cluster

Infrastructure files for Nordgedanken and Midnightthoughts.
git clone git://archive.git.mtrnord.blog/MTRNord/cluster.git
Log | Files | Refs | README

commit a2a41be0db3e468ae1b2f009856d8f60f01d42f1
parent ff9f89430b2a50886d14742cf67431d96ea56c9d
Author: MTRNord <MTRNord@users.noreply.github.com>
Date:   Mon,  6 Oct 2025 11:14:24 +0200

Add cgit

Diffstat:
Aapps/talos_cluster/cgit/deployment.yaml | 109+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Aapps/talos_cluster/cgit/kustomization.yaml | 7+++++++
Aapps/talos_cluster/cgit/service.yaml | 52++++++++++++++++++++++++++++++++++++++++++++++++++++
Aapps/talos_cluster/cgit/ssh-keys.yaml | 34++++++++++++++++++++++++++++++++++
Mapps/talos_cluster/envoy-gateway/gateway_settings.yaml | 420+++++++++++++++++++++++++++++++++++++++++--------------------------------------
Mapps/talos_cluster/kustomization.yaml | 1+
Aapps/talos_cluster/namespaces/cgit.yaml | 4++++
Mapps/talos_cluster/namespaces/kustomization.yaml | 1+
8 files changed, 428 insertions(+), 200 deletions(-)

diff --git a/apps/talos_cluster/cgit/deployment.yaml b/apps/talos_cluster/cgit/deployment.yaml @@ -0,0 +1,109 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: cgit + namespace: git +spec: + accessModes: + - ReadWriteMany + resources: + requests: + storage: 2Gi +--- +apiVersion: apps/v1 +kind: Deployment +metadata: + name: cgit + namespace: git + labels: + app.kubernetes.io/name: cgit +spec: + strategy: + rollingUpdate: + maxSurge: 25% + maxUnavailable: 25% + type: RollingUpdate + selector: + matchLabels: + app: cgit + template: + metadata: + labels: + app: cgit + app.kubernetes.io/name: cgit + spec: + imagePullSecrets: + - name: ghcr-pull + containers: + - name: cgit + image: ghcr.io/mtrnord/cgit-docker:main + imagePullPolicy: Always + resources: + limits: {} + requests: + memory: "344Mi" + cpu: "252m" + ports: + - containerPort: 8080 + name: http + protocol: TCP + - containerPort: 2222 + name: ssh + protocol: TCP + volumeMounts: + - mountPath: /var/lib/gitolite3 + name: storage + - mountPath: /tmp + name: tmp + - mountPath: /var/lib/git/.ssh/admin.pub + name: ssh-keys + subPath: admin.pub + readOnly: true + - mountPath: /etc/ssh/ssh_host_rsa_key + name: ssh-keys + subPath: ssh_host_rsa_key + readOnly: true + - mountPath: /etc/ssh/ssh_host_rsa_key.pub + name: ssh-keys + subPath: ssh_host_rsa_key.pub + readOnly: true + - mountPath: /etc/ssh/ssh_host_ecdsa_key + name: ssh-keys + subPath: ssh_host_ecdsa_key + readOnly: true + - mountPath: /etc/ssh/ssh_host_ecdsa_key.pub + name: ssh-keys + subPath: ssh_host_ecdsa_key.pub + readOnly: true + - mountPath: /etc/ssh/ssh_host_ed25519_key + name: ssh-keys + subPath: ssh_host_ed25519_key + readOnly: true + - mountPath: /etc/ssh/ssh_host_ed25519_key.pub + name: ssh-keys + subPath: ssh_host_ed25519_key.pub + readOnly: true + livenessProbe: + httpGet: + path: /healthz + port: http + scheme: HTTP + initialDelaySeconds: 15 + periodSeconds: 10 + startupProbe: + httpGet: + path: /healthz + port: http + initialDelaySeconds: 15 + failureThreshold: 30 + periodSeconds: 10 + volumes: + - name: storage + persistentVolumeClaim: + claimName: cgit + - name: tmp + emptyDir: + sizeLimit: 2048Mi + - name: ssh-keys + secret: + secretName: cgit-ssh-keys diff --git a/apps/talos_cluster/cgit/kustomization.yaml b/apps/talos_cluster/cgit/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: git +resources: + - ssh-keys.yaml + - deployment.yaml + - service.yaml diff --git a/apps/talos_cluster/cgit/service.yaml b/apps/talos_cluster/cgit/service.yaml @@ -0,0 +1,52 @@ +apiVersion: v1 +kind: Service +metadata: + name: cgit + namespace: git + labels: + app: cgit +spec: + selector: + app: cgit + ports: + - port: 8080 + targetPort: http + protocol: TCP + name: http + - port: 2222 + targetPort: ssh + protocol: TCP + name: ssh +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: cgit + namespace: git +spec: + parentRefs: + - name: envoy-gateway + namespace: envoy-gateway + hostnames: + - git.midnightthoughts.space + rules: + - backendRefs: + - name: cgit + port: 8080 +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: TCPRoute +metadata: + name: cgit-ssh + namespace: git + annotations: + external-dns.alpha.kubernetes.io/hostname: git.midnightthoughts.space +spec: + parentRefs: + - name: envoy-gateway + namespace: envoy-gateway + sectionName: ssh + rules: + - backendRefs: + - name: cgit + port: 2222 diff --git a/apps/talos_cluster/cgit/ssh-keys.yaml b/apps/talos_cluster/cgit/ssh-keys.yaml @@ -0,0 +1,34 @@ +apiVersion: v1 +kind: Secret +metadata: + name: cgit-ssh-keys + namespace: git +type: Opaque +stringData: + admin.pub: ENC[AES256_GCM,data:LwbtOfDiYc5osN93bWsCnfy+ZFH9G1aR8yBxfUcR2LX03J6WJs7+gcocdzikenpZbMFNlN0Kpv8wN6dmumYIRxNeNQWc1OEDexzFTg2frxaoeb224YK0CiQtE4+WbTmWHWA/pF7zOM9H,iv:oA5jtLrzoAsEaLxlv6thdeZaBKPICWE2DWyqn0BdGx4=,tag:wMOKjJtqM5azOsPkoqfR9w==,type:str] + ssh_host_rsa_key: ENC[AES256_GCM,data:BecbLpA8XJMrsHm8vPoWd4n9JxetQ054xfDk5NRSPKRob9tkiqFObn243m5WfX3KJeg3Z1PNPo91hXJp6A7Vvpn9RJVTUJAEC5WaRkBYtPJ3zh63gmHy6t9s0ubAdEsOPH+EgXa9h8yONp2PTFgQmsM2WwD2y2sPtak+pPNFOaAg/JcKtEVHr0Op4JjM0N1PsgzDvs0HJB0b9WrlKFKYCyz4gF9brSZaKi1VPiQLTjBsvuwLFBTjsJv9RhLBubDfIHeL5tcpSxXYOqPSeITkw306ZTYztSxuBV2WsH1HdhCym6KjpnVv6+RE6QbqVxytIWeX7dA/FXb5o8HtcmWdaWtwIbxMQI+eg/flg5HZl1QrJY/TF76Sq1idATi4HEzDi3W/4HRjcIOLYhsouELL9M1oSuLEJnyHsxCuMbzh6/D5N6gDERFjgcxtl4tmHJrmQC5Bq4F130HQvtrgF5u+xfm4aVunKLko+fF3GsRR3jHP3AnqKNOTBMqW8tio//ssKnWgzdPm9JyyYiHOOov29bUHsNHX6KoX/Q8SPuYobYeoKuupazKQhtCBCERtyAkBzIIL79Q3OO5d7CcxEVpZvUGlDpoMnZZrARiyb0MNLatIfr55ltN3W8T+g1d5j8tud1VUDaHi/J/7SiT/2uRENeUQ8rs4q6vrV6crMuHKhFpRC7cweMOYFfYZOnTknFC+Lt8TGox+56wguYxdpzbucEy0pz06GCXjyUzqtbLGrP6abupeu7cx3wUvBnIjzKfcRqIXv4nBx1pYKu/MDbk/Bcc/gcfZIs0pBOIe66zMm/Wlf6OTgfAmGCioHos1D6JXTYgcDY5YKwDzVNromgS61voDgg1A2I2c6eE/DmXUSvHZya/uEjRFKQu8cfAW0JfoL4MExP67sS6pRqpNPdeKufgrqmzzC2A3R0/cP3sJXH0ycymTrxiQtbHr0WmgwFmRXOuNnTuhOrvJluU0l8k5P2Scw7XPHGQhp2PDt6K8rMO99M/nB2k+OUmiSVaz1p2oRKCpm1yskHfCG0YaZldNU6j+BxadD0R+Xc7XNcVxpyWYWv095vXdpZwY+GLCxll3lWCEyRkQgyFKQN2NL3F9KefmaBCOCwM02iwZuVc0a/I7qxkaB1cwqE+uiJH/kJ0V1HMwbDyPa8zmxi9MAO8q42Ta3ffK/qwrjtTQUFWi6x8gs0D2jt8goC/CTcunSp23FteRmEgsRNFG/2hVCmVIITDekAee/PaqdI+ntMy7xvroRbNN8cDzAjvbJn6xFt7Yn/tq0G/Z0roOdrsF1j+JO6mPRNi9gMmyn8MxQz1uF6kxdfjFvHOqGX7ZN17iZJmjf0Do4iGTbVRPtFL6R4pdBtpIZKr0u/8ePQWjfmeRagsW4UctrgJz0Tp7uOxObOMQ68xvPEXJfD4JutTlvRIuDVYtP3waVqbS0TbYgBlZPZ0kDKAxhKksPofY2BQo+ggGCudTWSu9/uFLCGM5yE0BV2DtYSGg7BAib41LVHlljVm6Pn67I8Mmww5oSw6KtwCUjToD/y3E9AC07UXxVNc1HfVnYgiTtZ2x5DvDli5nieAdPWnT/pn4wXhT3e+bSnUAXtbaZL54DsvV4dpQeQj8ro8+QV8/eG9nAcOWf7eOvxG5y9fJQLEJoWH5wf+UUtWdzyKfS1epM2w+jLblQJR1eUzR8O/5IdEm9IqgIF50IUCOjg/iBSH8Dres7jQz6NFJSOxyhaqj+zW7amn3/GU3cbA7qr6dAIdfEzwGvYXdOzmpZlTTrmr/NPPkUJeKvF2or+oQOxDakU+tqofHjJVfNzPpdjAOUKAQwR8NJbq5T91hUDmt7bqL/dK5928Nky4sFqmpAclBwO0sepGXSb1vEVadoiCscfddPIB5e1geRoHvKq5kZpJ0britbP0s+o22bmypkmnhCdEmCkkvQEEHp4OZsf0Y9jUou+y2bG0XW3kd/Nlt0T2KFZJf7l3OBp/mF6U3Tap6kwtOI6AvzMI/yaUT9PL0KFsjuUvVcWW5o1F4n9zl0YT4fvJOSPe/IxxX8CRQMw89Bw6+ro08f56EjVvTVXurAL28fCApqsTKpRis8BmiMgcOrshexG09XTGNLA16sQIiNs5GbPPkyawbbaXmAXfjSw5kUSaDuGay285H8j53JIP+bE37jGIyXy4+h/doD3upeMXmPCrrYCBZDxQWFzqEi8L3itvctW/YBSwQj7eBha//3yH1dF2FxvZvVSYRdj3mE5NLFk8J2wpqy2xhczkRzTJnXeraNc68xi8c2ffozCTZyVlMBJWSEZPnVJ8ZqiMoJhfz7CNEm7ifvkoZTUFqBc1PAD/4WPyC/iXli/ppkv8W9xJs13QYmu4LULAo78q19Nj4oi71okZWb632AK69SioXbgMzILv3EQV60KM+6I32Ld3c8tt9fw9txjUg40g/5EFn+Kv82cBaG+jQFmH18ZkwvF0rBoRKpbP5QgGhbLwCGOYX3gv6GpyR1srQxrU9q2mDDJSghVWCdR1VbIa+i5DGPpxkvpGAiKNtMi5jgvQSuuMhjc5xU4DR+QnyyYkXenSRmXmD7Is736PDNRbbij1CcPZxmOvUTPYclO1a3+Y0sMQc4Nt03vUTpKfTt43IwDxnYfjYJ+w8KIPpGE7hJ4HsLJ/o9LHsxPk0dtUt5sojPHirv5vZCm0ktRnUztHwOHSaGTA7wdA2hGVfSIOan2mJc8jJFxLC+olhx+iaIeb87KKpzF1f4hjLYOaillxSyRezQkp4V0ZEcdhkI6v3LBnBconauxh6PuJuy5ACi7tNHrpt8FLuvpqi0ZB6lzaVrfjc1ks1Dq0OO3KbxFD4qWMa0EcutkzvPsWApoNhX+tWyxBpGR2wvODegjcjp303pt3roGnbCLsj7rHfVgOf/UxrFPrfOOGzzogpCrNieuKTvB5AQ0vXNWKhCHjf4QPH1aNEdH1DPWYVn0Ae5YhHrHtjCxtmrqoZ1FAhYK8w6WyahjSbXlhwxm8HHsewRJqFF3uCiniF2nBbzvqUQXgWGz8DP+muOn6umENHmEweIl8/HB9J0ZGxNDDpFgKvbQGN7f4EEMLDm/zPYH+J4u+yBFHahioAG4qWqo5b8E5bvT7S2gQ6qBM1VAi7DgprRRz9q5d+vcAtL5ij7CJUvZ7cjbeSg0/MVRm/sDI0/YRe0sgLqW3vWecCqET+datM7nZJNE+Epfk4rktq5PdjNGgZS14jG8i5ETdNp3skcyIR9X3WjnJ44yb8VT/+bwD2fUDMoVwKK9S0nZ5o0of+Gg4CZArSZZc138lr+Iljh9L2YMCFQMpIx+DUTIWmq5BAer7Su62pC+0XzaNsG/ylwYzN+Jz5w0+hpTx6XpfBgvvXD+Iq6npy/gYBIFOFQZGvXgKnWEURfcu/LooKcFBs/x2qTuo8mcKC9/BeG5SxNgxUpcMVzh9Y4h0+s2145RP1Ty93HZFKeXoB7UMvutmY4+TXTvqCDcR3HoEfgJcOdjTVk8qxX+Fjok02Asewpsr6eQbz+IKGENRCzh2d5eC7qmdMnjRAflWu4swNiCeWD5ooExzZWaYNp9H7IcSXSKw+QsghYSIXoBFE1repXtlHVrwiqLR/OszbLfguoYSPj5sYPNzbv8uTtcGYmDv6nxT7Jvz9JqZeH+SJMpKiLrIB2ma/tE/StVlYBLgMfRxfCqnEVk7SM4ljjr9KRoRhUCBHj/8bYI1Mrb37ymnZfWZX2UIopa4Geb10iODOVdd/eqEbci64gaFi8LG+y3NagsYcxkYLsKtqWZHI2P5wEeE7juGhz92HXwd9ihb+HwENUUCyvl66ok8PtYfNA4HWzJyPYksazdFRwVemgASOHfd5qPQfBfFVQ+mgjUmU8E2gGCyVOeqoqPjrgpQNpqgYH/riROY/4HOytRtgW4otdxEzkuvZXZ4FZMn+gRyvguet0/h3tR3kbrL/+YrXugb3WbCul89XFjH65gXezMH3jyNTDXPw5NleOTlbbaL4aX2YoJFoaYNJShA2fqGBDyBXPEy55+V0CPnJfurbgj95kEWFK0V9pSxeqW6NgcYupULwgR0WgRaKYvLkTyPwdFHrzaYTv6GjFHDuu2UXXkzCp4Nz8w1AfINa1dPQUtWN1zP5vkA2oRE/Js9UTR4jlKXHFMH9Vow7o2pEkW+ECv1rwcCmyB8OvKofTxxWIIGuHYuRwr2CKKBM3FbPTDryeirp+/rLWIqgizmgQwKZvrrded4HEhKztJIh92tCf3g5zd1+CFLjz7wQLLc2e9zxTNLvl1YhLlTWxEeKLvY7yFkEHQELBv1e4aMmSUEoBIyLaamx/v8ixmv52ivcxhAu68c5AhQsUOoxqcQKQFPR1VLYMk1Bs9HIb40+QdfXPwO+K9frHsZPAfD717HRm/mfvWye6uw8HMQ5ioGBJrUFYS88KptbKWXYAlJDngAU2ZdIPwEzbeP29rUdyJAOOCx2FCXlW3zTAazOtjPeU1r11Cjka7u7VRnsPD5ftChQhVQ=,iv:i0mqMP+t3oqehBwUwkg7pAI0KnMknZfQfRjS2GWepy8=,tag:FCd2YUy/m5I12qMozQ7PHA==,type:str] + ssh_host_rsa_key.pub: ENC[AES256_GCM,data:9pXOGC2YEjqYLBA28MWqjV46meK1S7hqpxj+5ixsbe2F7+nQAUIE8KdzI7oT+1+Ni/rq1rypHdGj2EoFDz2uP6HA1c42x6uwlbuxF4RN7t2neBlIQaZTAexwlMkyDi3lO8WZSTiCJyn9P5iDFlclSD4XLSUXwOueHkGydDB79NWf0HQThl4i3qMCt4QSBwggWY0jtkO814515Uame1sdF6DIB70vuyUCOkMz7mW64Y/tanSVGSOtRoWSRdMyHJwT1NDXxTIHsko45lZZ0JwmLsEmX88NO6LgzQxlIJNhwV97uUfzRE64BlkrCv8rhq+yaBfsNognpfY+aOYuxNm1bCFQ5VBZDVHZnng8kqrSMBMMUgTXajz2cv/SUpOp8JV7fE9rUooqpTU+VuzFXmrdSVXKm+4dN2J0kmrGaK3jFsnlqJjD2wuo2NN5bWGGZ8PjapIzOGXDaIsPm4riDY43L+igSKjgu2juA8u9FFmlqRVL8DflEfwRXJiI/t2kf5P9XIXJwijCM3To2CteOyecz4gudp/N5JE9SKUjR0xFb6Gy3CgChv6/4HmmygTOjWWBbH8Al75sEMJZomE5k6hi04AXdd+cO22XM/j0a0z3sjZinYi4vAuj8eS1Ro1h/r/NdLPyXg98F+Y5X5xOczI8z091uQjPGo80PjwZ1CTf7A0gXbAHUDxOD8v1nThA5OUkwjLNAXR2B5SwOcNy/TEkRTYkUmcaizjx/3tSeQUeNnlx9PVNlkQVINOrE11+hl/16A9mAf8K1M14NsTmKyQsBnf56bL3byoKToHjSU/AoZqwXoU6zUSM8fYOH5l/FyUirYf6ggA/wZuTlcJHfwEQK+NGV4lIKz7NM1FoVMrLKyOjlnwFqnKG0dxU80X8FKCrqM4XI5SQygrU/3rC43PdGaQG2g551jUEyEez6c2kLAQ1RjEB8Tf8qZIsK177uyPb92MwVM/ZsL1XVtdH8mKPwHvT/f99KlgxkM8AGA==,iv:8Xhwysqe4zw0j4BwX4T+hE80H9IOcmuC90vFCVYaeA8=,tag:dKhxAXtG0j4sRWy/OHUEZg==,type:str] + ssh_host_ecdsa_key: ENC[AES256_GCM,data:cIhIw/D/jbG9VjlP9kHLFiqhS+kkI1d+qSEWNzoKyq3ybD/cK6pKJV7MrLRostSZ0y4/tdrCfpYj833daXxqhhPZMIt3BuJEk/jujc37JtN30dFRrMIMYPNFewYKP3krXFDnQ1Z7McvUdQfXczIRkI1E34ruU1/ADGyRrYk0V/X1jlUezUwsYfY6daf5/oCaaKTwyHGQt88aSFYUAGzgPs9hmR0S8OwA8QaH2CiAWOx0vk9XHrcrM3TZjq92Yg6/obUndvIqzxvpDZPgVUVdFYw701PDJQkwe4ohPxD9YIIjR95c0RnDb4lmW5+bkH5l1VpMTeVM+bnTYSF+DmngI+6REKUjWLqJkWIrG72GkTMy3pZfIyGBLtehFGa/Qz/LVNjIccglpeMioFdptLxRAcU/oU2Yy8M0hKcQ5Fgtj6tBxSvPVbnzXr/kLZc4LcaNONEZIxGY4MTEApiv7ausuk6w4TrR0P/htTHKCOzSR0Sf7LcCXUV771y8Xv1PWD4GvjPpXOavMVMZZLE6qgVKL1++CFMntnYDhacDErx2CLwdSOkZmNieNgWrS5f7R8o9kwPTH0oZe2TIinhP9xdb8MKjcjupHeoWytXVFFlAJ5odNzqHgYwfxp1cYISUVM/IBKM5wrskTDFDuWwibOV7bMGpoIctF6VVtHZ/4GeTHppCGWk7m7CNcSnWEjHVKgCxZbc3rd2PFanlXaKBiG80bvDN7GD5VpEI5Ni3hX8e73u9PYNQGcmPY522nt7UeU1HY9MwVCAbuYF4JcIIRwVZq1xWKVEBrt55S/zVhcPWgkP/NMchSWKzsJtFp7QuUqPCw3DpjD2oah6623kUWZ5J9pkdug+MpLBQnX9PFcJCm/13FdCJ8GGcLU0juWx5fQVhv90jDSu/e8lzetDNy3zg11GwIvoiQHWRY8iwrfaVd1DF6MtmX1df/BrfDpQe/1bcFoskcY5sMpPkg69x3QBi2QBUAt9R/GGPASLSQg==,iv:z11k/g2I03wgp7k+bxo13+s7rPNyPm0pogImM4WHce4=,tag:A7nc6DyVeerBjz9VXJWrFQ==,type:str] + ssh_host_ecdsa_key.pub: ENC[AES256_GCM,data:QEWskO5K6QTizTN+EDHoUIj2R0Z+nhOY4vsvEdlyKWWAZ1CRbULynkQLQEvE90mYFM+tB+ccz2yyUPq12eyNmPzhT1mFwPR+IVcQQQ800QOu9Kh7bfhl/8raKtXWwU5GZQySpXfQR7QaBXSBx4oa9FUCNhU1Cq4Jyya7uYjFKzWRauwvI+GyOenOacSB4XHAbRePYFRtB8FvHLoQJ8MWqShRUh1BrjtqfT3RZTDUUZjpn+OqsaQGEG0oT3N2ZqAgqHJ30r6NroN3wKRtigyWDh91w+95NCqX7oDo7i9WGZg8M8Bz6dQz7fhK7CLy1Dvjw1E/hxcqrxn7WcvsLG0F5qCrq2U6EylexSatQpnGsp2NpH4quNs=,iv:WyaSaE1cPIfxFVFXPK6QT88TPzibnICkRdHq9ra7z0Q=,tag:La697YwiNcIAEr/58/VZsA==,type:str] + ssh_host_ed25519_key: ENC[AES256_GCM,data:dfByN5f6MHJnUtZiobRobEZwGMWu44PJdtkQqcbXsF5eAbllUn17dK8CDvKsmJL6eeYg60BhI9Ai9gQV097PXRRnfcgCFlGamlMYziEhRfVPpeAzjmodI/bRnP8oQ35hCW+Y+mNtwVhq1w+EIpyeKytOH2XhVCP5xARuRACkExjUBKaUdSh2jzu+27lGlwLifOLkxdQI3Ar5GjESbhA9ZQWQ+Xz8bHw7XMfjwTG4GMqvMpX3hcGEt/pvbJ+MzFlrY+tP/xDdLboeySkUecHHle3I5t9QrRnpmQW90wm/c2Pki8kZ4FXBpTA/IQwgYcLyjF1j3am43xgOTdm1PeCwaPzI46NATh68JhPMrSbHPSWxOENwWESqCtVntpqWt0xoFN+dCVSOwO0EpvHocDKSdjEl5oP2NAx/KeYHZ3Q4VcgHGMOSiuWdajGIWg0SoFd3TdW52DE/xpV+q/QhcE6RcM/UZS5doXs00DJAs/vMupa8RbD5DUeJ9LTcVA0vLcn3IW+quHAh1ayuq2GThBjtIpZYzXpB7/essxyCRhCOPAHNH0g=,iv:CgPueImkFnjd5GjBPVFVBGFjf/2+sb1Oe+kSu3ylAWQ=,tag:bieQgVSvbbUaOe7nEA+KnQ==,type:str] + ssh_host_ed25519_key.pub: ENC[AES256_GCM,data:9npZIGIyNWuXyY2ffds95/mBH4aY8wnaz+9BXkLwnZdoCihzmQGch6c+GECQuVW/HITP6oGKUwsiqf7ZkNcQs4gARUUOiPZuiUxvrT63DD8ibVbI+Foqhz38pnwWjUv8zSOUXf6GeHaVVA3s,iv:hj1FJq/uSf8EskGfhxJ9ZDloaDZ7FRYEc4VyF5QT6u8=,tag:U0f96nEtk3jAFNulOmA76A==,type:str] +sops: + kms: [] + gcp_kms: [] + azure_kv: [] + hc_vault: [] + age: + - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA3NStQT0J3ZDI0R3B2YXpw + cXNaVFJqRENDQithOHNvWkd0MmNScDhwU0JZCmJRZ1hFWlY4TThYTWloS0IvWjhW + aitISVlxWE5nU2krdktNaWtlZFcvTzQKLS0tIEZySDdjbVVQOEN4amFORW1xanJk + eFBUTktaMXNaWUozTzV4eks0L0lRU2MKg97kIN5YohhSdHVtlK1i/igia4xmZBHl + imBTxuQQhIx2y0Wz+rpZLSUVST20BQcjvmsTX7T2utY5CjN6wSTzVQ== + -----END AGE ENCRYPTED FILE----- + lastmodified: "2025-10-06T09:14:06Z" + mac: ENC[AES256_GCM,data:uM3HYa7IKhYBTTHaIDNDyvcdClz7743zxYYcv0QkPDBRdKtMcqBxmHEtKWp7i945KmFO+a3B9wHf23iMFEMYacj79PAgmxJxx90K68agelENwUVXIG7/MNcL42nTiA/ZFBxLDbQHvSBAAU3ZaUybXiCNbSWlodY0pdO3ESjO94E=,iv:ok4f6PnHwxyNjdcje/hW2a4C9hzfyz2Qp1ulzjPPM0I=,tag:vvN/DV3dIouTxV7I0hkjpQ==,type:str] + pgp: [] + encrypted_regex: ^(harborAdminPassword|kimaiAppSecret|kimaiAdminPassword|GITHUB_CLIENT_ID|GITHUB_CLIENT_SECRET|GITHUB_PRIVATE_KEY|woosh|root_password|rspamd_password|pgdb_password|matrix_access_token|pgdb_remote_url|hmac_secret_key|adminPassword|adminEmail|jenkinsAdminEmail|securityRealm|gerrit.config|routing_key|DATABASE_URL|SMTP_PASSWORD|SECRET_KEY_BASE|admin_password|extraCommands|key|clickhouseDatabaseURL|databaseURL|client_id|client_secret|secret_key_base|otp_secret|private_key|public_key|primaryKey|deterministicKey|keyDerivationSalt|token|clientId|secretKey|installationId|installationKey|uriOverride|adminToken.value|password.value|sql_password|erlangCookie|AUTHENTICATION_PASSWORD|ROOM_API_SECRET_KEY|adminPassword|configPassword|adminUser|configUser|MAIL_PASSWORD|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret|admin_token|integrationKey|rootPassword)$ + version: 3.9.1 diff --git a/apps/talos_cluster/envoy-gateway/gateway_settings.yaml b/apps/talos_cluster/envoy-gateway/gateway_settings.yaml @@ -48,42 +48,42 @@ spec: protocol: TCP port: 25 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submissions protocol: TCP port: 465 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submission protocol: TCP port: 587 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imap protocol: TCP port: 143 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imaps protocol: TCP port: 993 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All --- apiVersion: gateway.networking.k8s.io/v1 kind: Gateway @@ -103,356 +103,376 @@ spec: load-balancer.hetzner.cloud/uses-proxyprotocol: "true" # no wildcards due to Envoy bug: https://github.com/envoyproxy/gateway/issues/2675#issuecomment-1960449002 listeners: + - name: ssh + protocol: TCP + port: 22 + allowedRoutes: + kinds: + - kind: TCPRoute + namespaces: + from: All - name: https-talos-midnightthoughts protocol: HTTPS hostname: "talos.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: talos.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: talos.midnightthoughts.space-tls - name: https-nordgedanken.dev protocol: HTTPS hostname: "nordgedanken.dev" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: nordgedanken.dev-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: nordgedanken.dev-tls - name: https-openpgpkey.nordgedanken.dev protocol: HTTPS hostname: "openpgpkey.nordgedanken.dev" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: openpgpkey.nordgedanken.dev-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: openpgpkey.nordgedanken.dev-tls - name: https-midnightthoughts-auth protocol: HTTPS hostname: "auth.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: auth.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: auth.midnightthoughts.space-tls - name: https-midnightthoughts-grafana protocol: HTTPS hostname: "grafana.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: grafana.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: grafana.midnightthoughts.space-tls - name: https-draupnir-midnightthoughts protocol: HTTPS hostname: "draupnir.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: draupnir.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: draupnir.midnightthoughts.space-tls - name: https-matrix-draupnir-midnightthoughts protocol: HTTPS hostname: "matrix.draupnir.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: matrix.draupnir.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: matrix.draupnir.midnightthoughts.space-tls - name: https-midnightthoughts-vault protocol: HTTPS hostname: "vault.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: vault.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: vault.midnightthoughts.space-tls - name: https-midnightthoughts-budget protocol: HTTPS hostname: "budget.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: budget.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: budget.midnightthoughts.space-tls - name: https-midnightthoughts-ldap protocol: HTTPS hostname: "ldap.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: ldap.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: ldap.midnightthoughts.space-tls - name: ldap protocol: TCP port: 389 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: https-mtrnord-blog-gts protocol: HTTPS hostname: "gts.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: gts.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: gts.mtrnord.blog-tls - name: https-midnightthoughts-collabora protocol: HTTPS hostname: "collabora.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: collabora.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: collabora.midnightthoughts.space - name: https-midnightthoughts-webhook-kubernetes protocol: HTTPS hostname: "webhook.kubernetes.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: webhook.kubernetes.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: webhook.kubernetes.midnightthoughts.space-tls - name: https-api-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "api.connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: api.connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: api.connectivity-tester.mtrnord.blog-tls - name: https-stage-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "stage.connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: stage.connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: stage.connectivity-tester.mtrnord.blog-tls - name: https-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: connectivity-tester.mtrnord.blog-tls - name: https-federationtester-mtrnord-blog protocol: HTTPS hostname: "federationtester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: federationtester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: federationtester.mtrnord.blog-tls - name: https-mtrnord-blog-root protocol: HTTPS hostname: "mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: mtrnord.blog-tls - name: https-mtrnord-blog-matrix protocol: HTTPS hostname: "matrix.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: matrix.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: matrix.mtrnord.blog-tls - name: https-rss-mtrnord-blog protocol: HTTPS hostname: "rss.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rss.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rss.mtrnord.blog-tls - name: https-notify-mtrnord-blog protocol: HTTPS hostname: "notify.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: notify.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: notify.mtrnord.blog-tls - name: https-midnightthoughts-rspamd protocol: HTTPS hostname: "rspamd.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rspamd.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rspamd.midnightthoughts.space-tls - name: https-midnightthoughts-plane protocol: HTTPS hostname: "plane.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: plane.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: plane.midnightthoughts.space - name: https-midnightthoughts-kimai protocol: HTTPS hostname: "kimai.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: kimai.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: kimai.midnightthoughts.space - name: https-midnightthoughts-morg-statistics protocol: HTTPS hostname: "morg-statistics.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: morg-statistics.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: morg-statistics.midnightthoughts.space - name: https-midnightthoughts-mta-sts protocol: HTTPS hostname: "mta-sts.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mta-sts.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: mta-sts.midnightthoughts.space - name: https-midnightthoughts-lists protocol: HTTPS hostname: "lists.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" + tls: + mode: Terminate + certificateRefs: + - kind: Secret + name: lists.midnightthoughts.space + - name: https-midnightthoughts-git + protocol: HTTPS + hostname: "git.midnightthoughts.space" + port: 443 + allowedRoutes: + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: lists.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: git.midnightthoughts.space - name: http protocol: HTTP port: 80 allowedRoutes: - namespaces: - from: "All" - # - name: https-midnightthoughts-capacitor - # protocol: HTTPS - # hostname: "ui.k8s.midnightthoughts.space" - # port: 443 - # allowedRoutes: - # namespaces: - # from: "All" - # tls: - # mode: Terminate - # certificateRefs: - # - kind: Secret - # name: ui.k8s.midnightthoughts.space-tls + namespaces: + from: "All" + # - name: https-midnightthoughts-capacitor + # protocol: HTTPS + # hostname: "ui.k8s.midnightthoughts.space" + # port: 443 + # allowedRoutes: + # namespaces: + # from: "All" + # tls: + # mode: Terminate + # certificateRefs: + # - kind: Secret + # name: ui.k8s.midnightthoughts.space-tls --- apiVersion: gateway.envoyproxy.io/v1alpha1 kind: ClientTrafficPolicy diff --git a/apps/talos_cluster/kustomization.yaml b/apps/talos_cluster/kustomization.yaml @@ -20,4 +20,5 @@ resources: - ./plane - ./kimai - ./wkd + - ./cgit # - ./matrix-org-statistics diff --git a/apps/talos_cluster/namespaces/cgit.yaml b/apps/talos_cluster/namespaces/cgit.yaml @@ -0,0 +1,4 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: cgit diff --git a/apps/talos_cluster/namespaces/kustomization.yaml b/apps/talos_cluster/namespaces/kustomization.yaml @@ -18,3 +18,4 @@ resources: - kimai.yaml - statistics.yaml - harbor.yaml + - cgit.yaml