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1,93 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: authentik-server-service
|
|
||||||
namespace: authentik
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app: authentik-server
|
|
||||||
ports:
|
|
||||||
- port: 9000
|
|
||||||
targetPort: 9000
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: authentik-worker-service
|
|
||||||
namespace: authentik
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app: authentik-worker
|
|
||||||
ports:
|
|
||||||
- port: 9000
|
|
||||||
targetPort: 9000
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: authentik-server-deployment
|
|
||||||
namespace: authentik
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: authentik-server
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: authentik-server
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: authentik-server
|
|
||||||
image: ghcr.io/goauthentik/server:2025.10.2
|
|
||||||
args: ["server"]
|
|
||||||
envFrom:
|
|
||||||
- configMapRef:
|
|
||||||
name: authentik-config
|
|
||||||
- secretRef:
|
|
||||||
name: authentik-secrets
|
|
||||||
ports:
|
|
||||||
- containerPort: 9000
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "700Mi"
|
|
||||||
cpu: "300m"
|
|
||||||
limits:
|
|
||||||
memory: "1.5Gi"
|
|
||||||
cpu: "1000m"
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: authentik-worker-deployment
|
|
||||||
namespace: authentik
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: authentik-worker
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: authentik-worker
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: authentik-worker
|
|
||||||
image: ghcr.io/goauthentik/server:2025.10.2
|
|
||||||
args: ["worker"]
|
|
||||||
securityContext:
|
|
||||||
runAsUser: 0
|
|
||||||
envFrom:
|
|
||||||
- configMapRef:
|
|
||||||
name: authentik-config
|
|
||||||
- secretRef:
|
|
||||||
name: authentik-secrets
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "512Mi"
|
|
||||||
cpu: "300m"
|
|
||||||
limits:
|
|
||||||
memory: "1Gi"
|
|
||||||
cpu: "700m"
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: authentik-config
|
|
||||||
namespace: authentik
|
|
||||||
data:
|
|
||||||
AUTHENTIK_IMAGE: ghcr.io/goauthentik/server
|
|
||||||
AUTHENTIK_TAG: "2025.10.2"
|
|
||||||
AUTHENTIK_POSTGRESQL__HOST: authentik-postgres-service
|
|
||||||
AUTHENTIK_POSTGRESQL__NAME: authentik
|
|
||||||
AUTHENTIK_ERROR_REPORTING__ENABLED: "true"
|
|
||||||
@@ -1,31 +0,0 @@
|
|||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: authentik-prod
|
|
||||||
namespace: authentik
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`auth.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: authentik-server-service
|
|
||||||
port: 9000
|
|
||||||
tls:
|
|
||||||
certResolver: letsencrypt
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: authentik-local
|
|
||||||
namespace: authentik
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`auth.workstation.internal`) || Host(`auth.gigaforust.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: authentik-server-service
|
|
||||||
port: 9000
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: authentik
|
|
||||||
@@ -1,66 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: authentik-postgres-service
|
|
||||||
namespace: authentik
|
|
||||||
spec:
|
|
||||||
clusterIP: None
|
|
||||||
selector:
|
|
||||||
app: authentik-postgres
|
|
||||||
ports:
|
|
||||||
- port: 5432
|
|
||||||
targetPort: 5432
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: StatefulSet
|
|
||||||
metadata:
|
|
||||||
name: authentik-postgres-statefulset
|
|
||||||
namespace: authentik
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: authentik-postgres
|
|
||||||
serviceName: authentik-postgres-service
|
|
||||||
replicas: 1
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: authentik-postgres
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: postgres
|
|
||||||
image: docker.io/library/postgres:15-alpine
|
|
||||||
env:
|
|
||||||
- name: POSTGRES_DB
|
|
||||||
value: authentik
|
|
||||||
- name: POSTGRES_USER
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: authentik-secrets
|
|
||||||
key: AUTHENTIK_POSTGRESQL__USER
|
|
||||||
- name: POSTGRES_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: authentik-secrets
|
|
||||||
key: AUTHENTIK_POSTGRESQL__PASSWORD
|
|
||||||
ports:
|
|
||||||
- containerPort: 5432
|
|
||||||
name: postgres
|
|
||||||
volumeMounts:
|
|
||||||
- name: postgres-data
|
|
||||||
mountPath: /var/lib/postgresql/data
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "256Mi"
|
|
||||||
cpu: "200m"
|
|
||||||
limits:
|
|
||||||
memory: "1Gi"
|
|
||||||
cpu: "500m"
|
|
||||||
volumeClaimTemplates:
|
|
||||||
- metadata:
|
|
||||||
name: postgres-data
|
|
||||||
spec:
|
|
||||||
accessModes: ["ReadWriteOnce"]
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 5Gi
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: authentik-secrets
|
|
||||||
namespace: authentik
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
AUTHENTIK_SECRET_KEY: ""
|
|
||||||
AUTHENTIK_POSTGRESQL__PASSWORD: ""
|
|
||||||
AUTHENTIK_POSTGRESQL__USER: authentik
|
|
||||||
AUTHENTIK_BOOTSTRAP_PASSWORD: authentik
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
CLOUDFLARE_API_TOKEN=YOUR_CLOUDFLARE_API_TOKEN
|
|
||||||
DOMAINS=example.com,dns.example.com,mc.example.com,auth.example.com,ssh.example.com
|
|
||||||
IP4_DOMAINS=
|
|
||||||
IP6_DOMAINS=
|
|
||||||
IP4_PROVIDER=cloudflare.trace
|
|
||||||
IP6_PROVIDER=none # change if you want to update AAAA
|
|
||||||
UPDATE_CRON=@every 5m
|
|
||||||
UPDATE_ON_START=true
|
|
||||||
DELETE_ON_STOP=false
|
|
||||||
DELETE_ON_FAILURE=true
|
|
||||||
TTL=1
|
|
||||||
PROXIED=!is(dns.example.com) && !is(mc.example.com) && !is(ssh.example.com)
|
|
||||||
EMOJI=true
|
|
||||||
UPTIMEKUMA=https://uptime-kuma.example.com/api/push/AsaSDFGFkfklaFALSKffkfFKfkfkfkFK?status=up&msg=OK&ping=
|
|
||||||
REJECT_CLOUDFLARE_IPS=true
|
|
||||||
+6
-23
@@ -2,29 +2,12 @@ services:
|
|||||||
cloudflare-ddns:
|
cloudflare-ddns:
|
||||||
image: timothyjmiller/cloudflare-ddns:latest
|
image: timothyjmiller/cloudflare-ddns:latest
|
||||||
container_name: cloudflare-ddns
|
container_name: cloudflare-ddns
|
||||||
restart: unless-stopped
|
|
||||||
security_opt:
|
security_opt:
|
||||||
- no-new-privileges:true
|
- no-new-privileges:true
|
||||||
network_mode: "host"
|
network_mode: 'host'
|
||||||
# https://github.com/timothymiller/cloudflare-ddns#-quick-start
|
|
||||||
environment:
|
environment:
|
||||||
- CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN:?Cloudflare API token is required}
|
- PUID=1000
|
||||||
- DOMAINS=${DOMAINS:-}
|
- PGID=1000
|
||||||
- IP4_DOMAINS=${IP4_DOMAINS:-}
|
volumes:
|
||||||
- IP6_DOMAINS=${IP6_DOMAINS:-}
|
- ./config.json:/config.json
|
||||||
- IP4_PROVIDER=${IP4_PROVIDER:-cloudflare.trace}
|
restart: unless-stopped
|
||||||
- IP6_PROVIDER=${IP6_PROVIDER:-none}
|
|
||||||
- UPDATE_CRON=${UPDATE_CRON:-@every 5m}
|
|
||||||
- UPDATE_ON_START=${UPDATE_ON_START:-true}
|
|
||||||
- DELETE_ON_STOP=${DELETE_ON_STOP:-false}
|
|
||||||
- DELETE_ON_FAILURE=${DELETE_ON_FAILURE:-true}
|
|
||||||
- TTL=${TTL:-1} # 1=auto
|
|
||||||
# to proxy only "dns.example.com" and "wfs.example.com" use "!is(dns.domain.com) && !is (wfs.domain.com)"
|
|
||||||
- PROXIED=${PROXIED:-true}
|
|
||||||
- EMOJI=${EMOJI:-true}
|
|
||||||
- UPTIMEKUMA=${UPTIMEKUMA:-}
|
|
||||||
- HEALTHCHECKS=${HEALTHCHECKS:-}
|
|
||||||
- REJECT_CLOUDFLARE_IPS=${REJECT_CLOUDFLARE_IPS:-true}
|
|
||||||
# volumes:
|
|
||||||
# Prefer using environment variables for configuration, config.json legacy support
|
|
||||||
# - ./config.json:/config.json
|
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
"api_key": {
|
"api_key": {
|
||||||
"api_key": "api_key_here",
|
"api_key": "api_key_here",
|
||||||
"account_email": "your_email_here"
|
"account_email": "your_email_here"
|
||||||
},
|
}
|
||||||
"zone_id": "your_zone-id",
|
"zone_id": "your_zone-id",
|
||||||
"subdomains": [
|
"subdomains": [
|
||||||
{ "name": "", "proxied": true },
|
{ "name": "", "proxied": true },
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
secret.yaml
|
|
||||||
@@ -1,32 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: cfddns
|
|
||||||
labels:
|
|
||||||
app: cfddns
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: cfddns
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cfddns
|
|
||||||
spec:
|
|
||||||
hostNetwork: true
|
|
||||||
dnsPolicy: ClusterFirstWithHostNet
|
|
||||||
containers:
|
|
||||||
- name: cloudflare-ddns
|
|
||||||
image: timothyjmiller/cloudflare-ddns:latest
|
|
||||||
imagePullPolicy: Always
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "20Mi"
|
|
||||||
cpu: "30m"
|
|
||||||
limits:
|
|
||||||
memory: "64Mi"
|
|
||||||
cpu: "50m"
|
|
||||||
envFrom:
|
|
||||||
- secretRef:
|
|
||||||
name: cfddns-secrets
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: cfddns-secrets
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
CLOUDFLARE_API_TOKEN: your_token
|
|
||||||
DOMAINS: "example.com,www.example.com"
|
|
||||||
IP4_PROVIDER: cloudflare.trace
|
|
||||||
IP6_PROVIDER: none
|
|
||||||
UPDATE_CRON: "@every 5m"
|
|
||||||
UPDATE_ON_START: "true"
|
|
||||||
DELETE_ON_STOP: "false"
|
|
||||||
DELETE_ON_FAILURE: "true"
|
|
||||||
TTL: "1"
|
|
||||||
PROXIED: "true"
|
|
||||||
EMOJI: "true"
|
|
||||||
REJECT_CLOUDFLARE_IPS: "true"
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
CMK_PASSWORD=password
|
|
||||||
TZ=Europe/Berlin
|
|
||||||
@@ -1,39 +0,0 @@
|
|||||||
services:
|
|
||||||
checkmk:
|
|
||||||
image: "checkmk/check-mk-raw:2.4.0-latest"
|
|
||||||
container_name: "checkmk"
|
|
||||||
restart: unless-stopped
|
|
||||||
# ports:
|
|
||||||
# - 5000:5000
|
|
||||||
# - 6776:8000
|
|
||||||
volumes:
|
|
||||||
- sites:/omd/sites
|
|
||||||
tmpfs:
|
|
||||||
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
|
|
||||||
environment:
|
|
||||||
- CMK_PASSWORD=${CMK_PASSWORD:-password}
|
|
||||||
- CMK_SITE_ID=cmk
|
|
||||||
- TZ=${TZ:-Etc/UTC}
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.checkmk.loadbalancer.server.port=5000"
|
|
||||||
|
|
||||||
# Prod Router
|
|
||||||
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
|
||||||
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.checkmk.tls.certresolver=letsencrypt"
|
|
||||||
# Local Router
|
|
||||||
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)"
|
|
||||||
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.checkmk-local.tls=true"
|
|
||||||
# Dev Router
|
|
||||||
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
|
|
||||||
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.checkmk-dev.tls=true"
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
volumes:
|
|
||||||
sites:
|
|
||||||
@@ -1,68 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: checkmk-service
|
|
||||||
namespace: checkmk
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: checkmk
|
|
||||||
ports:
|
|
||||||
- port: 5000
|
|
||||||
targetPort: 5000
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: checkmk-deployment
|
|
||||||
namespace: checkmk
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: checkmk
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: checkmk
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: checkmk
|
|
||||||
image: checkmk/check-mk-raw:2.4.0-latest
|
|
||||||
envFrom:
|
|
||||||
- secretRef:
|
|
||||||
name: checkmk-secrets
|
|
||||||
- configMapRef:
|
|
||||||
name: checkmk-config
|
|
||||||
ports:
|
|
||||||
- containerPort: 5000
|
|
||||||
volumeMounts:
|
|
||||||
- name: sites
|
|
||||||
mountPath: /omd/sites
|
|
||||||
- name: tmp
|
|
||||||
mountPath: /opt/omd/sites/cmk/tmp
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "2Gi"
|
|
||||||
cpu: "600m"
|
|
||||||
limits:
|
|
||||||
memory: "5Gi"
|
|
||||||
cpu: "4"
|
|
||||||
volumes:
|
|
||||||
- name: sites
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: checkmk-sites-pvc
|
|
||||||
- name: tmp
|
|
||||||
emptyDir:
|
|
||||||
medium: Memory
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: checkmk-sites-pvc
|
|
||||||
namespace: checkmk
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 5Gi
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: checkmk-config
|
|
||||||
namespace: checkmk
|
|
||||||
data:
|
|
||||||
TZ: Europe/Bratislava
|
|
||||||
CMK_SITE_ID: cmk
|
|
||||||
@@ -1,31 +0,0 @@
|
|||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: checkmk-prod
|
|
||||||
namespace: checkmk
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`cmk.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: checkmk-service
|
|
||||||
port: 5000
|
|
||||||
tls:
|
|
||||||
certResolver: letsencrypt
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: checkmk-local
|
|
||||||
namespace: checkmk
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`cmk.workstation.internal`) || Host(`cmk.gigaforust.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: checkmk-service
|
|
||||||
port: 5000
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: checkmk
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: checkmk-secrets
|
|
||||||
namespace: checkmk
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
CMK_PASSWORD: "password"
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
ACCOUNT_REGISTRATION=false
|
|
||||||
HTTP_ALLOWED=false
|
|
||||||
ALLOW_UNAUTHENTICAED=false
|
|
||||||
AUTO_DELETE_EVERY_N_HOURS=24
|
|
||||||
WEBROOT=/convert
|
|
||||||
HIDE_HISTORY=false
|
|
||||||
LANGUAGE=en
|
|
||||||
UNAUTHED_USER_SHARING=false
|
|
||||||
MAX_CONVERT_PROCESS=0
|
|
||||||
@@ -1,70 +0,0 @@
|
|||||||
services:
|
|
||||||
convertx:
|
|
||||||
container_name: convertx
|
|
||||||
image: ghcr.io/c4illin/convertx:latest
|
|
||||||
restart: unless-stopped
|
|
||||||
ports:
|
|
||||||
- "9992:3000"
|
|
||||||
# https://github.com/C4illin/ConvertX#environment-variables
|
|
||||||
environment:
|
|
||||||
- JWT_SECRET=$(JWT_SECRET)
|
|
||||||
- ACCOUNT_REGISTRATION=$(ACCOUNT_REGISTRATION:-false)
|
|
||||||
- HTTP_ALLOWED=$(HTTP_ALLOWED:-false)
|
|
||||||
- ALLOW_UNAUTHENTICATED=$(ALLOW_UNAUTHENTICATED:-false)
|
|
||||||
- AUTO_DELETE_EVERY_N_HOURS=$(AUTO_DELETE_EVERY_N_HOURS:-24)
|
|
||||||
- WEBROOT=$(WEBROOT)
|
|
||||||
- HIDE_HISTORY=$(HIDE_HISTORY:-false)
|
|
||||||
- LANGUAGE=$(LANGUAGE:-en)
|
|
||||||
- UNAUTHENTICATED_USER_SHARING=$(UNAUTHENTICATED_USER_SHARING:-false)
|
|
||||||
- MAX_CONVERT_PROCESS=$(MAX_CONVERT_PROCESS:-0)
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.convertx.loadbalancer.server.port=3000"
|
|
||||||
# Prod Router
|
|
||||||
- "traefik.http.routers.convertx.rule=(Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/convert`)"
|
|
||||||
- "traefik.http.routers.convertx.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.convertx.priority=50"
|
|
||||||
- "traefik.http.routers.convertx.tls.certresolver=letsencrypt"
|
|
||||||
# Local Router
|
|
||||||
- "traefik.http.routers.convertx-local.rule=Host(`workstation.internal`) && PathPrefix(`/convert`)"
|
|
||||||
- "traefik.http.routers.convertx-local.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.convertx-local.priority=50"
|
|
||||||
- "traefik.http.routers.convertx-local.tls=true"
|
|
||||||
# Dev Router
|
|
||||||
- "traefik.http.routers.convertx-dev.rule=Host(`gigaforust.internal`) && PathPrefix(`/convert`)"
|
|
||||||
- "traefik.http.routers.convertx-dev.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.convertx-dev.priority=50"
|
|
||||||
- "traefik.http.routers.convertx-dev.tls=true"
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
volumes:
|
|
||||||
- data:/app/data
|
|
||||||
|
|
||||||
bentopdf:
|
|
||||||
container_name: bentopdf
|
|
||||||
image: bentopdf/bentopdf:latest
|
|
||||||
restart: unless-stopped
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.bentopdf.loadbalancer.server.port=8080"
|
|
||||||
|
|
||||||
# Prod router
|
|
||||||
- "traefik.http.routers.bentopdf.rule=Host(`pdf.forust.xyz`)"
|
|
||||||
- "traefik.http.routers.bentopdf.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.bentopdf.tls.certresolver=letsencrypt"
|
|
||||||
- "traefik.http.routers.bentopdf.tls=true"
|
|
||||||
# Local router
|
|
||||||
- "traefik.http.routers.bentopdf-local.rule=Host(`pdf.wokstation.internal`)"
|
|
||||||
- "traefik.http.routers.bentopdf-local.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.bentopdf-local.tls=true"
|
|
||||||
# Dev router
|
|
||||||
- "traefik.http.routers.bentopdf-dev.rule=Host(`pdf.gigaforust.internal`)"
|
|
||||||
- "traefik.http.routers.bentopdf-dev.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.bentopdf-dev.tls=true"
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
volumes:
|
|
||||||
data:
|
|
||||||
@@ -1,42 +0,0 @@
|
|||||||
kind: Service
|
|
||||||
apiVersion: v1
|
|
||||||
metadata:
|
|
||||||
name: bentopdf-service
|
|
||||||
namespace: converters
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: bentopdf
|
|
||||||
ports:
|
|
||||||
- port: 8080
|
|
||||||
targetPort: 8080
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: bentopdf-deployment
|
|
||||||
namespace: converters
|
|
||||||
spec:
|
|
||||||
replicas: 2
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: bentopdf
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: bentopdf
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- image: bentopdf/bentopdf:latest
|
|
||||||
imagePullPolicy: Always
|
|
||||||
name: bentopdf
|
|
||||||
ports:
|
|
||||||
- containerPort: 8080
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "50Mi"
|
|
||||||
cpu: "50m"
|
|
||||||
ephemeral-storage: "100Mi"
|
|
||||||
limits:
|
|
||||||
memory: "700Mi"
|
|
||||||
cpu: "700m"
|
|
||||||
ephemeral-storage: "5Gi"
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
# test manifest with docker and k8s config keys mismatch
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: convertx-config
|
|
||||||
namespace: converters
|
|
||||||
data:
|
|
||||||
ACCOUNT_REGISTRATION: "false"
|
|
||||||
HTTP_ALLOWED: "false"
|
|
||||||
ALLOW_UNAUTHENTICAED: "false"
|
|
||||||
AUTO_DELETE_EVERY_N_HOURS: "24"
|
|
||||||
WEBROOT: "/convert"
|
|
||||||
HIDE_HISTORY: "false"
|
|
||||||
LANGUAGE: "en"
|
|
||||||
UNAUTHED_USER_SHARING: "false"
|
|
||||||
MAX_CONVERT_PROCESS: "0"
|
|
||||||
@@ -1,63 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: convertx-service
|
|
||||||
namespace: converters
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: convertx
|
|
||||||
ports:
|
|
||||||
- port: 3000
|
|
||||||
targetPort: 3000
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: convertx-deployment
|
|
||||||
namespace: converters
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: convertx
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: convertx
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- image: ghcr.io/c4illin/convertx:latest
|
|
||||||
name: convertx
|
|
||||||
envFrom:
|
|
||||||
- configMapRef:
|
|
||||||
name: convertx-config
|
|
||||||
- secretRef:
|
|
||||||
name: convertx-secrets
|
|
||||||
ports:
|
|
||||||
- containerPort: 3000
|
|
||||||
volumeMounts:
|
|
||||||
- mountPath: /data
|
|
||||||
name: data
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "250Mi"
|
|
||||||
cpu: "100m"
|
|
||||||
limits:
|
|
||||||
cpu: "1500m"
|
|
||||||
memory: "1.5Gi"
|
|
||||||
volumes:
|
|
||||||
- name: data
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: convertx-pvc
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: convertx-pvc
|
|
||||||
namespace: converters
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 2Gi
|
|
||||||
@@ -1,65 +0,0 @@
|
|||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: convertx-prod
|
|
||||||
namespace: converters
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: (Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/convert`)
|
|
||||||
kind: Rule
|
|
||||||
priority: 50
|
|
||||||
services:
|
|
||||||
- name: convertx-service
|
|
||||||
port: 3000
|
|
||||||
tls:
|
|
||||||
certResolver: letsencrypt
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: convertx-local
|
|
||||||
namespace: converters
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: (Host(`workstation.internal`) || Host(`gigaforust.internal`)) && PathPrefix(`/convert`)
|
|
||||||
kind: Rule
|
|
||||||
priority: 50
|
|
||||||
services:
|
|
||||||
- name: convertx-service
|
|
||||||
port: 3000
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: bentopdf-prod
|
|
||||||
namespace: converters
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`pdf.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: bentopdf-service
|
|
||||||
port: 8080
|
|
||||||
tls:
|
|
||||||
certResolver: letsencrypt
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: bentopdf-local
|
|
||||||
namespace: converters
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`pdf.workstation.internal`) || Host(`pdf.gigaforust.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: bentopdf-service
|
|
||||||
port: 8080
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: converters
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: convertx-secrets
|
|
||||||
namespace: converters
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
jwt-secret: ""
|
|
||||||
+23
-15
@@ -3,44 +3,52 @@ services:
|
|||||||
image: darthnorse/dockmon:latest
|
image: darthnorse/dockmon:latest
|
||||||
container_name: dockmon
|
container_name: dockmon
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
# ports:
|
ports:
|
||||||
# - 8000:443
|
- 8000:443
|
||||||
|
environment:
|
||||||
|
- TZ=Europe/Bratislava
|
||||||
volumes:
|
volumes:
|
||||||
- data:/app/data
|
- ./data:/app/data
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
|
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
retries: 3
|
retries: 3
|
||||||
|
networks:
|
||||||
|
- traefik-proxy
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
- "traefik.docker.network=traefik-proxy"
|
||||||
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
|
||||||
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||||
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
||||||
- "traefik.http.routers.dockmon.middlewares=security-headers@file"
|
- "traefik.http.routers.dockmon.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.dockmon.tls.certresolver=letsencrypt"
|
- "traefik.http.routers.dockmon.service=dockmon"
|
||||||
|
- "traefik.http.routers.dockmon.tls=true"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
|
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`) || Host(`dockmon.internal`)"
|
||||||
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.dockmon-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.dockmon-local.service=dockmon"
|
||||||
- "traefik.http.routers.dockmon-local.tls=true"
|
- "traefik.http.routers.dockmon-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.dockmon-dev.middlewares=security-chain@file"
|
||||||
|
- "traefik.http.routers.dockmon-dev.service=dockmon"
|
||||||
- "traefik.http.routers.dockmon-dev.tls=true"
|
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||||
|
|
||||||
# Glance Metadata
|
|
||||||
- glance.name=dockmon
|
- glance.name=dockmon
|
||||||
- glance.url=https://dockmon.forust.xyz/
|
- glance.url=https://dockmon.forust.xyz/
|
||||||
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
traefik-proxy:
|
||||||
volumes:
|
|
||||||
data:
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1,68 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: dockmon-service
|
|
||||||
namespace: dockmon
|
|
||||||
spec:
|
|
||||||
clusterIP: None
|
|
||||||
selector:
|
|
||||||
app: dockmon
|
|
||||||
ports:
|
|
||||||
- port: 443
|
|
||||||
targetPort: 443
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: StatefulSet
|
|
||||||
metadata:
|
|
||||||
name: dockmon-statefulset
|
|
||||||
namespace: dockmon
|
|
||||||
spec:
|
|
||||||
serviceName: dockmon-service
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: dockmon
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: dockmon
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: dockmon
|
|
||||||
image: darthnorse/dockmon:latest
|
|
||||||
ports:
|
|
||||||
- containerPort: 443
|
|
||||||
volumeMounts:
|
|
||||||
- name: data
|
|
||||||
mountPath: /app/data
|
|
||||||
- name: docker-sock
|
|
||||||
mountPath: /var/run/docker.sock
|
|
||||||
livenessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /health
|
|
||||||
port: 443
|
|
||||||
scheme: HTTPS
|
|
||||||
initialDelaySeconds: 30
|
|
||||||
periodSeconds: 30
|
|
||||||
timeoutSeconds: 10
|
|
||||||
failureThreshold: 3
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "512Mi"
|
|
||||||
cpu: "200m"
|
|
||||||
limits:
|
|
||||||
memory: "1.5Gi"
|
|
||||||
cpu: "700m "
|
|
||||||
volumes:
|
|
||||||
- name: docker-sock
|
|
||||||
hostPath:
|
|
||||||
path: /var/run/docker.sock
|
|
||||||
type: Socket
|
|
||||||
volumeClaimTemplates:
|
|
||||||
- metadata:
|
|
||||||
name: data
|
|
||||||
spec:
|
|
||||||
accessModes: ["ReadWriteOnce"]
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 1Gi
|
|
||||||
@@ -1,43 +0,0 @@
|
|||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: ServersTransport
|
|
||||||
metadata:
|
|
||||||
name: dockmon-transport
|
|
||||||
namespace: dockmon
|
|
||||||
spec:
|
|
||||||
insecureSkipVerify: true
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: dockmon-prod
|
|
||||||
namespace: dockmon
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`dockmon.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
middlewares:
|
|
||||||
- name: security-headers@file
|
|
||||||
services:
|
|
||||||
- name: dockmon-service
|
|
||||||
port: 443
|
|
||||||
serversTransport: dockmon-transport
|
|
||||||
tls:
|
|
||||||
certResolver: letsencrypt
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: dockmon-local
|
|
||||||
namespace: dockmon
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`dockmon.workstation.internal`) || Host(`dockmon.gigaforust.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: dockmon-service
|
|
||||||
port: 443
|
|
||||||
serversTransport: dockmon-transport
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: dockmon
|
|
||||||
@@ -1,31 +0,0 @@
|
|||||||
services:
|
|
||||||
downtify:
|
|
||||||
container_name: downtify
|
|
||||||
image: ghcr.io/henriquesebastiao/downtify:latest
|
|
||||||
restart: unless-stopped
|
|
||||||
# ports:
|
|
||||||
# - '7077:8000'
|
|
||||||
volumes:
|
|
||||||
- ./Downtify_downloads:/downloads
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.downtify.loadbalancer.server.port=8000"
|
|
||||||
|
|
||||||
# Prod Router
|
|
||||||
- "traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)"
|
|
||||||
- "traefik.http.routers.downtify.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.downtify.middlewares=security-chain@file"
|
|
||||||
- "traefik.http.routers.downtify.tls.certresolver=letsencrypt"
|
|
||||||
# Local Router
|
|
||||||
- "traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`)"
|
|
||||||
- "traefik.http.routers.downtify-local.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.downtify-local.tls=true"
|
|
||||||
# Dev Router
|
|
||||||
- "traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)"
|
|
||||||
- "traefik.http.routers.downtify-dev.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.downtify-dev.tls=true"
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
@@ -1,58 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: downtify-service
|
|
||||||
namespace: downtify
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: downtify
|
|
||||||
ports:
|
|
||||||
- port: 8000
|
|
||||||
targetPort: 8000
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: downtify-deployment
|
|
||||||
namespace: downtify
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: downtify
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: downtify
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: downtify
|
|
||||||
image: ghcr.io/henriquesebastiao/downtify:latest
|
|
||||||
ports:
|
|
||||||
- containerPort: 8000
|
|
||||||
volumeMounts:
|
|
||||||
- name: downloads
|
|
||||||
mountPath: /downloads
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "128Mi"
|
|
||||||
cpu: "200m"
|
|
||||||
limits:
|
|
||||||
memory: "1Gi"
|
|
||||||
cpu: "1"
|
|
||||||
volumes:
|
|
||||||
- name: downloads
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: downtify-downloads-pvc
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: downtify-downloads-pvc
|
|
||||||
namespace: downtify
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 10Gi
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: downtify-prod
|
|
||||||
namespace: downtify
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`downtify.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
middlewares:
|
|
||||||
- name: security-chain@file
|
|
||||||
services:
|
|
||||||
- name: downtify-service
|
|
||||||
port: 8000
|
|
||||||
tls:
|
|
||||||
certResolver: letsencrypt
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: downtify-local
|
|
||||||
namespace: downtify
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`downtify.workstation.internal`) || Host(`downtify.gigaforust.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: downtify-service
|
|
||||||
port: 8000
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: downtify
|
|
||||||
@@ -3,11 +3,10 @@ services:
|
|||||||
build:
|
build:
|
||||||
context: .
|
context: .
