apiVersion: apps/v1 kind: Deployment metadata: name: yubal labels: app.kubernetes.io/controller: main app.kubernetes.io/instance: yubal app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal helm.sh/chart: yubal-4.6.2 namespace: yubal spec: revisionHistoryLimit: 3 replicas: 1 strategy: type: Recreate selector: matchLabels: app.kubernetes.io/controller: main app.kubernetes.io/name: yubal app.kubernetes.io/instance: yubal template: metadata: labels: app.kubernetes.io/controller: main app.kubernetes.io/instance: yubal app.kubernetes.io/name: yubal spec: enableServiceLinks: false serviceAccountName: default automountServiceAccountToken: true securityContext: fsGroup: 1000 runAsGroup: 1000 runAsUser: 1000 hostIPC: false hostNetwork: false hostPID: false dnsPolicy: ClusterFirst containers: - env: - name: YUBAL_TZ value: America/Chicago - name: YUBAL_HOST value: 0.0.0.0 - name: YUBAL_PORT value: "8000" - name: YUBAL_LOG_LEVEL value: INFO image: ghcr.io/guillevc/yubal:4.0.0 imagePullPolicy: IfNotPresent name: main resources: requests: cpu: 10m memory: 128Mi volumeMounts: - mountPath: /app/config name: config - mountPath: /app/data name: music volumes: - name: config persistentVolumeClaim: claimName: yubal - name: music persistentVolumeClaim: claimName: yubal-nfs-storage --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: yubal-backup-secret-external namespace: yubal labels: helm.sh/chart: volsync-target-config-0.8.0 app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal app.kubernetes.io/version: "0.8.0" app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal-backup-secret-external spec: secretStoreRef: kind: ClusterSecretStore name: vault target: template: mergePolicy: Merge engineVersion: v2 data: RESTIC_REPOSITORY: "{{ .BUCKET_ENDPOINT }}/yubal/yubal" data: - secretKey: BUCKET_ENDPOINT remoteRef: conversionStrategy: Default decodingStrategy: None key: /volsync/restic/digital-ocean metadataPolicy: None property: BUCKET_ENDPOINT - secretKey: RESTIC_PASSWORD remoteRef: conversionStrategy: Default decodingStrategy: None key: /volsync/restic/digital-ocean metadataPolicy: None property: RESTIC_PASSWORD - secretKey: AWS_DEFAULT_REGION remoteRef: conversionStrategy: Default decodingStrategy: None key: /digital-ocean/home-infra/volsync-backups metadataPolicy: None property: AWS_DEFAULT_REGION - secretKey: AWS_ACCESS_KEY_ID remoteRef: conversionStrategy: Default decodingStrategy: None key: /digital-ocean/home-infra/volsync-backups metadataPolicy: None property: AWS_ACCESS_KEY_ID - secretKey: AWS_SECRET_ACCESS_KEY remoteRef: conversionStrategy: Default decodingStrategy: None key: /digital-ocean/home-infra/volsync-backups metadataPolicy: None property: AWS_SECRET_ACCESS_KEY --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: yubal-backup-secret-local namespace: yubal labels: helm.sh/chart: volsync-target-config-0.8.0 app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal app.kubernetes.io/version: "0.8.0" app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal-backup-secret-local spec: secretStoreRef: kind: ClusterSecretStore name: vault target: template: mergePolicy: Merge engineVersion: v2 data: RESTIC_REPOSITORY: "{{ .BUCKET_ENDPOINT }}/yubal/yubal" data: - secretKey: BUCKET_ENDPOINT remoteRef: conversionStrategy: Default decodingStrategy: None key: /volsync/restic/garage-local metadataPolicy: None property: BUCKET_ENDPOINT - secretKey: RESTIC_PASSWORD remoteRef: conversionStrategy: Default decodingStrategy: None key: /volsync/restic/garage-local metadataPolicy: None property: RESTIC_PASSWORD - secretKey: AWS_DEFAULT_REGION remoteRef: conversionStrategy: Default decodingStrategy: None key: /garage/home-infra/volsync-backups metadataPolicy: None property: ACCESS_REGION - secretKey: AWS_ACCESS_KEY_ID remoteRef: conversionStrategy: Default decodingStrategy: None key: /garage/home-infra/volsync-backups metadataPolicy: None property: ACCESS_KEY_ID - secretKey: AWS_SECRET_ACCESS_KEY remoteRef: conversionStrategy: Default decodingStrategy: None key: /garage/home-infra/volsync-backups metadataPolicy: None property: ACCESS_SECRET_KEY --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: yubal-backup-secret-remote namespace: yubal labels: helm.sh/chart: volsync-target-config-0.8.0 app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal app.kubernetes.io/version: "0.8.0" app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal-backup-secret-remote spec: secretStoreRef: kind: ClusterSecretStore name: vault target: template: mergePolicy: Merge engineVersion: v2 data: RESTIC_REPOSITORY: "{{ .BUCKET_ENDPOINT }}/yubal/yubal" data: - secretKey: BUCKET_ENDPOINT remoteRef: conversionStrategy: Default decodingStrategy: None key: /volsync/restic/garage-remote metadataPolicy: None property: BUCKET_ENDPOINT - secretKey: RESTIC_PASSWORD remoteRef: conversionStrategy: Default decodingStrategy: None key: /volsync/restic/garage-remote metadataPolicy: None property: RESTIC_PASSWORD - secretKey: AWS_DEFAULT_REGION remoteRef: conversionStrategy: Default decodingStrategy: None key: /garage/home-infra/volsync-backups metadataPolicy: None property: ACCESS_REGION - secretKey: AWS_ACCESS_KEY_ID remoteRef: conversionStrategy: Default decodingStrategy: None key: /garage/home-infra/volsync-backups