commit a2a41be0db3e468ae1b2f009856d8f60f01d42f1
parent ff9f89430b2a50886d14742cf67431d96ea56c9d
Author: MTRNord <MTRNord@users.noreply.github.com>
Date: Mon, 6 Oct 2025 11:14:24 +0200
Add cgit
Diffstat:
8 files changed, 428 insertions(+), 200 deletions(-)
diff --git a/apps/talos_cluster/cgit/deployment.yaml b/apps/talos_cluster/cgit/deployment.yaml
@@ -0,0 +1,109 @@
+apiVersion: v1
+kind: PersistentVolumeClaim
+metadata:
+ name: cgit
+ namespace: git
+spec:
+ accessModes:
+ - ReadWriteMany
+ resources:
+ requests:
+ storage: 2Gi
+---
+apiVersion: apps/v1
+kind: Deployment
+metadata:
+ name: cgit
+ namespace: git
+ labels:
+ app.kubernetes.io/name: cgit
+spec:
+ strategy:
+ rollingUpdate:
+ maxSurge: 25%
+ maxUnavailable: 25%
+ type: RollingUpdate
+ selector:
+ matchLabels:
+ app: cgit
+ template:
+ metadata:
+ labels:
+ app: cgit
+ app.kubernetes.io/name: cgit
+ spec:
+ imagePullSecrets:
+ - name: ghcr-pull
+ containers:
+ - name: cgit
+ image: ghcr.io/mtrnord/cgit-docker:main
+ imagePullPolicy: Always
+ resources:
+ limits: {}
+ requests:
+ memory: "344Mi"
+ cpu: "252m"
+ ports:
+ - containerPort: 8080
+ name: http
+ protocol: TCP
+ - containerPort: 2222
+ name: ssh
+ protocol: TCP
+ volumeMounts:
+ - mountPath: /var/lib/gitolite3
+ name: storage
+ - mountPath: /tmp
+ name: tmp
+ - mountPath: /var/lib/git/.ssh/admin.pub
+ name: ssh-keys
+ subPath: admin.pub
+ readOnly: true
+ - mountPath: /etc/ssh/ssh_host_rsa_key
+ name: ssh-keys
+ subPath: ssh_host_rsa_key
+ readOnly: true
+ - mountPath: /etc/ssh/ssh_host_rsa_key.pub
+ name: ssh-keys
+ subPath: ssh_host_rsa_key.pub
+ readOnly: true
+ - mountPath: /etc/ssh/ssh_host_ecdsa_key
+ name: ssh-keys
+ subPath: ssh_host_ecdsa_key
+ readOnly: true
+ - mountPath: /etc/ssh/ssh_host_ecdsa_key.pub
+ name: ssh-keys
+ subPath: ssh_host_ecdsa_key.pub
+ readOnly: true
+ - mountPath: /etc/ssh/ssh_host_ed25519_key
+ name: ssh-keys
+ subPath: ssh_host_ed25519_key
+ readOnly: true
+ - mountPath: /etc/ssh/ssh_host_ed25519_key.pub
+ name: ssh-keys
+ subPath: ssh_host_ed25519_key.pub
+ readOnly: true
+ livenessProbe:
+ httpGet:
+ path: /healthz
+ port: http
+ scheme: HTTP
+ initialDelaySeconds: 15
+ periodSeconds: 10
+ startupProbe:
+ httpGet:
+ path: /healthz
+ port: http
+ initialDelaySeconds: 15
+ failureThreshold: 30
+ periodSeconds: 10
+ volumes:
+ - name: storage
+ persistentVolumeClaim:
+ claimName: cgit
+ - name: tmp
+ emptyDir:
+ sizeLimit: 2048Mi
+ - name: ssh-keys
+ secret:
+ secretName: cgit-ssh-keys
diff --git a/apps/talos_cluster/cgit/kustomization.yaml b/apps/talos_cluster/cgit/kustomization.yaml
@@ -0,0 +1,7 @@
+apiVersion: kustomize.config.k8s.io/v1beta1
+kind: Kustomization
+namespace: git
+resources:
+ - ssh-keys.yaml
+ - deployment.yaml
+ - service.yaml
diff --git a/apps/talos_cluster/cgit/service.yaml b/apps/talos_cluster/cgit/service.yaml
@@ -0,0 +1,52 @@
