Automated Manifest Update #5706

Merged
alexlebens merged 1 commits from auto/update-manifests into manifests 2026-04-08 02:08:18 +00:00
22 changed files with 33 additions and 109 deletions

View File

@@ -58,7 +58,7 @@ spec:
resources:
requests:
cpu: 50m
memory: 90Mi
memory: 512Mi
image: hashicorp/vault:1.21.4@sha256:4e33b126a59c0c333b76fb4e894722462659a6bec7c48c9ee8cea56fccfd2569
imagePullPolicy: IfNotPresent
command:
@@ -102,8 +102,6 @@ spec:
- name: HOME
value: "/home/vault"
volumeMounts:
- name: audit
mountPath: /vault/audit
- name: data
mountPath: /vault/data
- name: config
@@ -147,14 +145,3 @@ spec:
requests:
storage: 1Gi
storageClassName: ceph-block
- apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: audit
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 5Gi
storageClassName: ceph-block

View File

@@ -64,7 +64,7 @@ spec:
secretKeyRef:
key: secret
name: vaultwarden-oidc-secret
image: ghcr.io/vaultwarden/server:1.35.4@sha256:43498a94b22f9563f2a94b53760ab3e710eefc0d0cac2efda4b12b9eb8690664
image: ghcr.io/dani-garcia/vaultwarden:1.35.4@sha256:43498a94b22f9563f2a94b53760ab3e710eefc0d0cac2efda4b12b9eb8690664
name: main
resources:
requests:

View File

@@ -47,7 +47,7 @@ spec:
- --metrics-require-rbac=false
command:
- /manager
image: "0.15.0@sha256:4fedd41b3101dde090542009c4177f703d241bf4760d1767bd9df08fd8fd93a4"
image: "quay.io/backube/volsync:0.15.0@sha256:4fedd41b3101dde090542009c4177f703d241bf4760d1767bd9df08fd8fd93a4"
imagePullPolicy: IfNotPresent
env:
- name: VOLSYNC_NAMESPACE

View File

@@ -39,10 +39,9 @@ spec:
value: ollama-server-2.ollama
- name: WHODB_OLLAMA_PORT
value: "11434"
image: clidey/whodb:0.104.0
imagePullPolicy: IfNotPresent
image: clidey/whodb:0.104.0@sha256:ab485c021b862aac50bb88658f3342ca01d3eba33e933353692bc9989b2912c4
name: main
resources:
requests:
cpu: 10m
memory: 256Mi
cpu: 1m
memory: 20Mi

View File

@@ -23,7 +23,7 @@ spec:
name: whodb
namespace: whodb
port: 80
weight: 100
weight: 1
matches:
- path:
type: PathPrefix

View File

@@ -5,10 +5,10 @@ metadata:
namespace: yamtrack
labels:
app.kubernetes.io/name: yamtrack-postgresql-18-cluster
helm.sh/chart: postgres-18-cluster-7.10.0
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: yamtrack
app.kubernetes.io/part-of: yamtrack
app.kubernetes.io/version: "7.10.0"
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
instances: 3
@@ -26,8 +26,8 @@ spec:
limits:
hugepages-2Mi: 256Mi
requests:
cpu: 100m
memory: 256Mi
cpu: 20m
memory: 80Mi
affinity:
enablePodAntiAffinity: true
topologyKey: kubernetes.io/hostname

View File

@@ -36,7 +36,7 @@ spec:
containers:
- env:
- name: TZ
value: US/Central
value: America/Chicago
- name: URLS
value: https://yamtrack.alexlebens.net
- name: REGISTRATION
@@ -80,10 +80,9 @@ spec:
secretKeyRef:
key: port
name: yamtrack-postgresql-18-cluster-app
image: ghcr.io/fuzzygrim/yamtrack:0.25.0
imagePullPolicy: IfNotPresent
image: ghcr.io/fuzzygrim/yamtrack:0.25.0@sha256:df76008258452a6cda73d971dc4ffbcbca96c5220154a02c9b70bf0bb0e24931
name: main
resources:
requests:
cpu: 10m
memory: 256Mi
memory: 380Mi

View File

@@ -14,8 +14,5 @@ spec:
data:
- secretKey: SECRET
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /cl01tl/yamtrack/config
metadataPolicy: None
property: SECRET

View File

@@ -14,8 +14,5 @@ spec:
data:
- secretKey: SOCIALACCOUNT_PROVIDERS
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /authentik/oidc/yamtrack
metadataPolicy: None
property: SOCIALACCOUNT_PROVIDERS

View File

@@ -5,10 +5,10 @@ metadata:
namespace: yamtrack
labels:
app.kubernetes.io/name: yamtrack-postgresql-18-backup-garage-local-secret
helm.sh/chart: postgres-18-cluster-7.10.0
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: yamtrack
app.kubernetes.io/part-of: yamtrack
app.kubernetes.io/version: "7.10.0"
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
secretStoreRef:

