Jeffrey dcb127e9e8 crowdsec: add LAPI + AppSec and the Envoy ext_authz bouncer
Detection is CAPI community blocklists plus AppSec inline WAF, not Envoy
access-log parsing. Enforcement is gRPC ext_authz from Envoy Gateway.

Changes from the draft that was held:

Agent disabled rather than given an empty acquisition list. Chart 0.24.0
refuses to render the DaemonSet with acquisition: [] ("No acquisition or
additionalAcquisition configured"), and with no log tailing the agent has
nothing to do. The WAF collections moved to appsec.env, where they belong,
and base-http-scenarios was dropped since it only feeds log parsing. AppSec
registers with LAPI on its own, so it works without the agent.

Bouncer values updated for chart 0.8.0 (the app already pinned 0.8.0 while the
values were written against 0.6.3). Added waf.failOpen: true, whose chart
default is false and would deny every request if AppSec were unreachable.

SecurityPolicy now targets the whole gateway-public rather than the it-tools
listener. EG v1.3.2 rejects targetRefs.sectionName on SecurityPolicy, and
targeting the HTTPRoute instead would gate LAN traffic too since public routes
also parent gateway-internal. Blanket coverage of the public gateway is what we
want anyway, and failOpen keeps a bouncer outage from taking public apps down.

envoyproxy-public.yaml is kept as documentation but not applied. EG v1.3.2
already defaults envoyService.externalTrafficPolicy to Local, verified live on
all three gateway LB services, so the real client IP already reaches Envoy.

Not wired into the envoy-gateway kustomization yet. That lands once the
bouncer is up and healthy.
2026-08-26 17:00:34 +02:00
2026-07-08 09:07:03 +02:00

Kubernetes Manifests Repository

This repository contains Kubernetes manifest files for a comprehensive self-hosted platform running 40+ applications across various categories. This infrastructure was created for the migration from Docker to Kubernetes (K3S).

All applications are managed using GitOps principles with ArgoCD and utilize cert-manager for automated TLS certificate management.

Repository Structure

The repository is split into three top-level areas. Within each, there is one directory per application/component, and every manifest follows the <app>-<kind>.yaml naming convention.

├── infra/                       # Cluster infrastructure
│   ├── argocd/                  # GitOps continuous deployment
│   ├── cert-manager/            # TLS certificate management
│   ├── cloud-native-postgres/   # PostgreSQL operator
│   ├── envoy-gateway/           # Kubernetes Gateway API configuration
│   ├── kubevip/                 # High availability
│   ├── longhorn/                # Distributed storage
│   └── metallb/                 # Load balancer
│
├── applications/                # Deployed workloads
│   ├── authentik/               # Identity provider and SSO
│   ├── azure-ddns-python/       # Dynamic DNS updater
│   ├── bentopdf/                # PDF conversion
│   ├── comfyui/                 # Stable Diffusion workflow UI
│   ├── databasus/               # Database management
│   ├── excalidraw/              # Whiteboard / diagramming
│   ├── gitea/                   # Git service
│   ├── gotify/                  # Push notification server
│   ├── immich/                  # Photo and video management
│   ├── infisical/               # Secrets management
│   ├── it-tools/                # IT utilities
│   ├── jellyfin/                # Media server
│   ├── minecraft/               # Game servers
│   ├── minio-aistor/            # S3-compatible object storage
│   ├── n8n/                     # Workflow automation
│   ├── netbootxyz/              # Network boot service
│   ├── ollama/                  # Local LLM runner
│   ├── openwebui/               # Web UI for AI models
│   ├── outline/                 # Knowledge base / wiki
│   ├── passbolt/                # Password manager
│   ├── pelican/                 # Game server management panel
│   ├── proxmox/                 # Virtualization platform
│   ├── react-resume/            # Resume builder application
│   ├── searxng/                 # Privacy-respecting search engine
│   ├── technitium/              # DNS server
│   ├── truenas/                 # Storage system
│   ├── unifi/                   # Network controller
│   ├── uptime-kuma/             # Uptime monitoring
│   ├── victoria-metrics/        # Metrics and monitoring
│   ├── wikijs/                  # Documentation wiki
│   └── zipline/                 # File sharing
│
└── deprecated/                  # Deprecated applications

