Compare commits

...

15 Commits

Author SHA1 Message Date
unkin-agent fe51aa07be Give the puppetserver compilers the Vault cert helpers (#482)
profiles::pki::vault and profiles::ssh::sign shell out to
/usr/local/bin/certmanager and /usr/local/bin/sshsignhost from generate()
during catalog compilation. Neither binary exists in the compiler image, so
every node using them fails to compile.

- install certmanager v0.2.0 and sshsignhost v0.1.0 onto the shared bin volume with sha256 verification
- wrap both at /usr/local/bin from a pre-default entrypoint hook, failing startup loudly if either is missing
- mount read-only Vault configs for both: kubernetes auth on k8s/au/syd1, internal CA verified rather than skipped

Reviewed-on: #482
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-24 21:15:09 +10:00
unkin-agent cdaab736b5 Bump jellyfin-ha to v0.4.0 (#483)
The deployed v0.3.3 build returns 500 from /Shows/NextUp on PostgreSQL, breaking the home screen, and lets replicas diverge: library-visibility and shared-config changes never propagate, user data (resume, played state, favourites, ratings) is overwritten between pods, and eight scheduled tasks run on every replica instead of only the scan leader. v0.4.0 carries the fixes.

- Pin cheeztv and fafflix to jellyfin-ha:v0.4.0.

No config change needed: cross-pod invalidation reuses the transcode-store Redis connection string both apps already set.

Reviewed-on: #483
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-22 22:57:06 +10:00
unkin-agent b31517e6d9 Merge pull request #481 from benvin/jellyfin-sso-valkey-state
Roll jellyfin-ha to v0.3.3 and drop Service session affinity

Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-20 14:02:48 +10:00
unkin-agent 5a74b2cec6 Roll bind-operator to v0.2.7 (journal-aware zone seeding) (#480)
Deploy bind-operator v0.2.7. The operator seeded a fresh skeleton zone file at serial 1 over zones whose BIND journal was still on disk at a higher serial; BIND rejected the inconsistent pair (`addzone failed: out of range`) and, with a PVC per replica, the stale journal outlived restarts while every reconcile rewrote the skeleton, so it never converged. That SERVFAILed roughly 1 in 3 authoritative answers for k8s.syd1.au.unkin.net and resolvers cached the failures.

- Bumps the operator image to v0.2.7
- Bumps the CRD install pin to the v0.2.7 tag, which changes the CRDs

Expect one rolling restart of the operator Deployment as the new image lands.

Reviewed-on: #480
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-20 00:53:47 +10:00
unkin-agent f14bcc4d2a Add woodpecker ServiceAccount for jellyfin-plugin-sso CI (#479)
The new `unkin/jellyfin-plugin-sso` fork is getting a Woodpecker pipeline, and its build step will set `serviceAccountName: jellyfin-plugin-sso`. Without the SA declared here the pipeline pods fail to schedule.

- add a bare ServiceAccount `jellyfin-plugin-sso` in the `woodpecker` namespace
- register it in the woodpecker base kustomization

The step only builds .NET code, so no Vault kube-auth role or RBAC is needed.

Reviewed-on: #479
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 17:32:31 +10:00
unkin-agent b01e4c3241 Rewrite slash-less Authentik token endpoint to the canonical path (#478)
Authentik advertises the token endpoint with a trailing slash, but some OIDC clients (the ArgoCD iOS app) POST to /application/o/token without one; Django's APPEND_SLASH will not redirect a POST, so the token exchange gets 405 and login fails.

- Add an exact-match rule on /application/o/token to the authentik and authentik-internal HTTPRoutes.
- Rewrite it to /application/o/token/ with a URLRewrite ReplaceFullPath filter, preserving the method and the authentik-server backend.
- Leave the catch-all PathPrefix rule untouched; exact matches outrank it in Gateway API precedence.

Reviewed-on: #478
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 16:10:30 +10:00
unkin-agent bbd5bdaa95 Enable PKCE for ArgoCD OIDC login (#477)
The Authentik client for ArgoCD is now public (the iOS app can't hold
a secret), so Authentik no longer enforces client_secret on token
exchange. PKCE replaces that as the protection against
authorization-code interception.

