cluster

Infrastructure files for Nordgedanken and Midnightthoughts.
git clone git://archive.git.mtrnord.blog/MTRNord/cluster.git
Log | Files | Refs | README

commit b8228de0bf9eca397251bbac4c14f5200bc402db
parent ef39184940476cd6843be1089c25507588a80ab0
Author: MTRNord <MTRNord@users.noreply.github.com>
Date:   Sat, 29 Nov 2025 12:34:15 +0100

fix bugs

Signed-off-by: MTRNord <MTRNord@users.noreply.github.com>

Diffstat:
Mapps/talos_cluster/bookwyrm/deployment.yaml | 72++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mapps/talos_cluster/bookwyrm/initJob.yaml | 4+++-
Mapps/talos_cluster/bookwyrm/secret.yaml | 16++++++++--------
Mapps/talos_cluster/envoy-gateway/gateway_settings.yaml | 452+++++++++++++++++++++++++++++++++++++++++--------------------------------------
Mapps/talos_cluster/namespaces/bookwyrm.yaml | 7+++++--
5 files changed, 320 insertions(+), 231 deletions(-)

diff --git a/apps/talos_cluster/bookwyrm/deployment.yaml b/apps/talos_cluster/bookwyrm/deployment.yaml @@ -1,3 +1,19 @@ +--- +# Persistent Volume Claim for BookWyrm static, exports and media files +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: bookwyrm-pvc + labels: + app: bookwyrm +spec: + accessModes: + - ReadWriteMany + resources: + requests: + storage: 5Gi + storageClassName: longhorn +--- apiVersion: apps/v1 kind: Deployment metadata: @@ -19,6 +35,13 @@ spec: automountServiceAccountToken: false securityContext: fsGroup: 1000 + volumes: + - name: bookwyrm-script + configMap: + name: bookwyrm-script + - name: bookwyrm-data + persistentVolumeClaim: + claimName: bookwyrm-pvc initContainers: - name: bookwyrm-update image: ghcr.io/mtrnord/bookwyrm:v0.8.2 @@ -30,6 +53,15 @@ spec: - name: bookwyrm-script mountPath: /hl readOnly: true + - name: bookwyrm-data + mountPath: /app/static + subPath: static + - name: bookwyrm-data + mountPath: /app/media + subPath: media + - name: bookwyrm-data + mountPath: /app/exports + subPath: exports env: containers: - name: bookwyrm-web @@ -43,6 +75,16 @@ spec: requests: cpu: 200m memory: 500Mi + volumeMounts: + - name: bookwyrm-data + mountPath: /app/static + subPath: static + - name: bookwyrm-data + mountPath: /app/media + subPath: media + - name: bookwyrm-data + mountPath: /app/exports + subPath: exports env: livenessProbe: httpGet: @@ -69,6 +111,16 @@ spec: requests: cpu: 200m memory: 200Mi + volumeMounts: + - name: bookwyrm-data + mountPath: /app/static + subPath: static + - name: bookwyrm-data + mountPath: /app/media + subPath: media + - name: bookwyrm-data + mountPath: /app/exports + subPath: exports env: - name: bookwyrm-celery-beat image: ghcr.io/mtrnord/bookwyrm:v0.8.2 @@ -85,6 +137,16 @@ spec: requests: cpu: 200m memory: 200Mi + volumeMounts: + - name: bookwyrm-data + mountPath: /app/static + subPath: static + - name: bookwyrm-data + mountPath: /app/media + subPath: media + - name: bookwyrm-data + mountPath: /app/exports + subPath: exports env: - name: bookwyrm-flower image: ghcr.io/mtrnord/bookwyrm:v0.8.2 @@ -98,6 +160,16 @@ spec: requests: cpu: 200m memory: 200Mi + volumeMounts: + - name: bookwyrm-data + mountPath: /app/static + subPath: static + - name: bookwyrm-data + mountPath: /app/media + subPath: media + - name: bookwyrm-data + mountPath: /app/exports + subPath: exports env: ports: - name: flower-http diff --git a/apps/talos_cluster/bookwyrm/initJob.yaml b/apps/talos_cluster/bookwyrm/initJob.yaml @@ -2,12 +2,14 @@ apiVersion: batch/v1 kind: Job metadata: name: bookwyrm-init + namespace: bookwyrm labels: app: bookwyrm spec: template: metadata: name: bookwyrm-init + namespace: bookwyrm labels: app: bookwyrm spec: @@ -113,4 +115,4 @@ spec: volumes: - name: bookwyrm-script configMap: - name: bookwyrm-script + name: bookwyrm-script-d4kgf6b8fg diff --git a/apps/talos_cluster/bookwyrm/secret.yaml b/apps/talos_cluster/bookwyrm/secret.yaml @@ -1,7 +1,7 @@ apiVersion: v1 kind: Secret metadata: - name: grafana-ro + name: bookwyrm-secrets namespace: bookwyrm type: Opaque stringData: @@ -15,13 +15,13 @@ sops: age: - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh enc: | - -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBmQmU5U25vblh4eXNlNGwz - RHJJZ0drV0lGY3htc2wvWTV3Wm9SL1hkS0FZClN5cWVtVkFnR0RyYkw2Qy9Hazc5 - VThWN2RzN1ltcytDN21lc0xFei8rTTgKLS0tIFIvcVI1NjFKZDgwb3czZUVnMjlk - U0NiZlBEeTBsd0F6VHdiM21zV0hPOWsKL9kTCO3HsOUzYnE5+vINwrpEdCjdc8Bj - D4jl+fs7y/jL/7KUpkktDFq0qr9rY27z8qeB0SbnXbOugPqTauUC2Q== - -----END AGE ENCRYPTED FILE----- + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBmQmU5U25vblh4eXNlNGwz + RHJJZ0drV0lGY3htc2wvWTV3Wm9SL1hkS0FZClN5cWVtVkFnR0RyYkw2Qy9Hazc5 + VThWN2RzN1ltcytDN21lc0xFei8rTTgKLS0tIFIvcVI1NjFKZDgwb3czZUVnMjlk + U0NiZlBEeTBsd0F6VHdiM21zV0hPOWsKL9kTCO3HsOUzYnE5+vINwrpEdCjdc8Bj + D4jl+fs7y/jL/7KUpkktDFq0qr9rY27z8qeB0SbnXbOugPqTauUC2Q== + -----END AGE ENCRYPTED FILE----- lastmodified: "2025-11-29T11:17:37Z" mac: ENC[AES256_GCM,data:PMxhtxg9L6kaTRvs+SLd57lwpXkYyzHo78PtqxdiWgLSLlQMMxaqmI5b2ixRmf8rD6vsFY1E8Ham7hndoLJjE3SLSROudow4QF2gSdCNd+gLvy0xb9+eOVE9UhrbXYPCdpuHUkgv2IlJgAwrhj0SBxjIlu7dBtLhOO0kvhBPbAQ=,iv:dZG64PUwD378Kd3n6b//5ITCMkl1ZaZWcL75qSEmkbY=,tag:y+N8NEgeWdt8wrlX1zPjiA==,type:str] pgp: [] diff --git a/apps/talos_cluster/envoy-gateway/gateway_settings.yaml b/apps/talos_cluster/envoy-gateway/gateway_settings.yaml @@ -48,42 +48,42 @@ spec: protocol: TCP port: 25 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submissions protocol: TCP port: 465 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submission protocol: TCP port: 587 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imap protocol: TCP port: 143 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imaps protocol: TCP port: 993 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All --- apiVersion: gateway.networking.k8s.io/v1 kind: Gateway @@ -107,390 +107,402 @@ spec: protocol: TCP port: 22 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: Selector - selector: - matchLabels: - app: cgit + kinds: + - kind: TCPRoute + namespaces: + from: Selector + selector: + matchLabels: + app: cgit - name: https-talos-midnightthoughts protocol: HTTPS hostname: "talos.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: talos.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: talos.midnightthoughts.space-tls - name: https-nordgedanken.dev protocol: HTTPS hostname: "nordgedanken.dev" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: nordgedanken.dev-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: nordgedanken.dev-tls - name: https-openpgpkey.nordgedanken.dev protocol: HTTPS hostname: "openpgpkey.nordgedanken.dev" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: openpgpkey.nordgedanken.dev-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: openpgpkey.nordgedanken.dev-tls - name: https-midnightthoughts-auth protocol: HTTPS hostname: "auth.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: auth.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: auth.midnightthoughts.space-tls - name: https-midnightthoughts-grafana protocol: HTTPS hostname: "grafana.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: grafana.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: grafana.midnightthoughts.space-tls - name: https-draupnir-midnightthoughts protocol: HTTPS hostname: "draupnir.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: draupnir.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: draupnir.midnightthoughts.space-tls - name: https-matrix-draupnir-midnightthoughts protocol: HTTPS hostname: "matrix.draupnir.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: matrix.draupnir.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: matrix.draupnir.midnightthoughts.space-tls - name: https-midnightthoughts-vault protocol: HTTPS hostname: "vault.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: vault.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: vault.midnightthoughts.space-tls - name: https-midnightthoughts-budget protocol: HTTPS hostname: "budget.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: budget.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: budget.midnightthoughts.space-tls - name: https-midnightthoughts-ldap protocol: HTTPS hostname: "ldap.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: ldap.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: ldap.midnightthoughts.space-tls - name: ldap protocol: TCP port: 389 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: Selector - selector: - matchLabels: - app: authentik + kinds: + - kind: TCPRoute + namespaces: + from: Selector + selector: + matchLabels: + app: authentik - name: https-mtrnord-blog-gts protocol: HTTPS hostname: "gts.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: gts.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: gts.mtrnord.blog-tls + - name: https-mtrnord-blog-books + protocol: HTTPS + hostname: "books.mtrnord.blog" + port: 443 + allowedRoutes: + namespaces: + from: "All" + tls: + mode: Terminate + certificateRefs: + - kind: Secret + name: books.mtrnord.blog-tls - name: https-midnightthoughts-collabora protocol: HTTPS hostname: "collabora.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: collabora.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: collabora.midnightthoughts.space - name: https-midnightthoughts-webhook-kubernetes protocol: HTTPS hostname: "webhook.kubernetes.