commit b8228de0bf9eca397251bbac4c14f5200bc402db
parent ef39184940476cd6843be1089c25507588a80ab0
Author: MTRNord <MTRNord@users.noreply.github.com>
Date: Sat, 29 Nov 2025 12:34:15 +0100
fix bugs
Signed-off-by: MTRNord <MTRNord@users.noreply.github.com>
Diffstat:
5 files changed, 320 insertions(+), 231 deletions(-)
diff --git a/apps/talos_cluster/bookwyrm/deployment.yaml b/apps/talos_cluster/bookwyrm/deployment.yaml
@@ -1,3 +1,19 @@
+---
+# Persistent Volume Claim for BookWyrm static, exports and media files
+apiVersion: v1
+kind: PersistentVolumeClaim
+metadata:
+ name: bookwyrm-pvc
+ labels:
+ app: bookwyrm
+spec:
+ accessModes:
+ - ReadWriteMany
+ resources:
+ requests:
+ storage: 5Gi
+ storageClassName: longhorn
+---
apiVersion: apps/v1
kind: Deployment
metadata:
@@ -19,6 +35,13 @@ spec:
automountServiceAccountToken: false
securityContext:
fsGroup: 1000
+ volumes:
+ - name: bookwyrm-script
+ configMap:
+ name: bookwyrm-script
+ - name: bookwyrm-data
+ persistentVolumeClaim:
+ claimName: bookwyrm-pvc
initContainers:
- name: bookwyrm-update
image: ghcr.io/mtrnord/bookwyrm:v0.8.2
@@ -30,6 +53,15 @@ spec:
- name: bookwyrm-script
mountPath: /hl
readOnly: true
+ - name: bookwyrm-data
+ mountPath: /app/static
+ subPath: static
+ - name: bookwyrm-data
+ mountPath: /app/media
+ subPath: media
+ - name: bookwyrm-data
+ mountPath: /app/exports
+ subPath: exports
env:
containers:
- name: bookwyrm-web
@@ -43,6 +75,16 @@ spec:
requests:
cpu: 200m
memory: 500Mi
+ volumeMounts:
+ - name: bookwyrm-data
+ mountPath: /app/static
+ subPath: static
+ - name: bookwyrm-data
+ mountPath: /app/media
+ subPath: media
+ - name: bookwyrm-data
+ mountPath: /app/exports
+ subPath: exports
env:
livenessProbe:
httpGet:
@@ -69,6 +111,16 @@ spec:
requests:
cpu: 200m
memory: 200Mi
+ volumeMounts:
+ - name: bookwyrm-data
+ mountPath: /app/static
+ subPath: static
+ - name: bookwyrm-data
+ mountPath: /app/media
+ subPath: media
+ - name: bookwyrm-data
+ mountPath: /app/exports
+ subPath: exports
env:
- name: bookwyrm-celery-beat
image: ghcr.io/mtrnord/bookwyrm:v0.8.2
@@ -85,6 +137,16 @@ spec:
requests:
cpu: 200m
memory: 200Mi
+ volumeMounts:
+ - name: bookwyrm-data
+ mountPath: /app/static
+ subPath: static
+ - name: bookwyrm-data
+ mountPath: /app/media
+ subPath: media
+ - name: bookwyrm-data
+ mountPath: /app/exports
+ subPath: exports
env:
- name: bookwyrm-flower
image: ghcr.io/mtrnord/bookwyrm:v0.8.2
@@ -98,6 +160,16 @@ spec:
requests:
cpu: 200m
memory: 200Mi
+ volumeMounts:
+ - name: bookwyrm-data
+ mountPath: /app/static
+ subPath: static
+ - name: bookwyrm-data
+ mountPath: /app/media
+ subPath: media
+ - name: bookwyrm-data
+ mountPath: /app/exports
+ subPath: exports
env:
ports:
- name: flower-http
diff --git a/apps/talos_cluster/bookwyrm/initJob.yaml b/apps/talos_cluster/bookwyrm/initJob.yaml
@@ -2,12 +2,14 @@ apiVersion: batch/v1
kind: Job
metadata:
name: bookwyrm-init
+ namespace: bookwyrm
labels:
app: bookwyrm
spec:
template:
metadata:
name: bookwyrm-init
+ namespace: bookwyrm
labels:
app: bookwyrm
spec:
@@ -113,4 +115,4 @@ spec:
volumes:
- name: bookwyrm-script
configMap:
- name: bookwyrm-script
+ name: bookwyrm-script-d4kgf6b8fg
diff --git a/apps/talos_cluster/bookwyrm/secret.yaml b/apps/talos_cluster/bookwyrm/secret.yaml
@@ -1,7 +1,7 @@
apiVersion: v1
kind: Secret
metadata:
- name: grafana-ro
+ name: bookwyrm-secrets
namespace: bookwyrm
type: Opaque
stringData:
@@ -15,13 +15,13 @@ sops:
age:
- recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBmQmU5U25vblh4eXNlNGwz
- RHJJZ0drV0lGY3htc2wvWTV3Wm9SL1hkS0FZClN5cWVtVkFnR0RyYkw2Qy9Hazc5
- VThWN2RzN1ltcytDN21lc0xFei8rTTgKLS0tIFIvcVI1NjFKZDgwb3czZUVnMjlk
- U0NiZlBEeTBsd0F6VHdiM21zV0hPOWsKL9kTCO3HsOUzYnE5+vINwrpEdCjdc8Bj
- D4jl+fs7y/jL/7KUpkktDFq0qr9rY27z8qeB0SbnXbOugPqTauUC2Q==
- -----END AGE ENCRYPTED FILE-----
+ -----BEGIN AGE ENCRYPTED FILE-----
+ YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBmQmU5U25vblh4eXNlNGwz
+ RHJJZ0drV0lGY3htc2wvWTV3Wm9SL1hkS0FZClN5cWVtVkFnR0RyYkw2Qy9Hazc5
+ VThWN2RzN1ltcytDN21lc0xFei8rTTgKLS0tIFIvcVI1NjFKZDgwb3czZUVnMjlk
+ U0NiZlBEeTBsd0F6VHdiM21zV0hPOWsKL9kTCO3HsOUzYnE5+vINwrpEdCjdc8Bj
+ D4jl+fs7y/jL/7KUpkktDFq0qr9rY27z8qeB0SbnXbOugPqTauUC2Q==
+ -----END AGE ENCRYPTED FILE-----
lastmodified: "2025-11-29T11:17:37Z"
mac: ENC[AES256_GCM,data:PMxhtxg9L6kaTRvs+SLd57lwpXkYyzHo78PtqxdiWgLSLlQMMxaqmI5b2ixRmf8rD6vsFY1E8Ham7hndoLJjE3SLSROudow4QF2gSdCNd+gLvy0xb9+eOVE9UhrbXYPCdpuHUkgv2IlJgAwrhj0SBxjIlu7dBtLhOO0kvhBPbAQ=,iv:dZG64PUwD378Kd3n6b//5ITCMkl1ZaZWcL75qSEmkbY=,tag:y+N8NEgeWdt8wrlX1zPjiA==,type:str]