- Add `enablePKCEAuthentication: true` to the `oidc.config` block in
  `argocd-cm-patch.yaml`
- Note why PKCE is needed now that the client is public

Reviewed-on: #477
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 16:10:05 +10:00
unkin-agent 4762cf9e03 Add VMPodScrape for authentik-server metrics (#476)
Authentik server pods expose django_prometheus metrics on :9300, but only ldap-outpost and redis-exporter are scraped in this namespace. Add the missing per-app scrape.

- add apps/base/authentik/server-vmpodscrape.yaml selecting app.kubernetes.io/name=authentik, component=server on the metrics port
- wire it into apps/base/authentik/kustomization.yaml

Reviewed-on: #476
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 15:34:26 +10:00
unkin-agent c83a886e74 Enable pg_stat_statements on the authentik postgres cluster (#475)
The cluster preloads no statement-statistics library, so there is no per-query cost attribution in postgres and slow query paths have to be inferred from application-side metrics instead of read straight out of the database.

- preload `pg_stat_statements`
- set `pg_stat_statements.max` and `.track`, which is what makes CNPG manage the extension and create it in every database

Requires a postgres restart. Stacked on `benvin/authentik-cnpg-resources`.

Reviewed-on: #475
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 14:48:45 +10:00
unkin-agent 9a7200636c Raise authentik postgres CPU, memory and buffer sizing (#474)
The 500m CPU limit is a 50ms CFS quota per 100ms period, so the postgres pods are throttled on every burst even at ~0.01 cores average and each query pays that latency. 128MB of `shared_buffers` and a 256MB cache estimate also under-serve the planner on the joins authentik issues on its hot read paths.

- raise resources to requests `500m`/`1Gi`, limits `2`/`2Gi`
- raise `shared_buffers` to 512MB and `effective_cache_size` to 1536MB
- hold the post-incident memory headroom multiple over `shared_buffers`

Rolling restart with switchover. Stacked on `benvin/authentik-hot-standby-feedback`.

Reviewed-on: #474
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 14:35:16 +10:00
unkin-agent 9535bad9bc Enable hot_standby_feedback on the authentik postgres cluster (#473)
Authentik serves multi-second API reads from the CNPG hot standbys. Those reads outlive `max_standby_streaming_delay`, so recovery cancels them with `canceling statement due to conflict with recovery`, which authentik surfaces as HTTP 500 — enough to break a terraform apply mid-run.

- set `hot_standby_feedback` on so replicas report their oldest xmin to the primary and long reads stop being cancelled
- SIGHUP reload only, no restart or switchover
- retained-dead-tuple cost is negligible on a ~155MB database

Reviewed-on: #473
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 14:34:33 +10:00
unkin-agent 34dd70435e Auto-reload cheeztv and fafflix on plugin ConfigMap change (#471)
Edits to the cheeztv/fafflix plugin ConfigMaps only reach the pods via the inject-plugin-config initContainer, so a config change sat inert until someone manually rolled the StatefulSet. Reloader is deployed cluster-wide with autoReloadAll disabled, so each workload has to opt in.

- annotate both StatefulSets with configmap.reloader.stakater.com/auto: "true"

Reviewed-on: #471
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 12:25:08 +10:00
unkin-agent 6cc752336e Point jellyfin SSO at public Authentik hostname (#470)
The internal-CA identity.k8s.syd1.au.unkin.net host has no CA bundle mounted in the jellyfin pods, so the OIDC discovery fetch fails TLS handshake (PartialChain). Authentik's discovery response is host-relative, so the browser-facing hostname must be used, not the internal one.

- Change OidEndpoint to identity.unkin.net in fafflix plugin config
- Change OidEndpoint to identity.unkin.net in cheeztv plugin config

Reviewed-on: #470
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-19 12:09:31 +10:00
unkin-agent 47a2ab9152 Pin jellyfin-ha image to v0.3.2 (#468)
v0.3.0 and v0.3.1 crash-looped on Postgres migration/reader bugs and were reverted. v0.3.2 fixes both and was validated end to end against production-baseline Postgres and valkey: full migration chain completes, all previously-500 endpoints return 200, RedisTranscodeSessionStore and scan-leader gating confirmed active.

- Bump jellyfin-ha image tag v0.2.0 -> v0.3.2 in cheeztv and fafflix statefulsets

Depends on a pre-sync duplicate-username check and fresh pg_dump of both databases.

Reviewed-on: #468
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-13 23:08:44 +10:00
unkin-agent 4748df497a puppet: install toml into the puppetserver gem path (#467)
Catalog compiles fail with `LoadError: no such file to load -- toml`: server-side functions run in the puppetserver JRuby, whose gem path is separate from the agent CRuby path this hook installs into. puppet-prod's `profiles::puppet::gems` covers both; the hook only did the agent half.

- Install toml via `puppetserver gem`, mirroring the `puppetserver_gem` resource in puppet-prod
- Note in a comment that under `set -e` a failed install takes down an already-serving compiler

Reviewed-on: #467
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-09-13 23:08:31 +10:00
21 changed files with 212 additions and 16 deletions
+21 -6
View File
@@ -64,8 +64,12 @@ spec:
archive_mode: "on" archive_mode: "on"
archive_timeout: 5min archive_timeout: 5min
dynamic_shared_memory_type: posix dynamic_shared_memory_type: posix
effective_cache_size: 256MB effective_cache_size: 1536MB
full_page_writes: "on" full_page_writes: "on"
# Replicas report their oldest xmin to the primary, so multi-second reads on
# a hot standby stop exhausting max_standby_streaming_delay and being
# cancelled. Retained-dead-tuple cost is negligible on a ~155MB database.
hot_standby_feedback: "on"
log_destination: csvlog log_destination: csvlog
log_directory: /controller/log log_directory: /controller/log
log_filename: postgres log_filename: postgres
@@ -77,7 +81,12 @@ spec:
max_parallel_workers: "16" max_parallel_workers: "16"
max_replication_slots: "16" max_replication_slots: "16"
max_worker_processes: "16" max_worker_processes: "16"
shared_buffers: 128MB # A pg_stat_statements.* parameter is what makes CNPG treat the extension as
# managed and run CREATE EXTENSION in every database; preloading alone does
# not create it.
pg_stat_statements.max: "10000"
pg_stat_statements.track: top
shared_buffers: 512MB
shared_memory_type: mmap shared_memory_type: mmap
ssl_max_protocol_version: TLSv1.3 ssl_max_protocol_version: TLSv1.3
ssl_min_protocol_version: TLSv1.3 ssl_min_protocol_version: TLSv1.3
@@ -86,6 +95,9 @@ spec:
wal_log_hints: "on" wal_log_hints: "on"
wal_receiver_timeout: 5s wal_receiver_timeout: 5s
wal_sender_timeout: 5s wal_sender_timeout: 5s
# CNPG merges this with the libraries it manages itself.
shared_preload_libraries:
- pg_stat_statements
syncReplicaElectionConstraint: syncReplicaElectionConstraint:
enabled: false enabled: false
primaryUpdateMethod: restart primaryUpdateMethod: restart
@@ -105,13 +117,16 @@ spec:
updateInterval: 30 updateInterval: 30
resources: resources:
limits: limits:
cpu: 500m # 500m is a 50ms CFS quota per 100ms period, exhausted by bursts even at
# ~0.01 cores average, so every query pays throttle latency.
cpu: "2"
# 512Mi OOMKilled replicas under load (shared_buffers 128MB + # 512Mi OOMKilled replicas under load (shared_buffers 128MB +
# max_connections 200 leave no headroom) — see incident 2026-07-28. # max_connections 200 leave no headroom) — see incident 2026-07-28.
memory: 1Gi # shared_buffers 512MB needs the same headroom multiple, hence 2Gi.
memory: 2Gi
requests: requests:
cpu: 50m cpu: 500m
memory: 512Mi memory: 1Gi
smartShutdownTimeout: 180 smartShutdownTimeout: 180
startDelay: 3600 startDelay: 3600
stopDelay: 1800 stopDelay: 1800