+apiVersion: v1
+kind: Service
+metadata:
+ name: cgit
+ namespace: git
+ labels:
+ app: cgit
+spec:
+ selector:
+ app: cgit
+ ports:
+ - port: 8080
+ targetPort: http
+ protocol: TCP
+ name: http
+ - port: 2222
+ targetPort: ssh
+ protocol: TCP
+ name: ssh
+---
+apiVersion: gateway.networking.k8s.io/v1
+kind: HTTPRoute
+metadata:
+ name: cgit
+ namespace: git
+spec:
+ parentRefs:
+ - name: envoy-gateway
+ namespace: envoy-gateway
+ hostnames:
+ - git.midnightthoughts.space
+ rules:
+ - backendRefs:
+ - name: cgit
+ port: 8080
+---
+apiVersion: gateway.networking.k8s.io/v1
+kind: TCPRoute
+metadata:
+ name: cgit-ssh
+ namespace: git
+ annotations:
+ external-dns.alpha.kubernetes.io/hostname: git.midnightthoughts.space
+spec:
+ parentRefs:
+ - name: envoy-gateway
+ namespace: envoy-gateway
+ sectionName: ssh
+ rules:
+ - backendRefs:
+ - name: cgit
+ port: 2222
diff --git a/apps/talos_cluster/cgit/ssh-keys.yaml b/apps/talos_cluster/cgit/ssh-keys.yaml
@@ -0,0 +1,34 @@
+apiVersion: v1
+kind: Secret
+metadata:
+ name: cgit-ssh-keys
+ namespace: git
+type: Opaque
+stringData:
+ admin.pub: ENC[AES256_GCM,data:LwbtOfDiYc5osN93bWsCnfy+ZFH9G1aR8yBxfUcR2LX03J6WJs7+gcocdzikenpZbMFNlN0Kpv8wN6dmumYIRxNeNQWc1OEDexzFTg2frxaoeb224YK0CiQtE4+WbTmWHWA/pF7zOM9H,iv:oA5jtLrzoAsEaLxlv6thdeZaBKPICWE2DWyqn0BdGx4=,tag:wMOKjJtqM5azOsPkoqfR9w==,type:str]
+ ssh_host_rsa_key: ENC[AES256_GCM,data:BecbLpA8XJMrsHm8vPoWd4n9JxetQ054xfDk5NRSPKRob9tkiqFObn243m5WfX3KJeg3Z1PNPo91hXJp6A7Vvpn9RJVTUJAEC5WaRkBYtPJ3zh63gmHy6t9s0ubAdEsOPH+EgXa9h8yONp2PTFgQmsM2WwD2y2sPtak+pPNFOaAg/JcKtEVHr0Op4JjM0N1PsgzDvs0HJB0b9WrlKFKYCyz4gF9brSZaKi1VPiQLTjBsvuwLFBTjsJv9RhLBubDfIHeL5tcpSxXYOqPSeITkw306ZTYztSxuBV2WsH1HdhCym6KjpnVv6+RE6QbqVxytIWeX7dA/FXb5o8HtcmWdaWtwIbxMQI+eg/flg5HZl1QrJY/TF76Sq1idATi4HEzDi3W/4HRjcIOLYhsouELL9M1oSuLEJnyHsxCuMbzh6/D5N6gDERFjgcxtl4tmHJrmQC5Bq4F130HQvtrgF5u+xfm4aVunKLko+fF3GsRR3jHP3AnqKNOTBMqW8tio//ssKnWgzdPm9JyyYiHOOov29bUHsNHX6KoX/Q8SPuYobYeoKuupazKQhtCBCERtyAkBzIIL79Q3OO5d7CcxEVpZvUGlDpoMnZZrARiyb0MNLatIfr55ltN3W8T+g1d5j8tud1VUDaHi/J/7SiT/2uRENeUQ8rs4q6vrV6crMuHKhFpRC7cweMOYFfYZOnTknFC+Lt8TGox+56wguYxdpzbucEy0pz06GCXjyUzqtbLGrP6abupeu7cx3wUvBnIjzKfcRqIXv4nBx1pYKu/MDbk/Bcc/gcfZIs0pBOIe66zMm/Wlf6OTgfAmGCioHos1D6JXTYgcDY5YKwDzVNromgS61voDgg1A2I2c6eE/DmXUSvHZya/uEjRFKQu8cfAW0JfoL4MExP67sS6pRqpNPdeKufgrqmzzC2A3R0/cP3sJXH0ycymTrxiQtbHr0WmgwFmRXOuNnTuhOrvJluU0l8k5P2Scw7XPHGQhp2PDt6K8rMO99M/nB2k+OUmiSVaz1p2oRKCpm1yskHfCG0YaZldNU6j+BxadD0R+Xc7XNcVxpyWYWv095vXdpZwY+GLCxll3lWCEyRkQgyFKQN2NL3F9KefmaBCOCwM02iwZuVc0a/I7qxkaB1cwqE+uiJH/kJ0V1HMwbDyPa8zmxi9MAO8q42Ta3ffK/qwrjtTQUFWi6x8gs0D2jt8goC/CTcunSp23FteRmEgsRNFG/2hVCmVIITDekAee/PaqdI+ntMy7xvroRbNN8cDzAjvbJn6xFt7Yn/tq0G/Z0roOdrsF1j+JO6mPRNi9gMmyn8MxQz1uF6kxdfjFvHOqGX7ZN17iZJmjf0Do4iGTbVRPtFL6R4pdBtpIZKr0u/8ePQWjfmeRagsW4UctrgJz0Tp7uOxObOMQ68xvPEXJfD4JutTlvRIuDVYtP3waVqbS0TbYgBlZPZ0kDKAxhKksPofY2BQo+ggGCudTWSu9/uFLCGM5yE0BV2DtYSGg7BAib41LVHlljVm6Pn67I8Mmww5oSw6KtwCUjToD/y3E9AC07UXxVNc1HfVnYgiTtZ2x5DvDli5nieAdPWnT/pn4wXhT3e+bSnUAXtbaZL54DsvV4dpQeQj8ro8+QV8/eG9nAcOWf7eOvxG5y9fJQLEJoWH5wf+UUtWdzyKfS1epM2w+jLblQJR1eUzR8O/5IdEm9IqgIF50IUCOjg/iBSH8Dres7jQz6NFJSOxyhaqj+zW7amn3/GU3cbA7qr6dAIdfEzwGvYXdOzmpZlTTrmr/NPPkUJeKvF2or+oQOxDakU+tqofHjJVfNzPpdjAOUKAQwR8NJbq5T91hUDmt7bqL/dK5928Nky4sFqmpAclBwO0sepGXSb1vEVadoiCscfddPIB5e1geRoHvKq5kZpJ0britbP0s+o22bmypkmnhCdEmCkkvQEEHp4OZsf0Y9jUou+y2bG0XW3kd/Nlt0T2KFZJf7l3OBp/mF6U3Tap6kwtOI6AvzMI/yaUT9PL0KFsjuUvVcWW5o1F4n9zl0YT4fvJOSPe/IxxX8CRQMw89Bw6+ro08f56EjVvTVXurAL28fCApqsTKpRis8BmiMgcOrshexG09XTGNLA16sQIiNs5GbPPkyawbbaXmAXfjSw5kUSaDuGay285H8j53JIP+bE37jGIyXy4+h/doD3upeMXmPCrrYCBZDxQWFzqEi8L3itvctW/YBSwQj7eBha//3yH1dF2FxvZvVSYRdj3mE5NLFk8J2wpqy2xhczkRzTJnXeraNc68xi8c2ffozCTZyVlMBJWSEZPnVJ8ZqiMoJhfz7CNEm7ifvkoZTUFqBc1PAD/4WPyC/iXli/ppkv8W9xJs13QYmu4LULAo78q19Nj4oi71okZWb632AK69SioXbgMzILv3EQV60KM+6I32Ld3c8tt9fw9txjUg40g/5EFn+Kv82cBaG+jQFmH18ZkwvF0rBoRKpbP5QgGhbLwCGOYX3gv6GpyR1srQxrU9q2mDDJSghVWCdR1VbIa+i5DGPpxkvpGAiKNtMi5jgvQSuuMhjc5xU4DR+QnyyYkXenSRmXmD7Is736PDNRbbij1CcPZxmOvUTPYclO1a3+Y0sMQc4Nt03vUTpKfTt43IwDxnYfjYJ+w8KIPpGE7hJ4HsLJ/o9LHsxPk0dtUt5sojPHirv5vZCm0ktRnUztHwOHSaGTA7wdA2hGVfSIOan2mJc8jJFxLC+olhx+iaIeb87KKpzF1f4hjLYOaillxSyRezQkp4V0ZEcdhkI6v3LBnBconauxh6PuJuy5ACi7tNHrpt8FLuvpqi0ZB6lzaVrfjc1ks1Dq0OO3KbxFD4qWMa0EcutkzvPsWApoNhX+tWyxBpGR2wvODegjcjp303pt3roGnbCLsj7rHfVgOf/UxrFPrfOOGzzogpCrNieuKTvB5AQ0vXNWKhCHjf4QPH1aNEdH1DPWYVn0Ae5YhHrHtjCxtmrqoZ1FAhYK8w6WyahjSbXlhwxm8HHsewRJqFF3uCiniF2nBbzvqUQXgWGz8DP+muOn6umENHmEweIl8/HB9J0ZGxNDDpFgKvbQGN7f4EEMLDm/zPYH+J4u+yBFHahioAG4qWqo5b8E5bvT7S2gQ6qBM1VAi7DgprRRz9q5d+vcAtL5ij7CJUvZ7cjbeSg0/MVRm/sDI0/YRe0sgLqW3vWecCqET+datM7nZJNE+Epfk4rktq5PdjNGgZS14jG8i5ETdNp3skcyIR9X3WjnJ44yb8VT/+bwD2fUDMoVwKK9S0nZ5o0of+Gg4CZArSZZc138lr+Iljh9L2YMCFQMpIx+DUTIWmq5BAer7Su62pC+0XzaNsG/ylwYzN+Jz5w0+hpTx6XpfBgvvXD+Iq6npy/gYBIFOFQZGvXgKnWEURfcu/LooKcFBs/x2qTuo8mcKC9/BeG5SxNgxUpcMVzh9Y4h0+s2145RP1Ty93HZFKeXoB7UMvutmY4+TXTvqCDcR3HoEfgJcOdjTVk8qxX+Fjok02Asewpsr6eQbz+IKGENRCzh2d5eC7qmdMnjRAflWu4swNiCeWD5ooExzZWaYNp9H7IcSXSKw+QsghYSIXoBFE1repXtlHVrwiqLR/OszbLfguoYSPj5sYPNzbv8uTtcGYmDv6nxT7Jvz9JqZeH+SJMpKiLrIB2ma/tE/StVlYBLgMfRxfCqnEVk7SM4ljjr9KRoRhUCBHj/8bYI1Mrb37ymnZfWZX2UIopa4Geb10iODOVdd/eqEbci64gaFi8LG+y3NagsYcxkYLsKtqWZHI2P5wEeE7juGhz92HXwd9ihb+HwENUUCyvl66ok8PtYfNA4HWzJyPYksazdFRwVemgASOHfd5qPQfBfFVQ+mgjUmU8E2gGCyVOeqoqPjrgpQNpqgYH/riROY/4HOytRtgW4otdxEzkuvZXZ4FZMn+gRyvguet0/h3tR3kbrL/+YrXugb3WbCul89XFjH65gXezMH3jyNTDXPw5NleOTlbbaL4aX2YoJFoaYNJShA2fqGBDyBXPEy55+V0CPnJfurbgj95kEWFK0V9pSxeqW6NgcYupULwgR0WgRaKYvLkTyPwdFHrzaYTv6GjFHDuu2UXXkzCp4Nz8w1AfINa1dPQUtWN1zP5vkA2oRE/Js9UTR4jlKXHFMH9Vow7o2pEkW+ECv1rwcCmyB8OvKofTxxWIIGuHYuRwr2CKKBM3FbPTDryeirp+/rLWIqgizmgQwKZvrrded4HEhKztJIh92tCf3g5zd1+CFLjz7wQLLc2e9zxTNLvl1YhLlTWxEeKLvY7yFkEHQELBv1e4aMmSUEoBIyLaamx/v8ixmv52ivcxhAu68c5AhQsUOoxqcQKQFPR1VLYMk1Bs9HIb40+QdfXPwO+K9frHsZPAfD717HRm/mfvWye6uw8HMQ5ioGBJrUFYS88KptbKWXYAlJDngAU2ZdIPwEzbeP29rUdyJAOOCx2FCXlW3zTAazOtjPeU1r11Cjka7u7VRnsPD5ftChQhVQ=,iv:i0mqMP+t3oqehBwUwkg7pAI0KnMknZfQfRjS2GWepy8=,tag:FCd2YUy/m5I12qMozQ7PHA==,type:str]
