Compare commits
10 Commits
feature/ga
...
39de895f4c
| Author | SHA1 | Date | |
|---|---|---|---|
| 39de895f4c | |||
| 0011cdb33a | |||
| a85bbd0400 | |||
| 0be3ea17ca | |||
| 21cef5b45a | |||
| 07c3a0f086 | |||
| 4f3e35acf8 | |||
| b81eee425e | |||
| ba4900c257 | |||
| f012b6979c |
@@ -13,4 +13,4 @@ namespace: files
|
|||||||
images:
|
images:
|
||||||
- name: ocis
|
- name: ocis
|
||||||
newName: owncloud/ocis
|
newName: owncloud/ocis
|
||||||
newTag: "5.0.7"
|
newTag: "5.0.8"
|
||||||
|
|||||||
@@ -1,15 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
|
|
||||||
namespace: games
|
|
||||||
|
|
||||||
resources:
|
|
||||||
- namespace.yaml
|
|
||||||
|
|
||||||
helmCharts:
|
|
||||||
- name: games-on-whales
|
|
||||||
releaseName: games-on-whales
|
|
||||||
version: 2.0.0
|
|
||||||
valuesFile: values.yaml
|
|
||||||
repo: https://angelnu.github.io/helm-charts
|
|
||||||
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: placeholder
|
|
||||||
labels:
|
|
||||||
pod-security.kubernetes.io/enforce: privileged
|
|
||||||
@@ -1,143 +0,0 @@
|
|||||||
#
|
|
||||||
# IMPORTANT NOTE
|
|
||||||
#
|
|
||||||
# This chart inherits from our common library chart. You can check the default values/options here:
|
|
||||||
# https://github.com/k8s-at-home/library-charts/tree/main/charts/stable/common/values.yaml
|
|
||||||
#
|
|
||||||
|
|
||||||
ingress:
|
|
||||||
# -- Enable and configure ingress settings for the chart under this key.
|
|
||||||
# @default -- See values.yaml
|
|
||||||
main:
|
|
||||||
enabled: false
|
|
||||||
|
|
||||||
service:
|
|
||||||
# -- Enable and configure TCP service settings for the chart under this key.
|
|
||||||
# @default -- See values.yaml
|
|
||||||
main: {}
|
|
||||||
# type: LoadBalancer
|
|
||||||
# loadBalancerIP: 192.168.1.129
|
|
||||||
|
|
||||||
# -- Enable and configure UDP service settings for the chart under this key.
|
|
||||||
# @default -- See values.yaml
|
|
||||||
udp: {}
|
|
||||||
# type: LoadBalancer
|
|
||||||
# loadBalancerIP: 192.168.1.129
|
|
||||||
|
|
||||||
# -- Configure persistence settings for the chart under this key.
|
|
||||||
# @default -- See values.yaml
|
|
||||||
persistence:
|
|
||||||
home:
|
|
||||||
enabled: true
|
|
||||||
type: emptyDir
|
|
||||||
mountPath: /home/retro
|
|
||||||
|
|
||||||
# -- (object) Pass GPU resources to Xorg, steam and retroarch containers
|
|
||||||
# See Custom configuration section in the Readme
|
|
||||||
graphic_resources:
|
|
||||||
|
|
||||||
sunshine:
|
|
||||||
image:
|
|
||||||
# -- sunshine image repository
|
|
||||||
repository: ghcr.io/games-on-whales/sunshine
|
|
||||||
# -- sunshine image tag
|
|
||||||
tag: 1.0.0
|
|
||||||
# -- sunshine image pull policy
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
# -- sunshine web interface user
|
|
||||||
user: admin
|
|
||||||
# -- sunshine web interface pasword
|
|
||||||
password: admin
|
|
||||||
# -- sunshine log level
|
|
||||||
logLevel: info
|
|
||||||
# -- sunshine additional env settings
|
|
||||||
env: {}
|
|
||||||
xorg:
|
|
||||||
image:
|
|
||||||
# -- xorg image repository
|
|
||||||
repository: ghcr.io/games-on-whales/xorg
|
|
||||||
# -- xorg image tag
|
|
||||||
tag: 1.0.0
|
|
||||||
# -- xorg image pull policy
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
# -- xorg display ID
|
|
||||||
# display: :99
|
|
||||||
# -- xorg refresh rate
|
|
||||||
# refreshrate: 60
|
|
||||||
# -- xorg resolution
|
|
||||||
resolution: 1920x1080
|
|
||||||
pulseaudio:
|
|
||||||
image:
|
|
||||||
# -- pulseaudio image repository
|
|
||||||
repository: ghcr.io/games-on-whales/pulseaudio
|
|
||||||
# -- pulseaudio image tag
|
|
||||||
tag: 1.0.0
|
|
||||||
# -- pulseaudio image pull policy
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
retroarch:
|
|
||||||
# -- enable/disable retroarch container
|
|
||||||
enabled: true
|
|
||||||
image:
|
|
||||||
# -- retroarch image repository
|
|
||||||
repository: ghcr.io/games-on-whales/retroarch
|
|
||||||
# -- retroarch image tag
|
|
||||||
tag: 1.0.0
|
|
||||||
# -- retroarch image pull policy
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
# -- retroarch log level
|
|
||||||
logLevel: info
|
|
||||||
# -- retroarch extra volume mounts
|
|
||||||
volumeMounts: []
|
|
||||||
steam:
|
|
||||||
# -- enable/disable steam container
|
|
||||||
enabled: true
|
|
||||||
image:
|
|
||||||
# -- steam image repository
|
|
||||||
repository: ghcr.io/games-on-whales/steam
|
|
||||||
# -- steam image tag
|
|
||||||
tag: 1.0.0
|
|
||||||
# -- steam image pull policy
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
# -- enable proton log
|
|
||||||
protonLog: 1
|
|
||||||
# -- steam extra volume mounts
|
|
||||||
volumeMounts: []
|
|
||||||
firefox:
|
|
||||||
# -- enable/disable firefox container
|
|
||||||
enabled: true
|
|
||||||
image:
|
|
||||||
# -- image repository
|
|
||||||
repository: andrewmackrodt/firefox-x11
|
|
||||||
# -- image tag
|
|
||||||
tag: 125.0.2-r1
|
|
||||||
# -- image pull policy
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
# -- firefox log level
|
|
||||||
logLevel: info
|
|
||||||
# -- firefox extra volume mounts
|
|
||||||
volumeMounts: []
|
|
||||||
mkhomeretrodirs:
|
|
||||||
image:
|
|
||||||
# -- image repository
|
|
||||||
repository: busybox
|
|
||||||
# -- image tag
|
|
||||||
tag: 1.36.1
|
|
||||||
# -- image pull policy
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
|
|
||||||
# -- Configure pulse audio settings
|
|
||||||
# @default -- See values.yaml
|
|
||||||
pulse:
|
|
||||||
config:
|
|
||||||
default.pa: |-
|
|
||||||
.fail
|
|
||||||
load-module module-null-sink sink_name=sunshine
|
|
||||||
set-default-sink sunshine
|
|
||||||
load-module module-native-protocol-unix auth-anonymous=1 socket=/tmp/pulse/pulse-socket
|
|
||||||
client.conf: |-
|
|
||||||
default-sink = sink-sunshine-stereo
|
|
||||||
autospawn = no
|
|
||||||
daemon-binary = /bin/true
|
|
||||||
daemon.conf: |-
|
|
||||||
exit-idle-time = -1
|
|
||||||
flat-volumes = yes
|
|
||||||
52
apps/paperless/deployment.yaml
Normal file
52
apps/paperless/deployment.yaml
Normal file
@@ -0,0 +1,52 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: paperless
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: paperless
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: paperless
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: paperless
|
||||||
|
image: paperless
|
||||||
|
ports:
|
||||||
|
- containerPort: 8000
|
||||||
|
env:
|
||||||
|
- name: PAPERLESS_REDIS
|
||||||
|
value: redis://redis-master:6379
|
||||||
|
- name: PAPERLESS_TIME_ZONE
|
||||||
|
value: Europe/Berlin
|
||||||
|
- name: PAPERLESS_OCR_LANGUAGE
|
||||||
|
value: deu+eng+fra
|
||||||
|
- name: PAPERLESS_URL
|
||||||
|
value: https://paperless.kluster.moll.re
|
||||||
|
- name: PAPERLESS_SECRET_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: paperless-secret-key
|
||||||
|
key: key
|
||||||
|
- name: PAPERLESS_DATA_DIR
|
||||||
|
value: /data
|
||||||
|
- name: PAPERLESS_MEDIA_ROOT
|
||||||
|
value: /data
|
||||||
|
volumeMounts:
|
||||||
|
- name: data
|
||||||
|
mountPath: /data
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: "100m"
|
||||||
|
memory: "200Mi"
|
||||||
|
limits:
|
||||||
|
cpu: "2"
|
||||||
|
memory: "1Gi"
|
||||||
|
volumes:
|
||||||
|
- name: data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: paperless-data
|
||||||
|
|
||||||
17
apps/paperless/ingress.yaml
Normal file
17
apps/paperless/ingress.yaml
Normal file
@@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: paperless-ingressroute
|
||||||
|
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`paperless.kluster.moll.re`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: paperless-web
|
||||||
|
port: 8000
|
||||||
|
|
||||||
|
tls:
|
||||||
|
certResolver: default-tls
|
||||||
31
apps/paperless/kustomization.yaml
Normal file
31
apps/paperless/kustomization.yaml
Normal file
@@ -0,0 +1,31 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- pvc.yaml
|
||||||
|
- deployment.yaml
|
||||||
|
- service.yaml
|
||||||
|
- ingress.yaml
|
||||||
|
- paperless-secret-key.sealedsecret.yaml
|
||||||
|
|
||||||
|
namespace: paperless
|
||||||
|
|
||||||
|
images:
|
||||||
|
- name: paperless
|
||||||
|
newName: ghcr.io/paperless-ngx/paperless-ngx
|
||||||
|
newTag: "2.12.1"
|
||||||
|
|
||||||
|
|
||||||
|
helmCharts:
|
||||||
|
- name: redis
|
||||||
|
releaseName: redis
|
||||||
|
repo: https://charts.bitnami.com/bitnami
|
||||||
|
version: 20.1.5
|
||||||
|
valuesInline:
|
||||||
|
auth:
|
||||||
|
enabled: false
|
||||||
|
replica:
|
||||||
|
replicaCount: 0
|
||||||
|
master:
|
||||||
|
persistence:
|
||||||
|
storageClass: "nfs-client"
|
||||||
4
apps/paperless/namespace.yaml
Normal file
4
apps/paperless/namespace.yaml
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: placeholder
|
||||||
15
apps/paperless/paperless-secret-key.sealedsecret.yaml
Normal file
15
apps/paperless/paperless-secret-key.sealedsecret.yaml
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bitnami.com/v1alpha1
|
||||||
|
kind: SealedSecret
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: null
|
||||||
|
name: paperless-secret-key
|
||||||
|
namespace: paperless
|
||||||
|
spec:
|
||||||
|
encryptedData:
|
||||||
|
key: AgAjDxYW+bf+7a+65DR/u5Qrh37JSPQCstUrNWRdxq9We1eGf7qzTnmyke/O5TiE26rHVx3yzyK/Lcp/R+pJUnDauCvL6ja7k82DLzElkoRGhvRg4nr5Iehw488WIdJDXWqAbus4oLFCgnj5axs1B97hEiAN2onCPDsOuk7oSdJfG4mMI47Ass2qFPyQaff9TulLXQQEY5U7LrawCTudUPeiTCYGbOjBadPjEzn5pDwsyAd1G+NrqoPOwkrbNzrwMwbnwB4hLO0f+jrYOh2OMNcdZzMZgM671VH9cRYSVV6uz5iAN4A1NpZ1ZdenQN4pcWvaPmPOcvp14vjZtrYbGeyaNGnob5IycRrO4yaf+0V7DZ4Thwc/vqm6r5y/MR9U4Q9EFoNNHYmfo9VEw7LhivtaDOG8OaZXUnIFoXFLOZ59qfoZdIyK4eByTRQBZFZLK9rVgXOommbqlCgzNuDM7u11OGcYfROJFeiI9pH333x5u7GZsDz0hnAjWKphXzeTglXdaXMsQUeAHusdqKCn0X1cMatGUjkBAXwlOBrqmaDwSRdyc/+J2QIdkyQM9A+88+yoop7q8c5P8oizBikVaL7SojulUTJStH5cv7nRzhmpAY4j15+o3RQKrbEjGB4HVVx3VBFjjOiP9gfjhiYqxznYwkYTpXADPwjhLFf4opOPuhpoUD1M3OKXlQpPK/RvFTWWsh14jbJuL7WJpXbfyYs0+drbVdnYeUsn8OKlnFDoOaACdpNUCr6t9dSFMs7o7Mo8yN0E
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: null
|
||||||
|
name: paperless-secret-key
|
||||||
|
namespace: paperless
|
||||||
11
apps/paperless/pvc.yaml
Normal file
11
apps/paperless/pvc.yaml
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
kind: PersistentVolumeClaim
|
||||||
|
apiVersion: v1
|
||||||
|
metadata:
|
||||||
|
name: paperless-data
|
||||||
|
spec:
|
||||||
|
storageClassName: "nfs-client"
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 10Gi
|
||||||
10
apps/paperless/service.yaml
Normal file
10
apps/paperless/service.yaml
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: paperless-web
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: paperless
|
||||||
|
ports:
|
||||||
|
- port: 8000
|
||||||
|
targetPort: 8000
|
||||||
@@ -1,106 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: steam-headless
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: steam-headless
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: steam-headless
|
|
||||||
spec:
|
|
||||||
hostNetwork: true
|
|
||||||
securityContext:
|
|
||||||
fsGroup: 1000
|
|
||||||
nodeSelector:
|
|
||||||
gpu: full
|
|
||||||
containers:
|
|
||||||
- name: steam-headless
|
|
||||||
securityContext:
|
|
||||||
privileged: true
|
|
||||||
image: josh5/steam-headless:latest
|
|
||||||
resources: #Change CPU and Memory below
|
|
||||||
requests:
|
|
||||||
memory: "4G"
|
|
||||||
cpu: "1"
|
|
||||||
limits:
|
|
||||||
memory: "12G"
|
|
||||||
cpu: "4"
|
|
||||||
# set nodeSelector to the node label that matches the node you want to run the pod on
|
|
||||||
volumeMounts:
|
|
||||||
- name: home-dir
|
|
||||||
mountPath: /home/default/
|
|
||||||
- name: games-dir
|
|
||||||
mountPath: /mnt/games/
|
|
||||||
- name: input-devices
|
|
||||||
mountPath: /dev/input/
|
|
||||||
- name: dshm
|
|
||||||
mountPath: /dev/shm
|
|
||||||
- name: dri
|
|
||||||
mountPath: /dev/dri/
|
|
||||||
env: #Environmental Vars
|
|
||||||
- name: NAME
|
|
||||||
value: 'SteamHeadless'
|
|
||||||
- name: TZ
|
|
||||||
value: 'Europe/Zurich'
|
|
||||||
- name: USER_LOCALES
|
|
||||||
value: 'en_US.UTF-8 UTF-8'
|
|
||||||
- name: DISPLAY
|
|
||||||
value: ':55'
|
|
||||||
- name: SHM_SIZE
|
|
||||||
value: '2G'
|
|
||||||
- name: PUID
|
|
||||||
value: '1000'
|
|
||||||
- name: PGID
|
|
||||||
value: '1000'
|
|
||||||
- name: UMASK
|
|
||||||
value: '000'
|
|
||||||
- name: USER_PASSWORD
|
|
||||||
value: 'password' #changeme
|
|
||||||
- name: MODE
|
|
||||||
value: 'primary'
|
|
||||||
- name: WEB_UI_MODE
|
|
||||||
value: 'vnc'
|
|
||||||
- name: ENABLE_VNC_AUDIO
|
|
||||||
value: 'false'
|
|
||||||
- name: PORT_NOVNC_WEB
|
|
||||||
value: '8083'
|
|
||||||
- name: ENABLE_SUNSHINE
|
|
||||||
value: 'true'
|
|
||||||
- name: SUNSHINE_USER
|
|
||||||
value: 'sam'
|
|
||||||
- name: SUNSHINE_PASS
|
|
||||||
value: 'password'
|
|
||||||
- name: ENABLE_EVDEV_INPUTS
|
|
||||||
value: 'false'
|
|
||||||
ports:
|
|
||||||
# novnc
|
|
||||||
- containerPort: 8083
|
|
||||||
# moonlight webui
|
|
||||||
- containerPort: 47990
|
|
||||||
# moonlight stream
|
|
||||||
- containerPort: 47989
|
|
||||||
- containerPort: 47984
|
|
||||||
- containerPort: 48010
|
|
||||||
- containerPort: 47998
|
|
||||||
- containerPort: 47999
|
|
||||||
- containerPort: 47800
|
|
||||||
volumes:
|
|
||||||
- name: home-dir
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: home
|
|
||||||
- name: games-dir
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: games
|
|
||||||
- name: input-devices
|
|
||||||
hostPath:
|
|
||||||
path: /dev/input/
|
|
||||||
- name: dri
|
|
||||||
hostPath:
|
|
||||||
path: /dev/dri/
|
|
||||||
- name: dshm
|
|
||||||
emptyDir:
|
|
||||||
medium: Memory
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
|
|
||||||
namespace: steam
|
|
||||||
|
|
||||||
resources:
|
|
||||||
- namespace.yaml
|
|
||||||
- deployment.yaml
|
|
||||||
- service.yaml
|
|
||||||
- pvc.yaml
|
|
||||||
|
|
||||||
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: placeholder
|
|
||||||
labels:
|
|
||||||
pod-security.kubernetes.io/enforce: privileged
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: games
|
|
||||||
spec:
|
|
||||||
storageClassName: "nfs-client"
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: "25Gi"
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
metadata:
|
|
||||||
name: home
|
|
||||||
spec:
|
|
||||||
storageClassName: "nfs-client"
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: "5Gi"
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: steam-vnc
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: steam-headless
|
|
||||||
ports:
|
|
||||||
- port: 8083
|
|
||||||
targetPort: 8083
|
|
||||||
name: novnc
|
|
||||||
- port: 47990
|
|
||||||
targetPort: 47990
|
|
||||||
name: moonlight-web
|
|
||||||
- port: 47989
|
|
||||||
targetPort: 47989
|
|
||||||
name: moonlight0
|
|
||||||
- port: 47984
|
|
||||||
targetPort: 47984
|
|
||||||
name: moonlight1
|
|
||||||
- port: 48010
|
|
||||||
targetPort: 48010
|
|
||||||
name: moonlight2
|
|
||||||
protocol: UDP
|
|
||||||
- port: 47998
|
|
||||||
targetPort: 47998
|
|
||||||
name: moonlight3
|
|
||||||
protocol: UDP
|
|
||||||
- port: 47999
|
|
||||||
targetPort: 47999
|
|
||||||
name: moonlight4
|
|
||||||
protocol: UDP
|
|
||||||
- port: 47800
|
|
||||||
targetPort: 47800
|
|
||||||
name: moonlight5
|
|
||||||
protocol: UDP
|
|
||||||
type: LoadBalancer
|
|
||||||
loadBalancerIP: 192.168.3.5
|
|
||||||
@@ -1,15 +1,8 @@
|
|||||||
# How to restore
|
# How to initialize a new target
|
||||||
|
I used multiple targets for backup. Each target needs to be initialized with a repository.