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: webhook.kubernetes.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: webhook.kubernetes.midnightthoughts.space-tls - name: https-api-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "api.connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: api.connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: api.connectivity-tester.mtrnord.blog-tls - name: https-stage-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "stage.connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: stage.connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: stage.connectivity-tester.mtrnord.blog-tls - name: https-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: connectivity-tester.mtrnord.blog-tls - name: https-beta-connectivity-tester-mtrnord-blog protocol: HTTPS hostname: "beta.connectivity-tester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: beta.connectivity-tester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: beta.connectivity-tester.mtrnord.blog-tls - name: https-federationtester-mtrnord-blog protocol: HTTPS hostname: "federationtester.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: federationtester.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: federationtester.mtrnord.blog-tls - name: https-mtrnord-blog-root protocol: HTTPS hostname: "mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: mtrnord.blog-tls - name: https-mtrnord-blog-matrix protocol: HTTPS hostname: "matrix.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: matrix.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: matrix.mtrnord.blog-tls - name: https-rss-mtrnord-blog protocol: HTTPS hostname: "rss.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rss.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rss.mtrnord.blog-tls - name: https-notify-mtrnord-blog protocol: HTTPS hostname: "notify.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: notify.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: notify.mtrnord.blog-tls - name: https-midnightthoughts-rspamd protocol: HTTPS hostname: "rspamd.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rspamd.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rspamd.midnightthoughts.space-tls - name: https-midnightthoughts-plane protocol: HTTPS hostname: "plane.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: plane.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: plane.midnightthoughts.space - name: https-midnightthoughts-kimai protocol: HTTPS hostname: "kimai.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: kimai.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: kimai.midnightthoughts.space - name: https-midnightthoughts-morg-statistics protocol: HTTPS hostname: "morg-statistics.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: morg-statistics.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: morg-statistics.midnightthoughts.space - name: https-midnightthoughts-mta-sts protocol: HTTPS hostname: "mta-sts.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mta-sts.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: mta-sts.midnightthoughts.space - name: https-midnightthoughts-lists protocol: HTTPS hostname: "lists.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: lists.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: lists.midnightthoughts.space - name: https-midnightthoughts-git protocol: HTTPS hostname: "git.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: git.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: git.midnightthoughts.space - name: https-midnightthoughts-plausible protocol: HTTPS hostname: "plausible.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: plausible.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: plausible.midnightthoughts.space - name: http protocol: HTTP port: 80 allowedRoutes: - namespaces: - from: "Same" + namespaces: + from: "Same" --- apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute @@ -503,10 +515,10 @@ spec: sectionName: http rules: - filters: - - type: RequestRedirect - requestRedirect: - scheme: https - statusCode: 301 + - type: RequestRedirect + requestRedirect: + scheme: https + statusCode: 301 --- apiVersion: gateway.envoyproxy.io/v1alpha1 kind: ClientTrafficPolicy diff --git a/apps/talos_cluster/namespaces/bookwyrm.yaml b/apps/talos_cluster/namespaces/bookwyrm.yaml @@ -1,4 +1,8 @@ apiVersion: v1 kind: Namespace metadata: - name: bookwyrm -\ No newline at end of file + name: bookwyrm + labels: + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/warn: privileged