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
image: gcr.forust.xyz/forust/dtek-notif:latest
|
|
||||||
pull_policy: build
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
- TZ=Europe/Kyiv
|
- TZ=Europe/Kyiv
|
||||||
|
|
||||||
dns:
|
dns:
|
||||||
- 1.1.1.1
|
- 1.1.1.1
|
||||||
- 8.8.8.8
|
- 8.8.8.8
|
||||||
|
|||||||
+314
-284
File diff suppressed because it is too large
Load Diff
@@ -9,6 +9,5 @@ WEBINAR_CHECK_INTERVAL=60
|
|||||||
REDIS_HOST=redis
|
REDIS_HOST=redis
|
||||||
REDIS_PORT=6379
|
REDIS_PORT=6379
|
||||||
PLAYWRIGHT_WS=ws://playwright-service:3000/ws
|
PLAYWRIGHT_WS=ws://playwright-service:3000/ws
|
||||||
TZ=Europe/Kyiv
|
|
||||||
WEBINAR_TELEGRAM_TOKEN=your_telegram_bot_token_here
|
WEBINAR_TELEGRAM_TOKEN=your_telegram_bot_token_here
|
||||||
WEBINAR_ADMIN_ID=123456789
|
WEBINAR_ADMIN_ID=123456789
|
||||||
|
|||||||
@@ -17,8 +17,6 @@ services:
|
|||||||
|
|
||||||
session-keeper:
|
session-keeper:
|
||||||
build: ./phpsessid-bot
|
build: ./phpsessid-bot
|
||||||
image: gcr.forust.xyz/forust/session-keeper:latest
|
|
||||||
pull_policy: build
|
|
||||||
env_file: .env
|
env_file: .env
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
depends_on:
|
depends_on:
|
||||||
@@ -33,8 +31,6 @@ services:
|
|||||||
|
|
||||||
webinar-checker:
|
webinar-checker:
|
||||||
build: ./webinar-checker
|
build: ./webinar-checker
|
||||||
image: gcr.forust.xyz/forust/webinar-checker:latest
|
|
||||||
pull_policy: build
|
|
||||||
env_file: .env
|
env_file: .env
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
depends_on:
|
depends_on:
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: edu-master
|
|
||||||
@@ -1,57 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: playwright-service
|
|
||||||
namespace: edu-master
|
|
||||||
labels:
|
|
||||||
app: edu-master-playwright
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: edu-master-playwright
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: edu-master-playwright
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: playwright
|
|
||||||
image: mcr.microsoft.com/playwright:v1.56.0-jammy
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
command:
|
|
||||||
- npx
|
|
||||||
- -y
|
|
||||||
- playwright@1.56.0
|
|
||||||
- run-server
|
|
||||||
- --port
|
|
||||||
- "3000"
|
|
||||||
- --path
|
|
||||||
- /ws
|
|
||||||
ports:
|
|
||||||
- containerPort: 3000
|
|
||||||
readinessProbe:
|
|
||||||
tcpSocket:
|
|
||||||
port: 3000
|
|
||||||
initialDelaySeconds: 5
|
|
||||||
periodSeconds: 10
|
|
||||||
timeoutSeconds: 3
|
|
||||||
livenessProbe:
|
|
||||||
tcpSocket:
|
|
||||||
port: 3000
|
|
||||||
initialDelaySeconds: 15
|
|
||||||
periodSeconds: 20
|
|
||||||
timeoutSeconds: 3
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: playwright-service
|
|
||||||
namespace: edu-master
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: edu-master-playwright
|
|
||||||
ports:
|
|
||||||
- name: ws
|
|
||||||
port: 3000
|
|
||||||
targetPort: 3000
|
|
||||||
@@ -1,74 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: redis
|
|
||||||
namespace: edu-master
|
|
||||||
labels:
|
|
||||||
app: edu-master-redis
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: edu-master-redis
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: edu-master-redis
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: redis
|
|
||||||
image: redis:alpine
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
ports:
|
|
||||||
- containerPort: 6379
|
|
||||||
volumeMounts:
|
|
||||||
- name: redis-data
|
|
||||||
mountPath: /data
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 25m
|
|
||||||
memory: 64Mi
|
|
||||||
limits:
|
|
||||||
cpu: 250m
|
|
||||||
memory: 256Mi
|
|
||||||
readinessProbe:
|
|
||||||
exec:
|
|
||||||
command: ["redis-cli", "ping"]
|
|
||||||
initialDelaySeconds: 5
|
|
||||||
periodSeconds: 5
|
|
||||||
timeoutSeconds: 3
|
|
||||||
livenessProbe:
|
|
||||||
exec:
|
|
||||||
command: ["redis-cli", "ping"]
|
|
||||||
initialDelaySeconds: 10
|
|
||||||
periodSeconds: 10
|
|
||||||
timeoutSeconds: 3
|
|
||||||
volumes:
|
|
||||||
- name: redis-data
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: redis-data-pvc
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: redis-data-pvc
|
|
||||||
namespace: edu-master
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 1Gi
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: redis
|
|
||||||
namespace: edu-master
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: edu-master-redis
|
|
||||||
ports:
|
|
||||||
- name: redis
|
|
||||||
port: 6379
|
|
||||||
targetPort: 6379
|
|
||||||
@@ -1,50 +0,0 @@
|
|||||||
# One-time Job to migrate redis state from docker compose to k8s (maintenance window).
|
|
||||||
# The .example file is not applied by the deploy pipeline (mask *.example.yaml).
|
|
||||||
#
|
|
||||||
# Runbook:
|
|
||||||
# 1. docker compose -f <repo>/edu_master/compose.yaml stop # SIGTERM -> redis will flush dump.rdb
|
|
||||||
# 2. docker run --rm -v edu_master_redis-data:/data \
|
|
||||||
# -v /tmp/edu-master-backup:/backup \
|
|
||||||
# redis:alpine sh -c "cp /data/dump.rdb /backup/ && ls -la /backup"
|
|
||||||
# 3. kubectl apply -f edu_master/k8s/namespace.yaml
|
|
||||||
# 4. kubectl apply -f <only the PVC from redis.yaml> # seed must come BEFORE redis pod starts
|
|
||||||
# 5. kubectl apply -f edu_master/k8s/restore-seed-job.yaml.example
|
|
||||||
# kubectl wait --for=condition=complete job/redis-restore-seed -n edu-master --timeout=120s
|
|
||||||
# 6. kubectl delete job redis-restore-seed -n edu-master
|
|
||||||
# 7. kubectl apply -f edu_master/k8s/ -R # apply remaining manifests
|
|
||||||
apiVersion: batch/v1
|
|
||||||
kind: Job
|
|
||||||
metadata:
|
|
||||||
name: redis-restore-seed
|
|
||||||
namespace: edu-master
|
|
||||||
spec:
|
|
||||||
backoffLimit: 2
|
|
||||||
ttlSecondsAfterFinished: 3600
|
|
||||||
template:
|
|
||||||
spec:
|
|
||||||
restartPolicy: Never
|
|
||||||
containers:
|
|
||||||
- name: seed
|
|
||||||
image: redis:alpine
|
|
||||||
command:
|
|
||||||
- /bin/sh
|
|
||||||
- -ec
|
|
||||||
- |
|
|
||||||
ls -la /backup
|
|
||||||
cp /backup/dump.rdb /data/dump.rdb
|
|
||||||
chmod 644 /data/dump.rdb
|
|
||||||
ls -la /data
|
|
||||||
volumeMounts:
|
|
||||||
- name: redis-data
|
|
||||||
mountPath: /data
|
|
||||||
- name: backup
|
|
||||||
mountPath: /backup
|
|
||||||
readOnly: true
|
|
||||||
volumes:
|
|
||||||
- name: redis-data
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: redis-data-pvc
|
|
||||||
- name: backup
|
|
||||||
hostPath:
|
|
||||||
path: /tmp/edu-master-backup
|
|
||||||
type: DirectoryOrCreate
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: edu-master-secrets
|
|
||||||
namespace: edu-master
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
# Session keeper credentials
|
|
||||||
KEEPER_LOGIN: ""
|
|
||||||
KEEPER_PASSWORD: ""
|
|
||||||
KEEPER_INTERVAL: "10"
|
|
||||||
# EDU links
|
|
||||||
EDU_URL_BASE: "https://edu.edu.vn.ua"
|
|
||||||
EDU_URL_LOGIN: "/user/login"
|
|
||||||
EDU_URL_COURSES: "/course/userlist"
|
|
||||||
EDU_URL_WEBINAR: "/webinar/useractive"
|
|
||||||
# Playwright
|
|
||||||
USER_AGENT: ""
|
|
||||||
PLAYWRIGHT_WS: "ws://playwright-service:3000/ws"
|
|
||||||
# Webinar-checker
|
|
||||||
WEBINAR_TELEGRAM_TOKEN: ""
|
|
||||||
WEBINAR_ADMIN_ID: ""
|
|
||||||
WEBINAR_CHECK_INTERVAL: "60"
|
|
||||||
# Database
|
|
||||||
REDIS_HOST: "redis"
|
|
||||||
REDIS_PORT: "6379"
|
|
||||||
TZ: "Europe/Kyiv"
|
|
||||||
@@ -1,52 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: session-keeper
|
|
||||||
namespace: edu-master
|
|
||||||
labels:
|
|
||||||
app: edu-master-session-keeper
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: edu-master-session-keeper
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: edu-master-session-keeper
|
|
||||||
spec:
|
|
||||||
initContainers:
|
|
||||||
- name: wait-redis
|
|
||||||
image: redis:alpine
|
|
||||||
command:
|
|
||||||
- /bin/sh
|
|
||||||
- -ec
|
|
||||||
- |
|
|
||||||
i=0
|
|
||||||
until redis-cli -h redis ping | grep -q PONG; do
|
|
||||||
i=$((i+1))
|
|
||||||
[ "$i" -ge 300 ] && echo "TIMEOUT: redis not ready" && exit 1
|
|
||||||
sleep 2
|
|
||||||
done
|
|
||||||
echo "redis is ready"
|
|
||||||
containers:
|
|
||||||
- name: session-keeper
|
|
||||||
image: gcr.forust.xyz/forust/session-keeper:latest
|
|
||||||
imagePullPolicy: Always
|
|
||||||
envFrom:
|
|
||||||
- secretRef:
|
|
||||||
name: edu-master-secrets
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 25m
|
|
||||||
memory: 96Mi
|
|
||||||
limits:
|
|
||||||
cpu: 250m
|
|
||||||
memory: 256Mi
|
|
||||||
readinessProbe:
|
|
||||||
exec:
|
|
||||||
command: ["/bin/sh", "-ec", "redis-cli -h redis EXISTS EDU_PHPSESSID | grep -q 1"]
|
|
||||||
initialDelaySeconds: 15
|
|
||||||
periodSeconds: 30
|
|
||||||
timeoutSeconds: 5
|
|
||||||
failureThreshold: 10
|
|
||||||
@@ -1,62 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: webinar-checker
|
|
||||||
namespace: edu-master
|
|
||||||
labels:
|
|
||||||
app: edu-master-webinar-checker
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: edu-master-webinar-checker
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: edu-master-webinar-checker
|
|
||||||
spec:
|
|
||||||
# Enforces dependency order like compose depends_on:
|
|
||||||
# redis healthy -> session-keeper healthy (EXISTS EDU_PHPSESSID) -> playwright started
|
|
||||||
initContainers:
|
|
||||||
- name: wait-deps
|
|
||||||
image: redis:alpine
|
|
||||||
command:
|
|
||||||
- /bin/sh
|
|
||||||
- -ec
|
|
||||||
- |
|
|
||||||
i=0
|
|
||||||
until redis-cli -h redis ping | grep -q PONG; do
|
|
||||||
i=$((i+1))
|
|
||||||
[ "$i" -ge 300 ] && echo "TIMEOUT: redis not ready" && exit 1
|
|
||||||
sleep 2
|
|
||||||
done
|
|
||||||
echo "redis ok"
|
|
||||||
until [ "$(redis-cli -h redis EXISTS EDU_PHPSESSID)" = "1" ]; do
|
|
||||||
i=$((i+1))
|
|
||||||
[ "$i" -ge 300 ] && echo "TIMEOUT: no PHPSESSID (session-keeper down?)" && exit 1
|
|
||||||
sleep 2
|
|
||||||
done
|
|
||||||
echo "PHPSESSID ok"
|
|
||||||
until nc -z playwright-service 3000; do
|
|
||||||
i=$((i+1))
|
|
||||||
[ "$i" -ge 300 ] && echo "TIMEOUT: playwright-service not reachable" && exit 1
|
|
||||||
sleep 2
|
|
||||||
done
|
|
||||||
echo "playwright ok"
|
|
||||||
containers:
|
|
||||||
- name: webinar-checker
|
|
||||||
image: gcr.forust.xyz/forust/webinar-checker:latest
|
|
||||||
imagePullPolicy: Always
|
|
||||||
envFrom:
|
|
||||||
- secretRef:
|
|
||||||
name: edu-master-secrets
|
|
||||||
env:
|
|
||||||
- name: TZ
|
|
||||||
value: "Europe/Kyiv"
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 25m
|
|
||||||
memory: 128Mi
|
|
||||||
limits:
|
|
||||||
cpu: 300m
|
|
||||||
memory: 384Mi
|
|
||||||
@@ -3,10 +3,10 @@ FROM python:3.11-slim
|
|||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
# Install system dependencies
|
# Install system dependencies
|
||||||
RUN apt-get update && apt-get install -y --no-install-recommends redis-tools && rm -rf /var/lib/apt/lists/*
|
RUN apt-get update && apt-get install -y redis-tools && rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
# Install dependencies
|
# Install dependencies
|
||||||
RUN pip install --no-cache-dir requests==2.32.3 redis==5.2.1
|
RUN pip install requests redis
|
||||||
|
|
||||||
# Copy application code
|
# Copy application code
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|||||||
@@ -1,43 +1,28 @@
|
|||||||
import logging
|
|
||||||
import os
|
import os
|
||||||
import time
|
import time
|
||||||
|
import requests
|
||||||
|
import logging
|
||||||
|
import redis
|
||||||
from datetime import datetime
|
from datetime import datetime
|
||||||
|
|
||||||
import redis
|
|
||||||
import requests
|
|
||||||
|
|
||||||
# Configure logging
|
# Configure logging
|
||||||
logging.basicConfig(level=logging.INFO, format='%(asctime)s - %(levelname)s - %(message)s')
|
logging.basicConfig(
|
||||||
|
level=logging.INFO,
|
||||||
|
format='%(asctime)s - %(levelname)s - %(message)s'
|
||||||
|
)
|
||||||
logger = logging.getLogger(__name__)
|
logger = logging.getLogger(__name__)
|
||||||
|
|
||||||
|
# Load configuration
|
||||||
|
LOGIN = os.getenv('EDU_LOGIN')
|
||||||
|
PASSWORD = os.getenv('EDU_PASSWORD')
|
||||||
|
URL_LOGIN = os.getenv('EDU_URL_LOGIN', 'https://edu.edu.vn.ua/user/login')
|
||||||
|
URL_VERIFY = os.getenv('EDU_URL_VERIFY', 'https://edu.edu.vn.ua/course/userlist')
|
||||||
|
INTERVAL = int(os.getenv('PHPSESSID_INTERVAL', 10))
|
||||||
|
USER_AGENT = os.getenv('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||||
|
REDIS_HOST = os.getenv('REDIS_HOST', 'redis')
|
||||||
|
REDIS_PORT = int(os.getenv('REDIS_PORT', 6379))
|
||||||
|
|
||||||
# Load configuration (adapted to .env keys)
|
SUCCESS_FILE = '/tmp/last_success'
|
||||||
def _env(key, default=None):
|
|
||||||
v = os.getenv(key, default)
|
|
||||||
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")):
|
|
||||||
return v[1:-1]
|
|
||||||
return v
|
|
||||||
|
|
||||||
|
|
||||||
LOGIN = _env('KEEPER_LOGIN')
|
|
||||||
PASSWORD = _env('KEEPER_PASSWORD')
|
|
||||||
|
|
||||||
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
|
|
||||||
EDU_LOGIN_PATH = _env('EDU_URL_LOGIN', '/user/login')
|
|
||||||
EDU_COURSES_PATH = _env('EDU_URL_COURSES', '/course/userlist')
|
|
||||||
URL_LOGIN = f'{EDU_BASE.rstrip("/")}/{EDU_LOGIN_PATH.lstrip("/")}'
|
|
||||||
URL_VERIFY = f'{EDU_BASE.rstrip("/")}/{EDU_COURSES_PATH.lstrip("/")}'
|
|
||||||
|
|
||||||
INTERVAL = int(_env('KEEPER_INTERVAL', 10))
|
|
||||||
USER_AGENT = _env(
|
|
||||||
'USER_AGENT',
|
|
||||||
'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36',
|
|
||||||
)
|
|
||||||
REDIS_HOST = _env('REDIS_HOST', 'redis')
|
|
||||||
REDIS_PORT = int(_env('REDIS_PORT', 6379))
|
|
||||||
|
|
||||||
SUCCESS_FILE = '/tmp/last_success' # noqa: S108
|
|
||||||
|
|
||||||
|
|
||||||
def touch_success_file():
|
def touch_success_file():
|
||||||
"""Updates the timestamp of the success file for healthchecks."""
|
"""Updates the timestamp of the success file for healthchecks."""
|
||||||
@@ -45,19 +30,18 @@ def touch_success_file():
|
|||||||
with open(SUCCESS_FILE, 'w') as f:
|
with open(SUCCESS_FILE, 'w') as f:
|
||||||
f.write(str(datetime.now().timestamp()))
|
f.write(str(datetime.now().timestamp()))
|
||||||
except Exception as e:
|
except Exception as e:
|
||||||
logger.error(f'Failed to touch success file: {e}')
|
logger.error(f"Failed to touch success file: {e}")
|
||||||
|
|
||||||
|
|
||||||
def main():
|
def main():
|
||||||
logger.info('Starting Session Keeper Bot')
|
logger.info("Starting Session Keeper Bot")
|
||||||
|
|
||||||
# Connect to Redis
|
# Connect to Redis
|
||||||
try:
|
try:
|
||||||
redis_client = redis.Redis(host=REDIS_HOST, port=REDIS_PORT, decode_responses=True)
|
redis_client = redis.Redis(host=REDIS_HOST, port=REDIS_PORT, decode_responses=True)
|
||||||
redis_client.ping()
|
redis_client.ping()
|
||||||
logger.info(f'Connected to Redis at {REDIS_HOST}:{REDIS_PORT}')
|
logger.info(f"Connected to Redis at {REDIS_HOST}:{REDIS_PORT}")
|
||||||
except Exception as e:
|
except Exception as e:
|
||||||
logger.error(f'Failed to connect to Redis: {e}')
|
logger.error(f"Failed to connect to Redis: {e}")
|
||||||
return
|
return
|
||||||
|
|
||||||
session = requests.Session()
|
session = requests.Session()
|
||||||
@@ -77,16 +61,19 @@ def main():
|
|||||||
'Sec-Ch-Ua-Mobile': '?0',
|
'Sec-Ch-Ua-Mobile': '?0',
|
||||||
'Sec-Ch-Ua-Platform': '"Linux"',
|
'Sec-Ch-Ua-Platform': '"Linux"',
|
||||||
'Accept-Encoding': 'gzip, deflate, br',
|
'Accept-Encoding': 'gzip, deflate, br',
|
||||||
'Priority': 'u=0, i',
|
'Priority': 'u=0, i'
|
||||||
}
|
}
|
||||||
session.headers.update(headers)
|
session.headers.update(headers)
|
||||||
|
|
||||||
while True:
|
while True:
|
||||||
try:
|
try:
|
||||||
logger.info('Attempting login...')
|
logger.info("Attempting login...")
|
||||||
|
|
||||||
# Login payload
|
# Login payload
|
||||||
payload = {'login': LOGIN, 'password': PASSWORD}
|
payload = {
|
||||||
|
'login': LOGIN,
|
||||||
|
'password': PASSWORD
|
||||||
|
}
|
||||||
|
|
||||||
# Perform Login
|
# Perform Login
|
||||||
# Note: The user request shows a POST to /user/login with form data
|
# Note: The user request shows a POST to /user/login with form data
|
||||||
@@ -95,17 +82,17 @@ def main():
|
|||||||
|
|
||||||
login_response = session.post(URL_LOGIN, data=payload, allow_redirects=True)
|
login_response = session.post(URL_LOGIN, data=payload, allow_redirects=True)
|
||||||
|
|
||||||
logger.info(f'Login Response Status: {login_response.status_code}')
|
logger.info(f"Login Response Status: {login_response.status_code}")
|
||||||
logger.info(f'Cookies after login: {session.cookies.get_dict()}')
|
logger.info(f"Cookies after login: {session.cookies.get_dict()}")
|
||||||
|
|
||||||
# Verify Session
|
# Verify Session
|
||||||
logger.info('Verifying session...')
|
logger.info("Verifying session...")
|
||||||
verify_response = session.get(URL_VERIFY, allow_redirects=False)
|
verify_response = session.get(URL_VERIFY, allow_redirects=False)
|
||||||
|
|
||||||
logger.info(f'Verify Response Status: {verify_response.status_code}')
|
logger.info(f"Verify Response Status: {verify_response.status_code}")
|
||||||
|
|
||||||
if verify_response.status_code == 200:
|
if verify_response.status_code == 200:
|
||||||
logger.info('Session verification SUCCESS (200 OK).')
|
logger.info("Session verification SUCCESS (200 OK).")
|
||||||
touch_success_file()
|
touch_success_file()
|
||||||
|
|
||||||
# Save PHPSESSID to Redis
|
# Save PHPSESSID to Redis
|
||||||
@@ -113,20 +100,19 @@ def main():
|
|||||||
if phpsessid:
|
if phpsessid:
|
||||||
try:
|
try:
|
||||||
redis_client.set('EDU_PHPSESSID', phpsessid)
|
redis_client.set('EDU_PHPSESSID', phpsessid)
|
||||||
logger.info(f'Saved PHPSESSID to Redis: {phpsessid}')
|
logger.info(f"Saved PHPSESSID to Redis: {phpsessid}")
|
||||||
except Exception as e:
|
except Exception as e:
|
||||||
logger.error(f'Failed to save PHPSESSID to Redis: {e}')
|
logger.error(f"Failed to save PHPSESSID to Redis: {e}")
|
||||||
elif verify_response.status_code == 302:
|
elif verify_response.status_code == 302:
|
||||||
logger.warning('Session verification FAILED (302 Redirect). Session might be invalid.')
|
logger.warning("Session verification FAILED (302 Redirect). Session might be invalid.")
|
||||||
else:
|
else:
|
||||||
logger.warning(f'Session verification returned unexpected status: {verify_response.status_code}')
|
logger.warning(f"Session verification returned unexpected status: {verify_response.status_code}")
|
||||||
|
|
||||||
except Exception as e:
|
except Exception as e:
|
||||||
logger.error(f'An error occurred: {e}')
|
logger.error(f"An error occurred: {e}")
|
||||||
|
|
||||||
logger.info(f'Sleeping for {INTERVAL} minutes...')
|
logger.info(f"Sleeping for {INTERVAL} minutes...")
|
||||||
time.sleep(INTERVAL * 60)
|
time.sleep(INTERVAL * 60)
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
if __name__ == '__main__':
|
|
||||||
main()
|
main()
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ FROM python:3.11-slim
|
|||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
# Install dependencies
|
# Install dependencies
|
||||||
RUN pip install --no-cache-dir pip==25.0.1 && pip install --no-cache-dir playwright==1.56.0 redis==5.2.1 requests==2.32.3 "python-telegram-bot[job-queue]==21.10"
|
RUN pip install --upgrade pip && pip install playwright==1.56.0 redis requests "python-telegram-bot[job-queue]"
|
||||||
|
|
||||||
COPY checker.py .
|
COPY checker.py .
|
||||||
|
|
||||||
|
|||||||
+235
-1334
File diff suppressed because it is too large
Load Diff
@@ -1,5 +0,0 @@
|
|||||||
FROM nginx:alpine
|
|
||||||
RUN rm -rf /usr/share/nginx/html/*
|
|
||||||
COPY html /usr/share/nginx/html
|
|
||||||
EXPOSE 80
|
|
||||||
CMD ["nginx", "-g", "daemon off;"]
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
services:
|
|
||||||
errorpage:
|
|
||||||
build: .
|
|
||||||
image: gcr.forust.xyz/forust/error-pages:latest
|
|
||||||
pull_policy: build
|
|
||||||
container_name: error-pages
|
|
||||||
restart: unless-stopped
|
|
||||||
# ports:
|
|
||||||
# - 1234:80
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.error-pages.loadbalancer.server.port=80"
|
|
||||||
# Error handler middleware
|
|
||||||
- "traefik.http.middlewares.error-pages.errors.status=400,402-599"
|
|
||||||
- "traefik.http.middlewares.error-pages.errors.service=error-pages"
|
|
||||||
- "traefik.http.middlewares.error-pages.errors.query=/{status}.html"
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
@@ -1,208 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>403 // Forbidden</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="403">403</h1>
|
|
||||||
<p class="subtitle">> Forbidden / Access Denied.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>You do not have permission to access this resource.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> if you believe this is an
|
|
||||||
error.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ sudo access_resource</p>
|
|
||||||
<p>User is not in the sudoers file. This incident will be reported.</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>404 // Not Found</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="404">404</h1>
|
|
||||||
<p class="subtitle">> Page Not Found / Lost in the Void.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>The page you are looking for does not exist or has been moved.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> if you believe this is an error.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ ping target</p>
|
|
||||||
<p>Destination Host Unreachable</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>500 // Server Error</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="500">500</h1>
|
|
||||||
<p class="subtitle">> Internal Server Error / System Failure.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>Something went wrong on our end. We are working to fix it.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ systemctl status service</p>
|
|
||||||
<p>Active: failed (Result: core-dump)</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>502 // Bad Gateway</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="502">502</h1>
|
|
||||||
<p class="subtitle">> Bad Gateway / System Failure.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>The server received an invalid response from the upstream server.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ curl -I upstream_host</p>
|
|
||||||
<p>HTTP/1.1 502 Bad Gateway</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>503 // Service Unavailable</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="503">503</h1>
|
|
||||||
<p class="subtitle">> Service Unavailable / System Failure.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>The server is currently unable to handle the request due to maintenance or overload.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ systemctl start service</p>
|
|
||||||
<p>Job for service failed because the control process exited with error code.</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>504 // Gateway Timeout</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="504">504</h1>
|
|
||||||
<p class="subtitle">> Gateway Timeout / System Failure.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>The server did not receive a timely response from the upstream server.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ timeout 30s curl upstream</p>
|
|
||||||
<p>curl: (28) Operation timed out after 30001 milliseconds with 0 bytes received</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: error-pages-service
|
|
||||||
namespace: error-pages
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: error-pages
|
|
||||||
ports:
|
|
||||||
- port: 80
|
|
||||||
targetPort: 80
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: error-pages-deployment
|
|
||||||
namespace: error-pages
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: error-pages
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: error-pages
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: error-pages
|
|
||||||
image: gcr.forust.xyz/forust/error-pages:latest
|
|
||||||
ports:
|
|
||||||
- containerPort: 80
|
|
||||||
---
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: error-pages
|
|
||||||
@@ -1,6 +1,3 @@
|
|||||||
GITEA_POSTGRES_USER=
|
GITEA_POSTGRES_USER=
|
||||||
GITEA_POSTGRES_PASSWORD=
|
GITEA_POSTGRES_PASSWORD=
|
||||||
GITEA_POSTGRES_DB=gitea
|
GITEA_POSTGRES_DB=gitea
|
||||||
GITEA_SMTP_PASS=
|
|
||||||
MAILER_ADDR=
|
|
||||||
SERVICE_EMAIL=email.used.by.services@domain.tld
|
|
||||||
+22
-29
@@ -1,8 +1,7 @@
|
|||||||
services:
|
services:
|
||||||
server:
|
server:
|
||||||
image: docker.gitea.com/gitea:1.26
|
image: docker.gitea.com/gitea:1.25.1
|
||||||
container_name: gitea
|
container_name: gitea
|
||||||
restart: always
|
|
||||||
environment:
|
environment:
|
||||||
- USER_UID=1000
|
- USER_UID=1000
|
||||||
- USER_GID=1000
|
- USER_GID=1000
|
||||||
@@ -14,52 +13,45 @@ services:
|
|||||||
- GITEA__database__NAME=gitea
|
- GITEA__database__NAME=gitea
|
||||||
#Server
|
#Server
|
||||||
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
||||||
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
|
|
||||||
- GITEA__server__SSH_PORT=2221
|
- GITEA__server__SSH_PORT=2221
|
||||||
# Mailer
|
restart: always
|
||||||
- GITEA__mailer__ENABLED=true
|
networks:
|
||||||
- GITEA__mailer__FROM=${SERVICE_EMAIL}
|
- gitea-db
|
||||||
- GITEA__mailer__SMTP_ADDR=${MAILER_ADDR}:465
|
- traefik-proxy
|
||||||
- GITEA__mailer__USER=${SERVICE_EMAIL}
|
|
||||||
- GITEA__mailer__PASSWD=${GITEA_SMTP_PASS}
|
|
||||||
- GITEA__mailer__PROTOCOL=SMTP
|
|
||||||
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
|
|
||||||
- GITEA__service__ENABLE_NOTIFY_MAIL=true
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./gitea-data:/data
|
- ./gitea-data:/data
|
||||||
- /etc/timezone:/etc/timezone:ro
|
- /etc/timezone:/etc/timezone:ro
|
||||||
- /etc/localtime:/etc/localtime:ro
|
- /etc/localtime:/etc/localtime:ro
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
- "traefik.docker.network=traefik-proxy"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
||||||
- "traefik.http.routers.gitea.entrypoints=websecure"
|
- "traefik.http.routers.gitea.entrypoints=websecure"
|
||||||
- "traefik.http.routers.gitea.tls.certresolver"
|
- "traefik.http.routers.gitea.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.gitea.service=gitea"
|
||||||
|
- "traefik.http.routers.gitea.tls=true"
|
||||||
|
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`)"
|
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`) || Host(`gitea.internal`)"
|
||||||
- "traefik.http.routers.gitea-local.entrypoints=websecure"
|
- "traefik.http.routers.gitea-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.gitea-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.gitea-local.service=gitea"
|
||||||
- "traefik.http.routers.gitea-local.tls=true"
|
- "traefik.http.routers.gitea-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
|
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
|
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.gitea-dev.service=gitea"
|
||||||
- "traefik.http.routers.gitea-dev.tls=true"
|
- "traefik.http.routers.gitea-dev.tls=true"
|
||||||
# SSH Router
|
|
||||||
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
|
||||||
- "traefik.tcp.routers.gitea.entrypoints=ssh"
|
|
||||||
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
|
|
||||||
# Gitea container registry Router
|
|
||||||
- "traefik.http.routers.gitea-registry.rule=Host(`gcr.forust.xyz`) && PathPrefix(`/v2`)"
|
|
||||||
- "traefik.http.routers.gitea-registry.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.gitea-registry.tls.certresolver=letsencrypt"
|
|
||||||
ports:
|
ports:
|
||||||
- "2221:22"
|
- "2221:22"
|
||||||
networks:
|
|
||||||
- gitea-db
|
|
||||||
- proxy
|
|
||||||
depends_on:
|
depends_on:
|
||||||
- db
|
- db
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: docker.io/library/postgres:14
|
image: docker.io/library/postgres:14
|
||||||
restart: always
|
restart: always
|
||||||
@@ -67,12 +59,13 @@ services:
|
|||||||
- POSTGRES_USER=gitea
|
- POSTGRES_USER=gitea
|
||||||
- POSTGRES_PASSWORD=gitea
|
- POSTGRES_PASSWORD=gitea
|
||||||
- POSTGRES_DB=gitea
|
- POSTGRES_DB=gitea
|
||||||
volumes:
|
|
||||||
- ./gitea-db/:/var/lib/postgresql/data
|
|
||||||
networks:
|
networks:
|
||||||
- gitea-db
|
- gitea-db
|
||||||
|
volumes:
|
||||||
|
- ./gitea-db/:/var/lib/postgresql/data
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
gitea-db:
|
gitea-db:
|
||||||
external: false
|
external: false
|
||||||
proxy:
|
traefik-proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1,22 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: gitea-config
|
|
||||||
namespace: gitea
|
|
||||||
data:
|
|
||||||
GITEA__server__DOMAIN: "gitea.forust.xyz"
|
|
||||||
GITEA__server__ROOT_URL: "https://gitea.forust.xyz"
|
|
||||||
GITEA__server__SSH_DOMAIN: "gitssh.forust.xyz"
|
|
||||||
GITEA__server__SSH_PORT: "2221"
|
|
||||||
|
|
||||||
GITEA__database__DB_TYPE: "postgres"
|
|
||||||
GITEA__database__HOST: "gitea-postgres-service:5432"
|
|
||||||
GITEA__database__NAME: "gitea"
|
|
||||||
GITEA__security__REVERSE_PROXY_LIMIT: "1"
|
|
||||||
GITEA__security__REVERSE_PROXY_TRUSTED_PROXIES: "*"
|
|
||||||
|
|
||||||
GITEA__mailer__ENABLED: "false"
|
|
||||||
|
|
||||||
GITEA__log__logger__access__MODE: "console, file"
|
|
||||||
USER_UID: "1000"
|
|
||||||
USER_GID: "1000"
|
|
||||||
@@ -1,71 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: gitea-service
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: gitea
|
|
||||||
ports:
|
|
||||||
- port: 3000
|
|
||||||
name: http
|
|
||||||
targetPort: 3000
|
|
||||||
- port: 2221
|
|
||||||
name: ssh
|
|
||||||
targetPort: 22
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: gitea-deployment
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: gitea
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: gitea
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: gitea
|
|
||||||
image: docker.gitea.com/gitea:1.26
|
|
||||||
envFrom:
|
|
||||||
- configMapRef:
|
|
||||||
name: gitea-config
|
|
||||||
- secretRef:
|
|
||||||
name: gitea-secrets
|
|
||||||
ports:
|
|
||||||
- containerPort: 3000
|
|
||||||
name: http
|
|
||||||
- containerPort: 2221
|
|
||||||
name: ssh
|
|
||||||
volumeMounts:
|
|
||||||
- name: gitea-data
|
|
||||||
mountPath: /data
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "512Mi"
|
|
||||||
cpu: "300m"
|
|
||||||
limits:
|
|
||||||
memory: "1.5Gi"
|
|
||||||
cpu: "1300m"
|
|
||||||
volumes:
|
|
||||||
- name: gitea-data
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: gitea-pvc
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: gitea-pvc
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 5Gi
|
|
||||||
---
|
|
||||||
@@ -1,55 +0,0 @@
|
|||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: gitea-prod
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`gitea.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: gitea-service
|
|
||||||
port: 3000
|
|
||||||
- match: Host(`gcr.forust.xyz`) && PathPrefix(`/v2`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: gitea-service
|
|
||||||
port: 3000
|
|
||||||
tls:
|
|
||||||
certResolver: letsencrypt
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: gitea-local
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`gitea.workstation.internal`) || Host(`gitea.gigaforust.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: gitea-service
|
|
||||||
port: 3000
|
|
||||||
- match: (Host(`gcr.workstation.internal`) || Host(`gcr.gigaforust.internal`)) && PathPrefix(`/v2`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: gitea-service
|
|
||||||
port: 3000
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRouteTCP
|
|
||||||
metadata:
|
|
||||||
name: gitea-ssh
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- ssh
|
|
||||||
routes:
|
|
||||||
- match: HostSNI(`*`)
|
|
||||||
services:
|
|
||||||
- name: gitea-service
|
|
||||||
port: 2221
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: gitea
|
|
||||||
@@ -1,62 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: gitea-postgres-service
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
clusterIP: None
|
|
||||||
selector:
|
|
||||||
app: gitea-postgres
|
|
||||||
ports:
|
|
||||||
- port: 5432
|
|
||||||
targetPort: 5432
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: StatefulSet
|
|
||||||
metadata:
|
|
||||||
name: gitea-postgres-statefulset
|
|
||||||
namespace: gitea
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: gitea-postgres
|
|
||||||
serviceName: gitea-postgres-service
|
|
||||||
replicas: 1
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: gitea-postgres
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: gitea-postgres
|
|
||||||
image: postgres:14
|
|
||||||
env:
|
|
||||||
- name: POSTGRES_USER
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: gitea-secrets
|
|
||||||
key: GITEA__database__USER
|
|
||||||
- name: POSTGRES_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: gitea-secrets
|
|
||||||
key: GITEA__database__PASSWD
|
|
||||||
- name: POSTGRES_DB
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: gitea-secrets
|
|
||||||
key: GITEA__database__USER
|
|
||||||
ports:
|
|
||||||
- containerPort: 5432
|
|
||||||
name: postgres
|
|
||||||
volumeMounts:
|
|
||||||
- name: postgres-data
|
|
||||||
mountPath: /var/lib/postgresql/data
|
|
||||||
volumeClaimTemplates:
|
|
||||||
- metadata:
|
|
||||||
name: postgres-data
|
|
||||||
spec:
|
|
||||||
accessModes: ["ReadWriteOnce"]
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 1Gi
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: gitea-secrets
|
|
||||||
namespace: gitea
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
GITEA__database__USER: "gitea"
|
|
||||||
GITEA__database__PASSWD: "gitea"
|
|
||||||
+15
-11
@@ -11,26 +11,30 @@ services:
|
|||||||
env_file: .env
|
env_file: .env
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=traefik-proxy"
|
||||||
- "traefik.services.glance.loadbalancer.server.port=8080"
|
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.glance.rule=(Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/glance`)"
|
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
|
||||||
- "traefik.http.routers.glance.entrypoints=websecure"
|
- "traefik.http.routers.glance.entrypoints=websecure"
|
||||||
- "traefik.http.routers.glance.priority=50"
|
- "traefik.http.routers.glance.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.glance.tls.certresolver=letsencrypt"
|
- "traefik.http.routers.glance.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.glance-local.rule=Host(`workstation.internal`) && PathPrefix(`/glance`)"
|
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`) || Host(`glance.internal`)"
|
||||||
- "traefik.http.routers.glance-local.entrypoints=websecure"
|
- "traefik.http.routers.glance-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.glance-local.priority=50"
|
- "traefik.http.routers.glance-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.glance-local.tls=true"
|
- "traefik.http.routers.glance-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.glance-dev.rule=Host(`gigaforust.internal`) && PathPrefix(`/glance`)"
|
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.glance-dev.priority=50"
|
- "traefik.http.routers.glance-dev.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.glance-dev.tls=true"
|
- "traefik.http.routers.glance-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- traefik-proxy
|
||||||
|
dns:
|
||||||
|
- 1.1.1.1
|
||||||
|
- 8.8.8.8
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
traefik-proxy:
|
||||||
external: true
|
external: true
|
||||||
@@ -65,6 +65,7 @@
|
|||||||
- symbol: MSFT
|
- symbol: MSFT
|
||||||
name: Microsoft
|
name: Microsoft
|
||||||
|
|
||||||
|
|
||||||
- type: releases
|
- type: releases
|
||||||
cache: 1d
|
cache: 1d
|
||||||
# Without authentication the Github API allows for up to 60 requests per hour. You can create a
|
# Without authentication the Github API allows for up to 60 requests per hour. You can create a
|
||||||
|
|||||||
@@ -11,3 +11,5 @@
|
|||||||
widgets:
|
widgets:
|
||||||
- type: docker-containers
|
- type: docker-containers
|
||||||
hide-by-default: false
|
hide-by-default: false
|
||||||
|
|
||||||
|
|
||||||
@@ -1,211 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: glance-assets
|
|
||||||
namespace: glance
|
|
||||||
data:
|
|
||||||
# Инжектируем твой брутализм напрямую в ассеты
|
|
||||||
user.css: |
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Принудительно ставим моноширинный шрифт для всего дашборда */
|
|
||||||
body, id, main, div, span, p, a, h1, h2, h3 {
|
|
||||||
font-family: var(--font-mono) !important;
|
|
||||||
letter-spacing: -0.5px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Ломаем закругления Glance и делаем жесткие рамки */
|
|
||||||
.widget, .card, main div, [class*="widget"], [class*="card"] {
|
|
||||||
border-radius: 0px !important;
|
|
||||||
border: 1px solid var(--dim) !important;
|
|
||||||
box-shadow: none !important;
|
|
||||||
background-color: var(--bg-color) !important;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Стилизация ссылок под ховер-эффект из твоего style.css */
|
|
||||||
a {
|
|
||||||
color: var(--text-color) !important;
|
|
||||||
text-decoration: none !important;
|
|
||||||
border-bottom: 1px solid var(--dim) !important;
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color) !important;
|
|
||||||
color: var(--bg-color) !important;
|
|
||||||
border-color: var(--text-color) !important;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Кастомизация заголовков внутри модулей */
|
|
||||||
h2, .widget-title, [class*="title"] {
|
|
||||||
text-transform: uppercase;
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: glance-config
|
|
||||||
namespace: glance
|
|
||||||
data:
|
|
||||||
glance.yml: |
|
|
||||||
server:
|
|
||||||
assets-path: /app/assets
|
|
||||||
proxied: true
|
|
||||||
base-url: /glance
|
|
||||||
theme:
|
|
||||||
# Перевели #050505 и #e0e0e0 в формат HSL для Glance
|
|
||||||
background-color: 0 0 2 # Истинно черный фон
|
|
||||||
primary-color: 0 0 88 # Светло-серый текст
|
|
||||||
contrast-multiplier: 1.4
|
|
||||||
positive-color: 140 50 50 # Зеленый для UP-сервисов (не вырвиглазный)
|
|
||||||
negative-color: 0 70 50 # Красный для упавших сайтов
|
|
||||||
custom-css-file: /assets/user.css
|
|
||||||
pages:
|
|
||||||
- $include: home.yml
|
|
||||||
- $include: docker.yml
|
|
||||||
- $include: monitor.yml
|
|
||||||
|
|
||||||
home.yml: |
|
|
||||||
- name: Home
|
|
||||||
columns:
|
|
||||||
- size: small
|
|
||||||
widgets:
|
|
||||||
- type: clock
|
|
||||||
hour-format: 24h
|
|
||||||
timezones:
|
|
||||||
- timezone: Europe/Bratislava
|
|
||||||
label: Bratislava
|
|
||||||
- timezone: Europe/Kyiv
|
|
||||||
label: Kyiv
|
|
||||||
- timezone: Europe/Moscow
|
|
||||||
label: St. Petersburg
|
|
||||||
- type: calendar
|
|
||||||
first-day-of-week: monday
|
|
||||||
- type: rss
|
|
||||||
limit: 10
|
|
||||||
collapse-after: 3
|
|
||||||
cache: 12h
|
|
||||||
feeds:
|
|
||||||
- url: https://selfh.st/rss/
|
|
||||||
title: selfh.st
|
|
||||||
- size: full
|
|
||||||
widgets:
|
|
||||||
- type: group
|
|
||||||
widgets:
|
|
||||||
- type: hacker-news
|
|
||||||
- type: lobsters
|
|
||||||
- type: videos
|
|
||||||
channels:
|
|
||||||
- UCXuqSBlHAE6Xw-yeJA0Tunw
|
|
||||||
- UCR-DXc1voovS8nhAvccRZhg
|
|
||||||
- UCsBjURrPoezykLs9EqgamOA
|
|
||||||
- UCBJycsmduvYEL83R_U4JriQ
|
|
||||||
- UCHnyfMqiRRG1u-2MsSQLbXA
|
|
||||||
- type: group
|
|
||||||
widgets:
|
|
||||||
- type: reddit
|
|
||||||
subreddit: technology
|
|
||||||
show-thumbnails: true
|
|
||||||
- type: reddit
|
|
||||||
subreddit: selfhosted
|
|
||||||
show-thumbnails: true
|
|
||||||
- size: small
|
|
||||||
widgets:
|
|
||||||
- type: weather
|
|
||||||
location: London, United Kingdom
|
|
||||||
units: metric
|
|
||||||
hour-format: 12h
|
|
||||||
hide-location: true
|
|
||||||
- type: markets
|
|
||||||
markets:
|
|
||||||
- symbol: SPY
|
|
||||||
name: S&P 500
|
|
||||||
- symbol: BTC-USD
|
|
||||||
name: Bitcoin
|
|
||||||
- symbol: NVDA
|
|
||||||
name: NVIDIA
|
|
||||||
- symbol: AAPL
|
|
||||||
name: Apple
|
|
||||||
- symbol: MSFT
|
|
||||||
name: Microsoft
|
|
||||||
- type: releases
|
|
||||||
cache: 1d
|
|
||||||
repositories:
|
|
||||||
- glanceapp/glance
|
|
||||||
- go-gitea/gitea
|
|
||||||
- nextcloud/all-in-one
|
|
||||||
|
|
||||||
docker.yml: |
|
|
||||||
- name: Docker
|
|
||||||
columns:
|
|
||||||
- size: full
|
|
||||||
widgets:
|
|
||||||
- type: docker-containers
|
|
||||||
hide-by-default: false
|
|
||||||
|
|
||||||
monitor.yml: |
|
|
||||||
- name: Monitoring
|
|
||||||
columns:
|
|
||||||
- size: small
|
|
||||||
widgets:
|
|
||||||
- type: dns-stats
|
|
||||||
service: adguard
|
|
||||||
url: http://adguard-service.adguard.svc.cluster.local:3000
|
|
||||||
username: forust
|
|
||||||
password: ${ADGUARD_PASSWORD}
|
|
||||||
- size: full
|
|
||||||
widgets:
|
|
||||||
- type: monitor
|
|
||||||
title: Services Status
|
|
||||||
cache: 1m
|
|
||||||
sites:
|
|
||||||
- title: forust.xyz
|
|
||||||
url: https://forust.xyz
|
|
||||||
- title: dns.forust.xyz
|
|
||||||
url: https://dns.forust.xyz
|
|
||||||
- title: www.lk-tour.com.ua
|
|
||||||
url: https://www.lk-tour.com.ua
|
|
||||||
- title: lk-tour.com.ua
|
|
||||||
url: https://lk-tour.com.ua
|
|
||||||
# - title: gitssh.forust.xyz
|
|
||||||
# url: https://gitssh.forust.xyz
|
|
||||||
# - title: gcr.forust.xyz
|
|
||||||
# url: https://gcr.forust.xyz/v2/
|
|
||||||
- title: gitea.forust.xyz
|
|
||||||
url: https://gitea.forust.xyz
|
|
||||||
- title: nextcloud.forust.xyz
|
|
||||||
url: https://nextcloud.forust.xyz
|
|
||||||
- title: mc.forust.xyz
|
|
||||||
url: https://mc.forust.xyz/map
|
|
||||||
- title: auth.forust.xyz
|
|
||||||
url: https://auth.forust.xyz
|
|
||||||
- title: metube.forust.xyz
|
|
||||||
url: https://metube.forust.xyz
|
|
||||||
- title: dockmon.forust.xyz
|
|
||||||
url: https://dockmon.forust.xyz
|
|
||||||
- title: portainer.forust.xyz
|
|
||||||
url: https://portainer.forust.xyz
|
|
||||||
- title: termix.forust.xyz
|
|
||||||
url: https://termix.forust.xyz
|
|
||||||
- title: uptime.forust.xyz
|
|
||||||
url: https://uptime.forust.xyz
|
|
||||||
- title: cmk.forust.xyz
|
|
||||||
url: https://cmk.forust.xyz
|
|
||||||
- title: search.forust.xyz
|
|
||||||
url: https://search.forust.xyz
|
|
||||||
- title: status.forust.xyz
|
|
||||||
url: https://status.forust.xyz
|
|
||||||
- title: traefik.forust.xyz
|
|
||||||
url: https://traefik.forust.xyz
|
|
||||||
- title: media.forust.xyz
|
|
||||||
url: https://media.forust.xyz
|
|
||||||
- title: wfs.forust.xyz
|
|
||||||
url: https://wfs.forust.xyz
|
|
||||||
- title: forust.xyz/convert
|
|
||||||
url: https://forust.xyz/convert
|
|
||||||
@@ -1,78 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: glance-service
|
|
||||||
namespace: glance
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: glance
|
|
||||||
ports:
|
|
||||||
- port: 8080
|
|
||||||
targetPort: 8080
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: glance-deployment
|
|
||||||
namespace: glance
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: glance
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: glance
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: glance
|
|
||||||
image: glanceapp/glance
|
|
||||||
envFrom:
|
|
||||||
- secretRef:
|
|
||||||
name: glance-secrets
|
|
||||||
ports:
|
|
||||||
- containerPort: 8080
|
|
||||||
volumeMounts:
|
|
||||||
- name: glance-config
|
|
||||||
mountPath: /app/config/glance.yml
|
|
||||||
subPath: glance.yml
|
|
||||||
- name: glance-config
|
|
||||||
mountPath: /app/config/home.yml
|
|
||||||
subPath: home.yml
|
|
||||||
- name: glance-config
|
|
||||||
mountPath: /app/config/docker.yml
|
|
||||||
subPath: docker.yml
|
|
||||||
- name: glance-config
|
|
||||||
mountPath: /app/config/monitor.yml
|
|
||||||
subPath: monitor.yml
|
|
||||||
- name: glance-assets
|
|
||||||
mountPath: /app/assets/user.css
|
|
||||||
subPath: user.css
|
|
||||||
- name: docker-socket
|
|
||||||
mountPath: /var/run/docker.sock
|
|
||||||
- name: localtime
|
|
||||||
mountPath: /etc/localtime
|
|
||||||
readOnly: true
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "30Mi"
|
|
||||||
cpu: "20m"
|
|
||||||
limits:
|
|
||||||
memory: "100Mi"
|
|
||||||
cpu: "50m"
|
|
||||||
volumes:
|
|
||||||
- name: glance-config
|
|
||||||
configMap:
|
|
||||||
name: glance-config
|
|
||||||
- name: glance-assets
|
|
||||||
configMap:
|
|
||||||
name: glance-config
|
|
||||||
- name: docker-socket
|
|
||||||
hostPath:
|
|
||||||
path: /var/run/docker.sock
|
|
||||||
type: Socket
|
|
||||||
- name: localtime
|
|
||||||
hostPath:
|
|
||||||
path: /etc/localtime
|
|
||||||
type: File
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user