Categories

Core Infrastructure

  • ArgoCD: GitOps continuous deployment and application management
  • cert-manager: Automated TLS certificate provisioning using Azure DNS
  • MetalLB: Bare-metal load balancer (IP pool: 10.8.11.100-10.8.11.150)
  • KubeVIP: High-availability control plane
  • Longhorn: Distributed block storage
  • Cloud Native Postgres: PostgreSQL operator for database management
  • Envoy Gateway: Kubernetes Gateway API implementation
  • Infisical: Secrets management platform
  • Authentik: Identity provider and SSO

Media & Entertainment

  • Jellyfin: Media streaming server
  • Immich: Self-hosted photo and video management
  • Minecraft: Game servers (ATM-10 and Stacia 2 Expert modpacks)

AI & Machine Learning

  • Ollama: Local LLM runner
  • Open WebUI: Web interface for AI models
  • ComfyUI: Stable Diffusion workflow UI
  • Stable Diffusion: Image generation service

Self-Hosted Tools

  • Harbor: Container image registry
  • Pelican: Game server management panel

Development & CI/CD

  • Gitea: Self-hosted Git service with container registry
  • n8n: Workflow automation platform
  • MinIO AIStor: S3-compatible object storage

Productivity & Collaboration

  • React-Resume: Resume builder with MinIO and PostgreSQL
  • Passbolt: Team password manager
  • Wiki.js: Modern documentation platform
  • Outline: Team knowledge base and wiki (PostgreSQL, Redis/Valkey, MinIO S3, Authentik SSO)
  • Zipline: File sharing and screenshot service
  • Gotify: Push notification server with REST API and WebSocket support
  • BentoPDF: PDF conversion service
  • Excalidraw: Online whiteboard and diagramming tool
  • SearXNG: Privacy-respecting metasearch engine
  • Databasus: Database management UI
  • Uptime Kuma: Uptime and status monitoring

Administration & Monitoring

  • IT-Tools: Collection of useful IT utilities
  • Technitium: DNS server with web interface
  • Azure DDNS Python: Dynamic DNS updater for Azure DNS
  • NetbootXYZ: Network boot service for OS installation
  • VictoriaMetrics: Metrics collection and monitoring stack

External Service Integration

  • Proxmox: Virtualization platform integration
  • UniFi: Network controller integration
  • TrueNAS: Storage system integration

Deprecated

  • Nginx Ingress Controller: Replaced by Envoy Gateway; dropped after upstream support ended in March 2025
  • Psono: Self-hosted password manager; replaced by Passbolt
  • Vaultwarden: Self-hosted Bitwarden server; no longer in use
  • AFFiNE: Collaborative workspace and note-taking platform; no longer in use
  • Jenkins: CI/CD automation server; no longer in use
  • Ntfy: Push notification service; no longer in use

Infrastructure

  • Kubernetes Cluster: K3S v1.33+
  • Ingress: Envoy Gateway (Kubernetes Gateway API)
  • Load Balancer: MetalLB (IP pool: 10.8.11.100-10.8.11.150)
  • Storage: Longhorn distributed storage, separate PVCs per data type
  • TLS: cert-manager with Azure DNS validation, domain *.jsme.be
  • Secrets: Infisical secrets management
  • SSO: Authentik for centralized authentication
  • RBAC: Role-based access control for ArgoCD and service accounts

Deployment

ArgoCD monitors this repository and automatically syncs changes to the cluster. Rollbacks are possible through Git history.

Maintenance

  • GitOps: All changes made through Git commits
  • Certificate Renewal: Automated via cert-manager
  • Updates: Managed through image tag updates in manifests
S
Description
Kubernetes manifests for my self-hosted homelab cluster — 40+ applications managed with ArgoCD, Envoy Gateway, and Infisical."
Readme
985 KiB
Languages
Markdown 100%