View File

@@ -4,10 +4,10 @@ metadata:
name: yamtrack-postgresql-18-recovery-secret
namespace: yamtrack
labels:
helm.sh/chart: postgres-18-cluster-7.10.0
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: yamtrack
app.kubernetes.io/part-of: yamtrack
app.kubernetes.io/version: "7.10.0"
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: yamtrack-postgresql-18-recovery-secret
spec:

View File

@@ -23,7 +23,7 @@ spec:
name: yamtrack
namespace: yamtrack
port: 80
weight: 100
weight: 1
matches:
- path:
type: PathPrefix

View File

@@ -5,10 +5,10 @@ metadata:
namespace: yamtrack
labels:
app.kubernetes.io/name: yamtrack-postgresql-18-backup-garage-local
helm.sh/chart: postgres-18-cluster-7.10.0
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: yamtrack
app.kubernetes.io/part-of: yamtrack
app.kubernetes.io/version: "7.10.0"
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
retentionPolicy: 7d

View File

@@ -4,10 +4,10 @@ metadata:
name: "yamtrack-postgresql-18-recovery"
namespace: yamtrack
labels:
helm.sh/chart: postgres-18-cluster-7.10.0
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: yamtrack
app.kubernetes.io/part-of: yamtrack
app.kubernetes.io/version: "7.10.0"
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: "yamtrack-postgresql-18-recovery"
spec:

View File

@@ -5,10 +5,10 @@ metadata:
namespace: yamtrack
labels:
app.kubernetes.io/name: yamtrack-postgresql-18-alert-rules
helm.sh/chart: postgres-18-cluster-7.10.0
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: yamtrack
app.kubernetes.io/part-of: yamtrack
app.kubernetes.io/version: "7.10.0"
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
groups:

View File

@@ -5,10 +5,10 @@ metadata:
namespace: yamtrack
labels:
app.kubernetes.io/name: "yamtrack-postgresql-18-scheduled-backup-live-backup"
helm.sh/chart: postgres-18-cluster-7.10.0
helm.sh/chart: postgres-18-cluster-7.11.2
app.kubernetes.io/instance: yamtrack
app.kubernetes.io/part-of: yamtrack
app.kubernetes.io/version: "7.10.0"
app.kubernetes.io/version: "7.11.2"
app.kubernetes.io/managed-by: Helm
spec:
immediate: true

View File

@@ -95,7 +95,7 @@ spec:
resources:
requests:
cpu: 10m
memory: 128Mi
memory: 20Mi
volumeMounts:
- name: valkey-data
mountPath: /data
@@ -117,8 +117,8 @@ spec:
port: metrics
resources:
requests:
cpu: 10m
memory: 64M
cpu: 1m
memory: 10M
env:
- name: REDIS_ALIAS
value: yamtrack-valkey

View File

@@ -31,6 +31,7 @@ spec:
automountServiceAccountToken: true
securityContext:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
runAsGroup: 1000
runAsUser: 1000
hostIPC: false
@@ -48,12 +49,11 @@ spec:
- name: YUBAL_LOG_LEVEL
value: INFO
image: ghcr.io/guillevc/yubal:0.7.2@sha256:906b7c90b738e77ad140178f6a5145f98c12af36e8321d427148c092836c37be
imagePullPolicy: IfNotPresent
name: main
resources:
requests:
cpu: 10m
memory: 128Mi
memory: 200Mi
volumeMounts:
- mountPath: /app/config
name: config

View File

@@ -1,42 +0,0 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: yubal-wireguard-conf
namespace: yubal
labels:
app.kubernetes.io/name: yubal-wireguard-conf
app.kubernetes.io/instance: yubal
app.kubernetes.io/part-of: yubal
spec:
secretStoreRef:
kind: ClusterSecretStore
name: vault
data:
- secretKey: private-key
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /airvpn/conf/cl01tl
metadataPolicy: None
property: private-key
- secretKey: preshared-key
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /airvpn/conf/cl01tl
metadataPolicy: None
property: preshared-key
- secretKey: addresses
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /airvpn/conf/cl01tl
metadataPolicy: None
property: addresses
- secretKey: input-ports
remoteRef:
conversionStrategy: Default
decodingStrategy: None
key: /airvpn/conf/cl01tl
metadataPolicy: None
property: input-ports

View File

@@ -23,7 +23,7 @@ spec:
name: yubal
namespace: yubal
port: 80
weight: 100
weight: 1
matches:
- path:
type: PathPrefix

View File

@@ -1,11 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: yubal
labels:
app.kubernetes.io/name: yubal
app.kubernetes.io/instance: yubal
app.kubernetes.io/part-of: yubal
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/warn: privileged

View File

@@ -7,8 +7,6 @@ metadata:
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: yubal
helm.sh/chart: yubal-4.6.2
annotations:
helm.sh/resource-policy: keep
namespace: yubal
spec:
accessModes: