Jeffrey 2d078e10c0 pelican: expose wings-mc and wings-ark on the public gateway
The console will not work from outside without this. WebsocketController hands
the browser wss://<node fqdn>:443/api/servers/<uuid>/ws built from
Node::getConnectionAddress(), so the browser talks to wings directly and never
through the panel. Same for file upload and download, which FileUploadController
builds from the same address. Everything else (login, server list, file
browsing, power actions, sending console commands) already worked publicly,
because those go through the panel API.

Adds public listeners for both nodes reusing the existing wings-mc-tls and
wings-ark-tls certificates, and a gateway-public parentRef on each route.

Extends the wings ClientTrafficPolicy to the two new listeners. Without it the
public listeners would negotiate h2 and long-lived consoles would drop: wings
only speaks HTTP/1.1, and the idle timeout needs to be 3600s rather than the
default.

CrowdSec ext_authz already covers every listener on gateway-public, so both
nodes are behind the WAF and community blocklist from the moment they are live.
Wings itself is JWT-gated and returns 401 unauthenticated.
2026-08-26 21:54:49 +02:00
2026-07-08 09:07:03 +02:00

Kubernetes Manifests Repository

This repository contains Kubernetes manifest files for a comprehensive self-hosted platform running 40+ applications across various categories. This infrastructure was created for the migration from Docker to Kubernetes (K3S).

All applications are managed using GitOps principles with ArgoCD and utilize cert-manager for automated TLS certificate management.

Repository Structure

The repository is split into three top-level areas. Within each, there is one directory per application/component, and every manifest follows the <app>-<kind>.yaml naming convention.

├── infra/                       # Cluster infrastructure
│   ├── argocd/                  # GitOps continuous deployment
│   ├── cert-manager/            # TLS certificate management
│   ├── cloud-native-postgres/   # PostgreSQL operator
│   ├── envoy-gateway/           # Kubernetes Gateway API configuration
│   ├── kubevip/                 # High availability
│   ├── longhorn/                # Distributed storage
│   └── metallb/                 # Load balancer
│
├── applications/                # Deployed workloads
│   ├── authentik/               # Identity provider and SSO
│   ├── azure-ddns-python/       # Dynamic DNS updater
│   ├── bentopdf/                # PDF conversion
│   ├── comfyui/                 # Stable Diffusion workflow UI
│   ├── databasus/               # Database management
│   ├── excalidraw/              # Whiteboard / diagramming
│   ├── gitea/                   # Git service
│   ├── gotify/                  # Push notification server
│   ├── immich/                  # Photo and video management
│   ├── infisical/               # Secrets management
│   ├── it-tools/                # IT utilities
│   ├── jellyfin/                # Media server
│   ├── minecraft/               # Game servers
│   ├── minio-aistor/            # S3-compatible object storage
│   ├── n8n/                     # Workflow automation
│   ├── netbootxyz/              # Network boot service
│   ├── ollama/                  # Local LLM runner
│   ├── openwebui/               # Web UI for AI models
│   ├── outline/                 # Knowledge base / wiki
│   ├── passbolt/                # Password manager
│   ├── pelican/                 # Game server management panel
│   ├── proxmox/                 # Virtualization platform
│   ├── react-resume/            # Resume builder application
│   ├── searxng/                 # Privacy-respecting search engine
│   ├── technitium/              # DNS server
│   ├── truenas/                 # Storage system
│   ├── unifi/                   # Network controller
│   ├── uptime-kuma/             # Uptime monitoring
│   ├── victoria-metrics/        # Metrics and monitoring
│   ├── wikijs/                  # Documentation wiki
│   └── zipline/                 # File sharing
│
└── deprecated/                  # Deprecated applications

Categories

Core Infrastructure

  • ArgoCD: GitOps continuous deployment and application management
  • cert-manager: Automated TLS certificate provisioning using Azure DNS
  • MetalLB: Bare-metal load balancer (IP pool: 10.8.11.100-10.8.11.150)
  • KubeVIP: High-availability control plane
  • Longhorn: Distributed block storage
  • Cloud Native Postgres: PostgreSQL operator for database management
  • Envoy Gateway: Kubernetes Gateway API implementation
  • Infisical: Secrets management platform
  • Authentik: Identity provider and SSO

Media & Entertainment

  • Jellyfin: Media streaming server
  • Immich: Self-hosted photo and video management
  • Minecraft: Game servers (ATM-10 and Stacia 2 Expert modpacks)

AI & Machine Learning

  • Ollama: Local LLM runner
  • Open WebUI: Web interface for AI models
  • ComfyUI: Stable Diffusion workflow UI
  • Stable Diffusion: Image generation service

Self-Hosted Tools

  • Harbor: Container image registry
  • Pelican: Game server management panel

Development & CI/CD

  • Gitea: Self-hosted Git service with container registry
  • n8n: Workflow automation platform
  • MinIO AIStor: S3-compatible object storage

Productivity & Collaboration

  • React-Resume: Resume builder with MinIO and PostgreSQL
  • Passbolt: Team password manager
  • Wiki.js: Modern documentation platform
  • Outline: Team knowledge base and wiki (PostgreSQL, Redis/Valkey, MinIO S3, Authentik SSO)
  • Zipline: File sharing and screenshot service
  • Gotify: Push notification server with REST API and WebSocket support
  • BentoPDF: PDF conversion service
  • Excalidraw: Online whiteboard and diagramming tool
  • SearXNG: Privacy-respecting metasearch engine
  • Databasus: Database management UI
  • Uptime Kuma: Uptime and status monitoring

Administration & Monitoring

  • IT-Tools: Collection of useful IT utilities
  • Technitium: DNS server with web interface
  • Azure DDNS Python: Dynamic DNS updater for Azure DNS
  • NetbootXYZ: Network boot service for OS installation
  • VictoriaMetrics: Metrics collection and monitoring stack

External Service Integration

  • Proxmox: Virtualization platform integration
  • UniFi: Network controller integration
  • TrueNAS: Storage system integration

Deprecated

  • Nginx Ingress Controller: Replaced by Envoy Gateway; dropped after upstream support ended in March 2025
  • Psono: Self-hosted password manager; replaced by Passbolt
  • Vaultwarden: Self-hosted Bitwarden server; no longer in use
  • AFFiNE: Collaborative workspace and note-taking platform; no longer in use
  • Jenkins: CI/CD automation server; no longer in use
  • Ntfy: Push notification service; no longer in use

Infrastructure

  • Kubernetes Cluster: K3S v1.33+
  • Ingress: Envoy Gateway (Kubernetes Gateway API)
  • Load Balancer: MetalLB (IP pool: 10.8.11.100-10.8.11.150)
  • Storage: Longhorn distributed storage, separate PVCs per data type
  • TLS: cert-manager with Azure DNS validation, domain *.jsme.be
  • Secrets: Infisical secrets management
  • SSO: Authentik for centralized authentication
  • RBAC: Role-based access control for ArgoCD and service accounts

Deployment

ArgoCD monitors this repository and automatically syncs changes to the cluster. Rollbacks are possible through Git history.

Maintenance

  • GitOps: All changes made through Git commits
  • Certificate Renewal: Automated via cert-manager
  • Updates: Managed through image tag updates in manifests
S
Description
Kubernetes manifests for my self-hosted homelab cluster — 40+ applications managed with ArgoCD, Envoy Gateway, and Infisical."
Readme
985 KiB
Languages
Markdown 100%