commit c5bb4ff7e7e62863783073247d6820f8b8bd2503
parent 4cf357faa91488743b307058c9e7cc7c69dc6a50
Author: MTRNord <mtrnord1@gmail.com>
Date: Fri, 2 May 2025 00:50:34 +0200
Test livekit
Diffstat:
3 files changed, 277 insertions(+), 276 deletions(-)
diff --git a/apps/base/envoy-gateway/release.yaml b/apps/base/envoy-gateway/release.yaml
@@ -75,42 +75,42 @@ spec:
protocol: TCP
port: 25
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submissions
protocol: TCP
port: 465
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: submission
protocol: TCP
port: 587
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imap
protocol: TCP
port: 143
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: imaps
protocol: TCP
port: 993
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
---
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
@@ -135,451 +135,451 @@ spec:
hostname: "mas.matrix.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: mas.matrix.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: mas.matrix.midnightthoughts.space-tls
- name: https-matrix-midnightthoughts
protocol: HTTPS
hostname: "matrix.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: matrix.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: matrix.midnightthoughts.space-tls
- name: https-draupnir-midnightthoughts
protocol: HTTPS
hostname: "draupnir.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: draupnir.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: draupnir.midnightthoughts.space-tls
- name: https-matrix-draupnir-midnightthoughts
protocol: HTTPS
hostname: "matrix.draupnir.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: matrix.draupnir.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: matrix.draupnir.midnightthoughts.space-tls
- name: https-docuseal-midnightthoughts
protocol: HTTPS
hostname: "docuseal.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: docuseal.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: docuseal.midnightthoughts.space-tls
- name: https-midnightthoughts-neoboard
protocol: HTTPS
hostname: "miro-export.neoboard.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: miro-export.neoboard.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: miro-export.neoboard.midnightthoughts.space-tls
- name: https-midnightthoughts-certs
protocol: HTTPS
hostname: "certs.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: certs.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: certs.midnightthoughts.space-tls
- name: https-midnightthoughts-capacitor
protocol: HTTPS
hostname: "ui.k8s.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: ui.k8s.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: ui.k8s.midnightthoughts.space-tls
- name: https-midnightthoughts-auth
protocol: HTTPS
hostname: "auth.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: auth.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: auth.midnightthoughts.space-tls
- name: https-midnightthoughts-ldap
protocol: HTTPS
hostname: "ldap.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: ldap.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: ldap.midnightthoughts.space-tls
- name: https-midnightthoughts-status-webhook
protocol: HTTPS
hostname: "webhook.status.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: webhook.status.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: webhook.status.midnightthoughts.space-tls
- name: https-midnightthoughts-budget
protocol: HTTPS
hostname: "budget.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: budget.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: budget.midnightthoughts.space-tls
- name: https-midnightthoughts-bugzilla
protocol: HTTPS