|
||||||
|
|
||||||
1. Port forward the rest api for gcloud
|
After the target (bucket or other) is created, run the following command **locally** to initialize the target:
|
||||||
```bash
|
|
||||||
kubectl port-forward -n backup service/rclone-gcloud 8000
|
|
||||||
```
|
|
||||||
|
|
||||||
2. Load the snapshots locally
|
```bash
|
||||||
```bash
|
restic -r <target> init
|
||||||
restic -r rest:http://127.0.0.1:8000/kluster mount /mnt/restic
|
```
|
||||||
```
|
|
||||||
(The password is in a secret)
|
|
||||||
|
|
||||||
3. Copy relevant files to the correct location on the NAS
|
|
||||||
|
|
||||||
|
|||||||
@@ -7,10 +7,10 @@ metadata:
|
|||||||
namespace: backup
|
namespace: backup
|
||||||
spec:
|
spec:
|
||||||
encryptedData:
|
encryptedData:
|
||||||
bucket-id: AgBwwjlkGjskxMXXpXrnfcT9fJGgDXtbOO/6WcpqsX0exoADw31dADjLTHztiddsGYipiGFf2DBWge69UEnL04NXIzh/xTwWtWaqlz6yOJm/89FMQE1mfbrrLc7tk98TO3oS8i+IDAnkUiYyvDXJexgJg56QLY595PXkpplYit2bAk43mAB02yUZAK0gMs3KRDIvhHFsMq8Uiqx78En5KGGXwEg6KbVDyNvI2k8suEyy+C0yNO/M6dlczoUQiIJbllQzbqIzuxbOp609PfvGFAYHuPlz1kwsg+feZJ3kNsHYi4hWvpd64BWb30iO9J3dAYfW6d7C61t3S5uabmnd9E7bMYZA/OppD8SCknBFalXF91BUiJao9qBVd/BB7TCZOzhdzhxTW+FhgARcA+GIfg+nIzgBqHfAfQQmAOO2RZnsWrvMysyZaUpODvU8kSsLWZJ3CESVRVU3BHmJZpyxjX/s6QEXShQXZaLq54zoFJULZU/kbom5yFNNDWW5sKbURPvbKJcf/J9QabY5toO4yOwDk96Sr/FI+CHHvMh8/amigva0Upq6naiTHXMf4BR6+w3VKP5ALn5cbD5jG7EpUA/j1roMoLn68GMAtTJDLvSq2BGeJENWrUpOmjWZHDKZy8DEKorJk/Wbp46ksteSALE8eXpi4DRKXYDPvDb57EhzoJGQ9NMXgAvU9+1vw2nyTZE4gAWKpg0JkiHglu4Om79HfuGuewzJXlY=
|
bucket-id: AgBZ4U2eKOmIy5oj7KLvDy7LYi41KtyZLYhMsxRcKYeQVW0lYetrsHbnsCTsw1u3kqI6pSrjUVQslpOupAlwmEdwpT5pSfAvgmLpl8NV8JFLSf1vv4cd0yBe3raFxTtTjmt9BPrEaZY1NrvW2l9SeK1JsRBJoVo9+NOlNmMWAsABi2iK/r2O9bTr9e9sOKH1DQZrvxgZKYRH40CosaQL7eBJR9EZcxSvCCp5mjZISuVI0FSgA+Xj1pXODvnf7cXkDMRg6mDDOkdYCZsQ+3a7/YZkoDBEcrO734WojHDDMLVq8lEOqzepJZJnje0jLjz5vn2pDYKGe7j3cbmMPUsNpSnUDmjFFuXTIS70RIoHUAVaPvdRpWlhYYeZiwecc+Y8gKramApCYKuUUzu8opIcckpGd/qzHCaKPyKL7qwtm9aA1rkaKLkrYjJkIhF32gp6E1qiea2L4QQD3ww/2r3UryLHygNeiNbey22covJsABA15B7LbGBaNCHhj1sqaboYvDg+FWK+Nu09UYuIvvQYw2vhKWREILbtRbyHq5J46mWtekSA0B4JU/mZL/GKwGIyS32pSZGo8gFnNzpJUDC5aNSpOPdE0FyeuJ8o+XVA43Rs6DE6885uAYMGTZhNWLZtsgOIs45ly0o8Phg02P1KvWmZzyitHWpWyAW9TXADh4GETJbFOcH7AjrrAVC5+bqI6Dx8O3qM8wnN/5MTo3EnL/lxg1wBf2c1SQU=
|
||||||
key-id: AgBe4Iytjw9CkT7CqqNLHWyG4F8F+R6m8W1fnQZdGJvLy7D81+nB2ZDMCUZgUQV/mppGnXCkSxHyelcyTYCswQ9bD8hZsAIiQACq39v2UFxdORFEgNMj4bTWPo65fwhSK2giozPqN/4lzPopP91uyq1Z0gQaiqn/HDtbfNjq+Nu9kPmV06O1NUj1f7QqvfsMK+Xadv0G+DAA+ClGaq1q3fZPDkl2MSDdbEPGq+fLPK2DSdYu9fr1bc9TPyaU5JDFvGrCg8Nyigugi4wVGjQFtVwR1QsHAADmnoDAdXoj1Sz65QO5F+zNaDZWvnLnVFxAFrXJHihilc4ilAc8hSpE6YHQm7dGO5gGejLRNaaCspb/fPJD1g2XlnkckhFCSwd9sHNrXb07BZk8gFTHfndEC0t2UyUNloYpXsfap6fvehPK91ey35jbxDk9zYdgKZ7bz/tY0450CkofSbhisf2DwS3prt5YCEDaXasrpUqlk4dSbmLaGm6aee8lM5VpO8qYE56nvXY7qr0yB6z/NGWuLX3oH3fV+C8hH1P4mxDjvVEFdtewlF50Bf9WFoE7KpboSvmChZhBfjOkbtsGmQE41ZuNoYVupetXn6IfvYo6MzGoG6dTRVpJ5S2KLQDtsUljQfXJDFCSYwo87DD2dGBEn/z9GFCIPAYNO2ewzU4RUgcXPuDD4I2tdNIC+xdEBZq7BaWn/46Yfc1+FAWUA9VWEL/9kz5tK6hFD3Ww
|
key-id: AgCPco6/scrq+3BDVimLOssVYG78vAmNOLgo4ZM9k+ayfy9morHOBQRflAJDrLO+F/2fJFM0WvZ+8gd+NnR7W6i7R3wGImN5xr115sCsBWUAM7ued7QunyrumB+Sw/o1FDcW4+S5bqwONtr07bS/M5dYM7l8Uy1zO3BOxtvWOMqdEzSrmyW/j2Kg3tQq1lEze/TOPjS4LgXqqWMWHVCyzJTpfImS3u73EUisVQBPqO7y1m3fEUvZuqVeJVK9hT3PPGuX2HUAVcIMMKWIhsA2/aMYhHQ/J0UOgc/YrGzU6DWVQoaetAHPPrt+fFQXL+MbDVaLQwk18AaRe8vhMXMwWakQEzK3fGtwPeklJB78OV4HNwpGXGFQWr1wU+T1evMJ5mv8O4VvWg7pu6blwjLCEseaCuwib5tPghIFT+LXpl2jPuyRveD5Qdl4seDZwoE9joaTWlcPreQYfuCwsQnBX25Owf4uo3XzVuVrHHRfm4O7g2VqhI5W3NcVwKhfXKuqUKDfsAmbX/RlwcihmlX6UySL42EIO5Z3xcFqEtQzba3IYgLOP8yRjGzRKUklcKFjrtoa+ZQjewKjS5x685Ffjgb4PCmpearUlVeboqH34zQBiflnecZQrwdhntVRfd3F0tkbtA/Th550IqYwezBv3AqVwZZPm+q3jeM7i0HDu6JzVYsUVpxe2MTVSKncy2p6wihhdbJeTO0gnHHydlUsyd2C2P2pXUppgjoY
|
||||||
key-secret: AgBcKSHdXHeNBzkZRtbaOEZra7AAWVlzmubaQoklECr14gKNL7rTReqX87qQObjQjmGKXtnJlKXIVHGDuiuHGkqfxQ9PCxccvpA3/7LdbFZnZtlFDWpAv+VB6Tp7H7Quho/GeAo8u6de0BXz85lz7+RyDCssBpuuzpchMgOlcEmhhfgQM5E6ye7bD6LpAZWcay3PV6FW2xTrJvLobpCcJordye6iTdSySPKdk6zflkon9h1KuQT+njmW4cfTQg/u7iS/NDQYcHdCpDHRLCor4GkVmi7NW8q+WuYhUSGWBy55SGvcUobhUL7GEHFJZpKmyrBOwSbwiWUDoN+NjI2TR5xvG0Ldjd/Hj32Vk29I+xSnj/O7pZj5ho35qExlZ/WCe42i0VHjzHFbOoU1MkqB+Skm24L1cLufhyNBtA8NNN3GWZhkcozpe164gpx4H/Vfe0UyzxUn4VJIws/IXYiLb4DgDkGrV+wzigN2QfSgTgs6syQkSs4UJ4gUZeN0jsyq0YHIhq1VZ8qPtLH310d8LZLxpTjZdO0obBwJfnHkg3blwSABEt5756C5DvjKmvO1pjG+JX/PJ0yAINL9Sc+FsY7TnGlItVzD830NcZ3Gg9C4Tg4xBEHybUWCSl1rJjwMvmUvVKNcIzLBHPAOyle1VLTZ37zb13MnhwNwdUtBu7+RZTy9wVO26iqemXTtFVj13kgZkJsyLjM6bo2y2wvFmjBCV9EKQtm87ROStM7iKB46
|
key-secret: AgAQ9GBMK/sXev8MKfCeYYgtf3tW93xvDn2jjTHaO/trAoU2OgWMS3kWKme/E+ONOxVOA3qonHhUgXcWxyut4OgMFJj2yBGRb+TqD+e0fE0KCqAwRKuYhXgFFl5SgAPZiWOAnYIJM16xu5Ci3UbrM8a8QAXAVV9aH3eT5HMF+GeqgSvhEVEQO1C8KOjVkawoqIHmDmr5KUbK4SFnIut+zCz/2HQLApNkZhPUY2whZOZjz4rwMtu2NDu8k08lI3Zl03OAw38rsbcNfZC8KbENsf1vthn5YpVJomcJKp/prgEp+/C64ZexgBWzZysq1WHs96F8R/ZmgD/Hu1Am/VjvHoFrfbLvXYUZzXGhyCBjhSwqcysm08uI5FvCs9F7WGVbYe5M/sYUMMJwLP5iILd2fkodm/+GWgl/p3EzQ76aCH85FqFhL3/9zA69bM8mZUpVG85i2yNJ9HvLe8z2EnZrh4BTgMRod/DsP9qN5NlofP0dJhK4SyXvy6M+ZO2V7CE4ksLvdWWXcJFmzuiG35DC/dQYHu8tcgywYyFVOw6uAetXSVrIzgGSCche1PZ7RKz2N4CqV5eTe6zUAgNPf4IxPne86f2AGKkivh+QcsIqfXkkR4OzcMslaKskkCniKD0IMf2aFHniSWzivi07gk5PYDxjwpa9AM2yUGRXYTcDSZquNXAt4SxE1YLDb5twZ8JyPP1Q884dwJ3+/M1DwTJj4CewO+zhH4MIURfRaGvipwsV
|
||||||
repository-string: AgAEYSqT6VR4OKW9/ZDgjYV+rm4tK3uucZsQG2u7W+8rRO0Rowkuba1AbybjgTE+G3q8si/GtlgsB1J8suvztHcVLNxg0y0Olb40pn2sZjKd85Q8AzsM0pFMkzme1lvnwu1Bcgd6Ck+FCr4CuUnh+UvJM5iWhAoSHJtdBb/EKw2F1BhewAqMXSX4oWM7V/T8RTtW2wBUk4wgX4ia+gCBPMpTo6i00ZtSpRB3Ub9VfGJfRmiXZA7oh5j3yN9nJlXonbJYBp4DNWod76CF7s35HBnSzS7YfIV80R4lH4xAPgRbZ0tvPWkTLMhSBX8rJCEnxT7DjL2lS7WfyboLdL4Uy8WmP7n2difZSr7p2iic6SCP44YgQ8JY5UgXh2QZENQ6oLvjK/PpFTjQ4bfw3E1/dakg1EdCYc/6DPyK3YekccUe/pXvVBrazpgObxXWeKKT6RMDeYWLUXTBHWhJ5OaJHHePD5t9IM65FlFTtkuUFbxExTi/u+RczBlWWcy10Yow3I3LGrDPJ/PfBy4RPfHCeQDQ+WoLJkNT20nu5mBXEYYKgNvgdn4yogifSiNG8vsNpo4dO89aHppbnHdmdp7F9asfbn27btEoFoHzIFku/mEnY5srs+Smrhhzy0+iPKge9LOuW33Gi4oJban1UYFvLAjq8YsZGkbIO82r2p+v15UjwU3girWPl1KBUc8WzLJtnqBvRPWS1ul6/X9JIdmmrHJjC0KlcGiVMU/Ls9ljnQj7dgLXuDW7JzuK3MhTWV3Y2kS39ze3TskCKcbL
|
repository-string: AgBuD/n5Pnz2AwkFUR6ChGSPMTahm5fdStTay2dD12g+IJC+zNKGlY96rxy1RRLpGJi9sj5UzqIjWd2ke+BB9Xx3RfNygh+hjQEqwb15Z5w8Vo2j7iNRYdjqm/q/ug337Ycc+p2AAxEaA4GZln+Ujq7Xh0m0mOg58N640A+zuav5Xg8dQvUoO5vrqcx8lKzUwZuEayjubZPOZDtED14bTj8FWp6a8A88PjvH+xX9ZCi+omuplHFD8+iJyHewMaPq8CPxsa90J/jHR0FyEzkPcx3/zxryeodQFSiCtvMEb4TZsABMYGlFWOdJwqTcPvqSLRZH9Emx7NmaapknERxuoozDegl/KYF8GpshizBcHaV2YEPxNFiAcPMAqmLTJc0E8SbtGcWeilVdqz2z0+Ezqs0VL5DRICBVFg+HT01bYg3yL8FYd3dfeXepijXurMJodL+pORy0y6NeS9dSvOTqoGr7mf/SeaXSMG+cdHw1+V88CVozqFgV7yLe3NzoOPSIgjyoHckpprZSZHfYF9bgX4r8tT1vrlZqN/KlBcbyYsexYK9+s866b9rpZppvgYx1I50sWm+bAeMEYrVBy2sm6fAbpb1U+3+j9CICVnJ0E1VRyOCRCvh3ncpCRgDhvXAfZTMujxGWR6m9nAi6ixp6nLx3oWsgnszK0kAoxKoHTFiNGzdpr9M092ziBnjPosmLp4fV/HdmWKlldWMsbo0HkdMmPQlKQXmtzZ09WgeSHRh1T/3rSybzwXfukh1tj1IcVIM=
|
||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
creationTimestamp: null
|
creationTimestamp: null
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
apiVersion: batch/v1
|
apiVersion: batch/v1
|
||||||
kind: CronJob
|
kind: CronJob
|
||||||
metadata:
|
metadata:
|
||||||
name: restic-rclone-gdrive
|
name: restic-backblaze
|
||||||
|
|
||||||
spec:
|
spec:
|
||||||
successfulJobsHistoryLimit: 2
|
successfulJobsHistoryLimit: 2
|
||||||
@@ -12,7 +12,7 @@ spec:
|
|||||||
template:
|
template:
|
||||||
spec:
|
spec:
|
||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
hostname: restic-k3s-pod
|
hostname: restic-kluster
|
||||||
# used by restic to identify the host
|
# used by restic to identify the host
|
||||||
containers:
|
containers:
|
||||||
# run after completion of initContainers
|
# run after completion of initContainers
|
||||||
@@ -62,7 +62,7 @@ spec:
|
|||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: backblaze-credentials
|
name: backblaze-credentials
|
||||||
key: key-id
|
key: key-id
|
||||||
- name: AWS_ACCESS_KEY
|
- name: AWS_SECRET_ACCESS_KEY
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: backblaze-credentials
|
name: backblaze-credentials
|
||||||
|
|||||||
@@ -1,8 +0,0 @@
|
|||||||
```
|
|
||||||
k kustomize backup/overlays/backup | k apply -f -
|
|
||||||
> secret/restic-credentials-backup created
|
|
||||||
> cronjob.batch/restic-backblaze-backup created
|
|
||||||
k kustomize backup/overlays/prune | k apply -f -
|
|
||||||
> secret/restic-credentials-prune created
|
|
||||||
> cronjob.batch/restic-backblaze-prune created
|
|
||||||
```
|
|
||||||
@@ -13,12 +13,12 @@ patches:
|
|||||||
- path: restic-commands.yaml
|
- path: restic-commands.yaml
|
||||||
target:
|
target:
|
||||||
kind: CronJob
|
kind: CronJob
|
||||||
name: restic-rclone-gdrive
|
name: restic-backblaze
|
||||||
- target:
|
- target:
|
||||||
kind: CronJob
|
kind: CronJob
|
||||||
name: restic-rclone-gdrive
|
name: restic-backblaze
|
||||||
# replace the name of the cronjob
|
# replace the name of the cronjob
|
||||||
patch: |-
|
patch: |-
|
||||||
- op: replace
|
- op: replace
|
||||||
path: /metadata/name
|
path: /metadata/name
|
||||||
value: restic-gdrive-backup
|
value: restic-backblaze-backup
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
apiVersion: batch/v1
|
apiVersion: batch/v1
|
||||||
kind: CronJob
|
kind: CronJob
|
||||||
metadata:
|
metadata:
|
||||||
name: restic-gdrive-backup
|
name: restic-backblaze-backup
|
||||||
spec:
|
spec:
|
||||||
schedule: "0 2 * * *"
|
schedule: "0 2 * * *"
|
||||||
# at 2:00, every day
|
# at 2:00, every day
|
||||||
@@ -27,4 +27,4 @@ spec:
|
|||||||
- name: ntfy-command-send
|
- name: ntfy-command-send
|
||||||
env:
|
env:
|
||||||
- name: OPERATION
|
- name: OPERATION
|
||||||
value: "Restic backup to gdrive"
|
value: "Restic backup to backblaze"
|
||||||
@@ -11,12 +11,12 @@ patches:
|
|||||||
- path: restic-commands.yaml
|
- path: restic-commands.yaml
|
||||||
target:
|
target:
|
||||||
kind: CronJob
|
kind: CronJob
|
||||||
name: restic-rclone-gdrive
|
name: restic-backblaze
|
||||||
- target:
|
- target:
|
||||||
kind: CronJob
|
kind: CronJob
|
||||||
name: restic-rclone-gdrive
|
name: restic-backblaze
|
||||||
# replace the name of the cronjob
|
# replace the name of the cronjob
|
||||||
patch: |-
|
patch: |-
|
||||||
- op: replace
|
- op: replace
|
||||||
path: /metadata/name
|
path: /metadata/name
|
||||||
value: restic-gdrive-prune
|
value: restic-backblaze-prune
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
apiVersion: batch/v1
|
apiVersion: batch/v1
|
||||||
kind: CronJob
|
kind: CronJob
|
||||||
metadata:
|
metadata:
|
||||||
name: restic-gdrive-prune
|
name: restic-backblaze-prune
|
||||||
spec:
|
spec:
|
||||||
schedule: "0 0 1/15 * *"
|
schedule: "0 0 1/15 * *"
|
||||||
# at midnight, the first and 15. of every month
|
# at midnight, the first and 15. of every month
|
||||||
@@ -28,4 +28,4 @@ spec:
|
|||||||
- name: ntfy-command-send
|
- name: ntfy-command-send
|
||||||
env:
|
env:
|
||||||
- name: OPERATION
|
- name: OPERATION
|
||||||
value: "Restic prune on gdrive"
|
value: "Restic prune on backblaze"
|
||||||
@@ -1,32 +0,0 @@
|
|||||||
apiVersion: batch/v1
|
|
||||||
kind: CronJob
|
|
||||||
metadata:
|
|
||||||
name: postgres-backup
|
|
||||||
spec:
|
|
||||||
# Backup the database every day at 1AM
|
|
||||||
schedule: "0 1 * * *"
|
|
||||||
jobTemplate:
|
|
||||||
spec:
|
|
||||||
template:
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: postgres-backup
|
|
||||||
image: postgres:15
|
|
||||||
command: ["/bin/sh"]
|
|
||||||
args:
|
|
||||||
- '-c'
|
|
||||||
- 'pg_dumpall -U postgres -h postgres-postgresql.postgres > /backup/backup-$(date +"%m-%d-%Y-%H-%M").sql'
|
|
||||||
env:
|
|
||||||
- name: PGPASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: postgres-password
|
|
||||||
key: password
|
|
||||||
volumeMounts:
|
|
||||||
- mountPath: /backup
|
|
||||||
name: postgres-backup-claim
|
|
||||||
restartPolicy: Never
|
|
||||||
volumes:
|
|
||||||
- name: postgres-backup-claim
|
|
||||||
persistentVolumeClaim:
|
|
||||||
claimName: postgres-backup-claim
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
|
|
||||||
namespace: backup
|
|
||||||
|
|
||||||
resources:
|
|
||||||
- postgres.sealedsecret.yaml
|
|
||||||
- pvc.yaml
|
|
||||||
- cronjob.yaml
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
{
|
|
||||||
"kind": "SealedSecret",
|
|
||||||
"apiVersion": "bitnami.com/v1alpha1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "postgres-password",
|
|
||||||
"namespace": "backup",
|
|
||||||
"creationTimestamp": null
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"template": {
|
|
||||||
"metadata": {
|
|
||||||
"name": "postgres-password",
|
|
||||||
"namespace": "backup",
|
|
||||||
"creationTimestamp": null
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"encryptedData": {
|
|
||||||
"password": "AgBZViaCuD8Zm/nkDe95xVZXgeRVJ0zE64e8efigBrkM+XUT9ber034QY5USZWalJ8nC930FB5t4N96D+LyWWXiLrYQvnYHpsi+wxJd3H/EimQo1IJ7XKNHxRC226NGX8ugb9Lez71IZaldyK3tAX0yoQ5/j304+mzetP/535EKYjZ7NucYE7KMUDsb5JsAaswd2H5fIl61PK/lEVN9AJLIo9MKL0zbGDOJCh1WNG6bUn0oi825R9AT80QulXFl/qxBHQT8R/u1AIqJDnrhLf8CiMBCs60K4D/A/F3uFwzsfGF4t2tDrowbPnGL7abAfe+DeHW8WSQoiMQWe/rTb4mnaErRNWSWmSwOcFNtUt9QQG4LvH44RTLaXKxbNfZphsNtBYk+F8SPngOok8FxoyycwUwDbA5clCt/Kh9bMOfUQpXrPc/rfXR5FO23kxM8h2pfC7QYNej0k3LexcikdQrpqRj9yMAVMSI7xF35Tfc5buqasIDlgRxTSi2Pn/fAFIK3QqY7YQWZOYzuD3w6aTUx0trmHNTycmotKV/kbni/ZOMmf6NMGbZs5R3VbmA1vFtdp9YVD5dJ0t0aTXTdNuWjeC0+vQF0lnXPWonRYf65e8KOwcuDjTYU6ghDfQPngJ01FFoTgiF+X/1iZ+7uvIeIULak8dMIQz6CqfrCkahkimz5u2c+b3ZPlNnXRyPmZE/1JscLXaKuXvg=="
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: PersistentVolume
|
|
||||||
metadata:
|
|
||||||
name: pg-backup-data
|
|
||||||
spec:
|
|
||||||
capacity:
|
|
||||||
storage: "50Gi"
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
nfs:
|
|
||||||
path: /kluster/pg-backup
|
|
||||||
server: 192.168.1.157
|
|
||||||
---
|
|
||||||
kind: PersistentVolumeClaim
|
|
||||||
apiVersion: v1
|
|
||||||
|
|
||||||
metadata:
|
|
||||||
name: postgres-backup-claim
|
|
||||||
|
|
||||||
spec:
|
|
||||||
storageClassName: ""
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 10Gi
|
|
||||||
volumeName: pg-backup-data
|
|
||||||
@@ -1,22 +0,0 @@
|
|||||||
{
|
|
||||||
"kind": "SealedSecret",
|
|
||||||
"apiVersion": "bitnami.com/v1alpha1",
|
|
||||||
"metadata": {
|
|
||||||
"name": "rclone-config-files",
|
|
||||||
"namespace": "backup",
|
|
||||||
"creationTimestamp": null
|
|
||||||
},
|
|
||||||
"spec": {
|
|
||||||
"template": {
|
|
||||||
"metadata": {
|
|
||||||
"name": "rclone-config-files",
|
|
||||||
"namespace": "backup",
|
|
||||||
"creationTimestamp": null
|
|
||||||
},
|
|
||||||
"type": "Opaque"
|
|
||||||
},
|
|
||||||
"encryptedData": {
|
|
||||||
"rclone.conf": "AgCQ13IG+R6bs+nAxe1xuDXttYlvGlLfV3oQ6c0qtoF2jXB8hN3LftydHn+Se3LjghmQKAIErfsA7ZRhJoWfFuSm2AIc3w2mMonsga5gjBx/56/tZSvnT2Bzn/5UXktTVxwEINSBP0dYiMcn4/G+5hO3bngmG+lCZXeI7yWoTW8H+8NKYxDHUzdoBBhPPPLTERTRZHB8EzOPUlefHq/2y/NpUfkxyLSjYk0/X45W6XNzH6MfdA2x6omxd4giDQSEwJGdXqIXu1rPnPjV7WVcA8qJzkQbxhzjqpUcFgM12YsLGVVW8HSSdAy+ZNdTXmhCIu2+pI+AVuol4QY9r/gU3xlGhFmc3asW5k4iOfn7/ZEr3Yk8JplAYM+GWQ07s59MqYdGOhqFUpVmkjO97Z29iaeReQZCwxzl/PmxUtfI20eTmtUlFKE3fObMr27sZcXgeJS3ktHOONGoqvHHeuqd4hfTaVAGwVOAEoBY8Xnkq3ECN5ld8V4zR8e52QHtANflN4IJgjnGO5pMQyAW+XASAJDxG48q7ruu9i0mI4vuM0rVuoWi2v9I30/M7Mv2xAYnmKC7NIao1mDya3paidHwkIu12480oBDdHZpm5NSqHtQr/HKMQWnbu6CrufrDmTqoVe/ew5uaqjbfrBBys35k5ObUUPlhU3putgfmsR3YZXDaAqOwIoXQ30wm02gCA5z/WNEY3EaKP6RhgsowwkrPPniQfz4EaxQQjmZ/toe/xpwzSZjmoVnJtJabiuqL/B/eY6WpNOTjOzsc7Z69EOyhZMs41gNoA32RRUbFO1ppOu8518cE12KpsGbH6K6NcucSrKh2Gd3xNGwjaGQVT2vLTVi9YwByiwvrsVpNU06f2v0fcZWeRgoFoUkKMj746lw0E+X7oF0+PmfPT2IeTRszHECkbStSvFZNDivcdJyDFutocAZKNjDoAnVPlTNVYwKKcmHvw3sOOXhVN7NOj/+9UxSNyRvip7GPZKtRF1u9ftlD6OaLCCVSip7MJ41a7TugBTUUaMJbQUTmidWKZn6A0nctAvdrPbBatPI2BZQ4amwdXa2bWyE7DI13WaCm6kAVJijsAmfVrVX3C+Ft5p8unbjsVQ/ErdpKTjlq9mJsie3TQdME5r74GlcURiVXdLc7KcV7vpf6yy88XS6ee+Y9WmlYDAwRX+taMilRDlunMeF5Zmh12DCXMzsradEifEOZ/Mg5BMznxvrZv3iHDArm/j4QW7Bi0To3+f2826IAaXMlI4ze7e9Ny3NUbgy85yE+RNYiio0+wvWRKraxpqI0EODy/juBed3VcoWlOfch0hKU4BZTVrU5rDEmwYcp6oWnXE92fhVH7wjy4IV3WUSubYg="
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: rclone-gcloud
|
|
||||||
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: rclone-gcloud
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: rclone-gcloud
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: rclone
|
|
||||||
image: rclone/rclone:latest
|
|
||||||
command: ["/bin/sh", "-c"]
|
|
||||||
args: # mounted as a secret
|
|
||||||
# >- strips newlines
|
|
||||||
# sleep infinity
|
|
||||||
- >-
|
|
||||||
rclone
|
|
||||||
--config /config/rclone.conf
|
|
||||||
serve restic
|
|
||||||
--addr :8000
|
|
||||||
-v
|
|
||||||
ETHZ-gdrive:backup
|
|
||||||
|
|
||||||
volumeMounts:
|
|
||||||
# from secret
|
|
||||||
- name: rclone-config
|
|
||||||
mountPath: /config
|
|
||||||
readOnly: true
|
|
||||||
volumes:
|
|
||||||
- name: rclone-config
|
|
||||||
secret:
|
|
||||||
secretName: rclone-config-files
|
|
||||||
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: rclone-gcloud
|
|
||||||
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: rclone-gcloud
|
|
||||||
ports:
|
|
||||||
- protocol: TCP
|
|
||||||
port: 8000
|
|
||||||
targetPort: 8000
|
|
||||||
|
|
||||||
|
|
||||||
@@ -11,7 +11,7 @@ resources:
|
|||||||
images:
|
images:
|
||||||
- name: octodns
|
- name: octodns
|
||||||
newName: octodns/octodns # has all plugins
|
newName: octodns/octodns # has all plugins
|
||||||
newTag: "2024.08"
|
newTag: "2024.09"
|
||||||
|
|
||||||
- name: git
|
- name: git
|
||||||
newName: alpine/git
|
newName: alpine/git
|
||||||
|
|||||||
@@ -13,6 +13,6 @@ namespace: traefik-system
|
|||||||
helmCharts:
|
helmCharts:
|
||||||
- name: traefik
|
- name: traefik
|
||||||
releaseName: traefik
|
releaseName: traefik
|
||||||
version: 31.1.1
|
version: 32.0.0
|
||||||
valuesFile: values.yaml
|
valuesFile: values.yaml
|
||||||
repo: https://traefik.github.io/charts
|
repo: https://traefik.github.io/charts
|
||||||
|
|||||||
@@ -35,6 +35,7 @@ resources:
|
|||||||
- minecraft/application.yaml
|
- minecraft/application.yaml
|
||||||
- monitoring/
|
- monitoring/
|
||||||
- ntfy/
|
- ntfy/
|
||||||
|
- paperless/
|
||||||
- recipes/
|
- recipes/
|
||||||
- rss/
|
- rss/
|
||||||
- whoami/
|
- whoami/
|
||||||
|
|||||||
19
kluster-deployments/paperless/application.yaml
Normal file
19
kluster-deployments/paperless/application.yaml
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: paperless-application
|
||||||
|
namespace: argocd
|
||||||
|
|
||||||
|
spec:
|
||||||
|
project: infrastructure
|
||||||
|
source:
|
||||||
|
repoURL: ssh://git@git.kluster.moll.re:2222/remoll/k3s-infra.git
|
||||||
|
targetRevision: main
|
||||||
|
path: apps/paperless
|
||||||
|
destination:
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
namespace: paperless
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
selfHeal: true
|
||||||
4
kluster-deployments/paperless/kustomization.yaml
Normal file
4
kluster-deployments/paperless/kustomization.yaml
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- application.yaml
|
||||||
Reference in New Issue
Block a user