Compare commits
478
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5cf0c90258 | ||
|
|
90a452a253 | ||
|
|
a9eabfba02 | ||
|
|
46c7e99b1d | ||
|
|
8b2cf29771 | ||
|
|
7b7fc3bcb0 | ||
|
|
bc1e69ebe0 | ||
|
|
f29bb3d580 | ||
|
|
1f7166026b | ||
|
|
1cbdfc1d6f | ||
|
|
6be3769288 | ||
|
|
ef325cd3b1 | ||
|
|
aa81f1bf8a | ||
|
|
93d768e988 | ||
|
|
a8f7c79934 | ||
|
|
c42bf14c9a | ||
|
|
1e8479b853 | ||
|
|
c139d700f1 | ||
|
|
67b9996911 | ||
|
|
4e9ee567ca | ||
|
|
4863e13596 | ||
|
|
9c4580a522 | ||
|
|
4e3ad00202 | ||
|
|
86ac43567d | ||
|
|
35bf980bda | ||
|
|
51677ae184 | ||
|
|
c9e6fc0e2b | ||
|
|
ab386fc436 | ||
|
|
7e17ae638a | ||
|
|
872d9695c3 | ||
|
|
69e7df6a63 | ||
|
|
98aceef192 | ||
|
|
dfd9cc6fbf | ||
|
|
40e7499e7c | ||
|
|
7f0bd5f609 | ||
|
|
043923fc64 | ||
|
|
f0f8a35b0f | ||
|
|
f5f389b440 | ||
|
|
7cca330438 | ||
|
|
5936de3e56 | ||
|
|
c98ea8b957 | ||
|
|
34c33697bb | ||
|
|
92bd920113 | ||
|
|
8007f82d52 | ||
|
|
60b9766449 | ||
|
|
0ebb7264bc | ||
|
|
ce21c60eba | ||
|
|
53638f831d | ||
|
|
4953da2dd7 | ||
|
|
4ac65f743c | ||
|
|
8f2e9d66c8 | ||
|
|
c7d42fb90a | ||
|
|
003b1e5dca | ||
|
|
b3463705c3 | ||
|
|
52e1f50a80 | ||
|
|
cdc2f10fe8 | ||
|
|
89fbdef10e | ||
|
|
ac795feeed | ||
|
|
3af5ecd07f | ||
|
|
82949613db | ||
|
|
47d788ca13 | ||
|
|
77be606912 | ||
|
|
4eab6a43c8 | ||
|
|
6c24d4fb17 | ||
|
|
e36595a045 | ||
|
|
e07537ff8b | ||
|
|
303eaaa71b | ||
|
|
1e66b5f344 | ||
|
|
d638a2c1f9 | ||
|
|
b8512c6033 | ||
|
|
3e057ea18d | ||
|
|
77113fb629 | ||
|
|
a3a0ab92b7 | ||
|
|
68fb5eb45e | ||
|
|
1c58c78892 | ||
|
|
82124017c0 | ||
|
|
e502f46f43 | ||
|
|
a4f8218b5e | ||
|
|
d162a50bba | ||
|
|
9ca8514a0a | ||
|
|
6fa809a8d2 | ||
|
|
c6d8df2317 | ||
|
|
c28d7323b3 | ||
|
|
25f547ff78 | ||
|
|
50911b4ec1 | ||
|
|
663675f9a0 | ||
|
|
8b28bd24ff | ||
|
|
b5d6f75330 | ||
|
|
f5b5ecaafa | ||
|
|
7799b676ca | ||
|
|
24d3686f60 | ||
|
|
b8b3bba264 | ||
|
|
abfbc04067 | ||
|
|
23ed72826a | ||
|
|
7288058df6 | ||
|
|
6715f9e9af | ||
|
|
ccec1102ef | ||
|
|
360a6fc5dc | ||
|
|
9a806724af | ||
|
|
ed1ddaad5d | ||
|
|
726b3ee544 | ||
|
|
13309b26e0 | ||
|
|
eddc256bed | ||
|
|
52f821cbba | ||
|
|
0dbc2fff13 | ||
|
|
91ec83bc1c | ||
|
|
9fec1dae39 | ||
|
|
e5626b7b2d | ||
|
|
8fb12a2176 | ||
|
|
fe0c7067b6 | ||
|
|
d0f0843774 | ||
|
|
81a5b207ac | ||
|
|
e3d5970ae3 | ||
|
|
85f05c26cb | ||
|
|
68630eb773 | ||
|
|
dad9cf2104 | ||
|
|
60886e8be2 | ||
|
|
4528321225 | ||
|
|
b246a3dea1 | ||
|
|
4c59a2d2fe | ||
|
|
fcc7b0d611 | ||
|
|
9633fe3a10 | ||
|
|
d9f1c8325a | ||
|
|
861d89d36a | ||
|
|
71cddd6a91 | ||
|
|
30e6f05584 | ||
|
|
bc8d74fd28 | ||
|
|
d2d4efb0d7 | ||
|
|
b752bf88bd | ||
|
|
587611ca88 | ||
|
|
ace23ad1f9 | ||
|
|
92aa731e44 | ||
|
|
87ca3fd40c
|
||
|
|
82bcd30ed8
|
||
|
|
620262d98c | ||
|
|
831f3a46b0 | ||
|
|
f7902e74e8
|
||
|
|
eb8d1b361e
|
||
|
|
6e2cafb206
|
||
|
|
67b0c0824f
|
||
|
|
8e72e0a920
|
||
|
|
73a1132beb | ||
|
|
a128523c24 | ||
|
|
ee881acd0e | ||
|
|
bacb2f4b9f | ||
|
|
91211e7b78 | ||
|
|
9b3a7aadb4
|
||
|
|
b123621ead
|
||
|
|
a2df8504f5
|
||
|
|
fb43306571
|
||
|
|
f424d91405
|
||
|
|
88a8f2987f
|
||
|
|
17027b232b
|
||
|
|
6ecbbb39b4
|
||
|
|
175cbc8860
|
||
|
|
6363d050b0
|
||
|
|
c855764bc6
|
||
|
|
7d92b85e21
|
||
|
|
9364392bc0 | ||
|
|
4355f451d4 | ||
|
|
3eaef5dc90 | ||
|
|
69ffd3682e | ||
|
|
1930600c40 | ||
|
|
d74a705d53
|
||
|
|
3c383db9a7
|
||
|
|
7fb0a0e179 | ||
|
|
227e5fda27
|
||
|
|
20bce5b31c | ||
|
|
70d7855f06
|
||
|
|
c905bbd039 | ||
|
|
fc83176522
|
||
|
|
7ba6bc44f2 | ||
|
|
0506aaaac8
|
||
|
|
bd9724da69
|
||
|
|
3bad433f1a
|
||
|
|
2bd7a5176f
|
||
|
|
a9ff01261b
|
||
|
|
95cec59263 | ||
|
|
1362ebc3c2
|
||
|
|
2de6131ba7
|
||
|
|
1762962f32
|
||
|
|
7fb9e46c05
|
||
|
|
b33488342a
|
||
|
|
d53b14b1de
|
||
|
|
a6a6d933da
|
||
|
|
0803f3efff | ||
|
|
ec0420962b | ||
|
|
b407202e53 | ||
|
|
b9b8474455 | ||
|
|
76853637bc | ||
|
|
dac3777fc4 | ||
|
|
bb5a3697f2 | ||
|
|
e73aacb900 | ||
|
|
ea483da645 | ||
|
|
85d35f86a7 | ||
|
|
3d03ab1ea4 | ||
|
|
4ca3ccdad3 | ||
|
|
10e26cda72 | ||
|
|
c648dfd147 | ||
|
|
2f97821dc6 | ||
|
|
3d78b90f3a | ||
|
|
3dc8228e22 | ||
|
|
93171ad8e6 | ||
|
|
dca7ad0902 | ||
|
|
26d10f4e71 | ||
|
|
68c5eac164 | ||
|
|
30f0f05150 | ||
|
|
a97560eaf3 | ||
|
|
2dce972be2 | ||
|
|
c2ad1122e5 | ||
|
|
4c356924e7 | ||
|
|
51777f904f | ||
|
|
37550da086 | ||
|
|
12d59cb6f9 | ||
|
|
714d4896c6 | ||
|
|
e369875117 | ||
|
|
31e61a9513 | ||
|
|
9b21f8056c | ||
|
|
4623fbd8bd | ||
|
|
18d1e21690 | ||
|
|
20b8c93275 | ||
|
|
5f88ecf02b | ||
|
|
0093e5ac52 | ||
|
|
bb821e138a | ||
|
|
1ea669220b | ||
|
|
f068a3e6a0 | ||
|
|
b7854447af | ||
|
|
7a3708f70c | ||
|
|
01ae2dd5cf | ||
|
|
82595804bf | ||
|
|
31b3c5bc31 | ||
|
|
1cdbfb2d7b | ||
|
|
6232b77026 | ||
|
|
22ffd779cc | ||
|
|
d85b3f02f5 | ||
|
|
17b2dfdc2e | ||
|
|
b641e3bd94 | ||
|
|
e19660fdf4 | ||
|
|
36922a177c
|
||
|
|
f3d04e935c
|
||
|
|
e5797e60b7 | ||
|
|
444bb97f8e | ||
|
|
0c5cf29f83
|
||
|
|
4f01cdac31 | ||
|
|
43c38767a1
|
||
|
|
cb40b10ecf | ||
|
|
a68c01a68f | ||
|
|
bdcdb1cb3d | ||
|
|
fe2b80b51f | ||
|
|
b8d5bc747d | ||
|
|
6f77b7d845
|
||
|
|
ea286e117d | ||
|
|
6a050669e8 | ||
|
|
b9c11b8eab | ||
|
|
6dac841b2c | ||
|
|
bed58c84ef | ||
|
|
526a2b617a | ||
|
|
56e5d79e3e | ||
|
|
1e08391e0e | ||
|
|
cd0ce06246 | ||
|
|
0a31601b77 | ||
|
|
e9a9271d2f | ||
|
|
25eb89c902 | ||
|
|
d988b0f7db | ||
|
|
e873f37159 | ||
|
|
8362f45bdc | ||
|
|
fd5ea6cadd | ||
|
|
aa3598ee3d | ||
|
|
c0205fa49b
|
||
|
|
a22707770f
|
||
|
|
646f988a86
|
||
|
|
414d17d839
|
||
|
|
812e4eb87a
|
||
|
|
70b3b203fb | ||
|
|
d857f3838d | ||
|
|
f8620349a9 | ||
|
|
b1acff5c85 | ||
|
|
beb6dca6a2 | ||
|
|
aed6ff31f7 | ||
|
|
73684af21b | ||
|
|
cd5c90adcc | ||
|
|
578a1ca544 | ||
|
|
12ed20a306 | ||
|
|
400e7b6595
|
||
|
|
f58e96a25d | ||
|
|
a3e5f5a78b | ||
|
|
1a09a62a4c
|
||
|
|
2593b54402
|
||
|
|
42826a037c
|
||
|
|
d7a68237e5
|
||
|
|
bbb8bdf0a7 | ||
|
|
f4d3bd9c6d | ||
|
|
6b919df7c6
|
||
|
|
3ee0b96ed5 | ||
|
|
d25d213d9b | ||
|
|
a3b7c4c889
|
||
|
|
3dbb50c924 | ||
|
|
54da82432b | ||
|
|
e5eb234c41 | ||
|
|
721348e67f | ||
|
|
d58ae2a5e7
|
||
|
|
aa516c3445 | ||
|
|
b5cc7d9a0d
|
||
|
|
5dfa9c879b
|
||
|
|
3c5702a0fb | ||
|
|
dd0ca27f4f | ||
|
|
7f7d0de090 | ||
|
|
bee3f16cb2 | ||
|
|
303d23968d
|
||
|
|
b7ecf88052
|
||
|
|
5068591b8b
|
||
|
|
8e57f21e44
|
||
|
|
073d9ff569
|
||
|
|
c6d00e525b | ||
|
|
539994a145
|
||
|
|
95f0afbbee
|
||
|
|
9f86bd1142
|
||
|
|
af9668e8e6 | ||
|
|
53b71a33ad
|
||
|
|
bf72007b14
|
||
|
|
0bad0a817e
|
||
|
|
525fed3b92 | ||
|
|
fe5e5c5e35
|
||
|
|
72aa022048
|
||
|
|
f18d4d9be4
|
||
|
|
45ce789f58
|
||
|
|
d7c05fd058
|
||
|
|
c13056fba1 | ||
|
|
5fe8af82d5
|
||
|
|
6d97246997 | ||
|
|
6970279311 | ||
|
|
02f4e0ab42
|
||
|
|
4a25622552
|
||
|
|
0138fbd276
|
||
|
|
94b5f39207
|
||
|
|
403e88d548 | ||
|
|
d03a4844fb | ||
|
|
48ff08529e | ||
|
|
81592b6142
|
||
|
|
9480576966 | ||
|
|
9b43a9bef4 | ||
|
|
2b03335af5 | ||
|
|
ea738ec14c | ||
|
|
e4e9d96a0b
|
||
|
|
89576032b9 | ||
|
|
a9edfc0a25 | ||
|
|
acb8009307 | ||
|
|
21f4e46028 | ||
|
|
0234524635 | ||
|
|
26f5fb2fb9 | ||
|
|
122e6f6986 | ||
|
|
ce0bc4613a | ||
|
|
8f4f460ff3 | ||
|
|
c048efd569 | ||
|
|
1f1e13ff39 | ||
|
|
c80a6c5351 | ||
|
|
4fe3d660f1 | ||
|
|
9675eac2bf | ||
|
|
dc7fe64fbc | ||
|
|
502810a12e | ||
|
|
c047cc291d | ||
|
|
f2b951673c | ||
|
|
6b7c0df586 | ||
|
|
fb2f420520 | ||
|
|
60c7d4ff17 | ||
|
|
d20ec696a3 | ||
|
|
c030b4cffa | ||
|
|
e0f7ab6561 | ||
|
|
f0682319a7 | ||
|
|
dbd3f36f76 | ||
|
|
4471da827c | ||
|
|
163ea867ce | ||
|
|
dc75dbaf7c | ||
|
|
db0f0f7bb6 | ||
|
|
5e4c60bb30 | ||
|
|
a699ceb935 | ||
|
|
17cae71952 | ||
|
|
f4c695f95e | ||
|
|
6bdb16ad21 | ||
|
|
6eb62f41cc | ||
|
|
586f0e3f7d | ||
|
|
0e46193f53 | ||
|
|
aed28ed15c | ||
|
|
f3b73bae11 | ||
|
|
be049cfa0d | ||
|
|
bfb21adff7 | ||
|
|
1c75382a6e | ||
|
|
9c5e037567 | ||
|
|
4f9e7ea990 | ||
|
|
9f784d2c31 | ||
|
|
a07e27bff6 | ||
|
|
c31369f2b7 | ||
|
|
3bfcd6edf4 | ||
|
|
504cbc81a0 | ||
|
|
aa7239ee83 | ||
|
|
6d9427cf2a | ||
|
|
70d60ed40a | ||
|
|
aca6824309 | ||
|
|
d48a01775d | ||
|
|
99d50b43fe | ||
|
|
23e955bde7 | ||
|
|
7d7a0e5c8a | ||
|
|
a767107277 | ||
|
|
e68e37c285 | ||
|
|
fc6a11397b | ||
|
|
d776124f26 | ||
|
|
8a0ed85e7c | ||
|
|
15f0f35ce4 | ||
|
|
1ec145d4cf | ||
|
|
8b6815f314 | ||
|
|
2d05a1911c | ||
|
|
6f2f70ad09 | ||
|
|
ce66a546f1 | ||
|
|
6cb49be951 | ||
|
|
3bcabcce4b | ||
|
|
a54b7b000f | ||
|
|
5b1fa11b5e | ||
|
|
380288d103 | ||
|
|
8fae8bf75d | ||
|
|
d4e0e7f37a | ||
|
|
cb92bff0c5 | ||
|
|
bfbe841154 | ||
|
|
7cbc5bf4f3 | ||
|
|
258ed04f98 | ||
|
|
7ee0a1e7a2 | ||
|
|
739915c451 | ||
|
|
68b5467a37 | ||
|
|
61e6b2b5c7 | ||
|
|
272666d2fd | ||
|
|
aca485836b | ||
|
|
02671b9117 | ||
|
|
1c1170ca96 | ||
|
|
3eab3b254a | ||
|
|
5d9fc18ba5 | ||
|
|
03d39f8a32 | ||
|
|
7b60630d76 | ||
|
|
cc20d848f8 | ||
|
|
1040e4fdf7 | ||
|
|
7af5af0630 | ||
|
|
8f9be8a478 | ||
|
|
d1adaa54b1 | ||
|
|
b3b0d5b553 | ||
|
|
d22ef0cb44 | ||
|
|
7c29d74c72 | ||
|
|
b2ae170ea0 | ||
|
|
2c2474165b | ||
|
|
155bb8d02b | ||
|
|
ed1b41ca1d | ||
|
|
9bb5f070e3 | ||
|
|
b238e9ccf2 | ||
|
|
09a05a5ad5 | ||
|
|
5b05207985 | ||
|
|
319cf0ea1f | ||
|
|
53a0460476 | ||
|
|
13340b6ddc | ||
|
|
ed20fb6e2a | ||
|
|
4fe36be5ea | ||
|
|
6f8b780906 | ||
|
|
1f9a1c2c62 | ||
|
|
b20c012268 | ||
|
|
b4bce72611 | ||
|
|
e7d21bfe90 | ||
|
|
0f75fe02c2 | ||
|
|
2d895fe2bd | ||
|
|
45b0859ab5 | ||
|
|
45021933a6 | ||
|
|
d25570e293 | ||
|
|
6843befac3 | ||
|
|
0dfb09590d | ||
|
|
625eb9561b | ||
|
|
b367b64879 | ||
|
|
a30bda4940 | ||
|
|
b722467991 | ||
|
|
5f8fd05266 | ||
|
|
1c7afe5bb3 | ||
|
|
4ff80c07b0 | ||
|
|
3a5652daa7 | ||
|
|
4e18cd0eb3 |
No files matched your search
@@ -0,0 +1,191 @@
|
||||
# Инструкция: Анализ хранилища Kubernetes и настройка NFS
|
||||
|
||||
## Цель
|
||||
Проанализировать текущую конфигурацию хранилища Kubernetes и подготовить план внедрения NFS StorageClass для сохранения данных при удалении namespace.
|
||||
|
||||
## 1. Собрать информацию о кластере
|
||||
|
||||
### 1.1. Версия Kubernetes и тип дистрибутива
|
||||
```bash
|
||||
kubectl version --short
|
||||
# или
|
||||
kubectl version
|
||||
```
|
||||
|
||||
Определить, используется ли k3s, k8s, microk8s и т.д.:
|
||||
```bash
|
||||
# Проверить наличие k3s
|
||||
which k3s
|
||||
# Проверить процесс
|
||||
ps aux | grep -E 'kube|k3s'
|
||||
```
|
||||
|
||||
### 1.2. StorageClass
|
||||
```bash
|
||||
kubectl get storageclass -o wide
|
||||
```
|
||||
|
||||
Запомнить:
|
||||
- `PROVISIONER` — какой драйвер используется
|
||||
- `RECLAIMPOLICY` — Delete или Retain
|
||||
- Какой StorageClass помечен как `(default)`
|
||||
|
||||
### 1.3. Существующие PV и PVC
|
||||
```bash
|
||||
kubectl get pv -o wide
|
||||
kubectl get pvc --all-namespaces
|
||||
```
|
||||
|
||||
Посмотреть, какие PVC привязаны к каким PV, и какой reclaimPolicy у PV.
|
||||
|
||||
### 1.4. Нода и диски
|
||||
```bash
|
||||
# Список нод
|
||||
kubectl get nodes -o wide
|
||||
|
||||
# На каждой ноде (через ssh или локально):
|
||||
lsblk
|
||||
df -h
|
||||
cat /etc/fstab
|
||||
```
|
||||
|
||||
Определить:
|
||||
- Есть ли отдельный раздел/диск для данных
|
||||
- Куда смонтированы разделы
|
||||
- Сколько свободного места
|
||||
- Есть ли монтирование NTFS-разделов (как `/media/forust/Programs`)
|
||||
|
||||
### 1.5. Где local-path хранит данные (для k3s)
|
||||
```bash
|
||||
ls -la /var/lib/rancher/k3s/storage/ 2>/dev/null
|
||||
# или для microk8s
|
||||
ls -la /var/snap/microk8s/common/ 2>/dev/null
|
||||
```
|
||||
|
||||
## 2. Анализ: сохраняются ли данные при удалении namespace?
|
||||
|
||||
| Сценарий | Результат |
|
||||
|---|---|
|
||||
| `kubectl delete ns <ns>` | Все PVC в namespace удаляются |
|
||||
| PVC → PV c `reclaimPolicy: Delete` | PV и данные удалены |
|
||||
| PVC → PV c `reclaimPolicy: Retain` | PV остаётся (статус Released), данные целы |
|
||||
|
||||
**Вывод:** Если reclaimPolicy в StorageClass = `Delete`, то данные **пропадут**. Если `Retain` — сохранятся.
|
||||
|
||||
## 3. План внедрения NFS
|
||||
|
||||
### 3.1. Проверить, установлен ли NFS
|
||||
```bash
|
||||
which nfsstat exportfs mount.nfs
|
||||
systemctl status nfs-server 2>/dev/null || systemctl status nfs-kernel-server 2>/dev/null
|
||||
```
|
||||
|
||||
### 3.2. Выбрать директорию для NFS-экспорта
|
||||
|
||||
Варианты (выбрать подходящий):
|
||||
- `/var/lib/k8s-nfs/` — на корневом разделе
|
||||
- `<путь к отдельному разделу>/k8s-nfs/` — если есть отдельный диск/раздел
|
||||
- Не рекомендуется использовать NTFS-раздел (проблемы с правами и производительностью)
|
||||
|
||||
Требования:
|
||||
- Файловая система: ext4 или xfs (не ntfs!)
|
||||
- Достаточно свободного места
|
||||
- Права: `755`, владелец root
|
||||
|
||||
### 3.3. Установить NFS-сервер
|
||||
|
||||
```bash
|
||||
# Debian/Ubuntu
|
||||
apt update && apt install -y nfs-kernel-server
|
||||
|
||||
# RHEL/Fedora
|
||||
dnf install -y nfs-utils
|
||||
```
|
||||
|
||||
### 3.4. Настроить экспорт
|
||||
|
||||
Создать директорию:
|
||||
```bash
|
||||
mkdir -p /var/lib/k8s-nfs
|
||||
chmod 755 /var/lib/k8s-nfs
|
||||
```
|
||||
|
||||
Добавить в `/etc/exports`:
|
||||
```
|
||||
/var/lib/k8s-nfs *(rw,sync,no_subtree_check,no_root_squash)
|
||||
```
|
||||
|
||||
Применить:
|
||||
```bash
|
||||
exportfs -rav
|
||||
```
|
||||
|
||||
Проверить:
|
||||
```bash
|
||||
showmount -e localhost
|
||||
```
|
||||
|
||||
### 3.5. Выбрать способ интеграции с Kubernetes
|
||||
|
||||
#### Вариант A: nfs-subdir-external-provisioner (проще)
|
||||
```bash
|
||||
helm repo add nfs-subdir-external-provisioner https://kubernetes-sigs.github.io/nfs-subdir-external-provisioner/
|
||||
helm install nfs-provisioner nfs-subdir-external-provisioner/nfs-subdir-external-provisioner \
|
||||
--namespace kube-system \
|
||||
--set nfs.server=127.0.0.1 \
|
||||
--set nfs.path=/var/lib/k8s-nfs \
|
||||
--set storageClass.name=nfs \
|
||||
--set storageClass.defaultClass=false \
|
||||
--set storageClass.reclaimPolicy=Retain
|
||||
```
|
||||
|
||||
#### Вариант B: NFS CSI Driver
|
||||
```bash
|
||||
helm repo add csi-driver-nfs https://raw.githubusercontent.com/kubernetes-csi/csi-driver-nfs/master/charts
|
||||
helm install csi-driver-nfs csi-driver-nfs/csi-driver-nfs --namespace kube-system
|
||||
```
|
||||
|
||||
После установки CSI драйвера создать StorageClass:
|
||||
```yaml
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: StorageClass
|
||||
metadata:
|
||||
name: nfs
|
||||
provisioner: nfs.csi.k8s.io
|
||||
parameters:
|
||||
server: 127.0.0.1
|
||||
share: /var/lib/k8s-nfs
|
||||
reclaimPolicy: Retain
|
||||
volumeBindingMode: Immediate
|
||||
```
|
||||
|
||||
### 3.6. Проверить результат
|
||||
```bash
|
||||
kubectl get storageclass
|
||||
kubectl get pods -n kube-system | grep -E 'nfs|provisioner'
|
||||
```
|
||||
|
||||
## 4. Итоговая конфигурация
|
||||
|
||||
После внедрения в кластере будет два StorageClass:
|
||||
|
||||
| Имя | Provisioner | ReclaimPolicy | Назначение |
|
||||
|---|---|---|---|
|
||||
| `local-path` (default) | rancher.io/local-path | Delete | Временные данные, stateless |
|
||||
| `nfs` | nfs-subdir-external-provisioner или nfs.csi.k8s.io | Retain | Данные, которые нужно сохранять |
|
||||
|
||||
**Главное преимущество:** PVC c `storageClassName: nfs` при удалении namespace сохраняют данные на диске, так как NFS-провизор использует `reclaimPolicy: Retain` или файлы физически остаются в NFS-экспорте.
|
||||
|
||||
## 5. Ответы на частые вопросы
|
||||
|
||||
**В:** Не упадёт ли local-path при установке NFS?
|
||||
**О:** Нет, они независимы. local-path продолжает работать как обычно.
|
||||
|
||||
**В:** Данные NFS и local-path будут на одном диске?
|
||||
**О:** Да, можно настроить оба на одном разделе, в разных каталогах.
|
||||
|
||||
**В:** Что если у меня несколько нод?
|
||||
**О:** NFS сервер нужно поднять на одной ноде, а с других нод должна быть доступна шари. Для multi-node лучше использовать отдельный сервер или distributed storage (Longhorn, Rook/Ceph).
|
||||
|
||||
**В:** Можно ли использовать существующий NTFS-раздел для NFS?
|
||||
**О:** Не рекомендуется — NTFS не поддерживает права Linux (no_root_squash не сработает корректно), возможны проблемы с блокировками и производительностью.
|
||||
@@ -0,0 +1,24 @@
|
||||
root = true
|
||||
|
||||
[*]
|
||||
indent_style = space
|
||||
indent_size = 2
|
||||
end_of_line = lf
|
||||
charset = utf-8
|
||||
trim_trailing_whitespace = true
|
||||
insert_final_newline = true
|
||||
|
||||
[*.{yml,yaml}]
|
||||
indent_size = 2
|
||||
|
||||
[*.{json,jsonc}]
|
||||
indent_size = 2
|
||||
|
||||
[*.md]
|
||||
trim_trailing_whitespace = false
|
||||
|
||||
[*.py]
|
||||
indent_size = 4
|
||||
|
||||
[{Makefile,makefile}]
|
||||
indent_style = tab
|
||||
@@ -0,0 +1,70 @@
|
||||
|
||||
|
||||
#===============================
|
||||
# Basic auth credentials
|
||||
#===============================
|
||||
#
|
||||
#
|
||||
#
|
||||
#===============================
|
||||
|
||||
#===============================================
|
||||
#BEGIN TRAEFIK ENVIRONMENT VARIABLES ===========
|
||||
#===============================================
|
||||
|
||||
#===============================================
|
||||
# General Traefik Environment Variables
|
||||
#===============================================
|
||||
HOST=hostname
|
||||
EMAIL=your@email.here
|
||||
CF_DNS_API_TOKEN=API_TOKEN_HERE
|
||||
CF_EMAIL=your_cloudflare@email.here
|
||||
TZ=Europe/Berlin
|
||||
|
||||
#===============================================
|
||||
# Dockmon Traefik Configuration File
|
||||
#===============================================
|
||||
DOCKMON_APPNAME=dockmon
|
||||
DOCKMON_SUBDOMEN=dockmon
|
||||
#===============================================
|
||||
# Dashboard Traefik Environment Variables
|
||||
#===============================================
|
||||
DASHBOARD_APPNAME=traefik
|
||||
DASHBOARD_SUBDOMEN=traefik
|
||||
#===============================================
|
||||
# Watercrawl Traefik Environment Variables
|
||||
#===============================================
|
||||
WATERCRAWL_APPNAME=watercrawl
|
||||
WATERCRAWL_SUBDOMEN=watercrawl
|
||||
#===============================================
|
||||
# n8n Traefik Environment Variables
|
||||
#===============================================
|
||||
N8N_APPNAME=n8n
|
||||
N8N_SUBDOMEN=n8n
|
||||
#===============================================
|
||||
# Glance Traefik Environment Variables
|
||||
#===============================================
|
||||
GLANCE_APPNAME=glance
|
||||
GLANCE_SUBDOMEN=glance
|
||||
#===============================================
|
||||
# AdGuard Traefik Environment Variables
|
||||
#===============================================
|
||||
ADGUARD_APPNAME=adguard
|
||||
ADGUARD_SUBDOMEN=adguard
|
||||
#===============================================
|
||||
# Portainer Traefik Environment Variables
|
||||
#===============================================
|
||||
PORTAINER_APPNAME=portainer
|
||||
PORTAINER_SUBDOMEN=portainer
|
||||
#===============================================
|
||||
# Nextcloud Traefik Environment Variables
|
||||
#===============================================
|
||||
NEXTCLOUD_APPNAME=nextcloud
|
||||
NEXTCLOUD_SUBDOMEN=nextcloud
|
||||
#===============================================
|
||||
# Aio Traefik Environment Variables
|
||||
#===============================================
|
||||
NEXTCLOUD_AIO_APPNAME=nextcloud-aio
|
||||
NEXTCLOUD_AIO_SUBDOMEN=nextcloud-aio
|
||||
# END OF TRAEFIK ENVIRONMENT VARIABLES
|
||||
#===============================================
|
||||
@@ -0,0 +1,349 @@
|
||||
name: ci
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- "**"
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: ci-${{ github.ref }}
|
||||
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
|
||||
|
||||
env:
|
||||
REGISTRY: gcr.forust.xyz
|
||||
|
||||
jobs:
|
||||
lint-prettier:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Check formatting with Prettier
|
||||
shell: bash
|
||||
run: |
|
||||
mapfile -t prettier_files < <(
|
||||
git ls-files \
|
||||
| grep -E '\.(md|json|ya?ml|html|css)$' \
|
||||
| grep -Ev '^(\.docs/|\.zed/|errorpages/html/|homepages/(forust_files|xdfnx_files)/)'
|
||||
)
|
||||
|
||||
if [ "${#prettier_files[@]}" -eq 0 ]; then
|
||||
echo "No Prettier-managed files found."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
prettier --check --ignore-unknown "${prettier_files[@]}"
|
||||
|
||||
lint-ruff:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Lint Python with Ruff
|
||||
shell: bash
|
||||
run: |
|
||||
ruff check .
|
||||
|
||||
lint-yaml:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Lint YAML syntax
|
||||
shell: bash
|
||||
run: |
|
||||
mapfile -t yaml_files < <(
|
||||
git ls-files '*.yaml' '*.yml' \
|
||||
':!node_modules/**' \
|
||||
':!**/.venv/**'
|
||||
)
|
||||
|
||||
if [ "${#yaml_files[@]}" -eq 0 ]; then
|
||||
echo "No YAML files found."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
yamllint -c .yamllint "${yaml_files[@]}"
|
||||
|
||||
lint-dockerfiles:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Lint Dockerfiles
|
||||
shell: bash
|
||||
run: |
|
||||
mapfile -t dockerfiles < <(
|
||||
git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*'
|
||||
)
|
||||
|
||||
if [ "${#dockerfiles[@]}" -eq 0 ]; then
|
||||
echo "No Dockerfiles found."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
hadolint -c .hadolint.yaml "${dockerfiles[@]}"
|
||||
|
||||
validate:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Validate Kubernetes manifests
|
||||
shell: bash
|
||||
run: |
|
||||
mapfile -t manifests < <(
|
||||
git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \
|
||||
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'
|
||||
)
|
||||
|
||||
if [ "${#manifests[@]}" -eq 0 ]; then
|
||||
echo "No Kubernetes manifests found."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
kubeconform \
|
||||
-strict \
|
||||
-ignore-missing-schemas \
|
||||
-summary \
|
||||
"${manifests[@]}"
|
||||
|
||||
build:
|
||||
needs: [lint-prettier, lint-ruff, lint-yaml, lint-dockerfiles, validate]
|
||||
if: github.event_name != 'pull_request' && (github.ref_name == 'main' || github.ref_name == 'dev')
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
outputs:
|
||||
services: ${{ steps.services.outputs.services }}
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Detect changed docker-built services
|
||||
id: services
|
||||
shell: bash
|
||||
run: |
|
||||
base="${{ github.event.before }}"
|
||||
if [ -z "$base" ] || [ "$base" = "0000000000000000000000000000000000000000" ]; then
|
||||
base="$(git rev-list --max-parents=0 HEAD)"
|
||||
fi
|
||||
|
||||
mapfile -t changed_files < <(git diff --name-only "$base" "${GITHUB_SHA}")
|
||||
|
||||
services=()
|
||||
|
||||
add_service() {
|
||||
local name="$1"
|
||||
local seen=0
|
||||
for existing in "${services[@]}"; do
|
||||
if [ "$existing" = "$name" ]; then
|
||||
seen=1
|
||||
break
|
||||
fi
|
||||
done
|
||||
if [ "$seen" -eq 0 ]; then
|
||||
services+=("$name")
|
||||
fi
|
||||
}
|
||||
|
||||
for file in "${changed_files[@]}"; do
|
||||
case "$file" in
|
||||
dtek_notif/*)
|
||||
add_service dtek_notif
|
||||
;;
|
||||
errorpages/*)
|
||||
add_service errorpages
|
||||
;;
|
||||
userbot/*)
|
||||
add_service userbot
|
||||
;;
|
||||
homepages/*)
|
||||
add_service homepages
|
||||
;;
|
||||
edu_master/phpsessid-bot/*|edu_master/webinar-checker/*|edu_master/compose.yaml)
|
||||
add_service edu_master
|
||||
;;
|
||||
esac
|
||||
done
|
||||
|
||||
if [ "${#services[@]}" -eq 0 ]; then
|
||||
echo "No docker-built services changed."
|
||||
echo "services=" >> "$GITHUB_OUTPUT"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
printf '%s\n' "${services[@]}" | tee /tmp/services.txt
|
||||
echo "services=$(paste -sd, /tmp/services.txt)" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Log in to registry
|
||||
if: steps.services.outputs.services != ''
|
||||
shell: bash
|
||||
run: |
|
||||
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login "${REGISTRY}" \
|
||||
-u "${{ secrets.REGISTRY_USERNAME }}" \
|
||||
--password-stdin
|
||||
|
||||
- name: Build and push changed images
|
||||
if: steps.services.outputs.services != ''
|
||||
shell: bash
|
||||
run: |
|
||||
IFS=, read -r -a services <<< "${{ steps.services.outputs.services }}"
|
||||
|
||||
for service in "${services[@]}"; do
|
||||
case "$service" in
|
||||
dtek_notif)
|
||||
image="${REGISTRY}/forust/dtek-notif"
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" dtek_notif
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
;;
|
||||
errorpages)
|
||||
image="${REGISTRY}/forust/error-pages"
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" errorpages
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
;;
|
||||
userbot)
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
for target in runtime panel; do
|
||||
case "$target" in
|
||||
runtime)
|
||||
context="userbot"
|
||||
image="${REGISTRY}/forust/userbot"
|
||||
;;
|
||||
panel)
|
||||
context="userbot/panel"
|
||||
image="${REGISTRY}/forust/userbot-panel"
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" "$context"
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
done
|
||||
;;
|
||||
homepages)
|
||||
for service in forust xdfnx; do
|
||||
case "$service" in
|
||||
forust)
|
||||
image="${REGISTRY}/forust/forust-homepage"
|
||||
;;
|
||||
xdfnx)
|
||||
image="${REGISTRY}/forust/xdfnx-homepage"
|
||||
;;
|
||||
esac
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" -f "homepages/Dockerfile.${service}" homepages
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
done
|
||||
;;
|
||||
edu_master)
|
||||
for service in session-keeper webinar-checker; do
|
||||
case "$service" in
|
||||
session-keeper)
|
||||
context="edu_master/phpsessid-bot"
|
||||
image="${REGISTRY}/forust/session-keeper"
|
||||
;;
|
||||
webinar-checker)
|
||||
context="edu_master/webinar-checker"
|
||||
image="${REGISTRY}/forust/webinar-checker"
|
||||
;;
|
||||
esac
|
||||
tags=("latest")
|
||||
case "${GITHUB_REF_NAME}" in
|
||||
main)
|
||||
tags+=("main" "prod")
|
||||
;;
|
||||
dev)
|
||||
tags+=("dev")
|
||||
;;
|
||||
esac
|
||||
build_args=()
|
||||
for tag in "${tags[@]}"; do
|
||||
build_args+=(-t "${image}:${tag}")
|
||||
done
|
||||
docker build \
|
||||
--cache-from "type=registry,ref=${image}:buildcache" \
|
||||
--cache-to "type=registry,ref=${image}:buildcache,mode=max" \
|
||||
"${build_args[@]}" "$context"
|
||||
for tag in "${tags[@]}"; do
|
||||
docker push "${image}:${tag}"
|
||||
done
|
||||
done
|
||||
;;
|
||||
esac
|
||||
done
|
||||
@@ -0,0 +1,307 @@
|
||||
name: deploy
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: deploy-main
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
redeploy:
|
||||
runs-on: [self-hosted, linux, arch, homelab, prod]
|
||||
steps:
|
||||
- name: Redeploy workstation
|
||||
shell: bash
|
||||
env:
|
||||
DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }}
|
||||
DEPLOY_PORT: ${{ secrets.DEPLOY_PORT }}
|
||||
DEPLOY_USER: ${{ secrets.DEPLOY_USER }}
|
||||
DEPLOY_PATH: ${{ secrets.DEPLOY_PATH }}
|
||||
DEPLOY_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
|
||||
APPLY_PRUNE: ${{ vars.APPLY_PRUNE }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
: "${DEPLOY_HOST:?missing DEPLOY_HOST}"
|
||||
: "${DEPLOY_USER:?missing DEPLOY_USER}"
|
||||
: "${DEPLOY_KEY:?missing DEPLOY_SSH_KEY}"
|
||||
|
||||
deploy_port="${DEPLOY_PORT:-22}"
|
||||
deploy_path="${DEPLOY_PATH:-/srv/homelab}"
|
||||
|
||||
ssh_key="$RUNNER_TEMP/deploy_key"
|
||||
mkdir -p "$RUNNER_TEMP"
|
||||
printf '%s\n' "$DEPLOY_KEY" > "$ssh_key"
|
||||
chmod 600 "$ssh_key"
|
||||
|
||||
ssh_opts=(
|
||||
-i "$ssh_key"
|
||||
-p "$deploy_port"
|
||||
-o BatchMode=yes
|
||||
-o StrictHostKeyChecking=accept-new
|
||||
)
|
||||
|
||||
ssh "${ssh_opts[@]}" "${DEPLOY_USER}@${DEPLOY_HOST}" \
|
||||
"DEPLOY_PATH=$(printf '%q' \"$deploy_path\") APPLY_PRUNE=$(printf '%q' \"${APPLY_PRUNE:-false}\") bash -se" <<'EOF'
|
||||
set -euo pipefail
|
||||
|
||||
repo="${DEPLOY_PATH:-/srv/homelab}"
|
||||
|
||||
if [ ! -d "$repo/.git" ]; then
|
||||
echo "Repository not found at $repo"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
git -C "$repo" fetch origin main
|
||||
|
||||
echo "== Workstation state =="
|
||||
echo " local: $(git -C "$repo" rev-parse --short HEAD)"
|
||||
echo " remote: $(git -C "$repo" rev-parse --short origin/main)"
|
||||
|
||||
if [ -n "$(git -C "$repo" status --porcelain --untracked-files=no)" ]; then
|
||||
echo "ERROR: workstation has local tracked modifications, refusing reset:"
|
||||
git -C "$repo" status --porcelain --untracked-files=no
|
||||
git -C "$repo" diff --stat
|
||||
exit 1
|
||||
fi
|
||||
|
||||
git -C "$repo" reset --hard origin/main
|
||||
cd "$repo"
|
||||
|
||||
is_disabled() {
|
||||
local target="$1"
|
||||
if [ -f "$target" ]; then
|
||||
target="$(dirname "$target")"
|
||||
fi
|
||||
while true; do
|
||||
if [ -f "$target/DISABLED" ]; then
|
||||
return 0
|
||||
fi
|
||||
if [ "$target" = "$repo" ]; then
|
||||
break
|
||||
fi
|
||||
target="$(dirname "$target")"
|
||||
case "$target" in
|
||||
"$repo"/*) ;;
|
||||
*) break ;;
|
||||
esac
|
||||
done
|
||||
return 1
|
||||
}
|
||||
|
||||
collect_k8s() {
|
||||
git ls-files -- "$1" \
|
||||
| grep -E '\.ya?ml$' \
|
||||
| grep -Ev '/routing/|/overlays/' \
|
||||
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$' \
|
||||
| grep -Ev '(^|/)[^/]*secret[^/]*\.ya?ml$' \
|
||||
| sort
|
||||
}
|
||||
|
||||
collect_k8s_inactive() {
|
||||
collect_k8s "$1" \
|
||||
| grep -E '(^|/)namespace\.ya?ml$|/routing/'
|
||||
}
|
||||
|
||||
kustomize_overlay() {
|
||||
if [ -f "$1/overlays/prod/kustomization.yaml" ]; then
|
||||
echo "$1/overlays/prod"
|
||||
elif [ -f "$1/base/kustomization.yaml" ]; then
|
||||
echo "$1/base"
|
||||
fi
|
||||
}
|
||||
|
||||
mapfile -t k8s_dirs < <(
|
||||
git ls-files '*.yaml' '*.yml' \
|
||||
| grep -E '(^|/)k8s/' \
|
||||
| sed -E 's#((^|.*/)k8s)/.*#\1#' \
|
||||
| sort -u
|
||||
)
|
||||
|
||||
k8s_manifests=()
|
||||
kustomize_apps=()
|
||||
for kd_rel in "${k8s_dirs[@]}"; do
|
||||
kd="$repo/$kd_rel"
|
||||
if is_disabled "$kd"; then
|
||||
echo "skip (DISABLED): $kd_rel"
|
||||
continue
|
||||
fi
|
||||
if [ -f "$kd/active" ]; then
|
||||
overlay="$(kustomize_overlay "$kd" || true)"
|
||||
if [ -n "${overlay:-}" ]; then
|
||||
echo "kustomize app: ${overlay#$repo/}"
|
||||
kustomize_apps+=("$overlay")
|
||||
else
|
||||
while IFS= read -r f; do
|
||||
[ -n "$f" ] && k8s_manifests+=("$repo/$f")
|
||||
done < <(collect_k8s "$kd_rel" || true)
|
||||
fi
|
||||
else
|
||||
while IFS= read -r f; do
|
||||
[ -n "$f" ] && k8s_manifests+=("$repo/$f")
|
||||
done < <(collect_k8s_inactive "$kd_rel" || true)
|
||||
fi
|
||||
done
|
||||
|
||||
mapfile -t compose_rel < <(
|
||||
git ls-files '*/compose.yaml' '*/compose.yml' compose.yaml compose.yml | sort
|
||||
)
|
||||
|
||||
compose_stacks=()
|
||||
for cf_rel in "${compose_rel[@]}"; do
|
||||
cf="$repo/$cf_rel"
|
||||
if is_disabled "$cf"; then
|
||||
echo "skip (DISABLED): $cf_rel"
|
||||
continue
|
||||
fi
|
||||
if [ -f "$(dirname "$cf")/k8s/active" ]; then
|
||||
echo "skip (k8s-managed): $cf_rel"
|
||||
continue
|
||||
fi
|
||||
compose_stacks+=("$cf")
|
||||
done
|
||||
|
||||
echo "== Validate compose stacks =="
|
||||
for cf in "${compose_stacks[@]}"; do
|
||||
echo " config: $cf"
|
||||
docker compose -f "$cf" config --quiet
|
||||
done
|
||||
|
||||
echo "== Validate k8s manifests (kubectl dry-run=client) =="
|
||||
for m in "${k8s_manifests[@]}"; do
|
||||
echo " apply --dry-run=client $m"
|
||||
kubectl apply --dry-run=client -f "$m" >/dev/null
|
||||
done
|
||||
for k in "${kustomize_apps[@]}"; do
|
||||
echo " apply -k --dry-run=client $k"
|
||||
kubectl apply -k "$k" --dry-run=client >/dev/null
|
||||
done
|
||||
|
||||
echo "== Validate k8s manifests (kubectl dry-run=server) =="
|
||||
for m in "${k8s_manifests[@]}"; do
|
||||
echo " apply --dry-run=server $m"
|
||||
kubectl apply --dry-run=server -f "$m" >/dev/null
|
||||
done
|
||||
for k in "${kustomize_apps[@]}"; do
|
||||
echo " apply -k --dry-run=server $k"
|
||||
kubectl apply -k "$k" --dry-run=server >/dev/null
|
||||
done
|
||||
|
||||
echo "== Checking referenced Secrets exist =="
|
||||
echo " (deploy never applies *secret*.yaml; create missing ones from the laptop)"
|
||||
ref_secrets=()
|
||||
if [ "${#k8s_manifests[@]}" -gt 0 ]; then
|
||||
while IFS= read -r s; do
|
||||
[ -n "$s" ] && ref_secrets+=("$s")
|
||||
done < <(
|
||||
{
|
||||
grep -h -A1 -E 'secretRef:|secretKeyRef:' "${k8s_manifests[@]}" 2>/dev/null || true
|
||||
grep -h -E 'secretName:' "${k8s_manifests[@]}" 2>/dev/null || true
|
||||
} | grep -E 'name:' | sed -E 's/.*name:[[:space:]]*//' | tr -d '"'"'"' "'"'" | sed -E 's/[[:space:]]*#.*//' | awk 'NF' | sort -u || true
|
||||
)
|
||||
fi
|
||||
missing_secrets=()
|
||||
all_secrets="$(kubectl get secrets -A --no-headers -o custom-columns=:metadata.name 2>/dev/null || true)"
|
||||
for s in "${ref_secrets[@]}"; do
|
||||
if printf '%s\n' "$all_secrets" | grep -qx "$s"; then
|
||||
echo " ok: $s"
|
||||
else
|
||||
echo " MISSING: $s"
|
||||
missing_secrets+=("$s")
|
||||
fi
|
||||
done
|
||||
if [ "${#missing_secrets[@]}" -gt 0 ]; then
|
||||
echo "ERROR: ${#missing_secrets[@]} referenced Secret(s) not found in the cluster:"
|
||||
printf ' - %s\n' "${missing_secrets[@]}"
|
||||
echo "Create them manually from the laptop, e.g.:"
|
||||
echo " kubectl apply -f SERVICE/k8s/secrets.yaml # see SERVICE/k8s/secrets.yaml.example"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "== Applying Kubernetes manifests =="
|
||||
ns_files=()
|
||||
other_files=()
|
||||
for m in "${k8s_manifests[@]}"; do
|
||||
case "$m" in
|
||||
*/namespace.y?ml) ns_files+=("$m") ;;
|
||||
*) other_files+=("$m") ;;
|
||||
esac
|
||||
done
|
||||
|
||||
prune_opts=()
|
||||
if [ "${APPLY_PRUNE:-false}" = "true" ]; then
|
||||
prune_opts=(--prune -l app.kubernetes.io/managed-by=homelab-deploy)
|
||||
fi
|
||||
|
||||
if [ "${#ns_files[@]}" -gt 0 ]; then
|
||||
echo " namespaces first: ${ns_files[*]}"
|
||||
kubectl apply -f "${ns_files[@]}"
|
||||
fi
|
||||
if [ -f "$repo/prometheus-stack/k8s/active" ] && ! is_disabled "$repo/prometheus-stack/k8s"; then
|
||||
if [ ! -f "$repo/prometheus-stack/k8s/grafana-values.yaml" ]; then
|
||||
echo "ERROR: prometheus-stack/k8s/grafana-values.yaml (gitignored) missing on workstation, restore it first."
|
||||
exit 1
|
||||
fi
|
||||
echo "== Upgrading kube-prometheus-stack =="
|
||||
helm upgrade --install prometheus-stack prometheus-community/kube-prometheus-stack \
|
||||
--namespace prometheus \
|
||||
--version 86.2.3 \
|
||||
--values "$repo/prometheus-stack/k8s/grafana-values.yaml" \
|
||||
--wait --timeout 10m
|
||||
fi
|
||||
if [ -f "$repo/loki/k8s/active" ] && ! is_disabled "$repo/loki/k8s"; then
|
||||
echo "== Upgrading loki/alloy =="
|
||||
helm repo add grafana https://grafana.github.io/helm-charts >/dev/null 2>&1 || true
|
||||
helm repo update grafana >/dev/null 2>&1 || true
|
||||
helm upgrade --install loki grafana/loki \
|
||||
--version 7.3.0 \
|
||||
--namespace prometheus \
|
||||
--values "$repo/loki/k8s/loki-values.yaml" \
|
||||
--wait --timeout 10m
|
||||
helm upgrade --install alloy grafana/alloy \
|
||||
--version 1.12.1 \
|
||||
--namespace prometheus \
|
||||
--values "$repo/loki/k8s/alloy-values.yaml" \
|
||||
--wait --timeout 10m
|
||||
fi
|
||||
|
||||
if [ "${#other_files[@]}" -gt 0 ]; then
|
||||
echo " resources: ${other_files[*]}"
|
||||
kubectl apply "${prune_opts[@]}" -f "${other_files[@]}"
|
||||
fi
|
||||
|
||||
for k in "${kustomize_apps[@]}"; do
|
||||
echo "== Applying kustomize app: ${k#$repo/} =="
|
||||
kubectl apply -k "$k"
|
||||
done
|
||||
|
||||
if [ -f "$repo/userbot/k8s/active" ] && ! is_disabled "$repo/userbot"; then
|
||||
echo "== userbot panel hook =="
|
||||
if kubectl get secret userbot-common-secrets -n userbot >/dev/null 2>&1; then
|
||||
echo " userbot-common-secrets already present in userbot ns, not touching"
|
||||
elif kubectl get secret userbot-common-secrets -n default >/dev/null 2>&1; then
|
||||
echo " bootstrapping userbot-common-secrets into userbot ns"
|
||||
kubectl get secret userbot-common-secrets -n default -o json \
|
||||
| jq 'del(.metadata.annotations,.metadata.creationTimestamp,.metadata.resourceVersion,.metadata.uid,.metadata.managedFields) | .metadata.namespace = "userbot"' \
|
||||
| kubectl apply -f -
|
||||
else
|
||||
echo " WARNING: userbot-common-secrets missing in both default and userbot ns; create it manually from the laptop"
|
||||
fi
|
||||
kubectl rollout restart deployment/userbot-panel -n userbot
|
||||
kubectl rollout status deployment/userbot-panel -n userbot --timeout=180s
|
||||
fi
|
||||
|
||||
echo "== Redeploying docker compose stacks =="
|
||||
for cf in "${compose_stacks[@]}"; do
|
||||
echo " compose: $cf"
|
||||
if grep -Eq '^\s+pull_policy:\s*build\b' "$cf"; then
|
||||
docker compose -f "$cf" build
|
||||
docker compose -f "$cf" push
|
||||
fi
|
||||
docker compose -f "$cf" up -d --pull always --remove-orphans
|
||||
done
|
||||
EOF
|
||||
@@ -0,0 +1,52 @@
|
||||
name: renovate-ci
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
validate-renovate:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Validate Renovate Compose draft
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
trap 'rm -f renovate/.env' EXIT
|
||||
printf '%s\n' \
|
||||
'RENOVATE_ENDPOINT=https://gitea.example/api/v1' \
|
||||
'RENOVATE_TOKEN=test-token' \
|
||||
'RENOVATE_REPOSITORIES=forust/homelab' \
|
||||
> renovate/.env
|
||||
docker compose -f renovate/renovate-compose.yaml config --quiet
|
||||
|
||||
- name: Validate Kubernetes manifests
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
docker run --rm \
|
||||
-v "$PWD:/work" \
|
||||
-w /work \
|
||||
ghcr.io/yannh/kubeconform:latest \
|
||||
-strict \
|
||||
-ignore-missing-schemas \
|
||||
-summary \
|
||||
renovate/k8s/namespace.yaml \
|
||||
renovate/k8s/configmap.yaml \
|
||||
renovate/k8s/cronjob.yaml
|
||||
|
||||
- name: Validate Renovate repository config
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
docker run --rm \
|
||||
-v "$PWD:/work" \
|
||||
-w /work \
|
||||
renovate/renovate:44.103.0 \
|
||||
renovate-config-validator renovate.json
|
||||
@@ -0,0 +1,69 @@
|
||||
name: renovate-run
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
repositories:
|
||||
description: "Repositories to scan (comma-separated)"
|
||||
required: false
|
||||
default: "forust/homelab"
|
||||
log_level:
|
||||
description: "Renovate log level"
|
||||
required: false
|
||||
default: "info"
|
||||
type: choice
|
||||
options:
|
||||
- info
|
||||
- debug
|
||||
dry_run:
|
||||
description: "Plan only, do not open or update PRs"
|
||||
required: false
|
||||
default: false
|
||||
type: boolean
|
||||
|
||||
concurrency:
|
||||
group: renovate-run
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
run-renovate:
|
||||
runs-on: [self-hosted, linux, arch, homelab]
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
|
||||
- name: Validate Renovate config
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
docker run --rm \
|
||||
-v "$PWD/renovate/config.js:/opt/renovate/config.js:ro" \
|
||||
-e RENOVATE_CONFIG_FILE=/opt/renovate/config.js \
|
||||
renovate/renovate:44.103.0 \
|
||||
renovate-config-validator
|
||||
|
||||
- name: Run Renovate
|
||||
shell: bash
|
||||
env:
|
||||
RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}
|
||||
RENOVATE_GITHUB_COM_TOKEN: ${{ secrets.RENOVATE_GITHUB_COM_TOKEN }}
|
||||
RENOVATE_REPOSITORIES: ${{ inputs.repositories }}
|
||||
RENOVATE_DRY_RUN: ${{ inputs.dry_run && 'full' || '' }}
|
||||
LOG_LEVEL: ${{ inputs.log_level }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
: "${RENOVATE_TOKEN:?missing RENOVATE_TOKEN secret — add a renovate-bot PAT in repo/org Actions secrets}"
|
||||
|
||||
docker run --rm \
|
||||
-v "$PWD/renovate/config.js:/opt/renovate/config.js:ro" \
|
||||
-e RENOVATE_PLATFORM=gitea \
|
||||
-e RENOVATE_ENDPOINT=https://gitea.forust.xyz/api/v1 \
|
||||
-e RENOVATE_TOKEN="$RENOVATE_TOKEN" \
|
||||
-e RENOVATE_GITHUB_COM_TOKEN="${RENOVATE_GITHUB_COM_TOKEN:-}" \
|
||||
-e RENOVATE_REPOSITORIES="${RENOVATE_REPOSITORIES:-forust/homelab}" \
|
||||
-e RENOVATE_DRY_RUN="${RENOVATE_DRY_RUN:-}" \
|
||||
-e RENOVATE_CONFIG_FILE=/opt/renovate/config.js \
|
||||
-e RENOVATE_BASE_DIR=/tmp/renovate \
|
||||
-e LOG_LEVEL="${LOG_LEVEL:-info}" \
|
||||
renovate/renovate:44.103.0
|
||||
+104
-19
@@ -2,27 +2,112 @@
|
||||
sync.ffs_lock
|
||||
.sync.ffs_db
|
||||
|
||||
# Copyparty
|
||||
*.hist/
|
||||
|
||||
# Volumes, configs and data directories
|
||||
gitea/gitea-db/
|
||||
gitea/gitea-data/*
|
||||
n8n/n8n-data/*
|
||||
n8n/n8n-node-data/*
|
||||
adguardhome/conf/*
|
||||
dockmon/data/*
|
||||
portainer/portainer_data/*
|
||||
metube/MeTube_downloads
|
||||
uptime-kuma/data/
|
||||
termix/termix-data/*
|
||||
cfddns/config.json
|
||||
checkmk/checkmk/*
|
||||
downtify/Downtify_downloads
|
||||
headscale/config/*
|
||||
headscale/data/*
|
||||
searxng/core-config/*
|
||||
|
||||
# Steaming services files
|
||||
streaming/jellyfin/*
|
||||
streaming/jellyseerr/*
|
||||
streaming/sonarr/*
|
||||
streaming/radarr/*
|
||||
streaming/data/*
|
||||
streaming/qbittorrent/*
|
||||
streaming/prowlarr/*
|
||||
|
||||
# Homepage
|
||||
homepages/forust_files/.well-known/*
|
||||
|
||||
# Traefik files
|
||||
traefik/letsencrypt/acme.json
|
||||
traefik/dynamic/fileservers.yml
|
||||
traefik/dynamic/*.local.y*ml.*
|
||||
traefik/dynamic/*.external.y*ml
|
||||
traefik/k8s/fileservers.y*ml
|
||||
traefik/k8s/aliasHeadersStrategy.md
|
||||
|
||||
traefik/logs/*
|
||||
|
||||
# SSL Certificates
|
||||
adguardhome/certs/*
|
||||
traefik/certs/*
|
||||
certs/
|
||||
|
||||
# Monitoring
|
||||
monitoring/prometheus.yml
|
||||
|
||||
# Python
|
||||
.python-version
|
||||
venv/
|
||||
pyc
|
||||
unknown_errors.txt
|
||||
moonlogs.txt
|
||||
thumb.jpg
|
||||
antipm_pic.jpg
|
||||
musicbot/
|
||||
.trunk/
|
||||
previous_profiles/
|
||||
.python-version
|
||||
/modules/__pycache__/
|
||||
__pycache__/
|
||||
*.session
|
||||
*.session-old
|
||||
*.db
|
||||
*.sqlite3
|
||||
*-journal
|
||||
/venv/
|
||||
.venv/
|
||||
|
||||
# DataSecurity
|
||||
replacements.txt
|
||||
|
||||
# Vscode
|
||||
.vscode
|
||||
|
||||
# Git
|
||||
.gitattributes
|
||||
# Gitea/github Runners
|
||||
.runner
|
||||
|
||||
# Misc
|
||||
.DS_Store
|
||||
.idea
|
||||
|
||||
# Temp files
|
||||
edu_master/temp/
|
||||
temp/*
|
||||
|
||||
# Environment
|
||||
.env
|
||||
.env.anna
|
||||
.env.forust
|
||||
.env.*
|
||||
!*example
|
||||
|
||||
# Volumes and data directories
|
||||
gitea/gitea-db/*
|
||||
gitea/gitea-data/*
|
||||
n8n/n8n-data/*
|
||||
n8n/n8n-node-data/*
|
||||
adguardhome/data/*
|
||||
dockmon/data/*
|
||||
portainer/portainer_data/*
|
||||
metube/MeTube_downloads
|
||||
|
||||
# Traefik files
|
||||
traefik/letsencrypt/acme.json
|
||||
traefik/logs/*
|
||||
traefik/certs/*
|
||||
|
||||
# Python
|
||||
.python-version
|
||||
.venv/
|
||||
venv/
|
||||
# kubernetes
|
||||
*/k8s/*secret*
|
||||
!*/k8s/*secret*.example
|
||||
**/k8s/*secret*
|
||||
!**/k8s/*secret*.example
|
||||
# Local-only tweaks, not for upstream
|
||||
prometheus-stack/k8s/grafana-values.yaml
|
||||
traefik/k8s/local-tls.yaml
|
||||
converters/k8s/config.yaml
|
||||
convertx/k8s/config.yaml
|
||||
@@ -0,0 +1,10 @@
|
||||
ignored:
|
||||
- DL3008
|
||||
- DL3042
|
||||
- DL3018
|
||||
- DL3059
|
||||
trustedRegistries:
|
||||
- docker.io
|
||||
- ghcr.io
|
||||
- quay.io
|
||||
- gcr.forust.xyz
|
||||
@@ -0,0 +1,8 @@
|
||||
{
|
||||
"default": true,
|
||||
"MD013": false,
|
||||
"MD024": false,
|
||||
"MD033": false,
|
||||
"MD041": false,
|
||||
"MD046": false
|
||||
}
|
||||
@@ -0,0 +1,7 @@
|
||||
bracketSameLine: true
|
||||
htmlWhitespaceSensitivity: css
|
||||
printWidth: 120
|
||||
tabWidth: 2
|
||||
trailingComma: all
|
||||
proseWrap: preserve
|
||||
endOfLine: lf
|
||||
@@ -0,0 +1,22 @@
|
||||
extends: default
|
||||
|
||||
rules:
|
||||
comments:
|
||||
min-spaces-from-content: 1
|
||||
comments-indentation: false
|
||||
document-start: disable
|
||||
line-length: disable
|
||||
braces:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 1
|
||||
brackets:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 1
|
||||
indentation:
|
||||
spaces: 2
|
||||
indent-sequences: consistent
|
||||
truthy:
|
||||
allowed-values:
|
||||
- "true"
|
||||
- "false"
|
||||
- "on"
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"tab_size": 2,
|
||||
"soft_wrap": "prefer_line",
|
||||
"preferred_line_length": 120,
|
||||
"format_on_save": "on",
|
||||
"languages": {
|
||||
"YAML": {
|
||||
"tab_size": 2,
|
||||
"hard_tabs": false,
|
||||
"format_on_save": "on",
|
||||
"formatter": {
|
||||
"language_server": { "name": "yaml-language-server" },
|
||||
},
|
||||
},
|
||||
"Python": {
|
||||
"tab_size": 4,
|
||||
"format_on_save": "on",
|
||||
"language_servers": ["pyright", "ruff"],
|
||||
"formatter": {
|
||||
"language_server": { "name": "ruff" },
|
||||
},
|
||||
},
|
||||
},
|
||||
"lsp": {
|
||||
"yaml-language-server": {
|
||||
"settings": {
|
||||
"yaml": {
|
||||
"schemas": {
|
||||
"kubernetes": ["**/k8s/*.yaml", "**/k8s/*.yml"],
|
||||
},
|
||||
"validate": true,
|
||||
"completion": true,
|
||||
"format": {
|
||||
"enable": true,
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
+31
-11
@@ -1,28 +1,48 @@
|
||||
services:
|
||||
adguard:
|
||||
image: adguard/adguardhome:latest
|
||||
image: adguard/adguardhome:v0.107.79
|
||||
container_name: adguardhome
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- TZ=${TZ}
|
||||
ports:
|
||||
- "53:53/tcp"
|
||||
- "53:53/udp"
|
||||
- "853:853/tcp" # DNS over TLS
|
||||
# - "67:67/udp" # DHCP
|
||||
# - "68:68/tcp" # DHCP
|
||||
- "3000:3000/tcp"
|
||||
# - "3000:3000/tcp"
|
||||
volumes:
|
||||
- ./data/work:/opt/adguardhome/work
|
||||
- ./data/conf:/opt/adguardhome/conf
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- data:/opt/adguardhome/work
|
||||
- ./conf:/opt/adguardhome/conf
|
||||
- ./certs:/certs:ro
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
||||
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)"
|
||||
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)"
|
||||
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard-dev.tls=true"
|
||||
# DoH Router
|
||||
- "traefik.http.routers.dns-over-https.rule=(Host(`dns.forust.xyz` || Host(`adguard.forust.xyz`)) && PathPrefix(`/dns-query`))"
|
||||
- "traefik.http.routers.dns-over-https.entrypoints=websecure"
|
||||
- "traefik.http.routers.dns-over-https.tls.certresolver=letsencrypt"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=adguard
|
||||
# - glance.icon=si:adguard
|
||||
- glance.url=https://adguard.forust.xyz/
|
||||
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
Whitespace-only changes.
@@ -0,0 +1,118 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: adguard-lb-service
|
||||
namespace: adguard
|
||||
annotations:
|
||||
metallb.io/loadBalancerIPs: "192.168.80.3"
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
externalTrafficPolicy: Local
|
||||
selector:
|
||||
app: adguard
|
||||
ports:
|
||||
- name: dns-udp
|
||||
port: 53
|
||||
targetPort: 53
|
||||
protocol: UDP
|
||||
- name: dns-tcp
|
||||
port: 53
|
||||
targetPort: 53
|
||||
protocol: TCP
|
||||
- name: dot
|
||||
port: 853
|
||||
targetPort: 853
|
||||
protocol: TCP
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: adguard-service
|
||||
namespace: adguard
|
||||
spec:
|
||||
selector:
|
||||
app: adguard
|
||||
ports:
|
||||
- port: 3000
|
||||
name: webui
|
||||
targetPort: 3000
|
||||
- port: 53
|
||||
name: dns
|
||||
targetPort: 53
|
||||
protocol: UDP
|
||||
- port: 53
|
||||
name: dns-tcp
|
||||
targetPort: 53
|
||||
protocol: TCP
|
||||
- port: 853
|
||||
name: dot
|
||||
targetPort: 853
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: adguard-deployment
|
||||
namespace: adguard
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: adguard
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: adguard
|
||||
annotations:
|
||||
reloader.stakater.com/auto: "true"
|
||||
spec:
|
||||
containers:
|
||||
- name: adguard
|
||||
image: adguard/adguardhome:v0.107.79
|
||||
resources:
|
||||
limits:
|
||||
memory: "1.5Gi"
|
||||
cpu: "300m"
|
||||
requests:
|
||||
memory: "500Mi"
|
||||
cpu: "50m"
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
name: webui
|
||||
- containerPort: 53
|
||||
name: dns
|
||||
- containerPort: 853
|
||||
name: dot
|
||||
volumeMounts:
|
||||
- name: adguard-data
|
||||
mountPath: /opt/adguardhome/work
|
||||
subPath: work
|
||||
- name: adguard-data
|
||||
mountPath: /opt/adguardhome/conf
|
||||
subPath: conf
|
||||
- name: adguard-certs
|
||||
mountPath: /certs
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: adguard-data
|
||||
persistentVolumeClaim:
|
||||
claimName: adguard-pvc
|
||||
- name: adguard-certs
|
||||
secret:
|
||||
secretName: adguard-certs
|
||||
items:
|
||||
- key: tls.crt
|
||||
path: fullchain.pem
|
||||
- key: tls.key
|
||||
path: privkey.pem
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: adguard-pvc
|
||||
namespace: adguard
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 2Gi
|
||||
@@ -0,0 +1,12 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: adguard-certs
|
||||
namespace: adguard
|
||||
spec:
|
||||
secretName: adguard-certs
|
||||
dnsNames:
|
||||
- dns.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,46 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: adguard-prod
|
||||
namespace: adguard
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`dns.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
services:
|
||||
- name: adguard-service
|
||||
port: 3000
|
||||
- match: (Host(`dns.forust.xyz`)) && PathPrefix(`/dns-query`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: adguard-service
|
||||
port: 3000
|
||||
tls:
|
||||
secretName: adguard-certs
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: adguard-local
|
||||
namespace: adguard
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`) || Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: adguard-service
|
||||
port: 3000
|
||||
- match: (Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`) || Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)) && PathPrefix(`/dns-query`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: adguard-service
|
||||
port: 3000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,15 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: adguard
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: adguard
|
||||
@@ -0,0 +1,10 @@
|
||||
kubectl apply -f k8s/namespace.yaml && \
|
||||
kubectl create secret tls adguard-certs -n adguard \
|
||||
--cert=certs/fullchain.pem \
|
||||
--key=certs/privkey.pem --dry-run=client -o yaml > \
|
||||
k8s/secrets.yaml
|
||||
|
||||
# OR WITH NO FILE CREATION:
|
||||
kubectl create secret tls adguard-certs -n adguard \
|
||||
--cert=certs/fullchain.pem --key=certs/privkey.pem \
|
||||
--save-config
|
||||
@@ -0,0 +1,20 @@
|
||||
# ===================================
|
||||
# Authentification app (authentik)
|
||||
|
||||
# PostgresQL conf
|
||||
PG_PASS=change_this_cuz_its_ur_db_pass
|
||||
PG_USER=authentik # it's okay
|
||||
|
||||
# Image Settings
|
||||
AUTHENTIK_IMAGE=ghcr.io/goauthentik/server
|
||||
AUTHENTIK_TAG=2025.10.2
|
||||
|
||||
# Networking
|
||||
PORT_HTTP=9000
|
||||
PORT_HTTPS=9443 # btw likely already used by portainer
|
||||
|
||||
AUTHENTIK_SECRET_KEY=super_secret_super_scary_authenik_key
|
||||
|
||||
AUTHENTIK_BOOTSTRAP_PASSWORD=pls_change_this
|
||||
|
||||
AUTHENTIK_ERROR_REPORTING__ENABLED=true # Or false to turn off
|
||||
@@ -0,0 +1,95 @@
|
||||
services:
|
||||
postgresql:
|
||||
image: docker.io/library/postgres:15.19-alpine
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
POSTGRES_DB: ${PG_DB:-authentik}
|
||||
POSTGRES_PASSWORD: ${PG_PASS:?database password required}
|
||||
POSTGRES_USER: ${PG_USER:-authentik}
|
||||
healthcheck:
|
||||
interval: 30s
|
||||
retries: 5
|
||||
start_period: 20s
|
||||
test:
|
||||
- CMD-SHELL
|
||||
- pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}
|
||||
timeout: 5s
|
||||
volumes:
|
||||
- database:/var/lib/postgresql/data
|
||||
networks:
|
||||
- authentik
|
||||
|
||||
server:
|
||||
image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.10.2}
|
||||
command: server
|
||||
container_name: authentik-server
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - ${PORT_HTTP:-9000}:9000
|
||||
# - ${PORT_HTTPS:-9443}:9443
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
||||
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||
volumes:
|
||||
- ./media:/media
|
||||
- ./custom-templates:/templates
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.authentik-server.rule=Host(`auth.forust.xyz`)"
|
||||
- "traefik.http.routers.authentik-server.entrypoints=websecure"
|
||||
- "traefik.http.routers.authentik-server.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`)"
|
||||
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.authentik-server-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
||||
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.authentik-server-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
- authentik
|
||||
depends_on:
|
||||
postgresql:
|
||||
condition: service_healthy
|
||||
worker:
|
||||
image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.10.2}
|
||||
restart: unless-stopped
|
||||
user: root
|
||||
command: worker
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
||||
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./media:/media
|
||||
- ./certs:/certs
|
||||
- ./custom-templates:/templates
|
||||
networks:
|
||||
- authentik
|
||||
depends_on:
|
||||
postgresql:
|
||||
condition: service_healthy
|
||||
volumes:
|
||||
database:
|
||||
driver: local
|
||||
networks:
|
||||
authentik:
|
||||
proxy:
|
||||
external: true
|
||||
Whitespace-only changes.
@@ -0,0 +1,93 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: authentik-server-service
|
||||
namespace: authentik
|
||||
spec:
|
||||
type: ClusterIP
|
||||
selector:
|
||||
app: authentik-server
|
||||
ports:
|
||||
- port: 9000
|
||||
targetPort: 9000
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: authentik-worker-service
|
||||
namespace: authentik
|
||||
spec:
|
||||
type: ClusterIP
|
||||
selector:
|
||||
app: authentik-worker
|
||||
ports:
|
||||
- port: 9000
|
||||
targetPort: 9000
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: authentik-server-deployment
|
||||
namespace: authentik
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: authentik-server
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: authentik-server
|
||||
spec:
|
||||
containers:
|
||||
- name: authentik-server
|
||||
image: ghcr.io/goauthentik/server:2026.8.3
|
||||
args: ["server"]
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: authentik-config
|
||||
- secretRef:
|
||||
name: authentik-secrets
|
||||
ports:
|
||||
- containerPort: 9000
|
||||
resources:
|
||||
requests:
|
||||
memory: "700Mi"
|
||||
cpu: "300m"
|
||||
limits:
|
||||
memory: "1.5Gi"
|
||||
cpu: "1000m"
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: authentik-worker-deployment
|
||||
namespace: authentik
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: authentik-worker
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: authentik-worker
|
||||
spec:
|
||||
containers:
|
||||
- name: authentik-worker
|
||||
image: ghcr.io/goauthentik/server:2026.8.3
|
||||
args: ["worker"]
|
||||
securityContext:
|
||||
runAsUser: 0
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: authentik-config
|
||||
- secretRef:
|
||||
name: authentik-secrets
|
||||
resources:
|
||||
requests:
|
||||
memory: "512Mi"
|
||||
cpu: "300m"
|
||||
limits:
|
||||
memory: "1Gi"
|
||||
cpu: "700m"
|
||||
@@ -0,0 +1,28 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: authentik-prod-tls
|
||||
namespace: authentik
|
||||
spec:
|
||||
secretName: authentik-prod-tls
|
||||
dnsNames:
|
||||
- auth.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: authentik
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,11 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: authentik-config
|
||||
namespace: authentik
|
||||
data:
|
||||
AUTHENTIK_IMAGE: ghcr.io/goauthentik/server
|
||||
AUTHENTIK_TAG: "2025.10.2"
|
||||
AUTHENTIK_POSTGRESQL__HOST: postgres.database.svc.cluster.local
|
||||
AUTHENTIK_POSTGRESQL__NAME: authentik
|
||||
AUTHENTIK_ERROR_REPORTING__ENABLED: "true"
|
||||
@@ -0,0 +1,36 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: authentik-prod
|
||||
namespace: authentik
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`auth.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
services:
|
||||
- name: authentik-server-service
|
||||
port: 9000
|
||||
tls:
|
||||
secretName: authentik-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: authentik-local
|
||||
namespace: authentik
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`auth.workstation.internal`) || Host(`auth.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: authentik-server-service
|
||||
port: 9000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: authentik
|
||||
@@ -0,0 +1,11 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: authentik-secrets
|
||||
namespace: authentik
|
||||
type: Opaque
|
||||
stringData:
|
||||
AUTHENTIK_SECRET_KEY: ""
|
||||
AUTHENTIK_POSTGRESQL__PASSWORD: ""
|
||||
AUTHENTIK_POSTGRESQL__USER: authentik
|
||||
AUTHENTIK_BOOTSTRAP_PASSWORD: authentik
|
||||
@@ -0,0 +1,9 @@
|
||||
crds:
|
||||
enabled: true
|
||||
prometheus:
|
||||
servicemonitor:
|
||||
enabled: true
|
||||
interval: 60s
|
||||
scrapeTimeout: 30s
|
||||
labels:
|
||||
release: prometheus-stack
|
||||
@@ -0,0 +1,29 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: letsencrypt-staging
|
||||
spec:
|
||||
acme:
|
||||
email: bobrovod@national.shitposting.agency
|
||||
server: https://acme-staging-v02.api.letsencrypt.org/directory
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-staging-account-key
|
||||
solvers:
|
||||
- http01:
|
||||
ingress:
|
||||
class: traefik
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: letsencrypt-prod
|
||||
spec:
|
||||
acme:
|
||||
email: bobrovod@national.shitposting.agency
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-prod-account-key
|
||||
solvers:
|
||||
- http01:
|
||||
ingress:
|
||||
class: traefik
|
||||
@@ -0,0 +1,30 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIFFjCCAv6gAwIBAgIUetKpTfEDOn2985FFMu6G26itT+wwDQYJKoZIhvcNAQEN
|
||||
BQAwIzEhMB8GA1UEAxMYaG9tZWxhYiBpbnRlcm5hbCByb290IENBMB4XDTI2MDky
|
||||
MzEyNDA0N1oXDTM2MDkyMDEyNDA0N1owIzEhMB8GA1UEAxMYaG9tZWxhYiBpbnRl
|
||||
cm5hbCByb290IENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAvmNP
|
||||
ZCOoD8NtNuYJKVXBlTPjX7D7sJCSK5neH7ZbYV5+lmUlEErY8Mik7j37V5k5NfpF
|
||||
Ig85pOjP7RckTPz5V6ek3yaN40s4AL053sN5ZPauDVYjalaEHTgj5sEMqlLACQWI
|
||||
yZmJOZspZykae8dIpQnqCoFpRT4FurJ78v4a0ylnFVLMQn/lyCHedwTjkEdtYWYr
|
||||
ccJy8vQwqkzs/rWvEH1lDqZhennLOrmcCjfonG7D/pruMn4z+6E28p4+ejkRrI6x
|
||||
luak3KnpT1XMeHtgU21hiRGaMDBchHMFgAhnY1qosymKenXvfTZItwgjZbwa1hJI
|
||||
GAiDm+jQDKMjzRZ3rH6Xfc0auUcykNz73PpNu1NGm78nndXwCXcXn1LFKNQJ+r1U
|
||||
sJiyAmUZmXVn4aM4OMf2F38k7wTYIKg7nRGaUkNeKDlNkjA4HvgWw+jwO1KmdHQ/
|
||||
mOem1rosDWHRK01wg+Gga9mQCnhNhxglg3t/UeSic6uOaRsvaz4qkzHq8MbCujVz
|
||||
DpKQjqdikYOAXZOs4KlBLWrS7NaK4NzfSD02pBUErh54ruJfY/bWz9KyXzBD/lQZ
|
||||
VUTKyvUVB0bkVHEdf1jJmX3H4IZRQSF5JPqOBotW6bJI5fEGNBvj9Zxy4nm2WWGz
|
||||
yyP3uWsQz8U/Wdx9nXZLHInTZBsvgLYtKUAWA30CAwEAAaNCMEAwDgYDVR0PAQH/
|
||||
BAQDAgKkMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFEkKm2rxPaK6+O9WD80z
|
||||
BLC6F9QsMA0GCSqGSIb3DQEBDQUAA4ICAQAnFyHz97Umf5VIu+dKTJid7C73VugJ
|
||||
TIar/xJBs/4CxP+znBxhJjXygRoyIfzoVGWcB2ZSL//vL78Qlts79K/Imc9a4RFF
|
||||
wMvCxsRXAEQ4TpeWi3ophPNcs4rhsP+gQKQFtnyKP9519bqpfxp0bTqwOV2o18fn
|
||||
za7rlQViiEnNV58j7CVoM9+mJvVVfBEX1Km+GyJL9GadzbIQ7FxClVJZefCbft93
|
||||
zHVk9gDOw8ys1XGSR2OUCyCLinXO6mqS16CmBb2MAKXq/YyH7E0N8iotAPGtfA8V
|
||||
M/0ddy947rY0xCrtECfWwvGQpJS7NRv/Z9b2jCfXrI5LXmL2nfQRg0y9GE4Vjwr+
|
||||
WxtGU5jOeFt0jQ+xRzcgG0Op+qK3x55l5LSo2hOcOVYbiHxcHEJFgwNi1ADeBFwb
|
||||
q/HdysfURSOghqjIpMMAUabBp+DBUg2EUF7pIaUqbdqExFYcr9EYisEMiNsmKmN+
|
||||
8ZbcOeerFKDQj+t/R0bFXa7UBn2UWsjI8zlR74aa2kLDXwtyz/XlO/FlYm66eBFo
|
||||
2/eYUSeU+S4ej+wUAs/dvjF7f190/DUQGuwOTlLTahqWDztmhCk7qzbECu56CwKT
|
||||
E5Ect2P72UleYwdblkVOVd352AmiwEzdOaziIRrPh8uenEknH6JBYPO3mjk7cCg+
|
||||
GPGcNIBctjdXhg==
|
||||
-----END CERTIFICATE-----
|
||||
@@ -0,0 +1,33 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: selfsigned
|
||||
spec:
|
||||
selfSigned: {}
|
||||
---
|
||||
# Homelab internal root CA (10y). Install the .crt on clients (see below).
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-ca-root
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
isCA: true
|
||||
commonName: homelab internal root CA
|
||||
duration: 87600h
|
||||
renewBefore: 7200h
|
||||
secretName: internal-ca-root
|
||||
privateKey:
|
||||
algorithm: RSA
|
||||
size: 4096
|
||||
issuerRef:
|
||||
name: selfsigned
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: internal-ca
|
||||
spec:
|
||||
ca:
|
||||
secretName: internal-ca-root
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: cert-manager
|
||||
@@ -0,0 +1,15 @@
|
||||
CLOUDFLARE_API_TOKEN=YOUR_CLOUDFLARE_API_TOKEN
|
||||
DOMAINS=example.com,dns.example.com,mc.example.com,auth.example.com,ssh.example.com
|
||||
IP4_DOMAINS=
|
||||
IP6_DOMAINS=
|
||||
IP4_PROVIDER=cloudflare.trace
|
||||
IP6_PROVIDER=none # change if you want to update AAAA
|
||||
UPDATE_CRON=@every 5m
|
||||
UPDATE_ON_START=true
|
||||
DELETE_ON_STOP=false
|
||||
DELETE_ON_FAILURE=true
|
||||
TTL=1
|
||||
PROXIED=!is(dns.example.com) && !is(mc.example.com) && !is(ssh.example.com)
|
||||
EMOJI=true
|
||||
UPTIMEKUMA=https://uptime-kuma.example.com/api/push/AsaSDFGFkfklaFALSKffkfFKfkfkfkFK?status=up&msg=OK&ping=
|
||||
REJECT_CLOUDFLARE_IPS=true
|
||||
@@ -0,0 +1,30 @@
|
||||
services:
|
||||
cloudflare-ddns:
|
||||
image: timothyjmiller/cloudflare-ddns:2.2.0
|
||||
container_name: cloudflare-ddns
|
||||
restart: unless-stopped
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
network_mode: "host"
|
||||
# https://github.com/timothymiller/cloudflare-ddns#-quick-start
|
||||
environment:
|
||||
- CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN:?Cloudflare API token is required}
|
||||
- DOMAINS=${DOMAINS:-}
|
||||
- IP4_DOMAINS=${IP4_DOMAINS:-}
|
||||
- IP6_DOMAINS=${IP6_DOMAINS:-}
|
||||
- IP4_PROVIDER=${IP4_PROVIDER:-cloudflare.trace}
|
||||
- IP6_PROVIDER=${IP6_PROVIDER:-none}
|
||||
- UPDATE_CRON=${UPDATE_CRON:-@every 5m}
|
||||
- UPDATE_ON_START=${UPDATE_ON_START:-true}
|
||||
- DELETE_ON_STOP=${DELETE_ON_STOP:-false}
|
||||
- DELETE_ON_FAILURE=${DELETE_ON_FAILURE:-true}
|
||||
- TTL=${TTL:-1} # 1=auto
|
||||
# to proxy only "dns.example.com" and "wfs.example.com" use "!is(dns.domain.com) && !is (wfs.domain.com)"
|
||||
- PROXIED=${PROXIED:-true}
|
||||
- EMOJI=${EMOJI:-true}
|
||||
- UPTIMEKUMA=${UPTIMEKUMA:-}
|
||||
- HEALTHCHECKS=${HEALTHCHECKS:-}
|
||||
- REJECT_CLOUDFLARE_IPS=${REJECT_CLOUDFLARE_IPS:-true}
|
||||
# volumes:
|
||||
# Prefer using environment variables for configuration, config.json legacy support
|
||||
# - ./config.json:/config.json
|
||||
@@ -0,0 +1,22 @@
|
||||
{
|
||||
"cloudflare": [
|
||||
{
|
||||
"authentication": {
|
||||
"api_token": "API_TOKEN"
|
||||
},
|
||||
"api_key": {
|
||||
"api_key": "api_key_here",
|
||||
"account_email": "your_email_here"
|
||||
},
|
||||
"zone_id": "your_zone-id",
|
||||
"subdomains": [
|
||||
{ "name": "", "proxied": true },
|
||||
{ "name": "www", "proxied": true }
|
||||
]
|
||||
}
|
||||
],
|
||||
"a": true,
|
||||
"aaaa": false,
|
||||
"purgeUnknownRecords": false,
|
||||
"ttl": 300
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
secret.yaml
|
||||
Whitespace-only changes.
@@ -0,0 +1,32 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: cfddns
|
||||
labels:
|
||||
app: cfddns
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: cfddns
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: cfddns
|
||||
spec:
|
||||
hostNetwork: true
|
||||
dnsPolicy: ClusterFirstWithHostNet
|
||||
containers:
|
||||
- name: cloudflare-ddns
|
||||
image: timothyjmiller/cloudflare-ddns:2.2.0
|
||||
imagePullPolicy: Always
|
||||
resources:
|
||||
requests:
|
||||
memory: "20Mi"
|
||||
cpu: "30m"
|
||||
limits:
|
||||
memory: "64Mi"
|
||||
cpu: "50m"
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: cfddns-secrets
|
||||
@@ -0,0 +1,18 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: cfddns-secrets
|
||||
type: Opaque
|
||||
stringData:
|
||||
CLOUDFLARE_API_TOKEN: your_token
|
||||
DOMAINS: "example.com,www.example.com"
|
||||
IP4_PROVIDER: cloudflare.trace
|
||||
IP6_PROVIDER: none
|
||||
UPDATE_CRON: "@every 5m"
|
||||
UPDATE_ON_START: "true"
|
||||
DELETE_ON_STOP: "false"
|
||||
DELETE_ON_FAILURE: "true"
|
||||
TTL: "1"
|
||||
PROXIED: "true"
|
||||
EMOJI: "true"
|
||||
REJECT_CLOUDFLARE_IPS: "true"
|
||||
@@ -0,0 +1,2 @@
|
||||
CMK_PASSWORD=password
|
||||
TZ=Europe/Berlin
|
||||
@@ -0,0 +1,39 @@
|
||||
services:
|
||||
checkmk:
|
||||
image: "checkmk/check-mk-raw:2.4.0-2026.09.14"
|
||||
container_name: "checkmk"
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - 5000:5000
|
||||
# - 6776:8000
|
||||
volumes:
|
||||
- sites:/omd/sites
|
||||
tmpfs:
|
||||
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
|
||||
environment:
|
||||
- CMK_PASSWORD=${CMK_PASSWORD:-password}
|
||||
- CMK_SITE_ID=cmk
|
||||
- TZ=${TZ:-Etc/UTC}
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.checkmk.loadbalancer.server.port=5000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
||||
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)"
|
||||
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
|
||||
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
volumes:
|
||||
sites:
|
||||
Whitespace-only changes.
@@ -0,0 +1,28 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: checkmk-prod-tls
|
||||
namespace: checkmk
|
||||
spec:
|
||||
secretName: checkmk-prod-tls
|
||||
dnsNames:
|
||||
- cmk.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: checkmk
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,75 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: checkmk-service
|
||||
namespace: checkmk
|
||||
spec:
|
||||
selector:
|
||||
app: checkmk
|
||||
ports:
|
||||
- name: web
|
||||
port: 5000
|
||||
targetPort: 5000
|
||||
- name: agent-receiver
|
||||
port: 8000
|
||||
targetPort: 8000
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: checkmk-deployment
|
||||
namespace: checkmk
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: checkmk
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: checkmk
|
||||
spec:
|
||||
containers:
|
||||
- name: checkmk
|
||||
image: checkmk/check-mk-raw:2.4.0-2026.09.14
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: checkmk-secrets
|
||||
- configMapRef:
|
||||
name: checkmk-config
|
||||
ports:
|
||||
- name: web
|
||||
containerPort: 5000
|
||||
- name: agent-receiver
|
||||
containerPort: 8000
|
||||
volumeMounts:
|
||||
- name: sites
|
||||
mountPath: /omd/sites
|
||||
- name: tmp
|
||||
mountPath: /opt/omd/sites/cmk/tmp
|
||||
resources:
|
||||
requests:
|
||||
memory: "2Gi"
|
||||
cpu: "600m"
|
||||
limits:
|
||||
memory: "5Gi"
|
||||
cpu: "4"
|
||||
volumes:
|
||||
- name: sites
|
||||
persistentVolumeClaim:
|
||||
claimName: checkmk-sites-pvc
|
||||
- name: tmp
|
||||
emptyDir:
|
||||
medium: Memory
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: checkmk-sites-pvc
|
||||
namespace: checkmk
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 5Gi
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: checkmk-config
|
||||
namespace: checkmk
|
||||
data:
|
||||
TZ: Europe/Bratislava
|
||||
CMK_SITE_ID: cmk
|
||||
@@ -0,0 +1,52 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: checkmk-prod
|
||||
namespace: checkmk
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`cmk.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
services:
|
||||
- name: checkmk-service
|
||||
port: 5000
|
||||
tls:
|
||||
secretName: checkmk-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRouteTCP
|
||||
metadata:
|
||||
name: checkmk-agent-receiver
|
||||
namespace: checkmk
|
||||
spec:
|
||||
entryPoints:
|
||||
- checkmk-agent
|
||||
routes:
|
||||
- match: HostSNI(`*`)
|
||||
services:
|
||||
- name: checkmk-service
|
||||
port: 8000
|
||||
tls:
|
||||
passthrough: true
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: checkmk-local
|
||||
namespace: checkmk
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`cmk.workstation.internal`) || Host(`cmk.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: checkmk-service
|
||||
port: 5000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: checkmk
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: checkmk-secrets
|
||||
namespace: checkmk
|
||||
type: Opaque
|
||||
stringData:
|
||||
CMK_PASSWORD: "password"
|
||||
@@ -0,0 +1 @@
|
||||
secret.yaml
|
||||
Whitespace-only changes.
@@ -0,0 +1,37 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: cloudflared
|
||||
labels:
|
||||
app: cloudflared
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: cloudflared
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: cloudflared
|
||||
spec:
|
||||
containers:
|
||||
- name: cloudflared
|
||||
image: cloudflare/cloudflared:2026.9.1
|
||||
imagePullPolicy: IfNotPresent
|
||||
args:
|
||||
- tunnel
|
||||
- --no-autoupdate
|
||||
- run
|
||||
env:
|
||||
- name: TUNNEL_TOKEN
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: cloudflared-secrets
|
||||
key: TUNNEL_TOKEN
|
||||
resources:
|
||||
requests:
|
||||
memory: "32Mi"
|
||||
cpu: "30m"
|
||||
limits:
|
||||
memory: "128Mi"
|
||||
cpu: "200m"
|
||||
@@ -0,0 +1,7 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: cloudflared-secrets
|
||||
type: Opaque
|
||||
stringData:
|
||||
TUNNEL_TOKEN: your_tunnel_token_here
|
||||
@@ -0,0 +1,9 @@
|
||||
ACCOUNT_REGISTRATION=false
|
||||
HTTP_ALLOWED=false
|
||||
ALLOW_UNAUTHENTICAED=false
|
||||
AUTO_DELETE_EVERY_N_HOURS=24
|
||||
WEBROOT=/convert
|
||||
HIDE_HISTORY=false
|
||||
LANGUAGE=en
|
||||
UNAUTHED_USER_SHARING=false
|
||||
MAX_CONVERT_PROCESS=0
|
||||
@@ -0,0 +1,70 @@
|
||||
services:
|
||||
convertx:
|
||||
container_name: convertx
|
||||
image: ghcr.io/c4illin/convertx:v0.18.0
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "9992:3000"
|
||||
# https://github.com/C4illin/ConvertX#environment-variables
|
||||
environment:
|
||||
- JWT_SECRET=$(JWT_SECRET)
|
||||
- ACCOUNT_REGISTRATION=$(ACCOUNT_REGISTRATION:-false)
|
||||
- HTTP_ALLOWED=$(HTTP_ALLOWED:-false)
|
||||
- ALLOW_UNAUTHENTICATED=$(ALLOW_UNAUTHENTICATED:-false)
|
||||
- AUTO_DELETE_EVERY_N_HOURS=$(AUTO_DELETE_EVERY_N_HOURS:-24)
|
||||
- WEBROOT=$(WEBROOT)
|
||||
- HIDE_HISTORY=$(HIDE_HISTORY:-false)
|
||||
- LANGUAGE=$(LANGUAGE:-en)
|
||||
- UNAUTHENTICATED_USER_SHARING=$(UNAUTHENTICATED_USER_SHARING:-false)
|
||||
- MAX_CONVERT_PROCESS=$(MAX_CONVERT_PROCESS:-0)
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.convertx.loadbalancer.server.port=3000"
|
||||
# Prod Router
|
||||
- "traefik.http.routers.convertx.rule=(Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/convert`)"
|
||||
- "traefik.http.routers.convertx.entrypoints=websecure"
|
||||
- "traefik.http.routers.convertx.priority=50"
|
||||
- "traefik.http.routers.convertx.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.convertx-local.rule=Host(`workstation.internal`) && PathPrefix(`/convert`)"
|
||||
- "traefik.http.routers.convertx-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.convertx-local.priority=50"
|
||||
- "traefik.http.routers.convertx-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.convertx-dev.rule=Host(`gigaforust.internal`) && PathPrefix(`/convert`)"
|
||||
- "traefik.http.routers.convertx-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.convertx-dev.priority=50"
|
||||
- "traefik.http.routers.convertx-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
- data:/app/data
|
||||
|
||||
bentopdf:
|
||||
container_name: bentopdf
|
||||
image: bentopdf/bentopdf@sha256:4eb4ec8f5030faf87c29a73d3d5a2781f28a597cf440c3ab111eb96aee550871
|
||||
restart: unless-stopped
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.bentopdf.loadbalancer.server.port=8080"
|
||||
|
||||
# Prod router
|
||||
- "traefik.http.routers.bentopdf.rule=Host(`pdf.forust.xyz`)"
|
||||
- "traefik.http.routers.bentopdf.entrypoints=websecure"
|
||||
- "traefik.http.routers.bentopdf.tls.certresolver=letsencrypt"
|
||||
- "traefik.http.routers.bentopdf.tls=true"
|
||||
# Local router
|
||||
- "traefik.http.routers.bentopdf-local.rule=Host(`pdf.wokstation.internal`)"
|
||||
- "traefik.http.routers.bentopdf-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.bentopdf-local.tls=true"
|
||||
# Dev router
|
||||
- "traefik.http.routers.bentopdf-dev.rule=Host(`pdf.gigaforust.internal`)"
|
||||
- "traefik.http.routers.bentopdf-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.bentopdf-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
volumes:
|
||||
data:
|
||||
Whitespace-only changes.
@@ -0,0 +1,42 @@
|
||||
kind: Service
|
||||
apiVersion: v1
|
||||
metadata:
|
||||
name: bentopdf-service
|
||||
namespace: converters
|
||||
spec:
|
||||
selector:
|
||||
app: bentopdf
|
||||
ports:
|
||||
- port: 8080
|
||||
targetPort: 8080
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: bentopdf-deployment
|
||||
namespace: converters
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: bentopdf
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: bentopdf
|
||||
spec:
|
||||
containers:
|
||||
- image: bentopdf/bentopdf@sha256:4eb4ec8f5030faf87c29a73d3d5a2781f28a597cf440c3ab111eb96aee550871
|
||||
imagePullPolicy: Always
|
||||
name: bentopdf
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
resources:
|
||||
requests:
|
||||
memory: "50Mi"
|
||||
cpu: "50m"
|
||||
ephemeral-storage: "100Mi"
|
||||
limits:
|
||||
memory: "700Mi"
|
||||
cpu: "700m"
|
||||
ephemeral-storage: "5Gi"
|
||||
@@ -0,0 +1,42 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: convertx-prod-tls
|
||||
namespace: converters
|
||||
spec:
|
||||
secretName: convertx-prod-tls
|
||||
dnsNames:
|
||||
- forust.xyz
|
||||
- www.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: bentopdf-prod-tls
|
||||
namespace: converters
|
||||
spec:
|
||||
secretName: bentopdf-prod-tls
|
||||
dnsNames:
|
||||
- pdf.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: converters
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,16 @@
|
||||
# test manifest with docker and k8s config keys mismatch
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: convertx-config
|
||||
namespace: converters
|
||||
data:
|
||||
ACCOUNT_REGISTRATION: "false"
|
||||
HTTP_ALLOWED: "false"
|
||||
ALLOW_UNAUTHENTICAED: "false"
|
||||
AUTO_DELETE_EVERY_N_HOURS: "24"
|
||||
WEBROOT: "/convert"
|
||||
HIDE_HISTORY: "false"
|
||||
LANGUAGE: "en"
|
||||
UNAUTHED_USER_SHARING: "false"
|
||||
MAX_CONVERT_PROCESS: "0"
|
||||
@@ -0,0 +1,63 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: convertx-service
|
||||
namespace: converters
|
||||
spec:
|
||||
selector:
|
||||
app: convertx
|
||||
ports:
|
||||
- port: 3000
|
||||
targetPort: 3000
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: convertx-deployment
|
||||
namespace: converters
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: convertx
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: convertx
|
||||
spec:
|
||||
containers:
|
||||
- image: ghcr.io/c4illin/convertx:v0.18.0
|
||||
name: convertx
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: convertx-config
|
||||
- secretRef:
|
||||
name: convertx-secrets
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
volumeMounts:
|
||||
- mountPath: /data
|
||||
name: data
|
||||
resources:
|
||||
requests:
|
||||
memory: "250Mi"
|
||||
cpu: "100m"
|
||||
limits:
|
||||
cpu: "1500m"
|
||||
memory: "1.5Gi"
|
||||
volumes:
|
||||
- name: data
|
||||
persistentVolumeClaim:
|
||||
claimName: convertx-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: convertx-pvc
|
||||
namespace: converters
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 2Gi
|
||||
@@ -0,0 +1,70 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: convertx-prod
|
||||
namespace: converters
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: (Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/convert`)
|
||||
kind: Rule
|
||||
priority: 50
|
||||
services:
|
||||
- name: convertx-service
|
||||
port: 3000
|
||||
tls:
|
||||
secretName: convertx-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: convertx-local
|
||||
namespace: converters
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: (Host(`workstation.internal`) || Host(`gigaforust.internal`)) && PathPrefix(`/convert`)
|
||||
kind: Rule
|
||||
priority: 50
|
||||
services:
|
||||
- name: convertx-service
|
||||
port: 3000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: bentopdf-prod
|
||||
namespace: converters
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`pdf.forust.xyz`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: bentopdf-service
|
||||
port: 8080
|
||||
tls:
|
||||
secretName: bentopdf-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: bentopdf-local
|
||||
namespace: converters
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`pdf.workstation.internal`) || Host(`pdf.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: bentopdf-service
|
||||
port: 8080
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: converters
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: convertx-secrets
|
||||
namespace: converters
|
||||
type: Opaque
|
||||
stringData:
|
||||
jwt-secret: ""
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: Middleware
|
||||
metadata:
|
||||
name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
spec:
|
||||
plugin:
|
||||
crowdsec-bouncer:
|
||||
enabled: true
|
||||
LogLevel: INFO
|
||||
CrowdsecMode: live
|
||||
CrowdsecLapiScheme: http
|
||||
CrowdsecLapiHost: crowdsec-service.crowdsec.svc.cluster.local:8080
|
||||
CrowdsecLapiKeyFile: "/etc/traefik/secrets/traefik-api-key"
|
||||
@@ -0,0 +1,102 @@
|
||||
container_runtime: containerd
|
||||
|
||||
agent:
|
||||
acquisition: []
|
||||
additionalAcquisition:
|
||||
- labels:
|
||||
type: traefik
|
||||
limit: 1000
|
||||
query: |
|
||||
{namespace="traefik"}
|
||||
source: loki
|
||||
url: http://loki.prometheus.svc.cluster.local:3100/
|
||||
wait_for_ready: 30s
|
||||
env:
|
||||
- name: COLLECTIONS
|
||||
value: crowdsecurity/traefik crowdsecurity/base-http-scenarios
|
||||
- name: DISABLE_COLLECTIONS
|
||||
value: crowdsecurity/sshd
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
additionalLabels:
|
||||
release: prometheus-stack
|
||||
enabled: true
|
||||
# Static machine identity: agent pods mount pre-created LAPI credentials
|
||||
# (Secret crowdsec-agent-credentials, key local_api_credentials.yaml)
|
||||
# at the exact path the agent entrypoint expects. Together with the
|
||||
# patched register-init (enforced by janitor-cronjob.yaml) the agent
|
||||
# never calls `cscli lapi register` in steady state, so pod names,
|
||||
# restarts and reboots can no longer break it.
|
||||
extraVolumes:
|
||||
- name: static-creds
|
||||
secret:
|
||||
secretName: crowdsec-agent-credentials
|
||||
items:
|
||||
- key: local_api_credentials.yaml
|
||||
path: local_api_credentials.yaml
|
||||
extraVolumeMounts:
|
||||
- name: static-creds
|
||||
mountPath: /tmp_config/local_api_credentials.yaml
|
||||
subPath: local_api_credentials.yaml
|
||||
readOnly: true
|
||||
resources:
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 500Mi
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 100Mi
|
||||
|
||||
config:
|
||||
parsers:
|
||||
s02-enrich:
|
||||
mobile-whitelist.yaml: |
|
||||
name: forust/mobile-whitelist
|
||||
description: "Whitelist SWAN/4ka mobile network"
|
||||
whitelist:
|
||||
reason: "Mobile IP whitelist"
|
||||
cidr:
|
||||
- "84.245.64.0/18"
|
||||
|
||||
postoverflows:
|
||||
s01-whitelist:
|
||||
home-dynamic-ip.yaml: |
|
||||
name: forust/home-dynamic-ip
|
||||
description: "Whitelist home dynamic IP"
|
||||
whitelist:
|
||||
reason: "Home dynamic IP"
|
||||
expression:
|
||||
- evt.Overflow.Alert.Source.IP in LookupHost("ddns.forust.xyz")
|
||||
|
||||
lapi:
|
||||
env:
|
||||
- name: COLLECTIONS
|
||||
value: crowdsecurity/traefik crowdsecurity/base-http-scenarios
|
||||
- name: DISABLE_COLLECTIONS
|
||||
value: crowdsecurity/linux crowdsecurity/sshd
|
||||
metrics:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
additionalLabels:
|
||||
release: prometheus-stack
|
||||
enabled: true
|
||||
persistentVolume:
|
||||
config:
|
||||
enabled: true
|
||||
size: 100Mi
|
||||
storageClassName: local-path-retain
|
||||
data:
|
||||
enabled: true
|
||||
size: 1Gi
|
||||
storageClassName: local-path-retain
|
||||
resources:
|
||||
limits:
|
||||
cpu: 400m
|
||||
memory: 500Mi
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 150Mi
|
||||
service:
|
||||
type: ClusterIP
|
||||
storeLAPICscliCredentialsInSecret: true
|
||||
@@ -0,0 +1,32 @@
|
||||
apiVersion: v1
|
||||
data:
|
||||
crowdsec-overview.json: "{\n \"__inputs\": [\n {\n \"name\": \"DS_PROMETHEUS\",\n \"label\": \"Prometheus\",\n \"description\": \"\",\n \"type\": \"datasource\",\n \"pluginId\": \"prometheus\",\n \"pluginName\": \"Prometheus\"\n }\n ],\n \"__requires\": [\n {\n \"type\": \"grafana\",\n \"id\": \"grafana\",\n \"name\": \"Grafana\",\n \"version\": \"8.1.2\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"graph\",\n \"name\": \"Graph (old)\",\n \"version\": \"\"\n },\n {\n \"type\": \"datasource\",\n \"id\": \"prometheus\",\n \"name\": \"Prometheus\",\n \"version\": \"1.0.0\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"stat\",\n \"name\": \"Stat\",\n \"version\": \"\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"timeseries\",\n \"name\": \"Time series\",\n \"version\": \"\"\n }\n ],\n \"annotations\": {\n \"list\": [\n {\n \"builtIn\": 1,\n \"datasource\": \"-- Grafana --\",\n \"enable\": true,\n \"hide\": true,\n \"iconColor\": \"rgba(0, 211, 255, 1)\",\n \"name\": \"Annotations & Alerts\",\n \"target\": {\n \"limit\": 100,\n \"matchAny\": false,\n \"tags\": [],\n \"type\": \"dashboard\"\n },\n \"type\": \"dashboard\"\n }\n ]\n },\n \"editable\": true,\n \"gnetId\": null,\n \"graphTooltip\": 0,\n \"id\": null,\n \"links\": [],\n \"panels\": [\n {\n \"collapsed\": false,\n \"datasource\": null,\n \"gridPos\": {\n \"h\": 1,\n \"w\": 24,\n \"x\": 0,\n \"y\": 0\n },\n \"id\": 24,\n \"panels\": [],\n \"title\": \"Summary\",\n \"type\": \"row\"\n },\n {\n \"cacheTimeout\": null,\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"color\": {\n \"mode\": \"thresholds\"\n },\n \"mappings\": [\n {\n \"options\": {\n \"match\": \"null\",\n \"result\": {\n \"text\": \"N/A\"\n }\n },\n \"type\": \"special\"\n }\n ],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"#E02F44\",\n \"value\": null\n },\n {\n \"color\": \"#E02F44\",\n \"value\": 10\n },\n {\n \"color\": \"#299c46\",\n \"value\": 10\n }\n ]\n },\n \"unit\": \"none\"\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 8,\n \"w\": 6,\n \"x\": 0,\n \"y\": 1\n },\n \"id\": 2,\n \"interval\": null,\n \"links\": [],\n \"maxDataPoints\": 100,\n \"options\": {\n \"colorMode\": \"background\",\n \"graphMode\": \"none\",\n \"justifyMode\": \"auto\",\n \"orientation\": \"horizontal\",\n \"reduceOptions\": {\n \"calcs\": [\n \"lastNotNull\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\n \"text\": {},\n \"textMode\": \"auto\"\n },\n \"pluginVersion\": \"8.1.2\",\n \"targets\": [\n {\n \"exemplar\": true,\n \"expr\": \"count(cs_info)\",\n \"interval\": \"\",\n \"legendFormat\": \"\",\n \"refId\": \"A\"\n }\n ],\n \"timeFrom\": null,\n \"timeShift\": null,\n \"title\": \"Running Crowdsec\",\n \"transparent\": true,\n \"type\": \"stat\"\n },\n {\n \"aliasColors\": {},\n \"bars\": false,\n \"dashLength\": 10,\n \"dashes\": false,\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"decimals\": 1,\n \"fieldConfig\": {\n \"defaults\": {\n \"links\": []\n },\n \"overrides\": []\n },\n \"fill\": 1,\n \"fillGradient\": 0,\n \"gridPos\": {\n \"h\": 8,\n \"w\": 18,\n \"x\": 6,\n \"y\": 1\n },\n \"hiddenSeries\": false,\n \"id\": 8,\n \"legend\": {\n \"alignAsTable\": true,\n \"avg\": false,\n \"current\": false,\n \"max\": false,\n \"min\": false,\n \"rightSide\": true,\n \"show\": true,\n \"sort\": \"total\",\n \"sortDesc\": true,\n \"total\": true,\n \"values\": true\n },\n \"lines\": true,\n \"linewidth\": 1,\n \"nullPointMode\": \"null\",\n \"options\": {\n \"alertThreshold\": true\n },\n \"percentage\": false,\n \"pluginVersion\": \"8.1.2\",\n \"pointradius\": 2,\n \"points\": false,\n \"renLine truncated
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/managed-by: manual
|
||||
grafana_dashboard: "1"
|
||||
name: crowdsec-crowdsec-overview
|
||||
namespace: prometheus
|
||||
---
|
||||
apiVersion: v1
|
||||
data:
|
||||
crowdsec-lapi-metrics.json: "{\n \"__inputs\": [\n {\n \"name\": \"DS_PROMETHEUS\",\n \"label\": \"Prometheus\",\n \"description\": \"\",\n \"type\": \"datasource\",\n \"pluginId\": \"prometheus\",\n \"pluginName\": \"Prometheus\"\n }\n ],\n \"__requires\": [\n {\n \"type\": \"panel\",\n \"id\": \"bargauge\",\n \"name\": \"Bar gauge\",\n \"version\": \"\"\n },\n {\n \"type\": \"grafana\",\n \"id\": \"grafana\",\n \"name\": \"Grafana\",\n \"version\": \"8.1.2\"\n },\n {\n \"type\": \"datasource\",\n \"id\": \"prometheus\",\n \"name\": \"Prometheus\",\n \"version\": \"1.0.0\"\n }\n ],\n \"annotations\": {\n \"list\": [\n {\n \"builtIn\": 1,\n \"datasource\": \"-- Grafana --\",\n \"enable\": true,\n \"hide\": true,\n \"iconColor\": \"rgba(0, 211, 255, 1)\",\n \"name\": \"Annotations & Alerts\",\n \"target\": {\n \"limit\": 100,\n \"matchAny\": false,\n \"tags\": [],\n \"type\": \"dashboard\"\n },\n \"type\": \"dashboard\"\n }\n ]\n },\n \"editable\": true,\n \"gnetId\": null,\n \"graphTooltip\": 0,\n \"id\": null,\n \"iteration\": 1655915193937,\n \"links\": [],\n \"panels\": [\n {\n \"collapsed\": false,\n \"datasource\": null,\n \"gridPos\": {\n \"h\": 1,\n \"w\": 24,\n \"x\": 0,\n \"y\": 0\n },\n \"id\": 10,\n \"panels\": [],\n \"title\": \"Agents\",\n \"type\": \"row\"\n },\n {\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"color\": {\n \"mode\": \"thresholds\"\n },\n \"mappings\": [],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"green\",\n \"value\": null\n },\n {\n \"color\": \"red\",\n \"value\": 80\n }\n ]\n }\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 8,\n \"w\": 12,\n \"x\": 0,\n \"y\": 1\n },\n \"id\": 2,\n \"options\": {\n \"displayMode\": \"gradient\",\n \"orientation\": \"vertical\",\n \"reduceOptions\": {\n \"calcs\": [\n \"lastNotNull\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\n \"showUnfilled\": false,\n \"text\": {}\n },\n \"pluginVersion\": \"8.1.2\",\n \"repeat\": \"query0\",\n \"repeatDirection\": \"h\",\n \"targets\": [\n {\n \"exemplar\": false,\n \"expr\": \"sum(rate(cs_lapi_request_duration_seconds_bucket{endpoint=\\\"/v1/watchers/login\\\", instance=\\\"$lapi\\\"}[$__rate_interval])) by (le)\",\n \"format\": \"heatmap\",\n \"interval\": \"\",\n \"legendFormat\": \"{{le}}\",\n \"refId\": \"A\"\n }\n ],\n \"title\": \"Agents Login\",\n \"type\": \"heatmap\"\n },\n {\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"color\": {\n \"mode\": \"thresholds\"\n },\n \"mappings\": [],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"green\",\n \"value\": null\n }\n ]\n },\n \"unit\": \"none\"\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 8,\n \"w\": 12,\n \"x\": 12,\n \"y\": 1\n },\n \"id\": 6,\n \"options\": {\n \"displayMode\": \"gradient\",\n \"orientation\": \"auto\",\n \"reduceOptions\": {\n \"calcs\": [\n \"lastNotNull\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\n \"showUnfilled\": false,\n \"text\": {}\n },\n \"pluginVersion\": \"8.1.2\",\n \"targets\": [\n {\n \"exemplar\": true,\n \"expr\": \"sum(rate(cs_lapi_request_duration_seconds_bucket{endpoint=\\\"/v1/watchers/login\\\"}[$__rate_interval])) by (le)\",\n \"format\": \"heatmap\",\n \"interval\": \"\",\n \"legendFormat\": \"{{le}}\",\n \"refId\": \"A\"\n }\n ],\n \"title\": \"Heartbeat\",\n \"type\": \"heatmap\"\n },\n {\n \"collapsed\": false,\n \"datasource\": null,\n \"gridPos\": {\n \"h\": 1,\n \"w\": 24,\n \"x\": 0,\n \"y\": 9\n },\n \"id\": 12,\n \"panels\": [],\n \"title\": \"Decisions\",\n \"type\": \"row\"\n },\n {\n \"datasource\": \"${DS_PROMETHEUS}\",\n Line truncated
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/managed-by: manual
|
||||
grafana_dashboard: "1"
|
||||
name: crowdsec-crowdsec-lapi-metrics
|
||||
namespace: prometheus
|
||||
---
|
||||
apiVersion: v1
|
||||
data:
|
||||
crowdsec-insight.json: "{\n \"__inputs\": [\n {\n \"name\": \"DS_PROMETHEUS\",\n \"label\": \"Prometheus\",\n \"description\": \"\",\n \"type\": \"datasource\",\n \"pluginId\": \"prometheus\",\n \"pluginName\": \"Prometheus\"\n }\n ],\n \"__requires\": [\n {\n \"type\": \"panel\",\n \"id\": \"bargauge\",\n \"name\": \"Bar gauge\",\n \"version\": \"\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"gauge\",\n \"name\": \"Gauge\",\n \"version\": \"\"\n },\n {\n \"type\": \"grafana\",\n \"id\": \"grafana\",\n \"name\": \"Grafana\",\n \"version\": \"8.1.2\"\n },\n {\n \"type\": \"datasource\",\n \"id\": \"prometheus\",\n \"name\": \"Prometheus\",\n \"version\": \"1.0.0\"\n },\n {\n \"type\": \"panel\",\n \"id\": \"stat\",\n \"name\": \"Stat\",\n \"version\": \"\"\n }\n ],\n \"annotations\": {\n \"list\": [\n {\n \"builtIn\": 1,\n \"datasource\": \"-- Grafana --\",\n \"enable\": true,\n \"hide\": true,\n \"iconColor\": \"rgba(0, 211, 255, 1)\",\n \"name\": \"Annotations & Alerts\",\n \"target\": {\n \"limit\": 100,\n \"matchAny\": false,\n \"tags\": [],\n \"type\": \"dashboard\"\n },\n \"type\": \"dashboard\"\n }\n ]\n },\n \"editable\": true,\n \"gnetId\": null,\n \"graphTooltip\": 0,\n \"id\": null,\n \"iteration\": 1655915159751,\n \"links\": [],\n \"panels\": [\n {\n \"collapsed\": true,\n \"datasource\": null,\n \"gridPos\": {\n \"h\": 1,\n \"w\": 24,\n \"x\": 0,\n \"y\": 0\n },\n \"id\": 22,\n \"panels\": [\n {\n \"cacheTimeout\": null,\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"color\": {\n \"mode\": \"thresholds\"\n },\n \"mappings\": [\n {\n \"options\": {\n \"match\": \"null\",\n \"result\": {\n \"text\": \"N/A\"\n }\n },\n \"type\": \"special\"\n }\n ],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"green\",\n \"value\": null\n },\n {\n \"color\": \"red\",\n \"value\": 80\n }\n ]\n },\n \"unit\": \"dateTimeAsIso\"\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 9,\n \"w\": 5,\n \"x\": 2,\n \"y\": 1\n },\n \"id\": 2,\n \"interval\": null,\n \"links\": [],\n \"maxDataPoints\": 100,\n \"options\": {\n \"colorMode\": \"none\",\n \"graphMode\": \"none\",\n \"justifyMode\": \"auto\",\n \"orientation\": \"horizontal\",\n \"reduceOptions\": {\n \"calcs\": [\n \"lastNotNull\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\n \"text\": {},\n \"textMode\": \"auto\"\n },\n \"pluginVersion\": \"8.1.2\",\n \"targets\": [\n {\n \"exemplar\": true,\n \"expr\": \"(process_start_time_seconds{instance=\\\"$instance\\\"})*1000\",\n \"interval\": \"\",\n \"legendFormat\": \"{{instance}}\",\n \"refId\": \"A\"\n }\n ],\n \"timeFrom\": null,\n \"timeShift\": null,\n \"title\": \"Up since\",\n \"type\": \"stat\"\n },\n {\n \"datasource\": \"${DS_PROMETHEUS}\",\n \"fieldConfig\": {\n \"defaults\": {\n \"displayName\": \"\",\n \"mappings\": [],\n \"thresholds\": {\n \"mode\": \"absolute\",\n \"steps\": [\n {\n \"color\": \"green\",\n \"value\": null\n }\n ]\n },\n \"unit\": \"decbytes\"\n },\n \"overrides\": []\n },\n \"gridPos\": {\n \"h\": 9,\n \"w\": 5,\n \"x\": 7,\n \"y\": 1\n },\n \"id\": 4,\n \"options\": {\n \"orientation\": \"auto\",\n \"reduceOptions\": {\n \"calcs\": [\n \"mean\"\n ],\n \"fields\": \"\",\n \"values\": false\n },\Line truncated
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/managed-by: manual
|
||||
grafana_dashboard: "1"
|
||||
name: crowdsec-crowdsec-insight
|
||||
namespace: prometheus
|
||||
@@ -0,0 +1,195 @@
|
||||
# CrowdSec self-healing: static machine identity + enforcement loops.
|
||||
#
|
||||
# Problem it fixes: the chart's agent init container runs
|
||||
# `cscli lapi register --machine "$POD_NAME" ...`
|
||||
# unconditionally. Credentials live in an emptyDir, the machine row lives
|
||||
# in LAPI's persistent DB. Any init re-run for an already-known pod name
|
||||
# (kubelet restart, node reboot) dies with
|
||||
# 403 Forbidden: user '<pod>' already exist
|
||||
# and the DaemonSet pod sticks in Init forever. Every DS restart also
|
||||
# leaves an orphan machine row that is never cleaned.
|
||||
#
|
||||
# Design (name-independent):
|
||||
# * Agent identity is a STATIC machine `crowdsec-agent-workstation`
|
||||
# whose password lives in Secret `crowdsec-agent-credentials`
|
||||
# (created once, manually - like all other secrets in this repo).
|
||||
# The secret is mounted into agent pods at
|
||||
# /tmp_config/local_api_credentials.yaml (see extraVolumeMounts in
|
||||
# crowdsec-values.yaml), which is exactly the path the agent's main
|
||||
# container copies into place at startup.
|
||||
# * The DS init command is patched (strategic merge, by container name)
|
||||
# to SKIP registration when that file exists, keeping the legacy
|
||||
# register path only as fallback. Detection marker in the patched
|
||||
# command: `[ -s /tmp_config`.
|
||||
# * This CronJob enforces the desired state hourly, so recovery is
|
||||
# automatic even after `helm upgrade` reverts the DS patch or the
|
||||
# LAPI database is wiped:
|
||||
# 1. patch DS init if it still has the unconditional register
|
||||
# (no-op otherwise - no restart churn);
|
||||
# 2. prune machines with no heartbeat for 2h (orphan hygiene);
|
||||
# 3. ensure the static machine exists, recreating it with the
|
||||
# Secret password if missing (agent retry loops reconnect
|
||||
# on their own - same name + same password);
|
||||
# 4. prune bouncer entries idle for 30d.
|
||||
#
|
||||
# Manual apply (crowdsec/k8s is NOT managed by deploy.yaml):
|
||||
# kubectl apply -f crowdsec/k8s/janitor-cronjob.yaml
|
||||
# Force a run:
|
||||
# kubectl create job -n crowdsec --from=cronjob/crowdsec-janitor janitor-now
|
||||
#
|
||||
# Helm upgrades: the janitor's strategic patch puts the DS field under
|
||||
# the `kubectl-patch` field manager, so a plain `helm upgrade` FAILS
|
||||
# with an SSA conflict on initContainers[].command. Procedure:
|
||||
# 1. revert init to chart state (kills the conflict):
|
||||
# helm template crowdsec crowdsec/crowdsec --version <ver> \
|
||||
# -n crowdsec -f crowdsec/k8s/crowdsec-values.yaml > /tmp/r.yaml
|
||||
# python3 -c "import yaml,json; ..." # build revert patch from
|
||||
# the rendered DaemonSet init command, then
|
||||
# kubectl patch ds crowdsec-agent -n crowdsec \
|
||||
# --type strategic -p "\$(cat /tmp/revert_patch.json)"
|
||||
# 2. helm upgrade --install crowdsec ... (no --force needed)
|
||||
# 3. janitor-now right away (upgrade reverts init; new pods would
|
||||
# sit in Init until the next hourly run otherwise).
|
||||
#
|
||||
# One-time bootstrap (order matters):
|
||||
# 1. Create Secret + static machine (see commands in chat).
|
||||
# 2. Apply this file, trigger janitor-now, wait for agent 1/1.
|
||||
# 3. One-time orphan cleanup:
|
||||
# kubectl exec -n crowdsec deploy/crowdsec-lapi -- \
|
||||
# cscli machines prune --duration 1h --force
|
||||
# 4. Only then `helm upgrade` crowdsec with the extraVolumes values.
|
||||
# Upgrade reverts the DS patch; trigger janitor-now right after it
|
||||
# (otherwise new pods sit in Init until the next hourly run, then
|
||||
# self-heal anyway).
|
||||
#
|
||||
# Password rotation: update the Secret, delete the machine
|
||||
# (`cscli machines delete crowdsec-agent-workstation`), trigger
|
||||
# janitor-now (recreates it), then `kubectl rollout restart
|
||||
# ds/crowdsec-agent -n crowdsec` (agent reads the file at startup only).
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["pods"]
|
||||
verbs: ["get", "list"]
|
||||
- apiGroups: [""]
|
||||
resources: ["pods/exec"]
|
||||
verbs: ["create"]
|
||||
- apiGroups: ["apps"]
|
||||
resources: ["daemonsets"]
|
||||
verbs: ["get", "patch"]
|
||||
# `kubectl exec deploy/<name>` resolves deploy -> replicaset -> pod,
|
||||
# which needs read access to these (exec itself is pods/exec above).
|
||||
- apiGroups: ["apps"]
|
||||
resources: ["deployments", "replicasets"]
|
||||
verbs: ["get", "list"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
roleRef:
|
||||
kind: Role
|
||||
name: crowdsec-janitor
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
---
|
||||
apiVersion: batch/v1
|
||||
kind: CronJob
|
||||
metadata:
|
||||
name: crowdsec-janitor
|
||||
namespace: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
spec:
|
||||
schedule: "17 * * * *"
|
||||
concurrencyPolicy: Forbid
|
||||
successfulJobsHistoryLimit: 3
|
||||
failedJobsHistoryLimit: 3
|
||||
jobTemplate:
|
||||
spec:
|
||||
activeDeadlineSeconds: 300
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
spec:
|
||||
serviceAccountName: crowdsec-janitor
|
||||
restartPolicy: OnFailure
|
||||
containers:
|
||||
- name: janitor
|
||||
# Same image the chart itself uses for registration jobs;
|
||||
# IfNotPresent so it works while the node is offline
|
||||
# (layer cached from the chart install).
|
||||
image: alpine/kubectl:latest
|
||||
imagePullPolicy: IfNotPresent
|
||||
env:
|
||||
- name: AGENT_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: crowdsec-agent-credentials
|
||||
key: password
|
||||
command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- |
|
||||
set -eu
|
||||
LAPI_EXEC="kubectl exec -n crowdsec deploy/crowdsec-lapi --"
|
||||
echo "== 1. enforce patched agent init =="
|
||||
CUR=$(kubectl get ds crowdsec-agent -n crowdsec \
|
||||
-o jsonpath='{.spec.template.spec.initContainers[0].command[2]}')
|
||||
case "$CUR" in
|
||||
*'-s /tmp_config'*)
|
||||
echo "init already patched"
|
||||
;;
|
||||
*)
|
||||
echo "patching init"
|
||||
WAIT='until nc "$LAPI_HOST" "$LAPI_PORT" -z'
|
||||
WAIT="$WAIT; do echo waiting for lapi to start; sleep 5; done"
|
||||
LINK='ln -s /staging/etc/crowdsec /etc/crowdsec'
|
||||
REG='cscli lapi register --machine "$USERNAME"'
|
||||
REG="$REG -u \"\$LAPI_URL\" --token \"\$REGISTRATION_TOKEN\""
|
||||
CREDS=/tmp_config/local_api_credentials.yaml
|
||||
CMD="$WAIT; $LINK; [ -s $CREDS ] || {"
|
||||
CMD="$CMD $REG && cp"
|
||||
CMD="$CMD /etc/crowdsec/local_api_credentials.yaml $CREDS; }"
|
||||
ESC=$(printf '%s' "$CMD" | sed 's/"/\\"/g')
|
||||
PATCH='{"spec":{"template":{"spec":{"initContainers":'
|
||||
PATCH=$PATCH'[{"name":"wait-for-lapi-and-register",'
|
||||
PATCH=$PATCH'"command":["sh","-c","'$ESC'"]}]}}}}'
|
||||
kubectl patch ds crowdsec-agent -n crowdsec \
|
||||
--type strategic -p "$PATCH"
|
||||
;;
|
||||
esac
|
||||
echo "== 2. prune orphan machines (no heartbeat for 2h) =="
|
||||
$LAPI_EXEC cscli machines prune --duration 2h --force
|
||||
echo "== 3. ensure static machine exists =="
|
||||
if $LAPI_EXEC cscli machines inspect \
|
||||
crowdsec-agent-workstation >/dev/null 2>&1; then
|
||||
echo "static machine present"
|
||||
else
|
||||
echo "recreating static machine"
|
||||
$LAPI_EXEC cscli machines add crowdsec-agent-workstation \
|
||||
--password "$AGENT_PASSWORD" --force
|
||||
fi
|
||||
echo "== 4. prune stale bouncers (no pull for 30d) =="
|
||||
$LAPI_EXEC cscli bouncers prune -d 720h --force
|
||||
@@ -0,0 +1,6 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: crowdsec
|
||||
labels:
|
||||
app.kubernetes.io/part-of: crowdsec
|
||||
@@ -0,0 +1,34 @@
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: crowdsec-lapi
|
||||
namespace: crowdsec
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels:
|
||||
k8s-app: crowdsec
|
||||
type: lapi
|
||||
policyTypes:
|
||||
- Ingress
|
||||
ingress:
|
||||
- from:
|
||||
- namespaceSelector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: traefik
|
||||
podSelector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: traefik
|
||||
- podSelector:
|
||||
matchLabels:
|
||||
k8s-app: crowdsec
|
||||
type: agent
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 8080
|
||||
- from:
|
||||
- namespaceSelector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: prometheus
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 6060
|
||||
+28
-12
@@ -1,30 +1,46 @@
|
||||
services:
|
||||
dockmon:
|
||||
image: darthnorse/dockmon:latest
|
||||
image: darthnorse/dockmon:2.4.5
|
||||
container_name: dockmon
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- 8000:443
|
||||
environment:
|
||||
- TZ=Europe/Bratislava
|
||||
# ports:
|
||||
# - 8000:443
|
||||
volumes:
|
||||
- ./data:/app/data
|
||||
- data:/app/data
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-k", "-f", "https://localhost:443/health"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
networks:
|
||||
- traefik-proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.dockmon.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
|
||||
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=dockmon
|
||||
# - glance.icon=sh:dockmon
|
||||
- glance.url=https://dockmon.forust.xyz/
|
||||
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
||||
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
Whitespace-only changes.
@@ -0,0 +1,28 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: dockmon-prod-tls
|
||||
namespace: dockmon
|
||||
spec:
|
||||
secretName: dockmon-prod-tls
|
||||
dnsNames:
|
||||
- dockmon.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: dockmon
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,68 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: dockmon-service
|
||||
namespace: dockmon
|
||||
spec:
|
||||
clusterIP: None
|
||||
selector:
|
||||
app: dockmon
|
||||
ports:
|
||||
- port: 443
|
||||
targetPort: 443
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: dockmon-statefulset
|
||||
namespace: dockmon
|
||||
spec:
|
||||
serviceName: dockmon-service
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: dockmon
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: dockmon
|
||||
spec:
|
||||
containers:
|
||||
- name: dockmon
|
||||
image: darthnorse/dockmon:2.4.5
|
||||
ports:
|
||||
- containerPort: 443
|
||||
volumeMounts:
|
||||
- name: data
|
||||
mountPath: /app/data
|
||||
- name: docker-sock
|
||||
mountPath: /var/run/docker.sock
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /health
|
||||
port: 443
|
||||
scheme: HTTPS
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 10
|
||||
failureThreshold: 3
|
||||
resources:
|
||||
requests:
|
||||
memory: "512Mi"
|
||||
cpu: "200m"
|
||||
limits:
|
||||
memory: "1.5Gi"
|
||||
cpu: "700m "
|
||||
volumes:
|
||||
- name: docker-sock
|
||||
hostPath:
|
||||
path: /var/run/docker.sock
|
||||
type: Socket
|
||||
volumeClaimTemplates:
|
||||
- metadata:
|
||||
name: data
|
||||
spec:
|
||||
accessModes: ["ReadWriteOnce"]
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
@@ -0,0 +1,47 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: ServersTransport
|
||||
metadata:
|
||||
name: dockmon-transport
|
||||
namespace: dockmon
|
||||
spec:
|
||||
insecureSkipVerify: true
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: dockmon-prod
|
||||
namespace: dockmon
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`dockmon.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
- name: security-headers@file
|
||||
services:
|
||||
- name: dockmon-service
|
||||
port: 443
|
||||
serversTransport: dockmon-transport
|
||||
tls:
|
||||
secretName: dockmon-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: dockmon-local
|
||||
namespace: dockmon
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`dockmon.workstation.internal`) || Host(`dockmon.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: dockmon-service
|
||||
port: 443
|
||||
serversTransport: dockmon-transport
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: dockmon
|
||||
@@ -0,0 +1,31 @@
|
||||
services:
|
||||
downtify:
|
||||
container_name: downtify
|
||||
image: ghcr.io/henriquesebastiao/downtify:2.13.0
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - '7077:8000'
|
||||
volumes:
|
||||
- ./Downtify_downloads:/downloads
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.downtify.loadbalancer.server.port=8000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)"
|
||||
- "traefik.http.routers.downtify.entrypoints=websecure"
|
||||
- "traefik.http.routers.downtify.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.downtify.tls.certresolver=letsencrypt"
|
||||
# Local Router
|
||||
- "traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`)"
|
||||
- "traefik.http.routers.downtify-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.downtify-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)"
|
||||
- "traefik.http.routers.downtify-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.downtify-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -0,0 +1,58 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: downtify-service
|
||||
namespace: downtify
|
||||
spec:
|
||||
selector:
|
||||
app: downtify
|
||||
ports:
|
||||
- port: 8000
|
||||
targetPort: 8000
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: downtify-deployment
|
||||
namespace: downtify
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: downtify
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: downtify
|
||||
spec:
|
||||
containers:
|
||||
- name: downtify
|
||||
image: ghcr.io/henriquesebastiao/downtify:2.13.0
|
||||
ports:
|
||||
- containerPort: 8000
|
||||
volumeMounts:
|
||||
- name: downloads
|
||||
mountPath: /downloads
|
||||
resources:
|
||||
requests:
|
||||
memory: "128Mi"
|
||||
cpu: "200m"
|
||||
limits:
|
||||
memory: "1Gi"
|
||||
cpu: "1"
|
||||
volumes:
|
||||
- name: downloads
|
||||
persistentVolumeClaim:
|
||||
claimName: downtify-downloads-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: downtify-downloads-pvc
|
||||
namespace: downtify
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 10Gi
|
||||
@@ -0,0 +1,37 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: downtify-prod
|
||||
namespace: downtify
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`downtify.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
- name: security-chain@file
|
||||
services:
|
||||
- name: downtify-service
|
||||
port: 8000
|
||||
tls:
|
||||
secretName: downtify-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: downtify-local
|
||||
namespace: downtify
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`downtify.workstation.internal`) || Host(`downtify.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: downtify-service
|
||||
port: 8000
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: downtify
|
||||
@@ -0,0 +1,373 @@
|
||||
Mozilla Public License Version 2.0
|
||||
==================================
|
||||
|
||||
1. Definitions
|
||||
--------------
|
||||
|
||||
1.1. "Contributor"
|
||||
means each individual or legal entity that creates, contributes to
|
||||
the creation of, or owns Covered Software.
|
||||
|
||||
1.2. "Contributor Version"
|
||||
means the combination of the Contributions of others (if any) used
|
||||
by a Contributor and that particular Contributor's Contribution.
|
||||
|
||||
1.3. "Contribution"
|
||||
means Covered Software of a particular Contributor.
|
||||
|
||||
1.4. "Covered Software"
|
||||
means Source Code Form to which the initial Contributor has attached
|
||||
the notice in Exhibit A, the Executable Form of such Source Code
|
||||
Form, and Modifications of such Source Code Form, in each case
|
||||
including portions thereof.
|
||||
|
||||
1.5. "Incompatible With Secondary Licenses"
|
||||
means
|
||||
|
||||
(a) that the initial Contributor has attached the notice described
|
||||
in Exhibit B to the Covered Software; or
|
||||
|
||||
(b) that the Covered Software was made available under the terms of
|
||||
version 1.1 or earlier of the License, but not also under the
|
||||
terms of a Secondary License.
|
||||
|
||||
1.6. "Executable Form"
|
||||
means any form of the work other than Source Code Form.
|
||||
|
||||
1.7. "Larger Work"
|
||||
means a work that combines Covered Software with other material, in
|
||||
a separate file or files, that is not Covered Software.
|
||||
|
||||
1.8. "License"
|
||||
means this document.
|
||||
|
||||
1.9. "Licensable"
|
||||
means having the right to grant, to the maximum extent possible,
|
||||
whether at the time of the initial grant or subsequently, any and
|
||||
all of the rights conveyed by this License.
|
||||
|
||||
1.10. "Modifications"
|
||||
means any of the following:
|
||||
|
||||
(a) any file in Source Code Form that results from an addition to,
|
||||
deletion from, or modification of the contents of Covered
|
||||
Software; or
|
||||
|
||||
(b) any new file in Source Code Form that contains any Covered
|
||||
Software.
|
||||
|
||||
1.11. "Patent Claims" of a Contributor
|
||||
means any patent claim(s), including without limitation, method,
|
||||
process, and apparatus claims, in any patent Licensable by such
|
||||
Contributor that would be infringed, but for the grant of the
|
||||
License, by the making, using, selling, offering for sale, having
|
||||
made, import, or transfer of either its Contributions or its
|
||||
Contributor Version.
|
||||
|
||||
1.12. "Secondary License"
|
||||
means either the GNU General Public License, Version 2.0, the GNU
|
||||
Lesser General Public License, Version 2.1, the GNU Affero General
|
||||
Public License, Version 3.0, or any later versions of those
|
||||
licenses.
|
||||
|
||||
1.13. "Source Code Form"
|
||||
means the form of the work preferred for making modifications.
|
||||
|
||||
1.14. "You" (or "Your")
|
||||
means an individual or a legal entity exercising rights under this
|
||||
License. For legal entities, "You" includes any entity that
|
||||
controls, is controlled by, or is under common control with You. For
|
||||
purposes of this definition, "control" means (a) the power, direct
|
||||
or indirect, to cause the direction or management of such entity,
|
||||
whether by contract or otherwise, or (b) ownership of more than
|
||||
fifty percent (50%) of the outstanding shares or beneficial
|
||||
ownership of such entity.