+32
View File
@@ -37,6 +37,22 @@ spec:
name: authentik name: authentik
sectionName: https sectionName: https
rules: rules:
- backendRefs:
- group: ""
kind: Service
name: authentik-server
port: 80
weight: 1
filters:
- type: URLRewrite
urlRewrite:
path:
type: ReplaceFullPath
replaceFullPath: /application/o/token/
matches:
- path:
type: Exact
value: /application/o/token
- backendRefs: - backendRefs:
- group: "" - group: ""
kind: Service kind: Service
@@ -86,6 +102,22 @@ spec:
name: authentik-internal name: authentik-internal
sectionName: https sectionName: https
rules: rules:
- backendRefs:
- group: ""
kind: Service
name: authentik-server
port: 80
weight: 1
filters:
- type: URLRewrite
urlRewrite:
path:
type: ReplaceFullPath
replaceFullPath: /application/o/token/
matches:
- path:
type: Exact
value: /application/o/token
- backendRefs: - backendRefs:
- group: "" - group: ""
kind: Service kind: Service
+1
View File
@@ -19,6 +19,7 @@ resources:
- redis-deployment.yaml - redis-deployment.yaml
- redis-pvc.yaml - redis-pvc.yaml
- redis-service.yaml - redis-service.yaml
- server-vmpodscrape.yaml
- vaultauth.yaml - vaultauth.yaml
- vaultstaticsecret.yaml - vaultstaticsecret.yaml
- vmpodscrape.yaml - vmpodscrape.yaml
@@ -0,0 +1,16 @@
---
# Scrape the authentik server's django_prometheus endpoint (:9300). Picked up
# by the observability VMAgent (selectAllByDefault).
apiVersion: operator.victoriametrics.com/v1beta1
kind: VMPodScrape
metadata:
name: authentik-server
namespace: authentik
spec:
selector:
matchLabels:
app.kubernetes.io/name: authentik
app.kubernetes.io/component: server
podMetricsEndpoints:
- port: metrics
path: /metrics
+1 -1
View File
@@ -21,7 +21,7 @@ spec:
runAsNonRoot: true runAsNonRoot: true
containers: containers:
- name: operator - name: operator
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.2.6 image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.2.7
args: args:
- --metrics-bind-address=:8080 - --metrics-bind-address=:8080
- --health-probe-bind-address=:8081 - --health-probe-bind-address=:8081
+1 -1
View File
@@ -6,7 +6,7 @@ resources:
- namespace.yaml - namespace.yaml
# CRDs are pulled from the bind-operator repo at the matching tag rather than # CRDs are pulled from the bind-operator repo at the matching tag rather than
# vendored here, so they never drift from the operator. # vendored here, so they never drift from the operator.
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.6/config/crd/install.yaml - https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.7/config/crd/install.yaml
- rbac.yaml - rbac.yaml
- agent-dns-rbac.yaml - agent-dns-rbac.yaml
- deployment.yaml - deployment.yaml
+1 -1
View File
@@ -26,7 +26,7 @@ data:
</key> </key>
<value> <value>
<PluginConfiguration> <PluginConfiguration>
<OidEndpoint>https://identity.k8s.syd1.au.unkin.net/application/o/jellyfin/</OidEndpoint> <OidEndpoint>https://identity.unkin.net/application/o/jellyfin/</OidEndpoint>
<OidClientId>jellyfin</OidClientId> <OidClientId>jellyfin</OidClientId>
<OidSecret>@@CLIENT_SECRET@@</OidSecret> <OidSecret>@@CLIENT_SECRET@@</OidSecret>
<Enabled>true</Enabled> <Enabled>true</Enabled>
-2
View File
@@ -13,6 +13,4 @@ spec:
targetPort: http targetPort: http
selector: selector:
app: cheeztv app: cheeztv
# Pin each client to one replica to reduce transcode-session churn/takeover.
sessionAffinity: ClientIP
type: ClusterIP type: ClusterIP
+3 -1
View File
@@ -4,6 +4,8 @@ kind: StatefulSet
metadata: metadata:
name: cheeztv name: cheeztv
