Turn the single-replica jellyfin-ha app into a proper high-availability
deployment so the fork's Redis-coordinated distributed transcoding and
PostgreSQL main database can actually be exercised.
- Replace the Deployment with a 2-replica StatefulSet for stable pod
identity; set JELLYFIN_INSTANCE_ID from metadata.name (the fork's Redis
transcode-lease owner id), add soft podAntiAffinity and a PDB
minAvailable 1.
- Move the main Jellyfin DB to PostgreSQL via a CloudNativePG trio
(3-instance Cluster, PgBouncer Pooler, Ceph RGW barman backups) mirroring
the litellm pattern; an init container writes database.xml selecting the
fork's Jellyfin-PostgreSQL provider and the DSN is composed from the
CNPG-generated app secret pointed at the pooler.
- Share /config on an RWX cephfs PVC across replicas; keep /cache per-pod
via a volumeClaimTemplate.
- Fix the transcode mount to the fork's real path /config/transcodes on the
RWX PVC (raid5) so a surviving pod can resume the segments of the pod it
takes over.
- Add Intel iGPU hardware transcoding via the gpu.intel.com/i915 device
plugin resource plus render/video supplemental groups.
- Switch the Service to sessionAffinity ClientIP to reduce transcode churn.
- Disable UDP auto-discovery. Library scans still run on every replica; a
single-scanner leader election is a planned follow-up.
Deploys the jellyfin-ha fork (git.unkin.net/unkin/jellyfin-ha) to au-syd1
via ArgoCD, under a dedicated media AppProject/ApplicationSet rather than
extending platform.
- New media AppProject + media-apps ApplicationSet (watches
apps/overlays/*/jellyfin); registered in the argocd kustomizations
- apps/base/jellyfin: namespace, deployment (single replica to start),
service, in-namespace Redis (transcode session store), gateway + httproute
at jellyfin.k8s.syd1.au.unkin.net
- Storage: RWO config (cephrbd), RWX transcode scratch and RWX media
library (cephfs) per the HA fork's pod-takeover requirement
- au-syd1 overlay