hostname: "bugzilla.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: bugzilla.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: bugzilla.midnightthoughts.space-tls
- name: https-midnightthoughts-root
protocol: HTTPS
hostname: "midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: midnightthoughts.space-tls
- name: https-midnightthoughts-status
protocol: HTTPS
hostname: "status.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: status.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: status.midnightthoughts.space-tls
- name: https-midnightthoughts-webhook-kubernetes
protocol: HTTPS
hostname: "webhook.kubernetes.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: webhook.kubernetes.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: webhook.kubernetes.midnightthoughts.space-tls
- name: https-midnightthoughts-rspamd
protocol: HTTPS
hostname: "rspamd.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rspamd.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rspamd.midnightthoughts.space-tls
- name: https-midnightthoughts-grafana
protocol: HTTPS
hostname: "grafana.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: grafana.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: grafana.midnightthoughts.space-tls
- name: https-midnightthoughts-osticket
protocol: HTTPS
hostname: "osticket.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: osticket.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: osticket.midnightthoughts.space-tls
- name: https-midnightthoughts-vault
protocol: HTTPS
hostname: "vault.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: vault.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: vault.midnightthoughts.space-tls
- name: https-midnightthoughts-rook
protocol: HTTPS
hostname: "rook.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rook.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rook.midnightthoughts.space-tls
- name: https-midnightthoughts-jenkins
protocol: HTTPS
hostname: "jenkins.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: jenkins.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: jenkins.midnightthoughts.space-tls
- name: https-midnightthoughts-gerrit
protocol: HTTPS
hostname: "gerrit.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: gerrit.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: gerrit.midnightthoughts.space-tls
- name: https-midnightthoughts-uptime
protocol: HTTPS
hostname: "uptime.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: uptime.midnightthoughts.space-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: uptime.midnightthoughts.space-tls
- name: https-midnightthoughts-element-changes
protocol: HTTPS
hostname: "element-changes.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: element-changes.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: element-changes.midnightthoughts.space
- name: https-midnightthoughts-dav
protocol: HTTPS
hostname: "dav.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: dav.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: dav.midnightthoughts.space
- name: https-midnightthoughts-plane
protocol: HTTPS
hostname: "plane.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: plane.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: plane.midnightthoughts.space
- name: https-midnightthoughts-irc
protocol: HTTPS
hostname: "irc.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: irc.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: irc.midnightthoughts.space
- name: https-midnightthoughts-rspamd-matrix
protocol: HTTPS
hostname: "rspamd.matrix.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: rspamd.matrix.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: rspamd.matrix.midnightthoughts.space
- name: https-midnightthoughts-livekit
protocol: HTTPS
hostname: "livekit.matrix.midnightthoughts.space"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: livekit.matrix.midnightthoughts.space
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: livekit.matrix.midnightthoughts.space
- name: https-nordgedanken-root
protocol: HTTPS
hostname: "nordgedanken.dev"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: nordgedanken.dev-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: nordgedanken.dev-tls
- name: https-nordgedanken
protocol: HTTPS
hostname: "*.nordgedanken.dev"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: nordgedanken.dev-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: nordgedanken.dev-tls
- name: https-mtrnord-blog-root
protocol: HTTPS
hostname: "mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: mtrnord.blog-tls
- name: https-mtrnord-blog-hubzilla
protocol: HTTPS
hostname: "hub.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: hub.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: hub.mtrnord.blog-tls
- name: https-mtrnord-blog-mastodon
protocol: HTTPS
hostname: "mastodon.mtrnord.blog"
port: 443
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
tls:
- mode: Terminate
- certificateRefs:
- - kind: Secret
- name: mastodon.mtrnord.blog-tls
+ mode: Terminate
+ certificateRefs:
+ - kind: Secret
+ name: mastodon.mtrnord.blog-tls
- name: http
protocol: HTTP
port: 80
allowedRoutes:
- namespaces:
- from: "All"
+ namespaces:
+ from: "All"
- name: ldap
protocol: TCP
port: 389
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: gerrit-ssh
protocol: TCP
port: 29418
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
- name: ircs
protocol: TCP
port: 6697
allowedRoutes:
- kinds:
- - kind: TCPRoute
- namespaces:
- from: All
+ kinds:
+ - kind: TCPRoute
+ namespaces:
+ from: All
---
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: ClientTrafficPolicy
diff --git a/apps/base/externaldns/release.yaml b/apps/base/externaldns/release.yaml
@@ -31,6 +31,7 @@ spec:
- gateway-tcproute
- gateway-tlsroute
- gateway-udproute
+ - service
rbac:
additionalPermissions:
- apiGroups: [""]
diff --git a/apps/base/matrix/livekit/release.yaml b/apps/base/matrix/livekit/release.yaml
@@ -25,13 +25,13 @@ sops:
age:
- recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2WnplWS9tWmhoNFBWQS9s
- M2hxSWp4blJIZ255Q2t1K3lzbnBhSk5Eb0M0CmFvZER6UXErZW1ybGRlSVVzeDhn
- Tk9lVVZoTU5vcDRqM3dOS2pVZVNOTWcKLS0tIGVuVEpNNlB4OFBnK3BiN0JiMzBq
- bjRoS3hwNERmMnhkQU8yTVVYNE9XOVUKGtwCOFJog8ZHI6t6kGAFGQYSG/kzRVzQ
- fFDO4GsRsk760K0kKXkMfP4ePISGgmjhGP7uV4blp3/s/4vb+nXbmg==
- -----END AGE ENCRYPTED FILE-----
+ -----BEGIN AGE ENCRYPTED FILE-----
+ YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2WnplWS9tWmhoNFBWQS9s
+ M2hxSWp4blJIZ255Q2t1K3lzbnBhSk5Eb0M0CmFvZER6UXErZW1ybGRlSVVzeDhn
+ Tk9lVVZoTU5vcDRqM3dOS2pVZVNOTWcKLS0tIGVuVEpNNlB4OFBnK3BiN0JiMzBq
+ bjRoS3hwNERmMnhkQU8yTVVYNE9XOVUKGtwCOFJog8ZHI6t6kGAFGQYSG/kzRVzQ
+ fFDO4GsRsk760K0kKXkMfP4ePISGgmjhGP7uV4blp3/s/4vb+nXbmg==
+ -----END AGE ENCRYPTED FILE-----
lastmodified: "2025-05-01T22:18:52Z"
mac: ENC[AES256_GCM,data:jxx2qu8BkBEy+4mCan3k4FbVj04GnynLPQkWKtZkOGIsgHomn6utQMKlPZCpcIbcnvyQlhA1kENWB/WVXxzytXheYsQGlzyh0XUu8lHWuKbCA+aOaemOTjnvydt2Nh5XLOxsso72FoRBCF7jPZ2R+zjJiCx8dPFEBPY2JU6Z5EQ=,iv:fzBvlmU5tcUEUHCdkLmwm8/tC1yc6tIV4rdN2hs2pVg=,tag:kpwmXNjvt31oUFQCPWq33Q==,type:str]
pgp: []
@@ -52,13 +52,13 @@ sops:
age:
- recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2WnplWS9tWmhoNFBWQS9s
- M2hxSWp4blJIZ255Q2t1K3lzbnBhSk5Eb0M0CmFvZER6UXErZW1ybGRlSVVzeDhn
- Tk9lVVZoTU5vcDRqM3dOS2pVZVNOTWcKLS0tIGVuVEpNNlB4OFBnK3BiN0JiMzBq
- bjRoS3hwNERmMnhkQU8yTVVYNE9XOVUKGtwCOFJog8ZHI6t6kGAFGQYSG/kzRVzQ
- fFDO4GsRsk760K0kKXkMfP4ePISGgmjhGP7uV4blp3/s/4vb+nXbmg==
