cluster

Infrastructure files for Nordgedanken and Midnightthoughts.
git clone git://archive.git.mtrnord.blog/MTRNord/cluster.git
Log | Files | Refs | README

commit f09f1b84320b801143f0c8be1f08d0e4085a6ae2
parent 6e33ccd563d47394778f3d9b219633dc28c4d2a2
Author: MTRNord <mtrnord1@gmail.com>
Date:   Sat, 12 Apr 2025 16:41:21 +0200

Update synapse to 1.128.0

Diffstat:
Mapps/base/envoy-gateway/release.yaml | 464++++++++++++++++++++++++++++++++++++++++----------------------------------------
Mapps/base/irc/files/ircd.yaml | 22----------------------
Mapps/base/irc/resources.yaml | 106++++++++++++++++++++++++++++++++++++++++----------------------------------------
Mapps/base/matrix/synapse/release.yaml | 2+-
4 files changed, 286 insertions(+), 308 deletions(-)

diff --git a/apps/base/envoy-gateway/release.yaml b/apps/base/envoy-gateway/release.yaml @@ -75,42 +75,42 @@ spec: protocol: TCP port: 25 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submissions protocol: TCP port: 465 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: submission protocol: TCP port: 587 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imap protocol: TCP port: 143 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: imaps protocol: TCP port: 993 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All --- apiVersion: gateway.networking.k8s.io/v1 kind: Gateway @@ -135,427 +135,427 @@ spec: hostname: "mas.matrix.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mas.matrix.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: mas.matrix.midnightthoughts.space-tls - name: https-matrix-midnightthoughts protocol: HTTPS hostname: "matrix.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: matrix.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: matrix.midnightthoughts.space-tls - name: https-draupnir-midnightthoughts protocol: HTTPS hostname: "draupnir.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: draupnir.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: draupnir.midnightthoughts.space-tls - name: https-matrix-draupnir-midnightthoughts protocol: HTTPS hostname: "matrix.draupnir.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: matrix.draupnir.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: matrix.draupnir.midnightthoughts.space-tls - name: https-docuseal-midnightthoughts protocol: HTTPS hostname: "docuseal.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: docuseal.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: docuseal.midnightthoughts.space-tls - name: https-midnightthoughts-neoboard protocol: HTTPS hostname: "miro-export.neoboard.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: miro-export.neoboard.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: miro-export.neoboard.midnightthoughts.space-tls - name: https-midnightthoughts-certs protocol: HTTPS hostname: "certs.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: certs.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: certs.midnightthoughts.space-tls - name: https-midnightthoughts-capacitor protocol: HTTPS hostname: "ui.k8s.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: ui.k8s.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: ui.k8s.midnightthoughts.space-tls - name: https-midnightthoughts-auth protocol: HTTPS hostname: "auth.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: auth.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: auth.midnightthoughts.space-tls - name: https-midnightthoughts-ldap protocol: HTTPS hostname: "ldap.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: ldap.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: ldap.midnightthoughts.space-tls - name: https-midnightthoughts-status-webhook protocol: HTTPS hostname: "webhook.status.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: webhook.status.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: webhook.status.midnightthoughts.space-tls - name: https-midnightthoughts-budget protocol: HTTPS hostname: "budget.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: budget.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: budget.midnightthoughts.space-tls - name: https-midnightthoughts-bugzilla protocol: HTTPS hostname: "bugzilla.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: bugzilla.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: bugzilla.midnightthoughts.space-tls - name: https-midnightthoughts-root protocol: HTTPS hostname: "midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: midnightthoughts.space-tls - name: https-midnightthoughts-status protocol: HTTPS hostname: "status.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: status.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: status.midnightthoughts.space-tls - name: https-midnightthoughts-webhook-kubernetes protocol: HTTPS hostname: "webhook.kubernetes.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: webhook.kubernetes.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: webhook.kubernetes.midnightthoughts.space-tls - name: https-midnightthoughts-rspamd protocol: HTTPS hostname: "rspamd.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rspamd.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rspamd.midnightthoughts.space-tls - name: https-midnightthoughts-grafana protocol: HTTPS hostname: "grafana.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: grafana.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: grafana.midnightthoughts.space-tls - name: https-midnightthoughts-osticket protocol: HTTPS hostname: "osticket.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: osticket.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: osticket.midnightthoughts.space-tls - name: https-midnightthoughts-vault protocol: HTTPS hostname: "vault.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: vault.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: vault.midnightthoughts.space-tls - name: https-midnightthoughts-rook protocol: HTTPS hostname: "rook.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: rook.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: rook.midnightthoughts.space-tls - name: https-midnightthoughts-jenkins protocol: HTTPS hostname: "jenkins.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: jenkins.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: jenkins.midnightthoughts.space-tls - name: https-midnightthoughts-gerrit protocol: HTTPS hostname: "gerrit.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: gerrit.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: gerrit.midnightthoughts.space-tls - name: https-midnightthoughts-uptime protocol: HTTPS hostname: "uptime.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: uptime.midnightthoughts.space-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: uptime.midnightthoughts.space-tls - name: https-midnightthoughts-element-changes protocol: HTTPS hostname: "element-changes.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: element-changes.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: element-changes.midnightthoughts.space - name: https-midnightthoughts-dav protocol: HTTPS hostname: "dav.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: dav.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: dav.midnightthoughts.space - name: https-midnightthoughts-plane protocol: HTTPS hostname: "plane.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: plane.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: plane.midnightthoughts.space - name: https-midnightthoughts-irc protocol: HTTPS hostname: "irc.midnightthoughts.space" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: irc.midnightthoughts.space + mode: Terminate + certificateRefs: + - kind: Secret + name: irc.midnightthoughts.space - name: https-nordgedanken-root protocol: HTTPS hostname: "nordgedanken.dev" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: nordgedanken.dev-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: nordgedanken.dev-tls - name: https-nordgedanken protocol: HTTPS hostname: "*.nordgedanken.dev" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: nordgedanken.dev-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: nordgedanken.dev-tls - name: https-mtrnord-blog-root protocol: HTTPS hostname: "mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: mtrnord.blog-tls - name: https-mtrnord-blog-hubzilla protocol: HTTPS hostname: "hub.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: hub.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: hub.mtrnord.blog-tls - name: https-mtrnord-blog-mastodon protocol: HTTPS hostname: "mastodon.mtrnord.blog" port: 443 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" tls: - mode: Terminate - certificateRefs: - - kind: Secret - name: mastodon.mtrnord.blog-tls + mode: Terminate + certificateRefs: + - kind: Secret + name: mastodon.mtrnord.blog-tls - name: http protocol: HTTP port: 80 allowedRoutes: - namespaces: - from: "All" + namespaces: + from: "All" - name: ldap protocol: TCP port: 389 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: gerrit-ssh protocol: TCP port: 29418 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All - name: ircs protocol: TCP port: 6697 allowedRoutes: - kinds: - - kind: TCPRoute - namespaces: - from: All + kinds: + - kind: TCPRoute + namespaces: + from: All --- apiVersion: gateway.envoyproxy.io/v1alpha1 kind: ClientTrafficPolicy diff --git a/apps/base/irc/files/ircd.yaml b/apps/base/irc/files/ircd.yaml @@ -246,7 +246,6 @@ accounts: bcrypt-cost: 9 # length of time a user has to verify their account before it can be re-registered verify-timeout: "32h" - # options for email verification of account registrations email-verification: enabled: true @@ -332,7 +331,6 @@ accounts: # allow users to set their own nickname enforcement status, e.g., # to opt in to strict enforcement allow-custom-enforcement: false - # format for guest nicknames: # 1. these nicknames cannot be registered or reserved # 2. if a client is automatically renamed by the server, @@ -341,19 +339,16 @@ accounts: # a registered account will have this template applied to their # nicknames (e.g., 'katie' will become 'Guest-katie') guest-nickname-format: "Guest-*" - # when enabled, forces users not logged into an account to use # a nickname matching the guest template. a caveat: this may prevent # users from choosing nicknames in scripts different from the guest # nickname format. force-guest-format: false - # when enabled, forces users logged into an account to use the # account name as their nickname. when combined with strict nickname # enforcement, this lets users treat nicknames and account names # as equivalent for the purpose of ban/invite/exception lists. force-nick-equals-account: true - # parallel setting to force-nick-equals-account: if true, this forbids # anonymous users (i.e., users not logged into an account) to change their # nickname after the initial connection is complete @@ -402,11 +397,9 @@ channels: registration: # can users register new channels? enabled: true - # restrict new channel registrations to operators only? # (operators can then transfer channels to regular users using /CS TRANSFER) operator-only: false - # how many channels can each account register? max-channels-per-account: 15 # as a crude countermeasure against spambots, anonymous connections younger @@ -507,7 +500,6 @@ debug: # if you need to access it remotely, you can use an SSH tunnel. # set to `null`, "", leave blank, or omit to disable # pprof-listener: "localhost:6060" - # datastore configuration datastore: # path to the datastore @@ -540,38 +532,27 @@ languages: limits: # nicklen is the max nick length allowed nicklen: 32 - # identlen is the max ident length allowed identlen: 20 - # realnamelen is the maximum realname length allowed realnamelen: 150 - # channellen is the max channel length allowed channellen: 64 - # awaylen is the maximum length of an away message awaylen: 390 - # kicklen is the maximum length of a kick message kicklen: 390 - # topiclen is the maximum length of a channel topic topiclen: 390 - # maximum number of monitor entries a client can have monitor-entries: 100 - # whowas entries to store whowas-entries: 100 - # maximum length of channel lists (beI modes) chan-list-modes: 100 - # maximum number of messages to accept during registration (prevents # DoS / resource exhaustion attacks): registration-messages: 1024 - # message length limits for the new multiline cap multiline: max-bytes: 4096 # 0 means disabled @@ -643,7 +624,6 @@ history: # if this is set, messages older than this cannot be retrieved by anyone # (and will eventually be deleted from persistent storage, if that's enabled) expire-time: 2w - # this restricts access to channel history (it can be overridden by channel # owners). options are: 'none' (no restrictions), 'registration-time' # (logged-in users cannot retrieve messages older than their account @@ -652,7 +632,6 @@ history: # 'join-time' (users cannot retrieve messages older than the time they # joined the channel, so only always-on clients can view history). query-cutoff: "registration-time" - # if query-cutoff is set to 'registration-time', this allows retrieval # of messages that are up to 'grace-period' older than the above cutoff. # if you use 'registration-time', this is recommended to allow logged-out @@ -695,7 +674,6 @@ history: # whether to allow customization of the config at runtime using environment variables, # e.g., ERGO__SERVER__MAX_SENDQ=128k. see the manual for more details. allow-environment-overrides: true - # experimental support for mobile push notifications # see the manual for potential security, privacy, and performance implications. # DO NOT enable if you are running a Tor or I2P hidden service (i.e. one diff --git a/apps/base/irc/resources.yaml b/apps/base/irc/resources.yaml @@ -34,72 +34,72 @@ spec: - name: irc image: ghcr.io/ergochat/ergo:v2.15.0 ports: - - containerPort: 6697 - name: ircs - - containerPort: 443 - name: websocket + - containerPort: 6697 + name: ircs + - containerPort: 443 + name: websocket readinessProbe: - tcpSocket: - port: 6697 + tcpSocket: + port: 6697 livenessProbe: - tcpSocket: - port: 6697 + tcpSocket: + port: 6697 volumeMounts: - - mountPath: /ircd/ - name: irc-config - readOnly: true - - mountPath: /ircd/tls - name: irc-certs - readOnly: true - - mountPath: /ircd/db - name: irc-db + - mountPath: /ircd/ + name: irc-config + readOnly: true + - mountPath: /ircd/tls + name: irc-certs + readOnly: true + - mountPath: /ircd/db + name: irc-db env: - - name: ERGO__DATASTORE__MYSQL__PASSWORD - valueFrom: - secretKeyRef: - name: irc-db - key: password - - name: ERGO__ACCOUNTS__REGISTRATION__EMAIL_VERIFICATION__MTA__USERNAME - valueFrom: - secretKeyRef: - name: irc-db - key: emailUser - - name: ERGO__ACCOUNTS__REGISTRATION__EMAIL_VERIFICATION__MTA__PASSWORD - valueFrom: - secretKeyRef: - name: irc-db - key: emailPassword + - name: ERGO__DATASTORE__MYSQL__PASSWORD + valueFrom: + secretKeyRef: + name: irc-db + key: password + - name: ERGO__ACCOUNTS__REGISTRATION__EMAIL_VERIFICATION__MTA__USERNAME + valueFrom: + secretKeyRef: + name: irc-db + key: emailUser + - name: ERGO__ACCOUNTS__REGISTRATION__EMAIL_VERIFICATION__MTA__PASSWORD + valueFrom: + secretKeyRef: + name: irc-db + key: emailPassword - name: config-reloader # image is based on busybox which includes inotifyd + pkill image: ghcr.io/ergochat/ergo command: ["/bin/sh"] args: - - "-c" - - | - echo "Watching /ircd/"; - inotifyd - /ircd/:wMymndox /ircd/tls/:wMymndox | while read -r notifies ; do - echo "$notifies"; - echo "notify received, sending SIGHUP"; - pkill -HUP ergo; - done - echo "Exiting."; + - "-c" + - | + echo "Watching /ircd/"; + inotifyd - /ircd/:wMymndox /ircd/tls/:wMymndox | while read -r notifies ; do + echo "$notifies"; + echo "notify received, sending SIGHUP"; + pkill -HUP ergo; + done + echo "Exiting."; volumeMounts: - - mountPath: /ircd/ - name: irc-config - readOnly: true - - mountPath: /ircd/tls - name: irc-certs - readOnly: true + - mountPath: /ircd/ + name: irc-config + readOnly: true + - mountPath: /ircd/tls + name: irc-certs + readOnly: true volumes: - name: irc-config configMap: - name: irc-config + name: irc-config - name: irc-certs secret: - secretName: irc-certs + secretName: irc-certs - name: irc-db persistentVolumeClaim: - claimName: irc-db + claimName: irc-db --- apiVersion: v1 kind: Service @@ -132,8 +132,8 @@ spec: - irc.midnightthoughts.space rules: - backendRefs: - - name: irc - port: 443 + - name: irc + port: 443 --- apiVersion: gateway.networking.k8s.io/v1alpha2 kind: TCPRoute @@ -149,8 +149,8 @@ spec: sectionName: ircs rules: - backendRefs: - - name: irc - port: 6697 + - name: irc + port: 6697 --- apiVersion: gateway.envoyproxy.io/v1alpha1 kind: BackendTrafficPolicy diff --git a/apps/base/matrix/synapse/release.yaml b/apps/base/matrix/synapse/release.yaml @@ -51,7 +51,7 @@ spec: - email_address: support@nordgedanken.dev role: admin image: - tag: "v1.127.1" + tag: "v1.128.0" pullSecrets: - name: ghcr-pull extraConfig: