From e2d4b1edf3ca119fa117bbe4dc7708efa3551b06 Mon Sep 17 00:00:00 2001 From: gitea-bot Date: Thu, 4 Dec 2025 01:12:52 +0000 Subject: [PATCH] chore: Update manifests after change --- .../argo-workflows/argo-workflows.yaml | 44 +-- clusters/cl01tl/manifests/cilium/cilium.yaml | 16 +- clusters/cl01tl/manifests/garage/garage.yaml | 42 +-- clusters/cl01tl/manifests/harbor/harbor.yaml | 8 +- .../cl01tl/manifests/karakeep/karakeep.yaml | 2 +- .../matrix-synapse/matrix-synapse.yaml | 4 +- clusters/cl01tl/manifests/n8n/n8n.yaml | 54 +-- clusters/cl01tl/manifests/ollama/ollama.yaml | 326 +++++++++--------- .../manifests/qbittorrent/qbittorrent.yaml | 196 +++++------ .../manifests/s3-exporter/s3-exporter.yaml | 138 ++++---- .../cl01tl/manifests/searxng/searxng.yaml | 4 +- clusters/cl01tl/manifests/talos/talos.yaml | 144 ++++---- clusters/cl01tl/manifests/vault/vault.yaml | 96 +++--- 13 files changed, 537 insertions(+), 537 deletions(-) diff --git a/clusters/cl01tl/manifests/argo-workflows/argo-workflows.yaml b/clusters/cl01tl/manifests/argo-workflows/argo-workflows.yaml index 57b3d7fd9..2dab811e5 100644 --- a/clusters/cl01tl/manifests/argo-workflows/argo-workflows.yaml +++ b/clusters/cl01tl/manifests/argo-workflows/argo-workflows.yaml @@ -7,7 +7,7 @@ metadata: name: argo-workflows-argo-events-controller-manager namespace: "argo-workflows" labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-controller-manager app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: controller-manager @@ -22,7 +22,7 @@ metadata: name: argo-workflows-argo-events-events-webhook namespace: "argo-workflows" labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-events-webhook app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: events-webhook @@ -66,7 +66,7 @@ metadata: name: argo-workflows-argo-events-controller-manager namespace: "argo-workflows" labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-controller-manager app.kubernetes.io/instance: argo-workflows app.kubernetes.io/managed-by: Helm @@ -3079,7 +3079,7 @@ kind: ClusterRole metadata: name: argo-workflows-argo-events-controller-manager labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-controller-manager app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: controller-manager @@ -3173,7 +3173,7 @@ kind: ClusterRole metadata: name: argo-events-webhook labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-events-webhook app.kubernetes.io/instance: argo-workflows app.kubernetes.io/managed-by: Helm @@ -3671,7 +3671,7 @@ kind: ClusterRoleBinding metadata: name: argo-workflows-argo-events-controller-manager labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-controller-manager app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: controller-manager @@ -3692,7 +3692,7 @@ kind: ClusterRoleBinding metadata: name: argo-workflows-argo-events-events-webhook labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-events-webhook app.kubernetes.io/instance: argo-workflows app.kubernetes.io/managed-by: Helm @@ -3893,7 +3893,7 @@ metadata: name: argo-workflows-argo-events-controller-manager-metrics namespace: "argo-workflows" labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-controller-manager-metrics app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: controller-manager @@ -3916,7 +3916,7 @@ metadata: name: events-webhook namespace: "argo-workflows" labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-events-webhook app.kubernetes.io/instance: argo-workflows app.kubernetes.io/managed-by: Helm @@ -4004,13 +4004,13 @@ metadata: name: argo-workflows-argo-events-controller-manager namespace: "argo-workflows" labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-controller-manager app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: controller-manager app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: argo-events - app.kubernetes.io/version: "v1.9.8" + app.kubernetes.io/version: "v1.9.9" spec: selector: matchLabels: @@ -4021,25 +4021,25 @@ spec: template: metadata: annotations: - checksum/config: f6a1927c244b342165a873cdc9d662816fc3abe8ddd10d2cb5f6f6aa3b5553f0 + checksum/config: a98b80a2ffaf4c020ec162c5614927614c17e0ea3fea1999358dd37203b01d58 labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-controller-manager app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: controller-manager app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: argo-events - app.kubernetes.io/version: "v1.9.8" + app.kubernetes.io/version: "v1.9.9" spec: containers: - name: controller-manager - image: quay.io/argoproj/argo-events:v1.9.8 + image: quay.io/argoproj/argo-events:v1.9.9 imagePullPolicy: IfNotPresent args: - controller env: - name: ARGO_EVENTS_IMAGE - value: quay.io/argoproj/argo-events:v1.9.8 + value: quay.io/argoproj/argo-events:v1.9.9 - name: NAMESPACE valueFrom: fieldRef: @@ -4089,13 +4089,13 @@ metadata: name: events-webhook namespace: "argo-workflows" labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-events-webhook app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: events-webhook app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: argo-events - app.kubernetes.io/version: "v1.9.8" + app.kubernetes.io/version: "v1.9.9" spec: selector: matchLabels: @@ -4106,17 +4106,17 @@ spec: template: metadata: labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-events-webhook app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: events-webhook app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: argo-events - app.kubernetes.io/version: "v1.9.8" + app.kubernetes.io/version: "v1.9.9" spec: containers: - name: events-webhook - image: quay.io/argoproj/argo-events:v1.9.8 + image: quay.io/argoproj/argo-events:v1.9.9 imagePullPolicy: IfNotPresent args: - webhook-service @@ -4978,7 +4978,7 @@ metadata: name: argo-workflows-argo-events-controller-manager namespace: "argo-workflows" labels: - helm.sh/chart: argo-events-2.4.17 + helm.sh/chart: argo-events-2.4.18 app.kubernetes.io/name: argo-events-controller-manager app.kubernetes.io/instance: argo-workflows app.kubernetes.io/component: controller-manager diff --git a/clusters/cl01tl/manifests/cilium/cilium.yaml b/clusters/cl01tl/manifests/cilium/cilium.yaml index 851471fee..d27e5ac0b 100644 --- a/clusters/cl01tl/manifests/cilium/cilium.yaml +++ b/clusters/cl01tl/manifests/cilium/cilium.yaml @@ -51,8 +51,8 @@ metadata: name: cilium-ca namespace: kube-system data: - ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURFekNDQWZ1Z0F3SUJBZ0lRYUJaS0paekdId3VDMjY0dHBhY0kwakFOQmdrcWhraUc5dzBCQVFzRkFEQVUKTVJJd0VBWURWUVFERXdsRGFXeHBkVzBnUTBFd0hoY05NalV4TWpBME1EQTBOelF3V2hjTk1qZ3hNakF6TURBMApOelF3V2pBVU1SSXdFQVlEVlFRREV3bERhV3hwZFcwZ1EwRXdnZ0VpTUEwR0NTcUdTSWIzRFFFQkFRVUFBNElCCkR3QXdnZ0VLQW9JQkFRQ1JRZUU2ZEZPMHo1dDd1ZmFmUG90KytKTmk5SzRITEcwRmRwN1BEZG9yS0hDR0lPRFEKL3ZjNUlHazNIMllvU1drUHJGNitGMlRHK1JVS1JYaHJKQkVqdkt6R0krbHVpazhLUUdYN051eGs5ckg4bDluMwowSFhtWXhKcE5xcW4rRDBWTUwwN0pFSWtYV1M0MFhoSDh2cmNuTkE4dHljdlZFb3NXUnZReEJjaFFJVUVFd3RGCk1UbTI4WHBjTi82N2JkbC92cHhtdGxiZWlkVElPWW03b3M3NUtJem1KSGJ2L2wzS01hTytKT2t5UE5pc3dad0sKNURTMkpqYUtyZGYvWUhLSC85U3hHSFFTS1hoT3ZmTy80cGNualFSc2hiUG1GTzJ0TVdURVFJZVNJV0NncEcvWApiY3J0N2c0bGxZTStFdkpmNGsyMFR3d1FNakhTQ2NMM05vRUZBZ01CQUFHallUQmZNQTRHQTFVZER3RUIvd1FFCkF3SUNwREFkQmdOVkhTVUVGakFVQmdnckJnRUZCUWNEQVFZSUt3WUJCUVVIQXdJd0R3WURWUjBUQVFIL0JBVXcKQXdFQi96QWRCZ05WSFE0RUZnUVU2TnRlYW1VZWJjWHp0OC96Q2NNZGZRdHp6Und3RFFZSktvWklodmNOQVFFTApCUUFEZ2dFQkFGTCtCWU1TemRPVkJ3Sks0VVdXNENaM1l3TGtKblpYSi9mYkFqcFFRNlFVZnVoSU1yR2xGb3lICjRXYlNxWXY1OGxMd2JYemo4T2ZzdnBHN0t2Y0FzM2VvL2lOdDdDeVMrQTdGbFRBZVZzQW14STd3NGd1MHB4ZHgKLzF5NFYxZ1ZjdVhrdXRYUkpZT016cmppU05pUkRWN2pwUFVSL1hZVWp2THVlT0twLzJXUExxakdsditUemIxZgpxN2V1S3RiMGFhMWRZYWsrNEhMYVo4blUwN2ZuK3RDL0M2TzJndUdtWXg0OFkweGRKMWpqSERDU0tGcmdnaE53CnBkTWJTcTZ1NVNFVmwrVEZ5ZXZoY0x0SStudmFZRlhqSGRFamo1TjBDUjdaY3FkSEZaN3AyaXMzcXpVYTZ0ekwKZVFkck9vRU5iWEEweSsrYXdqd1h1ZFZPcXYwUGE3ST0KLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= - ca.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb2dJQkFBS0NBUUVBa1VIaE9uUlR0TStiZTduMm56NkxmdmlUWXZTdUJ5eHRCWGFlenczYUt5aHdoaURnCjBQNzNPU0JwTng5bUtFbHBENnhldmhka3h2a1ZDa1Y0YXlRUkk3eXN4aVBwYm9wUENrQmwremJzWlBheC9KZloKOTlCMTVtTVNhVGFxcC9nOUZUQzlPeVJDSkYxa3VORjRSL0w2M0p6UVBMY25MMVJLTEZrYjBNUVhJVUNGQkJNTApSVEU1dHZGNlhEZit1MjNaZjc2Y1pyWlczb25VeURtSnU2TE8rU2lNNWlSMjcvNWR5akdqdmlUcE1qellyTUdjCkN1UTB0aVkyaXEzWC8yQnloLy9Vc1JoMEVpbDRUcjN6ditLWEo0MEViSVd6NWhUdHJURmt4RUNIa2lGZ29LUnYKMTIzSzdlNE9KWldEUGhMeVgrSk50RThNRURJeDBnbkM5emFCQlFJREFRQUJBb0lCQUVBMXFRUVg2L0NmWFJIQwpVSnh3SDJYUEtBZTBOVUdDaCtiRVdzc1lTbnFOYzhBMnhHcGVhcFpjRjJhQWdMNEtSV0RpUnpjc1RDWVFjUmFMClF3SEpmYklZY3g5YlBKTGFuTG5oWWJNOHdoNlhWbkpjQmNRZjZCNGhhVUFOSkQ3LzRyQjlUUWpackVzNjVZMDEKTzBCQ3psVzdFK25pNUhWdGd5UTdkNm8vSkNKVUlud3ZMWGxqQTRrV1dXNU5sdXIyai9jVVJIY2Y3dVQzWlJycwpwSDI5WnFINmpoeHpLOXZIY3Zoek1panpsRnY3ci9vNTd5TUwzRzZNV1hyYUJuL1psRTBqVk9tZ2RDRStKcVBkCklGUVpKcmRsMExaVXhMTEJXd2hQN01RZ1N0b2VxTkhKajNVdnlzRjJoaS9tQUMzSXJYbEljNHpWQ0tGaFVTakoKNkxLdlgva0NnWUVBd05aNDkzRWk4QjlKYkJzTGVRNGxRbU9yWVZaU3h0SlFrb2lUaXg4WmVWSzRRQ0Y0VzRIWgprU0F0ZGVQTk9BLyt2NE9LeFptTDRqRVFJelI0L0NJbFFKVENkcWFucGNTWDJOT2JYNmlYK2h6dllCWWxoQzJ5CnRPVzZ0MFZWVWRUUXFtdmFXU0k1N0tWak9LVGlUNDQrYzlpdCtpWHJFM09NSzBINWhhUHRaTDhDZ1lFQXdOWEUKakw3QlJxem1wb1gzdUlTK3lEbzAwSGFPUG5FRFNJNGpjaWc2ZU9vSGRjd1E3blhvbEZKeFlNVFJqblpab2tXOQpiVGxZd0VrOHJKS1ozazNoa2xvK2JXUDYzNENBVWxxWnJaNUpNVDhIMHJZVkF4bFcrN3pyOTRlSXVZdGtYNzVrClBrV25oaDM1TENibVJ3cUtVMGdUVXB1eGh1bzN3WlVTd1BPMDl6c0NnWUFYMy9YbUhObkloUGNnTFZFRVVkNEgKRkRQNXZ5aE1lV21FV3VoNWh3WXVZVEZ5cnpJcGtqQVBxYjQzSkZjYUk5RFVnVUxES0RtTGJhdWowREZTZGgvSwptU0JpZEV1NVdGZThmcVp6OTNtcGU3K2ZVOTZkT05NeFZtZ0JuTkh0YWIzVCs3cHk0cXZ0UXFUQU5KbllZN0lUCndiWDRqSTFJUVR3UGR3R2ZyQ1lPSFFLQmdBZERCWmZYUnlnR010bHFpaDJrd2hxQU5xVHpFZ0EvK1VPdU5wK0IKN0ZISlhtYU5QTVgrSXJnVE1ybldMNTRSenVaUmdnU3UrQ3lsbFdkYVRma1ZMYjE1TUlpbUR6aURlbEdmbjlIdAorQXVtdUFDellxOHZNUnRoemZFUVpaRzNNaHg0NndWOVVnVzI4ejg2WjhtZEdBQnk0bWRsL1pWN0ZJWnh1cmNSCmRtc3BBb0dBRFhxQmYzTGZMaDhCcjRkR3d2N1d6Z3hHbFJFMHJ2b3VmeWdWSUw0MjQrbk54aFpuTDM3N29NdSsKVlhvT3hsZkR4bHVOdnpNdVBQWkJxZHVERE9YTDJIRFA3RSs4MjhsbTg0Yzl4aWVnaTUvTUUrU2JoWmRQREk1dgpKdVI4d3FZSzBzY0JwQUJzY0lSNkowN0hoUDBTRDB6MmNkQklncHR4TDRncVhqelc4Z3c9Ci0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg== + ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURGRENDQWZ5Z0F3SUJBZ0lSQUpUODAxYzVDQWRObi9wQTcrNzVTdFV3RFFZSktvWklodmNOQVFFTEJRQXcKRkRFU01CQUdBMVVFQXhNSlEybHNhWFZ0SUVOQk1CNFhEVEkxTVRJd05EQXhNRFV6TUZvWERUSTRNVEl3TXpBeApNRFV6TUZvd0ZERVNNQkFHQTFVRUF4TUpRMmxzYVhWdElFTkJNSUlCSWpBTkJna3Foa2lHOXcwQkFRRUZBQU9DCkFROEFNSUlCQ2dLQ0FRRUFzYXJVaDNwVjI0ekhQWkFoVXZPeExHNnN3MzFoMUlyTU9MelZzamdrSHA3OXFXWXYKY0R5U1BMSlBZUjRwZU9lMmgvTWJjN0lUQVMrR0MrcTJwRGFKOU9WcXdCV2xzVmUxWm1rZUVuSldFeUV6bE5VYgpBclRiVzFDbkdMUlBVZzljOFhJUDFHYnRGekE3TEF4UEZpWG5ZTW8yVDRMcU5xMGhtU2F2UUdBQTM0VzhQSHd0CkI2UHRkdDlTK0pjRzFSS05HR1A2K3N6U0NDWm5IR09TM2EvM2J5aml1WXdJckF1Mk82amt6WHMwU2pWQlhtNm4Kd1JJblBhTGFvNjNoL2pqR05SaVJMZ21BWjBEZzBKWi8xdDNoVW1iV3RTU25qUTZWcklKdFZFVnZwOEZpV3FYcwpKOHJOR2RJVDBKQjAxSFZMRTlpVlRYM1p4R1VtZ1VhdG5ZemM2UUlEQVFBQm8yRXdYekFPQmdOVkhROEJBZjhFCkJBTUNBcVF3SFFZRFZSMGxCQll3RkFZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQndNQ01BOEdBMVVkRXdFQi93UUYKTUFNQkFmOHdIUVlEVlIwT0JCWUVGQ1F6R2g5YlU3RldLWHcrMk10ZXBWKzBSTEgwTUEwR0NTcUdTSWIzRFFFQgpDd1VBQTRJQkFRQmJIMjJ1OG5ic0ZYdWxZbkZOdjF2bVpsTGI2bmVIbFkwaitwNGZ1Zk5vaDZkWmlxRXNtc0FoCjloZ2c2d3dmeUIwK2QwNTBwbFhXSW4velFnTkRoWXdsY2M3TTRVWlI4aGhjVTZEb3pLaHpCV1VFaFI4aVBCYkkKWjVSZ3l3VWE1a3Yvbmtndi9jM2dEUGUxZEFyVitieVZxYlJGOVdQaGRlREFwWlM5cTNscVd2TmxjQkVGaVBYMgpqNVd1VlZnVmFvT2VNZ0k3UFBZOWZRK0k2STBsR3o1eFlVNnRZTk5BTko3UmlXdjhOakQzdzRSdHBXOFJ3SWtJClhadHhZQnllU3BGQTJ5SUNlaUdNSmNhNTlHRkp3ZDFMbkJ5dENPTzRZdHpPTThWdEYrbkJ3Nm5sMjBFa09lYzkKelYwK0JZb1cxWXZwbVFVUk8xRCs0OXBpR3ZIUlBpMTgKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= + ca.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb3dJQkFBS0NBUUVBc2FyVWgzcFYyNHpIUFpBaFV2T3hMRzZzdzMxaDFJck1PTHpWc2pna0hwNzlxV1l2CmNEeVNQTEpQWVI0cGVPZTJoL01iYzdJVEFTK0dDK3EycERhSjlPVnF3Qldsc1ZlMVpta2VFbkpXRXlFemxOVWIKQXJUYlcxQ25HTFJQVWc5YzhYSVAxR2J0RnpBN0xBeFBGaVhuWU1vMlQ0THFOcTBobVNhdlFHQUEzNFc4UEh3dApCNlB0ZHQ5UytKY0cxUktOR0dQNitzelNDQ1puSEdPUzNhLzNieWppdVl3SXJBdTJPNmprelhzMFNqVkJYbTZuCndSSW5QYUxhbzYzaC9qakdOUmlSTGdtQVowRGcwSlovMXQzaFVtYld0U1NualE2VnJJSnRWRVZ2cDhGaVdxWHMKSjhyTkdkSVQwSkIwMUhWTEU5aVZUWDNaeEdVbWdVYXRuWXpjNlFJREFRQUJBb0lCQUZEZFpUQm9vUTExelBXYgpWVitSSlZJSTZiOXNvUXVCUlNTSjVtWGdvYWdDUzRnL3gxVzViQUlPVW96c2tvbkNSVlVwZEpRN04rVXhRVHpKClR1bjlITnVIVkFncmtpZmV1T1RzOFZBS0ZGMU9ubENla2xXd0JhdFJVVXl3UE80bnFmRUhMbWRKbFo0WlNNVnEKc05CdTNob3l6M2R2S2JWTEplQzBOODRBSkVXWHNnZ3htVmRrRDVINlc4SFhKMVRSUXdFcW1qSU0weVU1RHp2UQpOdFhBY09Sdi9sZnluOHZ6T0xtYURqOGU0czdaMXJzb01jMU5wQkN2SSt1bFNvVVFQUlZ2K25Lek1wR29XV3pICnd1VWJSazE2SXlmQy85VUd0RmRGbjdlL05FRTdldURkRmI3SFgxTElkQjJndFpJZTFHUEJTWXVXYjg5UlluMUQKaVYxbElDVUNnWUVBMTRiNFd6emt4azRXcFJtc2JLaXVnaWlTVHRmVk1qOW84cDEzV3V0QTZVVTJTc0F6a1RyTwpGTGJkYVo0MmNIYU5yVCt5UjJNRW4rTHJhMjFISkRSWXFKNGp0TkY1QTVPaU9sWkFhdjVFbDR4bFAwU2FybmtkCmlJcVBzRE5VUXVBZEJwU1RmeHBjaHI2V3ZHNmRQVXBIb3lFTGJwMC9oYjYxNytlMEZha0hhQjhDZ1lFQTB3ZlMKWnhBc2RQVUVNTmZDYy9jb21GRXdKSW84d3RlY2dQNGR6MC8rd25YNmtZVkp2ZHJUK2tUeDNNRTNuaGZHWkhpdgo0NzJBT0FJMjc0Mm53Q0RrbWxPd01mYTJtVjBtcVQrelljTG85Q2FFdVJNR2dVTEhhRFVxQnBidWV1WjlLWks3CnR0bzRMaFdkVHdGeHMxS3pBTEZIVllYYkd2cGpkWnJ2M21HM3VmY0NnWUJNYkxET2NZWlNCMGlpWExzMmdJMzQKMjNnZCt3eS9WNXJZUlJ3WW9ra1BMcHEwNFBpb0srajlrV1pyMkUxSGpkSnBONmY1QmxTU2VYMnZSejJ0eWQ0UwpWSmttdWd5bVJ3aUVsU2NjaVhNN0plNlZBN2V4M0lLcmN5N0dkVDBReGJXbEtyUXVvdU5pYUZ5OURxQTFKb3pHCmZLWTRJQXh4V1pIY014WTVoQWw3VXdLQmdRQytVQnlJdzhaRUI3OHF5VG5kV1RWc0FEUDVrQTF4N2Y1L09penEKREl1RkZkN09JN1U0R2NQM3ZQdWVDVVkrTmRTK1FUVG1ucnltUmlFQzh1NG96OEU2Q0dVcStnTDgxa3dLY0o4MgplQStjTjZ5VU43c3pFV1ZCN2tnalB6Ujg4NlpHdXNTOUI1bUl2Z2RxKzdOdGRCUm9lSGdMZ2JieVlvTVZ5WSt2Ckx0TUJTd0tCZ0RJWUV2NDBaLzFCNzA2OEU3UjRRWGowYkRsQUttM21KaXlJQ1JaMU85RUlha1Z6bktwVmZBeEIKN2VzbGZXUkw1WlBHWmNHZWw3ek52V1RralBScWNDWmdGWEVZRmNHNVl3Z2NLRGM3MzFaWGpTdjlrUHNkZjVTTApmdm5zWTlodTNEY1Z5aU9oSFlSejh6UlgxSEsxSEVoNDFIQTJHV2kyazJPQU16RXFvUTM4Ci0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg== --- # Source: cilium/charts/cilium/templates/hubble/tls-helm/relay-client-secret.yaml apiVersion: v1 @@ -62,9 +62,9 @@ metadata: namespace: kube-system type: kubernetes.io/tls data: - ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURFekNDQWZ1Z0F3SUJBZ0lRYUJaS0paekdId3VDMjY0dHBhY0kwakFOQmdrcWhraUc5dzBCQVFzRkFEQVUKTVJJd0VBWURWUVFERXdsRGFXeHBkVzBnUTBFd0hoY05NalV4TWpBME1EQTBOelF3V2hjTk1qZ3hNakF6TURBMApOelF3V2pBVU1SSXdFQVlEVlFRREV3bERhV3hwZFcwZ1EwRXdnZ0VpTUEwR0NTcUdTSWIzRFFFQkFRVUFBNElCCkR3QXdnZ0VLQW9JQkFRQ1JRZUU2ZEZPMHo1dDd1ZmFmUG90KytKTmk5SzRITEcwRmRwN1BEZG9yS0hDR0lPRFEKL3ZjNUlHazNIMllvU1drUHJGNitGMlRHK1JVS1JYaHJKQkVqdkt6R0krbHVpazhLUUdYN051eGs5ckg4bDluMwowSFhtWXhKcE5xcW4rRDBWTUwwN0pFSWtYV1M0MFhoSDh2cmNuTkE4dHljdlZFb3NXUnZReEJjaFFJVUVFd3RGCk1UbTI4WHBjTi82N2JkbC92cHhtdGxiZWlkVElPWW03b3M3NUtJem1KSGJ2L2wzS01hTytKT2t5UE5pc3dad0sKNURTMkpqYUtyZGYvWUhLSC85U3hHSFFTS1hoT3ZmTy80cGNualFSc2hiUG1GTzJ0TVdURVFJZVNJV0NncEcvWApiY3J0N2c0bGxZTStFdkpmNGsyMFR3d1FNakhTQ2NMM05vRUZBZ01CQUFHallUQmZNQTRHQTFVZER3RUIvd1FFCkF3SUNwREFkQmdOVkhTVUVGakFVQmdnckJnRUZCUWNEQVFZSUt3WUJCUVVIQXdJd0R3WURWUjBUQVFIL0JBVXcKQXdFQi96QWRCZ05WSFE0RUZnUVU2TnRlYW1VZWJjWHp0OC96Q2NNZGZRdHp6Und3RFFZSktvWklodmNOQVFFTApCUUFEZ2dFQkFGTCtCWU1TemRPVkJ3Sks0VVdXNENaM1l3TGtKblpYSi9mYkFqcFFRNlFVZnVoSU1yR2xGb3lICjRXYlNxWXY1OGxMd2JYemo4T2ZzdnBHN0t2Y0FzM2VvL2lOdDdDeVMrQTdGbFRBZVZzQW14STd3NGd1MHB4ZHgKLzF5NFYxZ1ZjdVhrdXRYUkpZT016cmppU05pUkRWN2pwUFVSL1hZVWp2THVlT0twLzJXUExxakdsditUemIxZgpxN2V1S3RiMGFhMWRZYWsrNEhMYVo4blUwN2ZuK3RDL0M2TzJndUdtWXg0OFkweGRKMWpqSERDU0tGcmdnaE53CnBkTWJTcTZ1NVNFVmwrVEZ5ZXZoY0x0SStudmFZRlhqSGRFamo1TjBDUjdaY3FkSEZaN3AyaXMzcXpVYTZ0ekwKZVFkck9vRU5iWEEweSsrYXdqd1h1ZFZPcXYwUGE3ST0KLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= - tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURTRENDQWpDZ0F3SUJBZ0lRSVdjWDY4ZWNubGRTOU1WUDdLYmk3REFOQmdrcWhraUc5dzBCQVFzRkFEQVUKTVJJd0VBWURWUVFERXdsRGFXeHBkVzBnUTBFd0hoY05NalV4TWpBME1EQTBOelF3V2hjTk1qWXhNakEwTURBMApOelF3V2pBak1TRXdId1lEVlFRRERCZ3FMbWgxWW1Kc1pTMXlaV3hoZVM1amFXeHBkVzB1YVc4d2dnRWlNQTBHCkNTcUdTSWIzRFFFQkFRVUFBNElCRHdBd2dnRUtBb0lCQVFDK3pzRnltK1VKWHRIZnVwZGx1bGhFakljak5VOGcKVWxLQU43d3NXZ2ZrNUNTeWFmTHdYRkRObWNueW81TVAyczQ1RjhRY21jbmtOV3UwWms4VllMdkFYSEp6ZDdlUQpvYjNHZTNWSjd5RkZyQlNtZVMxL2l6UElpR25pKzJiSTloeFYrMm9hZlE4VG9BOFRiTVdReFdySFBIbnFZMGhjCjQ3T0xtMW5GUUttTWtpS1kxRlJYRjFLcEpGbzdZVWlBQW5tYW5wY1VHQkJSY3VlZk0wT0ttcEFENkZjVm1DVEoKT29OMFFKNjN5bW95Q1prSlN5cm5aalBuM0FrUElvQWxGWDBBK0ZLYXA2cS9VUnhlSXhVOGdsUFZwUE9EMGlZNgpNVFBURVcvVWdnajFyN0FlTkFkaXY0WW9PREl5cG1BUVpMK2ZtNlMxSlBFa3lBNlJaRGFhWFZlN0FnTUJBQUdqCmdZWXdnWU13RGdZRFZSMFBBUUgvQkFRREFnV2dNQjBHQTFVZEpRUVdNQlFHQ0NzR0FRVUZCd01CQmdnckJnRUYKQlFjREFqQU1CZ05WSFJNQkFmOEVBakFBTUI4R0ExVWRJd1FZTUJhQUZPamJYbXBsSG0zRjg3ZlA4d25ESFgwTApjODBjTUNNR0ExVWRFUVFjTUJxQ0dDb3VhSFZpWW14bExYSmxiR0Y1TG1OcGJHbDFiUzVwYnpBTkJna3Foa2lHCjl3MEJBUXNGQUFPQ0FRRUFGbVJvZ3AwaGMvWXlhUExvM2NxTFZYMk5pM1d3THdtNVh6cGx3M0FFU3hGaE1nckIKMXhqb1FUUlQvVUIzcDdzVWFxRG9pWUFXQTcza3JmYitsK0dpTFZhcmZFN0wwS1YyTVZ6L1QxL2J1NHNHN0FjeApKaDcvRlhHbkFGak1WSVEyaHRqcExtVDhoMFVKZERHaVNXTEZaSkVkdTE2NWxRUHg0MmYzUlhzVWQ3MVd4YmxVCnQ0VUN4WGhGSEtwU2xKckFXd0V2WXhRdmFYTWRtVjdVcXVCK1dLRW8rR25iTStveG13d0VjWnl3L1RPSDFqQU4KajdYSThhdjYycTUveE1Ka0tMejFIWXNRcFA4S25vdm03RjRlRSsrM3hLOTdmVnJFcjlSRmdFeTY2S2ZzR2U0cAp1dkw4T1BFUHRMMHZwYnVkdE56RUVxb3BiU0pTQU9pV2JNTUpzUT09Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K - tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb3dJQkFBS0NBUUVBdnM3QmNwdmxDVjdSMzdxWFpicFlSSXlISXpWUElGSlNnRGU4TEZvSDVPUWtzbW55CjhGeFF6Wm5KOHFPVEQ5ck9PUmZFSEpuSjVEVnJ0R1pQRldDN3dGeHljM2Uza0tHOXhudDFTZThoUmF3VXBua3QKZjRzenlJaHA0dnRteVBZY1ZmdHFHbjBQRTZBUEUyekZrTVZxeHp4NTZtTklYT096aTV0WnhVQ3BqSklpbU5SVQpWeGRTcVNSYU8yRklnQUo1bXA2WEZCZ1FVWExubnpORGlwcVFBK2hYRlpna3lUcURkRUNldDhwcU1nbVpDVXNxCjUyWXo1OXdKRHlLQUpSVjlBUGhTbXFlcXYxRWNYaU1WUElKVDFhVHpnOUltT2pFejB4RnYxSUlJOWErd0hqUUgKWXIrR0tEZ3lNcVpnRUdTL241dWt0U1R4Sk1nT2tXUTJtbDFYdXdJREFRQUJBb0lCQUE4TW5hTmRlbDRYMVhQUQo4cm42VFpYeWc0SWFaVWhHVmUxNDkrV0RvRlhFVE1TcHFKaWVuMXpvQVU2YTZqRjQ3NFQvUTkrQm5iUGJKc2lPCnZUUVJjaDJFN1I0QVZrRVpFSy9EOHdkR3poZ0JyNHRGeVhuaXo4M0VQSjNEZUdMblRtclZycE95UTJzbjE2aVAKanJHUmNJK1FUSWxaRlU4R1FwWURSYnhTRWsxYzRpd1BQaEplMDZGUVBOcWE0c1VBMzJkYTZ3SVJNUG1VZ0hTdwpEdE5ZbmVVR1RUa245Q0IrNEJjeDczTXVEUjBzdERzV2wrdkVsM2N0L3hKbXNWVStTT08ycCtyNitLTXZIakc4CjQ1b2FxNWtudkZkcFphVGNZcmg1NE11Zm4xd0pybUZWcFp2d093N3hvcnNheklXL25rak0rY0t1cHgzK0RiYjgKdWF0NkI0a0NnWUVBK3BkSDJtM3hndzFLZjR6eFpIUW5FckN4ZFdzVzRMQU9yK1pDR2pzcHB6Vm1CZmZNckhvegozTC9KUnJkajVQQ01sbm5nbkJJUEVOSUNyc3BpR3RENzFyQVNwRmNwZGgwaG5VMzQvTVRaWVRodWxUYStGN1RwCkFHK3dybmZ3Wk5ZSC9BWHRYcmJCVllZZng5bFpJRE5UY3FUaHZPMjcwemIrMy84V210RSs5NjBDZ1lFQXd1MGYKbkl4d3BROGF4a2pTazk2Q1NOY1hLVDBITFRjSkZvZldHRURieGs0SFlZbE9tZERJdHZJc29HY2tZNFIwM2g2TwpIZjdFclZMa1NSQTNVaXBGQnlPejA0WjFLVWpOblR0TUp4UHpXYnhsc00zYjVEWnZaWVB2dVRib2oyT2FUNDVrCjdBdzYzQWk2ZXcxTmQwNDZRZEMzR3FpN3lTaHFqVnkrWlhJUkdnY0NnWUVBa1FjR3ZjTE5lS1F6am5oYXFHR1UKejN0VmFQaE9hRUZjYnE3YmFPVCtxVmY5TU0wR05uZ1BGZDRsTmZrakpqZVZsZXo1Y2puOVlDVzdDYi8xWVVHNwp6cmRlUXFCelRYbDBuOTZsa0Z5NDFreGJxNTNnREVaV1p6czh6T3g3UTFDZmxGczEwcEFBZW1mQ2N0NDJkNjFjCnlVZmxvWHNSTGg5eENPQlFDOCs0R28wQ2dZQkg5RUEzQ2FDTFRZZ1VxYzBSeUpGUFVoYTZva3lENUV6MmhDNEQKeGUxYXhuTHpEangxaXh5TWE5a05YUVdSdHROdEt0cExPRUJodXJlS1FQSXE0bStZc3hVdWYvTy95YUFjNmtheQpKaXN1ZE4wVTV1akUxVk5KcGVwWDlHemtnVi8wL2h0REIwQ3krSVhkNW9zeC95NkNIUWw2VGM4RDhtZGl4MW1CCkdSbzNBUUtCZ0dyVmkwemVVNmZDQzR2My9YbUJrT0t6aHQ2ZCsxWFFXZGJ0MWY5ZVVUdi90ZDdMZHhkVExBckoKeTlOU212alhmNm8yWEk4QTYyZ09YcGxuNFRFOGRMQmZKMStIeGdmN282bFBNbTdpb0lQOFd0WVdlY1hSMEdvSApuN1U0dXhmN0d1TE50TmFUQUZCREs3T2U4YURJeEdOVjN3Uy80a2lGckJRYU5rSFp4QkhyCi0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg== + ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURGRENDQWZ5Z0F3SUJBZ0lSQUpUODAxYzVDQWRObi9wQTcrNzVTdFV3RFFZSktvWklodmNOQVFFTEJRQXcKRkRFU01CQUdBMVVFQXhNSlEybHNhWFZ0SUVOQk1CNFhEVEkxTVRJd05EQXhNRFV6TUZvWERUSTRNVEl3TXpBeApNRFV6TUZvd0ZERVNNQkFHQTFVRUF4TUpRMmxzYVhWdElFTkJNSUlCSWpBTkJna3Foa2lHOXcwQkFRRUZBQU9DCkFROEFNSUlCQ2dLQ0FRRUFzYXJVaDNwVjI0ekhQWkFoVXZPeExHNnN3MzFoMUlyTU9MelZzamdrSHA3OXFXWXYKY0R5U1BMSlBZUjRwZU9lMmgvTWJjN0lUQVMrR0MrcTJwRGFKOU9WcXdCV2xzVmUxWm1rZUVuSldFeUV6bE5VYgpBclRiVzFDbkdMUlBVZzljOFhJUDFHYnRGekE3TEF4UEZpWG5ZTW8yVDRMcU5xMGhtU2F2UUdBQTM0VzhQSHd0CkI2UHRkdDlTK0pjRzFSS05HR1A2K3N6U0NDWm5IR09TM2EvM2J5aml1WXdJckF1Mk82amt6WHMwU2pWQlhtNm4Kd1JJblBhTGFvNjNoL2pqR05SaVJMZ21BWjBEZzBKWi8xdDNoVW1iV3RTU25qUTZWcklKdFZFVnZwOEZpV3FYcwpKOHJOR2RJVDBKQjAxSFZMRTlpVlRYM1p4R1VtZ1VhdG5ZemM2UUlEQVFBQm8yRXdYekFPQmdOVkhROEJBZjhFCkJBTUNBcVF3SFFZRFZSMGxCQll3RkFZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQndNQ01BOEdBMVVkRXdFQi93UUYKTUFNQkFmOHdIUVlEVlIwT0JCWUVGQ1F6R2g5YlU3RldLWHcrMk10ZXBWKzBSTEgwTUEwR0NTcUdTSWIzRFFFQgpDd1VBQTRJQkFRQmJIMjJ1OG5ic0ZYdWxZbkZOdjF2bVpsTGI2bmVIbFkwaitwNGZ1Zk5vaDZkWmlxRXNtc0FoCjloZ2c2d3dmeUIwK2QwNTBwbFhXSW4velFnTkRoWXdsY2M3TTRVWlI4aGhjVTZEb3pLaHpCV1VFaFI4aVBCYkkKWjVSZ3l3VWE1a3Yvbmtndi9jM2dEUGUxZEFyVitieVZxYlJGOVdQaGRlREFwWlM5cTNscVd2TmxjQkVGaVBYMgpqNVd1VlZnVmFvT2VNZ0k3UFBZOWZRK0k2STBsR3o1eFlVNnRZTk5BTko3UmlXdjhOakQzdzRSdHBXOFJ3SWtJClhadHhZQnllU3BGQTJ5SUNlaUdNSmNhNTlHRkp3ZDFMbkJ5dENPTzRZdHpPTThWdEYrbkJ3Nm5sMjBFa09lYzkKelYwK0JZb1cxWXZwbVFVUk8xRCs0OXBpR3ZIUlBpMTgKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= + tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURTVENDQWpHZ0F3SUJBZ0lSQVBGMTVCa1BXZTZ6dk4xaDZRY1hZaUl3RFFZSktvWklodmNOQVFFTEJRQXcKRkRFU01CQUdBMVVFQXhNSlEybHNhWFZ0SUVOQk1CNFhEVEkxTVRJd05EQXhNRFV6TUZvWERUSTJNVEl3TkRBeApNRFV6TUZvd0l6RWhNQjhHQTFVRUF3d1lLaTVvZFdKaWJHVXRjbVZzWVhrdVkybHNhWFZ0TG1sdk1JSUJJakFOCkJna3Foa2lHOXcwQkFRRUZBQU9DQVE4QU1JSUJDZ0tDQVFFQXJLL0FmdFRUWGlnWkFZWjRBalM4MnJjVVFTc1AKM3ExTmZxVEZWSFcrMm93a3BxZkE1UnpVeGNzUzhKZ2ZyeHdqM2R5YlZNa0VNbmpONVpsTTdtT0NRVEx5dldHMAp0dzNXdy9kQjNrWG4xc1JqVEh2TWNZajBtNGVpSDd3dEhSNVFHTlVsbzNjVHlYQzdMK3BNSW5VblkwUUFYNEFkCnVndzFpazhkdk90WWJzWDVMaFI2S3I4SjlkT2hTNVltTHo1eTBZQmhHWGs5QlQyYmFIcmVLUWFzaWhSYWJJcnIKY1VDd2M5SERIRkpDZXliUE9uZ2h6WS9LTG5BTmNqS25LRlMzUWdoR1g2ZWdvMW8yOW05SlE0TkpzOHZLWFY1YgpLQ0ZjTEg5YVpHMFRQMWxGWG5ZKzFHMVI3cE1yZ3pwbmFRQmQvUFh6YkJyQVdYYjFqMmp2V2tMY3NRSURBUUFCCm80R0dNSUdETUE0R0ExVWREd0VCL3dRRUF3SUZvREFkQmdOVkhTVUVGakFVQmdnckJnRUZCUWNEQVFZSUt3WUIKQlFVSEF3SXdEQVlEVlIwVEFRSC9CQUl3QURBZkJnTlZIU01FR0RBV2dCUWtNeG9mVzFPeFZpbDhQdGpMWHFWZgp0RVN4OURBakJnTlZIUkVFSERBYWdoZ3FMbWgxWW1Kc1pTMXlaV3hoZVM1amFXeHBkVzB1YVc4d0RRWUpLb1pJCmh2Y05BUUVMQlFBRGdnRUJBS1BaMjErU2pxSi95OGtZYVV4eEtkZkFwaGl0aXd5dlRtNUtFYVo4MDFab3gxNFQKNXRqa1RkaWhWYkt5MDJJeGhRdjMwbytDTk9HZE0xcG1uOFhnWFRjV3lTQmE1REZ3ZUZMV0tKMDcrVWNGNFIvRAp5UkoybkY2K2lDMms3ak44dVVrTlZCZ0xObzhDZUZqSTgvc1pwblRRNzFzUm50Q3hNRUlHc0Q5c3IwQUczNC9OCjZHSThrVmxNOE5CbnptY0lUbEVHSm1SVHY0dzUvMENMYkhUbUlrcmMwanhyOVplZ0ZJTk56SEpUb0phdWdGaXQKdzlWSXc4aGtISnZic0t3ZUFzZ3cwQ1pCVzhlUjZjb1BLZS8va0RMb3kvMDlFQ28yQzRDNFpEUVg4U25OYlBuYwp6WnI2MTdjMm1tRFpQelFyc2IxK05sREdhcGs2SFlyeURzZmdJMkU9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K + tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb3dJQkFBS0NBUUVBcksvQWZ0VFRYaWdaQVlaNEFqUzgycmNVUVNzUDNxMU5mcVRGVkhXKzJvd2twcWZBCjVSelV4Y3NTOEpnZnJ4d2ozZHliVk1rRU1uak41WmxNN21PQ1FUTHl2V0cwdHczV3cvZEIza1huMXNSalRIdk0KY1lqMG00ZWlIN3d0SFI1UUdOVWxvM2NUeVhDN0wrcE1JblVuWTBRQVg0QWR1Z3cxaWs4ZHZPdFlic1g1TGhSNgpLcjhKOWRPaFM1WW1MejV5MFlCaEdYazlCVDJiYUhyZUtRYXNpaFJhYklycmNVQ3djOUhESEZKQ2V5YlBPbmdoCnpZL0tMbkFOY2pLbktGUzNRZ2hHWDZlZ28xbzI5bTlKUTROSnM4dktYVjViS0NGY0xIOWFaRzBUUDFsRlhuWSsKMUcxUjdwTXJnenBuYVFCZC9QWHpiQnJBV1hiMWoyanZXa0xjc1FJREFRQUJBb0lCQVFDZHlJUmhIc0wyVURydwo2dFd5Wms5OHBEVnNpaFVaQ0U0N2ZnQVRlUFptcUJCQStoeEUrMy9xTGUvalI0d0Rxdm1XbVNDUWFvOWNNb2NtCjExaTBwTlY2RHp3K0VBMVlDTndIK0Y4RjRlZkFrM2FMaHI0NXFzS2RiV09VRFpORy9OQ0FzQmlROEpkeXduODIKZTZVUEF1NTNROFgzZkk4czFFVURWK0M3SW1xTjR2UGI2WHZuQzd5NUx6R0x1ME9oRlRSeEgvVm1QMldSSGxvcQprNWlNQWFxVXpzU05NaG41bDlMdks1ZExqUDVqV21JYUdJdzNTemRod2Uvb3YveksxcCtGWFdUMHZxVFAzUTNFClJHT2NnR0gzSU9USG1wQnBTb0hYNDBLYjFtZU82SFlYYXI5ZnRlUlE0eEJyVU16TC90NHp6VWFqS3RJand4NEEKdS93WGdkTEZBb0dCQU5FS1JJS3R4QkY2VlF1MkpsaWhNdXRSSUpEUDdaNmlvWXJ2YWtYeldjYUMrUHE0NXZrcwpPeC9SVEFqWHJrbnBITG5pQUJQeW5EM0VKMHVzSW5XckYyRElrclBmaFdLVTIrcGlPQmVGZ3UxTnZzUXdYMm5VCjd6ZUxXR003ZmROTVJmS1owbEZVM0srRXF2M0Q2VXFZYW9NMWFTQ2IxWlJkVjlIc0htVEpHVHNYQW9HQkFOTjYKMFpSTFJDZFFDK2l4WVVES09RS2xSNmNNWUtJRmFXdDA5Um0vajQwcXRYYzA1WXNnOWpUV3hWMk5iSE11SHlVago0L1FFV0lNQVhLRVZQbUV5UVl3YUdBMVZXcVZ6LzZ2QU9rRitCelV0SDZhOVU5MDJCdUwzUWVuekJERXFLMURBCk12dkp4SDNvdjdlb1dxWmhuTkZtdDB1UlF0cDJ3TXJDR2lvYTFlTjNBb0dBSEd0MjhRVksyTTEyN29hdkkvR1cKaUtPWTk5Y3RDUm8zT0RwZ2ltNFJVSW5SNjlSam9wQys0UTZGZGRaTTNjT1JvanYxb3NDak9VcUh4U1A3ODE5MQphRFVjck5QQXdLeFlVYjlVdk8zcjVQTmk4aTFaYTN3Rm9kbVNCTHU3MlpSUEZqS1BnM3MwSGJDOXhvNXlFekF4Cm12RVIvOXJ2NktIZ0pLd2pYYlJ4ZDdVQ2dZQmdwc0VpQlVRZ3MzUzk1Rk9PU04zRlY4Um5sRUNWeStOaU9SSEwKc3NEb3c1d3Izd0VKbFFieEh6Y1VpbzRHRmc0bDYwRkRSTGt2SmZzdm80WGU1aGtPN3Q0UE9mTXpxdEF1cnF2eApRcWdJcFpiUm5iVzJZL3JCd0Q5ZnJMRTl4d2dFMzlKdFFNbU13ZExkSFJSUTlrdTFhRHhkVFFaQTBnVktwV3RQCjB2UHVBUUtCZ0dpWURQTmxMVjJaZTVpWnVLZ3dTZjdDWkEvejQyTHJrQU01aWk1YktYSm9JcDdVR1lHY0gvVWIKUUwrL01tOEJUcTUrYkJ5aXk2M3FMemp2UkphZDQ1SVZ5bFREQmJIa1VITU9ZbWZwcVNWNFRES3RBbFhWNFpjSwpidkI4MEJua0d3cVBvQjNuZUh6eGhlb2ptaUZObUwxa2llc3NEdnZ5WlVEeUNxTlhjZzJzCi0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0tCg== --- # Source: cilium/charts/cilium/templates/hubble/tls-helm/server-secret.yaml apiVersion: v1 @@ -74,9 +74,9 @@ metadata: namespace: kube-system type: kubernetes.io/tls data: - ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURFekNDQWZ1Z0F3SUJBZ0lRYUJaS0paekdId3VDMjY0dHBhY0kwakFOQmdrcWhraUc5dzBCQVFzRkFEQVUKTVJJd0VBWURWUVFERXdsRGFXeHBkVzBnUTBFd0hoY05NalV4TWpBME1EQTBOelF3V2hjTk1qZ3hNakF6TURBMApOelF3V2pBVU1SSXdFQVlEVlFRREV3bERhV3hwZFcwZ1EwRXdnZ0VpTUEwR0NTcUdTSWIzRFFFQkFRVUFBNElCCkR3QXdnZ0VLQW9JQkFRQ1JRZUU2ZEZPMHo1dDd1ZmFmUG90KytKTmk5SzRITEcwRmRwN1BEZG9yS0hDR0lPRFEKL3ZjNUlHazNIMllvU1drUHJGNitGMlRHK1JVS1JYaHJKQkVqdkt6R0krbHVpazhLUUdYN051eGs5ckg4bDluMwowSFhtWXhKcE5xcW4rRDBWTUwwN0pFSWtYV1M0MFhoSDh2cmNuTkE4dHljdlZFb3NXUnZReEJjaFFJVUVFd3RGCk1UbTI4WHBjTi82N2JkbC92cHhtdGxiZWlkVElPWW03b3M3NUtJem1KSGJ2L2wzS01hTytKT2t5UE5pc3dad0sKNURTMkpqYUtyZGYvWUhLSC85U3hHSFFTS1hoT3ZmTy80cGNualFSc2hiUG1GTzJ0TVdURVFJZVNJV0NncEcvWApiY3J0N2c0bGxZTStFdkpmNGsyMFR3d1FNakhTQ2NMM05vRUZBZ01CQUFHallUQmZNQTRHQTFVZER3RUIvd1FFCkF3SUNwREFkQmdOVkhTVUVGakFVQmdnckJnRUZCUWNEQVFZSUt3WUJCUVVIQXdJd0R3WURWUjBUQVFIL0JBVXcKQXdFQi96QWRCZ05WSFE0RUZnUVU2TnRlYW1VZWJjWHp0OC96Q2NNZGZRdHp6Und3RFFZSktvWklodmNOQVFFTApCUUFEZ2dFQkFGTCtCWU1TemRPVkJ3Sks0VVdXNENaM1l3TGtKblpYSi9mYkFqcFFRNlFVZnVoSU1yR2xGb3lICjRXYlNxWXY1OGxMd2JYemo4T2ZzdnBHN0t2Y0FzM2VvL2lOdDdDeVMrQTdGbFRBZVZzQW14STd3NGd1MHB4ZHgKLzF5NFYxZ1ZjdVhrdXRYUkpZT016cmppU05pUkRWN2pwUFVSL1hZVWp2THVlT0twLzJXUExxakdsditUemIxZgpxN2V1S3RiMGFhMWRZYWsrNEhMYVo4blUwN2ZuK3RDL0M2TzJndUdtWXg0OFkweGRKMWpqSERDU0tGcmdnaE53CnBkTWJTcTZ1NVNFVmwrVEZ5ZXZoY0x0SStudmFZRlhqSGRFamo1TjBDUjdaY3FkSEZaN3AyaXMzcXpVYTZ0ekwKZVFkck9vRU5iWEEweSsrYXdqd1h1ZFZPcXYwUGE3ST0KLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= - tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURWakNDQWo2Z0F3SUJBZ0lRT2lWcnFOL3hnMENPN0huNTNYY1VOakFOQmdrcWhraUc5dzBCQVFzRkFEQVUKTVJJd0VBWURWUVFERXdsRGFXeHBkVzBnUTBFd0hoY05NalV4TWpBME1EQTBOelF3V2hjTk1qWXhNakEwTURBMApOelF3V2pBcU1TZ3dKZ1lEVlFRRERCOHFMbVJsWm1GMWJIUXVhSFZpWW14bExXZHljR011WTJsc2FYVnRMbWx2Ck1JSUJJakFOQmdrcWhraUc5dzBCQVFFRkFBT0NBUThBTUlJQkNnS0NBUUVBdllDSFlMWUFqOTAwYXVVY3BKUHEKWlRkZjNMeG9pQUV1ZVlMQUpsUVJLdVIvdmphVm9VYzBwU2JCemFpMlNrZGRwUWIxWDhHYXBhOTJjZTR2MXg2ZgpuSGxaTEhTM3dXeXhaSWxQOW54aFRoTVY4b1NVTTAxVUlrZ2pLTHhxUzBETjc1UjBJY2NwU29RQUJtMmZtNmlMCm9CWDhUMXIzMEdRRVdRdytwOFNRTUh0emFwWHlmSkpkZGozdnlaTXpvQktLWGhKak5wK3oyMTBpZE1LcUNwZ2cKK0Q0b1FsRTRwTUcxWVd5aU9YTTJjTVpUN2R0R3RxenZwVy9zakx1MlVWc2haclhRNDhZQ0NocHlVQUhraDNWUgpxZkJrVHQ1ME1idm5FWFlBOVd6dThUWFQ2MXNGMVJWR1VqV21kRFNUUjNkcVlpanJiN25lelZINmFWdVdGWm1OCnNRSURBUUFCbzRHTk1JR0tNQTRHQTFVZER3RUIvd1FFQXdJRm9EQWRCZ05WSFNVRUZqQVVCZ2dyQmdFRkJRY0QKQVFZSUt3WUJCUVVIQXdJd0RBWURWUjBUQVFIL0JBSXdBREFmQmdOVkhTTUVHREFXZ0JUbzIxNXFaUjV0eGZPMwp6L01Kd3gxOUMzUE5IREFxQmdOVkhSRUVJekFoZ2g4cUxtUmxabUYxYkhRdWFIVmlZbXhsTFdkeWNHTXVZMmxzCmFYVnRMbWx2TUEwR0NTcUdTSWIzRFFFQkN3VUFBNElCQVFBbkpRZ2hRMlkyMXVnRUc3R0EzV3V4VjY1Tk5wcFEKVUE1TXlCZTlITGJVMzlJd3dYYm11bWtPVHVUMnBxcjh4TWF2Uld0dUx1T3AzUzkvVm1aWWV6d05Eb2VXQlNzcApMdGNxTWlxaGFHejRJbTNPV1NlcjZvVUxITDRIdXZ1Qm1wOGU1ZmhBN1lXY20ybktNOEIwajh4S3VZTEhSNHliCkJHRkNrVCtjbFpjZDhpbDZvT3pBRlVIbkMxY1hQWG9MY05sQW1vNWdoMHVxSGdBYW1lYlFYTDZycW04TGoyYVkKWmpxTzBBdUZWNXA5SDdIeHhhTXdtVGoyUG8xVjZjL01EUko5Y0xuaFI4akRpbk1lcnBEbUN2MkcrWmllcUMvQgpJd0R0alhnNm9PZEw0Z2lYL1QzRStkd3BLTGc2NEMrNHZjQUZ2NWxuOUJWU3hjdkF5eTQzT25DUQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg== - tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcFFJQkFBS0NBUUVBdllDSFlMWUFqOTAwYXVVY3BKUHFaVGRmM0x4b2lBRXVlWUxBSmxRUkt1Ui92amFWCm9VYzBwU2JCemFpMlNrZGRwUWIxWDhHYXBhOTJjZTR2MXg2Zm5IbFpMSFMzd1d5eFpJbFA5bnhoVGhNVjhvU1UKTTAxVUlrZ2pLTHhxUzBETjc1UjBJY2NwU29RQUJtMmZtNmlMb0JYOFQxcjMwR1FFV1F3K3A4U1FNSHR6YXBYeQpmSkpkZGozdnlaTXpvQktLWGhKak5wK3oyMTBpZE1LcUNwZ2crRDRvUWxFNHBNRzFZV3lpT1hNMmNNWlQ3ZHRHCnRxenZwVy9zakx1MlVWc2haclhRNDhZQ0NocHlVQUhraDNWUnFmQmtUdDUwTWJ2bkVYWUE5V3p1OFRYVDYxc0YKMVJWR1VqV21kRFNUUjNkcVlpanJiN25lelZINmFWdVdGWm1Oc1FJREFRQUJBb0lCQVFDRmRodmlGTXhZaGVZQQowdE5WWllkVE9haWVBV050UmNmQmRFQjN2Z1ZKUEJ4cmptM2JaQmJEcVlRY241R2l4cGhCUGFGYWl6T3JOT1FxCllTSDRVMno5K3NpKzhvVG9DUEQyYVc2VG5nMjV1dDllS2RsbU9EUGs0UUZDRTFDWkowN2lTSjl4bXA2T0NHRXMKSmRDZkJCa3g2Y29FNllCV2w5b29ET09qckdBUWcrblFWRVFOUExwRG9ITTVsL0ZnNmR2MWQyMUlEWnBDajZhMApZOU0rNDV1ei9NK0xVdFlvV0c0ZlcwSE9IM2J5SkZSQWs4bnppV0tvdkNHTUpUSjFVTlFTTFBZVUp5OFFpS2taCkFqa3V3d1NvNWZneGFsZ3V0amJpNzBkTWFrdU5Gd3BOejh6VEhCcXNSTndEbTk0U05nZW5uTjBrMjBGK3dOeUoKY3R6cUNMMUJBb0dCQU1tRVFwbjdQNCttbXM3cFNDb0pXM2txOUZ4VjhrODVaSUVuR0FXSDdYSmJtY1UwTFo4TQowRXM3ME5QQ2VLMGVRWWMvWHoyOWdKWVd0bHJCcW9TclBoQnNXQmpKNTdyOGdhZDhlNDJacFNhQ01QVGJQQUJVCm52OHgvRW5zUnV0TUlQd0VyenZIRFo2RGxpcXlyaWxGN0g1YnNqYlNUSERzeldxdlUwcU1wbHh0QW9HQkFQQzgKc1p4QWNzYTFyK25wTjJMOStLU2dmdkRPU3FkNkl5elVIcUdSSGEyU1IxSWdlUzhWdUtDL050cjk4dkZvalpnTgpYMHBuQ2toZnc3MXorU3kxc1JwMDc1eEdLbjFTRzR1Y01wT2ZsZVBma0RmaFRtZVJLSC8rVXRzRnhIYldCOTQ5CnpmWjBUTzVzQXF4K3hPYlZRblFPOVRuYU1SSTlQWjJmei9QZjR1UFZBb0dCQUtsMGhLVURlQkdPSWdQNGUyeU4KN2RQWVlSLzhUZ1I4MkowYWlNS3Q2T2dQU3lGZm5UVndDd0FZenFRamxtTE5YSUVrc3l3eDNKMVpnQUtWZEpTWApnMXRBSUZ6SC9BdHJKb1AyMDliZzZ0V1ZDU0g5OFZpOXorMzgxSkE5RmUzcldKbFVQeDdmWmY1ejNLVVBHQkV3CjhZdllBK2JCdFBJSXp6djFMdTh6a3ZtSkFvR0JBUENqVGM3b3hWSklMeTNjUjljV0U4Tk1BMWZtZmMxblUxM3UKTXloQmpLOEI5M1RxclBnWitGSUdrV2phVEV4dnZJbnZZLzlWZkh2WDdpdWtqOERYWmM4U2NLbC9vZDFmZzlWTQpMMnBOTFdGNUNnb3hsMVFEVDc2UmxIVUhFTm5SSEZCVTYxcWQ2b0N4U3dMdVBSaVl1REtXK1IzNU12QU9jMWJxCmRzNUtUOXg1QW9HQUJJQ0hGM3VWTkxxTTFFWnVLdkVZMTlLKy9NVyt4MHZpOVpWRlJ1MHVqZWJGakVCYkVidU4KQ3ZsTW1mUy9ETVJvM3NDSVhEajliUnlPUmdhUVROUTByRFhjWnR6UGNCWmdUbDRPQitvV1VscG9DMFhibHdoQQp2My9FZzNjUisvemkvUUdXSVAxRlNGWE13eTBNa3RKeU84YU9yUkpOVzdyOW0zVVZQcCtETUNnPQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo= + ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURGRENDQWZ5Z0F3SUJBZ0lSQUpUODAxYzVDQWRObi9wQTcrNzVTdFV3RFFZSktvWklodmNOQVFFTEJRQXcKRkRFU01CQUdBMVVFQXhNSlEybHNhWFZ0SUVOQk1CNFhEVEkxTVRJd05EQXhNRFV6TUZvWERUSTRNVEl3TXpBeApNRFV6TUZvd0ZERVNNQkFHQTFVRUF4TUpRMmxzYVhWdElFTkJNSUlCSWpBTkJna3Foa2lHOXcwQkFRRUZBQU9DCkFROEFNSUlCQ2dLQ0FRRUFzYXJVaDNwVjI0ekhQWkFoVXZPeExHNnN3MzFoMUlyTU9MelZzamdrSHA3OXFXWXYKY0R5U1BMSlBZUjRwZU9lMmgvTWJjN0lUQVMrR0MrcTJwRGFKOU9WcXdCV2xzVmUxWm1rZUVuSldFeUV6bE5VYgpBclRiVzFDbkdMUlBVZzljOFhJUDFHYnRGekE3TEF4UEZpWG5ZTW8yVDRMcU5xMGhtU2F2UUdBQTM0VzhQSHd0CkI2UHRkdDlTK0pjRzFSS05HR1A2K3N6U0NDWm5IR09TM2EvM2J5aml1WXdJckF1Mk82amt6WHMwU2pWQlhtNm4Kd1JJblBhTGFvNjNoL2pqR05SaVJMZ21BWjBEZzBKWi8xdDNoVW1iV3RTU25qUTZWcklKdFZFVnZwOEZpV3FYcwpKOHJOR2RJVDBKQjAxSFZMRTlpVlRYM1p4R1VtZ1VhdG5ZemM2UUlEQVFBQm8yRXdYekFPQmdOVkhROEJBZjhFCkJBTUNBcVF3SFFZRFZSMGxCQll3RkFZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQndNQ01BOEdBMVVkRXdFQi93UUYKTUFNQkFmOHdIUVlEVlIwT0JCWUVGQ1F6R2g5YlU3RldLWHcrMk10ZXBWKzBSTEgwTUEwR0NTcUdTSWIzRFFFQgpDd1VBQTRJQkFRQmJIMjJ1OG5ic0ZYdWxZbkZOdjF2bVpsTGI2bmVIbFkwaitwNGZ1Zk5vaDZkWmlxRXNtc0FoCjloZ2c2d3dmeUIwK2QwNTBwbFhXSW4velFnTkRoWXdsY2M3TTRVWlI4aGhjVTZEb3pLaHpCV1VFaFI4aVBCYkkKWjVSZ3l3VWE1a3Yvbmtndi9jM2dEUGUxZEFyVitieVZxYlJGOVdQaGRlREFwWlM5cTNscVd2TmxjQkVGaVBYMgpqNVd1VlZnVmFvT2VNZ0k3UFBZOWZRK0k2STBsR3o1eFlVNnRZTk5BTko3UmlXdjhOakQzdzRSdHBXOFJ3SWtJClhadHhZQnllU3BGQTJ5SUNlaUdNSmNhNTlHRkp3ZDFMbkJ5dENPTzRZdHpPTThWdEYrbkJ3Nm5sMjBFa09lYzkKelYwK0JZb1cxWXZwbVFVUk8xRCs0OXBpR3ZIUlBpMTgKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= + tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURWekNDQWorZ0F3SUJBZ0lSQUtldDQ2SVU0UUFGaUU3VHBOQ0crMzR3RFFZSktvWklodmNOQVFFTEJRQXcKRkRFU01CQUdBMVVFQXhNSlEybHNhWFZ0SUVOQk1CNFhEVEkxTVRJd05EQXhNRFV6TUZvWERUSTJNVEl3TkRBeApNRFV6TUZvd0tqRW9NQ1lHQTFVRUF3d2ZLaTVrWldaaGRXeDBMbWgxWW1Kc1pTMW5jbkJqTG1OcGJHbDFiUzVwCmJ6Q0NBU0l3RFFZSktvWklodmNOQVFFQkJRQURnZ0VQQURDQ0FRb0NnZ0VCQUswZnlySEZvZFpvcHYwWVVieGQKK2d2U2ZTQlpYT3BpUXRMQTJIcUJIY1NSamFGa3hZWGdkd09IZXdRd0dmTURVTzFlcEY1L3NlMURCN2l4M3hRawprR2psZ2M1WUVoZ2hmb3k2VkQ5SWpsZzVJZ0VHbVVJaUxUMjE4RmQ5NHl0MWdWVXRzYTZoTzNhUjJsN1k4QVdqCitIWWV0eWhZMVFnVysvT0ZQSlptYk1pNlVDZjJsNUErNFZab0h3SVVjZGlCbGRpWVNqcDg2QWRSNkpWNEpaV0wKVjBKTEdrZHdSZFpvMVd2cXoxdlEwZE5hMFdtSW12MndhanB1OVV0UitudDVXUTROSUtubllIUlZyOHhnd2VBUQo5bTF2Ri9Qc0NDVzRUQ2Jzd0VYSUduTUlPb1ByWE5mV3cvSXliV0twR1l1L01lclQxQUExdEZRTWFPbnUzY2VCCmQ3OENBd0VBQWFPQmpUQ0JpakFPQmdOVkhROEJBZjhFQkFNQ0JhQXdIUVlEVlIwbEJCWXdGQVlJS3dZQkJRVUgKQXdFR0NDc0dBUVVGQndNQ01Bd0dBMVVkRXdFQi93UUNNQUF3SHdZRFZSMGpCQmd3Rm9BVUpETWFIMXRUc1ZZcApmRDdZeTE2bFg3UkVzZlF3S2dZRFZSMFJCQ013SVlJZktpNWtaV1poZFd4MExtaDFZbUpzWlMxbmNuQmpMbU5wCmJHbDFiUzVwYnpBTkJna3Foa2lHOXcwQkFRc0ZBQU9DQVFFQWZZdlBGN2tqUTY1SFE0ZHU4NDF2cGlHeGM2WWcKU096RzBvTzZUd21vRXNHMk1kVzd3S1pjWnNWQU00U0dFaVA1WkxLc2pZYkhoL05Xd3ZiVExIa0JBYnFOUDNTMAovL1JaSW0xZzFOM1lIcVdkQmtNTEs4SXk0aFZnUkt4bHlaaTN6aXg2dWUzRFNPZUlkNzJsa0x6NFJZQy9rMlFQCnBPemZTUGxtTy9OdGtvWUw4anlXb0ZnNVdSQ3N2Y2FTRmppWlB4MU5xdFFKNDBOekg2b0laalpQMHZQNVY3aU4KdW1JVnZJQjZicTA0QzNXTFJRYTVtSVd0YnlPS1ZRTW42d2MyL3RJMm40dGZSR2IwekZnQm1TVjI2c2poZVVpRgoxKytyWGRlWWJQV2xvYVAybzBkNGFMZ0J3ZlJTVVNkV3dNRHJNS0gwcktPTEZza1VQbEpxUDVmdkZBPT0KLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= + tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcEFJQkFBS0NBUUVBclIvS3NjV2gxbWltL1JoUnZGMzZDOUo5SUZsYzZtSkMwc0RZZW9FZHhKR05vV1RGCmhlQjNBNGQ3QkRBWjh3TlE3VjZrWG4reDdVTUh1TEhmRkNTUWFPV0J6bGdTR0NGK2pMcFVQMGlPV0RraUFRYVoKUWlJdFBiWHdWMzNqSzNXQlZTMnhycUU3ZHBIYVh0andCYVA0ZGg2M0tGalZDQmI3ODRVOGxtWnN5THBRSi9hWAprRDdoVm1nZkFoUngySUdWMkpoS09uem9CMUhvbFhnbGxZdFhRa3NhUjNCRjFtalZhK3JQVzlEUjAxclJhWWlhCi9iQnFPbTcxUzFINmUzbFpEZzBncWVkZ2RGV3Z6R0RCNEJEMmJXOFg4K3dJSmJoTUp1ekFSY2dhY3dnNmcrdGMKMTliRDhqSnRZcWtaaTc4eDZ0UFVBRFcwVkF4bzZlN2R4NEYzdndJREFRQUJBb0lCQUVOdzBRc3ppL24wUnFqdApvbG1ZMm1Ga20rM1FJZ3dFUHpmT2ZBWXM2aVc2OWN0YmNEN1kxRVFCc1FCT3BLMHdLNFJzaStkc0l5bmtKTXZrCkxweXdLYmxUUHAvZFd4OGZYU2NCSnZTSUZUdDA5alFrRit2VldINWpzNzdCZ1k5YWRRbHpoWFlieFFoSmhTSFIKcko3bDQxSlFZTlZNMWFBVEpBOFhaaVRJdmJQcmpHdi96RFZ1S0RNT0JOTVZPZUtEczI5Wm92SXRUSy9xU080bwo0MGk0VStrdzVMcStLSHlobDZERDBFa1hqcEppWDNKT0NWTDd5NEVGc0tMb05YRnlPdmtHZWdMRGxMdTcyUDlSCmlXaEJOYzdVeWxJMFRqWXZyTmJoSmIwV0NVTzFUY3pNdXR3NTVsY3RTc0JTR09kSnJ3aWtld2kvRGN3eVVEMW4KbXZ5RlByRUNnWUVBMFVaVHUzSUwwbk5Canl3ZXE4RlovdVN2bTVDV0JUNHFkR3FYTnZDVGw3S09tL21la29yWQpYamlqdWcvTy8zRWNjaWJxRlpHYnpIekVVRFFud3FnRFIreXJ4VHN1c1N3dmh4bG52ak14T2x2eHdrb2Y5UERWCnRHZ0VBUUZwTEQ0ak15Ri83dzhUOUw4N3NpMmRGdjdRRnYrajRKYmlTVXRvZzl5QXB1aHl0MDBDZ1lFQTA4Y3UKZitTOUdXeUxUR3VnK09SVy8vTUpLd3V2MDZIV1BrYVRnWXpPT250K0x3MEllbFRlZE05cEFXUzNYSS9yU1Yrawp6VlFmczV6T0Jta2UzUSt3YkJ0S0JlTGM4dW5pcityTXptUkU3a1Bob3lwTlltc1REaFZ5S0J5R0xKNnRuMHgrCmtJZVlYaDU5MGtZdmIwRUFJT1JMRnBocDZnZExvUWQrNzZmRG5Uc0NnWUEwN2xTL1ZGa3BJWDJ6ZUxWSk85NUgKV2hBUWlNRnBFaEFxNGNyZFdudjZJbTl2Zy9OWG5VYWNqamJiR0tTQ2QxbDZoZDB2RjJVUWszNFR5eDFEWHJ0MQp0YWE4ZS91VFZGbXhFZnZyWDRkVCsyMXFkdFVlWHN1dWxhQnRvSzI1UXY0a01KVHJJaVVxQWpSWEhMSmUzcFJEClBPVjJLTE9UVmo5WkdxeHZpdHQ1QVFLQmdRQ3U1cWc3amNDeXQ1ZFB0Ty9Mdm1Fdm54dHFSb3VlditDOXEvSDAKbzBKS3dHVFZIUEZzZnB6K1liRjZLaURaUEM3NGVSb1ZUYTJrM0JLMjdxaERyOHBuYmg0elFFcHovNzlzeEFFRApUNEl5T1RPbldxOXdZYmZxQU1JMzZGN1RpUFVoUTc2ZlJLME14aWZwdW5kQWJiRmFlTkNleDU5cFhUOFRyYW9pCjZTMi9zd0tCZ1FDRm5XZ2tPMzF2L0RRb3lWUExodXUwKzd4aEt0STZ6NzRxSjBCQkNyUEkzWDhrWEtYVmF5WkkKQ1kxYUE5YVpnZklwRFc4SWg1UEl5WU4waUp3cmhCT2hhcGlkekZyK3FaYTlpcUc2UzlWaS84NlNCekxqdWk2SQpDYmFHVStFYlJOUDF0TlFUYWpyeTJEUDRodnF3TXFYMjMrb1dkRVJhc2xKRER3bWM3YkRONmc9PQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo= --- # Source: cilium/charts/cilium/templates/cilium-configmap.yaml apiVersion: v1 diff --git a/clusters/cl01tl/manifests/garage/garage.yaml b/clusters/cl01tl/manifests/garage/garage.yaml index c6a707fef..2d0726004 100644 --- a/clusters/cl01tl/manifests/garage/garage.yaml +++ b/clusters/cl01tl/manifests/garage/garage.yaml @@ -46,6 +46,27 @@ data: --- kind: PersistentVolumeClaim apiVersion: v1 +metadata: + name: garage-data + labels: + app.kubernetes.io/instance: garage + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: garage + helm.sh/chart: garage-4.4.0 + annotations: + helm.sh/resource-policy: keep + namespace: garage +spec: + accessModes: + - "ReadWriteOnce" + resources: + requests: + storage: "800Gi" + storageClassName: "synology-iscsi-delete" +--- +# Source: garage/charts/garage/templates/common.yaml +kind: PersistentVolumeClaim +apiVersion: v1 metadata: name: garage-db labels: @@ -86,27 +107,6 @@ spec: storageClassName: "synology-iscsi-delete" --- # Source: garage/charts/garage/templates/common.yaml -kind: PersistentVolumeClaim -apiVersion: v1 -metadata: - name: garage-data - labels: - app.kubernetes.io/instance: garage - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: garage - helm.sh/chart: garage-4.4.0 - annotations: - helm.sh/resource-policy: keep - namespace: garage -spec: - accessModes: - - "ReadWriteOnce" - resources: - requests: - storage: "800Gi" - storageClassName: "synology-iscsi-delete" ---- -# Source: garage/charts/garage/templates/common.yaml apiVersion: v1 kind: Service metadata: diff --git a/clusters/cl01tl/manifests/harbor/harbor.yaml b/clusters/cl01tl/manifests/harbor/harbor.yaml index bcab9fcbf..523e791d2 100644 --- a/clusters/cl01tl/manifests/harbor/harbor.yaml +++ b/clusters/cl01tl/manifests/harbor/harbor.yaml @@ -74,9 +74,9 @@ metadata: app.kubernetes.io/version: "2.14.0" type: Opaque data: - tls.crt: "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURRakNDQWlxZ0F3SUJBZ0lRQVFjaUJYUWE1VzE4RlB2K05UdUtDVEFOQmdrcWhraUc5dzBCQVFzRkFEQVUKTVJJd0VBWURWUVFERXdsb1lYSmliM0l0WTJFd0hoY05NalV4TWpBME1EQTBPVEl6V2hjTk1qWXhNakEwTURBMApPVEl6V2pBZ01SNHdIQVlEVlFRREV4Vm9ZWEppYjNJdVlXeGxlR3hsWW1WdWN5NXVaWFF3Z2dFaU1BMEdDU3FHClNJYjNEUUVCQVFVQUE0SUJEd0F3Z2dFS0FvSUJBUURmczVMZHV6QlFtTGpOQWNXcmU4NW9YWHJPc2lCajFteEEKU3dLaDU0czRXdmxRdWVidnkrdllkQS91MUtZU1FDdk9GRHA3ME9hMkZuTGZFK2tDSkJJRFh3QnFFOGxqS0dNdgppY29qQmJNdVZvL3poN2Z2VW83cFlJbE9uQkNXT2xHSFh3QzZuZG9lTzlsbDJBUTN1cHNZTzJpZXJ5YWZTOGtsCmNRZEg1L0RONTBXWm9TeksrUThNVkUrZG01OHpmelVWcmlCb0JhK0lUSXAzNjV2cWQxNDRPd2U4aFZxMU9kQisKY2NLUGZEY0U5VU5lTHVyN2t5aUxmM1MzcjVDMUtMMGtXSmU1Wm1YencvVnprR1lYWjNQMWZlRkhTQk9hK3BnOApEODZmTUQ0V21ZcU1MMmxwU2xQSzdqeTZjbkRlSFEwc21CTjhxN0RmbDczVUZaOEtuOGI5QWdNQkFBR2pnWU13CmdZQXdEZ1lEVlIwUEFRSC9CQVFEQWdXZ01CMEdBMVVkSlFRV01CUUdDQ3NHQVFVRkJ3TUJCZ2dyQmdFRkJRY0QKQWpBTUJnTlZIUk1CQWY4RUFqQUFNQjhHQTFVZEl3UVlNQmFBRkk1bXlUTE9IbGZlNFkveU1qaXo5ZGZSNExnUQpNQ0FHQTFVZEVRUVpNQmVDRldoaGNtSnZjaTVoYkdWNGJHVmlaVzV6TG01bGREQU5CZ2txaGtpRzl3MEJBUXNGCkFBT0NBUUVBSXhFamVTcTZmQysyOE1wVnlBWk1XN2dwTHc0bElDQzBnbW9qMlBZdHVpd2pPdElFMTRoWTdBRkMKdXFabTAwby9lU1Bza3lVSHdGOGRJMmJQSm1NMzlFdzhUelJVQzBpWWdrQW9sK2krWGEwWkZvVnRaTTlpaFNDSgpHWlA5TVc4a2RNeHRrSWFpQjFJcjdQVnJHRldJRngwOVJhNjdQdEJYdE1obEl5R0JMa3E4Y3ZuL1JaWmVHeHNhCk9TemtINlZhcm90TlpDbUVpQzQvQ2h6TGFvSDh4M0N0NjZ3WnJ5S0ZtcjBhRXVTbU5xOFo2djJSTEo3a3hEVDkKbGFZc3VSWmdYNVoxTmZHdk5aWGtzMThIUU41eWNYSENwY01CVk1kNEwyMjRGNWw4cGUzZFV6ZXI2RnRrWVZROApINDJsczVrY0Z3OE5YdkVzc3ZXM1hCbFZaSUdjeWc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==" - tls.key: "LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcEFJQkFBS0NBUUVBMzdPUzNic3dVSmk0elFIRnEzdk9hRjE2enJJZ1k5WnNRRXNDb2VlTE9GcjVVTG5tCjc4dnIySFFQN3RTbUVrQXJ6aFE2ZTlEbXRoWnkzeFBwQWlRU0ExOEFhaFBKWXloakw0bktJd1d6TGxhUDg0ZTMKNzFLTzZXQ0pUcHdRbGpwUmgxOEF1cDNhSGp2WlpkZ0VON3FiR0R0b25xOG1uMHZKSlhFSFIrZnd6ZWRGbWFFcwp5dmtQREZSUG5adWZNMzgxRmE0Z2FBV3ZpRXlLZCt1YjZuZGVPRHNIdklWYXRUblFmbkhDajN3M0JQVkRYaTdxCis1TW9pMzkwdDYrUXRTaTlKRmlYdVdabDg4UDFjNUJtRjJkejlYM2hSMGdUbXZxWVBBL09uekErRnBtS2pDOXAKYVVwVHl1NDh1bkp3M2gwTkxKZ1RmS3V3MzVlOTFCV2ZDcC9HL1FJREFRQUJBb0lCQUI3MHJaVXJheU1zRHg2bgphU0F5MEx4V2UwRVJHelJWbnNOQzNnbGpqanR0TTJUOVpMeTRQbG5FcmRQQjczMUZEZ3JGZDlaY2NTQ3ZlSlB3CklHVmdjbkd1K3RLekRFSkJlNEEvbEE1R29xWDk2b3VyczBOVjdGclZOZ3IvdzdmV09DUUFmSXhXZmJHRFhMRWcKTkcwMTBIS0kvaEEvY3B2R2svNHZadStIWkNaSjRXMnRMTnBQdHNvSDFwbHJyQmp1RVErZkpIcG03TVU5K2RjTwpMTWhkOHBlVS9yVk9ldjYvN2lEc2pDUkxrZEhpZ29mVGhuK3hmK01QNTV4M1FYWlNqRDI3NGVoc1hoWVozSk9wCk5zdzlsUE9YQVk2YTFZOHp6VXQwZzFaczU5M1dvOHVwYXlmTGdvUlp0QitkK3ZuV1dsM1UwL3QzTzk0cS9jSVgKRGtRZmFrMENnWUVBOTVvZlVzeUZqZEdxZzNYcXJhU2Y4Qyt2d0F4aVp1a1RreHZOMDVoenlHY3dncytnUGYvagpEbm1MVmZOejArNUlSTXNMRlNueHYrdklCek9ZUTBjeHJTTnFOQkFvRTdHUEN1cml5UEFZRkVVRFZMTjJPS3pLCkhGYTZLbGRQcHNLb1FZaitMUEgyZ0ZBYlI5M1lvUDdRa3IvcnN3emRydG41SCttM0pCNmpYWDhDZ1lFQTUwbnQKY1J6ekh2SkUxaFdCTWdPUDY1ODRZZGF6WG1qSEhzc2pBbDdBb1NZM2VuRzdFblNBVUIrSFBNdXdtRHFvUFlyQgpNb04zbGlzSEdMVmhoQmRHeW5FYkhOUU92aUlIT1Z3cklZZTU3ZDU5MlFCdUh2VjlnUlVoU05vWGRVcklSN3ZUCmFWQit3SXJ2bjI5RlR3dHdKeGNVbVkvZG04d0Nta1dVUHBmdWtZTUNnWUVBeWNvV3l5RVpteW9MNEZXaWE5L2wKNVJiSUVpbEZyUDg1VDhQeUxBZHNIU0JUL2RmK2pXalZBSC80R1pWdWlZTUI3T2JaWW1jcnViRUw5U3FNWmhCSQpvUVZpMFlsMVVBOStOM1NVWFJTbld5V2ZnRkUrQVJSNUp6MWJQWlNvdW95Y0djVHUrV3c4Ni9mZE0rWE9YZTh0Cnh0dVkyUFNjV3BzVW1IaWVKRmEvNXpzQ2dZRUF3cm9hUC9hWXRvQlE5bEdxc1hvUVROZUR0OVAwdGxMTytwMGEKZjU5WTNSUjQ5dzBUN0lqTGt5bklTYVpRcXdvUHBhalIyZjZYeTRXMGR0Z1hId2dkNE1semcwVUNtSSs3dDA1agpQZHF3N3BVNUxWOVFWNTVtS1N5cUZsVVFGUDkrT2U3b0lxM1QyYlhmNDBMaWZwZHB1RytWTjJqSnNxY0R0ZkZJCnk1NU5ESk1DZ1lBeFRGcmgvMzh1S2J0enJQdkdZUDJxTVNJMFlsMm9BSk04V3JkNmNvOFh2WTVwSkRQZDFmVTMKSHg3cVFSLytTdGNFQXpxczR5TXhBOWhMclY3dGVIRmJyOTMwWHowV1E2L1dJWXhGd21CbHYzejFHU0xoYlhOdgpwdEZWR250bC9WMXhxTGFUdXhQSzFDYjZOOWN2RlZrYjdEVzhScmhjbkl6MWxBUVUyL3FUS2c9PQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo=" - ca.crt: "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURFekNDQWZ1Z0F3SUJBZ0lRSHJVU1N3UVZjMnBZNVVEckJSSkh4akFOQmdrcWhraUc5dzBCQVFzRkFEQVUKTVJJd0VBWURWUVFERXdsb1lYSmliM0l0WTJFd0hoY05NalV4TWpBME1EQTBPVEl6V2hjTk1qWXhNakEwTURBMApPVEl6V2pBVU1SSXdFQVlEVlFRREV3bG9ZWEppYjNJdFkyRXdnZ0VpTUEwR0NTcUdTSWIzRFFFQkFRVUFBNElCCkR3QXdnZ0VLQW9JQkFRQytTWFc3WU41OWJqWnc1U21yYStvNi9qMlYzZVQvRzhGRmlyVlhMWmhXVDlBSlM0ZUYKMEU5NlRTbGUvQUFvL3ZkNTdMWjYzVlMwQnBNUDhMZU9ZNUxZRklzZFN0TFZyMUh6bktyekZaRFV6Z1J5MGpkVQpTSjJyNHVaZW00ZmJpR3hYTVlaTStENGpUeHI0c1hqdm9ZWUp1VG9QUnhTZVpaMzBHbEpMRlV3VWNHYXNjU3A5CkFrRVd6QlI4V3VLYXhrRnpxYndJSTBjcWZmWWFRZVZ6TXg4UGxYUmVwQms1N3NkMlJRTmJLbEp0azRON1hFVUsKYUl2VS9qZmxIaGFWczkvTXRpckc0cS9Gd20vZm9PQUplK2RZMEU2dXB6dG4xYUNtbmhTTzhPTU1QdTVRbWVHWQp5Z25iSnZ3ZXIrZHdsN093REhkU08raGlrRDNEYWxqOU5aa0xBZ01CQUFHallUQmZNQTRHQTFVZER3RUIvd1FFCkF3SUNwREFkQmdOVkhTVUVGakFVQmdnckJnRUZCUWNEQVFZSUt3WUJCUVVIQXdJd0R3WURWUjBUQVFIL0JBVXcKQXdFQi96QWRCZ05WSFE0RUZnUVVqbWJKTXM0ZVY5N2hqL0l5T0xQMTE5SGd1QkF3RFFZSktvWklodmNOQVFFTApCUUFEZ2dFQkFFZFNNZTdqSStvZFJqemRQNG13WWZpeWNrRzBMNEJUdlpXMmdGQW5TNjQ1Y3VFOGQ1UWo2WmRRCkcraXJKTENFa2hRV0pDNEJKckFCWVJuZzVDRXRRRnBCc1FSUzZtQWd3eDYvdWlSTGNxS3EzVWNNQ3c2b2ppM0MKWG9jZGl4Y1JlRWJoV1pkVkJMRWYzYVZLQzQwODVHakMxdGRxS0hlYWJlOHVOYUlzcmEwZnh1Ty9ielBsckJLYwp1ZmtERlRuOXJuYnNwZkRIU2RRQUJZUWhHL2NkOHBPdDZPTnhxYktxREZYQS9EQ25aSGxHOHV2OEFiVXBsU0RaClFnYk9RYVpIdEVNK2w0MzEra2pnbUpnTXBDSEMzZ0lBbnFNYVRYN0pONURqRy96T3RKQTdKWVZnME9VbnRFYW0Ka3ZlOVZDS0QvWFBCNFM1T1hocmxRQ3FNeE1wUnc4QT0KLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo=" + tls.crt: "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURRekNDQWl1Z0F3SUJBZ0lSQU1ydDI5OVF3OExsWkZIV08zUjFxNjh3RFFZSktvWklodmNOQVFFTEJRQXcKRkRFU01CQUdBMVVFQXhNSmFHRnlZbTl5TFdOaE1CNFhEVEkxTVRJd05EQXhNRFkxT0ZvWERUSTJNVEl3TkRBeApNRFkxT0Zvd0lERWVNQndHQTFVRUF4TVZhR0Z5WW05eUxtRnNaWGhzWldKbGJuTXVibVYwTUlJQklqQU5CZ2txCmhraUc5dzBCQVFFRkFBT0NBUThBTUlJQkNnS0NBUUVBMGpSTzAxRVJkWFF0eFZwZ2lvLzF1MHV4cURyeUtuRTcKN2dqRFgwS2k0eFltbVcveTBwTFZ0eTA1WTlTcFlpT1NJUCtFNkdRQllDV3l3SmdNaXZ2dXhndjYybUlFYVBTQgpLeVUzTjVqQXdJaE9rOXdHbkdOS0JQZm53QkRRZGJETHl1V3djQWpCUURpSlBXbjhaWTQvMzJGcDJVNnN3NjlWClR6ejZ5VFdJWnlNVkFpR0xHNGprTWNKcEhLOGVmTG5pN0M4aFhZU1VuamlaaG9PVXpocENqSDhsMElnaldyM0oKVkpVSjRwak8ydEJ4NHZSdDNxOWpvMElYbmV5c1FNdkRIMk5ZeHAzNE14ZFg4WjVCS0twemVpM0pZMTI3VTg2NQplMERxejY5bUg4ek5lZ1FVei9BaEJEd1BBWVN4ZTVWb2FFejVqVUdtQzFoRTZNWmZjdm9WU3dJREFRQUJvNEdECk1JR0FNQTRHQTFVZER3RUIvd1FFQXdJRm9EQWRCZ05WSFNVRUZqQVVCZ2dyQmdFRkJRY0RBUVlJS3dZQkJRVUgKQXdJd0RBWURWUjBUQVFIL0JBSXdBREFmQmdOVkhTTUVHREFXZ0JTbTVaRjVzVkx4UldjNjg2RUcvQlprMXJpWApvekFnQmdOVkhSRUVHVEFYZ2hWb1lYSmliM0l1WVd4bGVHeGxZbVZ1Y3k1dVpYUXdEUVlKS29aSWh2Y05BUUVMCkJRQURnZ0VCQUlySUI0UXkwakthd1BnZUNyL05GKytZU0JabHpRYWZVU3hpYkxNMi9jWmNJSGlyM3lRdEFmVWMKS2crYVRDVnN1RDJWZW5hN0NLYjh3MEtpUERHL3lDcEtmZ0F1R0g4L1F0RlI2cHZSTE9TSjA4cnN5S1hiUEYyMAovdHJZbFZjdXJ4T1NXaDhyKzZGUTdXQTBEV3hPMzhEdmptM3poZW0wbjk3RWRHUDAxdGRadUJJT0NmUGNsMFF6CmQrSGdMRWpHRHR0QlV3ayttK05QYnNWS1FYSU0xSVp0UFFENU0zVHRuelJhUDJlaDQxUkw4OFdpcmk0Q1ZzcTUKMkxjbFFrTFc4emQyNGZWSExJamFWeVdhRUo1cGh0NVZLNW5wV0x3d0xCclBGRDltalorRHJpN1B4d0ZWNFEybQpCeURybjBhUXB4SVJseU96TUtseEI0a0lOd0xCTUFzPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==" + tls.key: "LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcEFJQkFBS0NBUUVBMGpSTzAxRVJkWFF0eFZwZ2lvLzF1MHV4cURyeUtuRTc3Z2pEWDBLaTR4WW1tVy95CjBwTFZ0eTA1WTlTcFlpT1NJUCtFNkdRQllDV3l3SmdNaXZ2dXhndjYybUlFYVBTQkt5VTNONWpBd0loT2s5d0cKbkdOS0JQZm53QkRRZGJETHl1V3djQWpCUURpSlBXbjhaWTQvMzJGcDJVNnN3NjlWVHp6NnlUV0laeU1WQWlHTApHNGprTWNKcEhLOGVmTG5pN0M4aFhZU1VuamlaaG9PVXpocENqSDhsMElnaldyM0pWSlVKNHBqTzJ0Qng0dlJ0CjNxOWpvMElYbmV5c1FNdkRIMk5ZeHAzNE14ZFg4WjVCS0twemVpM0pZMTI3VTg2NWUwRHF6NjltSDh6TmVnUVUKei9BaEJEd1BBWVN4ZTVWb2FFejVqVUdtQzFoRTZNWmZjdm9WU3dJREFRQUJBb0lCQUFtNlkvK0JtL1k4bHpXdgo5aEhUa2NMR1FRV1JITTM4Q1pMOWt0VWd4MXNORm1JNWZScGpzMEpUOUhqN1NZK0NKK3doQnl5ZUhEWXY2SExqClZvbEVHWXZPMkNBdE14a01YOEg0YWZMSHZmdnJFdi9peWVlSTdNOElEaENrZHBGTHlsS3NpSnJXdk9MVSt2ejkKbjdHdmdLTTg1ZUlwc3ZNbmRTSkNwelNTcHFwbkxzR1pJNTBENkwydDY1alc3eHROWmRta1czNHgzdzFhSHFZUApaVzN0MHB3anM4cUVRZ1hDUXp6QmU5eWk5SGtCQjdBc3JIVXpBMnJIZExSWUtyOUs1WnVTbVhGb3pXZWhXcFNnCk1tQ0duT1Z4Y2xHbXptcGpPamhzRmdYUnVXNzM0aUVFRzhqRDQvRmo0OTVyQ0F4cy9ISEs0N251bHhxczVvS2oKdjg2WlJuRUNnWUVBN3UvQnRWY2lTNDI2Uk9lR1dFSEltOFZidmVSY2RHbTlDS0hhUmZIeVl6NkdMcjNscjlTeAo1NWp4K1VOajNwRjZNZ1dNalV4TUh1b1hmVVdRZ0p4eUFFSlFKdjNWQXRYZW5OSmRTNnV5d0lSMXBXcTBaTXV5ClcwTDdWcVRIdCtSMWFSZFlUb0tmM2NiQys3S2U5OUMzYUhiV1FHYU8zQzFWR0xPZnRPTXM1K01DZ1lFQTRUZEUKbzRpRGU3bC96ZUc0OFVHOG1LNzBDcmVWNm11VnBhUkJzN0pGQitnUnlUanpSQUNVQnZRMk53UVdDWWJvK0p3aApXSVdhVlRNa1pvbVVOU1FWMHR4aDI4Wm1wSGUrdjROSzFZV3BnU2YrNUZKZmovNjYxRDlXQUF1SEdaN3BrcnR4CjQ4VWNqQTdQcHlqVzFLTnZ4eWhNZWgyajdpT1B4b25mSXpzNGlYa0NnWUVBblprZ29KYXZkVHd2UDJHaTJEWFQKdHdNUEJ3cEgvVFQ5VFdOTVVGUk10eTgzWEQ4Kzc2SVFFaDFzaFNmeENJM1dGb1pZZFo1OG11dDJ3TmNRZi9RdwpzWUVMMHh3YjB2bjBFbVlpeVZXZjJxSEQ0MjZsTzlLcmVzeU1jVkxRdExlSXhkOXpESjNXQ25jZWh0d0RSSnV6ClRjRU1nbi9pL05FZHp1UXpsQ0UvcmxjQ2dZQkYzZXBxUFJCbEVvL21ZODhHOFJpNzJSS1dQSXZDZEd1eFBqcXYKcjI4ZzI4cWd2UTBpbkhkUGpQVkFyZ0RVSmNraVR2VTlTLzByenpqTW9vT2ExTDM4Y3lmY2tUa0licWw3S2hUTwpGckFXQkQxYndYNHA0cUU4OVFVTjhJV1IyaTJsdW9iRFhVUFU0MGRpR1JaRVV3dDdJakpQYytDR0lQd2FZRzBiCnRlUjlLUUtCZ1FDNWJISlRJVStvQ1V2Zk44bjdRTnowSGsyWWVzYjdBYnRtazZNRjRGQ3NHd2tnbmVoQUlWRjIKU05EeExqbVdXK1lQS3l1NndWaDZ6UW94dmZxMSt4amc5d3hnRC9ydFEzSXVTTHI5Ry9KdmNPczY5UWVReEV0WgpxbTI2WG9ad2E4ai84N1h4QzVINFhvMVBWUnFSa011TVdWeCtuZ1V3QlVPU2M4KytITlViYlE9PQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo=" + ca.crt: "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURGRENDQWZ5Z0F3SUJBZ0lSQVBiekpPaldGZmIwRmEyT2NidndSNE13RFFZSktvWklodmNOQVFFTEJRQXcKRkRFU01CQUdBMVVFQXhNSmFHRnlZbTl5TFdOaE1CNFhEVEkxTVRJd05EQXhNRFkxT0ZvWERUSTJNVEl3TkRBeApNRFkxT0Zvd0ZERVNNQkFHQTFVRUF4TUphR0Z5WW05eUxXTmhNSUlCSWpBTkJna3Foa2lHOXcwQkFRRUZBQU9DCkFROEFNSUlCQ2dLQ0FRRUF5eFFvR24velZkWndiNHVRYmcyUi9JT044eEJHYmVhV0hHVzdmS2lJTk54Y2U4dWoKVFVVMFVGZGNNUFlxUXY5aE1kRzBOVVhPNzFqMHB2ZXJpTkVWVndOZUxQQmhSa0VjYWowSW9GSzdMLzVKckhsUAp0ZTFZd2hpRmhoVmtORXEzaVpjcEVIcDdLZ2NlNzAxMkZrM0xVQVFOU3hsMmpCOS96YjZUUWVPaUdjTkUvclROCnBYMlJLaHZPc2ZvOElkcENMT3E2RXBPZ3BJOENZaTZ6aWk5ZVJ6cHVsb3g1Mm1LZ01mOHNYaTRkd3VsOTBLS0gKQWxIRjlIM0gxRStZS0Z3Z1l3cDBFdWdYMnlKRXJ0OVVBNkhxVlV4Ymk1UVdHbXRCV1dTeW1tS3VLRUhhMm8zNApiNGQxT3c2cjJ6QUdDNWY4OHBOS3l4QVBBbVBHWVVnQzlRY0k3d0lEQVFBQm8yRXdYekFPQmdOVkhROEJBZjhFCkJBTUNBcVF3SFFZRFZSMGxCQll3RkFZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQndNQ01BOEdBMVVkRXdFQi93UUYKTUFNQkFmOHdIUVlEVlIwT0JCWUVGS2Jsa1hteFV2RkZaenJ6b1FiOEZtVFd1SmVqTUEwR0NTcUdTSWIzRFFFQgpDd1VBQTRJQkFRQUpVUXRYbm5TUzI0c3lQNm4zaVFESnVMeVI3OGtTOXZIbE1TNThKbndsa3AxbldQa2FFQWhCCm1NTlRSalRIcjNFcVFtODUySGRDZ1phK2ZHOFhoQWxpYXRQWjM4djlUNWlmQTdjZUlocDB4T1JnSkhzZXErSkYKcmNQT1FzR2w3c0ROQlNhcXYzSGR6MmNRL0hseG1vZUlIcnAxemF1cVdDQ0p0REpXejJaV0JCbVF1OHJwZHVXTQo4NGQ2M3JENy83RHREVVNtaHBuZ0l0ekNtSjdSb2Y5ZW1jZWFUWUdHNWFsRHRRaXhaQ3huMDZEMzJxV2NOQnZ0CllDa0V5MWZlS0phOE5QYW9nRitDWlJJQTZXLzBNZXY1WVkzQ216RHMvSm1KalFHRi9zMTRLREhpZUZJTzFhQnAKZ1FPVWRJTjFVVmYvQjloeVN5d3RhNU1mN0VSVGNaR2sKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo=" --- # Source: harbor/charts/harbor/templates/registry/registry-secret.yaml apiVersion: v1 @@ -1268,7 +1268,7 @@ spec: app.kubernetes.io/component: nginx annotations: checksum/configmap: 55921b41f4478ded4d60da7edb83b828382ba722214816271ce3ffd2a77aed35 - checksum/secret: 2da2a24466878021f0a5895c53bdb3de944b4a07e5e85274af2aaad9fc3ac6e3 + checksum/secret: a60583d64d5f3610d2581d66278105ccdaaf2a48330cce7969ccffd7e52eba48 spec: securityContext: runAsUser: 10000 diff --git a/clusters/cl01tl/manifests/karakeep/karakeep.yaml b/clusters/cl01tl/manifests/karakeep/karakeep.yaml index 4b87983ee..d243af100 100644 --- a/clusters/cl01tl/manifests/karakeep/karakeep.yaml +++ b/clusters/cl01tl/manifests/karakeep/karakeep.yaml @@ -316,7 +316,7 @@ spec: value: mxbai-embed-large - name: INFERENCE_JOB_TIMEOUT_SEC value: "720" - image: ghcr.io/karakeep-app/karakeep:0.29.0 + image: ghcr.io/karakeep-app/karakeep:0.29.1 imagePullPolicy: IfNotPresent name: main resources: diff --git a/clusters/cl01tl/manifests/matrix-synapse/matrix-synapse.yaml b/clusters/cl01tl/manifests/matrix-synapse/matrix-synapse.yaml index df5070c7a..4a14a5ec9 100644 --- a/clusters/cl01tl/manifests/matrix-synapse/matrix-synapse.yaml +++ b/clusters/cl01tl/manifests/matrix-synapse/matrix-synapse.yaml @@ -14,7 +14,7 @@ stringData: config.yaml: | ## Registration ## - registration_shared_secret: "bpkbHlW0G8zD8yI0jrumLKCl" + registration_shared_secret: "v6Ki4TFJuWXfXRJk480nMb7T" ## API Configuration ## @@ -552,7 +552,7 @@ spec: metadata: annotations: checksum/config: e77b3b25301ed2f4b5eac2f16ed5d058374ed1ffcd7e9ca4d8eef44867647feb - checksum/secrets: 38f9ec365ce263c2a096e6d3edfebb25425c58aece737b3d99bbccc0ced55516 + checksum/secrets: f82dccf76485881a9f8814ed951122a4c79c655e8d5f558fc1159872b3aa9cfe labels: app.kubernetes.io/name: matrix-synapse app.kubernetes.io/instance: matrix-synapse diff --git a/clusters/cl01tl/manifests/n8n/n8n.yaml b/clusters/cl01tl/manifests/n8n/n8n.yaml index c07658f0c..6ac24113a 100644 --- a/clusters/cl01tl/manifests/n8n/n8n.yaml +++ b/clusters/cl01tl/manifests/n8n/n8n.yaml @@ -22,6 +22,30 @@ spec: # Source: n8n/charts/n8n/templates/common.yaml apiVersion: v1 kind: Service +metadata: + name: n8n-worker + labels: + app.kubernetes.io/instance: n8n + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: n8n + app.kubernetes.io/service: n8n-worker + helm.sh/chart: n8n-4.4.0 + namespace: n8n +spec: + type: ClusterIP + ports: + - port: 80 + targetPort: 5678 + protocol: TCP + name: http + selector: + app.kubernetes.io/controller: worker + app.kubernetes.io/instance: n8n + app.kubernetes.io/name: n8n +--- +# Source: n8n/charts/n8n/templates/common.yaml +apiVersion: v1 +kind: Service metadata: name: n8n-main labels: @@ -68,30 +92,6 @@ spec: app.kubernetes.io/name: n8n --- # Source: n8n/charts/n8n/templates/common.yaml -apiVersion: v1 -kind: Service -metadata: - name: n8n-worker - labels: - app.kubernetes.io/instance: n8n - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: n8n - app.kubernetes.io/service: n8n-worker - helm.sh/chart: n8n-4.4.0 - namespace: n8n -spec: - type: ClusterIP - ports: - - port: 80 - targetPort: 5678 - protocol: TCP - name: http - selector: - app.kubernetes.io/controller: worker - app.kubernetes.io/instance: n8n - app.kubernetes.io/name: n8n ---- -# Source: n8n/charts/n8n/templates/common.yaml apiVersion: apps/v1 kind: DaemonSet metadata: @@ -182,7 +182,7 @@ spec: value: "false" - name: N8N_VERSION_NOTIFICATIONS_ENABLED value: "false" - image: ghcr.io/n8n-io/n8n:1.123.0 + image: ghcr.io/n8n-io/n8n:1.123.1 imagePullPolicy: IfNotPresent livenessProbe: failureThreshold: 3 @@ -305,7 +305,7 @@ spec: name: n8n-config-secret - name: WEBHOOK_URL value: https://n8n.alexlebens.net/ - image: ghcr.io/n8n-io/n8n:1.123.0 + image: ghcr.io/n8n-io/n8n:1.123.1 imagePullPolicy: IfNotPresent name: main resources: @@ -401,7 +401,7 @@ spec: name: n8n-config-secret - name: WEBHOOK_URL value: https://n8n.alexlebens.net/ - image: ghcr.io/n8n-io/n8n:1.123.0 + image: ghcr.io/n8n-io/n8n:1.123.1 imagePullPolicy: IfNotPresent livenessProbe: failureThreshold: 3 diff --git a/clusters/cl01tl/manifests/ollama/ollama.yaml b/clusters/cl01tl/manifests/ollama/ollama.yaml index ac9c74e54..17e2137af 100644 --- a/clusters/cl01tl/manifests/ollama/ollama.yaml +++ b/clusters/cl01tl/manifests/ollama/ollama.yaml @@ -3,6 +3,27 @@ --- kind: PersistentVolumeClaim apiVersion: v1 +metadata: + name: ollama-server-1 + labels: + app.kubernetes.io/instance: ollama + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ollama + helm.sh/chart: ollama-4.4.0 + annotations: + helm.sh/resource-policy: keep + namespace: ollama +spec: + accessModes: + - "ReadWriteOnce" + resources: + requests: + storage: "40Gi" + storageClassName: "ceph-block" +--- +# Source: ollama/charts/ollama/templates/common.yaml +kind: PersistentVolumeClaim +apiVersion: v1 metadata: name: ollama-server-2 labels: @@ -64,27 +85,6 @@ spec: storageClassName: "ceph-block" --- # Source: ollama/charts/ollama/templates/common.yaml -kind: PersistentVolumeClaim -apiVersion: v1 -metadata: - name: ollama-server-1 - labels: - app.kubernetes.io/instance: ollama - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: ollama - helm.sh/chart: ollama-4.4.0 - annotations: - helm.sh/resource-policy: keep - namespace: ollama -spec: - accessModes: - - "ReadWriteOnce" - resources: - requests: - storage: "40Gi" - storageClassName: "ceph-block" ---- -# Source: ollama/charts/ollama/templates/common.yaml apiVersion: v1 kind: Service metadata: @@ -215,6 +215,148 @@ spec: # Source: ollama/charts/ollama/templates/common.yaml apiVersion: apps/v1 kind: Deployment +metadata: + name: ollama-server-1 + labels: + app.kubernetes.io/controller: server-1 + app.kubernetes.io/instance: ollama + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ollama + helm.sh/chart: ollama-4.4.0 + namespace: ollama +spec: + revisionHistoryLimit: 3 + replicas: 1 + strategy: + type: Recreate + selector: + matchLabels: + app.kubernetes.io/controller: server-1 + app.kubernetes.io/name: ollama + app.kubernetes.io/instance: ollama + template: + metadata: + labels: + app.kubernetes.io/controller: server-1 + app.kubernetes.io/instance: ollama + app.kubernetes.io/name: ollama + ollama-type: server + spec: + enableServiceLinks: false + serviceAccountName: default + automountServiceAccountToken: true + hostIPC: false + hostNetwork: false + hostPID: false + dnsPolicy: ClusterFirst + affinity: + podAntiAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + - labelSelector: + matchExpressions: + - key: ollama-type + operator: In + values: + - server + topologyKey: kubernetes.io/hostname + containers: + - env: + - name: OLLAMA_KEEP_ALIVE + value: 24h + - name: OLLAMA_HOST + value: 0.0.0.0 + image: ollama/ollama:0.13.1 + imagePullPolicy: IfNotPresent + name: main + resources: + limits: + gpu.intel.com/i915: 1 + requests: + cpu: 100m + gpu.intel.com/i915: 1 + memory: 1Gi + volumeMounts: + - mountPath: /root/.ollama + name: server-1 + volumes: + - name: server-1 + persistentVolumeClaim: + claimName: ollama-server-1 +--- +# Source: ollama/charts/ollama/templates/common.yaml +apiVersion: apps/v1 +kind: Deployment +metadata: + name: ollama-server-2 + labels: + app.kubernetes.io/controller: server-2 + app.kubernetes.io/instance: ollama + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ollama + helm.sh/chart: ollama-4.4.0 + namespace: ollama +spec: + revisionHistoryLimit: 3 + replicas: 1 + strategy: + type: Recreate + selector: + matchLabels: + app.kubernetes.io/controller: server-2 + app.kubernetes.io/name: ollama + app.kubernetes.io/instance: ollama + template: + metadata: + labels: + app.kubernetes.io/controller: server-2 + app.kubernetes.io/instance: ollama + app.kubernetes.io/name: ollama + ollama-type: server + spec: + enableServiceLinks: false + serviceAccountName: default + automountServiceAccountToken: true + hostIPC: false + hostNetwork: false + hostPID: false + dnsPolicy: ClusterFirst + affinity: + podAntiAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + - labelSelector: + matchExpressions: + - key: ollama-type + operator: In + values: + - server + topologyKey: kubernetes.io/hostname + containers: + - env: + - name: OLLAMA_KEEP_ALIVE + value: 24h + - name: OLLAMA_HOST + value: 0.0.0.0 + image: ollama/ollama:0.13.1 + imagePullPolicy: IfNotPresent + name: main + resources: + limits: + gpu.intel.com/i915: 1 + requests: + cpu: 100m + gpu.intel.com/i915: 1 + memory: 1Gi + volumeMounts: + - mountPath: /root/.ollama + name: server-2 + volumes: + - name: server-2 + persistentVolumeClaim: + claimName: ollama-server-2 +--- +# Source: ollama/charts/ollama/templates/common.yaml +apiVersion: apps/v1 +kind: Deployment metadata: name: ollama-server-3 labels: @@ -378,148 +520,6 @@ spec: persistentVolumeClaim: claimName: ollama-web-data --- -# Source: ollama/charts/ollama/templates/common.yaml -apiVersion: apps/v1 -kind: Deployment -metadata: - name: ollama-server-1 - labels: - app.kubernetes.io/controller: server-1 - app.kubernetes.io/instance: ollama - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: ollama - helm.sh/chart: ollama-4.4.0 - namespace: ollama -spec: - revisionHistoryLimit: 3 - replicas: 1 - strategy: - type: Recreate - selector: - matchLabels: - app.kubernetes.io/controller: server-1 - app.kubernetes.io/name: ollama - app.kubernetes.io/instance: ollama - template: - metadata: - labels: - app.kubernetes.io/controller: server-1 - app.kubernetes.io/instance: ollama - app.kubernetes.io/name: ollama - ollama-type: server - spec: - enableServiceLinks: false - serviceAccountName: default - automountServiceAccountToken: true - hostIPC: false - hostNetwork: false - hostPID: false - dnsPolicy: ClusterFirst - affinity: - podAntiAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - - labelSelector: - matchExpressions: - - key: ollama-type - operator: In - values: - - server - topologyKey: kubernetes.io/hostname - containers: - - env: - - name: OLLAMA_KEEP_ALIVE - value: 24h - - name: OLLAMA_HOST - value: 0.0.0.0 - image: ollama/ollama:0.13.1 - imagePullPolicy: IfNotPresent - name: main - resources: - limits: - gpu.intel.com/i915: 1 - requests: - cpu: 100m - gpu.intel.com/i915: 1 - memory: 1Gi - volumeMounts: - - mountPath: /root/.ollama - name: server-1 - volumes: - - name: server-1 - persistentVolumeClaim: - claimName: ollama-server-1 ---- -# Source: ollama/charts/ollama/templates/common.yaml -apiVersion: apps/v1 -kind: Deployment -metadata: - name: ollama-server-2 - labels: - app.kubernetes.io/controller: server-2 - app.kubernetes.io/instance: ollama - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: ollama - helm.sh/chart: ollama-4.4.0 - namespace: ollama -spec: - revisionHistoryLimit: 3 - replicas: 1 - strategy: - type: Recreate - selector: - matchLabels: - app.kubernetes.io/controller: server-2 - app.kubernetes.io/name: ollama - app.kubernetes.io/instance: ollama - template: - metadata: - labels: - app.kubernetes.io/controller: server-2 - app.kubernetes.io/instance: ollama - app.kubernetes.io/name: ollama - ollama-type: server - spec: - enableServiceLinks: false - serviceAccountName: default - automountServiceAccountToken: true - hostIPC: false - hostNetwork: false - hostPID: false - dnsPolicy: ClusterFirst - affinity: - podAntiAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - - labelSelector: - matchExpressions: - - key: ollama-type - operator: In - values: - - server - topologyKey: kubernetes.io/hostname - containers: - - env: - - name: OLLAMA_KEEP_ALIVE - value: 24h - - name: OLLAMA_HOST - value: 0.0.0.0 - image: ollama/ollama:0.13.1 - imagePullPolicy: IfNotPresent - name: main - resources: - limits: - gpu.intel.com/i915: 1 - requests: - cpu: 100m - gpu.intel.com/i915: 1 - memory: 1Gi - volumeMounts: - - mountPath: /root/.ollama - name: server-2 - volumes: - - name: server-2 - persistentVolumeClaim: - claimName: ollama-server-2 ---- # Source: ollama/charts/postgres-17-cluster/templates/cluster.yaml apiVersion: postgresql.cnpg.io/v1 kind: Cluster diff --git a/clusters/cl01tl/manifests/qbittorrent/qbittorrent.yaml b/clusters/cl01tl/manifests/qbittorrent/qbittorrent.yaml index 33b501dc3..22a2d8794 100644 --- a/clusters/cl01tl/manifests/qbittorrent/qbittorrent.yaml +++ b/clusters/cl01tl/manifests/qbittorrent/qbittorrent.yaml @@ -254,27 +254,6 @@ spec: --- kind: PersistentVolumeClaim apiVersion: v1 -metadata: - name: qbittorrent-qbit-manage-config-data - labels: - app.kubernetes.io/instance: qbittorrent - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: qbittorrent - helm.sh/chart: qbittorrent-4.4.0 - annotations: - helm.sh/resource-policy: keep - namespace: qbittorrent -spec: - accessModes: - - "ReadWriteOnce" - resources: - requests: - storage: "1Gi" - storageClassName: "ceph-block" ---- -# Source: qbittorrent/charts/qbittorrent/templates/common.yaml -kind: PersistentVolumeClaim -apiVersion: v1 metadata: name: qbittorrent-qui-config-data labels: @@ -314,6 +293,27 @@ spec: storage: "1Gi" storageClassName: "ceph-block" --- +# Source: qbittorrent/charts/qbittorrent/templates/common.yaml +kind: PersistentVolumeClaim +apiVersion: v1 +metadata: + name: qbittorrent-qbit-manage-config-data + labels: + app.kubernetes.io/instance: qbittorrent + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: qbittorrent + helm.sh/chart: qbittorrent-4.4.0 + annotations: + helm.sh/resource-policy: keep + namespace: qbittorrent +spec: + accessModes: + - "ReadWriteOnce" + resources: + requests: + storage: "1Gi" + storageClassName: "ceph-block" +--- # Source: qbittorrent/templates/persistent-volume-claim.yaml apiVersion: v1 kind: PersistentVolumeClaim @@ -439,6 +439,83 @@ spec: # Source: qbittorrent/charts/qbittorrent/templates/common.yaml apiVersion: apps/v1 kind: Deployment +metadata: + name: qbittorrent-qui + labels: + app.kubernetes.io/controller: qui + app.kubernetes.io/instance: qbittorrent + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: qbittorrent + helm.sh/chart: qbittorrent-4.4.0 + namespace: qbittorrent +spec: + revisionHistoryLimit: 3 + replicas: 1 + strategy: + type: Recreate + selector: + matchLabels: + app.kubernetes.io/controller: qui + app.kubernetes.io/name: qbittorrent + app.kubernetes.io/instance: qbittorrent + template: + metadata: + labels: + app.kubernetes.io/controller: qui + app.kubernetes.io/instance: qbittorrent + app.kubernetes.io/name: qbittorrent + spec: + enableServiceLinks: false + serviceAccountName: default + automountServiceAccountToken: true + hostIPC: false + hostNetwork: false + hostPID: false + dnsPolicy: ClusterFirst + containers: + - env: + - name: QUI__METRICS_ENABLED + value: "true" + - name: QUI__METRICS_HOST + value: 0.0.0.0 + - name: QUI__METRICS_PORT + value: "9074" + - name: QUI__OIDC_ENABLED + value: "true" + - name: QUI__OIDC_ISSUER + value: https://auth.alexlebens.dev/application/o/qui/ + - name: QUI__OIDC_CLIENT_ID + valueFrom: + secretKeyRef: + key: client + name: qui-oidc-secret + - name: QUI__OIDC_CLIENT_SECRET + valueFrom: + secretKeyRef: + key: secret + name: qui-oidc-secret + - name: QUI__OIDC_REDIRECT_URL + value: https://qui.alexlebens.net/api/auth/oidc/callback + - name: QUI__OIDC_DISABLE_BUILT_IN_LOGIN + value: "false" + image: ghcr.io/autobrr/qui:v1.8.1 + imagePullPolicy: IfNotPresent + name: qui + resources: + requests: + cpu: 10m + memory: 128Mi + volumeMounts: + - mountPath: /config + name: qui-config-data + volumes: + - name: qui-config-data + persistentVolumeClaim: + claimName: qbittorrent-qui-config-data +--- +# Source: qbittorrent/charts/qbittorrent/templates/common.yaml +apiVersion: apps/v1 +kind: Deployment metadata: name: qbittorrent-main labels: @@ -729,83 +806,6 @@ spec: persistentVolumeClaim: claimName: qbittorrent-nfs-storage --- -# Source: qbittorrent/charts/qbittorrent/templates/common.yaml -apiVersion: apps/v1 -kind: Deployment -metadata: - name: qbittorrent-qui - labels: - app.kubernetes.io/controller: qui - app.kubernetes.io/instance: qbittorrent - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: qbittorrent - helm.sh/chart: qbittorrent-4.4.0 - namespace: qbittorrent -spec: - revisionHistoryLimit: 3 - replicas: 1 - strategy: - type: Recreate - selector: - matchLabels: - app.kubernetes.io/controller: qui - app.kubernetes.io/name: qbittorrent - app.kubernetes.io/instance: qbittorrent - template: - metadata: - labels: - app.kubernetes.io/controller: qui - app.kubernetes.io/instance: qbittorrent - app.kubernetes.io/name: qbittorrent - spec: - enableServiceLinks: false - serviceAccountName: default - automountServiceAccountToken: true - hostIPC: false - hostNetwork: false - hostPID: false - dnsPolicy: ClusterFirst - containers: - - env: - - name: QUI__METRICS_ENABLED - value: "true" - - name: QUI__METRICS_HOST - value: 0.0.0.0 - - name: QUI__METRICS_PORT - value: "9074" - - name: QUI__OIDC_ENABLED - value: "true" - - name: QUI__OIDC_ISSUER - value: https://auth.alexlebens.dev/application/o/qui/ - - name: QUI__OIDC_CLIENT_ID - valueFrom: - secretKeyRef: - key: client - name: qui-oidc-secret - - name: QUI__OIDC_CLIENT_SECRET - valueFrom: - secretKeyRef: - key: secret - name: qui-oidc-secret - - name: QUI__OIDC_REDIRECT_URL - value: https://qui.alexlebens.net/api/auth/oidc/callback - - name: QUI__OIDC_DISABLE_BUILT_IN_LOGIN - value: "false" - image: ghcr.io/autobrr/qui:v1.8.1 - imagePullPolicy: IfNotPresent - name: qui - resources: - requests: - cpu: 10m - memory: 128Mi - volumeMounts: - - mountPath: /config - name: qui-config-data - volumes: - - name: qui-config-data - persistentVolumeClaim: - claimName: qbittorrent-qui-config-data ---- # Source: qbittorrent/templates/external-secret.yaml apiVersion: external-secrets.io/v1 kind: ExternalSecret diff --git a/clusters/cl01tl/manifests/s3-exporter/s3-exporter.yaml b/clusters/cl01tl/manifests/s3-exporter/s3-exporter.yaml index 6f2fb3d96..c3e86fb39 100644 --- a/clusters/cl01tl/manifests/s3-exporter/s3-exporter.yaml +++ b/clusters/cl01tl/manifests/s3-exporter/s3-exporter.yaml @@ -99,6 +99,75 @@ spec: --- apiVersion: apps/v1 kind: Deployment +metadata: + name: s3-exporter-ceph-directus + labels: + app.kubernetes.io/controller: ceph-directus + app.kubernetes.io/instance: s3-exporter + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: s3-exporter + helm.sh/chart: s3-exporter-4.4.0 + namespace: s3-exporter +spec: + revisionHistoryLimit: 3 + replicas: 1 + strategy: + type: Recreate + selector: + matchLabels: + app.kubernetes.io/controller: ceph-directus + app.kubernetes.io/name: s3-exporter + app.kubernetes.io/instance: s3-exporter + template: + metadata: + labels: + app.kubernetes.io/controller: ceph-directus + app.kubernetes.io/instance: s3-exporter + app.kubernetes.io/name: s3-exporter + spec: + enableServiceLinks: false + serviceAccountName: default + automountServiceAccountToken: true + hostIPC: false + hostNetwork: false + hostPID: false + dnsPolicy: ClusterFirst + containers: + - env: + - name: S3_NAME + value: ceph-directus + - name: S3_ENDPOINT + valueFrom: + secretKeyRef: + key: BUCKET_HOST + name: s3-ceph-directus-secret + - name: S3_ACCESS_KEY + valueFrom: + secretKeyRef: + key: AWS_ACCESS_KEY_ID + name: s3-ceph-directus-secret + - name: S3_SECRET_KEY + valueFrom: + secretKeyRef: + key: AWS_SECRET_ACCESS_KEY + name: s3-ceph-directus-secret + - name: S3_REGION + value: us-east-1 + - name: LOG_LEVEL + value: info + - name: S3_FORCE_PATH_STYLE + value: "true" + image: molu8bits/s3bucket_exporter:1.0.2 + imagePullPolicy: IfNotPresent + name: main + resources: + requests: + cpu: 10m + memory: 64Mi +--- +# Source: s3-exporter/charts/s3-exporter/templates/common.yaml +apiVersion: apps/v1 +kind: Deployment metadata: name: s3-exporter-digital-ocean labels: @@ -297,75 +366,6 @@ spec: cpu: 10m memory: 64Mi --- -# Source: s3-exporter/charts/s3-exporter/templates/common.yaml -apiVersion: apps/v1 -kind: Deployment -metadata: - name: s3-exporter-ceph-directus - labels: - app.kubernetes.io/controller: ceph-directus - app.kubernetes.io/instance: s3-exporter - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: s3-exporter - helm.sh/chart: s3-exporter-4.4.0 - namespace: s3-exporter -spec: - revisionHistoryLimit: 3 - replicas: 1 - strategy: - type: Recreate - selector: - matchLabels: - app.kubernetes.io/controller: ceph-directus - app.kubernetes.io/name: s3-exporter - app.kubernetes.io/instance: s3-exporter - template: - metadata: - labels: - app.kubernetes.io/controller: ceph-directus - app.kubernetes.io/instance: s3-exporter - app.kubernetes.io/name: s3-exporter - spec: - enableServiceLinks: false - serviceAccountName: default - automountServiceAccountToken: true - hostIPC: false - hostNetwork: false - hostPID: false - dnsPolicy: ClusterFirst - containers: - - env: - - name: S3_NAME - value: ceph-directus - - name: S3_ENDPOINT - valueFrom: - secretKeyRef: - key: BUCKET_HOST - name: s3-ceph-directus-secret - - name: S3_ACCESS_KEY - valueFrom: - secretKeyRef: - key: AWS_ACCESS_KEY_ID - name: s3-ceph-directus-secret - - name: S3_SECRET_KEY - valueFrom: - secretKeyRef: - key: AWS_SECRET_ACCESS_KEY - name: s3-ceph-directus-secret - - name: S3_REGION - value: us-east-1 - - name: LOG_LEVEL - value: info - - name: S3_FORCE_PATH_STYLE - value: "true" - image: molu8bits/s3bucket_exporter:1.0.2 - imagePullPolicy: IfNotPresent - name: main - resources: - requests: - cpu: 10m - memory: 64Mi ---- # Source: s3-exporter/templates/external-secret.yaml apiVersion: external-secrets.io/v1 kind: ExternalSecret diff --git a/clusters/cl01tl/manifests/searxng/searxng.yaml b/clusters/cl01tl/manifests/searxng/searxng.yaml index 9069aebea..731f2d2df 100644 --- a/clusters/cl01tl/manifests/searxng/searxng.yaml +++ b/clusters/cl01tl/manifests/searxng/searxng.yaml @@ -4,7 +4,7 @@ kind: PersistentVolumeClaim apiVersion: v1 metadata: - name: searxng-browser-data + name: searxng-api-data labels: app.kubernetes.io/instance: searxng app.kubernetes.io/managed-by: Helm @@ -23,7 +23,7 @@ spec: kind: PersistentVolumeClaim apiVersion: v1 metadata: - name: searxng-api-data + name: searxng-browser-data labels: app.kubernetes.io/instance: searxng app.kubernetes.io/managed-by: Helm diff --git a/clusters/cl01tl/manifests/talos/talos.yaml b/clusters/cl01tl/manifests/talos/talos.yaml index 749981174..3df785f4e 100644 --- a/clusters/cl01tl/manifests/talos/talos.yaml +++ b/clusters/cl01tl/manifests/talos/talos.yaml @@ -186,6 +186,78 @@ spec: --- apiVersion: batch/v1 kind: CronJob +metadata: + name: etcd-defrag-defrag-2 + labels: + app.kubernetes.io/controller: defrag-2 + app.kubernetes.io/instance: talos + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: talos + helm.sh/chart: etcd-defrag-4.4.0 + namespace: talos +spec: + suspend: false + concurrencyPolicy: Forbid + startingDeadlineSeconds: 90 + timeZone: US/Central + schedule: "10 0 * * 0" + successfulJobsHistoryLimit: 3 + failedJobsHistoryLimit: 3 + jobTemplate: + spec: + parallelism: 1 + backoffLimit: 3 + template: + metadata: + labels: + app.kubernetes.io/controller: defrag-2 + app.kubernetes.io/instance: talos + app.kubernetes.io/name: talos + spec: + enableServiceLinks: false + serviceAccountName: default + automountServiceAccountToken: true + hostIPC: false + hostNetwork: false + hostPID: false + dnsPolicy: ClusterFirst + restartPolicy: Never + nodeSelector: + node-role.kubernetes.io/control-plane: "" + tolerations: + - effect: NoSchedule + key: node-role.kubernetes.io/control-plane + operator: Exists + containers: + - args: + - etcd + - defrag + - -n + - 10.232.1.12 + env: + - name: TALOSCONFIG + value: /tmp/.talos/config + image: ghcr.io/siderolabs/talosctl:v1.11.5 + imagePullPolicy: IfNotPresent + name: main + resources: + requests: + cpu: 100m + memory: 128Mi + volumeMounts: + - mountPath: /tmp/.talos/config + mountPropagation: None + name: talos-config-2 + readOnly: true + subPath: config + volumes: + - name: talos-config-2 + secret: + secretName: talos-etcd-defrag-secret +--- +# Source: talos/charts/etcd-defrag/templates/common.yaml +apiVersion: batch/v1 +kind: CronJob metadata: name: etcd-defrag-defrag-3 labels: @@ -327,78 +399,6 @@ spec: secret: secretName: talos-etcd-defrag-secret --- -# Source: talos/charts/etcd-defrag/templates/common.yaml -apiVersion: batch/v1 -kind: CronJob -metadata: - name: etcd-defrag-defrag-2 - labels: - app.kubernetes.io/controller: defrag-2 - app.kubernetes.io/instance: talos - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: talos - helm.sh/chart: etcd-defrag-4.4.0 - namespace: talos -spec: - suspend: false - concurrencyPolicy: Forbid - startingDeadlineSeconds: 90 - timeZone: US/Central - schedule: "10 0 * * 0" - successfulJobsHistoryLimit: 3 - failedJobsHistoryLimit: 3 - jobTemplate: - spec: - parallelism: 1 - backoffLimit: 3 - template: - metadata: - labels: - app.kubernetes.io/controller: defrag-2 - app.kubernetes.io/instance: talos - app.kubernetes.io/name: talos - spec: - enableServiceLinks: false - serviceAccountName: default - automountServiceAccountToken: true - hostIPC: false - hostNetwork: false - hostPID: false - dnsPolicy: ClusterFirst - restartPolicy: Never - nodeSelector: - node-role.kubernetes.io/control-plane: "" - tolerations: - - effect: NoSchedule - key: node-role.kubernetes.io/control-plane - operator: Exists - containers: - - args: - - etcd - - defrag - - -n - - 10.232.1.12 - env: - - name: TALOSCONFIG - value: /tmp/.talos/config - image: ghcr.io/siderolabs/talosctl:v1.11.5 - imagePullPolicy: IfNotPresent - name: main - resources: - requests: - cpu: 100m - memory: 128Mi - volumeMounts: - - mountPath: /tmp/.talos/config - mountPropagation: None - name: talos-config-2 - readOnly: true - subPath: config - volumes: - - name: talos-config-2 - secret: - secretName: talos-etcd-defrag-secret ---- # Source: talos/templates/external-secret.yaml apiVersion: external-secrets.io/v1 kind: ExternalSecret diff --git a/clusters/cl01tl/manifests/vault/vault.yaml b/clusters/cl01tl/manifests/vault/vault.yaml index 51a9cd6f1..111d7d079 100644 --- a/clusters/cl01tl/manifests/vault/vault.yaml +++ b/clusters/cl01tl/manifests/vault/vault.yaml @@ -251,6 +251,54 @@ spec: --- apiVersion: apps/v1 kind: Deployment +metadata: + name: vault-unseal-unseal-3 + labels: + app.kubernetes.io/controller: unseal-3 + app.kubernetes.io/instance: vault + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: vault + helm.sh/chart: unseal-4.4.0 + namespace: vault +spec: + revisionHistoryLimit: 3 + replicas: 1 + strategy: + type: Recreate + selector: + matchLabels: + app.kubernetes.io/controller: unseal-3 + app.kubernetes.io/name: vault + app.kubernetes.io/instance: vault + template: + metadata: + labels: + app.kubernetes.io/controller: unseal-3 + app.kubernetes.io/instance: vault + app.kubernetes.io/name: vault + spec: + enableServiceLinks: false + serviceAccountName: default + automountServiceAccountToken: true + hostIPC: false + hostNetwork: false + hostPID: false + dnsPolicy: ClusterFirst + containers: + - envFrom: + - secretRef: + name: vault-unseal-config-3 + image: ghcr.io/lrstanley/vault-unseal:0.7.2 + imagePullPolicy: IfNotPresent + name: main + resources: + requests: + cpu: 10m + memory: 24Mi +--- +# Source: vault/charts/unseal/templates/common.yaml +apiVersion: apps/v1 +kind: Deployment metadata: name: vault-unseal-unseal-1 labels: @@ -344,54 +392,6 @@ spec: cpu: 10m memory: 24Mi --- -# Source: vault/charts/unseal/templates/common.yaml -apiVersion: apps/v1 -kind: Deployment -metadata: - name: vault-unseal-unseal-3 - labels: - app.kubernetes.io/controller: unseal-3 - app.kubernetes.io/instance: vault - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: vault - helm.sh/chart: unseal-4.4.0 - namespace: vault -spec: - revisionHistoryLimit: 3 - replicas: 1 - strategy: - type: Recreate - selector: - matchLabels: - app.kubernetes.io/controller: unseal-3 - app.kubernetes.io/name: vault - app.kubernetes.io/instance: vault - template: - metadata: - labels: - app.kubernetes.io/controller: unseal-3 - app.kubernetes.io/instance: vault - app.kubernetes.io/name: vault - spec: - enableServiceLinks: false - serviceAccountName: default - automountServiceAccountToken: true - hostIPC: false - hostNetwork: false - hostPID: false - dnsPolicy: ClusterFirst - containers: - - envFrom: - - secretRef: - name: vault-unseal-config-3 - image: ghcr.io/lrstanley/vault-unseal:0.7.2 - imagePullPolicy: IfNotPresent - name: main - resources: - requests: - cpu: 10m - memory: 24Mi ---- # Source: vault/charts/vault/templates/server-statefulset.yaml # StatefulSet to run the actual vault server cluster. apiVersion: apps/v1