Compare commits
725 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 4ee1a7e442 | |||
| 40ed5b5645 | |||
| 12f746c252 | |||
| b70c2342b6 | |||
| 6b29f4e5e9 | |||
| 1259655d91 | |||
| 08310e6376 | |||
| 484c963bfa | |||
| a44e2c9c73 | |||
| ad3644cedf | |||
| f9f220486e | |||
| c097cac4df | |||
| abf06173c2 | |||
| fd82b1013b | |||
| a861eb2dad | |||
| 7fdd6707ce | |||
| 2d90dd3d22 | |||
| 1839db41b1 | |||
| 76e1da7b55 | |||
| f7d4812660 | |||
| 65532383e9 | |||
| dbe83c45b3 | |||
| 0435d65bfd | |||
| 0d50a8fc32 | |||
| 41abf0d421 | |||
| 50de14e1b8 | |||
| d77c40e8ac | |||
| 52d9149c0f | |||
| 3cb85dea90 | |||
| 2209e5211f | |||
| 277097493d | |||
| a45419dc2b | |||
| 51a064bf82 | |||
| c3cb76831a | |||
| 24cc0f4e53 | |||
| 7f67c90b94 | |||
| 2c20abda1d | |||
| 926020970b | |||
| 6eccd0219a | |||
|
|
eeb760c62d | ||
| 1b89106485 | |||
| e89f61dedd | |||
| 8827edd328 | |||
| c322a7627d | |||
|
|
239bccb8ee | ||
|
|
24593bae8d | ||
|
|
d2a3c7cce0 | ||
|
|
2fd8c948d9 | ||
|
|
a6ebd2b871 | ||
|
|
10b939c6d3 | ||
|
|
6563c80f12 | ||
|
|
5a39395e0f | ||
|
|
5a144bd2fe | ||
| ffc0f1fa86 | |||
| 84ce3303f6 | |||
| 4badef2780 | |||
| 7ff12ff8e5 | |||
| b8620ce286 | |||
| 6f5fe42ad9 | |||
|
|
b13914fb19 | ||
|
|
6e5023f84d | ||
| 63698af819 | |||
| 83bda54bb0 | |||
| c80cc05fd5 | |||
| ab50210834 | |||
| 12a16fb176 | |||
| 7db650dbb2 | |||
| 43b42f6442 | |||
| 1b3c7a3544 | |||
|
|
41a229af78 | ||
|
|
a1a24f6047 | ||
|
|
75bafa1f0b | ||
|
|
9c4bb86ee9 | ||
|
|
656f9e7b28 | ||
|
|
81922b6bce | ||
|
|
a09a0390b0 | ||
|
|
c8840f7662 | ||
| a9bcbff5ac | |||
| 9b1866525f | |||
| 1821800c3a | |||
|
|
f8fc4e79e2 | ||
| f4030bee91 | |||
| 24ebe68664 | |||
| a5126d3636 | |||
|
|
078f5bc388 | ||
|
|
24d0612222 | ||
|
|
be917876a3 | ||
|
|
d70e4d1db9 | ||
| e277602a5a | |||
| 21ec47187f | |||
| 035e599194 | |||
| 5bee409112 | |||
| 689da9b9db | |||
|
|
0851bfdae0 | ||
|
|
05b779600d | ||
|
|
821a667d1a | ||
| 79eec7e560 | |||
| 007efdcb8b | |||
| 86a9e8ebcf | |||
| 27e13655eb | |||
| aef60d765b | |||
| 4ec4dd99c7 | |||
| e540b1e6d1 | |||
| bef6a2d1d7 | |||
| 71eb4415f8 | |||
| 1897181c97 | |||
| be0873d8ee | |||
| 2143505817 | |||
| 3ca3e14c29 | |||
| 9d08c0eaee | |||
| 1fc6a66a5d | |||
| 216d839df2 | |||
| 1f89ccfae6 | |||
| 1ede5b2a08 | |||
| 6ddce7829b | |||
| 887f5ef8e9 | |||
| 11d60b0936 | |||
| fcdfd21fec | |||
| f58d2c7e5b | |||
|
|
217b140ab8 | ||
|
|
5b02095007 | ||
|
|
0a263eb1cc | ||
|
|
c4979c0698 | ||
| 29d038406a | |||
| 2261d13409 | |||
| 0ebb161e7a | |||
| e90948a3b7 | |||
| c18e158fd1 | |||
| 347ce9f572 | |||
| e46e58031a | |||
| 0ed82b270c | |||
| a97660b49f | |||
| 179c4708c4 | |||
| 8fb1d12c01 | |||
| 1e10e3fdda | |||
| d6ebb7314b | |||
| 23578283a3 | |||
| 67bd67ca32 | |||
| 8c44f6580c | |||
| 19367c78ba | |||
| 5cc7c45ccf | |||
| 8211dfb63a | |||
| 3a9f5cb46c | |||
| 729759d2bb | |||
| 42dfaf1aaf | |||
| b56063b06e | |||
| 2b66791a89 | |||
| 201e0c3566 | |||
| d31081957e | |||
| c566592097 | |||
| fbd952aad3 | |||
| e98f3d4b04 | |||
| 3fa4c7e305 | |||
| a2ba404db6 | |||
| 0444d567f0 | |||
| 1c6c77ef50 | |||
| 31529e8a13 | |||
| bd63376510 | |||
| 7d43851221 | |||
| 4d13b7a313 | |||
| ca282500d1 | |||
| 239c46c3c1 | |||
| e99a9f6003 | |||
| b0fcc72dfe | |||
| 5129dda963 | |||
| 77689317ce | |||
| eb28b4f2df | |||
| 97d3125aa1 | |||
| d1ca550071 | |||
| 55250717f3 | |||
|
|
9c748befcf | ||
|
|
fb6741a447 | ||
| d333a104ab | |||
| bbf32cfd01 | |||
| 750c0b6931 | |||
| 19019b9672 | |||
| 38b57ade6f | |||
| 0bd7cd005e | |||
| 3a2a0d47ef | |||
| 8513a01738 | |||
| 634e04b240 | |||
| c58e9b2bbb | |||
| 3628973c65 | |||
| cc4f5b0eb5 | |||
| a6049673eb | |||
| 79bc67730e | |||
| 92528aee1d | |||
| 673935d16d | |||
| 7906cd43be | |||
| 45743eccc2 | |||
| ea9c15ac52 | |||
| fea66ba7f1 | |||
| 31e68fe8f3 | |||
| 1c8577160e | |||
| 22ccacc30c | |||
| ea34e4a0eb | |||
| ff9a427106 | |||
| 83f3bf744d | |||
| e36338ef48 | |||
| 70c83afce0 | |||
| 824d2268f2 | |||
| 1ef7f09d56 | |||
| ad5486b2c7 | |||
| 3efb914168 | |||
| d6dfac7499 | |||
| 53b7c2e358 | |||
| b50e096242 | |||
| bf230033b9 | |||
| 9cfef254c1 | |||
| 4aef688cc8 | |||
| a13cca80b0 | |||
| 925001d18d | |||
| 30f1e63b6c | |||
| 4156250859 | |||
| 03c8a25d83 | |||
| 40c0b051a7 | |||
| 8b6a405a7a | |||
| 0e65ec0f11 | |||
| 021b88337d | |||
| 0515542c8c | |||
| 746dad8983 | |||
| dfc13bdac2 | |||
| ec2821c023 | |||
| ba6aea45fd | |||
| 0c5d9828fd | |||
| d1c594a91e | |||
| aec9d77b08 | |||
| d16d48f1e1 | |||
| 26c9482345 | |||
| 7822ba599b | |||
| 2ef7c26453 | |||
| e1ffab5edc | |||
| ae03e9bf1d | |||
| e04d267791 | |||
| de3b6f07fc | |||
| 3c9f1b8b47 | |||
| 0abe7ae464 | |||
| 4c794b471f | |||
| 333892ffca | |||
| 302becc82e | |||
| 6ff35d3e12 | |||
|
|
966ec21418 | ||
| 91a7c4df71 | |||
| c3122a8eae | |||
| 251ed76c60 | |||
|
|
8b43b149d8 | ||
| be6000a721 | |||
| 3cd9aa2dba | |||
| 7f09bb35c8 | |||
| 61d9990269 | |||
| 69a94b9339 | |||
| c521d70b11 | |||
| ddd485c7ac | |||
| 9afab5d853 | |||
| afebee4777 | |||
| 1e5661b6ee | |||
|
|
ef76774251 | ||
| cdeb762e25 | |||
| e28e807f18 | |||
| 2c4258ffdc | |||
|
|
9e24b14d78 | ||
|
|
b7b69d4721 | ||
| e7d9a6c892 | |||
| 76d041bcde | |||
| 421723d8f0 | |||
| d5f78da216 | |||
| 95dbef7b19 | |||
| 68ead251a8 | |||
| 763c33ca7d | |||
| d5362b5818 | |||
| 2f549443e0 | |||
| 5fc0f3b467 | |||
| ba1b7a9b3b | |||
|
|
5b5475f912 | ||
|
|
da279b3c44 | ||
|
|
80e888ec26 | ||
| e6172a0d7d | |||
| e4ae42e89f | |||
| 9f8c6fcf30 | |||
| 563298321c | |||
| 4d2bb25dd2 | |||
| ae0950625c | |||
| b46d5d66d2 | |||
| f95f5ea23e | |||
| 118994d7f5 | |||
| fc15336438 | |||
| 3b71257f0b | |||
| cdf5816d5d | |||
| a049158ff6 | |||
| 9184a02490 | |||
| 65d3c58080 | |||
| 8b33462a96 | |||
| 23c2febeec | |||
| 6d3c1e4405 | |||
| aa9ca6f517 | |||
| f121a6e0d9 | |||
| 4686703176 | |||
| 479c75360e | |||
|
|
46b846fca1 | ||
|
|
a085fa35f7 | ||
|
|
34ba9ecba7 | ||
| b396ff1776 | |||
| 13640fb351 | |||
| 255dbb62b2 | |||
| 9ecff31ebb | |||
| 5f4daca17f | |||
| a3dbf1a26f | |||
| eb74c435c1 | |||
| b2685f6ce3 | |||
| 6ceed3014e | |||
| 028948a640 | |||
| af5fd10104 | |||
| 3a25bbbf24 | |||
| 8d1e15beca | |||
| d76202ebb0 | |||
| b35a0c0614 | |||
| 51d8695393 | |||
|
|
1fa83c2b1c | ||
|
|
0b9ca3a9ad | ||
| 3bfaf7366f | |||
| f18146c964 | |||
| 3d4da1f3c4 | |||
|
|
d189cc9cce | ||
| 516fe6b3d1 | |||
| c118bfe668 | |||
| 5bf74dc33b | |||
| 1339a39e89 | |||
| 7aadca21b0 | |||
|
|
4310e62837 | ||
| 0d4061158a | |||
| ebb12d5098 | |||
| 7b4d071801 | |||
| 1ddb46a894 | |||
| 54f75ec765 | |||
| d7bd8b5138 | |||
| e679f4bef7 | |||
| a104e9a293 | |||
| ffc9e84eda | |||
| f34665e1ff | |||
| d6342dd340 | |||
| 23e93865a1 | |||
| 8ce8cc5fbd | |||
|
|
59d17c054d | ||
| 23ce20b6c8 | |||
| b89c999f5f | |||
| 50ce645c6d | |||
| 7c80b4fe48 | |||
| 5b3bd4447d | |||
| 1bbb4aa6c1 | |||
| 750952af7b | |||
| ef400a6bef | |||
| 95d37de264 | |||
| aa9398ecb5 | |||
| 272973a3ed | |||
| c399c9186c | |||
| f8e417a8bb | |||
| 96f0721499 | |||
| 64fa627751 | |||
| b4f19f4a23 | |||
| 28c269c98d | |||
| 10c527966d | |||
| 976ff956ce | |||
| 5bf65cdf2b | |||
| 26c94742ae | |||
| 0d207fdb0c | |||
|
|
3c981366b6 | ||
| 049f201130 | |||
| 2b82537a21 | |||
| eddab7443e | |||
| 638252e082 | |||
| 956d7be62b | |||
| d38b1fec14 | |||
| ba51b204a4 | |||
| 5e118fb35e | |||
| 4ed61fc34a | |||
| b479b929ec | |||
| 52de130b4a | |||
| 13061e392a | |||
| c140c94a98 | |||
| 3c1b887fc8 | |||
| 6d443dbdc6 | |||
| 50b3a9d46d | |||
| ff6a89bead | |||
| 07e86511c5 | |||
| dcb64cc04b | |||
| c420790a4e | |||
| 8be0f7dbc2 | |||
| 6dc77a9dca | |||
| 710f771fb9 | |||
| 998bf9428a | |||
| 50f52e5e23 | |||
| f2a7a538ff | |||
| 0d321a4864 | |||
| df2f7bce39 | |||
| ecf703c938 | |||
| 592ce843a5 | |||
| 303593d886 | |||
| 4ffc8e4ea6 | |||
| 9c7b06f78d | |||
| 9ecf48108d | |||
| 1db752520e | |||
| b63c1c691b | |||
| c021cf7ef7 | |||
| 13f9b3830c | |||
| b2c289aee3 | |||
| 3176a9c92a | |||
| f41889854d | |||
| c748bd7f9a | |||
| 4752c35680 | |||
| 5dd093f13f | |||
| 45353f5fb2 | |||
| 799bd202f5 | |||
| fd80464945 | |||
| fc5fcc4185 | |||
| e1ae00b104 | |||
| 4770aac82a | |||
| 8f9b7aebab | |||
| c21fcba11a | |||
| dda8324d8f | |||
| 5d8d6159d5 | |||
| 3d31bd7f6e | |||
| 907418eb7f | |||
| 809f619ee8 | |||
| 668223937a | |||
| 0cca217e17 | |||
| 1a831f97d1 | |||
| 7967f8fec9 | |||
| 70a742c89c | |||
| 1ae337b223 | |||
| 358f5bf0cc | |||
| f7d48608b8 | |||
| 0ccbc331e8 | |||
| af58f48071 | |||
| 6fd3e765b7 | |||
| 621be852b6 | |||
| 54e2db8955 | |||
| 42beecfb21 | |||
|
|
5e4655a608 | ||
|
|
105c49f7f5 | ||
| 4480a433b8 | |||
| 5048e3a264 | |||
|
|
2807898ec5 | ||
| e889cd5c86 | |||
| 130ffcde8d | |||
| 22dc196dc0 | |||
|
|
bc5b64e9bb | ||
|
|
10df513e78 | ||
|
|
8cf2e14ffa | ||
|
|
6c45266da1 | ||
| dd2a5caa43 | |||
| c5f276fc0c | |||
| 65919f08c7 | |||
| fa4f6c0c52 | |||
| a04c0b52ba | |||
| 72adf64aa7 | |||
| d9acb2dd04 | |||
| 2b7769e01a | |||
| e70e8c762b | |||
| 3b25eb51fd | |||
|
|
2b68fbcce2 | ||
|
|
547a112648 | ||
|
|
b93513b084 | ||
|
|
db930c86c0 | ||
|
|
521ef95ed8 | ||
|
|
65a40645d4 | ||
|
|
d8b138793e | ||
|
|
87b463842c | ||
|
|
2f24412251 | ||
|
|
273b09e726 | ||
| aaeda43cc6 | |||
| c1b813fd83 | |||
| 233f407d1c | |||
| 8e9bd6655d | |||
| 6b83b8b77a | |||
| 17ea544346 | |||
| 2b9a299668 | |||
| 63fcc89442 | |||
| 9f782de92e | |||
| d9f4b19f69 | |||
| a78cf23c95 | |||
| 0f6ff9111a | |||
| 164ef2595c | |||
| ee5bdcd65f | |||
| b2fbb8e4eb | |||
|
|
5e0eb6efcb | ||
| 2db48a9dfb | |||
| 6194e7ee6a | |||
| 88cf0a69c6 | |||
| 424796c3f4 | |||
| a06e6d3e80 | |||
| 0b49d82b0c | |||
|
|
b61c8f9e43 | ||
| 7f83e0918b | |||
|
|
a560d129b7 | ||
|
|
2ebedaf2ff | ||
| 7a5ee5a76a | |||
|
|
ed07260999 | ||
|
|
e523402a04 | ||
|
|
623f64531a | ||
| 64a4d412b4 | |||
| 7faf4862b2 | |||
| 4a69b291ac | |||
| 0421376817 | |||
| 720a9765ef | |||
| 01b171d711 | |||
| facf3fb416 | |||
| 22447958aa | |||
| d51db1c9b9 | |||
| 2b2455ec54 | |||
| 5bad4d966f | |||
| d9956d3de0 | |||
|
|
ff12c75d88 | ||
| 6e7a0e6de8 | |||
| 3b39a31cb7 | |||
|
|
c163a6097f | ||
|
|
8f171d3dd2 | ||
|
|
fe82b53ca2 | ||
| 4ad6116189 | |||
|
|
12a12ffad6 | ||
|
|
8b0d79710d | ||
|
|
a115589109 | ||
|
|
1eb715d1d6 | ||
|
|
41ace3062f | ||
| 3e7ba6318d | |||
|
|
a58f05fdda | ||
|
|
9dfdedeeec | ||
|
|
4793c298ee | ||
|
|
04f465c369 | ||
|
|
e62c538328 | ||
|
|
be5711935c | ||
|
|
155f950ff8 | ||
| f8de5fc2d3 | |||
| f4a3bf6499 | |||
| 80b977c4b4 | |||
| 4ce5e3a80b | |||
| 8984160f0c | |||
| eedd95f08c | |||
| 84f2b83b45 | |||
| 0d8b8a39b4 | |||
| f7da84a143 | |||
| cd45bd38a8 | |||
| 6a5b7af21c | |||
| 877e16604e | |||
| 7f4f16c197 | |||
| bf0c3728d0 | |||
| 39ed806b09 | |||
| 37b07cb30a | |||
| d82f776b38 | |||
| 1bbcda8018 | |||
| 3a7413706b | |||
| 5829e794a2 | |||
| e5b8069048 | |||
| 2f70ced11f | |||
| 47d971e78b | |||
| 055538b5f9 | |||
| 6cbfad1cd4 | |||
| 0ff5103523 | |||
| 268398cb6a | |||
| f8fad63c35 | |||
| 54bd519bb6 | |||
| 560dec476c | |||
| e4068b2db9 | |||
| 3ac49ba4af | |||
| 031498d423 | |||
| 07d63f54eb | |||
| eb8cedda06 | |||
| 9a290527ba | |||
| f92cbe0bbd | |||
| de65e8c98e | |||
| 6e2596734d | |||
| d8d99875c2 | |||
| 5f575d648d | |||
| 8033f69fe7 | |||
| 83b25dcd4a | |||
| b9245e0061 | |||
| db3a9bc011 | |||
| fe6ee006f0 | |||
| efbf02a3b0 | |||
| 903af6eafc | |||
| 3f29a1ed20 | |||
| b5c39659ba | |||
| f6659be48a | |||
| 5c0b3da27a | |||
| c396de9310 | |||
| 2dcc967255 | |||
| aad41d130d | |||
| dfec1e9d3f | |||
| 3c3bec4eaf | |||
| f60562926f | |||
| cbf6ad96a7 | |||
| e8a889b99a | |||
| 691bacc165 | |||
| 68d1c5e0aa | |||
| 6f0c30b5d0 | |||
| 73cad93054 | |||
| 1d32f45c78 | |||
| 447188e7a3 | |||
| f92e481b4e | |||
| 117d3801cd | |||
| 595ab125b4 | |||
| 8e95e5dc15 | |||
| 041b6a3a7c | |||
| 085567be66 | |||
| 81240f5047 | |||
| a20e0a82e8 | |||
| cf74619a4c | |||
| 18edeb5b13 | |||
| 762add7fca | |||
| 135a05859c | |||
| ca5d248dfe | |||
| 4ff066d57d | |||
| df2e21829d | |||
| e17b44b4ff | |||
| eaa5e2bd90 | |||
| 267d73071f | |||
| 465fd8930c | |||
| 4b929dd7a3 | |||
| 47cfc63136 | |||
| 67efd1a11a | |||
| e2c8af04d4 | |||
| 0c118a2114 | |||
| 1fd1ee61c1 | |||
| 47e8be8ab7 | |||
| 6000b4c449 | |||
| 0748934663 | |||
| 5e416dc9d6 | |||
| 272124212a | |||
| f3fe41065e | |||
| 7219a645d7 | |||
| 22689d1c43 | |||
| 6f91b63aec | |||
| 2c55fb299b | |||
| 84925f2cc7 | |||
| e6c3221a8c | |||
| c22dca0e57 | |||
| b70c0fd102 | |||
| 533966ff8b | |||
| 699b105043 | |||
| e20c88d6b6 | |||
| 3021cbd870 | |||
| 02a3c5daf1 | |||
| fa293193db | |||
| a0ec18ff6d | |||
| 0e89ae83e5 | |||
| b3ef68dedc | |||
| 870ab93230 | |||
| 3d4b81d000 | |||
| aaaaaba58c | |||
| 3e53ea4141 | |||
| b076fb478e | |||
| d824b2df95 | |||
| 719c75b91e | |||
| ac3d427b48 | |||
| 0ca6b01104 | |||
| b784548a9a | |||
| c6f36d62a2 | |||
| 4357a49812 | |||
| f99f86a26b | |||
| 5c8f285073 | |||
| e605349548 | |||
| 580e65a41f | |||
| 01d31e604b | |||
| 54dfd4f13b | |||
| bf65bffcf0 | |||
| 7237b12431 | |||
| 42762e98ae | |||
| 7b1059cfe4 | |||
| 7335517cdd | |||
| 8f5f651a15 | |||
| 713a12073c | |||
| e0b2175c55 | |||
| fc3d7b8591 | |||
| dd2d16e782 | |||
| 677535c473 | |||
| a56375bdb7 | |||
| 8d45d45699 | |||
| a84b605d22 | |||
| 5a9a85c955 | |||
| c16ef7c55e | |||
| 3e8f0430ca | |||
| a657ade1a7 | |||
| f38508fbe7 | |||
| d98644b629 | |||
| be19a2a536 | |||
| 7640a8b33e | |||
| cf00ceb288 | |||
| 230d0e7964 | |||
| 6f4dddfcd8 | |||
| 0302995691 | |||
| 6510ccfec8 | |||
| 68e4c1a928 | |||
| 1a9ee0e76e | |||
| 015707f6d4 | |||
| be7aca7e9d | |||
| 9055b752d9 | |||
| 7815350430 | |||
| f7140b8e0c | |||
| 6a01ee6a70 | |||
| 9eb37f4d1d | |||
| 5e225bf8c3 | |||
| bdd7cb9bed | |||
| 808140813b | |||
| 7b59ae37dc | |||
| 2526c08025 | |||
| 23a7dd3fbf | |||
| 088bb0c04a | |||
| d9999a8076 | |||
| 21c57dc6fe | |||
| 36e9c2af90 | |||
| 7fc277efb1 | |||
| 3549352583 | |||
| 0ac50a685b | |||
| efed7d8da5 | |||
| b56e2bbdeb | |||
| 5021171c43 | |||
| 78022c4a42 | |||
| b7504d0ba6 | |||
| b96a3b3211 | |||
| 6cd4f58d80 | |||
| b5548e7e9d | |||
| 32c2ed46be | |||
| 97eda280ac | |||
| d90237b933 | |||
| c073fb7d69 | |||
| 184d7ea4d7 |
@@ -16,7 +16,7 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: adguard-home
|
||||
image: adguard/adguardhome:v0.107.51
|
||||
image: adguard/adguardhome:v0.107.52
|
||||
ports:
|
||||
- protocol: TCP
|
||||
containerPort: 53
|
||||
|
||||
@@ -3,12 +3,15 @@ kind: Service
|
||||
metadata:
|
||||
name: adguard-home
|
||||
namespace: adguard-home
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
labels:
|
||||
app.kubernetes.io/name: adguard-home
|
||||
spec:
|
||||
selector:
|
||||
app.kubernetes.io/name: adguard-home
|
||||
type: ClusterIP
|
||||
type: LoadBalancer
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- protocol: TCP
|
||||
@@ -32,11 +35,11 @@ spec:
|
||||
targetPort: 80
|
||||
name: http-tcp
|
||||
- protocol: TCP
|
||||
port: 443
|
||||
port: 10443
|
||||
targetPort: 443
|
||||
name: https-tcp
|
||||
- protocol: UDP
|
||||
port: 443
|
||||
port: 10443
|
||||
targetPort: 443
|
||||
name: https-udp
|
||||
- protocol: TCP
|
||||
|
||||
61
apps/adguard-home/env/k3s-cluster/ingress.yaml
vendored
61
apps/adguard-home/env/k3s-cluster/ingress.yaml
vendored
@@ -1,61 +0,0 @@
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: adguard-home-ingress
|
||||
namespace: adguard-home
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "false"
|
||||
nginx.ingress.kubernetes.io/use-regex: "true"
|
||||
spec:
|
||||
ingressClassName: nginx
|
||||
rules:
|
||||
- host: "adguard-home.cluster.edward.sydney"
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: adguard-home
|
||||
port:
|
||||
number: 10080
|
||||
- host: "adguard-home.cluster.local"
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: adguard-home
|
||||
port:
|
||||
number: 10080
|
||||
- host: "setup.adguard-home.cluster.edward.sydney"
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: adguard-home
|
||||
port:
|
||||
number: 13000
|
||||
- host: "setup.adguard-home.cluster.local"
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: adguard-home
|
||||
port:
|
||||
number: 13000
|
||||
- host: "doh.adguard-home.cluster.edward.sydney"
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: adguard-home
|
||||
port:
|
||||
number: 443
|
||||
@@ -1,5 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
- ./ingress.yaml
|
||||
- ../../base
|
||||
12
apps/chartmuseum/env/k3s-cluster/config.json
vendored
Normal file
12
apps/chartmuseum/env/k3s-cluster/config.json
vendored
Normal file
@@ -0,0 +1,12 @@
|
||||
{
|
||||
"appName": "chartmuseum",
|
||||
"userGivenName": "chartmuseum",
|
||||
"namespace": "chartmuseum",
|
||||
"destNamespace": "chartmuseum",
|
||||
"destServer": "https://kubernetes.default.svc",
|
||||
"srcPath": "apps/chartmuseum/env/k3s-cluster",
|
||||
"srcRepoURL": "https://github.com/3dwardch3ng/home-cluster-ops.git",
|
||||
"srcTargetRevision": "",
|
||||
"labels": null,
|
||||
"annotations": null
|
||||
}
|
||||
8
apps/chartmuseum/env/k3s-cluster/kustomization.yaml
vendored
Normal file
8
apps/chartmuseum/env/k3s-cluster/kustomization.yaml
vendored
Normal file
@@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
helmCharts:
|
||||
- name: chartmuseum
|
||||
repo: https://chartmuseum.github.io/charts
|
||||
version: 3.10.3
|
||||
releaseName: chartmuseum
|
||||
valuesFile: values.yaml
|
||||
24
apps/chartmuseum/env/k3s-cluster/values.yaml
vendored
Normal file
24
apps/chartmuseum/env/k3s-cluster/values.yaml
vendored
Normal file
@@ -0,0 +1,24 @@
|
||||
env:
|
||||
open:
|
||||
AUTH_ANONYMOUS_GET: true
|
||||
DISABLE_API: false
|
||||
CACHE: redis
|
||||
CACHE_REDIS_ADDR: redis-master.redis.svc.cluster.local:6379
|
||||
existingSecret: chartmuseum-secrets
|
||||
existingSecretMappings:
|
||||
BASIC_AUTH_USER: auth-user
|
||||
BASIC_AUTH_PASS: auth-password
|
||||
CACHE_REDIS_PASSWORD: redis-password
|
||||
service:
|
||||
type: LoadBalancer
|
||||
externalPort: 8899
|
||||
persistence:
|
||||
enabled: true
|
||||
existingClaim: chartmuseum-pvc
|
||||
ingress:
|
||||
enabled: true
|
||||
hosts:
|
||||
- name: chartmuseum.cluster.edward.sydney
|
||||
tls: true
|
||||
tlsSecret: chartmuseum-tls
|
||||
ingressClassName: nginx
|
||||
@@ -3,6 +3,6 @@ kind: Kustomization
|
||||
helmCharts:
|
||||
- name: coder
|
||||
repo: https://helm.coder.com/v2
|
||||
version: 2.13.1
|
||||
version: 2.15.0
|
||||
releaseName: coder
|
||||
valuesFile: values.yaml
|
||||
10
apps/coder/env/k3s-cluster/values.yaml
vendored
10
apps/coder/env/k3s-cluster/values.yaml
vendored
@@ -18,5 +18,11 @@ coder:
|
||||
- name: coder-data
|
||||
mountPath: /config
|
||||
service:
|
||||
type: NodePort
|
||||
httpNodePort: 31180
|
||||
type: ClusterIP
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
ingress:
|
||||
enable: true
|
||||
className: nginx
|
||||
host: "coder.cluster.edward.sydney"
|
||||
12
apps/ec-config-server/env/k3s-cluster/config.json
vendored
Normal file
12
apps/ec-config-server/env/k3s-cluster/config.json
vendored
Normal file
@@ -0,0 +1,12 @@
|
||||
{
|
||||
"appName": "ec-config-server",
|
||||
"userGivenName": "ec-config-server",
|
||||
"namespace": "ec-proj",
|
||||
"destNamespace": "ec-proj",
|
||||
"destServer": "https://kubernetes.default.svc",
|
||||
"srcPath": "apps/ec-config-server/env/k3s-cluster",
|
||||
"srcRepoURL": "https://github.com/3dwardch3ng/home-cluster-ops.git",
|
||||
"srcTargetRevision": "",
|
||||
"labels": null,
|
||||
"annotations": null
|
||||
}
|
||||
8
apps/ec-config-server/env/k3s-cluster/kustomization.yaml
vendored
Normal file
8
apps/ec-config-server/env/k3s-cluster/kustomization.yaml
vendored
Normal file
@@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
helmCharts:
|
||||
- name: ec-config-server
|
||||
repo: https://chartmuseum.cluster.edward.sydney:8899/
|
||||
version: 1.0.12
|
||||
releaseName: ec-config-server
|
||||
valuesFile: values.yaml
|
||||
9
apps/ec-config-server/env/k3s-cluster/values.yaml
vendored
Normal file
9
apps/ec-config-server/env/k3s-cluster/values.yaml
vendored
Normal file
@@ -0,0 +1,9 @@
|
||||
environment:
|
||||
configServerAuth:
|
||||
existingSecret: ec-config-server-auth-secrets
|
||||
service:
|
||||
type: LoadBalancer
|
||||
spring:
|
||||
activeprofile: native,k3s
|
||||
persistence:
|
||||
hostPath: /mnt/nfs/AppData/ec-config-server/config
|
||||
@@ -3,6 +3,6 @@ kind: Kustomization
|
||||
helmCharts:
|
||||
- name: gitea
|
||||
repo: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 2.3.14
|
||||
version: 2.3.22
|
||||
releaseName: gitea
|
||||
valuesFile: values.yaml
|
||||
24
apps/gitea/env/k3s-cluster/values.yaml
vendored
24
apps/gitea/env/k3s-cluster/values.yaml
vendored
@@ -1,4 +1,7 @@
|
||||
namespaceOverride: "gitea"
|
||||
rootURL: "https://gitea.cluster.edward.sydney"
|
||||
updateStrategy:
|
||||
type: Recreate
|
||||
podAntiAffinityPreset: ""
|
||||
adminUsername: "gitea_admin"
|
||||
adminEmail: "edward@cheng.sydney"
|
||||
@@ -11,12 +14,21 @@ smtpUser: "me@edward.sydney"
|
||||
smtpExistingSecret: "gitea-secrets"
|
||||
persistence:
|
||||
existingClaim: "gitea-pvc"
|
||||
resourcesPreset: "xlarge"
|
||||
podSecurityContext:
|
||||
fsGroup: 1000
|
||||
containerSecurityContext:
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
service:
|
||||
ports:
|
||||
http: 10080
|
||||
ssh: 10022
|
||||
http: 10880
|
||||
ssh: 10222
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
ingress:
|
||||
enabled: true
|
||||
enabled: false
|
||||
ingressClassName: "nginx"
|
||||
hostname: "gitea.cluster.edward.sydney"
|
||||
serviceAccount:
|
||||
@@ -27,4 +39,8 @@ externalDatabase:
|
||||
host: "postgresql-primary.argocd.svc.cluster.local"
|
||||
user: "gitea_user"
|
||||
existingSecret: "gitea-secrets"
|
||||
existingSecretPasswordKey: "db-password"
|
||||
existingSecretPasswordKey: "db-password"
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
kubernetes.io/arch: amd64
|
||||
kubernetes.io/hostname: k3s-cluster-node-y
|
||||
62
apps/gitlab/env/k3s-cluster/deployment.yaml
vendored
62
apps/gitlab/env/k3s-cluster/deployment.yaml
vendored
@@ -1,62 +0,0 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: gitlab
|
||||
namespace: gitlab
|
||||
labels:
|
||||
app.kubernetes.io/name: gitlab
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: gitlab
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: gitlab
|
||||
spec:
|
||||
containers:
|
||||
- name: gitlab
|
||||
image: gitlab/gitlab-ce:17.2.1-ce.0
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
env:
|
||||
- name: GITLAB_OMNIBUS_CONFIG
|
||||
value: "external_url 'https://gitlab.cluster.edward.sydney'"
|
||||
ports:
|
||||
- protocol: TCP
|
||||
containerPort: 443
|
||||
name: https
|
||||
- protocol: TCP
|
||||
containerPort: 80
|
||||
name: http
|
||||
- protocol: TCP
|
||||
containerPort: 22
|
||||
name: ssh
|
||||
volumeMounts:
|
||||
- name: dshm
|
||||
mountPath: /dev/shm
|
||||
- name: gitlab-config
|
||||
mountPath: /etc/config
|
||||
- name: gitlab-log
|
||||
mountPath: /var/log/gitlab
|
||||
- name: gitlab-data
|
||||
mountPath: /var/opt/gitlab
|
||||
volumes:
|
||||
- name: dshm
|
||||
emptyDir:
|
||||
medium: Memory
|
||||
sizeLimit: 1Gi
|
||||
- name: gitlab-config
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/gitlab/config
|
||||
type: Directory
|
||||
- name: gitlab-log
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/gitlab/log
|
||||
type: Directory
|
||||
- name: gitlab-data
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/gitlab/data
|
||||
type: Directory
|
||||
nodeSelector:
|
||||
kubernetes.io/arch: amd64
|
||||
25
apps/gitlab/env/k3s-cluster/service.yaml
vendored
25
apps/gitlab/env/k3s-cluster/service.yaml
vendored
@@ -1,25 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: gitlab
|
||||
namespace: gitlab
|
||||
labels:
|
||||
app.kubernetes.io/name: gitlab
|
||||
spec:
|
||||
selector:
|
||||
app.kubernetes.io/name: gitlab
|
||||
type: LoadBalancer
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 10080
|
||||
targetPort: 80
|
||||
name: http
|
||||
- protocol: TCP
|
||||
port: 10443
|
||||
targetPort: 443
|
||||
name: https
|
||||
- protocol: TCP
|
||||
port: 10022
|
||||
targetPort: 22
|
||||
name: ssh
|
||||
@@ -32,10 +32,12 @@ spec:
|
||||
containerPort: 8088
|
||||
name: http
|
||||
volumeMounts:
|
||||
- name: assets
|
||||
mountPath: /www/assets
|
||||
- name: www
|
||||
mountPath: /www
|
||||
volumes:
|
||||
- name: assets
|
||||
- name: www
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/homer/www/assets
|
||||
path: /mnt/nfs/AppData/homer/www
|
||||
type: Directory
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
|
||||
@@ -3,12 +3,15 @@ kind: Service
|
||||
metadata:
|
||||
name: homer
|
||||
namespace: homer
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
labels:
|
||||
app.kubernetes.io/name: homer
|
||||
spec:
|
||||
selector:
|
||||
app.kubernetes.io/name: homer
|
||||
type: ClusterIP
|
||||
type: LoadBalancer
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- protocol: TCP
|
||||
|
||||
@@ -1,5 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
- ./ingress.yaml
|
||||
- ../../base
|
||||
8
apps/jellyfin/base/kustomization.yaml
Normal file
8
apps/jellyfin/base/kustomization.yaml
Normal file
@@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
helmCharts:
|
||||
- name: jellyfin
|
||||
repo: https://beluga-cloud.github.io/charts
|
||||
version: 2.3.0
|
||||
releaseName: jellyfin
|
||||
valuesFile: values.yaml
|
||||
155
apps/jellyfin/base/values.yaml
Normal file
155
apps/jellyfin/base/values.yaml
Normal file
@@ -0,0 +1,155 @@
|
||||
podSecurityContext:
|
||||
runAsGroup: 1000
|
||||
runAsUser: 1000
|
||||
fsGroup: 1000
|
||||
containerSecurityContext:
|
||||
runAsGroup: 1000
|
||||
runAsUser: 1000
|
||||
persistence:
|
||||
config:
|
||||
enabled: true
|
||||
volumeClaimSpec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
volumeName: jellyfin-config
|
||||
storageClassName: local-path
|
||||
data:
|
||||
enabled: true
|
||||
volumeClaimSpec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
volumeName: jellyfin-data
|
||||
storageClassName: local-path
|
||||
jellyfin:
|
||||
mediaVolumes:
|
||||
- name: movies
|
||||
readOnly: false
|
||||
volumeSpec:
|
||||
storageClassName: local-path
|
||||
volumeMode: Filesystem
|
||||
capacity:
|
||||
storage: 256Gi
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
nodeAffinity:
|
||||
required:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
claimRef:
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
name: jellyfin-mediavol-movies
|
||||
namespace: jellyfin
|
||||
hostPath:
|
||||
path: "/mnt/nfs/media/movie"
|
||||
type: "Directory"
|
||||
- name: series
|
||||
readOnly: false
|
||||
volumeSpec:
|
||||
storageClassName: local-path
|
||||
volumeMode: Filesystem
|
||||
capacity:
|
||||
storage: 256Gi
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
nodeAffinity:
|
||||
required:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
claimRef:
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
name: jellyfin-mediavol-series
|
||||
namespace: jellyfin
|
||||
hostPath:
|
||||
path: "/mnt/nfs/media/tv"
|
||||
type: "Directory"
|
||||
- name: music-videos
|
||||
readOnly: false
|
||||
volumeSpec:
|
||||
storageClassName: local-path
|
||||
volumeMode: Filesystem
|
||||
capacity:
|
||||
storage: 128Gi
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
nodeAffinity:
|
||||
required:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
claimRef:
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
name: jellyfin-mediavol-music-videos
|
||||
namespace: jellyfin
|
||||
hostPath:
|
||||
path: "/mnt/nfs/media/music-video"
|
||||
type: "Directory"
|
||||
- name: short-videos
|
||||
readOnly: false
|
||||
volumeSpec:
|
||||
storageClassName: local-path
|
||||
volumeMode: Filesystem
|
||||
capacity:
|
||||
storage: 32Gi
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
nodeAffinity:
|
||||
required:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
claimRef:
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
name: jellyfin-mediavol-short-videos
|
||||
namespace: jellyfin
|
||||
hostPath:
|
||||
path: "/mnt/nfs/media/short-video"
|
||||
type: "Directory"
|
||||
- name: gv
|
||||
readOnly: false
|
||||
volumeSpec:
|
||||
storageClassName: local-path
|
||||
volumeMode: Filesystem
|
||||
capacity:
|
||||
storage: 64Gi
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
nodeAffinity:
|
||||
required:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
claimRef:
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
name: jellyfin-mediavol-gv
|
||||
namespace: jellyfin
|
||||
hostPath:
|
||||
path: "/mnt/nfs/media/gv"
|
||||
type: "Directory"
|
||||
persistentTranscodes: true
|
||||
12
apps/jellyfin/env/k3s-cluster/config.json
vendored
Normal file
12
apps/jellyfin/env/k3s-cluster/config.json
vendored
Normal file
@@ -0,0 +1,12 @@
|
||||
{
|
||||
"appName": "jellyfin",
|
||||
"userGivenName": "jellyfin",
|
||||
"namespace": "jellyfin",
|
||||
"destNamespace": "jellyfin",
|
||||
"destServer": "https://kubernetes.default.svc",
|
||||
"srcPath": "apps/jellyfin/env/k3s-cluster",
|
||||
"srcRepoURL": "https://github.com/3dwardch3ng/home-cluster-ops.git",
|
||||
"srcTargetRevision": "",
|
||||
"labels": null,
|
||||
"annotations": null
|
||||
}
|
||||
@@ -1,21 +1,21 @@
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: trillium-ingress
|
||||
namespace: trillium
|
||||
name: jellyfin-ingress
|
||||
namespace: jellyfin
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "false"
|
||||
nginx.ingress.kubernetes.io/use-regex: "true"
|
||||
spec:
|
||||
ingressClassName: nginx
|
||||
rules:
|
||||
- host: "trillium.cluster.edward.sydney"
|
||||
- host: "jellyfin.cluster.edward.sydney"
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: trillium
|
||||
name: jellyfin
|
||||
port:
|
||||
number: 8080
|
||||
number: 8096
|
||||
5
apps/jellyfin/env/k3s-cluster/kustomization.yaml
vendored
Normal file
5
apps/jellyfin/env/k3s-cluster/kustomization.yaml
vendored
Normal file
@@ -0,0 +1,5 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
# - ./ingress.yaml
|
||||
@@ -20,7 +20,7 @@ spec:
|
||||
app.kubernetes.io/instance: kavita
|
||||
spec:
|
||||
containers:
|
||||
- image: jvmilazz0/kavita:0.8.1
|
||||
- image: jvmilazz0/kavita:0.8.3
|
||||
imagePullPolicy: IfNotPresent
|
||||
name: kavita
|
||||
ports:
|
||||
|
||||
@@ -3,6 +3,6 @@ kind: Kustomization
|
||||
helmCharts:
|
||||
- name: kubernetes-dashboard
|
||||
repo: https://kubernetes.github.io/dashboard/
|
||||
version: 7.5.0
|
||||
version: 7.6.1
|
||||
releaseName: kubernetes-dashboard
|
||||
valuesFile: values.yaml
|
||||
@@ -22,10 +22,10 @@ spec:
|
||||
resources:
|
||||
limits:
|
||||
memory: "3Gi"
|
||||
cpu: "1"
|
||||
cpu: "2"
|
||||
requests:
|
||||
memory: "2Gi"
|
||||
cpu: "500m"
|
||||
cpu: "2"
|
||||
ports:
|
||||
- containerPort: 8081
|
||||
volumeMounts:
|
||||
@@ -35,4 +35,7 @@ spec:
|
||||
- name: nexus-data
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/nexus
|
||||
type: Directory
|
||||
type: Directory
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
kubernetes.io/arch: arm64
|
||||
@@ -10,8 +10,7 @@ metadata:
|
||||
spec:
|
||||
selector:
|
||||
app: nexus
|
||||
type: NodePort
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- port: 8081
|
||||
targetPort: 8081
|
||||
nodePort: 32000
|
||||
targetPort: 8081
|
||||
@@ -1,21 +1,21 @@
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: homer-ingress
|
||||
namespace: homer
|
||||
name: nexus-ingress
|
||||
namespace: nexus
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "false"
|
||||
nginx.ingress.kubernetes.io/use-regex: "true"
|
||||
spec:
|
||||
ingressClassName: nginx
|
||||
rules:
|
||||
- host: "home.edward.sydney"
|
||||
- host: "nexus.cluster.edward.sydney"
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: homer
|
||||
name: nexus
|
||||
port:
|
||||
number: 8088
|
||||
number: 8081
|
||||
28
apps/plane/base/configmap.yaml
Normal file
28
apps/plane/base/configmap.yaml
Normal file
@@ -0,0 +1,28 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-app-vars
|
||||
data:
|
||||
SENTRY_DSN: ""
|
||||
SENTRY_ENVIRONMENT: ""
|
||||
DEBUG: "0"
|
||||
DOCKERIZED: "1"
|
||||
GUNICORN_WORKERS: "1"
|
||||
WEB_URL: "http://plane.cluster.edward.sydney"
|
||||
CORS_ALLOWED_ORIGINS: "http://plane.cluster.edward.sydney,https://plane.cluster.edward.sydney"
|
||||
REDIS_URL: "redis://plane-redis.plane.svc.cluster.local:6379/"
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-doc-store-vars
|
||||
data:
|
||||
FILE_SIZE_LIMIT: "5242880"
|
||||
AWS_S3_BUCKET_NAME: "plane"
|
||||
MINIO_ROOT_USER: "admin"
|
||||
AWS_S3_ENDPOINT_URL: "http://minio.minio.svc.cluster.local:19000"
|
||||
USE_MINIO: "1"
|
||||
---
|
||||
274
apps/plane/base/deployment.yaml
Normal file
274
apps/plane/base/deployment.yaml
Normal file
@@ -0,0 +1,274 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-admin-wl
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app.name: plane-admin
|
||||
template:
|
||||
metadata:
|
||||
namespace: plane
|
||||
labels:
|
||||
app.name: plane-admin
|
||||
spec:
|
||||
containers:
|
||||
- name: plane-admin
|
||||
imagePullPolicy: Always
|
||||
image: makeplane/plane-admin:stable
|
||||
stdin: true
|
||||
tty: true
|
||||
resources:
|
||||
requests:
|
||||
memory: "50Mi"
|
||||
cpu: "50m"
|
||||
limits:
|
||||
memory: "1000Mi"
|
||||
cpu: "500m"
|
||||
command:
|
||||
- node
|
||||
args:
|
||||
- admin/server.js
|
||||
- admin
|
||||
serviceAccount: plane-srv-account
|
||||
serviceAccountName: plane-srv-account
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-api-wl
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app.name: plane-api
|
||||
template:
|
||||
metadata:
|
||||
namespace: plane
|
||||
labels:
|
||||
app.name: plane-api
|
||||
spec:
|
||||
containers:
|
||||
- name: plane-api
|
||||
imagePullPolicy: Always
|
||||
image: makeplane/plane-backend:stable
|
||||
stdin: true
|
||||
tty: true
|
||||
resources:
|
||||
requests:
|
||||
memory: "50Mi"
|
||||
cpu: "50m"
|
||||
limits:
|
||||
memory: "1000Mi"
|
||||
cpu: "500m"
|
||||
command:
|
||||
- ./bin/docker-entrypoint-api.sh
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: plane-app-vars
|
||||
optional: false
|
||||
- secretRef:
|
||||
name: plane-app-secrets
|
||||
optional: false
|
||||
- configMapRef:
|
||||
name: plane-doc-store-vars
|
||||
optional: false
|
||||
- secretRef:
|
||||
name: plane-doc-store-secrets
|
||||
optional: false
|
||||
readinessProbe:
|
||||
failureThreshold: 30
|
||||
httpGet:
|
||||
path: /
|
||||
port: 8000
|
||||
scheme: HTTP
|
||||
periodSeconds: 10
|
||||
successThreshold: 1
|
||||
timeoutSeconds: 1
|
||||
serviceAccount: plane-srv-account
|
||||
serviceAccountName: plane-srv-account
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-beat-worker-wl
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app.name: plane-beat-worker
|
||||
template:
|
||||
metadata:
|
||||
namespace: plane
|
||||
labels:
|
||||
app.name: plane-beat-worker
|
||||
spec:
|
||||
containers:
|
||||
- name: plane-beat-worker
|
||||
imagePullPolicy: Always
|
||||
image: makeplane/plane-backend:stable
|
||||
stdin: true
|
||||
tty: true
|
||||
resources:
|
||||
requests:
|
||||
memory: "50Mi"
|
||||
cpu: "50m"
|
||||
limits:
|
||||
memory: "1000Mi"
|
||||
cpu: "500m"
|
||||
command:
|
||||
- ./bin/docker-entrypoint-beat.sh
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: plane-app-vars
|
||||
optional: false
|
||||
- secretRef:
|
||||
name: plane-app-secrets
|
||||
optional: false
|
||||
- configMapRef:
|
||||
name: plane-doc-store-vars
|
||||
optional: false
|
||||
- secretRef:
|
||||
name: plane-doc-store-secrets
|
||||
optional: false
|
||||
serviceAccount: plane-srv-account
|
||||
serviceAccountName: plane-srv-account
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-space-wl
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app.name: plane-space
|
||||
template:
|
||||
metadata:
|
||||
namespace: plane
|
||||
labels:
|
||||
app.name: plane-space
|
||||
spec:
|
||||
containers:
|
||||
- name: plane-space
|
||||
imagePullPolicy: Always
|
||||
image: makeplane/plane-space:stable
|
||||
stdin: true
|
||||
tty: true
|
||||
resources:
|
||||
requests:
|
||||
memory: "50Mi"
|
||||
cpu: "50m"
|
||||
limits:
|
||||
memory: "1000Mi"
|
||||
cpu: "500m"
|
||||
command:
|
||||
- node
|
||||
args:
|
||||
- space/server.js
|
||||
- space
|
||||
serviceAccount: plane-srv-account
|
||||
serviceAccountName: plane-srv-account
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-web-wl
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app.name: plane-web
|
||||
template:
|
||||
metadata:
|
||||
namespace: plane
|
||||
labels:
|
||||
app.name: plane-web
|
||||
spec:
|
||||
containers:
|
||||
- name: plane-web
|
||||
imagePullPolicy: Always
|
||||
image: makeplane/plane-frontend:stable
|
||||
stdin: true
|
||||
tty: true
|
||||
resources:
|
||||
requests:
|
||||
memory: "50Mi"
|
||||
cpu: "50m"
|
||||
limits:
|
||||
memory: "1000Mi"
|
||||
cpu: "500m"
|
||||
command:
|
||||
- node
|
||||
args:
|
||||
- web/server.js
|
||||
- web
|
||||
serviceAccount: plane-srv-account
|
||||
serviceAccountName: plane-srv-account
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-worker-wl
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app.name: plane-worker
|
||||
template:
|
||||
metadata:
|
||||
namespace: plane
|
||||
labels:
|
||||
app.name: plane-worker
|
||||
spec:
|
||||
containers:
|
||||
- name: plane-worker
|
||||
imagePullPolicy: Always
|
||||
image: makeplane/plane-backend:stable
|
||||
stdin: true
|
||||
tty: true
|
||||
resources:
|
||||
requests:
|
||||
memory: "50Mi"
|
||||
cpu: "50m"
|
||||
limits:
|
||||
memory: "1000Mi"
|
||||
cpu: "500m"
|
||||
command:
|
||||
- ./bin/docker-entrypoint-worker.sh
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: plane-app-vars
|
||||
optional: false
|
||||
- secretRef:
|
||||
name: plane-app-secrets
|
||||
optional: false
|
||||
- configMapRef:
|
||||
name: plane-doc-store-vars
|
||||
optional: false
|
||||
- secretRef:
|
||||
name: plane-doc-store-secrets
|
||||
optional: false
|
||||
serviceAccount: plane-srv-account
|
||||
serviceAccountName: plane-srv-account
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
---
|
||||
35
apps/plane/base/job.yaml
Normal file
35
apps/plane/base/job.yaml
Normal file
@@ -0,0 +1,35 @@
|
||||
---
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-api-migrate
|
||||
spec:
|
||||
backoffLimit: 3
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app.name: plane-api-migrate
|
||||
spec:
|
||||
containers:
|
||||
- name: plane-api-migrate
|
||||
image: makeplane/plane-backend:stable
|
||||
command:
|
||||
- ./bin/docker-entrypoint-migrator.sh
|
||||
imagePullPolicy: Always
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: plane-app-vars
|
||||
optional: false
|
||||
- secretRef:
|
||||
name: plane-app-secrets
|
||||
optional: false
|
||||
- configMapRef:
|
||||
name: plane-doc-store-vars
|
||||
optional: false
|
||||
- secretRef:
|
||||
name: plane-doc-store-secrets
|
||||
optional: false
|
||||
restartPolicy: OnFailure
|
||||
serviceAccount: plane-srv-account
|
||||
serviceAccountName: plane-srv-account
|
||||
9
apps/plane/base/kustomization.yaml
Normal file
9
apps/plane/base/kustomization.yaml
Normal file
@@ -0,0 +1,9 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./configmap.yaml
|
||||
- ./service-account.yaml
|
||||
- ./job.yaml
|
||||
- ./deployment.yaml
|
||||
- ./stateful-set.yaml
|
||||
- ./service.yaml
|
||||
6
apps/plane/base/service-account.yaml
Normal file
6
apps/plane/base/service-account.yaml
Normal file
@@ -0,0 +1,6 @@
|
||||
apiVersion: v1
|
||||
automountServiceAccountToken: true
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-srv-account
|
||||
85
apps/plane/base/service.yaml
Normal file
85
apps/plane/base/service.yaml
Normal file
@@ -0,0 +1,85 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-admin
|
||||
labels:
|
||||
app.name: plane-admin
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- name: admin-3000
|
||||
port: 3333
|
||||
protocol: TCP
|
||||
targetPort: 3000
|
||||
selector:
|
||||
app.name: plane-admin
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-api
|
||||
labels:
|
||||
app.name: plane-api
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- name: api-8000
|
||||
port: 8808
|
||||
protocol: TCP
|
||||
targetPort: 8000
|
||||
selector:
|
||||
app.name: plane-api
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-space
|
||||
labels:
|
||||
app.name: plane-space
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- name: space-3000
|
||||
port: 3330
|
||||
protocol: TCP
|
||||
targetPort: 3000
|
||||
selector:
|
||||
app.name: plane-space
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-web
|
||||
labels:
|
||||
app.name: plane-web
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- name: web-3000
|
||||
port: 3033
|
||||
protocol: TCP
|
||||
targetPort: 3000
|
||||
selector:
|
||||
app.name: plane-web
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-redis
|
||||
labels:
|
||||
app.name: plane-redis
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- name: redis-6379
|
||||
port: 6379
|
||||
protocol: TCP
|
||||
targetPort: 6379
|
||||
selector:
|
||||
app.name: plane-redis
|
||||
32
apps/plane/base/stateful-set.yaml
Normal file
32
apps/plane/base/stateful-set.yaml
Normal file
@@ -0,0 +1,32 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
namespace: plane
|
||||
name: plane-redis-wl
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app.name: plane-redis
|
||||
serviceName: plane-redis
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app.name: plane-redis
|
||||
spec:
|
||||
containers:
|
||||
- image: valkey/valkey:8.0.0-alpine
|
||||
imagePullPolicy: Always
|
||||
name: plane-redis
|
||||
stdin: true
|
||||
tty: true
|
||||
volumeMounts:
|
||||
- mountPath: /data
|
||||
name: plane-redis-data
|
||||
volumes:
|
||||
- name: plane-redis-data
|
||||
persistentVolumeClaim:
|
||||
claimName: plane-redis-pvc
|
||||
serviceAccount: plane-srv-account
|
||||
serviceAccountName: plane-srv-account
|
||||
---
|
||||
12
apps/plane/env/k3s-cluster/config.json
vendored
Normal file
12
apps/plane/env/k3s-cluster/config.json
vendored
Normal file
@@ -0,0 +1,12 @@
|
||||
{
|
||||
"appName": "plane",
|
||||
"userGivenName": "plane",
|
||||
"namespace": "plane",
|
||||
"destNamespace": "plane",
|
||||
"destServer": "https://kubernetes.default.svc",
|
||||
"srcPath": "apps/plane/env/k3s-cluster",
|
||||
"srcRepoURL": "https://github.com/3dwardch3ng/home-cluster-ops.git",
|
||||
"srcTargetRevision": "",
|
||||
"labels": null,
|
||||
"annotations": null
|
||||
}
|
||||
4
apps/plane/env/k3s-cluster/kustomization.yaml
vendored
Normal file
4
apps/plane/env/k3s-cluster/kustomization.yaml
vendored
Normal file
@@ -0,0 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
@@ -8,29 +8,47 @@ extraEnv:
|
||||
PLEX_UID: 1000
|
||||
PLEX_GID: 1000
|
||||
ALLOWED_NETWORKS: "0.0.0.0/0"
|
||||
service:
|
||||
type: LoadBalancer
|
||||
port: 32400
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
extraVolumeMounts:
|
||||
- name: plex-tv
|
||||
mountPath: /tv
|
||||
- name: plex-movie
|
||||
mountPath: /movie
|
||||
- name: plex-short-video
|
||||
mountPath: /short-video
|
||||
- name: plex-music
|
||||
mountPath: /music
|
||||
- name: plex-music-video
|
||||
mountPath: /music-video
|
||||
- name: plex-gv
|
||||
mountPath: /gv
|
||||
extraVolumes:
|
||||
- name: plex-tv
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/plex/tv
|
||||
path: /mnt/nfs/media/tv
|
||||
type: Directory
|
||||
- name: plex-movie
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/plex/movie
|
||||
path: /mnt/nfs/media/movie
|
||||
type: Directory
|
||||
- name: plex-short-video
|
||||
hostPath:
|
||||
path: /mnt/nfs/media/short-video
|
||||
type: Directory
|
||||
- name: plex-music
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/plex/music
|
||||
path: /mnt/nfs/media/music
|
||||
type: Directory
|
||||
- name: plex-music-video
|
||||
hostPath:
|
||||
path: /mnt/nfs/media/music-video
|
||||
type: Directory
|
||||
- name: plex-gv
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/plex/gv
|
||||
path: /mnt/nfs/media/gv
|
||||
type: Directory
|
||||
56
apps/qbittorrent/base/deployment.yaml
Normal file
56
apps/qbittorrent/base/deployment.yaml
Normal file
@@ -0,0 +1,56 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: qbittorrent
|
||||
namespace: qbittorrent
|
||||
labels:
|
||||
app.kubernetes.io/name: qbittorrent
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: qbittorrent
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: qbittorrent
|
||||
spec:
|
||||
containers:
|
||||
- name: qbittorrent
|
||||
image: lscr.io/linuxserver/qbittorrent:latest
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
env:
|
||||
- name: PUID
|
||||
value: "1000"
|
||||
- name: PGID
|
||||
value: "1000"
|
||||
- name: TZ
|
||||
value: Australia/Sydney
|
||||
- name: WEBUI_PORT
|
||||
value: "8080"
|
||||
- name: TORRENTING_PORT
|
||||
value: "6881"
|
||||
ports:
|
||||
- protocol: TCP
|
||||
containerPort: 8080
|
||||
name: qb-ui
|
||||
- protocol: TCP
|
||||
containerPort: 6881
|
||||
name: torrenting
|
||||
- protocol: UDP
|
||||
containerPort: 6881
|
||||
name: torrenting-udp
|
||||
volumeMounts:
|
||||
- name: qbittorrent-config
|
||||
mountPath: /config
|
||||
- name: qbittorrent-downloads
|
||||
mountPath: /downloads
|
||||
volumes:
|
||||
- name: qbittorrent-config
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/qbittorrent/config
|
||||
type: Directory
|
||||
- name: qbittorrent-downloads
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/qbittorrent/downloads
|
||||
type: Directory
|
||||
28
apps/qbittorrent/base/service.yaml
Normal file
28
apps/qbittorrent/base/service.yaml
Normal file
@@ -0,0 +1,28 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: qbittorrent
|
||||
namespace: qbittorrent
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
labels:
|
||||
app.kubernetes.io/name: qbittorrent
|
||||
spec:
|
||||
selector:
|
||||
app.kubernetes.io/name: qbittorrent
|
||||
type: LoadBalancer
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 18880
|
||||
targetPort: 8080
|
||||
name: qb-ui
|
||||
- protocol: TCP
|
||||
port: 6881
|
||||
targetPort: 6881
|
||||
name: torrenting
|
||||
- protocol: UDP
|
||||
port: 6881
|
||||
targetPort: 6881
|
||||
name: torrenting-udp
|
||||
12
apps/qbittorrent/env/k3s-cluster/config.json
vendored
Normal file
12
apps/qbittorrent/env/k3s-cluster/config.json
vendored
Normal file
@@ -0,0 +1,12 @@
|
||||
{
|
||||
"appName": "qbittorrent",
|
||||
"userGivenName": "qbittorrent",
|
||||
"namespace": "qbittorrent",
|
||||
"destNamespace": "qbittorrent",
|
||||
"destServer": "https://kubernetes.default.svc",
|
||||
"srcPath": "apps/qbittorrent/env/k3s-cluster",
|
||||
"srcRepoURL": "https://github.com/3dwardch3ng/home-cluster-ops.git",
|
||||
"srcTargetRevision": "",
|
||||
"labels": null,
|
||||
"annotations": null
|
||||
}
|
||||
4
apps/qbittorrent/env/k3s-cluster/kustomization.yaml
vendored
Normal file
4
apps/qbittorrent/env/k3s-cluster/kustomization.yaml
vendored
Normal file
@@ -0,0 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
@@ -19,7 +19,7 @@ spec:
|
||||
runAsGroup: 1000
|
||||
containers:
|
||||
- name: rlpa-server
|
||||
image: damonto/estkme-cloud:1.0.11
|
||||
image: damonto/estkme-cloud:1.1.0
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
ports:
|
||||
|
||||
@@ -3,12 +3,15 @@ kind: Service
|
||||
metadata:
|
||||
name: rlpa-server
|
||||
namespace: rlpa
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
labels:
|
||||
app.kubernetes.io/name: rlpa
|
||||
spec:
|
||||
selector:
|
||||
app.kubernetes.io/name: rlpa
|
||||
type: ClusterIP
|
||||
type: LoadBalancer
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- protocol: TCP
|
||||
|
||||
@@ -32,3 +32,6 @@ spec:
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/snippet-box
|
||||
type: Directory
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
kubernetes.io/arch: arm64
|
||||
|
||||
@@ -2,5 +2,4 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./deployment.yaml
|
||||
- ./service.yaml
|
||||
- ./ingress.yaml
|
||||
- ./service.yaml
|
||||
@@ -8,10 +8,10 @@ metadata:
|
||||
spec:
|
||||
selector:
|
||||
app.kubernetes.io/name: snippet-box
|
||||
type: ClusterIP
|
||||
type: LoadBalancer
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 5000
|
||||
port: 5055
|
||||
targetPort: 5000
|
||||
name: snippet-box
|
||||
|
||||
12
apps/sonarqube/env/k3s-cluster/config.json
vendored
Normal file
12
apps/sonarqube/env/k3s-cluster/config.json
vendored
Normal file
@@ -0,0 +1,12 @@
|
||||
{
|
||||
"appName": "sonarqube",
|
||||
"userGivenName": "sonarqube",
|
||||
"namespace": "sonarqube",
|
||||
"destNamespace": "sonarqube",
|
||||
"destServer": "https://kubernetes.default.svc",
|
||||
"srcPath": "apps/sonarqube/env/k3s-cluster",
|
||||
"srcRepoURL": "https://github.com/3dwardch3ng/home-cluster-ops.git",
|
||||
"srcTargetRevision": "",
|
||||
"labels": null,
|
||||
"annotations": null
|
||||
}
|
||||
@@ -3,6 +3,6 @@ kind: Kustomization
|
||||
helmCharts:
|
||||
- name: sonarqube
|
||||
repo: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 5.2.10
|
||||
version: 5.2.13
|
||||
releaseName: sonarqube
|
||||
valuesFile: values.yaml
|
||||
20
apps/sonarqube/env/k3s-cluster/values.yaml
vendored
20
apps/sonarqube/env/k3s-cluster/values.yaml
vendored
@@ -1,6 +1,9 @@
|
||||
priorityClassName: system-cluster-critical
|
||||
image:
|
||||
debug: true
|
||||
podAntiAffinityPreset: ""
|
||||
namespaceOverride: "sonarqube"
|
||||
clusterDomain: sonarqube.cluster.edward.sydney
|
||||
clusterDomain: cluster.edward.sydney
|
||||
sonarqubeUsername: sonarqube
|
||||
existingSecret: "sonarqube-secrets"
|
||||
sonarqubeEmail: "me@edward.sydney"
|
||||
@@ -9,22 +12,21 @@ smtpPort: "587"
|
||||
smtpUser: "me@edward.sydney"
|
||||
smtpProtocol: "TLS"
|
||||
smtpExistingSecret: "sonarqube-secrets"
|
||||
resourcesPreset: "2xlarge"
|
||||
podSecurityContext:
|
||||
fsGroup: 1000
|
||||
containerSecurityContext:
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
updateStrategy:
|
||||
type: Recreate
|
||||
service:
|
||||
ports:
|
||||
http: 8090
|
||||
elastic: 9091
|
||||
nodePorts:
|
||||
http: 30080
|
||||
elastic: 30091
|
||||
ingress:
|
||||
enabled: true
|
||||
ingressClassName: "nginx"
|
||||
hostname: "sonarqube.cluster.edward.sydney"
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
persistence:
|
||||
enabled: true
|
||||
storageClass: local-path
|
||||
@@ -38,3 +40,5 @@ externalDatabase:
|
||||
host: "postgresql-primary.argocd.svc.cluster.local"
|
||||
user: "sonarqube_user"
|
||||
existingSecret: "sonarqube-secrets"
|
||||
nodeSelector:
|
||||
kubernetes.io/hostname: k3s-cluster-node-y
|
||||
|
||||
55
apps/stirling-pdf/base/deployment.yaml
Normal file
55
apps/stirling-pdf/base/deployment.yaml
Normal file
@@ -0,0 +1,55 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: stirling-pdf
|
||||
namespace: stirling-pdf
|
||||
labels:
|
||||
app.kubernetes.io/name: stirling-pdf
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: stirling-pdf
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: stirling-pdf
|
||||
spec:
|
||||
containers:
|
||||
- name: stirling-pdf
|
||||
image: frooodle/s-pdf:0.29.0
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
env:
|
||||
- name: DOCKER_ENABLE_SECURITY
|
||||
value: "true"
|
||||
ports:
|
||||
- protocol: TCP
|
||||
containerPort: 8080
|
||||
name: http
|
||||
volumeMounts:
|
||||
- name: s-pdf-tessdata
|
||||
mountPath: /usr/share/tesseract-ocr/5/tessdata
|
||||
- name: s-pdf-configs
|
||||
mountPath: /configs
|
||||
- name: s-pdf-custom-files
|
||||
mountPath: /customFiles
|
||||
- name: s-pdf-logs
|
||||
mountPath: /logs
|
||||
volumes:
|
||||
- name: s-pdf-tessdata
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/stirling-pdf/tessdata
|
||||
type: Directory
|
||||
- name: s-pdf-configs
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/stirling-pdf/configs
|
||||
type: Directory
|
||||
- name: s-pdf-custom-files
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/stirling-pdf/customFiles
|
||||
type: Directory
|
||||
- name: s-pdf-logs
|
||||
hostPath:
|
||||
path: /mnt/nfs/AppData/stirling-pdf/logs
|
||||
type: Directory
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./service.yaml
|
||||
- ./deployment.yaml
|
||||
- ./ingress.yaml
|
||||
- ./service.yaml
|
||||
20
apps/stirling-pdf/base/service.yaml
Normal file
20
apps/stirling-pdf/base/service.yaml
Normal file
@@ -0,0 +1,20 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: stirling-pdf
|
||||
namespace: stirling-pdf
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
labels:
|
||||
app.kubernetes.io/name: stirling-pdf
|
||||
spec:
|
||||
selector:
|
||||
app.kubernetes.io/name: stirling-pdf
|
||||
type: LoadBalancer
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 8880
|
||||
targetPort: 8080
|
||||
name: http
|
||||
12
apps/stirling-pdf/env/k3s-cluster/config.json
vendored
Normal file
12
apps/stirling-pdf/env/k3s-cluster/config.json
vendored
Normal file
@@ -0,0 +1,12 @@
|
||||
{
|
||||
"appName": "stirling-pdf",
|
||||
"userGivenName": "stirling-pdf",
|
||||
"namespace": "stirling-pdf",
|
||||
"destNamespace": "stirling-pdf",
|
||||
"destServer": "https://kubernetes.default.svc",
|
||||
"srcPath": "apps/stirling-pdf/env/k3s-cluster",
|
||||
"srcRepoURL": "https://github.com/3dwardch3ng/home-cluster-ops.git",
|
||||
"srcTargetRevision": "",
|
||||
"labels": null,
|
||||
"annotations": null
|
||||
}
|
||||
4
apps/stirling-pdf/env/k3s-cluster/kustomization.yaml
vendored
Normal file
4
apps/stirling-pdf/env/k3s-cluster/kustomization.yaml
vendored
Normal file
@@ -0,0 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
@@ -3,12 +3,15 @@ kind: Service
|
||||
metadata:
|
||||
name: trillium
|
||||
namespace: trillium
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
labels:
|
||||
app.kubernetes.io/name: trillium
|
||||
spec:
|
||||
selector:
|
||||
app.kubernetes.io/name: trillium
|
||||
type: ClusterIP
|
||||
type: LoadBalancer
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- protocol: TCP
|
||||
|
||||
@@ -1,5 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
- ./ingress.yaml
|
||||
- ../../base
|
||||
@@ -23,7 +23,7 @@ spec:
|
||||
runAsNonRoot: true
|
||||
runAsGroup: 1000
|
||||
name: vaultwarden
|
||||
image: vaultwarden/server:1.31.0
|
||||
image: vaultwarden/server:1.32.0
|
||||
env:
|
||||
- name: DOMAIN
|
||||
value: https://vaultwarden.cluster.edward.sydney
|
||||
|
||||
@@ -3,12 +3,15 @@ kind: Service
|
||||
metadata:
|
||||
name: vaultwarden
|
||||
namespace: vaultwarden
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
labels:
|
||||
app.kubernetes.io/name: vaultwarden
|
||||
spec:
|
||||
selector:
|
||||
app.kubernetes.io/name: vaultwarden
|
||||
type: ClusterIP
|
||||
type: LoadBalancer
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- protocol: TCP
|
||||
|
||||
21
apps/vaultwarden/env/k3s-cluster/ingress.yaml
vendored
21
apps/vaultwarden/env/k3s-cluster/ingress.yaml
vendored
@@ -1,21 +0,0 @@
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: vaultwarden-ingress
|
||||
namespace: vaultwarden
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "false"
|
||||
nginx.ingress.kubernetes.io/use-regex: "true"
|
||||
spec:
|
||||
ingressClassName: nginx
|
||||
rules:
|
||||
- host: "vaultwarden.cluster.edward.sydney"
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: vaultwarden
|
||||
port:
|
||||
number: 11080
|
||||
@@ -1,5 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
- ./ingress.yaml
|
||||
- ../../base
|
||||
26
infrastructures/argo-events/base/cluster-role-binding.yaml
Normal file
26
infrastructures/argo-events/base/cluster-role-binding.yaml
Normal file
@@ -0,0 +1,26 @@
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: argo-events-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: argo-events-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: argo-events-sa
|
||||
namespace: argo-events
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: argo-events-webhook-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: argo-events-webhook
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: argo-events-webhook-sa
|
||||
namespace: argo-events
|
||||
230
infrastructures/argo-events/base/cluster-role.yaml
Normal file
230
infrastructures/argo-events/base/cluster-role.yaml
Normal file
@@ -0,0 +1,230 @@
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
rbac.authorization.k8s.io/aggregate-to-admin: "true"
|
||||
name: argo-events-aggregate-to-admin
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- sensors
|
||||
- sensors/finalizers
|
||||
- sensors/status
|
||||
- eventsources
|
||||
- eventsources/finalizers
|
||||
- eventsources/status
|
||||
- eventbus
|
||||
- eventbus/finalizers
|
||||
- eventbus/status
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- deletecollection
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
rbac.authorization.k8s.io/aggregate-to-edit: "true"
|
||||
name: argo-events-aggregate-to-edit
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- sensors
|
||||
- sensors/finalizers
|
||||
- sensors/status
|
||||
- eventsources
|
||||
- eventsources/finalizers
|
||||
- eventsources/status
|
||||
- eventbus
|
||||
- eventbus/finalizers
|
||||
- eventbus/status
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- deletecollection
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
rbac.authorization.k8s.io/aggregate-to-view: "true"
|
||||
name: argo-events-aggregate-to-view
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- sensors
|
||||
- sensors/finalizers
|
||||
- sensors/status
|
||||
- eventsources
|
||||
- eventsources/finalizers
|
||||
- eventsources/status
|
||||
- eventbus
|
||||
- eventbus/finalizers
|
||||
- eventbus/status
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: argo-events-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- create
|
||||
- patch
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
- leases
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- sensors
|
||||
- sensors/finalizers
|
||||
- sensors/status
|
||||
- eventsources
|
||||
- eventsources/finalizers
|
||||
- eventsources/status
|
||||
- eventbus
|
||||
- eventbus/finalizers
|
||||
- eventbus/status
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- deletecollection
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- pods/exec
|
||||
- configmaps
|
||||
- services
|
||||
- persistentvolumeclaims
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- secrets
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- statefulsets
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: argo-events-webhook
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- patch
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- admissionregistration.k8s.io
|
||||
resources:
|
||||
- validatingwebhookconfigurations
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- patch
|
||||
- watch
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- eventbus
|
||||
- eventsources
|
||||
- sensors
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- rbac.authorization.k8s.io
|
||||
resources:
|
||||
- clusterroles
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
76
infrastructures/argo-events/base/configmap.yaml
Normal file
76
infrastructures/argo-events/base/configmap.yaml
Normal file
@@ -0,0 +1,76 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
data:
|
||||
controller-config.yaml: |
|
||||
eventBus:
|
||||
nats:
|
||||
versions:
|
||||
- version: 0.22.1
|
||||
natsStreamingImage: nats-streaming:0.22.1
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.8.0
|
||||
jetstream:
|
||||
# Default JetStream settings, could be overridden by EventBus JetStream specs
|
||||
settings: |
|
||||
# https://docs.nats.io/running-a-nats-service/configuration#jetstream
|
||||
# Only configure "max_memory_store" or "max_file_store", do not set "store_dir" as it has been hardcoded.
|
||||
# e.g. 1G. -1 means no limit, up to 75% of available memory
|
||||
max_memory_store: -1
|
||||
# e.g. 20G. -1 means no limit, Up to 1TB if available
|
||||
max_file_store: 1TB
|
||||
streamConfig: |
|
||||
# The default properties of the streams to be created in this JetStream service
|
||||
maxMsgs: 50000
|
||||
maxAge: 168h
|
||||
maxBytes: -1
|
||||
replicas: 3
|
||||
duplicates: 300s
|
||||
versions:
|
||||
- version: latest
|
||||
natsImage: nats:2.10.10
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.14.0
|
||||
configReloaderImage: natsio/nats-server-config-reloader:0.14.0
|
||||
startCommand: /nats-server
|
||||
- version: 2.8.1
|
||||
natsImage: nats:2.8.1
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.9.1
|
||||
configReloaderImage: natsio/nats-server-config-reloader:0.7.0
|
||||
startCommand: /nats-server
|
||||
- version: 2.8.1-alpine
|
||||
natsImage: nats:2.8.1-alpine
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.9.1
|
||||
configReloaderImage: natsio/nats-server-config-reloader:0.7.0
|
||||
startCommand: nats-server
|
||||
- version: 2.8.2
|
||||
natsImage: nats:2.8.2
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.9.1
|
||||
configReloaderImage: natsio/nats-server-config-reloader:0.7.0
|
||||
startCommand: /nats-server
|
||||
- version: 2.8.2-alpine
|
||||
natsImage: nats:2.8.2-alpine
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.9.1
|
||||
configReloaderImage: natsio/nats-server-config-reloader:0.7.0
|
||||
startCommand: nats-server
|
||||
- version: 2.9.1
|
||||
natsImage: nats:2.9.1
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.9.1
|
||||
configReloaderImage: natsio/nats-server-config-reloader:0.7.0
|
||||
startCommand: /nats-server
|
||||
- version: 2.9.12
|
||||
natsImage: nats:2.9.12
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.9.1
|
||||
configReloaderImage: natsio/nats-server-config-reloader:0.7.0
|
||||
startCommand: /nats-server
|
||||
- version: 2.9.16
|
||||
natsImage: nats:2.9.16
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.9.1
|
||||
configReloaderImage: natsio/nats-server-config-reloader:0.7.0
|
||||
startCommand: /nats-server
|
||||
- version: 2.10.10
|
||||
natsImage: nats:2.10.10
|
||||
metricsExporterImage: natsio/prometheus-nats-exporter:0.14.0
|
||||
configReloaderImage: natsio/nats-server-config-reloader:0.14.0
|
||||
startCommand: /nats-server
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: argo-events-controller-config
|
||||
namespace: argo-events
|
||||
120
infrastructures/argo-events/base/custom-resource-definition.yaml
Normal file
120
infrastructures/argo-events/base/custom-resource-definition.yaml
Normal file
@@ -0,0 +1,120 @@
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: eventbus.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: EventBus
|
||||
listKind: EventBusList
|
||||
plural: eventbus
|
||||
shortNames:
|
||||
- eb
|
||||
singular: eventbus
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
status:
|
||||
type: object
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: eventsources.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: EventSource
|
||||
listKind: EventSourceList
|
||||
plural: eventsources
|
||||
shortNames:
|
||||
- es
|
||||
singular: eventsource
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
status:
|
||||
type: object
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: sensors.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: Sensor
|
||||
listKind: SensorList
|
||||
plural: sensors
|
||||
shortNames:
|
||||
- sn
|
||||
singular: sensor
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
status:
|
||||
type: object
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
82
infrastructures/argo-events/base/deployment.yaml
Normal file
82
infrastructures/argo-events/base/deployment.yaml
Normal file
@@ -0,0 +1,82 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: controller-manager
|
||||
namespace: argo-events
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: controller-manager
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: controller-manager
|
||||
spec:
|
||||
containers:
|
||||
- args:
|
||||
- controller
|
||||
env:
|
||||
- name: ARGO_EVENTS_IMAGE
|
||||
value: quay.io/argoproj/argo-events:v1.9.2
|
||||
- name: NAMESPACE
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.namespace
|
||||
image: quay.io/argoproj/argo-events:v1.9.2
|
||||
imagePullPolicy: Always
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: 8081
|
||||
initialDelaySeconds: 3
|
||||
periodSeconds: 3
|
||||
name: controller-manager
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /readyz
|
||||
port: 8081
|
||||
initialDelaySeconds: 3
|
||||
periodSeconds: 3
|
||||
volumeMounts:
|
||||
- mountPath: /etc/argo-events
|
||||
name: controller-config-volume
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 9731
|
||||
serviceAccountName: argo-events-sa
|
||||
volumes:
|
||||
- configMap:
|
||||
name: argo-events-controller-config
|
||||
name: controller-config-volume
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: events-webhook
|
||||
namespace: argo-events
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: events-webhook
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: events-webhook
|
||||
spec:
|
||||
containers:
|
||||
- args:
|
||||
- webhook-service
|
||||
env:
|
||||
- name: NAMESPACE
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.namespace
|
||||
- name: PORT
|
||||
value: "443"
|
||||
image: quay.io/argoproj/argo-events:v1.9.2
|
||||
imagePullPolicy: Always
|
||||
name: webhook
|
||||
serviceAccountName: argo-events-webhook-sa
|
||||
10
infrastructures/argo-events/base/kustomization.yaml
Normal file
10
infrastructures/argo-events/base/kustomization.yaml
Normal file
@@ -0,0 +1,10 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./custom-resource-definition.yaml
|
||||
- ./service-account.yaml
|
||||
- ./cluster-role.yaml
|
||||
- ./cluster-role-binding.yaml
|
||||
- ./configmap.yaml
|
||||
- ./deployment.yaml
|
||||
- ./service.yaml
|
||||
12
infrastructures/argo-events/base/service-account.yaml
Normal file
12
infrastructures/argo-events/base/service-account.yaml
Normal file
@@ -0,0 +1,12 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: argo-events-sa
|
||||
namespace: argo-events
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: argo-events-webhook-sa
|
||||
namespace: argo-events
|
||||
12
infrastructures/argo-events/base/service.yaml
Normal file
12
infrastructures/argo-events/base/service.yaml
Normal file
@@ -0,0 +1,12 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: events-webhook
|
||||
namespace: argo-events
|
||||
spec:
|
||||
ports:
|
||||
- port: 443
|
||||
targetPort: 443
|
||||
selector:
|
||||
app: events-webhook
|
||||
14
infrastructures/argo-events/env/k3s-cluster/config.json
vendored
Normal file
14
infrastructures/argo-events/env/k3s-cluster/config.json
vendored
Normal file
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"appName": "argo-events",
|
||||
"userGivenName": "argo-events",
|
||||
"namespace": "argo-events",
|
||||
"destNamespace": "argo-events",
|
||||
"destServer": "https://kubernetes.default.svc",
|
||||
"srcPath": "infrastructures/argo-events/env/k3s-cluster",
|
||||
"srcRepoURL": "https://github.com/3dwardch3ng/home-cluster-ops.git",
|
||||
"srcTargetRevision": "",
|
||||
"labels": null,
|
||||
"annotations": {
|
||||
"argo-events.argoproj.io/release-version": "v1.9.2"
|
||||
}
|
||||
}
|
||||
37
infrastructures/argo-events/env/k3s-cluster/examples/event-source.yaml
vendored
Normal file
37
infrastructures/argo-events/env/k3s-cluster/examples/event-source.yaml
vendored
Normal file
@@ -0,0 +1,37 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: EventSource
|
||||
metadata:
|
||||
name: webhook
|
||||
spec:
|
||||
service:
|
||||
ports:
|
||||
- port: 12000
|
||||
targetPort: 12000
|
||||
webhook:
|
||||
# event-source can run multiple HTTP servers. Simply define a unique port to start a new HTTP server
|
||||
example:
|
||||
# port to run HTTP server on
|
||||
port: "12000"
|
||||
# endpoint to listen to
|
||||
endpoint: /example
|
||||
# HTTP request method to allow. In this case, only POST requests are accepted
|
||||
method: POST
|
||||
|
||||
# example-foo:
|
||||
# port: "12000"
|
||||
# endpoint: /example2
|
||||
# method: POST
|
||||
|
||||
# Uncomment to use secure webhook
|
||||
# example-secure:
|
||||
# port: "13000"
|
||||
# endpoint: "/secure"
|
||||
# method: "POST"
|
||||
# # k8s secret that contains the cert
|
||||
# serverCertSecret:
|
||||
# name: my-secret
|
||||
# key: cert-key
|
||||
# # k8s secret that contains the private key
|
||||
# serverKeySecret:
|
||||
# name: my-secret
|
||||
# key: pk-key
|
||||
24
infrastructures/argo-events/env/k3s-cluster/examples/eventbus.yaml
vendored
Normal file
24
infrastructures/argo-events/env/k3s-cluster/examples/eventbus.yaml
vendored
Normal file
@@ -0,0 +1,24 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: EventBus
|
||||
metadata:
|
||||
name: default
|
||||
spec:
|
||||
nats:
|
||||
native:
|
||||
# Optional, defaults to 3. If it is < 3, set it to 3, that is the minimal requirement.
|
||||
replicas: 3
|
||||
# Optional, authen strategy, "none" or "token", defaults to "none"
|
||||
auth: token
|
||||
# containerTemplate:
|
||||
# resources:
|
||||
# requests:
|
||||
# cpu: "10m"
|
||||
# metricsContainerTemplate:
|
||||
# resources:
|
||||
# requests:
|
||||
# cpu: "10m"
|
||||
# antiAffinity: false
|
||||
# persistence:
|
||||
# storageClassName: standard
|
||||
# accessMode: ReadWriteOnce
|
||||
# volumeSize: 10Gi
|
||||
@@ -1,21 +1,21 @@
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: snippet-box-ingress
|
||||
namespace: snippet-box
|
||||
name: event-example-ingress
|
||||
namespace: argo-events
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "false"
|
||||
nginx.ingress.kubernetes.io/use-regex: "true"
|
||||
spec:
|
||||
ingressClassName: nginx
|
||||
rules:
|
||||
- host: "snippet-box.cluster.edward.sydney"
|
||||
- host: "event-example.cluster.edward.sydney"
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: snippet-box
|
||||
name: webhook-eventsource-svc
|
||||
port:
|
||||
number: 5000
|
||||
number: 12000
|
||||
33
infrastructures/argo-events/env/k3s-cluster/examples/sensor.yaml
vendored
Normal file
33
infrastructures/argo-events/env/k3s-cluster/examples/sensor.yaml
vendored
Normal file
@@ -0,0 +1,33 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: operate-workflow-sa
|
||||
---
|
||||
# Similarly you can use a ClusterRole and ClusterRoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: operate-workflow-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
verbs:
|
||||
- "*"
|
||||
resources:
|
||||
- workflows
|
||||
- workflowtemplates
|
||||
- cronworkflows
|
||||
- clusterworkflowtemplates
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: operate-workflow-role-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: operate-workflow-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: operate-workflow-sa
|
||||
47
infrastructures/argo-events/env/k3s-cluster/examples/webhook.yaml
vendored
Normal file
47
infrastructures/argo-events/env/k3s-cluster/examples/webhook.yaml
vendored
Normal file
@@ -0,0 +1,47 @@
|
||||
---
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Sensor
|
||||
metadata:
|
||||
name: webhook
|
||||
spec:
|
||||
template:
|
||||
serviceAccountName: operate-workflow-sa
|
||||
dependencies:
|
||||
- name: test-dep
|
||||
eventSourceName: webhook
|
||||
eventName: example
|
||||
triggers:
|
||||
- template:
|
||||
name: webhook-workflow-trigger
|
||||
k8s:
|
||||
operation: create
|
||||
source:
|
||||
resource:
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Workflow
|
||||
metadata:
|
||||
generateName: webhook-
|
||||
spec:
|
||||
entrypoint: whalesay
|
||||
arguments:
|
||||
parameters:
|
||||
- name: message
|
||||
# the value will get overridden by event payload from test-dep
|
||||
value: "hello world!"
|
||||
templates:
|
||||
- name: whalesay
|
||||
inputs:
|
||||
parameters:
|
||||
- name: message
|
||||
container:
|
||||
image: docker/whalesay:latest
|
||||
command: [cowsay]
|
||||
args: ["{{inputs.parameters.message}}"]
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
kubernetes.io/arch: amd64
|
||||
parameters:
|
||||
- src:
|
||||
dependencyName: test-dep
|
||||
dataKey: body
|
||||
dest: spec.arguments.parameters.0.value
|
||||
29
infrastructures/argo-events/env/k3s-cluster/examples/workflow.yaml
vendored
Normal file
29
infrastructures/argo-events/env/k3s-cluster/examples/workflow.yaml
vendored
Normal file
@@ -0,0 +1,29 @@
|
||||
# This file enables a Workflow Pod (running Emissary executor) to be able to read and patch WorkflowTaskResults,
|
||||
# which get shared with the Workflow Controller. The Controller uses the results to update Workflow status.
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
annotations:
|
||||
workflows.argoproj.io/description: |
|
||||
Recomended minimum permissions for the `emissary` executor.
|
||||
name: executor
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflowtaskresults
|
||||
verbs:
|
||||
- create
|
||||
- patch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: executor-default
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: executor
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: default
|
||||
10
infrastructures/argo-events/env/k3s-cluster/kustomization.yaml
vendored
Normal file
10
infrastructures/argo-events/env/k3s-cluster/kustomization.yaml
vendored
Normal file
@@ -0,0 +1,10 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
# - ./examples/eventbus.yaml
|
||||
# - ./examples/event-source.yaml
|
||||
# - ./examples/ingress.yaml
|
||||
# - ./examples/sensor.yaml
|
||||
# - ./examples/workflow.yaml
|
||||
# - ./examples/webhook.yaml
|
||||
@@ -0,0 +1,52 @@
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: argo-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: argo-cluster-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: argo
|
||||
namespace: argo
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: argo-clusterworkflowtemplate-role-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: argo-clusterworkflowtemplate-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: argo
|
||||
namespace: argo
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: argo-server-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: argo-server-cluster-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: argo-server
|
||||
namespace: argo
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: argo-server-clusterworkflowtemplate-role-binding
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: argo-server-clusterworkflowtemplate-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: argo-server
|
||||
namespace: argo
|
||||
298
infrastructures/argo-workflows/base/cluster-role.yaml
Normal file
298
infrastructures/argo-workflows/base/cluster-role.yaml
Normal file
@@ -0,0 +1,298 @@
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
rbac.authorization.k8s.io/aggregate-to-admin: "true"
|
||||
name: argo-aggregate-to-admin
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflows
|
||||
- workflows/finalizers
|
||||
- workfloweventbindings
|
||||
- workfloweventbindings/finalizers
|
||||
- workflowtemplates
|
||||
- workflowtemplates/finalizers
|
||||
- cronworkflows
|
||||
- cronworkflows/finalizers
|
||||
- clusterworkflowtemplates
|
||||
- clusterworkflowtemplates/finalizers
|
||||
- workflowtasksets
|
||||
- workflowtasksets/finalizers
|
||||
- workflowtaskresults
|
||||
- workflowtaskresults/finalizers
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- deletecollection
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
rbac.authorization.k8s.io/aggregate-to-edit: "true"
|
||||
name: argo-aggregate-to-edit
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflows
|
||||
- workflows/finalizers
|
||||
- workfloweventbindings
|
||||
- workfloweventbindings/finalizers
|
||||
- workflowtemplates
|
||||
- workflowtemplates/finalizers
|
||||
- cronworkflows
|
||||
- cronworkflows/finalizers
|
||||
- clusterworkflowtemplates
|
||||
- clusterworkflowtemplates/finalizers
|
||||
- workflowtaskresults
|
||||
- workflowtaskresults/finalizers
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- deletecollection
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
rbac.authorization.k8s.io/aggregate-to-view: "true"
|
||||
name: argo-aggregate-to-view
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflows
|
||||
- workflows/finalizers
|
||||
- workfloweventbindings
|
||||
- workfloweventbindings/finalizers
|
||||
- workflowtemplates
|
||||
- workflowtemplates/finalizers
|
||||
- cronworkflows
|
||||
- cronworkflows/finalizers
|
||||
- clusterworkflowtemplates
|
||||
- clusterworkflowtemplates/finalizers
|
||||
- workflowtaskresults
|
||||
- workflowtaskresults/finalizers
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: argo-cluster-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- pods/exec
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
verbs:
|
||||
- get
|
||||
- watch
|
||||
- list
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- persistentvolumeclaims
|
||||
- persistentvolumeclaims/finalizers
|
||||
verbs:
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- get
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflows
|
||||
- workflows/finalizers
|
||||
- workflowtasksets
|
||||
- workflowtasksets/finalizers
|
||||
- workflowartifactgctasks
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- create
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflowtemplates
|
||||
- workflowtemplates/finalizers
|
||||
- clusterworkflowtemplates
|
||||
- clusterworkflowtemplates/finalizers
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflowtaskresults
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- deletecollection
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- serviceaccounts
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- cronworkflows
|
||||
- cronworkflows/finalizers
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- create
|
||||
- patch
|
||||
- apiGroups:
|
||||
- policy
|
||||
resources:
|
||||
- poddisruptionbudgets
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- delete
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: argo-clusterworkflowtemplate-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- clusterworkflowtemplates
|
||||
- clusterworkflowtemplates/finalizers
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: argo-server-cluster-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
verbs:
|
||||
- get
|
||||
- watch
|
||||
- list
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- pods/exec
|
||||
- pods/log
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- watch
|
||||
- create
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- serviceaccounts
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- eventsources
|
||||
- sensors
|
||||
- workflows
|
||||
- workfloweventbindings
|
||||
- workflowtemplates
|
||||
- cronworkflows
|
||||
- clusterworkflowtemplates
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: argo-server-clusterworkflowtemplate-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- clusterworkflowtemplates
|
||||
- clusterworkflowtemplates/finalizers
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- watch
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
110
infrastructures/argo-workflows/base/configmap.yaml
Normal file
110
infrastructures/argo-workflows/base/configmap.yaml
Normal file
@@ -0,0 +1,110 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
data:
|
||||
artifactRepository: |
|
||||
s3:
|
||||
bucket: argo-workflows
|
||||
endpoint: minio.minio.svc.cluster.local:19000
|
||||
insecure: true
|
||||
accessKeySecret:
|
||||
name: argo-workflows-minio-cred
|
||||
key: accesskey
|
||||
secretKeySecret:
|
||||
name: argo-workflows-minio-cred
|
||||
key: secretkey
|
||||
columns: |
|
||||
- name: Workflow Completed
|
||||
type: label
|
||||
key: workflows.argoproj.io/completed
|
||||
executor: |
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 64Mi
|
||||
images: |
|
||||
docker/whalesay:v3.5.10:
|
||||
cmd: [cowsay]
|
||||
links: |
|
||||
- name: Workflow Link
|
||||
scope: workflow
|
||||
url: http://logging-facility?namespace=${metadata.namespace}&workflowName=${metadata.name}&startedAt=${status.startedAt}&finishedAt=${status.finishedAt}
|
||||
- name: Pod Link
|
||||
scope: pod
|
||||
url: http://logging-facility?namespace=${metadata.namespace}&podName=${metadata.name}&startedAt=${status.startedAt}&finishedAt=${status.finishedAt}
|
||||
- name: Pod Logs Link
|
||||
scope: pod-logs
|
||||
url: http://logging-facility?namespace=${metadata.namespace}&podName=${metadata.name}&startedAt=${status.startedAt}&finishedAt=${status.finishedAt}
|
||||
- name: Event Source Logs Link
|
||||
scope: event-source-logs
|
||||
url: http://logging-facility?namespace=${metadata.namespace}&podName=${metadata.name}&startedAt=${status.startedAt}&finishedAt=${status.finishedAt}
|
||||
- name: Sensor Logs Link
|
||||
scope: sensor-logs
|
||||
url: http://logging-facility?namespace=${metadata.namespace}&podName=${metadata.name}&startedAt=${status.startedAt}&finishedAt=${status.finishedAt}
|
||||
- name: Completed Workflows
|
||||
scope: workflow-list
|
||||
url: http://workflows?label=workflows.argoproj.io/completed=true
|
||||
metricsConfig: |
|
||||
enabled: true
|
||||
path: /metrics
|
||||
port: 9090
|
||||
namespaceParallelism: "10"
|
||||
persistence: |
|
||||
connectionPool:
|
||||
maxIdleConns: 100
|
||||
maxOpenConns: 0
|
||||
connMaxLifetime: 0s
|
||||
nodeStatusOffLoad: true
|
||||
archive: true
|
||||
archiveTTL: 7d
|
||||
postgresql:
|
||||
host: postgresql-primary.argocd.svc.cluster.local
|
||||
port: 5432
|
||||
database: argo_workflows
|
||||
tableName: argo_workflows
|
||||
userNameSecret:
|
||||
name: argo-workflows-postgres-config
|
||||
key: username
|
||||
passwordSecret:
|
||||
name: argo-workflows-postgres-config
|
||||
key: password
|
||||
retentionPolicy: |
|
||||
completed: 10
|
||||
failed: 3
|
||||
errored: 3
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: workflow-controller-configmap
|
||||
namespace: argo
|
||||
---
|
||||
apiVersion: v1
|
||||
data:
|
||||
default-v1: |
|
||||
archiveLogs: true
|
||||
s3:
|
||||
bucket: argo-workflows
|
||||
endpoint: minio.minio.svc.cluster.local:19000
|
||||
insecure: true
|
||||
accessKeySecret:
|
||||
name: argo-workflows-minio-cred
|
||||
key: accesskey
|
||||
secretKeySecret:
|
||||
name: argo-workflows-minio-cred
|
||||
key: secretkey
|
||||
empty: ""
|
||||
my-key: |
|
||||
archiveLogs: true
|
||||
s3:
|
||||
bucket: argo-workflows
|
||||
endpoint: minio.minio.svc.cluster.local:19000
|
||||
insecure: true
|
||||
accessKeySecret:
|
||||
name: argo-workflows-minio-cred
|
||||
key: accesskey
|
||||
secretKeySecret:
|
||||
name: argo-workflows-minio-cred
|
||||
key: secretkey
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
annotations:
|
||||
workflows.argoproj.io/default-artifact-repository: default-v1
|
||||
name: artifact-repositories
|
||||
@@ -0,0 +1,888 @@
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: clusterworkflowtemplates.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: ClusterWorkflowTemplate
|
||||
listKind: ClusterWorkflowTemplateList
|
||||
plural: clusterworkflowtemplates
|
||||
shortNames:
|
||||
- clusterwftmpl
|
||||
- cwft
|
||||
singular: clusterworkflowtemplate
|
||||
scope: Cluster
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: cronworkflows.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: CronWorkflow
|
||||
listKind: CronWorkflowList
|
||||
plural: cronworkflows
|
||||
shortNames:
|
||||
- cwf
|
||||
- cronwf
|
||||
singular: cronworkflow
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
status:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: workflowartifactgctasks.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: WorkflowArtifactGCTask
|
||||
listKind: WorkflowArtifactGCTaskList
|
||||
plural: workflowartifactgctasks
|
||||
shortNames:
|
||||
- wfat
|
||||
singular: workflowartifactgctask
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
status:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: workfloweventbindings.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: WorkflowEventBinding
|
||||
listKind: WorkflowEventBindingList
|
||||
plural: workfloweventbindings
|
||||
shortNames:
|
||||
- wfeb
|
||||
singular: workfloweventbinding
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: workflows.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: Workflow
|
||||
listKind: WorkflowList
|
||||
plural: workflows
|
||||
shortNames:
|
||||
- wf
|
||||
singular: workflow
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- additionalPrinterColumns:
|
||||
- description: Status of the workflow
|
||||
jsonPath: .status.phase
|
||||
name: Status
|
||||
type: string
|
||||
- description: When the workflow was started
|
||||
format: date-time
|
||||
jsonPath: .status.startedAt
|
||||
name: Age
|
||||
type: date
|
||||
- description: Human readable message indicating details about why the workflow
|
||||
is in this condition.
|
||||
jsonPath: .status.message
|
||||
name: Message
|
||||
type: string
|
||||
name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
status:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
subresources: {}
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: workflowtaskresults.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: WorkflowTaskResult
|
||||
listKind: WorkflowTaskResultList
|
||||
plural: workflowtaskresults
|
||||
singular: workflowtaskresult
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
message:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
outputs:
|
||||
properties:
|
||||
artifacts:
|
||||
items:
|
||||
properties:
|
||||
archive:
|
||||
properties:
|
||||
none:
|
||||
type: object
|
||||
tar:
|
||||
properties:
|
||||
compressionLevel:
|
||||
format: int32
|
||||
type: integer
|
||||
type: object
|
||||
zip:
|
||||
type: object
|
||||
type: object
|
||||
archiveLogs:
|
||||
type: boolean
|
||||
artifactGC:
|
||||
properties:
|
||||
podMetadata:
|
||||
properties:
|
||||
annotations:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
labels:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
type: object
|
||||
serviceAccountName:
|
||||
type: string
|
||||
strategy:
|
||||
enum:
|
||||
- ""
|
||||
- OnWorkflowCompletion
|
||||
- OnWorkflowDeletion
|
||||
- Never
|
||||
type: string
|
||||
type: object
|
||||
artifactory:
|
||||
properties:
|
||||
passwordSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
url:
|
||||
type: string
|
||||
usernameSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
required:
|
||||
- url
|
||||
type: object
|
||||
azure:
|
||||
properties:
|
||||
accountKeySecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
blob:
|
||||
type: string
|
||||
container:
|
||||
type: string
|
||||
endpoint:
|
||||
type: string
|
||||
useSDKCreds:
|
||||
type: boolean
|
||||
required:
|
||||
- blob
|
||||
- container
|
||||
- endpoint
|
||||
type: object
|
||||
deleted:
|
||||
type: boolean
|
||||
from:
|
||||
type: string
|
||||
fromExpression:
|
||||
type: string
|
||||
gcs:
|
||||
properties:
|
||||
bucket:
|
||||
type: string
|
||||
key:
|
||||
type: string
|
||||
serviceAccountKeySecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
git:
|
||||
properties:
|
||||
branch:
|
||||
type: string
|
||||
depth:
|
||||
format: int64
|
||||
type: integer
|
||||
disableSubmodules:
|
||||
type: boolean
|
||||
fetch:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
insecureIgnoreHostKey:
|
||||
type: boolean
|
||||
passwordSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
repo:
|
||||
type: string
|
||||
revision:
|
||||
type: string
|
||||
singleBranch:
|
||||
type: boolean
|
||||
sshPrivateKeySecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
usernameSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
required:
|
||||
- repo
|
||||
type: object
|
||||
globalName:
|
||||
type: string
|
||||
hdfs:
|
||||
properties:
|
||||
addresses:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
force:
|
||||
type: boolean
|
||||
hdfsUser:
|
||||
type: string
|
||||
krbCCacheSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
krbConfigConfigMap:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
krbKeytabSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
krbRealm:
|
||||
type: string
|
||||
krbServicePrincipalName:
|
||||
type: string
|
||||
krbUsername:
|
||||
type: string
|
||||
path:
|
||||
type: string
|
||||
required:
|
||||
- path
|
||||
type: object
|
||||
http:
|
||||
properties:
|
||||
auth:
|
||||
properties:
|
||||
basicAuth:
|
||||
properties:
|
||||
passwordSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
usernameSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
type: object
|
||||
clientCert:
|
||||
properties:
|
||||
clientCertSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
clientKeySecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
type: object
|
||||
oauth2:
|
||||
properties:
|
||||
clientIDSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
clientSecretSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
endpointParams:
|
||||
items:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
value:
|
||||
type: string
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
type: array
|
||||
scopes:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
tokenURLSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
type: object
|
||||
type: object
|
||||
headers:
|
||||
items:
|
||||
properties:
|
||||
name:
|
||||
type: string
|
||||
value:
|
||||
type: string
|
||||
required:
|
||||
- name
|
||||
- value
|
||||
type: object
|
||||
type: array
|
||||
url:
|
||||
type: string
|
||||
required:
|
||||
- url
|
||||
type: object
|
||||
mode:
|
||||
format: int32
|
||||
type: integer
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
oss:
|
||||
properties:
|
||||
accessKeySecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
bucket:
|
||||
type: string
|
||||
createBucketIfNotPresent:
|
||||
type: boolean
|
||||
endpoint:
|
||||
type: string
|
||||
key:
|
||||
type: string
|
||||
lifecycleRule:
|
||||
properties:
|
||||
markDeletionAfterDays:
|
||||
format: int32
|
||||
type: integer
|
||||
markInfrequentAccessAfterDays:
|
||||
format: int32
|
||||
type: integer
|
||||
type: object
|
||||
secretKeySecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
securityToken:
|
||||
type: string
|
||||
useSDKCreds:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
path:
|
||||
type: string
|
||||
raw:
|
||||
properties:
|
||||
data:
|
||||
type: string
|
||||
required:
|
||||
- data
|
||||
type: object
|
||||
recurseMode:
|
||||
type: boolean
|
||||
s3:
|
||||
properties:
|
||||
accessKeySecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
bucket:
|
||||
type: string
|
||||
caSecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
createBucketIfNotPresent:
|
||||
properties:
|
||||
objectLocking:
|
||||
type: boolean
|
||||
type: object
|
||||
encryptionOptions:
|
||||
properties:
|
||||
enableEncryption:
|
||||
type: boolean
|
||||
kmsEncryptionContext:
|
||||
type: string
|
||||
kmsKeyId:
|
||||
type: string
|
||||
serverSideCustomerKeySecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
type: object
|
||||
endpoint:
|
||||
type: string
|
||||
insecure:
|
||||
type: boolean
|
||||
key:
|
||||
type: string
|
||||
region:
|
||||
type: string
|
||||
roleARN:
|
||||
type: string
|
||||
secretKeySecret:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
useSDKCreds:
|
||||
type: boolean
|
||||
type: object
|
||||
subPath:
|
||||
type: string
|
||||
required:
|
||||
- name
|
||||
type: object
|
||||
type: array
|
||||
exitCode:
|
||||
type: string
|
||||
parameters:
|
||||
items:
|
||||
properties:
|
||||
default:
|
||||
type: string
|
||||
description:
|
||||
type: string
|
||||
enum:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
globalName:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
value:
|
||||
type: string
|
||||
valueFrom:
|
||||
properties:
|
||||
configMapKeyRef:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
optional:
|
||||
type: boolean
|
||||
required:
|
||||
- key
|
||||
type: object
|
||||
default:
|
||||
type: string
|
||||
event:
|
||||
type: string
|
||||
expression:
|
||||
type: string
|
||||
jqFilter:
|
||||
type: string
|
||||
jsonPath:
|
||||
type: string
|
||||
parameter:
|
||||
type: string
|
||||
path:
|
||||
type: string
|
||||
supplied:
|
||||
type: object
|
||||
type: object
|
||||
required:
|
||||
- name
|
||||
type: object
|
||||
type: array
|
||||
result:
|
||||
type: string
|
||||
type: object
|
||||
phase:
|
||||
type: string
|
||||
progress:
|
||||
type: string
|
||||
required:
|
||||
- metadata
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: workflowtasksets.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: WorkflowTaskSet
|
||||
listKind: WorkflowTaskSetList
|
||||
plural: workflowtasksets
|
||||
shortNames:
|
||||
- wfts
|
||||
singular: workflowtaskset
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
status:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: workflowtemplates.argoproj.io
|
||||
spec:
|
||||
group: argoproj.io
|
||||
names:
|
||||
kind: WorkflowTemplate
|
||||
listKind: WorkflowTemplateList
|
||||
plural: workflowtemplates
|
||||
shortNames:
|
||||
- wftmpl
|
||||
singular: workflowtemplate
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
type: string
|
||||
kind:
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
type: object
|
||||
x-kubernetes-map-type: atomic
|
||||
x-kubernetes-preserve-unknown-fields: true
|
||||
required:
|
||||
- metadata
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
142
infrastructures/argo-workflows/base/deployment.yaml
Normal file
142
infrastructures/argo-workflows/base/deployment.yaml
Normal file
@@ -0,0 +1,142 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: argo-server
|
||||
namespace: argo
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: argo-server
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: argo-server
|
||||
spec:
|
||||
containers:
|
||||
- args:
|
||||
- server
|
||||
- --auth-mode
|
||||
- server
|
||||
- --auth-mode
|
||||
- client
|
||||
env: []
|
||||
image: quay.io/argoproj/argocli:v3.5.11
|
||||
name: argo-server
|
||||
ports:
|
||||
- containerPort: 2746
|
||||
name: web
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /
|
||||
port: 2746
|
||||
scheme: HTTPS
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 20
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
readOnlyRootFilesystem: true
|
||||
runAsNonRoot: true
|
||||
volumeMounts:
|
||||
- mountPath: /tmp
|
||||
name: tmp
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
kubernetes.io/arch: amd64
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
serviceAccountName: argo-server
|
||||
volumes:
|
||||
- emptyDir: {}
|
||||
name: tmp
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: workflow-controller
|
||||
namespace: argo
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: workflow-controller
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: workflow-controller
|
||||
spec:
|
||||
containers:
|
||||
- args: []
|
||||
command:
|
||||
- workflow-controller
|
||||
env:
|
||||
- name: LEADER_ELECTION_IDENTITY
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
apiVersion: v1
|
||||
fieldPath: metadata.name
|
||||
image: quay.io/argoproj/workflow-controller:v3.5.11
|
||||
livenessProbe:
|
||||
failureThreshold: 3
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: 6060
|
||||
initialDelaySeconds: 90
|
||||
periodSeconds: 60
|
||||
timeoutSeconds: 30
|
||||
name: workflow-controller
|
||||
ports:
|
||||
- containerPort: 9090
|
||||
name: metrics
|
||||
- containerPort: 6060
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
readOnlyRootFilesystem: true
|
||||
runAsNonRoot: true
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
kubernetes.io/arch: amd64
|
||||
priorityClassName: workflow-controller
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
serviceAccountName: argo
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
labels:
|
||||
app: httpbin
|
||||
name: httpbin
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: httpbin
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: httpbin
|
||||
spec:
|
||||
automountServiceAccountToken: false
|
||||
containers:
|
||||
- image: kong/httpbin
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /get
|
||||
port: 80
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
name: main
|
||||
ports:
|
||||
- containerPort: 80
|
||||
name: api
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /get
|
||||
port: 80
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
14
infrastructures/argo-workflows/base/kustomization.yaml
Normal file
14
infrastructures/argo-workflows/base/kustomization.yaml
Normal file
@@ -0,0 +1,14 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ./custom-resource-definition.yaml
|
||||
- ./service-account.yaml
|
||||
- ./role.yaml
|
||||
- ./cluster-role.yaml
|
||||
- ./role-binding.yaml
|
||||
- ./cluster-role-binding.yaml
|
||||
- ./configmap.yaml
|
||||
- ./secret.yaml
|
||||
- ./service.yaml
|
||||
- ./priority-class.yaml
|
||||
- ./deployment.yaml
|
||||
6
infrastructures/argo-workflows/base/priority-class.yaml
Normal file
6
infrastructures/argo-workflows/base/priority-class.yaml
Normal file
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: scheduling.k8s.io/v1
|
||||
kind: PriorityClass
|
||||
metadata:
|
||||
name: workflow-controller
|
||||
value: 1000000
|
||||
87
infrastructures/argo-workflows/base/role-binding.yaml
Normal file
87
infrastructures/argo-workflows/base/role-binding.yaml
Normal file
@@ -0,0 +1,87 @@
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: argo-binding
|
||||
namespace: argo
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: argo-role
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: argo
|
||||
namespace: argo
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: agent-default
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: agent
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: default
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: artifactgc-default
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: artifactgc
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: default
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: executor-default
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: executor
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: default
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: github.com
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: submit-workflow-template
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: github.com
|
||||
namespace: argo
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: pod-manager-default
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: pod-manager
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: default
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: workflow-manager-default
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: workflow-manager
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: default
|
||||
142
infrastructures/argo-workflows/base/role.yaml
Normal file
142
infrastructures/argo-workflows/base/role.yaml
Normal file
@@ -0,0 +1,142 @@
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: argo-role
|
||||
namespace: argo
|
||||
rules:
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
- leases
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
annotations:
|
||||
workflows.argoproj.io/description: |
|
||||
This is the minimum recommended permissions needed if you want to use the agent, e.g. for HTTP or plugin templates.
|
||||
|
||||
If <= v3.2 you must replace `workflowtasksets/status` with `patch workflowtasksets`.
|
||||
name: agent
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflowtasksets
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflowtasksets/status
|
||||
verbs:
|
||||
- patch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
annotations:
|
||||
workflows.argoproj.io/description: |
|
||||
This is the minimum recommended permissions needed if you want to use artifact GC.
|
||||
name: artifactgc
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflowartifactgctasks
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflowartifactgctasks/status
|
||||
verbs:
|
||||
- patch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
annotations:
|
||||
workflows.argoproj.io/description: |
|
||||
Recomended minimum permissions for the `emissary` executor.
|
||||
name: executor
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflowtaskresults
|
||||
verbs:
|
||||
- create
|
||||
- patch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
annotations:
|
||||
workflows.argoproj.io/description: |
|
||||
This is an example of the permissions you would need if you wanted to use a resource template to create and manage
|
||||
other pods. The same pattern would be suitable for other resurces, e.g. a service
|
||||
name: pod-manager
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- patch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: submit-workflow-template
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workfloweventbindings
|
||||
verbs:
|
||||
- list
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflowtemplates
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflows
|
||||
verbs:
|
||||
- create
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
annotations:
|
||||
workflows.argoproj.io/description: |
|
||||
This is an example of the permissions you would need if you wanted to use a resource template to create and manage
|
||||
other workflows. The same pattern would be suitable for other resurces, e.g. a service
|
||||
name: workflow-manager
|
||||
rules:
|
||||
- apiGroups:
|
||||
- argoproj.io
|
||||
resources:
|
||||
- workflows
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
16
infrastructures/argo-workflows/base/secret.yaml
Normal file
16
infrastructures/argo-workflows/base/secret.yaml
Normal file
@@ -0,0 +1,16 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: default
|
||||
name: default.service-account-token
|
||||
type: kubernetes.io/service-account-token
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: github.com
|
||||
name: github.com.service-account-token
|
||||
type: kubernetes.io/service-account-token
|
||||
17
infrastructures/argo-workflows/base/service-account.yaml
Normal file
17
infrastructures/argo-workflows/base/service-account.yaml
Normal file
@@ -0,0 +1,17 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: argo
|
||||
namespace: argo
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: argo-server
|
||||
namespace: argo
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: github.com
|
||||
32
infrastructures/argo-workflows/base/service.yaml
Normal file
32
infrastructures/argo-workflows/base/service.yaml
Normal file
@@ -0,0 +1,32 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
annotations:
|
||||
metallb.universe.tf/address-pool: k3s-cluster-ip-pool
|
||||
metallb.universe.tf/allow-shared-ip: k3s-cluster
|
||||
name: argo-server
|
||||
namespace: argo
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- name: web
|
||||
port: 2746
|
||||
targetPort: 2746
|
||||
selector:
|
||||
app: argo-server
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
labels:
|
||||
app: httpbin
|
||||
name: httpbin
|
||||
spec:
|
||||
ports:
|
||||
- name: api
|
||||
port: 9100
|
||||
protocol: TCP
|
||||
targetPort: 80
|
||||
selector:
|
||||
app: httpbin
|
||||
14
infrastructures/argo-workflows/env/k3s-cluster/config.json
vendored
Normal file
14
infrastructures/argo-workflows/env/k3s-cluster/config.json
vendored
Normal file
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"appName": "argo-workflows",
|
||||
"userGivenName": "argo-workflows",
|
||||
"namespace": "argo",
|
||||
"destNamespace": "argo",
|
||||
"destServer": "https://kubernetes.default.svc",
|
||||
"srcPath": "infrastructures/argo-workflows/env/k3s-cluster",
|
||||
"srcRepoURL": "https://github.com/3dwardch3ng/home-cluster-ops.git",
|
||||
"srcTargetRevision": "",
|
||||
"labels": null,
|
||||
"annotations": {
|
||||
"argo-workflows.argoproj.io/release-version": "v3.5.10"
|
||||
}
|
||||
}
|
||||
4
infrastructures/argo-workflows/env/k3s-cluster/kustomization.yaml
vendored
Normal file
4
infrastructures/argo-workflows/env/k3s-cluster/kustomization.yaml
vendored
Normal file
@@ -0,0 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
@@ -0,0 +1,23 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: clusterissuer
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
acme:
|
||||
email: "edward@cheng.sydney"
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
privateKeySecretRef:
|
||||
name: cluster-issuer-account-key
|
||||
solvers:
|
||||
- dns01:
|
||||
cloudflare:
|
||||
email: "edward@cheng.sydney"
|
||||
apiTokenSecretRef:
|
||||
name: clusterissuer-secrets
|
||||
namespace: cert-manager
|
||||
key: cloudflare_api_token
|
||||
selector:
|
||||
dnsNames:
|
||||
- "cluster.edward.sydney"
|
||||
- "*.cluster.edward.sydney"
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- clusterissuer-cloudflare.yaml
|
||||
4
infrastructures/cert-manager-clusterissuer/env/k3s-cluster/kustomization.yaml
vendored
Normal file
4
infrastructures/cert-manager-clusterissuer/env/k3s-cluster/kustomization.yaml
vendored
Normal file
@@ -0,0 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- ../../base
|
||||
8
infrastructures/cert-manager/base/kustomization.yaml
Normal file
8
infrastructures/cert-manager/base/kustomization.yaml
Normal file
@@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
helmCharts:
|
||||
- name: cert-manager
|
||||
repo: https://charts.jetstack.io
|
||||
version: v1.15.3
|
||||
releaseName: cert-manager
|
||||
valuesFile: values.yaml
|
||||
4
infrastructures/cert-manager/base/values.yaml
Normal file
4
infrastructures/cert-manager/base/values.yaml
Normal file
@@ -0,0 +1,4 @@
|
||||
global:
|
||||
priorityClassName: system-cluster-critical
|
||||
namespace: cert-manager
|
||||
installCRDs: true
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user