44 Commits

Author SHA1 Message Date
6c0bf67db8 Update Helm release traefik to v37 2025-09-10 08:02:53 +00:00
d6552712a7 Merge pull request 'Update Helm release authelia to v0.10.45' (#589) from renovate/authelia-0.x into main 2025-09-09 10:03:56 +00:00
be04581b38 Update Helm release authelia to v0.10.45 2025-09-09 10:03:48 +00:00
8164550515 Merge pull request 'Update Helm release redis to v22' (#588) from renovate/redis-22.x into main
Reviewed-on: #588
2025-09-09 09:11:19 +00:00
271c02ae19 Merge pull request 'Update Helm release gitea to v12.2.0' (#584) from renovate/gitea-12.x into main
Reviewed-on: #584
2025-09-09 09:10:53 +00:00
35fecb4f49 Merge pull request 'Update sissbruecker/linkding Docker tag to v1.42.0' (#587) from renovate/sissbruecker-linkding-1.x into main
Reviewed-on: #587
2025-09-09 09:10:11 +00:00
c29812bc12 Update Helm release redis to v22 2025-09-08 14:04:47 +00:00
2c557e567a Update sissbruecker/linkding Docker tag to v1.42.0 2025-09-08 12:03:50 +00:00
2e078b68fe Merge pull request 'Update ghcr.io/paperless-ngx/paperless-ngx Docker tag to v2.18.4' (#583) from renovate/ghcr.io-paperless-ngx-paperless-ngx-2.x into main
Reviewed-on: #583
2025-09-08 11:19:35 +00:00
989edb4da2 Merge pull request 'Update docker.io/bitnami/sealed-secrets-controller Docker tag to v0.31.0' (#580) from renovate/docker.io-bitnami-sealed-secrets-controller-0.x into main
Reviewed-on: #580
2025-09-08 11:19:17 +00:00
0b8a725360 Merge pull request 'Update homeassistant/home-assistant Docker tag to v2025.9' (#585) from renovate/homeassistant-home-assistant-2025.x into main
Reviewed-on: #585
2025-09-08 11:18:54 +00:00
3ebec1dfcc Update ghcr.io/paperless-ngx/paperless-ngx Docker tag to v2.18.4 2025-09-08 00:01:38 +00:00
19e7cf8fc5 Update homeassistant/home-assistant Docker tag to v2025.9 2025-09-07 10:01:40 +00:00
c55a142946 remove superfluous value 2025-09-07 09:42:46 +00:00
fbe4a2ba05 Merge pull request 'Update ghcr.io/mealie-recipes/mealie Docker tag to v3.1.2' (#582) from renovate/ghcr.io-mealie-recipes-mealie-3.x into main
Reviewed-on: #582
2025-09-07 08:57:05 +00:00
7fbabb7e9a Update Helm release gitea to v12.2.0 2025-09-07 00:02:24 +00:00
d4cbabf15a Update ghcr.io/mealie-recipes/mealie Docker tag to v3.1.2 2025-09-06 22:01:30 +00:00
a10b70206d Merge pull request 'Update Helm release loki to v6.39.0' (#549) from renovate/loki-6.x into main
Reviewed-on: #549
2025-09-06 21:35:39 +00:00
f038453389 Merge pull request 'Update actualbudget/actual-server Docker tag to v25.9.0' (#571) from renovate/actualbudget-actual-server-25.x into main
Reviewed-on: #571
2025-09-06 21:35:08 +00:00
2d5c52e91a Merge pull request 'Update ghcr.io/advplyr/audiobookshelf Docker tag to v2.29.0' (#572) from renovate/ghcr.io-advplyr-audiobookshelf-2.x into main
Reviewed-on: #572
2025-09-06 21:34:50 +00:00
244d897b9c Merge pull request 'Update Helm release grafana to v9.4.4' (#565) from renovate/grafana-9.x into main
Reviewed-on: #565
2025-09-06 21:25:49 +00:00
71815928a1 Update docker.io/bitnami/sealed-secrets-controller Docker tag to v0.31.0 2025-09-05 18:02:21 +00:00
e11f68f69a Merge pull request 'Update Helm release authelia to v0.10.44' (#579) from renovate/authelia-0.x into main 2025-09-05 18:02:04 +00:00
8fb4642c62 Update Helm release authelia to v0.10.44 2025-09-05 18:01:56 +00:00
b82731ddaf Merge pull request 'Update binwiederhier/ntfy Docker tag to v2.14.0' (#576) from renovate/binwiederhier-ntfy-2.x into main
Reviewed-on: #576
2025-09-05 16:51:00 +00:00
9229e02482 update immich 2025-09-04 23:30:10 +02:00
00bc237aeb Update Helm release loki to v6.39.0 2025-09-04 16:04:29 +00:00
742a30cd0c Update actualbudget/actual-server Docker tag to v25.9.0 2025-09-04 00:01:39 +00:00
48dc85476e Update Helm release grafana to v9.4.4 2025-09-03 13:45:25 +00:00
2917e73559 Update ghcr.io/advplyr/audiobookshelf Docker tag to v2.29.0 2025-09-03 13:45:10 +00:00
18c05d49ff Update binwiederhier/ntfy Docker tag to v2.14.0 2025-09-03 13:45:04 +00:00
1c3fdde1dd Merge pull request 'Update Helm release redis to v21.2.14' (#575) from renovate/redis-21.x into main 2025-09-03 13:44:49 +00:00
4582b19aaf Update Helm release redis to v21.2.14 2025-09-03 13:40:34 +00:00
fe46e81fd9 Merge pull request 'Update Helm release authelia to v0.10.42' (#574) from renovate/authelia-0.x into main 2025-09-03 12:02:47 +00:00
3064d4ec7a Update Helm release authelia to v0.10.42 2025-09-03 12:02:39 +00:00
3aa05f3e30 Merge pull request 'Update adguard/adguardhome Docker tag to v0.107.65' (#573) from renovate/adguard-adguardhome-0.x into main 2025-09-03 12:02:28 +00:00
a2cff0bf55 Update adguard/adguardhome Docker tag to v0.107.65 2025-09-03 12:02:07 +00:00
b54b6b0f60 updated bootstrapping procedure with more sane defaults 2025-09-03 13:20:17 +02:00
e98d7330f1 Merge pull request 'Update Helm release gitea to v12.1.2' (#496) from renovate/gitea-12.x into main
Reviewed-on: #496
2025-07-29 07:35:52 +00:00
08ed1eafa6 Update adguard/adguardhome Docker tag to v0.107.64 2025-07-28 14:02:08 +00:00
71d881830f Update aaronleopold/stump Docker tag to v0.0.11 2025-07-26 22:01:21 +00:00
18790396bd Merge pull request 'Update Immich containers to v1.136.0' (#563) from renovate/immich-app-images into main
Reviewed-on: #563
2025-07-26 16:25:50 +00:00
6251c63353 Update Immich containers to v1.136.0 2025-07-24 18:02:01 +00:00
1bf165bb4a Update Helm release gitea to v12.1.2 2025-07-19 16:01:24 +00:00
23 changed files with 52 additions and 53 deletions

View File

@@ -1,7 +1,7 @@
# Kluster setup and IaaC using argoCD
### Initial setup
### Description
#### Requirements:
- A running k3s instance
- `sealedsecrets` deployed
@@ -27,20 +27,21 @@ The app-of-apps will bootstrap a fully featured cluster with the following compo
- immich
- ...
#### Recap
- install sealedsecrets see [README](./infrastructure/sealedsecrets/README.md)
## Setup instructions
1. install sealedsecrets see [README](./infrastructure/sealedsecrets/README.md)
```bash
kubectl apply -k infrastructure/sealedsecrets
kubectl apply -f infrastructure/sealedsecrets/main.key
kubectl delete pod -n kube-system -l name=sealed-secrets-controller
```
- install argocd
1. install argocd and the app-of-apps bundled with it
```bash
kubectl apply -k infrastructure/argocd
```
- wait...
> NOTE: The argocd kustomization already mentions some CRDs available only after the full bootstrapping (traefik). You might have to apply the last step twice
### Adding an application
todo

View File

@@ -10,7 +10,7 @@ resources:
images:
- name: adguard/adguardhome
newName: adguard/adguardhome
newTag: v0.107.63
newTag: v0.107.65
namespace: adguard

View File

@@ -12,4 +12,4 @@ namespace: audiobookshelf
images:
- name: audiobookshelf
newName: ghcr.io/advplyr/audiobookshelf
newTag: "2.26.3"
newTag: "2.29.0"

View File

@@ -14,4 +14,4 @@ resources:
images:
- name: actualbudget
newName: actualbudget/actual-server
newTag: 25.7.1
newTag: 25.9.0

View File

@@ -17,5 +17,5 @@ helmCharts:
- releaseName: grafana
name: grafana
repo: https://grafana.github.io/helm-charts
version: 9.2.10
version: 9.4.4
valuesFile: grafana.values.yaml

View File

@@ -15,4 +15,4 @@ resources:
images:
- name: homeassistant
newName: homeassistant/home-assistant
newTag: "2025.7"
newTag: "2025.9"

View File

@@ -22,9 +22,9 @@ helmCharts:
images:
- name: ghcr.io/immich-app/immich-machine-learning
newTag: v1.135.3
newTag: v1.140.1
- name: ghcr.io/immich-app/immich-server
newTag: v1.135.3
newTag: v1.140.1
patches:

View File

@@ -13,4 +13,4 @@ namespace: linkding
images:
- name: linkding
newName: sissbruecker/linkding
newTag: "1.41.0"
newTag: "1.42.0"

View File

@@ -13,4 +13,4 @@ resources:
images:
- name: binwiederhier/ntfy
newName: binwiederhier/ntfy
newTag: v2.13.0
newTag: v2.14.0

View File

@@ -14,14 +14,14 @@ namespace: paperless
images:
- name: paperless
newName: ghcr.io/paperless-ngx/paperless-ngx
newTag: "2.17.1"
newTag: "2.18.4"
helmCharts:
- name: redis
releaseName: redis
repo: https://charts.bitnami.com/bitnami
version: 21.2.13
version: 22.0.7
valuesInline:
auth:
enabled: false