pgp: []
diff --git a/apps/talos_cluster/envoy-gateway/gateway_settings.yaml b/apps/talos_cluster/envoy-gateway/gateway_settings.yaml
@@ -48,42 +48,42 @@ spec:
protocol: TCP
port: 25
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submissions
protocol: TCP
port: 465
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submission
protocol: TCP
port: 587
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imap
protocol: TCP
port: 143
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imaps
protocol: TCP
port: 993
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
---
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
@@ -107,390 +107,402 @@ spec:
protocol: TCP
port: 22
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: Selector
- selector:
- matchLabels:
- app: cgit
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: Selector
+ selector:
+ matchLabels:
+ app: cgit
- name: https-talos-midnightthoughts
protocol: HTTPS
hostname: "talos.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: talos.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: talos.midnightthoughts.space-tls
- name: https-nordgedanken.dev
protocol: HTTPS
hostname: "nordgedanken.dev"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: nordgedanken.dev-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: nordgedanken.dev-tls
- name: https-openpgpkey.nordgedanken.dev
protocol: HTTPS
hostname: "openpgpkey.nordgedanken.dev"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: openpgpkey.nordgedanken.dev-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: openpgpkey.nordgedanken.dev-tls
- name: https-midnightthoughts-auth
protocol: HTTPS
hostname: "auth.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: auth.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: auth.midnightthoughts.space-tls
- name: https-midnightthoughts-grafana
protocol: HTTPS
hostname: "grafana.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: grafana.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: grafana.midnightthoughts.space-tls
- name: https-draupnir-midnightthoughts
protocol: HTTPS
hostname: "draupnir.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: draupnir.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: draupnir.midnightthoughts.space-tls
- name: https-matrix-draupnir-midnightthoughts
protocol: HTTPS
hostname: "matrix.draupnir.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: matrix.draupnir.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: matrix.draupnir.midnightthoughts.space-tls
- name: https-midnightthoughts-vault
protocol: HTTPS
hostname: "vault.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: vault.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: vault.midnightthoughts.space-tls
- name: https-midnightthoughts-budget
protocol: HTTPS
hostname: "budget.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: budget.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: budget.midnightthoughts.space-tls
- name: https-midnightthoughts-ldap
protocol: HTTPS
hostname: "ldap.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: ldap.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: ldap.midnightthoughts.space-tls
- name: ldap
protocol: TCP
port: 389
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: Selector
- selector:
- matchLabels:
- app: authentik
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: Selector
+ selector:
+ matchLabels:
+ app: authentik
- name: https-mtrnord-blog-gts
protocol: HTTPS
hostname: "gts.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: gts.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: gts.mtrnord.blog-tls
+ - name: https-mtrnord-blog-books
+ protocol: HTTPS
+ hostname: "books.mtrnord.blog"
+ port: 443
+ allowedRoutes:
+ namespaces:
+ from: "All"
+ tls:
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: books.mtrnord.blog-tls
- name: https-midnightthoughts-collabora
protocol: HTTPS
hostname: "collabora.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: collabora.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: collabora.midnightthoughts.space
- name: https-midnightthoughts-webhook-kubernetes
protocol: HTTPS
hostname: "webhook.kubernetes.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: webhook.kubernetes.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: webhook.kubernetes.midnightthoughts.space-tls
