commit 462ff699e7f084ed7a78a48a2002b7d28721fd2e
parent 7367494c589383cb4f64f8575f113ee8e695e262
Author: MTRNord <MTRNord@users.noreply.github.com>
Date: Mon, 4 Aug 2025 16:11:08 +0200
Migrate ntfy
Diffstat:
11 files changed, 481 insertions(+), 338 deletions(-)
diff --git a/apps/base/envoy-gateway/release.yaml b/apps/base/envoy-gateway/release.yaml
@@ -75,42 +75,42 @@ spec:
protocol: TCP
port: 25
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submissions
protocol: TCP
port: 465
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submission
protocol: TCP
port: 587
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imap
protocol: TCP
port: 143
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imaps
protocol: TCP
port: 993
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
---
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
@@ -159,25 +159,25 @@ spec:
hostname: "docuseal.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: docuseal.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: docuseal.midnightthoughts.space-tls
- name: https-midnightthoughts-neoboard
protocol: HTTPS
hostname: "miro-export.neoboard.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: miro-export.neoboard.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: miro-export.neoboard.midnightthoughts.space-tls
# - name: https-midnightthoughts-certs
# protocol: HTTPS
# hostname: "certs.midnightthoughts.space"
@@ -255,13 +255,13 @@ spec:
hostname: "bugzilla.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: bugzilla.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: bugzilla.midnightthoughts.space-tls
# - name: https-midnightthoughts-root
# protocol: HTTPS
# hostname: "midnightthoughts.space"
@@ -303,13 +303,13 @@ spec:
hostname: "rspamd.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rspamd.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rspamd.midnightthoughts.space-tls
# - name: https-midnightthoughts-grafana
# protocol: HTTPS
# hostname: "grafana.midnightthoughts.space"
@@ -327,13 +327,13 @@ spec:
hostname: "osticket.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: osticket.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: osticket.midnightthoughts.space-tls
# - name: https-midnightthoughts-vault
# protocol: HTTPS
# hostname: "vault.midnightthoughts.space"
@@ -351,13 +351,13 @@ spec:
hostname: "rook.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rook.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rook.midnightthoughts.space-tls
# - name: https-midnightthoughts-jenkins
# protocol: HTTPS
# hostname: "jenkins.midnightthoughts.space"
@@ -423,13 +423,13 @@ spec:
hostname: "plane.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: plane.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: plane.midnightthoughts.space
# - name: https-midnightthoughts-irc
# protocol: HTTPS
# hostname: "irc.midnightthoughts.space"
@@ -531,13 +531,13 @@ spec:
hostname: "mastodon.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: mastodon.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: mastodon.mtrnord.blog-tls
# - name: https-api-connectivity-tester-mtrnord-blog
# protocol: HTTPS
# hostname: "api.connectivity-tester.mtrnord.blog"
@@ -591,55 +591,55 @@ spec:
hostname: "notify.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: notify.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: notify.mtrnord.blog-tls
- name: https-rss-mtrnord-blog
protocol: HTTPS
hostname: "rss.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rss.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rss.mtrnord.blog-tls
- name: http
protocol: HTTP
port: 80
allowedRoutes:
- namespaces:
- from: "All"
- # - name: ldap
- # protocol: TCP
- # port: 389
- # allowedRoutes:
- # kinds:
- # - kind: TCPRoute
- # namespaces:
- # from: All
- # - name: gerrit-ssh
- # protocol: TCP
- # port: 29418
- # allowedRoutes:
- # kinds:
- # - kind: TCPRoute
- # namespaces:
- # from: All
- # - name: ircs
- # protocol: TCP
- # port: 6697
- # allowedRoutes:
- # kinds:
- # - kind: TCPRoute
- # namespaces:
- # from: All
+ namespaces:
+ from: "All"
+ # - name: ldap
+ # protocol: TCP
+ # port: 389
+ # allowedRoutes:
+ # kinds:
+ # - kind: TCPRoute
+ # namespaces:
+ # from: All
+ # - name: gerrit-ssh
+ # protocol: TCP
+ # port: 29418
+ # allowedRoutes:
+ # kinds:
+ # - kind: TCPRoute
+ # namespaces:
+ # from: All
+ # - name: ircs
+ # protocol: TCP
+ # port: 6697
+ # allowedRoutes:
+ # kinds:
+ # - kind: TCPRoute
+ # namespaces:
+ # from: All
---
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: ClientTrafficPolicy
diff --git a/apps/talos_cluster/connectivity-tester/deployment.yaml b/apps/talos_cluster/connectivity-tester/deployment.yaml
@@ -21,11 +21,11 @@ spec:
podAntiAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- labelSelector:
- matchExpressions:
- - key: app
- operator: In
- values:
- - connectivity-tester
+ matchExpressions:
+ - key: app
+ operator: In
+ values:
+ - connectivity-tester
topologyKey: "kubernetes.io/hostname"
imagePullSecrets:
- name: ghcr-pull
@@ -35,48 +35,48 @@ spec:
image: ghcr.io/mtrnord/matrix-connection-tester-ui:v0.2.0
imagePullPolicy: Always
lifecycle:
- preStop:
- exec:
- command:
- - sleep
- - "10"
+ preStop:
+ exec:
+ command:
+ - sleep
+ - "10"
resources:
- limits: {}
- requests:
- memory: "100Mi"
- cpu: "100m"
+ limits: {}
+ requests:
+ memory: "100Mi"
+ cpu: "100m"
ports:
- - containerPort: 3000
- name: web
- protocol: TCP
+ - containerPort: 3000
+ name: web
+ protocol: TCP
volumeMounts:
- - name: configs
- mountPath: "/usr/share/nginx/html/config.json"
- subPath: config.json
- readOnly: true
- - mountPath: /tmp
- name: tmp
+ - name: configs
+ mountPath: "/usr/share/nginx/html/config.json"
+ subPath: config.json
+ readOnly: true
+ - mountPath: /tmp
+ name: tmp
livenessProbe:
- httpGet:
- path: /
- port: web
- scheme: HTTP
+ httpGet:
+ path: /
+ port: web
+ scheme: HTTP
readinessProbe:
- httpGet:
- path: /
- port: web
- scheme: HTTP
+ httpGet:
+ path: /
+ port: web
+ scheme: HTTP
startupProbe:
- httpGet:
- path: /
- port: web
+ httpGet:
+ path: /
+ port: web
volumes:
- name: configs
configMap:
- name: connectivity-tester-config
+ name: connectivity-tester-config
- name: tmp
emptyDir:
- sizeLimit: 2048Mi
+ sizeLimit: 2048Mi
---
apiVersion: apps/v1
kind: Deployment
@@ -101,11 +101,11 @@ spec:
podAntiAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- labelSelector:
- matchExpressions:
- - key: app
- operator: In
- values:
- - connectivity-tester-api
+ matchExpressions:
+ - key: app
+ operator: In
+ values:
+ - connectivity-tester-api
topologyKey: "kubernetes.io/hostname"
imagePullSecrets:
- name: ghcr-pull
@@ -116,41 +116,41 @@ spec:
image: ghcr.io/mtrnord/rust-federation-tester:v0.2.2
imagePullPolicy: IfNotPresent
resources:
- limits: {}
- requests:
- memory: "344Mi"
- cpu: "252m"
+ limits: {}
+ requests:
+ memory: "344Mi"
+ cpu: "252m"
volumeMounts:
- - name: api-config
- mountPath: /app/config.yaml
- subPath: config.yaml
- readOnly: true
+ - name: api-config
+ mountPath: /app/config.yaml
+ subPath: config.yaml
+ readOnly: true
securityContext:
- runAsUser: 1000
- runAsGroup: 1000
- readOnlyRootFilesystem: true
+ runAsUser: 1000
+ runAsGroup: 1000
+ readOnlyRootFilesystem: true
ports:
- - containerPort: 8080
- name: api
- protocol: TCP
+ - containerPort: 8080
+ name: api
+ protocol: TCP
readinessProbe:
- httpGet:
- path: /healthz
- port: api
- scheme: HTTP
+ httpGet:
+ path: /healthz
+ port: api
+ scheme: HTTP
livenessProbe:
- httpGet:
- path: /healthz
- port: api
- scheme: HTTP
+ httpGet:
+ path: /healthz
+ port: api
+ scheme: HTTP
startupProbe:
- httpGet:
- path: /healthz
- port: api
+ httpGet:
+ path: /healthz
+ port: api
volumes:
- name: api-config
secret:
- secretName: connectivity-tester-config
+ secretName: connectivity-tester-config
---
apiVersion: flagger.app/v1beta1
kind: MetricTemplate
@@ -251,18 +251,18 @@ spec:
# max error rate (5xx responses)
# percentage (0-100)
templateRef:
- name: connectivity-tester-error-rate
- namespace: matrix
+ name: connectivity-tester-error-rate
+ namespace: matrix
thresholdRange:
- max: 2
+ max: 2
interval: 1m
- name: latency
templateRef:
- name: connectivity-tester-latency
- namespace: matrix
+ name: connectivity-tester-latency
+ namespace: matrix
# seconds
thresholdRange:
- max: 1
+ max: 1
interval: 30s
sessionAffinity:
cookieName: flagger-cookie
@@ -273,13 +273,13 @@ spec:
url: http://flagger-loadtester.flagger-system/
timeout: 15s
metadata:
- type: bash
- cmd: "curl -s http://connectivity-tester-canary.matrix:3000"
+ type: bash
+ cmd: "curl -s http://connectivity-tester-canary.matrix:3000"
- name: load-test
url: http://flagger-loadtester.flagger-system/
timeout: 10m
metadata:
- cmd: "hey -z 10m -q 10 -c 2 http://connectivity-tester-canary.matrix/?serverName=mtrnord.blog"
+ cmd: "hey -z 10m -q 10 -c 2 http://connectivity-tester-canary.matrix/?serverName=mtrnord.blog"
---
apiVersion: flagger.app/v1beta1
kind: Canary
@@ -332,18 +332,18 @@ spec:
# max error rate (5xx responses)
# percentage (0-100)
templateRef:
- name: connectivity-tester-error-rate
- namespace: matrix
+ name: connectivity-tester-error-rate
+ namespace: matrix
thresholdRange:
- max: 2
+ max: 2
interval: 1m
- name: latency
templateRef:
- name: connectivity-tester-latency
- namespace: matrix
+ name: connectivity-tester-latency
+ namespace: matrix
# seconds
thresholdRange:
- max: 1
+ max: 1
interval: 30s
sessionAffinity:
cookieName: flagger-cookie
@@ -354,10 +354,10 @@ spec:
url: http://flagger-loadtester.flagger-system/
timeout: 15s
metadata:
- type: bash
- cmd: "curl -s http://connectivity-tester-api-canary.matrix:8080/healthz | grep 'ok'"
+ type: bash
+ cmd: "curl -s http://connectivity-tester-api-canary.matrix:8080/healthz | grep 'ok'"
- name: load-test
url: http://flagger-loadtester.flagger-system/
timeout: 10m
metadata:
- cmd: "hey -z 10m -q 10 -c 2 http://connectivity-tester-api-canary.matrix/api/federation/federation-ok?serverName=mtrnord.blog&no_cache=true"
+ cmd: "hey -z 10m -q 10 -c 2 http://connectivity-tester-api-canary.matrix/api/federation/federation-ok?serverName=mtrnord.blog&no_cache=true"
diff --git a/apps/talos_cluster/continuwuity/deployment.yaml b/apps/talos_cluster/continuwuity/deployment.yaml
@@ -1,4 +1,3 @@
----
apiVersion: apps/v1
kind: Deployment
metadata:
diff --git a/apps/talos_cluster/continuwuity/kustomization.yaml b/apps/talos_cluster/continuwuity/kustomization.yaml
@@ -8,5 +8,5 @@ secretGenerator:
- name: continuwuity-config
namespace: continuwuity
files:
- - conduwuit.toml=continuwuity.toml
+ - conduwuit.toml=continuwuity.toml
type: Opaque
diff --git a/apps/talos_cluster/envoy-gateway/gateway_settings.yaml b/apps/talos_cluster/envoy-gateway/gateway_settings.yaml
@@ -48,42 +48,42 @@ spec:
protocol: TCP
port: 25
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submissions
protocol: TCP
port: 465
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submission
protocol: TCP
port: 587
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imap
protocol: TCP
port: 143
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imaps
protocol: TCP
port: 993
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
---
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
@@ -108,225 +108,237 @@ spec:
hostname: "talos.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: talos.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: talos.midnightthoughts.space-tls
- name: https-midnightthoughts-auth
protocol: HTTPS
hostname: "auth.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: auth.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: auth.midnightthoughts.space-tls
- name: https-midnightthoughts-grafana
protocol: HTTPS
hostname: "grafana.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: grafana.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: grafana.midnightthoughts.space-tls
- name: https-draupnir-midnightthoughts
protocol: HTTPS
hostname: "draupnir.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: draupnir.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: draupnir.midnightthoughts.space-tls
- name: https-matrix-draupnir-midnightthoughts
protocol: HTTPS
hostname: "matrix.draupnir.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: matrix.draupnir.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: matrix.draupnir.midnightthoughts.space-tls
- name: https-midnightthoughts-vault
protocol: HTTPS
hostname: "vault.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: vault.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: vault.midnightthoughts.space-tls
- name: https-midnightthoughts-budget
protocol: HTTPS
hostname: "budget.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: budget.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: budget.midnightthoughts.space-tls
- name: https-midnightthoughts-ldap
protocol: HTTPS
hostname: "ldap.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: ldap.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: ldap.midnightthoughts.space-tls
- name: ldap
protocol: TCP
port: 389
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: https-mtrnord-blog-gts
protocol: HTTPS
hostname: "gts.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: gts.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: gts.mtrnord.blog-tls
- name: https-midnightthoughts-collabora
protocol: HTTPS
hostname: "collabora.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: collabora.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: collabora.midnightthoughts.space
- name: https-midnightthoughts-webhook-kubernetes
protocol: HTTPS
hostname: "webhook.kubernetes.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: webhook.kubernetes.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: webhook.kubernetes.midnightthoughts.space-tls
- name: https-api-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "api.connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: api.connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: api.connectivity-tester.mtrnord.blog-tls
- name: https-stage-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "stage.connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: stage.connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: stage.connectivity-tester.mtrnord.blog-tls
- name: https-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: connectivity-tester.mtrnord.blog-tls
- name: https-federationtester-mtrnord-blog
protocol: HTTPS
hostname: "federationtester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: federationtester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: federationtester.mtrnord.blog-tls
- name: https-mtrnord-blog-root
protocol: HTTPS
hostname: "mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: mtrnord.blog-tls
- name: https-mtrnord-blog-matrix
protocol: HTTPS
hostname: "matrix.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: matrix.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: matrix.mtrnord.blog-tls
- name: https-rss-mtrnord-blog
protocol: HTTPS
hostname: "rss.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rss.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rss.mtrnord.blog-tls
+ - name: https-notify-mtrnord-blog
+ protocol: HTTPS
+ hostname: "notify.mtrnord.blog"
+ port: 443
+ allowedRoutes:
+ namespaces:
+ from: "All"
+ tls:
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: notify.mtrnord.blog-tls
# - name: https-docuseal-midnightthoughts
# protocol: HTTPS
# hostname: "docuseal.midnightthoughts.space"
@@ -411,18 +423,6 @@ spec:
# certificateRefs:
# - kind: Secret
# name: plane.midnightthoughts.space
- # - name: https-notify-mtrnord-blog
- # protocol: HTTPS
- # hostname: "notify.mtrnord.blog"
- # port: 443
- # allowedRoutes:
- # namespaces:
- # from: "All"
- # tls:
- # mode: Terminate
- # certificateRefs:
- # - kind: Secret
- # name: notify.mtrnord.blog-tls
# - name: http
# protocol: HTTP
# port: 80
diff --git a/apps/talos_cluster/freshrss/deployment.yaml b/apps/talos_cluster/freshrss/deployment.yaml
@@ -1,4 +1,3 @@
----
apiVersion: apps/v1
kind: Deployment
metadata:
diff --git a/apps/talos_cluster/kustomization.yaml b/apps/talos_cluster/kustomization.yaml
@@ -15,3 +15,4 @@ resources:
- ./connectivity-tester
- ./continuwuity
- ./freshrss
+ - ./ntfy
diff --git a/apps/talos_cluster/ntfy/kustomization.yaml b/apps/talos_cluster/ntfy/kustomization.yaml
@@ -0,0 +1,10 @@
+apiVersion: kustomize.config.k8s.io/v1beta1
+kind: Kustomization
+namespace: ntfy
+resources:
+ - pvc.yaml
+ #- release.yaml
+configMapGenerator:
+ - name: ntfy-config
+ files:
+ - ntfy.yml
diff --git a/apps/talos_cluster/ntfy/ntfy.yml b/apps/talos_cluster/ntfy/ntfy.yml
@@ -0,0 +1,10 @@
+default-host: "https://notify.mtrnord.blog"
+base-url: "https://notify.mtrnord.blog"
+listen-http: ":8080"
+cache-file: "/etc/ntfy/cache.db"
+behind-proxy: true
+attachment-cache-dir: "/var/cache/ntfy/attachments"
+keepalive-interval: "45s"
+auth-file: "/etc/ntfy/user.db"
+auth-default-access: "deny-all"
+web-root: "disable"
diff --git a/apps/talos_cluster/ntfy/pvc.yaml b/apps/talos_cluster/ntfy/pvc.yaml
@@ -0,0 +1,13 @@
+apiVersion: v1
+kind: PersistentVolumeClaim
+metadata:
+ name: ntfy-data
+ namespace: ntfy
+spec:
+ resources:
+ requests:
+ storage: 200Mi
+ volumeMode: Filesystem
+ accessModes:
+ - ReadWriteMany
+ storageClassName: longhorn
diff --git a/apps/talos_cluster/ntfy/release.yaml b/apps/talos_cluster/ntfy/release.yaml
@@ -0,0 +1,111 @@
+apiVersion: apps/v1
+kind: Deployment
+metadata:
+ name: ntfy
+spec:
+ selector:
+ matchLabels:
+ app: ntfy
+ template:
+ metadata:
+ labels:
+ app: ntfy
+ spec:
+ securityContext:
+ runAsUser: 1000
+ runAsGroup: 1000
+ fsGroup: 1000
+ initContainers:
+ - name: fix-permissions
+ image: busybox
+ securityContext:
+ runAsUser: 0
+ runAsGroup: 0
+ allowPrivilegeEscalation: true
+ command: ["sh", "-c", "chown -R 1000:1000 /opt/docker/ntfy/cache /etc/ntfy"]
+ volumeMounts:
+ - name: ntfy-cache
+ mountPath: /opt/docker/ntfy/cache
+ - name: ntfy-data
+ mountPath: /etc/ntfy
+ - name: ntfy-cache-2
+ mountPath: /var/cache/ntfy
+ containers:
+ - name: ntfy
+ securityContext:
+ allowPrivilegeEscalation: false
+ runAsUser: 1000
+ runAsGroup: 1000
+ readOnlyRootFilesystem: true
+ image: binwiederhier/ntfy
+ args: ["serve", "--config", "/opt/docker/ntfy/config/ntfy.yml"]
+ env:
+ - name: TZ
+ value: "Europe/Berlin"
+ resources:
+ limits:
+ memory: "256Mi"
+ cpu: "700m"
+ requests:
+ memory: "128Mi"
+ cpu: "500m"
+ ports:
+ - containerPort: 8080
+ name: http
+ volumeMounts:
+ - name: ntfy-config
+ mountPath: /opt/docker/ntfy/config
+ - name: ntfy-cache
+ mountPath: /opt/docker/ntfy/cache
+ - name: ntfy-data
+ mountPath: /etc/ntfy
+ - name: ntfy-cache-2
+ mountPath: /var/cache/ntfy
+ probes:
+ livenessProbe:
+ httpGet:
+ path: /v1/health
+ port: 8080
+ readinessProbe:
+ httpGet:
+ path: /v1/health
+ port: 8080
+ volumes:
+ - name: ntfy-config
+ configMap:
+ name: ntfy-config
+ - name: ntfy-cache
+ emptyDir: {}
+ - name: ntfy-cache-2
+ emptyDir: {}
+ - name: ntfy-data
+ persistentVolumeClaim:
+ claimName: ntfy-data
+---
+apiVersion: v1
+kind: Service
+metadata:
+ name: ntfy-service
+ namespace: ntfy
+spec:
+ selector:
+ app: ntfy
+ ports:
+ - port: 8080
+ targetPort: 8080
+---
+apiVersion: gateway.networking.k8s.io/v1
+kind: HTTPRoute
+metadata:
+ name: ntfy
+ namespace: ntfy
+spec:
+ parentRefs:
+ - name: envoy-gateway
+ namespace: envoy-gateway
+ hostnames:
+ - notify.mtrnord.blog
+ rules:
+ - backendRefs:
+ - name: ntfy-service
+ port: 8080