chore: Update manifests after change

This commit is contained in:
2026-04-09 01:19:56 +00:00
parent 9499756bb3
commit 37751a8d00
52 changed files with 1822 additions and 3 deletions

View File

@@ -0,0 +1,57 @@
apiVersion: postgresql.cnpg.io/v1
kind: Cluster
metadata:
name: kyoo-postgresql-18-cluster
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-postgresql-18-cluster
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
instances: 3
imageName: "ghcr.io/cloudnative-pg/postgresql:18.3-standard-trixie"
imagePullPolicy: IfNotPresent
postgresUID: 26
postgresGID: 26
storage:
size: 10Gi
storageClass: local-path
walStorage:
size: 2Gi
storageClass: local-path
resources:
limits:
hugepages-2Mi: 256Mi
requests:
cpu: 20m
memory: 80Mi
affinity:
enablePodAntiAffinity: true
topologyKey: kubernetes.io/hostname
primaryUpdateMethod: switchover
primaryUpdateStrategy: unsupervised
logLevel: info
enableSuperuserAccess: false
enablePDB: true
postgresql:
parameters:
hot_standby_feedback: "on"
max_slot_wal_keep_size: 2000MB
shared_buffers: 128MB
monitoring:
enablePodMonitor: true
disableDefaultQueries: false
plugins:
- name: barman-cloud.cloudnative-pg.io
enabled: true
isWALArchiver: true
parameters:
barmanObjectName: "kyoo-postgresql-18-backup-garage-local"
serverName: "kyoo-postgresql-18-backup-1"
bootstrap:
initdb:
database: app
owner: app

View File

@@ -0,0 +1,21 @@
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: kyoo-postgresql-18-database-kyoo-api
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-postgresql-18-database-kyoo-api
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
name: kyoo_api
cluster:
name: kyoo-postgresql-18-cluster
ensure: present
owner: app
template: template1
encoding: UTF8
databaseReclaimPolicy: retain

View File

@@ -0,0 +1,21 @@
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: kyoo-postgresql-18-database-kyoo-auth
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-postgresql-18-database-kyoo-auth
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
name: kyoo_auth
cluster:
name: kyoo-postgresql-18-cluster
ensure: present
owner: app
template: template1
encoding: UTF8
databaseReclaimPolicy: retain

View File

@@ -0,0 +1,21 @@
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: kyoo-postgresql-18-database-kyoo-scanner
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-postgresql-18-database-kyoo-scanner
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
name: kyoo_scanner
cluster:
name: kyoo-postgresql-18-cluster
ensure: present
owner: app
template: template1
encoding: UTF8
databaseReclaimPolicy: retain

View File

@@ -0,0 +1,21 @@
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: kyoo-postgresql-18-database-kyoo-transcoder
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-postgresql-18-database-kyoo-transcoder
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
name: kyoo_transcoder
cluster:
name: kyoo-postgresql-18-cluster
ensure: present
owner: app
template: template1
encoding: UTF8
databaseReclaimPolicy: retain

View File

@@ -0,0 +1,92 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: kyoo-api
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-api
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: api
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/name: kyoo-api
app.kubernetes.io/instance: kyoo
template:
metadata:
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-api
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: api
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
securityContext:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
serviceAccountName: kyoo-api
initContainers:
containers:
- name: main
image: ghcr.io/zoriya/kyoo_api:5.0.0@sha256:dc0210f235e23ae616b0f5952af7867dcbc52e0354c2683ec3c4190fdcd17744
imagePullPolicy: IfNotPresent
args:
env:
- name: JWT_ISSUER
value: "https://kyoo.alexlebens.net"
- name: AUTH_SERVER
value: "http://kyoo-auth:4568"
- name: TRANSCODER_SERVER
value: "http://kyoo-transcoder:7666"
- name: IMAGES_PATH
value: "/images"
- name: PGUSER
valueFrom:
secretKeyRef:
key: user
name: kyoo-postgresql-18-cluster-app
- name: PGPASSWORD
valueFrom:
secretKeyRef:
key: password
name: kyoo-postgresql-18-cluster-app
- name: PGDATABASE
value: "kyoo_api"
- name: PGHOST
value: "kyoo-postgresql-18-cluster-rw"
- name: PGPORT
value: "5432"
- name: PGSSLMODE
value: "disable"
ports:
- name: main
containerPort: 3567
protocol: TCP
livenessProbe:
httpGet:
path: /api/health
port: main
readinessProbe:
httpGet:
path: /api/ready
port: main
resources:
requests:
cpu: 10m
memory: 100Mi
volumeMounts:
- name: apiimagedata
mountPath: /images
volumes:
- name: apiimagedata
persistentVolumeClaim:
claimName: kyoo-apimetadata

View File

@@ -0,0 +1,133 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: kyoo-auth
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-auth
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: auth
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: kyoo-auth
app.kubernetes.io/instance: kyoo
template:
metadata:
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-auth
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: auth
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
securityContext:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
serviceAccountName: kyoo-auth
containers:
- name: main
image: ghcr.io/zoriya/kyoo_auth:5.0.0
imagePullPolicy: IfNotPresent
args:
env:
- name: EXTRA_CLAIMS
value: "{\"permissions\": [\"core.read\", \"core.play\"], \"verified\": false}"
- name: FIRST_USER_CLAIMS
value: "{\"permissions\": [\"users.read\", \"users.write\", \"apikeys.read\", \"apikeys.write\", \"users.delete\", \"core.read\", \"core.write\", \"core.play\", \"scanner.trigger\", \"scanner.guess\", \"scanner.search\", \"scanner.add\"], \"verified\": true}"
- name: GUEST_CLAIMS
value: "{\"permissions\": [\"core.read\"], \"verified\": true}"
- name: PROTECTED_CLAIMS
value: "permissions,verified"
- name: PUBLIC_URL
value: "https://kyoo.alexlebens.net"
- name: KEIBI_APIKEY_SCANNER
valueFrom:
secretKeyRef:
key: scanner-apikey
name: kyoo-key-secret
- name: KEIBI_APIKEY_SCANNER_CLAIMS
value: "{\"permissions\": [\"core.read\", \"core.write\"]}"
- name: PGUSER
valueFrom:
secretKeyRef:
key: user
name: kyoo-postgresql-18-cluster-app
- name: PGPASSWORD
valueFrom:
secretKeyRef:
key: password
name: kyoo-postgresql-18-cluster-app
- name: PGDATABASE
value: "kyoo_auth"
- name: PGHOST
value: "kyoo-postgresql-18-cluster-rw"
- name: PGPORT
value: "5432"
- name: PGSSLMODE
value: "disable"
- name: RSA_PRIVATE_KEY_PATH
value: /mnt/private_key/private_key.pem
- name: OIDC_AUTHENTIK_NAME
value: "Authentik"
- name: OIDC_AUTHENTIK_LOGO
value: "https://cdn.jsdelivr.net/gh/selfhst/icons@main/webp/authentik.webp"
- name: OIDC_AUTHENTIK_CLIENTID
valueFrom:
secretKeyRef:
key: client
name: kyoo-oidc-secret
- name: OIDC_AUTHENTIK_SECRET
valueFrom:
secretKeyRef:
key: secret
name: kyoo-oidc-secret
- name: OIDC_AUTHENTIK_AUTHORIZATION
value: "https://authentik.alexlebens.net/application/o/authorize/"
- name: OIDC_AUTHENTIK_TOKEN
value: "https://authentik.alexlebens.net/application/o/token/"
- name: OIDC_AUTHENTIK_PROFILE
value: "https://authentik.alexlebens.net/application/o/userinfo/"
- name: OIDC_AUTHENTIK_SCOPE
value: "email openid profile"
- name: OIDC_AUTHENTIK_AUTHMETHOD
value: "ClientSecretBasic"
ports:
- name: main
containerPort: 4568
protocol: TCP
livenessProbe:
httpGet:
path: /auth/health
port: main
readinessProbe:
httpGet:
path: /auth/ready
port: main
resources:
requests:
cpu: 10m
memory: 100Mi
volumeMounts:
- name: profilepictures
mountPath: /profile_pictures
- name: private-key
mountPath: /mnt/private_key
readOnly: true
volumes:
- name: profilepictures
persistentVolumeClaim:
claimName: kyoo-authprofile-pictures
- name: private-key
secret:
secretName: kyoo-key-secret
items:
- key: rsa-private
path: private_key.pem

View File

@@ -0,0 +1,50 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: kyoo-front
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-front
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: front
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: kyoo-front
app.kubernetes.io/instance: kyoo
template:
metadata:
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-front
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: front
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
securityContext:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
serviceAccountName: kyoo-front
containers:
- name: main
image: ghcr.io/zoriya/kyoo_front:5.0.0@sha256:985f892470b304f13ef1950fb5f7e9ef33ee39b71705c627cb045773e6dfb7b4
imagePullPolicy: IfNotPresent
args:
env:
- name: KYOO_URL
value: "http://kyoo-api:5000/api"
ports:
- name: main
containerPort: 8901
protocol: TCP
resources:
requests:
cpu: 10m
memory: 100Mi

View File

@@ -0,0 +1,139 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: kyoo-scanner
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-scanner
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: scanner
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: kyoo-scanner
app.kubernetes.io/instance: kyoo
template:
metadata:
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-scanner
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: scanner
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
securityContext:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
serviceAccountName: kyoo-scanner
containers:
- name: main
image: ghcr.io/zoriya/kyoo_scanner:5.0.0@sha256:fa972f3f1e534264f4de153e30fe9481839754a3e724cc2663524a2b30e82b46
imagePullPolicy: IfNotPresent
args:
env:
- name: SCANNER_LIBRARY_ROOT
value: "/media"
- name: LIBRARY_IGNORE_PATTERN
value: ".*/[dD]ownloads?/.*"
- name: KYOO_URL
value: "http://kyoo-traefik/api"
- name: JWKS_URL
value: "http://kyoo-auth:4568/.well-known/jwks.json"
- name: JWT_ISSUER
value: "https://kyoo.alexlebens.net"
- name: KYOO_APIKEY
valueFrom:
secretKeyRef:
key: scanner-apikey
name: kyoo-key-secret
- name: THEMOVIEDB_API_ACCESS_TOKEN
valueFrom:
secretKeyRef:
key: tmdb-apikey
name: kyoo-key-secret
optional: true
- name: PGUSER
valueFrom:
secretKeyRef:
key: user
name: kyoo-postgresql-18-cluster-app
- name: PGPASSWORD
valueFrom:
secretKeyRef:
key: password
name: kyoo-postgresql-18-cluster-app
- name: PGDATABASE
value: "kyoo_scanner"
- name: PGHOST
value: "kyoo-postgresql-18-cluster-rw"
- name: PGPORT
value: "5432"
- name: PGSSLMODE
value: "disable"
ports:
- name: main
containerPort: 4389
protocol: TCP
livenessProbe:
httpGet:
path: /health
port: main
readinessProbe:
httpGet:
path: /ready
port: main
resources:
requests:
cpu: 10m
memory: 100Mi
volumeMounts:
- mountPath: /media/anime
name: kyoo-media-anime-nfs-storage
readOnly: true
- mountPath: /media/anime-movies
name: kyoo-media-anime-movies-nfs-storage
readOnly: true
- mountPath: /media/movies
name: kyoo-media-movies-nfs-storage
readOnly: true
- mountPath: /media/movies-4k
name: kyoo-media-movies-4k-nfs-storage
readOnly: true
- mountPath: /media/standup
name: kyoo-media-standup-nfs-storage
readOnly: true
- mountPath: /media/tvshows
name: kyoo-media-tvshows-nfs-storage
readOnly: true
- mountPath: /media/tvshows-4k
name: kyoo-media-tvshows-4k-nfs-storage
readOnly: true
volumes:
- name: kyoo-media-anime-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-anime-nfs-storage
- name: kyoo-media-anime-movies-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-anime-movies-nfs-storage
- name: kyoo-media-movies-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-movies-nfs-storage
- name: kyoo-media-movies-4k-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-movies-4k-nfs-storage
- name: kyoo-media-standup-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-standup-nfs-storage
- name: kyoo-media-tvshows-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-tvshows-nfs-storage
- name: kyoo-media-tvshows-4k-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-tvshows-4k-nfs-storage

View File

@@ -0,0 +1,148 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: kyoo-transcoder
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-transcoder
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: transcoder
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/name: kyoo-transcoder
app.kubernetes.io/instance: kyoo
template:
metadata:
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-transcoder
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: transcoder
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
securityContext:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
serviceAccountName: kyoo-transcoder
containers:
- name: main
image: ghcr.io/zoriya/kyoo_transcoder:5.0.0@sha256:59974794f8a638175408fa20f023ba9598108b54ad8ed9a22ec87a1a211dfc43
imagePullPolicy: IfNotPresent
args:
env:
- name: JWKS_URL
value: "http://kyoo-auth:4568/.well-known/jwks.json"
- name: GOCODER_HWACCEL
value: "qsv"
- name: GOCODER_PRESET
value: "fast"
- name: GOCODER_CACHE_ROOT
value: "/cache"
- name: GOCODER_METADATA_ROOT
value: "/metadata"
- name: GOCODER_VAAPI_RENDERER
value: "/dev/dri/renderD128"
- name: GOCODER_QSV_RENDERER
value: "/dev/dri/renderD128"
- name: GOCODER_SAFE_PATH
value: "/media"
- name: PGUSER
valueFrom:
secretKeyRef:
key: user
name: kyoo-postgresql-18-cluster-app
- name: PGPASSWORD
valueFrom:
secretKeyRef:
key: password
name: kyoo-postgresql-18-cluster-app
- name: PGDATABASE
value: "kyoo_transcoder"
- name: PGHOST
value: "kyoo-postgresql-18-cluster-rw"
- name: PGPORT
value: "5432"
- name: PGSSLMODE
value: "disable"
ports:
- name: main
containerPort: 7666
protocol: TCP
livenessProbe:
httpGet:
path: /video/health
port: main
readinessProbe:
httpGet:
path: /video/ready
port: main
resources:
limits:
gpu.intel.com/i915: 1
requests:
cpu: 1
gpu.intel.com/i915: 1
memory: 1Gi
volumeMounts:
- mountPath: /media/anime
name: kyoo-media-anime-nfs-storage
readOnly: true
- mountPath: /media/anime-movies
name: kyoo-media-anime-movies-nfs-storage
readOnly: true
- mountPath: /media/movies
name: kyoo-media-movies-nfs-storage
readOnly: true
- mountPath: /media/movies-4k
name: kyoo-media-movies-4k-nfs-storage
readOnly: true
- mountPath: /media/standup
name: kyoo-media-standup-nfs-storage
readOnly: true
- mountPath: /media/tvshows
name: kyoo-media-tvshows-nfs-storage
readOnly: true
- mountPath: /media/tvshows-4k
name: kyoo-media-tvshows-4k-nfs-storage
readOnly: true
- name: transcodermetadata
mountPath: /metadata
- mountPath: /cache
name: cache
volumes:
- name: kyoo-media-anime-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-anime-nfs-storage
- name: kyoo-media-anime-movies-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-anime-movies-nfs-storage
- name: kyoo-media-movies-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-movies-nfs-storage
- name: kyoo-media-movies-4k-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-movies-4k-nfs-storage
- name: kyoo-media-standup-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-standup-nfs-storage
- name: kyoo-media-tvshows-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-tvshows-nfs-storage
- name: kyoo-media-tvshows-4k-nfs-storage
persistentVolumeClaim:
claimName: kyoo-media-tvshows-4k-nfs-storage
- name: transcodermetadata
persistentVolumeClaim:
claimName: kyoo-transcodermetadata
- emptyDir: {}
name: cache

View File

@@ -0,0 +1,30 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: kyoo-key-secret
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-key-secret
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
secretStoreRef:
kind: ClusterSecretStore
name: vault
data:
- secretKey: rsa-private
remoteRef:
key: /cl01tl/kyoo/key
property: rsa-private
- secretKey: scanner-apikey
remoteRef:
key: /cl01tl/kyoo/key
property: scanner
- secretKey: tmdb-apikey
remoteRef:
key: /tmdb/alexlebens
property: api-key
- secretKey: tvdb-apikey
remoteRef:
key: /tvdb/alexlebens
property: api-key

View File

@@ -0,0 +1,22 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: kyoo-oidc-secret
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-oidc-secret
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
secretStoreRef:
kind: ClusterSecretStore
name: vault
data:
- secretKey: rsa-private
remoteRef:
key: /authentik/oidc/kyoo
property: client
- secretKey: scanner-apikey
remoteRef:
key: /authentik/oidc/kyoo
property: secret

View File

@@ -0,0 +1,38 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: kyoo-postgresql-18-backup-garage-local-secret
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-postgresql-18-backup-garage-local-secret
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
secretStoreRef:
kind: ClusterSecretStore
name: vault
data:
- secretKey: ACCESS_REGION
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /garage/home-infra/postgres-backups
metadataPolicy: None
property: ACCESS_REGION
- secretKey: ACCESS_KEY_ID
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /garage/home-infra/postgres-backups
metadataPolicy: None
property: ACCESS_KEY_ID
- secretKey: ACCESS_SECRET_KEY
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /garage/home-infra/postgres-backups
metadataPolicy: None
property: ACCESS_SECRET_KEY

View File

@@ -0,0 +1,38 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: kyoo-postgresql-18-recovery-secret
namespace: kyoo
labels:
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: kyoo-postgresql-18-recovery-secret
spec:
secretStoreRef:
kind: ClusterSecretStore
name: vault
data:
- secretKey: ACCESS_REGION
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /garage/home-infra/postgres-backups
metadataPolicy: None
property: ACCESS_REGION
- secretKey: ACCESS_KEY_ID
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /garage/home-infra/postgres-backups
metadataPolicy: None
property: ACCESS_KEY_ID
- secretKey: ACCESS_SECRET_KEY
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /garage/home-infra/postgres-backups
metadataPolicy: None
property: ACCESS_SECRET_KEY

View File

@@ -0,0 +1,88 @@
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: kyoo
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: traefik-gateway
namespace: traefik
hostnames:
- kyoo.alexlebens.net
rules:
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- group: ''
kind: Service
name: front
port: 8901
weight: 100
- matches:
- path:
type: PathPrefix
value: /video
backendRefs:
- group: ''
kind: Service
name: transcoder
port: 7666
weight: 100
- matches:
- path:
type: PathPrefix
value: /auth/
backendRefs:
- group: ''
kind: Service
name: auth
port: 4568
weight: 100
- matches:
- path:
type: PathPrefix
value: /.well-known/
backendRefs:
- group: ''
kind: Service
name: auth
port: 4568
weight: 100
- matches:
- path:
type: PathPrefix
value: /api/
backendRefs:
- group: ''
kind: Service
name: api
port: 3567
weight: 100
- matches:
- path:
type: PathPrefix
value: /swagger
backendRefs:
- group: ''
kind: Service
name: api
port: 3567
weight: 100
- matches:
- path:
type: PathPrefix
value: /scanner/
backendRefs:
- group: ''
kind: Service
name: scanner
port: 4389
weight: 100

View File

@@ -0,0 +1,33 @@
apiVersion: barmancloud.cnpg.io/v1
kind: ObjectStore
metadata:
name: kyoo-postgresql-18-backup-garage-local
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-postgresql-18-backup-garage-local
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
retentionPolicy: 7d
instanceSidecarConfiguration:
env:
- name: AWS_REQUEST_CHECKSUM_CALCULATION
value: when_required
- name: AWS_RESPONSE_CHECKSUM_VALIDATION
value: when_required
configuration:
destinationPath: s3://postgres-backups/cl01tl/kyoo/kyoo-postgresql-18-cluster
endpointURL: http://garage-main.garage:3900
s3Credentials:
accessKeyId:
name: kyoo-postgresql-18-backup-garage-local-secret
key: ACCESS_KEY_ID
secretAccessKey:
name: kyoo-postgresql-18-backup-garage-local-secret
key: ACCESS_SECRET_KEY
region:
name: kyoo-postgresql-18-backup-garage-local-secret
key: ACCESS_REGION

View File

@@ -0,0 +1,32 @@
apiVersion: barmancloud.cnpg.io/v1
kind: ObjectStore
metadata:
name: "kyoo-postgresql-18-recovery"
namespace: kyoo
labels:
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: "kyoo-postgresql-18-recovery"
spec:
configuration:
destinationPath: s3://postgres-backups/cl01tl/kyoo/kyoo-postgresql-18-cluster
endpointURL: http://garage-main.garage:3900
wal:
compression: snappy
maxParallel: 1
data:
compression: snappy
jobs: 1
s3Credentials:
accessKeyId:
name: kyoo-postgresql-18-recovery-secret
key: ACCESS_KEY_ID
secretAccessKey:
name: kyoo-postgresql-18-recovery-secret
key: ACCESS_SECRET_KEY
region:
name: kyoo-postgresql-18-recovery-secret
key: ACCESS_REGION

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: PersistentVolume
metadata:
name: kyoo-media-anime-movies-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-anime-movies-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs-client
capacity:
storage: 1Gi
accessModes:
- ReadWriteMany
nfs:
path: /volume2/Storage/Anime Movies
server: synologybond.alexlebens.net
mountOptions:
- vers=4
- minorversion=1
- noac

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: PersistentVolume
metadata:
name: kyoo-media-anime-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-anime-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs-client
capacity:
storage: 1Gi
accessModes:
- ReadWriteMany
nfs:
path: /volume2/Storage/Anime
server: synologybond.alexlebens.net
mountOptions:
- vers=4
- minorversion=1
- noac

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: PersistentVolume
metadata:
name: kyoo-media-movies-4k-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-movies-4k-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs-client
capacity:
storage: 1Gi
accessModes:
- ReadWriteMany
nfs:
path: /volume2/Storage/Movies 4K
server: synologybond.alexlebens.net
mountOptions:
- vers=4
- minorversion=1
- noac

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: PersistentVolume
metadata:
name: kyoo-media-movies-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-movies-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs-client
capacity:
storage: 1Gi
accessModes:
- ReadWriteMany
nfs:
path: /volume2/Storage/Movies
server: synologybond.alexlebens.net
mountOptions:
- vers=4
- minorversion=1
- noac

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: PersistentVolume
metadata:
name: kyoo-media-standup-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-standup-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs-client
capacity:
storage: 1Gi
accessModes:
- ReadWriteMany
nfs:
path: /volume2/Storage/Stand Up
server: synologybond.alexlebens.net
mountOptions:
- vers=4
- minorversion=1
- noac

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: PersistentVolume
metadata:
name: kyoo-media-tvshows-4k-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-tvshows-4k-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs-client
capacity:
storage: 1Gi
accessModes:
- ReadWriteMany
nfs:
path: /volume2/Storage/TV Shows
server: synologybond.alexlebens.net
mountOptions:
- vers=4
- minorversion=1
- noac

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: PersistentVolume
metadata:
name: kyoo-media-tvshows-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-tvshows-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs-client
capacity:
storage: 1Gi
accessModes:
- ReadWriteMany
nfs:
path: /volume2/Storage/TV Shows
server: synologybond.alexlebens.net
mountOptions:
- vers=4
- minorversion=1
- noac

View File

@@ -0,0 +1,20 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-apimetadata
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-api
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: api
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
storageClassName: ceph-block

View File

@@ -0,0 +1,20 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-authprofile-pictures
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-auth
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: auth
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 500Mi
storageClassName: ceph-block

View File

@@ -0,0 +1,17 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-media-anime-movies-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-anime-movies-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
volumeName: kyoo-media-anime-movies-nfs-storage
storageClassName: nfs-client
accessModes:
- ReadWriteMany
resources:
requests:
storage: 1Gi

View File

@@ -0,0 +1,17 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-media-anime-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-anime-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
volumeName: kyoo-media-anime-nfs-storage
storageClassName: nfs-client
accessModes:
- ReadWriteMany
resources:
requests:
storage: 1Gi

View File

@@ -0,0 +1,17 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-media-movies-4k-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-movies-4k-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
volumeName: kyoo-media-movies-4k-nfs-storage
storageClassName: nfs-client
accessModes:
- ReadWriteMany
resources:
requests:
storage: 1Gi

View File

@@ -0,0 +1,17 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-media-movies-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-movies-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
volumeName: kyoo-media-movies-nfs-storage
storageClassName: nfs-client
accessModes:
- ReadWriteMany
resources:
requests:
storage: 1Gi

View File

@@ -0,0 +1,17 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-media-standup-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-standup-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
volumeName: kyoo-media-standup-nfs-storage
storageClassName: nfs-client
accessModes:
- ReadWriteMany
resources:
requests:
storage: 1Gi

View File

@@ -0,0 +1,17 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-media-tvshows-4k-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-tvshows-4k-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
volumeName: kyoo-media-tvshows-4k-nfs-storage
storageClassName: nfs-client
accessModes:
- ReadWriteMany
resources:
requests:
storage: 1Gi

View File

@@ -0,0 +1,17 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-media-tvshows-nfs-storage
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-media-tvshows-nfs-storage
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
spec:
volumeName: kyoo-media-tvshows-nfs-storage
storageClassName: nfs-client
accessModes:
- ReadWriteMany
resources:
requests:
storage: 1Gi

View File

@@ -0,0 +1,20 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: kyoo-transcodermetadata
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-transcoder
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: transcoder
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
storageClassName: ceph-block

View File

@@ -0,0 +1,270 @@
apiVersion: monitoring.coreos.com/v1
kind: PrometheusRule
metadata:
name: kyoo-postgresql-18-alert-rules
namespace: kyoo
labels:
app.kubernetes.io/name: kyoo-postgresql-18-alert-rules
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
groups:
- name: cloudnative-pg/kyoo-postgresql-18
rules:
- alert: CNPGClusterBackendsWaitingWarning
annotations:
summary: CNPG Cluster a backend is waiting for longer than 5 minutes.
description: |-
Pod {{ $labels.pod }}
has been waiting for longer than 5 minutes
expr: |
cnpg_backends_waiting_total{namespace="kyoo"} > 300
for: 1m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterDatabaseDeadlockConflictsWarning
annotations:
summary: CNPG Cluster has over 10 deadlock conflicts.
description: |-
There are over 10 deadlock conflicts in
{{ $labels.pod }}
expr: |
cnpg_pg_stat_database_deadlocks{namespace="kyoo"} > 10
for: 1m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterHACritical
annotations:
summary: CNPG Cluster has no standby replicas!
description: |-
CloudNativePG Cluster "{{`{{`}} $labels.job {{`}}`}}" has no ready standby replicas. Your cluster at a severe
risk of data loss and downtime if the primary instance fails.
The primary instance is still online and able to serve queries, although connections to the `-ro` endpoint
will fail. The `-r` endpoint os operating at reduced capacity and all traffic is being served by the main.
This can happen during a normal fail-over or automated minor version upgrades in a cluster with 2 or less
instances. The replaced instance may need some time to catch-up with the cluster primary instance.
This alarm will be always trigger if your cluster is configured to run with only 1 instance. In this
case you may want to silence it.
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterHACritical.md
expr: |
max by (job) (cnpg_pg_replication_streaming_replicas{namespace="kyoo"} - cnpg_pg_replication_is_wal_receiver_up{namespace="kyoo"}) < 1
for: 5m
labels:
severity: critical
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterHAWarning
annotations:
summary: CNPG Cluster less than 2 standby replicas.
description: |-
CloudNativePG Cluster "{{`{{`}} $labels.job {{`}}`}}" has only {{`{{`}} $value {{`}}`}} standby replicas, putting
your cluster at risk if another instance fails. The cluster is still able to operate normally, although
the `-ro` and `-r` endpoints operate at reduced capacity.
This can happen during a normal fail-over or automated minor version upgrades. The replaced instance may
need some time to catch-up with the cluster primary instance.
This alarm will be constantly triggered if your cluster is configured to run with less than 3 instances.
In this case you may want to silence it.
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterHAWarning.md
expr: |
max by (job) (cnpg_pg_replication_streaming_replicas{namespace="kyoo"} - cnpg_pg_replication_is_wal_receiver_up{namespace="kyoo"}) < 2
for: 5m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterHighConnectionsCritical
annotations:
summary: CNPG Instance maximum number of connections critical!
description: |-
CloudNativePG Cluster "kyoo/kyoo-postgresql-18-cluster" instance {{`{{`}} $labels.pod {{`}}`}} is using {{`{{`}} $value {{`}}`}}% of
the maximum number of connections.
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterHighConnectionsCritical.md
expr: |
sum by (pod) (cnpg_backends_total{namespace="kyoo", pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"}) / max by (pod) (cnpg_pg_settings_setting{name="max_connections", namespace="kyoo", pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"}) * 100 > 95
for: 5m
labels:
severity: critical
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterHighConnectionsWarning
annotations:
summary: CNPG Instance is approaching the maximum number of connections.
description: |-
CloudNativePG Cluster "kyoo/kyoo-postgresql-18-cluster" instance {{`{{`}} $labels.pod {{`}}`}} is using {{`{{`}} $value {{`}}`}}% of
the maximum number of connections.
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterHighConnectionsWarning.md
expr: |
sum by (pod) (cnpg_backends_total{namespace="kyoo", pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"}) / max by (pod) (cnpg_pg_settings_setting{name="max_connections", namespace="kyoo", pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"}) * 100 > 80
for: 5m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterHighReplicationLag
annotations:
summary: CNPG Cluster high replication lag
description: |-
CloudNativePG Cluster "kyoo/kyoo-postgresql-18-cluster" is experiencing a high replication lag of
{{`{{`}} $value {{`}}`}}ms.
High replication lag indicates network issues, busy instances, slow queries or suboptimal configuration.
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterHighReplicationLag.md
expr: |
max(cnpg_pg_replication_lag{namespace="kyoo",pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"}) * 1000 > 1000
for: 5m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterInstancesOnSameNode
annotations:
summary: CNPG Cluster instances are located on the same node.
description: |-
CloudNativePG Cluster "kyoo/kyoo-postgresql-18-cluster" has {{`{{`}} $value {{`}}`}}
instances on the same node {{`{{`}} $labels.node {{`}}`}}.
A failure or scheduled downtime of a single node will lead to a potential service disruption and/or data loss.
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterInstancesOnSameNode.md
expr: |
count by (node) (kube_pod_info{namespace="kyoo", pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"}) > 1
for: 5m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterLongRunningTransactionWarning
annotations:
summary: CNPG Cluster query is taking longer than 5 minutes.
description: |-
CloudNativePG Cluster Pod {{ $labels.pod }}
is taking more than 5 minutes (300 seconds) for a query.
expr: |-
cnpg_backends_max_tx_duration_seconds{namespace="kyoo"} > 300
for: 1m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterLowDiskSpaceCritical
annotations:
summary: CNPG Instance is running out of disk space!
description: |-
CloudNativePG Cluster "kyoo/kyoo-postgresql-18-cluster" is running extremely low on disk space. Check attached PVCs!
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterLowDiskSpaceCritical.md
expr: |
max(max by(persistentvolumeclaim) (1 - kubelet_volume_stats_available_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"} / kubelet_volume_stats_capacity_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"})) > 0.9 OR
max(max by(persistentvolumeclaim) (1 - kubelet_volume_stats_available_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$-wal"} / kubelet_volume_stats_capacity_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$-wal"})) > 0.9 OR
max(sum by (namespace,persistentvolumeclaim) (kubelet_volume_stats_used_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$-tbs.*"})
/
sum by (namespace,persistentvolumeclaim) (kubelet_volume_stats_capacity_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$-tbs.*"})
*
on(namespace, persistentvolumeclaim) group_left(volume)
kube_pod_spec_volumes_persistentvolumeclaims_info{pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"}
) > 0.9
for: 5m
labels:
severity: critical
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterLowDiskSpaceWarning
annotations:
summary: CNPG Instance is running out of disk space.
description: |-
CloudNativePG Cluster "kyoo/kyoo-postgresql-18-cluster" is running low on disk space. Check attached PVCs.
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterLowDiskSpaceWarning.md
expr: |
max(max by(persistentvolumeclaim) (1 - kubelet_volume_stats_available_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"} / kubelet_volume_stats_capacity_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"})) > 0.7 OR
max(max by(persistentvolumeclaim) (1 - kubelet_volume_stats_available_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$-wal"} / kubelet_volume_stats_capacity_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$-wal"})) > 0.7 OR
max(sum by (namespace,persistentvolumeclaim) (kubelet_volume_stats_used_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$-tbs.*"})
/
sum by (namespace,persistentvolumeclaim) (kubelet_volume_stats_capacity_bytes{namespace="kyoo", persistentvolumeclaim=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$-tbs.*"})
*
on(namespace, persistentvolumeclaim) group_left(volume)
kube_pod_spec_volumes_persistentvolumeclaims_info{pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"}
) > 0.7
for: 5m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterOffline
annotations:
summary: CNPG Cluster has no running instances!
description: |-
CloudNativePG Cluster "kyoo/kyoo-postgresql-18-cluster" has no ready instances.
Having an offline cluster means your applications will not be able to access the database, leading to
potential service disruption and/or data loss.
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterOffline.md
expr: |
(count(cnpg_collector_up{namespace="kyoo",pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"}) OR on() vector(0)) == 0
for: 5m
labels:
severity: critical
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterPGDatabaseXidAgeWarning
annotations:
summary: CNPG Cluster has a number of transactions from the frozen XID to the current one.
description: |-
Over 300,000,000 transactions from frozen xid
on pod {{ $labels.pod }}
expr: |
cnpg_pg_database_xid_age{namespace="kyoo"} > 300000000
for: 1m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterPGReplicationWarning
annotations:
summary: CNPG Cluster standby is lagging behind the primary.
description: |-
Standby is lagging behind by over 300 seconds (5 minutes)
expr: |
cnpg_pg_replication_lag{namespace="kyoo"} > 300
for: 1m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterReplicaFailingReplicationWarning
annotations:
summary: CNPG Cluster has a replica is failing to replicate.
description: |-
Replica {{ $labels.pod }}
is failing to replicate
expr: |
cnpg_pg_replication_in_recovery{namespace="kyoo"} > cnpg_pg_replication_is_wal_receiver_up{namespace="kyoo"}
for: 1m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster
- alert: CNPGClusterZoneSpreadWarning
annotations:
summary: CNPG Cluster instances in the same zone.
description: |-
CloudNativePG Cluster "kyoo/kyoo-postgresql-18-cluster" has instances in the same availability zone.
A disaster in one availability zone will lead to a potential service disruption and/or data loss.
runbook_url: https://github.com/cloudnative-pg/charts/blob/main/charts/cluster/docs/runbooks/CNPGClusterZoneSpreadWarning.md
expr: |
3 > count(count by (label_topology_kubernetes_io_zone) (kube_pod_info{namespace="kyoo", pod=~"kyoo-postgresql-18-cluster-([1-9][0-9]*)$"} * on(node,instance) group_left(label_topology_kubernetes_io_zone) kube_node_labels)) < 3
for: 5m
labels:
severity: warning
namespace: kyoo
cnpg_cluster: kyoo-postgresql-18-cluster

View File

@@ -0,0 +1,24 @@
apiVersion: postgresql.cnpg.io/v1
kind: ScheduledBackup
metadata:
name: "kyoo-postgresql-18-scheduled-backup-live-backup"
namespace: kyoo
labels:
app.kubernetes.io/name: "kyoo-postgresql-18-scheduled-backup-live-backup"
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: kyoo
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
immediate: true
suspend: false
schedule: "0 5 14 * * *"
backupOwnerReference: self
cluster:
name: kyoo-postgresql-18-cluster
method: plugin
pluginConfiguration:
name: barman-cloud.cloudnative-pg.io
parameters:
barmanObjectName: "kyoo-postgresql-18-backup-garage-local"

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: Service
metadata:
name: kyoo-api
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-api
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: api
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
type: ClusterIP
ports:
- port: 3567
targetPort: 3567
protocol: TCP
name: main
selector:
app.kubernetes.io/name: kyoo-api
app.kubernetes.io/instance: kyoo

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: Service
metadata:
name: kyoo-auth
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-auth
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: auth
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
type: ClusterIP
ports:
- port: 4568
targetPort: 4568
protocol: TCP
name: main
selector:
app.kubernetes.io/name: kyoo-auth
app.kubernetes.io/instance: kyoo

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: Service
metadata:
name: kyoo-front
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-front
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: front
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
type: ClusterIP
ports:
- port: 8901
targetPort: 8901
protocol: TCP
name: main
selector:
app.kubernetes.io/name: kyoo-front
app.kubernetes.io/instance: kyoo

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: Service
metadata:
name: kyoo-scanner
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-scanner
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: scanner
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
type: ClusterIP
ports:
- port: 4389
targetPort: 4389
protocol: TCP
name: main
selector:
app.kubernetes.io/name: kyoo-scanner
app.kubernetes.io/instance: kyoo

View File

@@ -0,0 +1,23 @@
apiVersion: v1
kind: Service
metadata:
name: kyoo-transcoder
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-transcoder
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: transcoder
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"
spec:
type: ClusterIP
ports:
- port: 7666
targetPort: 7666
protocol: TCP
name: main
selector:
app.kubernetes.io/name: kyoo-transcoder
app.kubernetes.io/instance: kyoo

View File

@@ -0,0 +1,14 @@
apiVersion: v1
kind: ServiceAccount
automountServiceAccountToken: true
metadata:
name: kyoo-api
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-api
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: api
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"

View File

@@ -0,0 +1,14 @@
apiVersion: v1
kind: ServiceAccount
automountServiceAccountToken: true
metadata:
name: kyoo-auth
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-auth
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: auth
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"

View File

@@ -0,0 +1,14 @@
apiVersion: v1
kind: ServiceAccount
automountServiceAccountToken: true
metadata:
name: kyoo-front
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-front
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: front
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"

View File

@@ -0,0 +1,14 @@
apiVersion: v1
kind: ServiceAccount
automountServiceAccountToken: true
metadata:
name: kyoo-scanner
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-scanner
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: scanner
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"

View File

@@ -0,0 +1,14 @@
apiVersion: v1
kind: ServiceAccount
automountServiceAccountToken: true
metadata:
name: kyoo-transcoder
namespace: kyoo
labels:
helm.sh/chart: kyoo-5.0.0
app.kubernetes.io/name: kyoo-transcoder
app.kubernetes.io/instance: kyoo
app.kubernetes.io/component: transcoder
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/part-of: kyoo
app.kubernetes.io/version: "5.0.0"