- -----END AGE ENCRYPTED FILE-----
+ -----BEGIN AGE ENCRYPTED FILE-----
+ YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2WnplWS9tWmhoNFBWQS9s
+ M2hxSWp4blJIZ255Q2t1K3lzbnBhSk5Eb0M0CmFvZER6UXErZW1ybGRlSVVzeDhn
+ Tk9lVVZoTU5vcDRqM3dOS2pVZVNOTWcKLS0tIGVuVEpNNlB4OFBnK3BiN0JiMzBq
+ bjRoS3hwNERmMnhkQU8yTVVYNE9XOVUKGtwCOFJog8ZHI6t6kGAFGQYSG/kzRVzQ
+ fFDO4GsRsk760K0kKXkMfP4ePISGgmjhGP7uV4blp3/s/4vb+nXbmg==
+ -----END AGE ENCRYPTED FILE-----
lastmodified: "2025-05-01T22:18:52Z"
mac: ENC[AES256_GCM,data:jxx2qu8BkBEy+4mCan3k4FbVj04GnynLPQkWKtZkOGIsgHomn6utQMKlPZCpcIbcnvyQlhA1kENWB/WVXxzytXheYsQGlzyh0XUu8lHWuKbCA+aOaemOTjnvydt2Nh5XLOxsso72FoRBCF7jPZ2R+zjJiCx8dPFEBPY2JU6Z5EQ=,iv:fzBvlmU5tcUEUHCdkLmwm8/tC1yc6tIV4rdN2hs2pVg=,tag:kpwmXNjvt31oUFQCPWq33Q==,type:str]
pgp: []
@@ -147,8 +147,8 @@ spec:
# clusterIssuer: letsencrypt-prod
tls:
- hosts:
- - livekit.matrix.midnightthoughts.space
- - turn.matrix.midnightthoughts.space
+ - livekit.matrix.midnightthoughts.space
+ - turn.matrix.midnightthoughts.space
# with alb, certificates needs to reside in ACM for self-discovery
# with do, use cert-manager and create certificate for turn. Load balancer is autoamtic
# with gke, specify one or more secrets to use for the certificate
@@ -188,13 +188,13 @@ sops:
age:
- recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2WnplWS9tWmhoNFBWQS9s
- M2hxSWp4blJIZ255Q2t1K3lzbnBhSk5Eb0M0CmFvZER6UXErZW1ybGRlSVVzeDhn
- Tk9lVVZoTU5vcDRqM3dOS2pVZVNOTWcKLS0tIGVuVEpNNlB4OFBnK3BiN0JiMzBq
- bjRoS3hwNERmMnhkQU8yTVVYNE9XOVUKGtwCOFJog8ZHI6t6kGAFGQYSG/kzRVzQ
- fFDO4GsRsk760K0kKXkMfP4ePISGgmjhGP7uV4blp3/s/4vb+nXbmg==
- -----END AGE ENCRYPTED FILE-----
+ -----BEGIN AGE ENCRYPTED FILE-----
+ YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2WnplWS9tWmhoNFBWQS9s
+ M2hxSWp4blJIZ255Q2t1K3lzbnBhSk5Eb0M0CmFvZER6UXErZW1ybGRlSVVzeDhn
+ Tk9lVVZoTU5vcDRqM3dOS2pVZVNOTWcKLS0tIGVuVEpNNlB4OFBnK3BiN0JiMzBq
+ bjRoS3hwNERmMnhkQU8yTVVYNE9XOVUKGtwCOFJog8ZHI6t6kGAFGQYSG/kzRVzQ
+ fFDO4GsRsk760K0kKXkMfP4ePISGgmjhGP7uV4blp3/s/4vb+nXbmg==
+ -----END AGE ENCRYPTED FILE-----
lastmodified: "2025-05-01T22:18:52Z"
mac: ENC[AES256_GCM,data:jxx2qu8BkBEy+4mCan3k4FbVj04GnynLPQkWKtZkOGIsgHomn6utQMKlPZCpcIbcnvyQlhA1kENWB/WVXxzytXheYsQGlzyh0XUu8lHWuKbCA+aOaemOTjnvydt2Nh5XLOxsso72FoRBCF7jPZ2R+zjJiCx8dPFEBPY2JU6Z5EQ=,iv:fzBvlmU5tcUEUHCdkLmwm8/tC1yc6tIV4rdN2hs2pVg=,tag:kpwmXNjvt31oUFQCPWq33Q==,type:str]
pgp: []
@@ -214,8 +214,8 @@ spec:
- livekit.matrix.midnightthoughts.space
rules:
- backendRefs:
- - name: livekit-livekit-server
- port: 80
+ - name: livekit-livekit-server
+ port: 80
sops:
kms: []
gcp_kms: []
@@ -224,13 +224,13 @@ sops:
age:
- recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2WnplWS9tWmhoNFBWQS9s
- M2hxSWp4blJIZ255Q2t1K3lzbnBhSk5Eb0M0CmFvZER6UXErZW1ybGRlSVVzeDhn
- Tk9lVVZoTU5vcDRqM3dOS2pVZVNOTWcKLS0tIGVuVEpNNlB4OFBnK3BiN0JiMzBq
- bjRoS3hwNERmMnhkQU8yTVVYNE9XOVUKGtwCOFJog8ZHI6t6kGAFGQYSG/kzRVzQ
- fFDO4GsRsk760K0kKXkMfP4ePISGgmjhGP7uV4blp3/s/4vb+nXbmg==
- -----END AGE ENCRYPTED FILE-----
+ -----BEGIN AGE ENCRYPTED FILE-----
+ YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB2WnplWS9tWmhoNFBWQS9s
+ M2hxSWp4blJIZ255Q2t1K3lzbnBhSk5Eb0M0CmFvZER6UXErZW1ybGRlSVVzeDhn
+ Tk9lVVZoTU5vcDRqM3dOS2pVZVNOTWcKLS0tIGVuVEpNNlB4OFBnK3BiN0JiMzBq
+ bjRoS3hwNERmMnhkQU8yTVVYNE9XOVUKGtwCOFJog8ZHI6t6kGAFGQYSG/kzRVzQ
+ fFDO4GsRsk760K0kKXkMfP4ePISGgmjhGP7uV4blp3/s/4vb+nXbmg==
+ -----END AGE ENCRYPTED FILE-----
lastmodified: "2025-05-01T22:18:52Z"
mac: ENC[AES256_GCM,data:jxx2qu8BkBEy+4mCan3k4FbVj04GnynLPQkWKtZkOGIsgHomn6utQMKlPZCpcIbcnvyQlhA1kENWB/WVXxzytXheYsQGlzyh0XUu8lHWuKbCA+aOaemOTjnvydt2Nh5XLOxsso72FoRBCF7jPZ2R+zjJiCx8dPFEBPY2JU6Z5EQ=,iv:fzBvlmU5tcUEUHCdkLmwm8/tC1yc6tIV4rdN2hs2pVg=,tag:kpwmXNjvt31oUFQCPWq33Q==,type:str]
pgp: []