cluster

Infrastructure files for Nordgedanken and Midnightthoughts.
git clone git://archive.git.mtrnord.blog/MTRNord/cluster.git
Log | Files | Refs | README

commit 462ff699e7f084ed7a78a48a2002b7d28721fd2e
parent 7367494c589383cb4f64f8575f113ee8e695e262
Author: MTRNord <MTRNord@users.noreply.github.com>
Date:   Mon,  4 Aug 2025 16:11:08 +0200

Migrate ntfy

Diffstat:
Mapps/base/envoy-gateway/release.yaml | 212++++++++++++++++++++++++++++++++++++++++----------------------------------------
Mapps/talos_cluster/connectivity-tester/deployment.yaml | 170++++++++++++++++++++++++++++++++++++++++----------------------------------------
Mapps/talos_cluster/continuwuity/deployment.yaml | 1-
Mapps/talos_cluster/continuwuity/kustomization.yaml | 2+-
Mapps/talos_cluster/envoy-gateway/gateway_settings.yaml | 288++++++++++++++++++++++++++++++++++++++++----------------------------------------
Mapps/talos_cluster/freshrss/deployment.yaml | 1-
Mapps/talos_cluster/kustomization.yaml | 1+
Aapps/talos_cluster/ntfy/kustomization.yaml | 10++++++++++
Aapps/talos_cluster/ntfy/ntfy.yml | 10++++++++++
Aapps/talos_cluster/ntfy/pvc.yaml | 13+++++++++++++
Aapps/talos_cluster/ntfy/release.yaml | 111+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
11 files changed, 481 insertions(+), 338 deletions(-)

diff --git a/apps/base/envoy-gateway/release.yaml b/apps/base/envoy-gateway/release.yaml @@ -75,42 +75,42 @@ spec: protocol: TCP port: 25 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submissions protocol: TCP port: 465 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submission protocol: TCP port: 587 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imap protocol: TCP port: 143 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imaps protocol: TCP port: 993 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All --- apiVersion: gateway.networking.k8s.io/v1 kind: Gateway @@ -159,25 +159,25 @@ spec: hostname: "docuseal.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: docuseal.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: docuseal.midnightthoughts.space-tls - name: https-midnightthoughts-neoboard protocol: HTTPS hostname: "miro-export.neoboard.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: miro-export.neoboard.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: miro-export.neoboard.midnightthoughts.space-tls # - name: https-midnightthoughts-certs # protocol: HTTPS # hostname: "certs.midnightthoughts.space" @@ -255,13 +255,13 @@ spec: hostname: "bugzilla.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: bugzilla.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: bugzilla.midnightthoughts.space-tls # - name: https-midnightthoughts-root # protocol: HTTPS # hostname: "midnightthoughts.space" @@ -303,13 +303,13 @@ spec: hostname: "rspamd.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rspamd.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rspamd.midnightthoughts.space-tls # - name: https-midnightthoughts-grafana # protocol: HTTPS # hostname: "grafana.midnightthoughts.space" @@ -327,13 +327,13 @@ spec: hostname: "osticket.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: osticket.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: osticket.midnightthoughts.space-tls # - name: https-midnightthoughts-vault # protocol: HTTPS # hostname: "vault.midnightthoughts.space" @@ -351,13 +351,13 @@ spec: hostname: "rook.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rook.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rook.midnightthoughts.space-tls # - name: https-midnightthoughts-jenkins # protocol: HTTPS # hostname: "jenkins.midnightthoughts.space" @@ -423,13 +423,13 @@ spec: hostname: "plane.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: plane.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: plane.midnightthoughts.space # - name: https-midnightthoughts-irc # protocol: HTTPS # hostname: "irc.midnightthoughts.space" @@ -531,13 +531,13 @@ spec: hostname: "mastodon.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mastodon.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: mastodon.mtrnord.blog-tls # - name: https-api-connectivity-tester-mtrnord-blog # protocol: HTTPS # hostname: "api.connectivity-tester.mtrnord.blog" @@ -591,55 +591,55 @@ spec: hostname: "notify.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: notify.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: notify.mtrnord.blog-tls - name: https-rss-mtrnord-blog protocol: HTTPS hostname: "rss.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rss.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rss.mtrnord.blog-tls - name: http protocol: HTTP port: 80 allowedRoutes: - namespaces: - from: "All" - # - name: ldap - # protocol: TCP - # port: 389 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All - # - name: gerrit-ssh - # protocol: TCP - # port: 29418 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All - # - name: ircs - # protocol: TCP - # port: 6697 - # allowedRoutes: - # kinds: - # - kind: TCPRoute - # namespaces: - # from: All + namespaces: + from: "All" + # - name: ldap + # protocol: TCP + # port: 389 + # allowedRoutes: + # kinds: + # - kind: TCPRoute + # namespaces: + # from: All + # - name: gerrit-ssh + # protocol: TCP + # port: 29418 + # allowedRoutes: + # kinds: + # - kind: TCPRoute + # namespaces: + # from: All + # - name: ircs + # protocol: TCP + # port: 6697 + # allowedRoutes: + # kinds: + # - kind: TCPRoute + # namespaces: + # from: All --- apiVersion: gateway.envoyproxy.io/v1alpha1 kind: ClientTrafficPolicy diff --git a/apps/talos_cluster/connectivity-tester/deployment.yaml b/apps/talos_cluster/connectivity-tester/deployment.yaml @@ -21,11 +21,11 @@ spec: podAntiAffinity: requiredDuringSchedulingIgnoredDuringExecution: - labelSelector: - matchExpressions: - - key: app - operator: In - values: - - connectivity-tester + matchExpressions: + - key: app + operator: In + values: + - connectivity-tester topologyKey: "kubernetes.io/hostname" imagePullSecrets: - name: ghcr-pull @@ -35,48 +35,48 @@ spec: image: ghcr.io/mtrnord/matrix-connection-tester-ui:v0.2.0 imagePullPolicy: Always lifecycle: - preStop: - exec: - command: - - sleep - - "10" + preStop: + exec: + command: + - sleep + - "10" resources: - limits: {} - requests: - memory: "100Mi" - cpu: "100m" + limits: {} + requests: + memory: "100Mi" + cpu: "100m" ports: - - containerPort: 3000 - name: web - protocol: TCP + - containerPort: 3000 + name: web + protocol: TCP volumeMounts: - - name: configs - mountPath: "/usr/share/nginx/html/config.json" - subPath: config.json - readOnly: true - - mountPath: /tmp - name: tmp + - name: configs + mountPath: "/usr/share/nginx/html/config.json" + subPath: config.json + readOnly: true + - mountPath: /tmp + name: tmp livenessProbe: - httpGet: - path: / - port: web - scheme: HTTP + httpGet: + path: / + port: web + scheme: HTTP readinessProbe: - httpGet: - path: / - port: web - scheme: HTTP + httpGet: + path: / + port: web + scheme: HTTP startupProbe: - httpGet: - path: / - port: web + httpGet: + path: / + port: web volumes: - name: configs configMap: - name: connectivity-tester-config + name: connectivity-tester-config - name: tmp emptyDir: - sizeLimit: 2048Mi + sizeLimit: 2048Mi --- apiVersion: apps/v1 kind: Deployment @@ -101,11 +101,11 @@ spec: podAntiAffinity: requiredDuringSchedulingIgnoredDuringExecution: - labelSelector: - matchExpressions: - - key: app - operator: In - values: - - connectivity-tester-api + matchExpressions: + - key: app + operator: In + values: + - connectivity-tester-api topologyKey: "kubernetes.io/hostname" imagePullSecrets: - name: ghcr-pull @@ -116,41 +116,41 @@ spec: image: ghcr.io/mtrnord/rust-federation-tester:v0.2.2 imagePullPolicy: IfNotPresent resources: - limits: {} - requests: - memory: "344Mi" - cpu: "252m" + limits: {} + requests: + memory: "344Mi" + cpu: "252m" volumeMounts: - - name: api-config - mountPath: /app/config.yaml - subPath: config.yaml - readOnly: true + - name: api-config + mountPath: /app/config.yaml + subPath: config.yaml + readOnly: true securityContext: - runAsUser: 1000 - runAsGroup: 1000 - readOnlyRootFilesystem: true + runAsUser: 1000 + runAsGroup: 1000 + readOnlyRootFilesystem: true ports: - - containerPort: 8080 - name: api - protocol: TCP + - containerPort: 8080 + name: api + protocol: TCP readinessProbe: - httpGet: - path: /healthz - port: api - scheme: HTTP + httpGet: + path: /healthz + port: api + scheme: HTTP livenessProbe: - httpGet: - path: /healthz - port: api - scheme: HTTP + httpGet: + path: /healthz + port: api + scheme: HTTP startupProbe: - httpGet: - path: /healthz - port: api + httpGet: + path: /healthz + port: api volumes: - name: api-config secret: - secretName: connectivity-tester-config + secretName: connectivity-tester-config --- apiVersion: flagger.app/v1beta1 kind: MetricTemplate @@ -251,18 +251,18 @@ spec: # max error rate (5xx responses) # percentage (0-100) templateRef: - name: connectivity-tester-error-rate - namespace: matrix + name: connectivity-tester-error-rate + namespace: matrix thresholdRange: - max: 2 + max: 2 interval: 1m - name: latency templateRef: - name: connectivity-tester-latency - namespace: matrix + name: connectivity-tester-latency + namespace: matrix # seconds thresholdRange: - max: 1 + max: 1 interval: 30s sessionAffinity: cookieName: flagger-cookie @@ -273,13 +273,13 @@ spec: url: http://flagger-loadtester.flagger-system/ timeout: 15s metadata: - type: bash - cmd: "curl -s http://connectivity-tester-canary.matrix:3000" + type: bash + cmd: "curl -s http://connectivity-tester-canary.matrix:3000" - name: load-test url: http://flagger-loadtester.flagger-system/ timeout: 10m metadata: - cmd: "hey -z 10m -q 10 -c 2 http://connectivity-tester-canary.matrix/?serverName=mtrnord.blog" + cmd: "hey -z 10m -q 10 -c 2 http://connectivity-tester-canary.matrix/?serverName=mtrnord.blog" --- apiVersion: flagger.app/v1beta1 kind: Canary @@ -332,18 +332,18 @@ spec: # max error rate (5xx responses) # percentage (0-100) templateRef: - name: connectivity-tester-error-rate - namespace: matrix + name: connectivity-tester-error-rate + namespace: matrix thresholdRange: - max: 2 + max: 2 interval: 1m - name: latency templateRef: - name: connectivity-tester-latency - namespace: matrix + name: connectivity-tester-latency + namespace: matrix # seconds thresholdRange: - max: 1 + max: 1 interval: 30s sessionAffinity: cookieName: flagger-cookie @@ -354,10 +354,10 @@ spec: url: http://flagger-loadtester.flagger-system/ timeout: 15s metadata: - type: bash - cmd: "curl -s http://connectivity-tester-api-canary.matrix:8080/healthz | grep 'ok'" + type: bash + cmd: "curl -s http://connectivity-tester-api-canary.matrix:8080/healthz | grep 'ok'" - name: load-test url: http://flagger-loadtester.flagger-system/ timeout: 10m metadata: - cmd: "hey -z 10m -q 10 -c 2 http://connectivity-tester-api-canary.matrix/api/federation/federation-ok?serverName=mtrnord.blog&no_cache=true" + cmd: "hey -z 10m -q 10 -c 2 http://connectivity-tester-api-canary.matrix/api/federation/federation-ok?serverName=mtrnord.blog&no_cache=true" diff --git a/apps/talos_cluster/continuwuity/deployment.yaml b/apps/talos_cluster/continuwuity/deployment.yaml @@ -1,4 +1,3 @@ ---- apiVersion: apps/v1 kind: Deployment metadata: diff --git a/apps/talos_cluster/continuwuity/kustomization.yaml b/apps/talos_cluster/continuwuity/kustomization.yaml @@ -8,5 +8,5 @@ secretGenerator: - name: continuwuity-config namespace: continuwuity files: - - conduwuit.toml=continuwuity.toml + - conduwuit.toml=continuwuity.toml type: Opaque diff --git a/apps/talos_cluster/envoy-gateway/gateway_settings.yaml b/apps/talos_cluster/envoy-gateway/gateway_settings.yaml @@ -48,42 +48,42 @@ spec: protocol: TCP port: 25 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submissions protocol: TCP port: 465 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submission protocol: TCP port: 587 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imap protocol: TCP port: 143 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imaps protocol: TCP port: 993 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All --- apiVersion: gateway.networking.k8s.io/v1 kind: Gateway @@ -108,225 +108,237 @@ spec: hostname: "talos.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: talos.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: talos.midnightthoughts.space-tls - name: https-midnightthoughts-auth protocol: HTTPS hostname: "auth.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: auth.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: auth.midnightthoughts.space-tls - name: https-midnightthoughts-grafana protocol: HTTPS hostname: "grafana.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: grafana.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: grafana.midnightthoughts.space-tls - name: https-draupnir-midnightthoughts protocol: HTTPS hostname: "draupnir.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: draupnir.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: draupnir.midnightthoughts.space-tls - name: https-matrix-draupnir-midnightthoughts protocol: HTTPS hostname: "matrix.draupnir.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: matrix.draupnir.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: matrix.draupnir.midnightthoughts.space-tls - name: https-midnightthoughts-vault protocol: HTTPS hostname: "vault.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: vault.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: vault.midnightthoughts.space-tls - name: https-midnightthoughts-budget protocol: HTTPS hostname: "budget.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: budget.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: budget.midnightthoughts.space-tls - name: https-midnightthoughts-ldap protocol: HTTPS hostname: "ldap.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: ldap.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: ldap.midnightthoughts.space-tls - name: ldap protocol: TCP port: 389 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: https-mtrnord-blog-gts protocol: HTTPS hostname: "gts.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: gts.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: gts.mtrnord.blog-tls - name: https-midnightthoughts-collabora protocol: HTTPS hostname: "collabora.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: collabora.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: collabora.midnightthoughts.space - name: https-midnightthoughts-webhook-kubernetes protocol: HTTPS hostname: "webhook.kubernetes.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: webhook.kubernetes.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: webhook.kubernetes.midnightthoughts.space-tls - name: https-api-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "api.connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: api.connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: api.connectivity-tester.mtrnord.blog-tls - name: https-stage-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "stage.connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: stage.connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: stage.connectivity-tester.mtrnord.blog-tls - name: https-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: connectivity-tester.mtrnord.blog-tls - name: https-federationtester-mtrnord-blog protocol: HTTPS hostname: "federationtester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: federationtester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: federationtester.mtrnord.blog-tls - name: https-mtrnord-blog-root protocol: HTTPS hostname: "mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: mtrnord.blog-tls - name: https-mtrnord-blog-matrix protocol: HTTPS hostname: "matrix.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: matrix.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: matrix.mtrnord.blog-tls - name: https-rss-mtrnord-blog protocol: HTTPS hostname: "rss.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rss.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rss.mtrnord.blog-tls + - name: https-notify-mtrnord-blog + protocol: HTTPS + hostname: "notify.mtrnord.blog" + port: 443 + allowedRoutes: + namespaces: + from: "All" + tls: + mode: Terminate + certificateRefs: + - kind: Secret + name: notify.mtrnord.blog-tls # - name: https-docuseal-midnightthoughts # protocol: HTTPS # hostname: "docuseal.midnightthoughts.space" @@ -411,18 +423,6 @@ spec: # certificateRefs: # - kind: Secret # name: plane.midnightthoughts.space - # - name: https-notify-mtrnord-blog - # protocol: HTTPS - # hostname: "notify.mtrnord.blog" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: notify.mtrnord.blog-tls # - name: http # protocol: HTTP # port: 80 diff --git a/apps/talos_cluster/freshrss/deployment.yaml b/apps/talos_cluster/freshrss/deployment.yaml @@ -1,4 +1,3 @@ ---- apiVersion: apps/v1 kind: Deployment metadata: diff --git a/apps/talos_cluster/kustomization.yaml b/apps/talos_cluster/kustomization.yaml @@ -15,3 +15,4 @@ resources: - ./connectivity-tester - ./continuwuity - ./freshrss + - ./ntfy diff --git a/apps/talos_cluster/ntfy/kustomization.yaml b/apps/talos_cluster/ntfy/kustomization.yaml @@ -0,0 +1,10 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: ntfy +resources: + - pvc.yaml + #- release.yaml +configMapGenerator: + - name: ntfy-config + files: + - ntfy.yml diff --git a/apps/talos_cluster/ntfy/ntfy.yml b/apps/talos_cluster/ntfy/ntfy.yml @@ -0,0 +1,10 @@ +default-host: "https://notify.mtrnord.blog" +base-url: "https://notify.mtrnord.blog" +listen-http: ":8080" +cache-file: "/etc/ntfy/cache.db" +behind-proxy: true +attachment-cache-dir: "/var/cache/ntfy/attachments" +keepalive-interval: "45s" +auth-file: "/etc/ntfy/user.db" +auth-default-access: "deny-all" +web-root: "disable" diff --git a/apps/talos_cluster/ntfy/pvc.yaml b/apps/talos_cluster/ntfy/pvc.yaml @@ -0,0 +1,13 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: ntfy-data + namespace: ntfy +spec: + resources: + requests: + storage: 200Mi + volumeMode: Filesystem + accessModes: + - ReadWriteMany + storageClassName: longhorn diff --git a/apps/talos_cluster/ntfy/release.yaml b/apps/talos_cluster/ntfy/release.yaml @@ -0,0 +1,111 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: ntfy +spec: + selector: + matchLabels: + app: ntfy + template: + metadata: + labels: + app: ntfy + spec: + securityContext: + runAsUser: 1000 + runAsGroup: 1000 + fsGroup: 1000 + initContainers: + - name: fix-permissions + image: busybox + securityContext: + runAsUser: 0 + runAsGroup: 0 + allowPrivilegeEscalation: true + command: ["sh", "-c", "chown -R 1000:1000 /opt/docker/ntfy/cache /etc/ntfy"] + volumeMounts: + - name: ntfy-cache + mountPath: /opt/docker/ntfy/cache + - name: ntfy-data + mountPath: /etc/ntfy + - name: ntfy-cache-2 + mountPath: /var/cache/ntfy + containers: + - name: ntfy + securityContext: + allowPrivilegeEscalation: false + runAsUser: 1000 + runAsGroup: 1000 + readOnlyRootFilesystem: true + image: binwiederhier/ntfy + args: ["serve", "--config", "/opt/docker/ntfy/config/ntfy.yml"] + env: + - name: TZ + value: "Europe/Berlin" + resources: + limits: + memory: "256Mi" + cpu: "700m" + requests: + memory: "128Mi" + cpu: "500m" + ports: + - containerPort: 8080 + name: http + volumeMounts: + - name: ntfy-config + mountPath: /opt/docker/ntfy/config + - name: ntfy-cache + mountPath: /opt/docker/ntfy/cache + - name: ntfy-data + mountPath: /etc/ntfy + - name: ntfy-cache-2 + mountPath: /var/cache/ntfy + probes: + livenessProbe: + httpGet: + path: /v1/health + port: 8080 + readinessProbe: + httpGet: + path: /v1/health + port: 8080 + volumes: + - name: ntfy-config + configMap: + name: ntfy-config + - name: ntfy-cache + emptyDir: {} + - name: ntfy-cache-2 + emptyDir: {} + - name: ntfy-data + persistentVolumeClaim: + claimName: ntfy-data +--- +apiVersion: v1 +kind: Service +metadata: + name: ntfy-service + namespace: ntfy +spec: + selector: + app: ntfy + ports: + - port: 8080 + targetPort: 8080 +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: ntfy + namespace: ntfy +spec: + parentRefs: + - name: envoy-gateway + namespace: envoy-gateway + hostnames: + - notify.mtrnord.blog + rules: + - backendRefs: + - name: ntfy-service + port: 8080