Commit Graph
78 Commits
Author SHA1 Message Date
Jeffrey 304c8e71db envoy-gateway: comment out orphaned listeners and certificates
Ten Gateway listeners had zero attached routes. Eight of them are in this repo
and are removed here by commenting them out of the kustomization, which prunes
the listener and its cert-manager Certificate.

Deprecated, workloads already live in deprecated/:
  vaultwarden (vault.jsme.be), affine (affine.jsme.be)

Superseded by minio-aistor:
  resume-minio (resume-minio.jsme.be), resume-minioweb (resume-minioweb.jsme.be)

Written but never deployed, no namespace in the cluster:
  n8n (n8n.jsme.be), wikijs (wiki.jsme.be), ollama (ollama.jsme.be),
  openwebui (forge.jsme.be)

wiki.jsme.be was one of these on the PUBLIC gateway: a listener with a valid
certificate, no backend, and an allowedRoutes selector that would attach the
first HTTPRoute appearing in a matching namespace. Deploying Wiki.js later
expecting it to be internal would have published it.

Commented rather than deleted so redeploying an app is a two line uncomment.
The certificate and the gateway patch must be uncommented together.

Verified with kubectl kustomize: 45 listeners render, down from 53, with all
eight orphan hostnames gone and every live service still present.
2026-08-26 20:10:20 +02:00
Jeffrey 3451b755d4 envoy-gateway: enable CrowdSec ext_authz on the public gateway
Wires crowdsec/gateway-public-securitypolicy.yaml into the kustomization now
that LAPI, AppSec and the bouncer are all healthy and the envoy bouncer is
registered with LAPI.

Covers every listener on gateway-public rather than just one app, since EG
v1.3.2 rejects targetRefs.sectionName on SecurityPolicy. gateway-internal is a
separate Gateway and is untouched, so LAN access is unaffected. failOpen is
true, so a bouncer outage lets traffic through instead of denying it.
2026-08-26 17:31:19 +02:00
Jeffrey 16e265239b crowdsec: cut lapi and appsec cpu requests so they schedule
Chart defaults set requests == limits == 500m for both. The node is at 95% of
allocatable CPU in requests while actually using about 10%, so lapi sat Pending
with Insufficient cpu. Requests dropped to 50m/100m with the limits left
generous, since appsec runs inline on every public request.
2026-08-26 17:05:56 +02:00
Jeffrey dcb127e9e8 crowdsec: add LAPI + AppSec and the Envoy ext_authz bouncer
Detection is CAPI community blocklists plus AppSec inline WAF, not Envoy
access-log parsing. Enforcement is gRPC ext_authz from Envoy Gateway.

Changes from the draft that was held:

Agent disabled rather than given an empty acquisition list. Chart 0.24.0
refuses to render the DaemonSet with acquisition: [] ("No acquisition or
additionalAcquisition configured"), and with no log tailing the agent has
nothing to do. The WAF collections moved to appsec.env, where they belong,
and base-http-scenarios was dropped since it only feeds log parsing. AppSec
registers with LAPI on its own, so it works without the agent.

Bouncer values updated for chart 0.8.0 (the app already pinned 0.8.0 while the
values were written against 0.6.3). Added waf.failOpen: true, whose chart
default is false and would deny every request if AppSec were unreachable.

SecurityPolicy now targets the whole gateway-public rather than the it-tools
listener. EG v1.3.2 rejects targetRefs.sectionName on SecurityPolicy, and
targeting the HTTPRoute instead would gate LAN traffic too since public routes
also parent gateway-internal. Blanket coverage of the public gateway is what we
want anyway, and failOpen keeps a bouncer outage from taking public apps down.

envoyproxy-public.yaml is kept as documentation but not applied. EG v1.3.2
already defaults envoyService.externalTrafficPolicy to Local, verified live on
all three gateway LB services, so the real client IP already reaches Envoy.

Not wired into the envoy-gateway kustomization yet. That lands once the
bouncer is up and healthy.
2026-08-26 17:00:34 +02:00
Jeffrey 63056b313a pelican: move panel image to ghcr.io/pelican/panel and pin beta38
The ghcr.io/pelican-dev/panel package is no longer anonymously pullable
(token endpoint returns DENIED for every tag, package page 404s). Upstream
renamed the org to "pelican" in beta38 and compose.yml now points at
ghcr.io/pelican/panel. Verified a real pull of v1.0.0-beta38 from the new
location succeeds.

Pinning the tag also replaces :latest, which combined with IfNotPresent meant
the running version depended on whatever the node happened to have cached.
beta36 was clean against all six published advisories, but four of them landed
in the last five months, so a deliberate patch path matters here.

beta37/38 carry no breaking changes or manual migration steps. beta37 fixes
Passkeys origin validation, which is wanted before enrolling 2FA.
2026-08-26 16:59:06 +02:00
Jeffrey 023f233f99 Revert reactive-resume to v5.0
v5.2.8 aborts startup when OIDC discovery fails. Discovery URL points at
authentik.jsme.be, which pods cannot reach due to hairpin NAT.
2026-08-24 23:18:47 +02:00
Jeffrey a57860a576 Update application and chart versions to latest
Bumps every outdated image and chart except databases, which are
deliberately left on their current versions.

Applications:
  authentik       2026.5.2 -> 2026.8.0 (server and worker)
  immich          v2.7.5 -> v3.1.0
  gitea           1.25 -> 1.27.2
  gotify          2.9.1 -> 3.0.0
  uptime-kuma     2.2.1 -> 2.5.3
  zipline         4.5.3 -> 4.7.0
  outline         1.8.1 -> 1.9.2
  reactive-resume v5.0 -> v5.2.8
  netbootxyz      nbxyz18 -> nbxyz24
  bentopdf        v2.8.2 -> v2.8.7
  jellyfin        10.11.9 -> 10.11.11
  gitea runner init busybox 1.37.0 -> 1.38.0

Infra:
  kube-vip                    v0.9.1 -> v1.2.3
  victoria-metrics-k8s-stack  0.77.0 -> 0.91.2
  intel-device-plugins        v0.35.0 -> v0.36.0
  crowdsec-envoy-bouncer      0.6.3 -> 0.8.0

Immich v3 drops pgvecto.rs support. Verified the live database already
runs vchord 0.4.3 and pgvector 0.8.1 with no pgvecto.rs extension, both
inside the ranges v3 accepts, so no database change is required.

The victoria-metrics chart renamed defaultRules.create to
defaultRules.enabled at both the top level and per group. Migrated those
keys so the etcd, kubeScheduler, kubernetesSystemControllerManager and
kubernetesSystemScheduler exclusions keep applying. Without the rename
those groups revert to enabled and alert on control-plane components
that k3s runs embedded.

That chart also moved default rules and dashboards to a runtime sync job
instead of templating them, so ArgoCD will prune the VMRules and
dashboard ConfigMaps it currently owns and the job will recreate them.

kube-vip is not managed by ArgoCD. The manifest change is inert until
applied by hand.
2026-08-24 23:12:22 +02:00
Jeffrey 38a03bb131 infisical: add resource requests and limits to postgres and valkey
Both ran as BestEffort QoS, making them first in line for eviction under node memory pressure. Requests also give the scheduler real numbers to place them with.
2026-08-24 00:46:31 +02:00
Jeffrey c505924d27 longhorn: track the longhorn-static StorageClass in Git
Longhorn auto-creates this class when missing and it is not backed by the longhorn-storageclass ConfigMap, so it had no source of truth. Set to Retain.
2026-08-24 00:43:26 +02:00
Jeffrey a7f4618d4f argocd: enable directory recurse on the remaining Directory apps
Without it, moving manifests into component directories makes ArgoCD stop seeing them and prune the workload.
2026-08-24 00:35:31 +02:00
Jeffrey 0177c73fa9 gitea: migrate to envFrom with per-container InfisicalSecrets
Flat CR narrowed to recursive: false; it still serves the SMB mount credentials and the Actions runner token, which the runner Helm chart reads via existingSecret.
2026-08-24 00:20:29 +02:00
Jeffrey 079830a8ff authentik: migrate to envFrom with per-container InfisicalSecrets
Server and worker share one Secret since their env is byte-identical. Database and SMTP values are Infisical references rather than copies.
2026-08-24 00:16:26 +02:00
Jeffrey 3e13b76c6a react-resume: migrate to envFrom with per-container InfisicalSecrets
Stores PRINTER_ENDPOINT pre-assembled instead of building it from CHROME_TOKEN via $() interpolation.
2026-08-23 23:47:13 +02:00
Jeffrey 3c24cd4b9d gotify: migrate to envFrom with per-container InfisicalSecrets
Stores the fully assembled database DSN in Infisical instead of building it from three helper vars with $() interpolation, which envFrom cannot feed.
2026-08-23 23:38:16 +02:00
Jeffrey f382c87f58 pelican: migrate to envFrom with per-container InfisicalSecrets
Folds the pelican-config ConfigMap into Infisical so the container has a single envFrom. Pins imagePullPolicy to IfNotPresent because ghcr.io/pelican-dev/panel no longer allows anonymous pulls.
2026-08-23 23:16:37 +02:00
Jeffrey 647d82fe0f argocd: enable recurse on the ddns application
azure-ddns now uses a component directory like the other apps, and without recurse ArgoCD stopped seeing its StatefulSet and InfisicalSecret.
2026-08-23 22:51:15 +02:00
Jeffrey 0329546d87 azure-ddns: migrate to envFrom with a per-container InfisicalSecret
Also moves the manifests into a component directory, matching the other migrated apps.
2026-08-23 22:42:09 +02:00
Jeffrey c408522988 immich: migrate to envFrom with per-container InfisicalSecrets
Flat CR narrowed to recursive: false so it keeps serving the SMB credentials that immich-data-smb references by name.
2026-08-23 22:15:10 +02:00
Jeffrey 77b8bd4475 passbolt: migrate to envFrom with per-container InfisicalSecrets
Also removes the now-stale flat CR files for searxng, outline and passbolt, which ArgoCD would otherwise recreate pointing at emptied folders.
2026-08-23 21:54:06 +02:00
Jeffrey fccf9074d2 outline: migrate to envFrom with per-container InfisicalSecrets
All 31 env entries, secrets and literals alike, now live in Infisical under /outline/outline and /outline/postgres. Manifest rationale carried across as Infisical secret comments.
2026-08-23 20:55:21 +02:00
Jeffrey 10545c03be searxng: migrate to envFrom; move remaining literals into Infisical
Non-secret config now lives in Infisical alongside the secrets, so containers carry envFrom only and no loose env entries.
2026-08-23 20:34:38 +02:00
Jeffrey 14ef1c6e91 zipline: migrate to envFrom with per-container InfisicalSecrets
Flat CR narrowed to recursive: false so it keeps serving the SMB mount credentials that zipline-uploads-pv references by name.
2026-08-23 20:08:43 +02:00
Jeffrey 3bec829396 infisical: repoint secret CRs at the rebuilt machine identity
Also tracks the auth ServiceAccounts and RBAC in Git so a namespace rebuild restores Kubernetes auth on its own.
2026-08-23 20:08:28 +02:00
Jeffrey 7956c6b1b9 Migrate to using EnvFrom with the use of Infisical Secret sync for env vars 2026-08-23 18:23:56 +02:00
Jeffrey 19bab56874 Revert "infisical: add resource requests and limits to postgres and valkey"
This reverts commit c72c6a322e.
2026-08-22 17:04:27 +02:00
Jeffrey c72c6a322e infisical: add resource requests and limits to postgres and valkey
Both ran as BestEffort QoS, making them first in line for eviction
under node memory pressure. Requests also give the scheduler real
numbers to place them with.
2026-08-22 16:55:50 +02:00
Jeffrey 1a4c765fec Bump technitium to 15.4.0 2026-08-22 13:12:34 +02:00
Jeffrey 43af4997ab pelican: wings-ark backend is live at 10.8.11.51 2026-08-16 21:19:22 +02:00
Jeffrey 17c84d2ba8 pelican: split wings into wings-mc and wings-ark domains 2026-08-16 21:09:00 +02:00
Jeffrey 7403edf7d5 argocd: manage namespaces via manifests instead of CreateNamespace 2026-08-16 21:08:41 +02:00
Jeffrey 39f8a78306 fix: point postgres PGDATA at the actual mounted PVC for zipline and immich 2026-08-02 12:55:18 +02:00
Jeffrey 37737670b5 infisical: bring self-hosted stack under GitOps (postgres, valkey, backend); secret.yaml excluded template 2026-07-16 21:47:28 +02:00
Jeffrey 1d026f8d57 infisical: migrate all InfisicalSecrets to Kubernetes auth; drop universal-auth secret 2026-07-16 21:18:47 +02:00
Jeffrey 7526ea0a1b infisical: route infisical.jsme.be to infisical-backend service 2026-07-15 22:20:12 +02:00
Jeffrey fc4ca1f3f1 infisical(netbootxyz): use autoCreateServiceAccountToken (short-lived k8s auth) 2026-07-15 22:07:22 +02:00
Jeffrey 596fa5380a infisical(netbootxyz): switch to Kubernetes auth (pilot) 2026-07-15 21:54:43 +02:00
Jeffrey 571c5d5d0b Move Jenkins and ntfy to deprecated 2026-07-08 09:07:03 +02:00
Jeffrey e467340edd Upgrade storage on Jellyfin 2026-07-04 17:41:36 +02:00
Jeffrey fc54063272 Increate PVC size Jellyfin 2026-06-27 14:17:55 +02:00
Jeffrey 2505812fe7 Ignore Gateway certificateRefs group diff 2026-06-22 23:41:54 +02:00
Jeffrey 9841e6a55f Fix envoy-gateway-config to use kustomize 2026-06-22 23:40:18 +02:00
Jeffrey be9bd3a227 Add Outline 2026-06-22 23:32:35 +02:00
Jeffrey 62137018ea Track envoy-gateway-config app; move affine to deprecated in README 2026-06-21 12:45:21 +02:00
Jeffrey c40577589d Split manifests into infra/ and applications/ 2026-06-21 12:23:20 +02:00
Jeffrey 64e8bf7d78 Standardize manifest filenames to <app>-<kind>.yaml 2026-06-21 12:23:20 +02:00
Jeffrey edef407a7e Move affine to deprecated 2026-06-21 10:22:47 +02:00
Jeffrey e83fe33109 Up resource usage 2026-06-20 17:51:59 +02:00
Jeffrey 4512784ce4 Fix Env variables 2026-06-20 17:23:41 +02:00
Jeffrey 862dcf73a8 Update version and addition zone name + Gotify support 2026-06-20 17:08:14 +02:00
Gitea CI f776c85482 ci: update azure-ddns-python image to 1.1 2026-06-20 15:07:47 +00:00