Merge pull request 'Automated Manifest Update' (#5706) from auto/update-manifests into manifests
Reviewed-on: #5706
This commit was merged in pull request #5706.
This commit is contained in:
@@ -58,7 +58,7 @@ spec:
|
|||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 50m
|
cpu: 50m
|
||||||
memory: 90Mi
|
memory: 512Mi
|
||||||
image: hashicorp/vault:1.21.4@sha256:4e33b126a59c0c333b76fb4e894722462659a6bec7c48c9ee8cea56fccfd2569
|
image: hashicorp/vault:1.21.4@sha256:4e33b126a59c0c333b76fb4e894722462659a6bec7c48c9ee8cea56fccfd2569
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
command:
|
command:
|
||||||
@@ -102,8 +102,6 @@ spec:
|
|||||||
- name: HOME
|
- name: HOME
|
||||||
value: "/home/vault"
|
value: "/home/vault"
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: audit
|
|
||||||
mountPath: /vault/audit
|
|
||||||
- name: data
|
- name: data
|
||||||
mountPath: /vault/data
|
mountPath: /vault/data
|
||||||
- name: config
|
- name: config
|
||||||
@@ -147,14 +145,3 @@ spec:
|
|||||||
requests:
|
requests:
|
||||||
storage: 1Gi
|
storage: 1Gi
|
||||||
storageClassName: ceph-block
|
storageClassName: ceph-block
|
||||||
- apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: audit
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 5Gi
|
|
||||||
storageClassName: ceph-block
|
|
||||||
|
|||||||
@@ -64,7 +64,7 @@ spec:
|
|||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
key: secret
|
key: secret
|
||||||
name: vaultwarden-oidc-secret
|
name: vaultwarden-oidc-secret
|
||||||
image: ghcr.io/vaultwarden/server:1.35.4@sha256:43498a94b22f9563f2a94b53760ab3e710eefc0d0cac2efda4b12b9eb8690664
|
image: ghcr.io/dani-garcia/vaultwarden:1.35.4@sha256:43498a94b22f9563f2a94b53760ab3e710eefc0d0cac2efda4b12b9eb8690664
|
||||||
name: main
|
name: main
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
|
|||||||
@@ -47,7 +47,7 @@ spec:
|
|||||||
- --metrics-require-rbac=false
|
- --metrics-require-rbac=false
|
||||||
command:
|
command:
|
||||||
- /manager
|
- /manager
|
||||||
image: "0.15.0@sha256:4fedd41b3101dde090542009c4177f703d241bf4760d1767bd9df08fd8fd93a4"
|
image: "quay.io/backube/volsync:0.15.0@sha256:4fedd41b3101dde090542009c4177f703d241bf4760d1767bd9df08fd8fd93a4"
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
env:
|
env:
|
||||||
- name: VOLSYNC_NAMESPACE
|
- name: VOLSYNC_NAMESPACE
|
||||||
|
|||||||
@@ -39,10 +39,9 @@ spec:
|
|||||||
value: ollama-server-2.ollama
|
value: ollama-server-2.ollama
|
||||||
- name: WHODB_OLLAMA_PORT
|
- name: WHODB_OLLAMA_PORT
|
||||||
value: "11434"
|
value: "11434"
|
||||||
image: clidey/whodb:0.104.0
|
image: clidey/whodb:0.104.0@sha256:ab485c021b862aac50bb88658f3342ca01d3eba33e933353692bc9989b2912c4
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
name: main
|
name: main
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 10m
|
cpu: 1m
|
||||||
memory: 256Mi
|
memory: 20Mi
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
name: whodb
|
name: whodb
|
||||||
namespace: whodb
|
namespace: whodb
|
||||||
port: 80
|
port: 80
|
||||||
weight: 100
|
weight: 1
|
||||||
matches:
|
matches:
|
||||||
- path:
|
- path:
|
||||||
type: PathPrefix
|
type: PathPrefix
|
||||||
|
|||||||
@@ -5,10 +5,10 @@ metadata:
|
|||||||
namespace: yamtrack
|
namespace: yamtrack
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: yamtrack-postgresql-18-cluster
|
app.kubernetes.io/name: yamtrack-postgresql-18-cluster
|
||||||
helm.sh/chart: postgres-18-cluster-7.10.0
|
helm.sh/chart: postgres-18-cluster-7.11.2
|
||||||
app.kubernetes.io/instance: yamtrack
|
app.kubernetes.io/instance: yamtrack
|
||||||
app.kubernetes.io/part-of: yamtrack
|
app.kubernetes.io/part-of: yamtrack
|
||||||
app.kubernetes.io/version: "7.10.0"
|
app.kubernetes.io/version: "7.11.2"
|
||||||
app.kubernetes.io/managed-by: Helm
|
app.kubernetes.io/managed-by: Helm
|
||||||
spec:
|
spec:
|
||||||
instances: 3
|
instances: 3
|
||||||
@@ -26,8 +26,8 @@ spec:
|
|||||||
limits:
|
limits:
|
||||||
hugepages-2Mi: 256Mi
|
hugepages-2Mi: 256Mi
|
||||||
requests:
|
requests:
|
||||||
cpu: 100m
|
cpu: 20m
|
||||||
memory: 256Mi
|
memory: 80Mi
|
||||||
affinity:
|
affinity:
|
||||||
enablePodAntiAffinity: true
|
enablePodAntiAffinity: true
|
||||||
topologyKey: kubernetes.io/hostname
|
topologyKey: kubernetes.io/hostname
|
||||||
|
|||||||
@@ -36,7 +36,7 @@ spec:
|
|||||||
containers:
|
containers:
|
||||||
- env:
|
- env:
|
||||||
- name: TZ
|
- name: TZ
|
||||||
value: US/Central
|
value: America/Chicago
|
||||||
- name: URLS
|
- name: URLS
|
||||||
value: https://yamtrack.alexlebens.net
|
value: https://yamtrack.alexlebens.net
|
||||||
- name: REGISTRATION
|
- name: REGISTRATION
|
||||||
@@ -80,10 +80,9 @@ spec:
|
|||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
key: port
|
key: port
|
||||||
name: yamtrack-postgresql-18-cluster-app
|
name: yamtrack-postgresql-18-cluster-app
|
||||||
image: ghcr.io/fuzzygrim/yamtrack:0.25.0
|
image: ghcr.io/fuzzygrim/yamtrack:0.25.0@sha256:df76008258452a6cda73d971dc4ffbcbca96c5220154a02c9b70bf0bb0e24931
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
name: main
|
name: main
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 10m
|
cpu: 10m
|
||||||
memory: 256Mi
|
memory: 380Mi
|
||||||
|
|||||||
@@ -14,8 +14,5 @@ spec:
|
|||||||
data:
|
data:
|
||||||
- secretKey: SECRET
|
- secretKey: SECRET
|
||||||
remoteRef:
|
remoteRef:
|
||||||
conversionStrategy: Default
|
|
||||||
decodingStrategy: None
|
|
||||||
key: /cl01tl/yamtrack/config
|
key: /cl01tl/yamtrack/config
|
||||||
metadataPolicy: None
|
|
||||||
property: SECRET
|
property: SECRET
|
||||||
|
|||||||
@@ -14,8 +14,5 @@ spec:
|
|||||||
data:
|
data:
|
||||||
- secretKey: SOCIALACCOUNT_PROVIDERS
|
- secretKey: SOCIALACCOUNT_PROVIDERS
|
||||||
remoteRef:
|
remoteRef:
|
||||||
conversionStrategy: Default
|
|
||||||
decodingStrategy: None
|
|
||||||
key: /authentik/oidc/yamtrack
|
key: /authentik/oidc/yamtrack
|
||||||
metadataPolicy: None
|
|
||||||
property: SOCIALACCOUNT_PROVIDERS
|
property: SOCIALACCOUNT_PROVIDERS
|
||||||
|
|||||||
@@ -5,10 +5,10 @@ metadata:
|
|||||||
namespace: yamtrack
|
namespace: yamtrack
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: yamtrack-postgresql-18-backup-garage-local-secret
|
app.kubernetes.io/name: yamtrack-postgresql-18-backup-garage-local-secret
|
||||||
helm.sh/chart: postgres-18-cluster-7.10.0
|
helm.sh/chart: postgres-18-cluster-7.11.2
|
||||||
app.kubernetes.io/instance: yamtrack
|
app.kubernetes.io/instance: yamtrack
|
||||||
app.kubernetes.io/part-of: yamtrack
|
app.kubernetes.io/part-of: yamtrack
|
||||||
app.kubernetes.io/version: "7.10.0"
|
app.kubernetes.io/version: "7.11.2"
|
||||||
app.kubernetes.io/managed-by: Helm
|
app.kubernetes.io/managed-by: Helm
|
||||||
spec:
|
spec:
|
||||||
secretStoreRef:
|
secretStoreRef:
|
||||||
|
|||||||
@@ -4,10 +4,10 @@ metadata:
|
|||||||
name: yamtrack-postgresql-18-recovery-secret
|
name: yamtrack-postgresql-18-recovery-secret
|
||||||
namespace: yamtrack
|
namespace: yamtrack
|
||||||
labels:
|
labels:
|
||||||
helm.sh/chart: postgres-18-cluster-7.10.0
|
helm.sh/chart: postgres-18-cluster-7.11.2
|
||||||
app.kubernetes.io/instance: yamtrack
|
app.kubernetes.io/instance: yamtrack
|
||||||
app.kubernetes.io/part-of: yamtrack
|
app.kubernetes.io/part-of: yamtrack
|
||||||
app.kubernetes.io/version: "7.10.0"
|
app.kubernetes.io/version: "7.11.2"
|
||||||
app.kubernetes.io/managed-by: Helm
|
app.kubernetes.io/managed-by: Helm
|
||||||
app.kubernetes.io/name: yamtrack-postgresql-18-recovery-secret
|
app.kubernetes.io/name: yamtrack-postgresql-18-recovery-secret
|
||||||
spec:
|
spec:
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
name: yamtrack
|
name: yamtrack
|
||||||
namespace: yamtrack
|
namespace: yamtrack
|
||||||
port: 80
|
port: 80
|
||||||
weight: 100
|
weight: 1
|
||||||
matches:
|
matches:
|
||||||
- path:
|
- path:
|
||||||
type: PathPrefix
|
type: PathPrefix
|
||||||
|
|||||||
@@ -5,10 +5,10 @@ metadata:
|
|||||||
namespace: yamtrack
|
namespace: yamtrack
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: yamtrack-postgresql-18-backup-garage-local
|
app.kubernetes.io/name: yamtrack-postgresql-18-backup-garage-local
|
||||||
helm.sh/chart: postgres-18-cluster-7.10.0
|
helm.sh/chart: postgres-18-cluster-7.11.2
|
||||||
app.kubernetes.io/instance: yamtrack
|
app.kubernetes.io/instance: yamtrack
|
||||||
app.kubernetes.io/part-of: yamtrack
|
app.kubernetes.io/part-of: yamtrack
|
||||||
app.kubernetes.io/version: "7.10.0"
|
app.kubernetes.io/version: "7.11.2"
|
||||||
app.kubernetes.io/managed-by: Helm
|
app.kubernetes.io/managed-by: Helm
|
||||||
spec:
|
spec:
|
||||||
retentionPolicy: 7d
|
retentionPolicy: 7d
|
||||||
|
|||||||
@@ -4,10 +4,10 @@ metadata:
|
|||||||
name: "yamtrack-postgresql-18-recovery"
|
name: "yamtrack-postgresql-18-recovery"
|
||||||
namespace: yamtrack
|
namespace: yamtrack
|
||||||
labels:
|
labels:
|
||||||
helm.sh/chart: postgres-18-cluster-7.10.0
|
helm.sh/chart: postgres-18-cluster-7.11.2
|
||||||
app.kubernetes.io/instance: yamtrack
|
app.kubernetes.io/instance: yamtrack
|
||||||
app.kubernetes.io/part-of: yamtrack
|
app.kubernetes.io/part-of: yamtrack
|
||||||
app.kubernetes.io/version: "7.10.0"
|
app.kubernetes.io/version: "7.11.2"
|
||||||
app.kubernetes.io/managed-by: Helm
|
app.kubernetes.io/managed-by: Helm
|
||||||
app.kubernetes.io/name: "yamtrack-postgresql-18-recovery"
|
app.kubernetes.io/name: "yamtrack-postgresql-18-recovery"
|
||||||
spec:
|
spec:
|
||||||
|
|||||||
@@ -5,10 +5,10 @@ metadata:
|
|||||||
namespace: yamtrack
|
namespace: yamtrack
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: yamtrack-postgresql-18-alert-rules
|
app.kubernetes.io/name: yamtrack-postgresql-18-alert-rules
|
||||||
helm.sh/chart: postgres-18-cluster-7.10.0
|
helm.sh/chart: postgres-18-cluster-7.11.2
|
||||||
app.kubernetes.io/instance: yamtrack
|
app.kubernetes.io/instance: yamtrack
|
||||||
app.kubernetes.io/part-of: yamtrack
|
app.kubernetes.io/part-of: yamtrack
|
||||||
app.kubernetes.io/version: "7.10.0"
|
app.kubernetes.io/version: "7.11.2"
|
||||||
app.kubernetes.io/managed-by: Helm
|
app.kubernetes.io/managed-by: Helm
|
||||||
spec:
|
spec:
|
||||||
groups:
|
groups:
|
||||||
|
|||||||
@@ -5,10 +5,10 @@ metadata:
|
|||||||
namespace: yamtrack
|
namespace: yamtrack
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: "yamtrack-postgresql-18-scheduled-backup-live-backup"
|
app.kubernetes.io/name: "yamtrack-postgresql-18-scheduled-backup-live-backup"
|
||||||
helm.sh/chart: postgres-18-cluster-7.10.0
|
helm.sh/chart: postgres-18-cluster-7.11.2
|
||||||
app.kubernetes.io/instance: yamtrack
|
app.kubernetes.io/instance: yamtrack
|
||||||
app.kubernetes.io/part-of: yamtrack
|
app.kubernetes.io/part-of: yamtrack
|
||||||
app.kubernetes.io/version: "7.10.0"
|
app.kubernetes.io/version: "7.11.2"
|
||||||
app.kubernetes.io/managed-by: Helm
|
app.kubernetes.io/managed-by: Helm
|
||||||
spec:
|
spec:
|
||||||
immediate: true
|
immediate: true
|
||||||
|
|||||||
@@ -95,7 +95,7 @@ spec:
|
|||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 10m
|
cpu: 10m
|
||||||
memory: 128Mi
|
memory: 20Mi
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: valkey-data
|
- name: valkey-data
|
||||||
mountPath: /data
|
mountPath: /data
|
||||||
@@ -117,8 +117,8 @@ spec:
|
|||||||
port: metrics
|
port: metrics
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 10m
|
cpu: 1m
|
||||||
memory: 64M
|
memory: 10M
|
||||||
env:
|
env:
|
||||||
- name: REDIS_ALIAS
|
- name: REDIS_ALIAS
|
||||||
value: yamtrack-valkey
|
value: yamtrack-valkey
|
||||||
|
|||||||
@@ -31,6 +31,7 @@ spec:
|
|||||||
automountServiceAccountToken: true
|
automountServiceAccountToken: true
|
||||||
securityContext:
|
securityContext:
|
||||||
fsGroup: 1000
|
fsGroup: 1000
|
||||||
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
runAsGroup: 1000
|
runAsGroup: 1000
|
||||||
runAsUser: 1000
|
runAsUser: 1000
|
||||||
hostIPC: false
|
hostIPC: false
|
||||||
@@ -48,12 +49,11 @@ spec:
|
|||||||
- name: YUBAL_LOG_LEVEL
|
- name: YUBAL_LOG_LEVEL
|
||||||
value: INFO
|
value: INFO
|
||||||
image: ghcr.io/guillevc/yubal:0.7.2@sha256:906b7c90b738e77ad140178f6a5145f98c12af36e8321d427148c092836c37be
|
image: ghcr.io/guillevc/yubal:0.7.2@sha256:906b7c90b738e77ad140178f6a5145f98c12af36e8321d427148c092836c37be
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
name: main
|
name: main
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: 10m
|
cpu: 10m
|
||||||
memory: 128Mi
|
memory: 200Mi
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- mountPath: /app/config
|
- mountPath: /app/config
|
||||||
name: config
|
name: config
|
||||||
|
|||||||
@@ -1,42 +0,0 @@
|
|||||||
apiVersion: external-secrets.io/v1
|
|
||||||
kind: ExternalSecret
|
|
||||||
metadata:
|
|
||||||
name: yubal-wireguard-conf
|
|
||||||
namespace: yubal
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: yubal-wireguard-conf
|
|
||||||
app.kubernetes.io/instance: yubal
|
|
||||||
app.kubernetes.io/part-of: yubal
|
|
||||||
spec:
|
|
||||||
secretStoreRef:
|
|
||||||
kind: ClusterSecretStore
|
|
||||||
name: vault
|
|
||||||
data:
|
|
||||||
- secretKey: private-key
|
|
||||||
remoteRef:
|
|
||||||
conversionStrategy: Default
|
|
||||||
decodingStrategy: None
|
|
||||||
key: /airvpn/conf/cl01tl
|
|
||||||
metadataPolicy: None
|
|
||||||
property: private-key
|
|
||||||
- secretKey: preshared-key
|
|
||||||
remoteRef:
|
|
||||||
conversionStrategy: Default
|
|
||||||
decodingStrategy: None
|
|
||||||
key: /airvpn/conf/cl01tl
|
|
||||||
metadataPolicy: None
|
|
||||||
property: preshared-key
|
|
||||||
- secretKey: addresses
|
|
||||||
remoteRef:
|
|
||||||
conversionStrategy: Default
|
|
||||||
decodingStrategy: None
|
|
||||||
key: /airvpn/conf/cl01tl
|
|
||||||
metadataPolicy: None
|
|
||||||
property: addresses
|
|
||||||
- secretKey: input-ports
|
|
||||||
remoteRef:
|
|
||||||
conversionStrategy: Default
|
|
||||||
decodingStrategy: None
|
|
||||||
key: /airvpn/conf/cl01tl
|
|
||||||
metadataPolicy: None
|
|
||||||
property: input-ports
|
|
||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
name: yubal
|
name: yubal
|
||||||
namespace: yubal
|
namespace: yubal
|
||||||
port: 80
|
port: 80
|
||||||
weight: 100
|
weight: 1
|
||||||
matches:
|
matches:
|
||||||
- path:
|
- path:
|
||||||
type: PathPrefix
|
type: PathPrefix
|
||||||
|
|||||||
@@ -1,11 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: yubal
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: yubal
|
|
||||||
app.kubernetes.io/instance: yubal
|
|
||||||
app.kubernetes.io/part-of: yubal
|
|
||||||
pod-security.kubernetes.io/audit: privileged
|
|
||||||
pod-security.kubernetes.io/enforce: privileged
|
|
||||||
pod-security.kubernetes.io/warn: privileged
|
|
||||||
@@ -7,8 +7,6 @@ metadata:
|
|||||||
app.kubernetes.io/managed-by: Helm
|
app.kubernetes.io/managed-by: Helm
|
||||||
app.kubernetes.io/name: yubal
|
app.kubernetes.io/name: yubal
|
||||||
helm.sh/chart: yubal-4.6.2
|
helm.sh/chart: yubal-4.6.2
|
||||||
annotations:
|
|
||||||
helm.sh/resource-policy: keep
|
|
||||||
namespace: yubal
|
namespace: yubal
|
||||||
spec:
|
spec:
|
||||||
accessModes:
|
accessModes:
|
||||||
|
|||||||
Reference in New Issue
Block a user