- name: https-api-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "api.connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: api.connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: api.connectivity-tester.mtrnord.blog-tls
- name: https-stage-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "stage.connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: stage.connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: stage.connectivity-tester.mtrnord.blog-tls
- name: https-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: connectivity-tester.mtrnord.blog-tls
- name: https-beta-connectivity-tester-mtrnord-blog
protocol: HTTPS
hostname: "beta.connectivity-tester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: beta.connectivity-tester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: beta.connectivity-tester.mtrnord.blog-tls
- name: https-federationtester-mtrnord-blog
protocol: HTTPS
hostname: "federationtester.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: federationtester.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: federationtester.mtrnord.blog-tls
- name: https-mtrnord-blog-root
protocol: HTTPS
hostname: "mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: mtrnord.blog-tls
- name: https-mtrnord-blog-matrix
protocol: HTTPS
hostname: "matrix.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: matrix.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: matrix.mtrnord.blog-tls
- name: https-rss-mtrnord-blog
protocol: HTTPS
hostname: "rss.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rss.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rss.mtrnord.blog-tls
- name: https-notify-mtrnord-blog
protocol: HTTPS
hostname: "notify.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: notify.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: notify.mtrnord.blog-tls
- name: https-midnightthoughts-rspamd
protocol: HTTPS
hostname: "rspamd.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rspamd.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rspamd.midnightthoughts.space-tls
- name: https-midnightthoughts-plane
protocol: HTTPS
hostname: "plane.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: plane.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: plane.midnightthoughts.space
- name: https-midnightthoughts-kimai
protocol: HTTPS
hostname: "kimai.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: kimai.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: kimai.midnightthoughts.space
- name: https-midnightthoughts-morg-statistics
protocol: HTTPS
hostname: "morg-statistics.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: morg-statistics.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: morg-statistics.midnightthoughts.space
- name: https-midnightthoughts-mta-sts
protocol: HTTPS
hostname: "mta-sts.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: mta-sts.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: mta-sts.midnightthoughts.space
- name: https-midnightthoughts-lists
protocol: HTTPS
hostname: "lists.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: lists.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: lists.midnightthoughts.space
- name: https-midnightthoughts-git
protocol: HTTPS
hostname: "git.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: git.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: git.midnightthoughts.space
- name: https-midnightthoughts-plausible
protocol: HTTPS
hostname: "plausible.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: plausible.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: plausible.midnightthoughts.space
- name: http
protocol: HTTP
port: 80
allowedRoutes:
- namespaces:
- from: "Same"
+ namespaces:
+ from: "Same"
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
@@ -503,10 +515,10 @@ spec:
sectionName: http
rules:
- filters:
- - type: RequestRedirect
- requestRedirect:
- scheme: https
- statusCode: 301
+ - type: RequestRedirect
+ requestRedirect:
+ scheme: https
+ statusCode: 301
---
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: ClientTrafficPolicy
diff --git a/apps/talos_cluster/namespaces/bookwyrm.yaml b/apps/talos_cluster/namespaces/bookwyrm.yaml
@@ -1,4 +1,8 @@
apiVersion: v1
kind: Namespace
metadata:
- name: bookwyrm
-\ No newline at end of file
+ name: bookwyrm
+ labels:
+ pod-security.kubernetes.io/audit: privileged
+ pod-security.kubernetes.io/enforce: privileged
+ pod-security.kubernetes.io/warn: privileged