View File

@@ -13,5 +13,5 @@ resources:
images:
- name: mealie
newTag: v3.0.2
newTag: v3.1.2
newName: ghcr.io/mealie-recipes/mealie

View File

@@ -14,4 +14,4 @@ namespace: stump
images:
- name: stump
newName: aaronleopold/stump
newTag: "0.0.10"
newTag: "0.0.11"

View File

@@ -27,6 +27,6 @@ images:
helmCharts:
- name: authelia
releaseName: authelia
version: 0.10.41
version: 0.10.45
repo: https://charts.authelia.com
valuesFile: authelia.values.yaml

View File

@@ -23,6 +23,6 @@ helmCharts:
- name: gitea
namespace: gitea # needs to be set explicitly for svc to be referenced correctly
releaseName: gitea
version: 12.0.0
version: 12.2.0
valuesFile: gitea.values.yaml
repo: https://dl.gitea.io/charts/

View File

@@ -2,7 +2,6 @@ apiVersion: metallb.io/v1beta1
kind: IPAddressPool
metadata:
name: default
namespace: metallb-system
spec:
addresses:
- 192.168.3.0/24
@@ -10,5 +9,8 @@ spec:
apiVersion: metallb.io/v1beta1
kind: L2Advertisement
metadata:
name: empty
namespace: metallb-system
name: default
# selector is left empty on purpose to match all IPAddressPools
# spec:
# ipAddressPools:
# - default

View File

@@ -1,15 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- namespace.yaml
- ipaddresspool.yaml
namespace: metallb-system
resources:
# - namespace.yaml
# namespace is already included in the remote kustomization
# - github.com/metallb/metallb/config/native?ref=v0.15.2
- github.com/metallb/metallb/config/frr?ref=v0.15.2
- ipaddresspool.yaml
helmCharts:
- name: metallb
repo: https://metallb.github.io/metallb
version: 0.15.2
releaseName: metallb
valuesFile: values.yaml

View File

@@ -1,6 +1,6 @@
apiVersion: v1
kind: Namespace
metadata:
name: placeholder
labels:
pod-security.kubernetes.io/enforce: privileged
name: metallb-system
# labels:
# pod-security.kubernetes.io/enforce: privileged

View File

@@ -24,7 +24,7 @@ helmCharts:
- name: loki
releaseName: loki
repo: https://grafana.github.io/helm-charts
version: 6.31.0
version: 6.39.0
valuesFile: loki.values.yaml
- name: prometheus-node-exporter
releaseName: prometheus-node-exporter

View File

@@ -30,7 +30,6 @@ loki:
filesystem:
chunks_directory: /var/loki/chunks
rules_directory: /var/loki/rules
admin_api_directory: /var/loki/admin
minio:
enabled: false

View File

@@ -9,4 +9,4 @@ resources:
images:
- name: controller
newName: docker.io/bitnami/sealed-secrets-controller
newTag: 0.30.0
newTag: 0.31.0

View File

@@ -5,15 +5,15 @@ metadata:
data:
traefik.toml: |
[ping]
[global]
checkNewVersion = false
# renovate does that
sendAnonymousUsage = false
[log]
level = "INFO"
[accessLog]
[accessLog.fields]
defaultMode = "keep"
@@ -41,17 +41,17 @@ data:
dashboard = true
insecure = true
debug = false
[providers]
[providers.kubernetesCRD]
allowCrossNamespace = true
[providers.kubernetesIngress]
allowExternalNameServices = true
ingressClass = "traefik"
ingressClass = "traefik"
[serversTransport]
insecureSkipVerify = true
[entryPoints]
[entryPoints.web]
address = ":8000"
@@ -66,13 +66,13 @@ data:
[entryPoints.websecure.forwardedHeaders]
insecure = true
# forward ip headers no matter where they come from
[entryPoints.metrics]
address = ":9100"
[entryPoints.traefik]
address = ":9000"
address = ":8080"
[entryPoints.dnsovertls]
address = ":8853"
# route dns over https to other pods but provide own certificate

View File

@@ -13,6 +13,6 @@ namespace: traefik-system
helmCharts:
- name: traefik
releaseName: traefik
version: 36.3.0
version: 37.1.1
valuesFile: values.yaml
repo: https://traefik.github.io/charts

View File

@@ -23,8 +23,7 @@ ingressClass:
# true is not unit-testable yet, pending https://github.com/rancher/helm-unittest/pull/12
enabled: true
isDefaultClass: true
# Use to force a networking.k8s.io API Version for certain CI/CD applications. E.g. "v1beta1"
fallbackApiVersion: ""
# Activate Pilot integration
pilot:
@@ -67,10 +66,11 @@ providers:
kubernetesIngress:
enabled: true
allowExternalNameServices: true
ingressClass: traefik
# Ingresses missing the annotation, having an empty value, or the value traefik are processed by default.
# ingressClass: traefik
# labelSelector: environment=production,method=traefik
# Additional volumeMounts to add to the Traefik container
additionalVolumeMounts: