2 Commits

Author SHA1 Message Date
5b61f70f64 Update ghcr.io/immich-app/immich-server Docker tag to v1.135.3
All checks were successful
lint-test-helm / helm-lint (pull_request) Successful in 9s
2025-07-08 23:24:27 +00:00
5eefb67cae update config
All checks were successful
lint-test-helm / helm-lint (push) Successful in 8s
renovate / renovate (push) Successful in 56s
2025-07-08 18:23:43 -05:00
3 changed files with 28 additions and 48 deletions

View File

@@ -9,7 +9,7 @@ immich:
main: main:
image: image:
repository: ghcr.io/immich-app/immich-server repository: ghcr.io/immich-app/immich-server
tag: v1.132.3 tag: v1.135.3
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
env: env:
- name: TZ - name: TZ

View File

@@ -27,43 +27,6 @@ spec:
metadataPolicy: None metadataPolicy: None
property: VAULT_APPROLE_SECRET_ID property: VAULT_APPROLE_SECRET_ID
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: vault-snapshot-s3
namespace: {{ .Release.Namespace }}
labels:
app.kubernetes.io/name: vault-snapshot-s3
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/part-of: {{ .Release.Name }}
spec:
secretStoreRef:
kind: ClusterSecretStore
name: vault
data:
- secretKey: AWS_ACCESS_KEY_ID
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /digital-ocean/home-infra/vault-backup
metadataPolicy: None
property: AWS_ACCESS_KEY_ID
- secretKey: AWS_SECRET_ACCESS_KEY
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /digital-ocean/home-infra/vault-backup
metadataPolicy: None
property: AWS_SECRET_ACCESS_KEY
- secretKey: S3_REPOSITORY
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /digital-ocean/home-infra/vault-backup
metadataPolicy: None
property: S3_REPOSITORY
--- ---
apiVersion: external-secrets.io/v1 apiVersion: external-secrets.io/v1
kind: ExternalSecret kind: ExternalSecret
@@ -83,9 +46,16 @@ spec:
remoteRef: remoteRef:
conversionStrategy: Default conversionStrategy: Default
decodingStrategy: None decodingStrategy: None
key: /cl01tl/vault/snapshot key: /digital-ocean/home-infra/vault-backup
metadataPolicy: None metadataPolicy: None
property: s3cfg property: s3cfg
- secretKey: BUCKET
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /digital-ocean/home-infra/vault-backup
metadataPolicy: None
property: BUCKET
--- ---
apiVersion: external-secrets.io/v1 apiVersion: external-secrets.io/v1

View File

@@ -206,12 +206,15 @@ snapshot:
- -ec - -ec
- | - |
echo ">> Running S3 backup for Vault snapshot" echo ">> Running S3 backup for Vault snapshot"
s3cmd put --no-check-md5 --no-check-certificate -v /opt/backup/vault-snapshot-s3.snap ${S3_REPOSITORY}/vault-snapshot-$(date +"%Y%m%d-%H-%M").snap; s3cmd put --no-check-md5 --no-check-certificate -v /opt/backup/vault-snapshot-s3.snap ${BUCKET}/cl01tl/cl01tl-vault-snapshots/vault-snapshot-$(date +"%Y%m%d-%H-%M").snap;
rm -f /opt/backup/vault-snapshot-s3.snap; rm -f /opt/backup/vault-snapshot-s3.snap;
echo ">> Completed S3 backup for Vault snapshot" echo ">> Completed S3 backup for Vault snapshot"
envFrom: env:
- secretRef: - name: BUCKET
name: vault-snapshot-s3 valueFrom:
secretKeyRef:
name: gitea-s3cmd-config
key: BUCKET
resources: resources:
requests: requests:
cpu: 100m cpu: 100m
@@ -227,17 +230,24 @@ snapshot:
- -ec - -ec
- | - |
export MONTH_AGO=$(date -d @$(( $(date +%s) - 2592000 )) +%Y-%m-%d\ %H:%M:%S); export MONTH_AGO=$(date -d @$(( $(date +%s) - 2592000 )) +%Y-%m-%d\ %H:%M:%S);
export TIME_RANGE="$MONTH_AGO"
echo ">> Running S3 prune for Vault snapshot repository" echo ">> Running S3 prune for Vault snapshot repository"
echo ">> Backups prior to '$MONTH_AGO' will be removed" echo ">> Backups prior to '$TIME_RANGE' will be removed"
s3cmd ls -v $S3_REPOSITORY | echo ">> File list:"
s3cmd ls -v ${BUCKET}/cl01tl/cl01tl-vault-snapshots/
echo ">> Deleting ..."
s3cmd ls -v ${BUCKET}/cl01tl/cl01tl-vault-snapshots/ |
awk -v month_ago="$MONTH_AGO" '$1 < month_ago {print $4}' | awk -v month_ago="$MONTH_AGO" '$1 < month_ago {print $4}' |
while read file; while read file;
do s3cmd del -v "$file"; do s3cmd del -v "$file";
done; done;
echo ">> Completed S3 prune for Vault snapshot repository" echo ">> Completed S3 prune for Vault snapshot repository"
envFrom: env:
- secretRef: - name: BUCKET
name: vault-snapshot-s3 valueFrom:
secretKeyRef:
name: gitea-s3cmd-config
key: BUCKET
resources: resources:
requests: requests:
cpu: 100m cpu: 100m