|
||||
|
||||
2. License Grants and Conditions
|
||||
--------------------------------
|
||||
|
||||
2.1. Grants
|
||||
|
||||
Each Contributor hereby grants You a world-wide, royalty-free,
|
||||
non-exclusive license:
|
||||
|
||||
(a) under intellectual property rights (other than patent or trademark)
|
||||
Licensable by such Contributor to use, reproduce, make available,
|
||||
modify, display, perform, distribute, and otherwise exploit its
|
||||
Contributions, either on an unmodified basis, with Modifications, or
|
||||
as part of a Larger Work; and
|
||||
|
||||
(b) under Patent Claims of such Contributor to make, use, sell, offer
|
||||
for sale, have made, import, and otherwise transfer either its
|
||||
Contributions or its Contributor Version.
|
||||
|
||||
2.2. Effective Date
|
||||
|
||||
The licenses granted in Section 2.1 with respect to any Contribution
|
||||
become effective for each Contribution on the date the Contributor first
|
||||
distributes such Contribution.
|
||||
|
||||
2.3. Limitations on Grant Scope
|
||||
|
||||
The licenses granted in this Section 2 are the only rights granted under
|
||||
this License. No additional rights or licenses will be implied from the
|
||||
distribution or licensing of Covered Software under this License.
|
||||
Notwithstanding Section 2.1(b) above, no patent license is granted by a
|
||||
Contributor:
|
||||
|
||||
(a) for any code that a Contributor has removed from Covered Software;
|
||||
or
|
||||
|
||||
(b) for infringements caused by: (i) Your and any other third party's
|
||||
modifications of Covered Software, or (ii) the combination of its
|
||||
Contributions with other software (except as part of its Contributor
|
||||
Version); or
|
||||
|
||||
(c) under Patent Claims infringed by Covered Software in the absence of
|
||||
its Contributions.
|
||||
|
||||
This License does not grant any rights in the trademarks, service marks,
|
||||
or logos of any Contributor (except as may be necessary to comply with
|
||||
the notice requirements in Section 3.4).
|
||||
|
||||
2.4. Subsequent Licenses
|
||||
|
||||
No Contributor makes additional grants as a result of Your choice to
|
||||
distribute the Covered Software under a subsequent version of this
|
||||
License (see Section 10.2) or under the terms of a Secondary License (if
|
||||
permitted under the terms of Section 3.3).
|
||||
|
||||
2.5. Representation
|
||||
|
||||
Each Contributor represents that the Contributor believes its
|
||||
Contributions are its original creation(s) or it has sufficient rights
|
||||
to grant the rights to its Contributions conveyed by this License.
|
||||
|
||||
2.6. Fair Use
|
||||
|
||||
This License is not intended to limit any rights You have under
|
||||
applicable copyright doctrines of fair use, fair dealing, or other
|
||||
equivalents.
|
||||
|
||||
2.7. Conditions
|
||||
|
||||
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted
|
||||
in Section 2.1.
|
||||
|
||||
3. Responsibilities
|
||||
-------------------
|
||||
|
||||
3.1. Distribution of Source Form
|
||||
|
||||
All distribution of Covered Software in Source Code Form, including any
|
||||
Modifications that You create or to which You contribute, must be under
|
||||
the terms of this License. You must inform recipients that the Source
|
||||
Code Form of the Covered Software is governed by the terms of this
|
||||
License, and how they can obtain a copy of this License. You may not
|
||||
attempt to alter or restrict the recipients' rights in the Source Code
|
||||
Form.
|
||||
|
||||
3.2. Distribution of Executable Form
|
||||
|
||||
If You distribute Covered Software in Executable Form then:
|
||||
|
||||
(a) such Covered Software must also be made available in Source Code
|
||||
Form, as described in Section 3.1, and You must inform recipients of
|
||||
the Executable Form how they can obtain a copy of such Source Code
|
||||
Form by reasonable means in a timely manner, at a charge no more
|
||||
than the cost of distribution to the recipient; and
|
||||
|
||||
(b) You may distribute such Executable Form under the terms of this
|
||||
License, or sublicense it under different terms, provided that the
|
||||
license for the Executable Form does not attempt to limit or alter
|
||||
the recipients' rights in the Source Code Form under this License.
|
||||
|
||||
3.3. Distribution of a Larger Work
|
||||
|
||||
You may create and distribute a Larger Work under terms of Your choice,
|
||||
provided that You also comply with the requirements of this License for
|
||||
the Covered Software. If the Larger Work is a combination of Covered
|
||||
Software with a work governed by one or more Secondary Licenses, and the
|
||||
Covered Software is not Incompatible With Secondary Licenses, this
|
||||
License permits You to additionally distribute such Covered Software
|
||||
under the terms of such Secondary License(s), so that the recipient of
|
||||
the Larger Work may, at their option, further distribute the Covered
|
||||
Software under the terms of either this License or such Secondary
|
||||
License(s).
|
||||
|
||||
3.4. Notices
|
||||
|
||||
You may not remove or alter the substance of any license notices
|
||||
(including copyright notices, patent notices, disclaimers of warranty,
|
||||
or limitations of liability) contained within the Source Code Form of
|
||||
the Covered Software, except that You may alter any license notices to
|
||||
the extent required to remedy known factual inaccuracies.
|
||||
|
||||
3.5. Application of Additional Terms
|
||||
|
||||
You may choose to offer, and to charge a fee for, warranty, support,
|
||||
indemnity or liability obligations to one or more recipients of Covered
|
||||
Software. However, You may do so only on Your own behalf, and not on
|
||||
behalf of any Contributor. You must make it absolutely clear that any
|
||||
such warranty, support, indemnity, or liability obligation is offered by
|
||||
You alone, and You hereby agree to indemnify every Contributor for any
|
||||
liability incurred by such Contributor as a result of warranty, support,
|
||||
indemnity or liability terms You offer. You may include additional
|
||||
disclaimers of warranty and limitations of liability specific to any
|
||||
jurisdiction.
|
||||
|
||||
4. Inability to Comply Due to Statute or Regulation
|
||||
---------------------------------------------------
|
||||
|
||||
If it is impossible for You to comply with any of the terms of this
|
||||
License with respect to some or all of the Covered Software due to
|
||||
statute, judicial order, or regulation then You must: (a) comply with
|
||||
the terms of this License to the maximum extent possible; and (b)
|
||||
describe the limitations and the code they affect. Such description must
|
||||
be placed in a text file included with all distributions of the Covered
|
||||
Software under this License. Except to the extent prohibited by statute
|
||||
or regulation, such description must be sufficiently detailed for a
|
||||
recipient of ordinary skill to be able to understand it.
|
||||
|
||||
5. Termination
|
||||
--------------
|
||||
|
||||
5.1. The rights granted under this License will terminate automatically
|
||||
if You fail to comply with any of its terms. However, if You become
|
||||
compliant, then the rights granted under this License from a particular
|
||||
Contributor are reinstated (a) provisionally, unless and until such
|
||||
Contributor explicitly and finally terminates Your grants, and (b) on an
|
||||
ongoing basis, if such Contributor fails to notify You of the
|
||||
non-compliance by some reasonable means prior to 60 days after You have
|
||||
come back into compliance. Moreover, Your grants from a particular
|
||||
Contributor are reinstated on an ongoing basis if such Contributor
|
||||
notifies You of the non-compliance by some reasonable means, this is the
|
||||
first time You have received notice of non-compliance with this License
|
||||
from such Contributor, and You become compliant prior to 30 days after
|
||||
Your receipt of the notice.
|
||||
|
||||
5.2. If You initiate litigation against any entity by asserting a patent
|
||||
infringement claim (excluding declaratory judgment actions,
|
||||
counter-claims, and cross-claims) alleging that a Contributor Version
|
||||
directly or indirectly infringes any patent, then the rights granted to
|
||||
You by any and all Contributors for the Covered Software under Section
|
||||
2.1 of this License shall terminate.
|
||||
|
||||
5.3. In the event of termination under Sections 5.1 or 5.2 above, all
|
||||
end user license agreements (excluding distributors and resellers) which
|
||||
have been validly granted by You or Your distributors under this License
|
||||
prior to termination shall survive termination.
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 6. Disclaimer of Warranty *
|
||||
* ------------------------- *
|
||||
* *
|
||||
* Covered Software is provided under this License on an "as is" *
|
||||
* basis, without warranty of any kind, either expressed, implied, or *
|
||||
* statutory, including, without limitation, warranties that the *
|
||||
* Covered Software is free of defects, merchantable, fit for a *
|
||||
* particular purpose or non-infringing. The entire risk as to the *
|
||||
* quality and performance of the Covered Software is with You. *
|
||||
* Should any Covered Software prove defective in any respect, You *
|
||||
* (not any Contributor) assume the cost of any necessary servicing, *
|
||||
* repair, or correction. This disclaimer of warranty constitutes an *
|
||||
* essential part of this License. No use of any Covered Software is *
|
||||
* authorized under this License except under this disclaimer. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
************************************************************************
|
||||
* *
|
||||
* 7. Limitation of Liability *
|
||||
* -------------------------- *
|
||||
* *
|
||||
* Under no circumstances and under no legal theory, whether tort *
|
||||
* (including negligence), contract, or otherwise, shall any *
|
||||
* Contributor, or anyone who distributes Covered Software as *
|
||||
* permitted above, be liable to You for any direct, indirect, *
|
||||
* special, incidental, or consequential damages of any character *
|
||||
* including, without limitation, damages for lost profits, loss of *
|
||||
* goodwill, work stoppage, computer failure or malfunction, or any *
|
||||
* and all other commercial damages or losses, even if such party *
|
||||
* shall have been informed of the possibility of such damages. This *
|
||||
* limitation of liability shall not apply to liability for death or *
|
||||
* personal injury resulting from such party's negligence to the *
|
||||
* extent applicable law prohibits such limitation. Some *
|
||||
* jurisdictions do not allow the exclusion or limitation of *
|
||||
* incidental or consequential damages, so this exclusion and *
|
||||
* limitation may not apply to You. *
|
||||
* *
|
||||
************************************************************************
|
||||
|
||||
8. Litigation
|
||||
-------------
|
||||
|
||||
Any litigation relating to this License may be brought only in the
|
||||
courts of a jurisdiction where the defendant maintains its principal
|
||||
place of business and such litigation shall be governed by laws of that
|
||||
jurisdiction, without reference to its conflict-of-law provisions.
|
||||
Nothing in this Section shall prevent a party's ability to bring
|
||||
cross-claims or counter-claims.
|
||||
|
||||
9. Miscellaneous
|
||||
----------------
|
||||
|
||||
This License represents the complete agreement concerning the subject
|
||||
matter hereof. If any provision of this License is held to be
|
||||
unenforceable, such provision shall be reformed only to the extent
|
||||
necessary to make it enforceable. Any law or regulation which provides
|
||||
that the language of a contract shall be construed against the drafter
|
||||
shall not be used to construe this License against a Contributor.
|
||||
|
||||
10. Versions of the License
|
||||
---------------------------
|
||||
|
||||
10.1. New Versions
|
||||
|
||||
Mozilla Foundation is the license steward. Except as provided in Section
|
||||
10.3, no one other than the license steward has the right to modify or
|
||||
publish new versions of this License. Each version will be given a
|
||||
distinguishing version number.
|
||||
|
||||
10.2. Effect of New Versions
|
||||
|
||||
You may distribute the Covered Software under the terms of the version
|
||||
of the License under which You originally received the Covered Software,
|
||||
or under the terms of any subsequent version published by the license
|
||||
steward.
|
||||
|
||||
10.3. Modified Versions
|
||||
|
||||
If you create software not governed by this License, and you want to
|
||||
create a new license for such software, you may create and use a
|
||||
modified version of this License if you rename the license and remove
|
||||
any references to the name of the license steward (except to note that
|
||||
such modified license differs from this License).
|
||||
|
||||
10.4. Distributing Source Code Form that is Incompatible With Secondary
|
||||
Licenses
|
||||
|
||||
If You choose to distribute Source Code Form that is Incompatible With
|
||||
Secondary Licenses under the terms of this version of the License, the
|
||||
notice described in Exhibit B of this License must be attached.
|
||||
|
||||
Exhibit A - Source Code Form License Notice
|
||||
-------------------------------------------
|
||||
|
||||
This Source Code Form is subject to the terms of the Mozilla Public
|
||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
file, You can obtain one at https://mozilla.org/MPL/2.0/.
|
||||
|
||||
If it is not possible or desirable to put the notice in a particular
|
||||
file, then You may include the notice in a location (such as a LICENSE
|
||||
file in a relevant directory) where a recipient would be likely to look
|
||||
for such a notice.
|
||||
|
||||
You may add additional accurate notices of copyright ownership.
|
||||
|
||||
Exhibit B - "Incompatible With Secondary Licenses" Notice
|
||||
---------------------------------------------------------
|
||||
|
||||
This Source Code Form is "Incompatible With Secondary Licenses", as
|
||||
defined by the Mozilla Public License, v. 2.0.
|
||||
@@ -3,10 +3,11 @@ services:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
image: gcr.forust.xyz/forust/dtek-notif:latest
|
||||
pull_policy: build
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- TZ=Europe/Kyiv
|
||||
|
||||
dns:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
|
||||
+284
-314
File diff suppressed because it is too large.
Load diff
@@ -0,0 +1,14 @@
|
||||
EDU_LOGIN=your_edu_login_here
|
||||
EDU_PASSWORD=your_edu_password_here
|
||||
EDU_URL_LOGIN=https://edu.edu.vn.ua/user/login
|
||||
EDU_URL_VERIFY=https://edu.edu.vn.ua/course/userlist
|
||||
PHPSESSID_INTERVAL=10
|
||||
USER_AGENT="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36"
|
||||
WEBINAR_URL=https://edu.edu.vn.ua/webinar/useractive
|
||||
WEBINAR_CHECK_INTERVAL=60
|
||||
REDIS_HOST=redis
|
||||
REDIS_PORT=6379
|
||||
PLAYWRIGHT_WS=ws://playwright-service:3000/ws
|
||||
TZ=Europe/Kyiv
|
||||
WEBINAR_TELEGRAM_TOKEN=your_telegram_bot_token_here
|
||||
WEBINAR_ADMIN_ID=123456789
|
||||
@@ -0,0 +1 @@
|
||||
1.56.0
|
||||
@@ -1,15 +0,0 @@
|
||||
ARG VERSION
|
||||
# Use the official WaterCrawl image as the base image
|
||||
FROM watercrawl/watercrawl:${VERSION:-v0.10.2}
|
||||
|
||||
# Set working directory
|
||||
WORKDIR /var/www
|
||||
|
||||
# Copy the extra requirements file
|
||||
COPY extra_requirements.txt /var/www/extra_requirements.txt
|
||||
|
||||
# Install any additional packages
|
||||
RUN poetry run pip install -r /var/www/extra_requirements.txt
|
||||
|
||||
# The rest of the configuration is inherited from the base image
|
||||
# The entrypoint and command should be defined in docker-compose.yml
|
||||
@@ -1 +0,0 @@
|
||||
# Add your additional Python packages here, one per line
|
||||
+37
-250
@@ -1,262 +1,49 @@
|
||||
x-app: &app
|
||||
build:
|
||||
context: ./backend/
|
||||
dockerfile: Dockerfile
|
||||
args:
|
||||
- VERSION=${VERSION:-v0.10.2}
|
||||
depends_on:
|
||||
db:
|
||||
condition: service_healthy
|
||||
dns:
|
||||
- 8.8.8.8
|
||||
- 1.1.1.1
|
||||
environment:
|
||||
- SECRET_KEY=${SECRET_KEY:-django-insecure-el4wo4a4--=f0+ag#omp@^w4eq^8v4(scda&1a(td_y2@=sh6&}
|
||||
- API_ENCRYPTION_KEY=${API_ENCRYPTION_KEY:-8zSd6JIuC7ovfZ4AoxG_XmhubW6CPnQWW7Qe_4TD1TQ=}
|
||||
- DEBUG=${DEBUG:-True}
|
||||
- ALLOWED_HOSTS=${ALLOWED_HOSTS:-*}
|
||||
- LANGUAGE_CODE=${LANGUAGE_CODE:-en-us}
|
||||
- TIME_ZONE=${TIME_ZONE:-UTC}
|
||||
- USE_I18N=${USE_I18N:-True}
|
||||
- USE_TZ=${USE_TZ:-True}
|
||||
- STATIC_ROOT=${STATIC_ROOT:-storage/static/}
|
||||
- MEDIA_ROOT=${MEDIA_ROOT:-storage/media/}
|
||||
- LOG_LEVEL=${LOG_LEVEL:-INFO}
|
||||
- REDIS_URL=${REDIS_URL:-redis://redis:6379/1}
|
||||
- DATABASE_URL=postgres://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@${POSTGRES_HOST:-db}:${POSTGRES_PORT:-5432}/${POSTGRES_DB:-postgres}
|
||||
- CELERY_BROKER_URL=${CELERY_BROKER_URL:-redis://redis:6379/0}
|
||||
- CELERY_RESULT_BACKEND=${CELERY_RESULT_BACKEND:-django-db}
|
||||
- REDIS_LOCKER_URL=${REDIS_LOCKER_URL:-redis://redis:6379/3}
|
||||
- MINIO_ENDPOINT=minio:9000
|
||||
- MINIO_EXTERNAL_ENDPOINT=nginx
|
||||
- MINIO_REGION=us-east-1
|
||||
- MINIO_ACCESS_KEY=minio
|
||||
- MINIO_SECRET_KEY=minio123
|
||||
- MINIO_USE_HTTPS=False
|
||||
- MINIO_EXTERNAL_ENDPOINT_USE_HTTPS=False
|
||||
- MINIO_URL_EXPIRY_HOURS=7
|
||||
- MINIO_PRIVATE_BUCKET=private
|
||||
- MINIO_PUBLIC_BUCKET=public
|
||||
- CSRF_TRUSTED_ORIGINS=${CSRF_TRUSTED_ORIGINS:-}
|
||||
- CORS_ALLOWED_ORIGINS=${CORS_ALLOWED_ORIGINS:-}
|
||||
- CORS_ALLOWED_ORIGIN_REGEXES=${CORS_ALLOWED_ORIGIN_REGEXES:-}
|
||||
- CORS_ALLOW_ALL_ORIGINS=${CORS_ALLOW_ALL_ORIGINS:-False}
|
||||
- FRONTEND_URL=${FRONTEND_URL:-http://localhost}
|
||||
- IS_LOGIN_ACTIVE=${IS_LOGIN_ACTIVE:-True}
|
||||
- IS_SIGNUP_ACTIVE=${IS_SIGNUP_ACTIVE:-True}
|
||||
- IS_GITHUB_LOGIN_ACTIVE=${IS_GITHUB_LOGIN_ACTIVE:-True}
|
||||
- IS_GOOGLE_LOGIN_ACTIVE=${IS_GOOGLE_LOGIN_ACTIVE:-True}
|
||||
- GITHUB_CLIENT_ID=${GITHUB_CLIENT_ID:-}
|
||||
- GITHUB_CLIENT_SECRET=${GITHUB_CLIENT_SECRET:-}
|
||||
- GOOGLE_CLIENT_ID=${GOOGLE_CLIENT_ID:-}
|
||||
- GOOGLE_CLIENT_SECRET=${GOOGLE_CLIENT_SECRET:-}
|
||||
- ACCESS_TOKEN_LIFETIME_MINUTES=${ACCESS_TOKEN_LIFETIME_MINUTES:-5}
|
||||
- REFRESH_TOKEN_LIFETIME_DAYS=${REFRESH_TOKEN_LIFETIME_DAYS:-30}
|
||||
- EMAIL_BACKEND=${EMAIL_BACKEND:-django.core.mail.backends.smtp.EmailBackend}
|
||||
- EMAIL_HOST=${EMAIL_HOST:-}
|
||||
- EMAIL_PORT=${EMAIL_PORT:-587}
|
||||
- EMAIL_USE_TLS=${EMAIL_USE_TLS:-True}
|
||||
- EMAIL_HOST_USER=${EMAIL_HOST_USER:-}
|
||||
- EMAIL_HOST_PASSWORD=${EMAIL_HOST_PASSWORD:-}
|
||||
- DEFAULT_FROM_EMAIL=${DEFAULT_FROM_EMAIL:-}
|
||||
- SCRAPY_USER_AGENT=${SCRAPY_USER_AGENT:-WaterCrawl/0.1 (+https://github.com/watercrawl/watercrawl)}
|
||||
- SCRAPY_ROBOTSTXT_OBEY=${SCRAPY_ROBOTSTXT_OBEY:-True}
|
||||
- SCRAPY_CONCURRENT_REQUESTS=${SCRAPY_CONCURRENT_REQUESTS:-16}
|
||||
- SCRAPY_DOWNLOAD_DELAY=${SCRAPY_DOWNLOAD_DELAY:-0}
|
||||
- SCRAPY_CONCURRENT_REQUESTS_PER_DOMAIN=${SCRAPY_CONCURRENT_REQUESTS_PER_DOMAIN:-4}
|
||||
- SCRAPY_CONCURRENT_REQUESTS_PER_IP=${SCRAPY_CONCURRENT_REQUESTS_PER_IP:-4}
|
||||
- SCRAPY_COOKIES_ENABLED=${SCRAPY_COOKIES_ENABLED:-False}
|
||||
- SCRAPY_HTTPCACHE_ENABLED=${SCRAPY_HTTPCACHE_ENABLED:-True}
|
||||
- SCRAPY_HTTPCACHE_EXPIRATION_SECS=${SCRAPY_HTTPCACHE_EXPIRATION_SECS:-3600}
|
||||
- SCRAPY_HTTPCACHE_DIR=${SCRAPY_HTTPCACHE_DIR:-httpcache}
|
||||
- SCRAPY_LOG_LEVEL=${SCRAPY_LOG_LEVEL:-ERROR}
|
||||
- SCRAPY_GOOGLE_API_KEY=${SCRAPY_GOOGLE_API_KEY:-}
|
||||
- SCRAPY_GOOGLE_CSE_ID=${SCRAPY_GOOGLE_CSE_ID:-}
|
||||
- SCRAPY_MAX_NUMBER_OF_SITEMAP_URLS=${SCRAPY_MAX_NUMBER_OF_SITEMAP_URLS:-20000}
|
||||
- SCRAPY_SITEMAP_CRAWL_PAGE_LIMIT=${SCRAPY_SITEMAP_CRAWL_PAGE_LIMIT:-100}
|
||||
- PLAYWRIGHT_SERVER=${PLAYWRIGHT_SERVER:-http://playwright:8000}
|
||||
- PLAYWRIGHT_API_KEY=${PLAYWRIGHT_API_KEY:-your-secret-api-key}
|
||||
- OPENAI_API_KEY=${OPENAI_API_KEY:-}
|
||||
- STRIPE_SECRET_KEY=${STRIPE_SECRET_KEY:-}
|
||||
- STRIPE_WEBHOOK_SECRET=${STRIPE_WEBHOOK_SECRET:-}
|
||||
- GOOGLE_ANALYTICS_ID=${GOOGLE_ANALYTICS_ID:-}
|
||||
- IS_ENTERPRISE_MODE_ACTIVE=${IS_ENTERPRISE_MODE_ACTIVE:-False}
|
||||
- MAX_CRAWL_DEPTH=${MAX_CRAWL_DEPTH:--1}
|
||||
- CAPTURE_USAGE_HISTORY=${CAPTURE_USAGE_HISTORY:-True}
|
||||
- MCP_SERVER=${MCP_SERVER:-http://localhost/sse}
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- default
|
||||
- n8n
|
||||
|
||||
x-frontend: &frontend
|
||||
image: watercrawl/frontend:${VERSION:-v0.10.2}
|
||||
environment:
|
||||
- VITE_API_BASE_URL=${API_BASE_URL:-http://localhost/api}
|
||||
depends_on:
|
||||
- app
|
||||
|
||||
services:
|
||||
nginx:
|
||||
image: nginx:alpine
|
||||
volumes:
|
||||
- ./nginx/nginx.conf:/etc/nginx/conf.d/default.conf.template
|
||||
- ./nginx/entrypoint.sh:/entrypoint.sh
|
||||
environment:
|
||||
- MINIO_PRIVATE_BUCKET=${MINIO_PRIVATE_BUCKET:-private}
|
||||
- MINIO_PUBLIC_BUCKET=${MINIO_PUBLIC_BUCKET:-public}
|
||||
command: ["/bin/sh", "/entrypoint.sh"]
|
||||
depends_on:
|
||||
- app
|
||||
- frontend
|
||||
- minio
|
||||
restart: unless-stopped
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- n8n
|
||||
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
app:
|
||||
<<: *app
|
||||
command: [ "gunicorn", "-b", "0.0.0.0:9000", "-w", "2", "watercrawl.wsgi:application", "--access-logfile", "-", "--error-logfile", "-", "--timeout", "60" ]
|
||||
|
||||
celery:
|
||||
<<: *app
|
||||
command: [ "celery", "-A", "watercrawl", "worker", "-l", "info", "-S", "django" ]
|
||||
dns:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
|
||||
celery-beat:
|
||||
<<: *app
|
||||
command: [ "celery", "-A", "watercrawl", "beat", "-l", "info", "-S", "django" ]
|
||||
|
||||
frontend:
|
||||
<<: *frontend
|
||||
command: [ "npm", "run", "serve" ]
|
||||
|
||||
minio:
|
||||
image: minio/minio:RELEASE.2024-11-07T00-52-20Z
|
||||
redis:
|
||||
image: redis:8.10.1-alpine
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./volumes/minio-data:/data
|
||||
command: server /data --console-address ":9001"
|
||||
environment:
|
||||
- MINIO_BROWSER_REDIRECT_URL=${MINIO_BROWSER_REDIRECT_URL:-http://localhost/minio-console/}
|
||||
- MINIO_SERVER_URL=${MINIO_SERVER_URL:-http://localhost/}
|
||||
- MINIO_ROOT_USER=${MINIO_ACCESS_KEY:-minio}
|
||||
- MINIO_ROOT_PASSWORD=${MINIO_SECRET_KEY:-minio123}
|
||||
|
||||
playwright:
|
||||
image: watercrawl/playwright:1.1
|
||||
restart: unless-stopped
|
||||
user: root
|
||||
environment:
|
||||
- AUTH_API_KEY=${PLAYWRIGHT_API_KEY:-your-secret-api-key}
|
||||
- PORT=${PLAYWRIGHT_PORT:-8000}
|
||||
- HOST=${PLAYWRIGHT_HOST:-0.0.0.0}
|
||||
dns:
|
||||
- 8.8.8.8
|
||||
- 1.1.1.1
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- n8n
|
||||
|
||||
db:
|
||||
image: postgres:17.2-alpine3.21
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-postgres}
|
||||
- POSTGRES_USER=${POSTGRES_USER:-postgres}
|
||||
- POSTGRES_DB=${POSTGRES_DB:-postgres}
|
||||
volumes:
|
||||
- ./volumes/postgres-db:/var/lib/postgresql/data
|
||||
- redis-data:/data
|
||||
healthcheck:
|
||||
test: [ "CMD-SHELL", "pg_isready" ]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
test: ["CMD", "redis-cli", "ping"]
|
||||
interval: 5s
|
||||
timeout: 3s
|
||||
retries: 5
|
||||
|
||||
mcp:
|
||||
image: watercrawl/mcp:v1.2.0
|
||||
playwright-service:
|
||||
image: mcr.microsoft.com/playwright:v1.56.0-jammy
|
||||
restart: unless-stopped
|
||||
command: [ "sse", "--base-url", "http://app:9000", '--port', '3000', '--endpoint', '/sse' ]
|
||||
networks:
|
||||
- n8n
|
||||
command: npx -y playwright@1.56.0 run-server --port 3000 --path /ws
|
||||
|
||||
session-keeper:
|
||||
build: ./phpsessid-bot
|
||||
image: gcr.forust.xyz/forust/session-keeper:latest
|
||||
pull_policy: build
|
||||
env_file: .env
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
redis:
|
||||
image: redis:latest
|
||||
condition: service_healthy
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "redis-cli -h redis EXISTS EDU_PHPSESSID | grep -q 1"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
retries: 10
|
||||
start_period: 60s
|
||||
|
||||
webinar-checker:
|
||||
build: ./webinar-checker
|
||||
image: gcr.forust.xyz/forust/webinar-checker:latest
|
||||
pull_policy: build
|
||||
env_file: .env
|
||||
restart: unless-stopped
|
||||
|
||||
llm:
|
||||
image: ollama/ollama:latest
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./volumes/ollama-models:/root/.ollama
|
||||
environment:
|
||||
- OLLAMA_DISABLE_TELEMETRY=true
|
||||
- OLLAMA_KEEP_ALIVE=5m
|
||||
- OLLAMA_HOST=0.0.0.0:11434
|
||||
- OLLAMA_NUM_PARALLEL=1
|
||||
- OLLAMA_MAX_LOADED_MODELS=1
|
||||
dns:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
networks:
|
||||
- n8n
|
||||
|
||||
# docker exec -it edu_master-llm-1 ollama pull neural-chat:7b-q4
|
||||
# docker exec -it edu_master-llm-1 ollama pull mistral:7b-q4
|
||||
|
||||
# lessons-bot:
|
||||
# build:
|
||||
# context: edu_master/lessons_bot/
|
||||
# dockerfile: Dockerfile
|
||||
# restart: unless-stopped
|
||||
# environment:
|
||||
# - LESSONS_BOT_TOKEN=${LESSONS_BOT_TOKEN}
|
||||
# - N8N_WEBHOOK_URL=${N8N_WEBHOOK_URL:-http://n8n:5678/webhook-test/get-lessons}
|
||||
# - N8N_SECRET=${N8N_SECRET:-your-secret-token-here}
|
||||
# - WATERCRAWL_API_URL=${WATERCRAWL_API_URL:-http://app:9000/api}
|
||||
# - PHPSESSID_BOT_URL=${PHPSESSID_BOT_URL:-http://phpsessid-bot:5000}
|
||||
# - EDU_HOST=${EDU_HOST:-edu.edu.vn.ua}
|
||||
# depends_on:
|
||||
# - n8n
|
||||
# - app
|
||||
# - phpsessid-bot
|
||||
# dns:
|
||||
# - 1.1.1.1
|
||||
# - 8.8.8.8
|
||||
# networks:
|
||||
# - default
|
||||
|
||||
phpsessid-bot:
|
||||
build:
|
||||
context: ./phpsessid_bot/
|
||||
dockerfile: Dockerfile
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- EDU_HOST=${EDU_HOST:-edu.edu.vn.ua}
|
||||
- EDU_LOGIN=${EDU_LOGIN}
|
||||
- EDU_PASSWORD=${EDU_PASSWORD}
|
||||
- BOT_PORT=${PHPSESSID_BOT_PORT:-5000}
|
||||
- BOT_HOST=${PHPSESSID_BOT_HOST:-0.0.0.0}
|
||||
dns:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
networks:
|
||||
- default
|
||||
|
||||
depends_on:
|
||||
redis:
|
||||
condition: service_healthy
|
||||
session-keeper:
|
||||
condition: service_healthy
|
||||
playwright-service:
|
||||
condition: service_started
|
||||
|
||||
volumes:
|
||||
n8n_data:
|
||||
postgres-db:
|
||||
minio-data:
|
||||
ollama-models:
|
||||
lmstudio_data:
|
||||
networks:
|
||||
traefik-proxy:
|
||||
external: true
|
||||
redis-data:
|
||||
Whitespace-only changes.
@@ -0,0 +1,77 @@
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: PrometheusRule
|
||||
metadata:
|
||||
name: edu-master-webinar
|
||||
namespace: edu-master
|
||||
labels:
|
||||
release: prometheus-stack
|
||||
spec:
|
||||
groups:
|
||||
- name: edu_master.webinar
|
||||
rules:
|
||||
# No successful webinar check for 5m (~2-3 missed 2-min checks).
|
||||
# Catches: playwright hangs/timeouts, version skew, site changes, hung job.
|
||||
- alert: WebinarCheckerNoSuccessfulCheck
|
||||
expr: |
|
||||
(time() - webinar_check_last_success_timestamp_seconds > 300)
|
||||
and (webinar_check_last_run_timestamp_seconds > 0)
|
||||
for: 2m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Webinar checker has no successful check for 5m"
|
||||
description: "edu-master/webinar-checker: last successful webinar check was {{ $value | humanizeDuration }} ago. Checks are failing or hanging (see consecutive failures alert). Notifications about new webinars are NOT being sent."
|
||||
|
||||
# Fast path: 3 consecutive failures (~6+ min at 2-min interval).
|
||||
- alert: WebinarCheckerConsecutiveFailures
|
||||
expr: |
|
||||
webinar_check_consecutive_failures >= 3
|
||||
for: 5m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Webinar checker failing consecutively"
|
||||
description: 'edu-master/webinar-checker: {{ $value }} consecutive webinar check failures (timeout / playwright error / page error). Check pod logs (Loki: {namespace="edu-master", container="webinar-checker"}).'
|
||||
|
||||
# Metrics endpoint not scraped for 10m: pod down, metrics server dead, or ServiceMonitor broken.
|
||||
- alert: WebinarCheckerScrapeDown
|
||||
expr: |
|
||||
absent(webinar_check_last_run_timestamp_seconds) == 1
|
||||
for: 10m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Webinar checker metrics missing"
|
||||
description: "edu-master/webinar-checker: no metrics series for 10m. Pod may be down, metrics server dead, or ServiceMonitor/Service broken. Webinar checks are unobserved."
|
||||
|
||||
# EDU session lost: session-keeper down or credentials expired. Without PHPSESSID every check is skipped.
|
||||
- alert: EduPhpsessidMissing
|
||||
expr: |
|
||||
edu_phpsessid_present == 0
|
||||
for: 10m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "EDU_PHPSESSID missing"
|
||||
description: "edu-master: EDU_PHPSESSID absent from redis for 10m. Webinar/diari/schedule checks are all skipped. Check session-keeper logs and EDU credentials."
|
||||
|
||||
# Hard deps: checker and playwright deployments unavailable.
|
||||
- alert: WebinarCheckerDeploymentDown
|
||||
expr: |
|
||||
kube_deployment_status_replicas_unavailable{deployment="webinar-checker", namespace="edu-master"} > 0
|
||||
for: 10m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Webinar checker deployment unavailable"
|
||||
description: "edu-master/webinar-checker deployment has {{ $value }} unavailable replica(s) for 10m."
|
||||
|
||||
- alert: PlaywrightServiceDown
|
||||
expr: |
|
||||
kube_deployment_status_replicas_unavailable{deployment="playwright-service", namespace="edu-master"} > 0
|
||||
for: 10m
|
||||
labels:
|
||||
severity: critical
|
||||
annotations:
|
||||
summary: "Playwright service unavailable"
|
||||
description: "edu-master/playwright-service deployment has {{ $value }} unavailable replica(s) for 10m. All webinar/diari/schedule checks fail without it."
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: edu-master
|
||||
@@ -0,0 +1,58 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: playwright-service
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-playwright
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-playwright
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: edu-master-playwright
|
||||
spec:
|
||||
containers:
|
||||
- name: playwright
|
||||
# renovate: datasource=docker depName=mcr.microsoft.com/playwright versioning=docker
|
||||
image: mcr.microsoft.com/playwright:v1.56.0-jammy
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- npx
|
||||
- -y
|
||||
- playwright@1.56.0
|
||||
- run-server
|
||||
- --port
|
||||
- "3000"
|
||||
- --path
|
||||
- /ws
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
readinessProbe:
|
||||
tcpSocket:
|
||||
port: 3000
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 3
|
||||
livenessProbe:
|
||||
tcpSocket:
|
||||
port: 3000
|
||||
initialDelaySeconds: 15
|
||||
periodSeconds: 20
|
||||
timeoutSeconds: 3
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: playwright-service
|
||||
namespace: edu-master
|
||||
spec:
|
||||
selector:
|
||||
app: edu-master-playwright
|
||||
ports:
|
||||
- name: ws
|
||||
port: 3000
|
||||
targetPort: 3000
|
||||
@@ -0,0 +1,75 @@
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: redis
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-redis
|
||||
spec:
|
||||
serviceName: redis
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-redis
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: edu-master-redis
|
||||
spec:
|
||||
containers:
|
||||
- name: redis
|
||||
image: redis:8.10.1-alpine
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 6379
|
||||
volumeMounts:
|
||||
- name: redis-data
|
||||
mountPath: /data
|
||||
resources:
|
||||
requests:
|
||||
cpu: 25m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
cpu: 250m
|
||||
memory: 256Mi
|
||||
readinessProbe:
|
||||
exec:
|
||||
command: ["redis-cli", "ping"]
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 5
|
||||
timeoutSeconds: 3
|
||||
livenessProbe:
|
||||
exec:
|
||||
command: ["redis-cli", "ping"]
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 3
|
||||
volumes:
|
||||
- name: redis-data
|
||||
persistentVolumeClaim:
|
||||
claimName: redis-data-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: redis-data-pvc
|
||||
namespace: edu-master
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: redis
|
||||
namespace: edu-master
|
||||
spec:
|
||||
selector:
|
||||
app: edu-master-redis
|
||||
ports:
|
||||
- name: redis
|
||||
port: 6379
|
||||
targetPort: 6379
|
||||
@@ -0,0 +1,50 @@
|
||||
# One-time Job to migrate redis state from docker compose to k8s (maintenance window).
|
||||
# The .example file is not applied by the deploy pipeline (mask *.example.yaml).
|
||||
#
|
||||
# Runbook:
|
||||
# 1. docker compose -f <repo>/edu_master/compose.yaml stop # SIGTERM -> redis will flush dump.rdb
|
||||
# 2. docker run --rm -v edu_master_redis-data:/data \
|
||||
# -v /tmp/edu-master-backup:/backup \
|
||||
# redis:alpine sh -c "cp /data/dump.rdb /backup/ && ls -la /backup"
|
||||
# 3. kubectl apply -f edu_master/k8s/namespace.yaml
|
||||
# 4. kubectl apply -f <only the PVC from redis.yaml> # seed must come BEFORE redis pod starts
|
||||
# 5. kubectl apply -f edu_master/k8s/restore-seed-job.yaml.example
|
||||
# kubectl wait --for=condition=complete job/redis-restore-seed -n edu-master --timeout=120s
|
||||
# 6. kubectl delete job redis-restore-seed -n edu-master
|
||||
# 7. kubectl apply -f edu_master/k8s/ -R # apply remaining manifests
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: redis-restore-seed
|
||||
namespace: edu-master
|
||||
spec:
|
||||
backoffLimit: 2
|
||||
ttlSecondsAfterFinished: 3600
|
||||
template:
|
||||
spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: seed
|
||||
image: redis:alpine
|
||||
command:
|
||||
- /bin/sh
|
||||
- -ec
|
||||
- |
|
||||
ls -la /backup
|
||||
cp /backup/dump.rdb /data/dump.rdb
|
||||
chmod 644 /data/dump.rdb
|
||||
ls -la /data
|
||||
volumeMounts:
|
||||
- name: redis-data
|
||||
mountPath: /data
|
||||
- name: backup
|
||||
mountPath: /backup
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: redis-data
|
||||
persistentVolumeClaim:
|
||||
claimName: redis-data-pvc
|
||||
- name: backup
|
||||
hostPath:
|
||||
path: /tmp/edu-master-backup
|
||||
type: DirectoryOrCreate
|
||||
@@ -0,0 +1,29 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: edu-master-secrets
|
||||
namespace: edu-master
|
||||
type: Opaque
|
||||
stringData:
|
||||
# Session keeper credentials
|
||||
KEEPER_LOGIN: ""
|
||||
KEEPER_PASSWORD: ""
|
||||
KEEPER_INTERVAL: "10"
|
||||
# EDU links
|
||||
EDU_URL_BASE: "https://edu.edu.vn.ua"
|
||||
EDU_URL_LOGIN: "/user/login"
|
||||
EDU_URL_COURSES: "/course/userlist"
|
||||
EDU_URL_WEBINAR: "/webinar/useractive"
|
||||
# Playwright
|
||||
USER_AGENT: ""
|
||||
PLAYWRIGHT_WS: "ws://playwright-service:3000/ws"
|
||||
# Webinar-checker
|
||||
WEBINAR_TELEGRAM_TOKEN: ""
|
||||
WEBINAR_ADMIN_ID: ""
|
||||
WEBINAR_CHECK_INTERVAL: "60"
|
||||
# Prometheus metrics endpoint (scraped via ServiceMonitor, alerts in k8s/alerts.yaml)
|
||||
METRICS_PORT: "8000"
|
||||
# Database
|
||||
REDIS_HOST: "redis"
|
||||
REDIS_PORT: "6379"
|
||||
TZ: "Europe/Kyiv"
|
||||
@@ -0,0 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: webinar-checker
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-webinar-checker
|
||||
spec:
|
||||
selector:
|
||||
app: edu-master-webinar-checker
|
||||
ports:
|
||||
- name: metrics
|
||||
port: 8000
|
||||
targetPort: metrics
|
||||
protocol: TCP
|
||||
@@ -0,0 +1,16 @@
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: webinar-checker
|
||||
namespace: edu-master
|
||||
labels:
|
||||
release: prometheus-stack
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-webinar-checker
|
||||
endpoints:
|
||||
- port: metrics
|
||||
path: /metrics
|
||||
interval: 30s
|
||||
scrapeTimeout: 10s
|
||||
@@ -0,0 +1,52 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: session-keeper
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-session-keeper
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-session-keeper
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: edu-master-session-keeper
|
||||
spec:
|
||||
initContainers:
|
||||
- name: wait-redis
|
||||
image: redis:8.10.1-alpine
|
||||
command:
|
||||
- /bin/sh
|
||||
- -ec
|
||||
- |
|
||||
i=0
|
||||
until redis-cli -h redis ping | grep -q PONG; do
|
||||
i=$((i+1))
|
||||
[ "$i" -ge 300 ] && echo "TIMEOUT: redis not ready" && exit 1
|
||||
sleep 2
|
||||
done
|
||||
echo "redis is ready"
|
||||
containers:
|
||||
- name: session-keeper
|
||||
image: gcr.forust.xyz/forust/session-keeper:latest
|
||||
imagePullPolicy: Always
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: edu-master-secrets
|
||||
resources:
|
||||
requests:
|
||||
cpu: 25m
|
||||
memory: 96Mi
|
||||
limits:
|
||||
cpu: 250m
|
||||
memory: 256Mi
|
||||
readinessProbe:
|
||||
exec:
|
||||
command: ["/bin/sh", "-ec", "redis-cli -h redis EXISTS EDU_PHPSESSID | grep -q 1"]
|
||||
initialDelaySeconds: 15
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 10
|
||||
@@ -0,0 +1,66 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: webinar-checker
|
||||
namespace: edu-master
|
||||
labels:
|
||||
app: edu-master-webinar-checker
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: edu-master-webinar-checker
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: edu-master-webinar-checker
|
||||
spec:
|
||||
# Enforces dependency order like compose depends_on:
|
||||
# redis healthy -> session-keeper healthy (EXISTS EDU_PHPSESSID) -> playwright started
|
||||
initContainers:
|
||||
- name: wait-deps
|
||||
image: redis:8.10.1-alpine
|
||||
command:
|
||||
- /bin/sh
|
||||
- -ec
|
||||
- |
|
||||
i=0
|
||||
until redis-cli -h redis ping | grep -q PONG; do
|
||||
i=$((i+1))
|
||||
[ "$i" -ge 300 ] && echo "TIMEOUT: redis not ready" && exit 1
|
||||
sleep 2
|
||||
done
|
||||
echo "redis ok"
|
||||
until [ "$(redis-cli -h redis EXISTS EDU_PHPSESSID)" = "1" ]; do
|
||||
i=$((i+1))
|
||||
[ "$i" -ge 300 ] && echo "TIMEOUT: no PHPSESSID (session-keeper down?)" && exit 1
|
||||
sleep 2
|
||||
done
|
||||
echo "PHPSESSID ok"
|
||||
until nc -z playwright-service 3000; do
|
||||
i=$((i+1))
|
||||
[ "$i" -ge 300 ] && echo "TIMEOUT: playwright-service not reachable" && exit 1
|
||||
sleep 2
|
||||
done
|
||||
echo "playwright ok"
|
||||
containers:
|
||||
- name: webinar-checker
|
||||
image: gcr.forust.xyz/forust/webinar-checker:latest
|
||||
imagePullPolicy: Always
|
||||
ports:
|
||||
- name: metrics
|
||||
containerPort: 8000
|
||||
protocol: TCP
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: edu-master-secrets
|
||||
env:
|
||||
- name: TZ
|
||||
value: "Europe/Kyiv"
|
||||
resources:
|
||||
requests:
|
||||
cpu: "50m"
|
||||
memory: "128Mi"
|
||||
limits:
|
||||
cpu: "600m"
|
||||
memory: "512Mi"
|
||||
Loaded 100 of 472 files, more files were not shown because too many files have changed in this diff.
Show more
Reference in new issue
Block a user