metadataPolicy: None property: ACCESS_KEY_ID - secretKey: AWS_SECRET_ACCESS_KEY remoteRef: conversionStrategy: Default decodingStrategy: None key: /garage/home-infra/volsync-backups metadataPolicy: None property: ACCESS_SECRET_KEY --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: yubal-wireguard-conf namespace: yubal labels: app.kubernetes.io/name: yubal-wireguard-conf app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal spec: secretStoreRef: kind: ClusterSecretStore name: vault data: - secretKey: private-key remoteRef: conversionStrategy: Default decodingStrategy: None key: /protonvpn/conf/cl01tl metadataPolicy: None property: private-key - secretKey: proton-email remoteRef: conversionStrategy: Default decodingStrategy: None key: /protonvpn/conf/cl01tl metadataPolicy: None property: email - secretKey: proton-password remoteRef: conversionStrategy: Default decodingStrategy: None key: /protonvpn/conf/cl01tl metadataPolicy: None property: password --- apiVersion: gateway.networking.k8s.io/v1alpha2 kind: HTTPRoute metadata: name: yubal labels: app.kubernetes.io/instance: yubal app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal helm.sh/chart: yubal-4.6.2 namespace: yubal spec: parentRefs: - group: gateway.networking.k8s.io kind: Gateway name: traefik-gateway namespace: traefik hostnames: - "yubal.alexlebens.net" rules: - backendRefs: - group: "" kind: Service name: yubal namespace: yubal port: 80 weight: 100 matches: - path: type: PathPrefix value: / --- apiVersion: v1 kind: Namespace metadata: name: yubal labels: app.kubernetes.io/name: yubal app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal pod-security.kubernetes.io/audit: privileged pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/warn: privileged --- apiVersion: v1 kind: PersistentVolume metadata: name: yubal-nfs-storage namespace: yubal labels: app.kubernetes.io/name: yubal-nfs-storage app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal spec: persistentVolumeReclaimPolicy: Retain storageClassName: nfs-client capacity: storage: 1Gi accessModes: - ReadWriteMany nfs: path: /volume2/Storage/Music Youtube/ server: synologybond.alexlebens.net mountOptions: - vers=4 - minorversion=1 - noac --- apiVersion: v1 kind: PersistentVolumeClaim metadata: name: yubal-nfs-storage namespace: yubal labels: app.kubernetes.io/name: yubal-nfs-storage app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal spec: volumeName: yubal-nfs-storage storageClassName: nfs-client accessModes: - ReadWriteMany resources: requests: storage: 1Gi --- kind: PersistentVolumeClaim apiVersion: v1 metadata: name: yubal labels: app.kubernetes.io/instance: yubal app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal helm.sh/chart: yubal-4.6.2 annotations: helm.sh/resource-policy: keep namespace: yubal spec: accessModes: - "ReadWriteOnce" resources: requests: storage: "1Gi" storageClassName: "ceph-block" --- apiVersion: volsync.backube/v1alpha1 kind: ReplicationSource metadata: name: yubal-backup-source-external namespace: yubal labels: helm.sh/chart: volsync-target-config-0.8.0 app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal app.kubernetes.io/version: "0.8.0" app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal-backup spec: sourcePVC: yubal trigger: schedule: 34 14 * * * restic: pruneIntervalDays: 7 repository: yubal-backup-secret-external retain: daily: 7 hourly: 0 monthly: 3 weekly: 4 yearly: 1 copyMethod: Snapshot storageClassName: ceph-block volumeSnapshotClassName: ceph-blockpool-snapshot cacheCapacity: 1Gi --- apiVersion: volsync.backube/v1alpha1 kind: ReplicationSource metadata: name: yubal-backup-source-local namespace: yubal labels: helm.sh/chart: volsync-target-config-0.8.0 app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal app.kubernetes.io/version: "0.8.0" app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal-backup spec: sourcePVC: yubal trigger: schedule: 34 11 * * * restic: pruneIntervalDays: 7 repository: yubal-backup-secret-local retain: daily: 7 hourly: 0 monthly: 3 weekly: 4 yearly: 1 copyMethod: Snapshot storageClassName: ceph-block volumeSnapshotClassName: ceph-blockpool-snapshot cacheCapacity: 1Gi --- apiVersion: volsync.backube/v1alpha1 kind: ReplicationSource metadata: name: yubal-backup-source-remote namespace: yubal labels: helm.sh/chart: volsync-target-config-0.8.0 app.kubernetes.io/instance: yubal app.kubernetes.io/part-of: yubal app.kubernetes.io/version: "0.8.0" app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal-backup spec: sourcePVC: yubal trigger: schedule: 34 12 * * * restic: pruneIntervalDays: 7 repository: yubal-backup-secret-remote retain: daily: 7 hourly: 0 monthly: 3 weekly: 4 yearly: 1 copyMethod: Snapshot storageClassName: ceph-block volumeSnapshotClassName: ceph-blockpool-snapshot cacheCapacity: 1Gi --- apiVersion: v1 kind: Service metadata: name: yubal labels: app.kubernetes.io/instance: yubal app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: yubal app.kubernetes.io/service: yubal helm.sh/chart: yubal-4.6.2 namespace: yubal spec: type: ClusterIP ports: - port: 80 targetPort: 8000 protocol: TCP name: http selector: app.kubernetes.io/controller: main app.kubernetes.io/instance: yubal app.kubernetes.io/name: yubal