Compare commits
8
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
51e22b61bf | ||
|
|
cc9c3dea88 | ||
|
|
815cd85b9a | ||
|
|
9021eddbc3 | ||
|
|
2adf17c307 | ||
|
|
1add5b5cd7 | ||
|
|
34f10211ab | ||
|
|
02447f2946 |
No files matched your search
@@ -0,0 +1,4 @@
|
|||||||
|
SECRET_ENCRYPTION_KEY="REPLACE_ME"
|
||||||
|
TZ="Europe/Bratislava"
|
||||||
|
PUID="1000"
|
||||||
|
PGID="1000"
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
services:
|
||||||
|
homarr:
|
||||||
|
container_name: homarr
|
||||||
|
image: ghcr.io/homarr-labs/homarr:v2.1.2
|
||||||
|
restart: unless-stopped
|
||||||
|
volumes:
|
||||||
|
- ./appdata:/appdata
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
|
- ./kubeconfig:/app/config/kubeconfig:ro
|
||||||
|
env_file: .env
|
||||||
|
ports:
|
||||||
|
- 80:7575
|
||||||
|
- 81:3000
|
||||||
|
environment:
|
||||||
|
- TZ=${TZ:-Europe/Bratislava}
|
||||||
|
- TURBO_TELEMETRY_DISABLED=1
|
||||||
|
- KUBECONFIG=/app/config/kubeconfig
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.services.homarr.loadbalancer.server.port=7575"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.homarr.rule=Host(`homarr.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.homarr.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.homarr.tls.certresolver=letsencrypt"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.homarr-local.rule=Host(`homarr.workstation.internal`)"
|
||||||
|
- "traefik.http.routers.homarr-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.homarr-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.homarr-dev.rule=Host(`homarr.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.homarr-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.homarr-dev.tls=true"
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
networks:
|
||||||
|
proxy:
|
||||||
|
external: true
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
# apiVersion: cert-manager.io/v1
|
||||||
|
# kind: Certificate
|
||||||
|
# metadata:
|
||||||
|
# name: home-prod-tls
|
||||||
|
# namespace: homarr
|
||||||
|
# spec:
|
||||||
|
# secretName: home-prod-tls
|
||||||
|
# dnsNames:
|
||||||
|
# - home.forust.xyz
|
||||||
|
# issuerRef:
|
||||||
|
# name: letsencrypt-prod
|
||||||
|
# kind: ClusterIssuer
|
||||||
|
# ---
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: internal-wildcard-tls
|
||||||
|
namespace: homarr
|
||||||
|
spec:
|
||||||
|
secretName: internal-wildcard-tls
|
||||||
|
dnsNames:
|
||||||
|
- "*.workstation.internal"
|
||||||
|
- "*.gigaforust.internal"
|
||||||
|
- workstation.internal
|
||||||
|
- gigaforust.internal
|
||||||
|
issuerRef:
|
||||||
|
name: internal-ca
|
||||||
|
kind: ClusterIssuer
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: homarr-config
|
||||||
|
namespace: homarr
|
||||||
|
data:
|
||||||
|
TZ: "Europe/Bratislava"
|
||||||
|
TURBO_TELEMETRY_DISABLED: "1"
|
||||||
|
ENABLE_KUBERNETES: "true"
|
||||||
@@ -0,0 +1,81 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: homarr-service
|
||||||
|
namespace: homarr
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: homarr
|
||||||
|
ports:
|
||||||
|
- port: 7575
|
||||||
|
targetPort: 7575
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: homarr-deployment
|
||||||
|
namespace: homarr
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: homarr
|
||||||
|
strategy:
|
||||||
|
type: Recreate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: homarr
|
||||||
|
spec:
|
||||||
|
serviceAccountName: homarr
|
||||||
|
containers:
|
||||||
|
- name: homarr
|
||||||
|
image: ghcr.io/homarr-labs/homarr:v2.1.2
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: homarr-config
|
||||||
|
- secretRef:
|
||||||
|
name: homarr-secrets
|
||||||
|
ports:
|
||||||
|
- containerPort: 7575
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: 7575
|
||||||
|
initialDelaySeconds: 30
|
||||||
|
periodSeconds: 10
|
||||||
|
failureThreshold: 6
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: 7575
|
||||||
|
initialDelaySeconds: 60
|
||||||
|
periodSeconds: 30
|
||||||
|
failureThreshold: 3
|
||||||
|
volumeMounts:
|
||||||
|
- name: homarr-data
|
||||||
|
mountPath: /appdata
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: "250m"
|
||||||
|
memory: "350Mi"
|
||||||
|
limits:
|
||||||
|
cpu: "500m"
|
||||||
|
memory: "700Mi"
|
||||||
|
volumes:
|
||||||
|
- name: homarr-data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: homarr-pvc
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: homarr-pvc
|
||||||
|
namespace: homarr
|
||||||
|
spec:
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 2Gi
|
||||||
|
volumeMode: Filesystem
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
# apiVersion: traefik.io/v1alpha1
|
||||||
|
# kind: IngressRoute
|
||||||
|
# metadata:
|
||||||
|
# name: homarr-prod
|
||||||
|
# namespace: homarr
|
||||||
|
# spec:
|
||||||
|
# entryPoints:
|
||||||
|
# - websecure
|
||||||
|
# routes:
|
||||||
|
# - match: Host(`home.forust.xyz`)
|
||||||
|
# kind: Rule
|
||||||
|
# services:
|
||||||
|
# - name: homarr-service
|
||||||
|
# port: 7575
|
||||||
|
# tls:
|
||||||
|
# secretName: home-prod-tls
|
||||||
|
# ---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: homarr-local
|
||||||
|
namespace: homarr
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`home.workstation.internal`) || Host(`home.gigaforust.internal`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: homarr-service
|
||||||
|
port: 7575
|
||||||
|
tls:
|
||||||
|
secretName: internal-wildcard-tls
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: homarr
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: homarr
|
||||||
|
namespace: homarr
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: homarr-readonly
|
||||||
|
rules:
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- endpoints
|
||||||
|
- namespaces
|
||||||
|
- nodes
|
||||||
|
- configmaps
|
||||||
|
- persistentvolumeclaims
|
||||||
|
- events
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
- apiGroups: ["apps"]
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
- statefulsets
|
||||||
|
- daemonsets
|
||||||
|
- replicasets
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
- apiGroups: ["networking.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- ingresses
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
- apiGroups: ["traefik.io"]
|
||||||
|
resources:
|
||||||
|
- ingressroutes
|
||||||
|
- ingressroutetcps
|
||||||
|
- ingressrouteudps
|
||||||
|
- middlewares
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
- apiGroups: ["metrics.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- nodes
|
||||||
|
verbs: ["get", "list"]
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: homarr-readonly
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: homarr-readonly
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: homarr
|
||||||
|
namespace: homarr
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: homarr-secrets
|
||||||
|
namespace: homarr
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
# openssl rand -hex 32
|
||||||
|
SECRET_ENCRYPTION_KEY: "REPLACE_ME"
|
||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
services:
|
services:
|
||||||
n8n:
|
n8n:
|
||||||
image: docker.n8n.io/n8nio/n8n:2.42.2
|
image: docker.n8n.io/n8nio/n8n:2.42.3
|
||||||
container_name: n8n
|
container_name: n8n
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
|
|||||||
+1
-1
@@ -29,7 +29,7 @@ spec:
|
|||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: n8n
|
- name: n8n
|
||||||
image: docker.n8n.io/n8nio/n8n:2.42.2
|
image: docker.n8n.io/n8nio/n8n:2.42.3
|
||||||
envFrom:
|
envFrom:
|
||||||
- configMapRef:
|
- configMapRef:
|
||||||
name: n8n-config
|
name: n8n-config
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
POSTGRES_ADMIN_PASSWORD=
|
POSTGRES_ADMIN_PASSWORD=
|
||||||
AUTHENTIK_DB_PASSWORD=
|
AUTHENTIK_DB_PASSWORD=
|
||||||
GITEA_DB_PASSWORD=
|
GITEA_DB_PASSWORD=
|
||||||
|
NETBOX_DB_PASSWORD=
|
||||||
NETRONOME_DB_PASSWORD=
|
NETRONOME_DB_PASSWORD=
|
||||||
PENPOT_DB_PASSWORD=
|
PENPOT_DB_PASSWORD=
|
||||||
STATUSPAGE_DB_PASSWORD=
|
STATUSPAGE_DB_PASSWORD=
|
||||||
@@ -218,6 +218,34 @@ data:
|
|||||||
"matchUpdateTypes": ["patch"],
|
"matchUpdateTypes": ["patch"],
|
||||||
"groupName": "all patch updates",
|
"groupName": "all patch updates",
|
||||||
"groupSlug": "all-patch"
|
"groupSlug": "all-patch"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.",
|
||||||
|
"matchDatasources": ["docker"],
|
||||||
|
"matchPackageNames": ["python"],
|
||||||
|
"groupName": "python base image",
|
||||||
|
"groupSlug": "python",
|
||||||
|
"automerge": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "Rolling/floating tags (streaming stack, nextcloud beta, kubectl latest) - never automerge, every bump is a manual review. Placed last so automerge:false wins over the shared digest/patch rule.",
|
||||||
|
"matchDatasources": ["docker"],
|
||||||
|
"matchPackageNames": [
|
||||||
|
"lscr.io/linuxserver/jellyfin",
|
||||||
|
"lscr.io/linuxserver/qbittorrent",
|
||||||
|
"lscr.io/linuxserver/sonarr",
|
||||||
|
"lscr.io/linuxserver/radarr",
|
||||||
|
"lscr.io/linuxserver/prowlarr",
|
||||||
|
"lscr.io/linuxserver/bazarr",
|
||||||
|
"ghcr.io/seerr-team/seerr",
|
||||||
|
"fallenbagel/jellyseerr",
|
||||||
|
"ghcr.io/lampac-nextgen/lampac",
|
||||||
|
"ghcr.io/nextcloud-releases/all-in-one",
|
||||||
|
"alpine/kubectl"
|
||||||
|
],
|
||||||
|
"groupName": "floating images - manual",
|
||||||
|
"groupSlug": "floating-manual",
|
||||||
|
"automerge": false
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
@@ -19,7 +19,7 @@ spec:
|
|||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
containers:
|
containers:
|
||||||
- name: renovate
|
- name: renovate
|
||||||
image: renovate/renovate:44.132.2
|
image: renovate/renovate:44.136.0
|
||||||
env:
|
env:
|
||||||
- name: RENOVATE_PLATFORM
|
- name: RENOVATE_PLATFORM
|
||||||
value: gitea
|
value: gitea
|
||||||
|
|||||||
@@ -207,6 +207,34 @@
|
|||||||
"matchUpdateTypes": ["patch"],
|
"matchUpdateTypes": ["patch"],
|
||||||
"groupName": "all patch updates",
|
"groupName": "all patch updates",
|
||||||
"groupSlug": "all-patch"
|
"groupSlug": "all-patch"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "Python Y-bumps break compat (3.11->3.12->3.13->3.14) - keep the base image out of the shared minor/patch groups, review every bump separately. Placed last so its groupName wins.",
|
||||||
|
"matchDatasources": ["docker"],
|
||||||
|
"matchPackageNames": ["python"],
|
||||||
|
"groupName": "python base image",
|
||||||
|
"groupSlug": "python",
|
||||||
|
"automerge": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "Rolling/floating tags (streaming stack, nextcloud beta, kubectl latest) - never automerge, every bump is a manual review. Placed last so automerge:false wins over the shared digest/patch rule.",
|
||||||
|
"matchDatasources": ["docker"],
|
||||||
|
"matchPackageNames": [
|
||||||
|
"lscr.io/linuxserver/jellyfin",
|
||||||
|
"lscr.io/linuxserver/qbittorrent",
|
||||||
|
"lscr.io/linuxserver/sonarr",
|
||||||
|
"lscr.io/linuxserver/radarr",
|
||||||
|
"lscr.io/linuxserver/prowlarr",
|
||||||
|
"lscr.io/linuxserver/bazarr",
|
||||||
|
"ghcr.io/seerr-team/seerr",
|
||||||
|
"fallenbagel/jellyseerr",
|
||||||
|
"ghcr.io/lampac-nextgen/lampac",
|
||||||
|
"ghcr.io/nextcloud-releases/all-in-one",
|
||||||
|
"alpine/kubectl"
|
||||||
|
],
|
||||||
|
"groupName": "floating images - manual",
|
||||||
|
"groupSlug": "floating-manual",
|
||||||
|
"automerge": false
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
+7
-36
@@ -1,6 +1,6 @@
|
|||||||
services:
|
services:
|
||||||
jellyfin:
|
jellyfin:
|
||||||
image: lscr.io/linuxserver/jellyfin:latest
|
image: lscr.io/linuxserver/jellyfin:version-12.1ubu2604
|
||||||
container_name: jellyfin
|
container_name: jellyfin
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
@@ -19,7 +19,7 @@ services:
|
|||||||
- streaming
|
- streaming
|
||||||
|
|
||||||
qbittorrent:
|
qbittorrent:
|
||||||
image: lscr.io/linuxserver/qbittorrent:latest
|
image: lscr.io/linuxserver/qbittorrent:5.2.4
|
||||||
container_name: qbittorrent
|
container_name: qbittorrent
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
@@ -38,7 +38,7 @@ services:
|
|||||||
- streaming
|
- streaming
|
||||||
|
|
||||||
sonarr:
|
sonarr:
|
||||||
image: lscr.io/linuxserver/sonarr:latest
|
image: lscr.io/linuxserver/sonarr:4.0.20
|
||||||
container_name: sonarr
|
container_name: sonarr
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
@@ -55,7 +55,7 @@ services:
|
|||||||
- streaming
|
- streaming
|
||||||
|
|
||||||
radarr:
|
radarr:
|
||||||
image: lscr.io/linuxserver/radarr:latest
|
image: lscr.io/linuxserver/radarr:6.4.4
|
||||||
container_name: radarr
|
container_name: radarr
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
@@ -72,7 +72,7 @@ services:
|
|||||||
- streaming
|
- streaming
|
||||||
|
|
||||||
prowlarr:
|
prowlarr:
|
||||||
image: lscr.io/linuxserver/prowlarr:latest
|
image: lscr.io/linuxserver/prowlarr:2.6.5
|
||||||
container_name: prowlarr
|
container_name: prowlarr
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
@@ -87,9 +87,8 @@ services:
|
|||||||
- streaming
|
- streaming
|
||||||
|
|
||||||
jellyseerr:
|
jellyseerr:
|
||||||
image: ghcr.io/seerr-team/seerr:latest
|
image: fallenbagel/jellyseerr:latest
|
||||||
container_name: jellyseerr
|
container_name: jellyseerr
|
||||||
init: true
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
- TZ=${TZ:-Europe/Berlin}
|
||||||
@@ -101,7 +100,7 @@ services:
|
|||||||
- streaming
|
- streaming
|
||||||
|
|
||||||
bazarr:
|
bazarr:
|
||||||
image: lscr.io/linuxserver/bazarr:latest
|
image: lscr.io/linuxserver/bazarr:1.6.2
|
||||||
container_name: bazarr
|
container_name: bazarr
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
@@ -117,31 +116,6 @@ services:
|
|||||||
networks:
|
networks:
|
||||||
- streaming
|
- streaming
|
||||||
|
|
||||||
lampac:
|
|
||||||
image: ghcr.io/lampac-nextgen/lampac:latest
|
|
||||||
container_name: lampac
|
|
||||||
restart: unless-stopped
|
|
||||||
shm_size: 1024mb
|
|
||||||
# Restore persisted passwd/init.conf from seed volume before start,
|
|
||||||
# so config survives container recreation (upstream entrypoint is
|
|
||||||
# ENTRYPOINT ["dotnet", "Core.dll"], WORKDIR /lampac, USER lampac).
|
|
||||||
entrypoint:
|
|
||||||
[
|
|
||||||
"/bin/sh",
|
|
||||||
"-c",
|
|
||||||
"if [ -f /seed/passwd ] && [ ! -f /lampac/passwd ]; then cp /seed/passwd /lampac/passwd; fi; if [ -f /seed/init.conf ] && [ ! -f /lampac/init.conf ]; then cp /seed/init.conf /lampac/init.conf; fi; exec /usr/share/dotnet/dotnet Core.dll",
|
|
||||||
]
|
|
||||||
environment:
|
|
||||||
- TZ=${TZ:-Europe/Berlin}
|
|
||||||
volumes:
|
|
||||||
- lampac-seed:/seed
|
|
||||||
- lampac-cache:/lampac/cache
|
|
||||||
- lampac-db:/lampac/database
|
|
||||||
ports:
|
|
||||||
- "19118:9118"
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
jellyfin-cfg:
|
jellyfin-cfg:
|
||||||
qbittorrent-cfg:
|
qbittorrent-cfg:
|
||||||
@@ -150,9 +124,6 @@ volumes:
|
|||||||
prowlarr-cfg:
|
prowlarr-cfg:
|
||||||
jellyseerr-cfg:
|
jellyseerr-cfg:
|
||||||
bazarr-cfg:
|
bazarr-cfg:
|
||||||
lampac-seed:
|
|
||||||
lampac-cache:
|
|
||||||
lampac-db:
|
|
||||||
downloads:
|
downloads:
|
||||||
movies:
|
movies:
|
||||||
tv:
|
tv:
|
||||||
|
|||||||
@@ -13,32 +13,19 @@ spec:
|
|||||||
issuerRef:
|
issuerRef:
|
||||||
name: internal-ca
|
name: internal-ca
|
||||||
kind: ClusterIssuer
|
kind: ClusterIssuer
|
||||||
---
|
# ---
|
||||||
apiVersion: cert-manager.io/v1
|
# apiVersion: cert-manager.io/v1
|
||||||
kind: Certificate
|
# kind: Certificate
|
||||||
metadata:
|
# metadata:
|
||||||
name: jelly-prod-tls
|
# name: jellyfin-prod-tls
|
||||||
namespace: streaming
|
# namespace: streaming
|
||||||
spec:
|
# spec:
|
||||||
secretName: jelly-prod-tls
|
# secretName: jellyfin-prod-tls
|
||||||
dnsNames:
|
# dnsNames:
|
||||||
- jelly.forust.xyz
|
# - jellyfin.forust.xyz
|
||||||
issuerRef:
|
# issuerRef:
|
||||||
name: letsencrypt-prod
|
# name: letsencrypt-prod
|
||||||
kind: ClusterIssuer
|
# kind: ClusterIssuer
|
||||||
---
|
|
||||||
apiVersion: cert-manager.io/v1
|
|
||||||
kind: Certificate
|
|
||||||
metadata:
|
|
||||||
name: seerr-prod-tls
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
secretName: seerr-prod-tls
|
|
||||||
dnsNames:
|
|
||||||
- seerr.forust.xyz
|
|
||||||
issuerRef:
|
|
||||||
name: letsencrypt-prod
|
|
||||||
kind: ClusterIssuer
|
|
||||||
# ---
|
# ---
|
||||||
# apiVersion: cert-manager.io/v1
|
# apiVersion: cert-manager.io/v1
|
||||||
# kind: Certificate
|
# kind: Certificate
|
||||||
@@ -91,3 +78,16 @@ spec:
|
|||||||
# issuerRef:
|
# issuerRef:
|
||||||
# name: letsencrypt-prod
|
# name: letsencrypt-prod
|
||||||
# kind: ClusterIssuer
|
# kind: ClusterIssuer
|
||||||
|
# ---
|
||||||
|
# apiVersion: cert-manager.io/v1
|
||||||
|
# kind: Certificate
|
||||||
|
# metadata:
|
||||||
|
# name: jellyseerr-prod-tls
|
||||||
|
# namespace: streaming
|
||||||
|
# spec:
|
||||||
|
# secretName: jellyseerr-prod-tls
|
||||||
|
# dnsNames:
|
||||||
|
# - jellyseerr.forust.xyz
|
||||||
|
# issuerRef:
|
||||||
|
# name: letsencrypt-prod
|
||||||
|
# kind: ClusterIssuer
|
||||||
@@ -186,30 +186,3 @@ endpoints:
|
|||||||
- "192.168.88.100"
|
- "192.168.88.100"
|
||||||
conditions:
|
conditions:
|
||||||
ready: true
|
ready: true
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: lampac
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: 19118
|
|
||||||
targetPort: 19118
|
|
||||||
---
|
|
||||||
apiVersion: discovery.k8s.io/v1
|
|
||||||
kind: EndpointSlice
|
|
||||||
metadata:
|
|
||||||
name: lampac
|
|
||||||
namespace: streaming
|
|
||||||
labels:
|
|
||||||
kubernetes.io/service-name: lampac
|
|
||||||
addressType: IPv4
|
|
||||||
ports:
|
|
||||||
- port: 19118
|
|
||||||
protocol: TCP
|
|
||||||
endpoints:
|
|
||||||
- addresses:
|
|
||||||
- "192.168.88.100"
|
|
||||||
conditions:
|
|
||||||
ready: true
|
|
||||||
@@ -116,54 +116,3 @@ spec:
|
|||||||
port: 16767
|
port: 16767
|
||||||
tls:
|
tls:
|
||||||
secretName: internal-wildcard-tls
|
secretName: internal-wildcard-tls
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: lampac-local
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`lampac.workstation.internal`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: lampac
|
|
||||||
port: 19118
|
|
||||||
tls:
|
|
||||||
secretName: internal-wildcard-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: jellyfin-prod
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`jelly.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: jellyfin
|
|
||||||
port: 18096
|
|
||||||
tls:
|
|
||||||
secretName: jelly-prod-tls
|
|
||||||
---
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: seerr-prod
|
|
||||||
namespace: streaming
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
- match: Host(`seerr.forust.xyz`)
|
|
||||||
kind: Rule
|
|
||||||
services:
|
|
||||||
- name: jellyseerr
|
|
||||||
port: 15055
|
|
||||||
tls:
|
|
||||||
secretName: seerr-prod-tls
|
|
||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
services:
|
services:
|
||||||
termix:
|
termix:
|
||||||
image: ghcr.io/lukegus/termix:2.9.0
|
image: ghcr.io/lukegus/termix:2.9.1
|
||||||
container_name: termix
|
container_name: termix
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
# ports:
|
# ports:
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ spec:
|
|||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: termix
|
- name: termix
|
||||||
image: ghcr.io/lukegus/termix:2.9.0
|
image: ghcr.io/lukegus/termix:2.9.1
|
||||||
envFrom:
|
envFrom:
|
||||||
- configMapRef:
|
- configMapRef:
|
||||||
name: termix-config
|
name: termix-config
|
||||||
|
|||||||
@@ -94,7 +94,7 @@ ports:
|
|||||||
exposedPort: 8080
|
exposedPort: 8080
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
expose:
|
expose:
|
||||||
default: false
|
default: true
|
||||||
http:
|
http:
|
||||||
aliasHeadersStrategy: delete
|
aliasHeadersStrategy: delete
|
||||||
ssh:
|
ssh:
|
||||||
|
|||||||
Reference in new issue
Block a user