304c8e71dbd20ad4cfefda837f747b99c5941512
Ten Gateway listeners had zero attached routes. Eight of them are in this repo and are removed here by commenting them out of the kustomization, which prunes the listener and its cert-manager Certificate. Deprecated, workloads already live in deprecated/: vaultwarden (vault.jsme.be), affine (affine.jsme.be) Superseded by minio-aistor: resume-minio (resume-minio.jsme.be), resume-minioweb (resume-minioweb.jsme.be) Written but never deployed, no namespace in the cluster: n8n (n8n.jsme.be), wikijs (wiki.jsme.be), ollama (ollama.jsme.be), openwebui (forge.jsme.be) wiki.jsme.be was one of these on the PUBLIC gateway: a listener with a valid certificate, no backend, and an allowedRoutes selector that would attach the first HTTPRoute appearing in a matching namespace. Deploying Wiki.js later expecting it to be internal would have published it. Commented rather than deleted so redeploying an app is a two line uncomment. The certificate and the gateway patch must be uncommented together. Verified with kubectl kustomize: 45 listeners render, down from 53, with all eight orphan hostnames gone and every live service still present.
Kubernetes Manifests Repository
This repository contains Kubernetes manifest files for a comprehensive self-hosted platform running 40+ applications across various categories. This infrastructure was created for the migration from Docker to Kubernetes (K3S).
All applications are managed using GitOps principles with ArgoCD and utilize cert-manager for automated TLS certificate management.
Repository Structure
The repository is split into three top-level areas. Within each, there is one directory per application/component, and every manifest follows the <app>-<kind>.yaml naming convention.
├── infra/ # Cluster infrastructure
│ ├── argocd/ # GitOps continuous deployment
│ ├── cert-manager/ # TLS certificate management
│ ├── cloud-native-postgres/ # PostgreSQL operator
│ ├── envoy-gateway/ # Kubernetes Gateway API configuration
│ ├── kubevip/ # High availability
│ ├── longhorn/ # Distributed storage
│ └── metallb/ # Load balancer
│
├── applications/ # Deployed workloads
│ ├── authentik/ # Identity provider and SSO
│ ├── azure-ddns-python/ # Dynamic DNS updater
│ ├── bentopdf/ # PDF conversion
│ ├── comfyui/ # Stable Diffusion workflow UI
│ ├── databasus/ # Database management
│ ├── excalidraw/ # Whiteboard / diagramming
│ ├── gitea/ # Git service
│ ├── gotify/ # Push notification server
│ ├── immich/ # Photo and video management
│ ├── infisical/ # Secrets management
│ ├── it-tools/ # IT utilities
│ ├── jellyfin/ # Media server
│ ├── minecraft/ # Game servers
│ ├── minio-aistor/ # S3-compatible object storage
│ ├── n8n/ # Workflow automation
│ ├── netbootxyz/ # Network boot service
│ ├── ollama/ # Local LLM runner
│ ├── openwebui/ # Web UI for AI models
│ ├── outline/ # Knowledge base / wiki
│ ├── passbolt/ # Password manager
│ ├── pelican/ # Game server management panel
│ ├── proxmox/ # Virtualization platform
│ ├── react-resume/ # Resume builder application
│ ├── searxng/ # Privacy-respecting search engine
│ ├── technitium/ # DNS server
│ ├── truenas/ # Storage system
│ ├── unifi/ # Network controller
│ ├── uptime-kuma/ # Uptime monitoring
│ ├── victoria-metrics/ # Metrics and monitoring
│ ├── wikijs/ # Documentation wiki
│ └── zipline/ # File sharing
│
└── deprecated/ # Deprecated applications
Categories
Core Infrastructure
- ArgoCD: GitOps continuous deployment and application management
- cert-manager: Automated TLS certificate provisioning using Azure DNS
- MetalLB: Bare-metal load balancer (IP pool: 10.8.11.100-10.8.11.150)
- KubeVIP: High-availability control plane
- Longhorn: Distributed block storage
- Cloud Native Postgres: PostgreSQL operator for database management
- Envoy Gateway: Kubernetes Gateway API implementation
- Infisical: Secrets management platform
- Authentik: Identity provider and SSO
Media & Entertainment
- Jellyfin: Media streaming server
- Immich: Self-hosted photo and video management
- Minecraft: Game servers (ATM-10 and Stacia 2 Expert modpacks)
AI & Machine Learning
- Ollama: Local LLM runner
- Open WebUI: Web interface for AI models
- ComfyUI: Stable Diffusion workflow UI
- Stable Diffusion: Image generation service
Self-Hosted Tools
- Harbor: Container image registry
- Pelican: Game server management panel
Development & CI/CD
- Gitea: Self-hosted Git service with container registry
- n8n: Workflow automation platform
- MinIO AIStor: S3-compatible object storage
Productivity & Collaboration
- React-Resume: Resume builder with MinIO and PostgreSQL
- Passbolt: Team password manager
- Wiki.js: Modern documentation platform
- Outline: Team knowledge base and wiki (PostgreSQL, Redis/Valkey, MinIO S3, Authentik SSO)
- Zipline: File sharing and screenshot service
- Gotify: Push notification server with REST API and WebSocket support
- BentoPDF: PDF conversion service
- Excalidraw: Online whiteboard and diagramming tool
- SearXNG: Privacy-respecting metasearch engine
- Databasus: Database management UI
- Uptime Kuma: Uptime and status monitoring
Administration & Monitoring
- IT-Tools: Collection of useful IT utilities
- Technitium: DNS server with web interface
- Azure DDNS Python: Dynamic DNS updater for Azure DNS
- NetbootXYZ: Network boot service for OS installation
- VictoriaMetrics: Metrics collection and monitoring stack
External Service Integration
- Proxmox: Virtualization platform integration
- UniFi: Network controller integration
- TrueNAS: Storage system integration
Deprecated
- Nginx Ingress Controller: Replaced by Envoy Gateway; dropped after upstream support ended in March 2025
- Psono: Self-hosted password manager; replaced by Passbolt
- Vaultwarden: Self-hosted Bitwarden server; no longer in use
- AFFiNE: Collaborative workspace and note-taking platform; no longer in use
- Jenkins: CI/CD automation server; no longer in use
- Ntfy: Push notification service; no longer in use
Infrastructure
- Kubernetes Cluster: K3S v1.33+
- Ingress: Envoy Gateway (Kubernetes Gateway API)
- Load Balancer: MetalLB (IP pool: 10.8.11.100-10.8.11.150)
- Storage: Longhorn distributed storage, separate PVCs per data type
- TLS: cert-manager with Azure DNS validation, domain *.jsme.be
- Secrets: Infisical secrets management
- SSO: Authentik for centralized authentication
- RBAC: Role-based access control for ArgoCD and service accounts
Deployment
ArgoCD monitors this repository and automatically syncs changes to the cluster. Rollbacks are possible through Git history.
Maintenance
- GitOps: All changes made through Git commits
- Certificate Renewal: Automated via cert-manager
- Updates: Managed through image tag updates in manifests
Description
Kubernetes manifests for my self-hosted homelab cluster — 40+ applications managed with ArgoCD, Envoy Gateway, and Infisical."
985 KiB
Languages
Markdown
100%