+ ssh_host_rsa_key.pub: ENC[AES256_GCM,data:9pXOGC2YEjqYLBA28MWqjV46meK1S7hqpxj+5ixsbe2F7+nQAUIE8KdzI7oT+1+Ni/rq1rypHdGj2EoFDz2uP6HA1c42x6uwlbuxF4RN7t2neBlIQaZTAexwlMkyDi3lO8WZSTiCJyn9P5iDFlclSD4XLSUXwOueHkGydDB79NWf0HQThl4i3qMCt4QSBwggWY0jtkO814515Uame1sdF6DIB70vuyUCOkMz7mW64Y/tanSVGSOtRoWSRdMyHJwT1NDXxTIHsko45lZZ0JwmLsEmX88NO6LgzQxlIJNhwV97uUfzRE64BlkrCv8rhq+yaBfsNognpfY+aOYuxNm1bCFQ5VBZDVHZnng8kqrSMBMMUgTXajz2cv/SUpOp8JV7fE9rUooqpTU+VuzFXmrdSVXKm+4dN2J0kmrGaK3jFsnlqJjD2wuo2NN5bWGGZ8PjapIzOGXDaIsPm4riDY43L+igSKjgu2juA8u9FFmlqRVL8DflEfwRXJiI/t2kf5P9XIXJwijCM3To2CteOyecz4gudp/N5JE9SKUjR0xFb6Gy3CgChv6/4HmmygTOjWWBbH8Al75sEMJZomE5k6hi04AXdd+cO22XM/j0a0z3sjZinYi4vAuj8eS1Ro1h/r/NdLPyXg98F+Y5X5xOczI8z091uQjPGo80PjwZ1CTf7A0gXbAHUDxOD8v1nThA5OUkwjLNAXR2B5SwOcNy/TEkRTYkUmcaizjx/3tSeQUeNnlx9PVNlkQVINOrE11+hl/16A9mAf8K1M14NsTmKyQsBnf56bL3byoKToHjSU/AoZqwXoU6zUSM8fYOH5l/FyUirYf6ggA/wZuTlcJHfwEQK+NGV4lIKz7NM1FoVMrLKyOjlnwFqnKG0dxU80X8FKCrqM4XI5SQygrU/3rC43PdGaQG2g551jUEyEez6c2kLAQ1RjEB8Tf8qZIsK177uyPb92MwVM/ZsL1XVtdH8mKPwHvT/f99KlgxkM8AGA==,iv:8Xhwysqe4zw0j4BwX4T+hE80H9IOcmuC90vFCVYaeA8=,tag:dKhxAXtG0j4sRWy/OHUEZg==,type:str]
+ ssh_host_ecdsa_key: ENC[AES256_GCM,data:cIhIw/D/jbG9VjlP9kHLFiqhS+kkI1d+qSEWNzoKyq3ybD/cK6pKJV7MrLRostSZ0y4/tdrCfpYj833daXxqhhPZMIt3BuJEk/jujc37JtN30dFRrMIMYPNFewYKP3krXFDnQ1Z7McvUdQfXczIRkI1E34ruU1/ADGyRrYk0V/X1jlUezUwsYfY6daf5/oCaaKTwyHGQt88aSFYUAGzgPs9hmR0S8OwA8QaH2CiAWOx0vk9XHrcrM3TZjq92Yg6/obUndvIqzxvpDZPgVUVdFYw701PDJQkwe4ohPxD9YIIjR95c0RnDb4lmW5+bkH5l1VpMTeVM+bnTYSF+DmngI+6REKUjWLqJkWIrG72GkTMy3pZfIyGBLtehFGa/Qz/LVNjIccglpeMioFdptLxRAcU/oU2Yy8M0hKcQ5Fgtj6tBxSvPVbnzXr/kLZc4LcaNONEZIxGY4MTEApiv7ausuk6w4TrR0P/htTHKCOzSR0Sf7LcCXUV771y8Xv1PWD4GvjPpXOavMVMZZLE6qgVKL1++CFMntnYDhacDErx2CLwdSOkZmNieNgWrS5f7R8o9kwPTH0oZe2TIinhP9xdb8MKjcjupHeoWytXVFFlAJ5odNzqHgYwfxp1cYISUVM/IBKM5wrskTDFDuWwibOV7bMGpoIctF6VVtHZ/4GeTHppCGWk7m7CNcSnWEjHVKgCxZbc3rd2PFanlXaKBiG80bvDN7GD5VpEI5Ni3hX8e73u9PYNQGcmPY522nt7UeU1HY9MwVCAbuYF4JcIIRwVZq1xWKVEBrt55S/zVhcPWgkP/NMchSWKzsJtFp7QuUqPCw3DpjD2oah6623kUWZ5J9pkdug+MpLBQnX9PFcJCm/13FdCJ8GGcLU0juWx5fQVhv90jDSu/e8lzetDNy3zg11GwIvoiQHWRY8iwrfaVd1DF6MtmX1df/BrfDpQe/1bcFoskcY5sMpPkg69x3QBi2QBUAt9R/GGPASLSQg==,iv:z11k/g2I03wgp7k+bxo13+s7rPNyPm0pogImM4WHce4=,tag:A7nc6DyVeerBjz9VXJWrFQ==,type:str]
+ ssh_host_ecdsa_key.pub: ENC[AES256_GCM,data:QEWskO5K6QTizTN+EDHoUIj2R0Z+nhOY4vsvEdlyKWWAZ1CRbULynkQLQEvE90mYFM+tB+ccz2yyUPq12eyNmPzhT1mFwPR+IVcQQQ800QOu9Kh7bfhl/8raKtXWwU5GZQySpXfQR7QaBXSBx4oa9FUCNhU1Cq4Jyya7uYjFKzWRauwvI+GyOenOacSB4XHAbRePYFRtB8FvHLoQJ8MWqShRUh1BrjtqfT3RZTDUUZjpn+OqsaQGEG0oT3N2ZqAgqHJ30r6NroN3wKRtigyWDh91w+95NCqX7oDo7i9WGZg8M8Bz6dQz7fhK7CLy1Dvjw1E/hxcqrxn7WcvsLG0F5qCrq2U6EylexSatQpnGsp2NpH4quNs=,iv:WyaSaE1cPIfxFVFXPK6QT88TPzibnICkRdHq9ra7z0Q=,tag:La697YwiNcIAEr/58/VZsA==,type:str]
+ ssh_host_ed25519_key: ENC[AES256_GCM,data:dfByN5f6MHJnUtZiobRobEZwGMWu44PJdtkQqcbXsF5eAbllUn17dK8CDvKsmJL6eeYg60BhI9Ai9gQV097PXRRnfcgCFlGamlMYziEhRfVPpeAzjmodI/bRnP8oQ35hCW+Y+mNtwVhq1w+EIpyeKytOH2XhVCP5xARuRACkExjUBKaUdSh2jzu+27lGlwLifOLkxdQI3Ar5GjESbhA9ZQWQ+Xz8bHw7XMfjwTG4GMqvMpX3hcGEt/pvbJ+MzFlrY+tP/xDdLboeySkUecHHle3I5t9QrRnpmQW90wm/c2Pki8kZ4FXBpTA/IQwgYcLyjF1j3am43xgOTdm1PeCwaPzI46NATh68JhPMrSbHPSWxOENwWESqCtVntpqWt0xoFN+dCVSOwO0EpvHocDKSdjEl5oP2NAx/KeYHZ3Q4VcgHGMOSiuWdajGIWg0SoFd3TdW52DE/xpV+q/QhcE6RcM/UZS5doXs00DJAs/vMupa8RbD5DUeJ9LTcVA0vLcn3IW+quHAh1ayuq2GThBjtIpZYzXpB7/essxyCRhCOPAHNH0g=,iv:CgPueImkFnjd5GjBPVFVBGFjf/2+sb1Oe+kSu3ylAWQ=,tag:bieQgVSvbbUaOe7nEA+KnQ==,type:str]
+ ssh_host_ed25519_key.pub: ENC[AES256_GCM,data:9npZIGIyNWuXyY2ffds95/mBH4aY8wnaz+9BXkLwnZdoCihzmQGch6c+GECQuVW/HITP6oGKUwsiqf7ZkNcQs4gARUUOiPZuiUxvrT63DD8ibVbI+Foqhz38pnwWjUv8zSOUXf6GeHaVVA3s,iv:hj1FJq/uSf8EskGfhxJ9ZDloaDZ7FRYEc4VyF5QT6u8=,tag:U0f96nEtk3jAFNulOmA76A==,type:str]
+sops:
+ kms: []
+ gcp_kms: []
+ azure_kv: []
+ hc_vault: []
+ age:
+ - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
+ enc: |
+ -----BEGIN AGE ENCRYPTED FILE-----
+ YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA3NStQT0J3ZDI0R3B2YXpw
+ cXNaVFJqRENDQithOHNvWkd0MmNScDhwU0JZCmJRZ1hFWlY4TThYTWloS0IvWjhW
+ aitISVlxWE5nU2krdktNaWtlZFcvTzQKLS0tIEZySDdjbVVQOEN4amFORW1xanJk
+ eFBUTktaMXNaWUozTzV4eks0L0lRU2MKg97kIN5YohhSdHVtlK1i/igia4xmZBHl
+ imBTxuQQhIx2y0Wz+rpZLSUVST20BQcjvmsTX7T2utY5CjN6wSTzVQ==
+ -----END AGE ENCRYPTED FILE-----
+ lastmodified: "2025-10-06T09:14:06Z"
+ mac: ENC[AES256_GCM,data:uM3HYa7IKhYBTTHaIDNDyvcdClz7743zxYYcv0QkPDBRdKtMcqBxmHEtKWp7i945KmFO+a3B9wHf23iMFEMYacj79PAgmxJxx90K68agelENwUVXIG7/MNcL42nTiA/ZFBxLDbQHvSBAAU3ZaUybXiCNbSWlodY0pdO3ESjO94E=,iv:ok4f6PnHwxyNjdcje/hW2a4C9hzfyz2Qp1ulzjPPM0I=,tag:vvN/DV3dIouTxV7I0hkjpQ==,type:str]
+ pgp: []
+ encrypted_regex: ^(harborAdminPassword|kimaiAppSecret|kimaiAdminPassword|GITHUB_CLIENT_ID|GITHUB_CLIENT_SECRET|GITHUB_PRIVATE_KEY|woosh|root_password|rspamd_password|pgdb_password|matrix_access_token|pgdb_remote_url|hmac_secret_key|adminPassword|adminEmail|jenkinsAdminEmail|securityRealm|gerrit.config|routing_key|DATABASE_URL|SMTP_PASSWORD|SECRET_KEY_BASE|admin_password|extraCommands|key|clickhouseDatabaseURL|databaseURL|client_id|client_secret|secret_key_base|otp_secret|private_key|public_key|primaryKey|deterministicKey|keyDerivationSalt|token|clientId|secretKey|installationId|installationKey|uriOverride|adminToken.value|password.value|sql_password|erlangCookie|AUTHENTICATION_PASSWORD|ROOM_API_SECRET_KEY|adminPassword|configPassword|adminUser|configUser|MAIL_PASSWORD|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret|admin_token|integrationKey|rootPassword)$
+ version: 3.9.1
diff --git a/apps/talos_cluster/envoy-gateway/gateway_settings.yaml b/apps/talos_cluster/envoy-gateway/gateway_settings.yaml
@@ -48,42 +48,42 @@ spec:
protocol: TCP
port: 25
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submissions
protocol: TCP
port: 465
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submission
protocol: TCP
port: 587
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imap
protocol: TCP
port: 143
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imaps
protocol: TCP
port: 993
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
---
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
@@ -103,356 +103,376 @@ spec:
load-balancer.hetzner.cloud/uses-proxyprotocol: "true"
# no wildcards due to Envoy bug: https://github.com/envoyproxy/gateway/issues/2675#issuecomment-1960449002
listeners:
+ - name: ssh
+ protocol: TCP
+ port: 22
+ allowedRoutes:
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: https-talos-midnightthoughts
protocol: HTTPS
hostname: "talos.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: talos.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: talos.midnightthoughts.space-tls
- name: https-nordgedanken.dev
protocol: HTTPS
hostname: "nordgedanken.dev"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: nordgedanken.dev-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: nordgedanken.dev-tls
- name: https-openpgpkey.nordgedanken.dev
protocol: HTTPS
hostname: "openpgpkey.nordgedanken.dev"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: openpgpkey.nordgedanken.dev-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: openpgpkey.nordgedanken.dev-tls
- name: https-midnightthoughts-auth
protocol: HTTPS
hostname: "auth.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: auth.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: auth.midnightthoughts.space-tls
- name: https-midnightthoughts-grafana
protocol: HTTPS
hostname: "grafana.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: grafana.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: grafana.midnightthoughts.space-tls
- name: https-draupnir-midnightthoughts
protocol: HTTPS
hostname: "draupnir.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: draupnir.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: draupnir.midnightthoughts.space-tls
- name: https-matrix-draupnir-midnightthoughts
protocol: HTTPS
hostname: "matrix.draupnir.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: matrix.draupnir.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: matrix.draupnir.midnightthoughts.space-tls
- name: https-midnightthoughts-vault
protocol: HTTPS
hostname: "vault.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: vault.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: vault.midnightthoughts.space-tls
- name: https-midnightthoughts-budget
protocol: HTTPS
hostname: "budget.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: budget.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: budget.midnightthoughts.space-tls
- name: https-midnightthoughts-ldap
protocol: HTTPS
hostname: "ldap.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: ldap.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: ldap.midnightthoughts.space-tls
- name: ldap
protocol: TCP
port: 389
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: https-mtrnord-blog-gts
protocol: HTTPS
hostname: "gts.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: gts.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: gts.mtrnord.blog-tls
- name: https-midnightthoughts-collabora
protocol: HTTPS
hostname: "collabora.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: collabora.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: collabora.midnightthoughts.space
- name: https-midnightthoughts-webhook-kubernetes
protocol: HTTPS
hostname: "webhook.kubernetes.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: webhook.kubernetes.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: webhook.kubernetes.midnightthoughts.space-tls
- name: https-api-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "api.connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: api.connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: api.connectivity-tester.mtrnord.blog-tls
- name: https-stage-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "stage.connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: stage.connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: stage.connectivity-tester.mtrnord.blog-tls
- name: https-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: connectivity-tester.mtrnord.blog-tls
- name: https-federationtester-mtrnord-blog
protocol: HTTPS
hostname: "federationtester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: federationtester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: federationtester.mtrnord.blog-tls
- name: https-mtrnord-blog-root
protocol: HTTPS
hostname: "mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: mtrnord.blog-tls
- name: https-mtrnord-blog-matrix
protocol: HTTPS
hostname: "matrix.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: matrix.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: matrix.mtrnord.blog-tls
- name: https-rss-mtrnord-blog
protocol: HTTPS
hostname: "rss.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rss.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rss.mtrnord.blog-tls
- name: https-notify-mtrnord-blog
protocol: HTTPS
hostname: "notify.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: notify.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: notify.mtrnord.blog-tls
- name: https-midnightthoughts-rspamd
protocol: HTTPS
hostname: "rspamd.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rspamd.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rspamd.midnightthoughts.space-tls
- name: https-midnightthoughts-plane
protocol: HTTPS
hostname: "plane.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: plane.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: plane.midnightthoughts.space
- name: https-midnightthoughts-kimai
protocol: HTTPS
hostname: "kimai.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: kimai.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: kimai.midnightthoughts.space
- name: https-midnightthoughts-morg-statistics
protocol: HTTPS
hostname: "morg-statistics.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: morg-statistics.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: morg-statistics.midnightthoughts.space
- name: https-midnightthoughts-mta-sts
protocol: HTTPS
hostname: "mta-sts.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: mta-sts.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: mta-sts.midnightthoughts.space
- name: https-midnightthoughts-lists
protocol: HTTPS
hostname: "lists.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
+ tls:
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: lists.midnightthoughts.space
+ - name: https-midnightthoughts-git
+ protocol: HTTPS
+ hostname: "git.midnightthoughts.space"
+ port: 443
+ allowedRoutes:
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: lists.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: git.midnightthoughts.space
- name: http
protocol: HTTP
port: 80
allowedRoutes:
- namespaces:
- from: "All"
- # - name: https-midnightthoughts-capacitor
- # protocol: HTTPS
- # hostname: "ui.k8s.midnightthoughts.space"
- # port: 443
- # allowedRoutes:
- # namespaces:
- # from: "All"
- # tls:
- # mode: Terminate
- # certificateRefs:
- # - kind: Secret
- # name: ui.k8s.midnightthoughts.space-tls
+ namespaces:
+ from: "All"
+ # - name: https-midnightthoughts-capacitor
+ # protocol: HTTPS
+ # hostname: "ui.k8s.midnightthoughts.space"
+ # port: 443
+ # allowedRoutes:
+ # namespaces:
+ # from: "All"
+ # tls:
+ # mode: Terminate
+ # certificateRefs:
+ # - kind: Secret
+ # name: ui.k8s.midnightthoughts.space-tls
---
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: ClientTrafficPolicy
diff --git a/apps/talos_cluster/kustomization.yaml b/apps/talos_cluster/kustomization.yaml
@@ -20,4 +20,5 @@ resources:
- ./plane
- ./kimai
- ./wkd
+ - ./cgit
# - ./matrix-org-statistics
diff --git a/apps/talos_cluster/namespaces/cgit.yaml b/apps/talos_cluster/namespaces/cgit.yaml
@@ -0,0 +1,4 @@
+apiVersion: v1
+kind: Namespace
+metadata:
+ name: cgit
diff --git a/apps/talos_cluster/namespaces/kustomization.yaml b/apps/talos_cluster/namespaces/kustomization.yaml
@@ -18,3 +18,4 @@ resources:
- kimai.yaml
- statistics.yaml
- harbor.yaml
+ - cgit.yaml