namespace: cheeztv namespace: cheeztv
annotations:
configmap.reloader.stakater.com/auto: "true"
spec: spec:
# HA: two replicas coordinate transcode session ownership through Valkey and # HA: two replicas coordinate transcode session ownership through Valkey and
# resume each other's HLS segments off the shared RWX transcode PVC. Stable # resume each other's HLS segments off the shared RWX transcode PVC. Stable
@@ -162,7 +164,7 @@ spec:
readOnly: true readOnly: true
containers: containers:
- name: cheeztv - name: cheeztv
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.2.0 image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
ports: ports:
- name: http - name: http
+1 -1
View File
@@ -26,7 +26,7 @@ data:
</key> </key>
<value> <value>
<PluginConfiguration> <PluginConfiguration>
<OidEndpoint>https://identity.k8s.syd1.au.unkin.net/application/o/jellyfin/</OidEndpoint> <OidEndpoint>https://identity.unkin.net/application/o/jellyfin/</OidEndpoint>
<OidClientId>jellyfin</OidClientId> <OidClientId>jellyfin</OidClientId>
<OidSecret>@@CLIENT_SECRET@@</OidSecret> <OidSecret>@@CLIENT_SECRET@@</OidSecret>
<Enabled>true</Enabled> <Enabled>true</Enabled>
-2
View File
@@ -13,6 +13,4 @@ spec:
targetPort: http targetPort: http
selector: selector:
app: fafflix app: fafflix
# Pin each client to one replica to reduce transcode-session churn/takeover.
sessionAffinity: ClientIP
type: ClusterIP type: ClusterIP
+3 -1
View File
@@ -4,6 +4,8 @@ kind: StatefulSet
metadata: metadata:
name: fafflix name: fafflix
namespace: fafflix namespace: fafflix
annotations:
configmap.reloader.stakater.com/auto: "true"
spec: spec:
# HA: two replicas coordinate transcode session ownership through Valkey and # HA: two replicas coordinate transcode session ownership through Valkey and
# resume each other's HLS segments off the shared RWX transcode PVC. Stable # resume each other's HLS segments off the shared RWX transcode PVC. Stable
@@ -162,7 +164,7 @@ spec:
readOnly: true readOnly: true
containers: containers:
- name: fafflix - name: fafflix
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.2.0 image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
ports: ports:
- name: http - name: http
@@ -105,6 +105,17 @@ spec:
- mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh - mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh
name: compiler-auth-conf-seed name: compiler-auth-conf-seed
subPath: 10-auth-conf.sh subPath: 10-auth-conf.sh
- mountPath: /docker-custom-entrypoint.d/pre-default/20-vault-helpers.sh
name: compiler-vault-helpers-seed
subPath: 20-vault-helpers.sh
- mountPath: /opt/certmanager/config.yaml
name: certmanager-config
subPath: certmanager.yaml
readOnly: true
- mountPath: /opt/sshsignhost/config.yaml
name: sshsignhost-config
subPath: sshsignhost.yaml
readOnly: true
initContainers: initContainers:
- name: copy-configmaps - name: copy-configmaps
image: busybox:1.35 image: busybox:1.35
@@ -202,7 +213,38 @@ spec:
echo "$EXPECTED encapic" | sha256sum -c - echo "$EXPECTED encapic" | sha256sum -c -
install -m 0755 encapic /opt/bin/encapic install -m 0755 encapic /opt/bin/encapic
# Puppet shells out to these two from generate() during catalog
# compilation: profiles::pki::vault runs certmanager and
# profiles::ssh::sign runs sshsignhost.
install_release() {
name=$1
version=$2
asset="$name-linux-amd64"
base="https://git.unkin.net/unkin/$name/releases/download/$version"
curl -fsSL -o "$name" "$base/$asset"
curl -fsSL -o "$name.checksums" "$base/checksums.txt"
# checksums.txt covers every release asset; pick the line for the
# one we downloaded and verify it under our local filename.
expected=$(awk -v a="$asset" '$NF == a || $NF == "*"a {print $1}' "$name.checksums")
if [ -z "$expected" ]; then
echo "no checksum for $asset in $version checksums.txt" >&2
exit 1
fi
echo "$expected $name" | sha256sum -c -
install -m 0755 "$name" "/opt/bin/$name"
}
install_release certmanager v0.2.0
install_release sshsignhost v0.1.0
echo "Shared binaries setup completed" echo "Shared binaries setup completed"
resources:
limits:
cpu: 300m
memory: 256Mi
requests:
cpu: 100m
memory: 64Mi
volumeMounts: volumeMounts:
- mountPath: /opt/bin/ - mountPath: /opt/bin/
name: puppet-shared-bins name: puppet-shared-bins
@@ -247,5 +289,15 @@ spec:
configMap: configMap:
name: compiler-auth-conf-seed name: compiler-auth-conf-seed
defaultMode: 0755 defaultMode: 0755
- name: compiler-vault-helpers-seed
configMap:
name: compiler-vault-helpers-seed
defaultMode: 0755
- name: certmanager-config
configMap:
name: certmanager-config
- name: sshsignhost-config
configMap:
name: sshsignhost-config
strategy: strategy:
type: RollingUpdate type: RollingUpdate
+15
View File
@@ -64,6 +64,21 @@ configMapGenerator:
- resources/compiler/10-auth-conf.sh - resources/compiler/10-auth-conf.sh
options: options:
disableNameSuffixHash: true disableNameSuffixHash: true
- name: compiler-vault-helpers-seed
files:
- resources/compiler/20-vault-helpers.sh
options:
disableNameSuffixHash: true
- name: certmanager-config
files:
- resources/compiler/certmanager.yaml
options:
disableNameSuffixHash: true
- name: sshsignhost-config
files:
- resources/compiler/sshsignhost.yaml
options:
disableNameSuffixHash: true
- name: additional-ruby-gems - name: additional-ruby-gems
files: files:
- resources/additional-ruby-gems.sh - resources/additional-ruby-gems.sh
@@ -6,4 +6,6 @@ echo "Installing additional Ruby gems..."
/opt/puppetlabs/puppet/bin/gem install ipaddr /opt/puppetlabs/puppet/bin/gem install ipaddr
/opt/puppetlabs/puppet/bin/gem install hiera-eyaml /opt/puppetlabs/puppet/bin/gem install hiera-eyaml
/opt/puppetlabs/puppet/bin/gem install toml /opt/puppetlabs/puppet/bin/gem install toml
# Under set -e a failed install kills the entrypoint post-startup hooks, taking down an already-serving compiler.
/opt/puppetlabs/bin/puppetserver gem install toml
echo "Additional Ruby gems installed successfully" echo "Additional Ruby gems installed successfully"
+29
View File
@@ -0,0 +1,29 @@
#!/bin/bash
set -euo pipefail
BIN_DIR=/opt/bin
CA=/opt/vault-ca-cert.crt
if [ ! -s "$CA" ]; then
echo "FATAL: $CA missing or empty; certmanager and sshsignhost cannot verify Vault" >&2
exit 1
fi
# profiles::pki::vault and profiles::ssh::sign shell out to fixed /usr/local/bin
# paths from generate(); the binaries ship on the shared PVC, and /usr/local/bin
# lives in the image. Wrappers rather than symlinks because neither binary reads
# a CA path from its config: SSL_CERT_FILE scopes the internal CA to these two
# processes instead of the puppetserver JVM's own trust store.
for bin in certmanager sshsignhost; do
if [ ! -x "$BIN_DIR/$bin" ]; then
echo "FATAL: $BIN_DIR/$bin missing; generate() would abort every catalog compile" >&2
exit 1
fi
cat > "/usr/local/bin/$bin" <<WRAPPER
#!/bin/sh
SSL_CERT_FILE=$CA
export SSL_CERT_FILE
exec $BIN_DIR/$bin "\$@"
WRAPPER
chmod 0755 "/usr/local/bin/$bin"
done
@@ -0,0 +1,12 @@
---
vault:
addr: https://vault.service.consul:8200
auth_method: kubernetes
k8s_mount: k8s/au/syd1
k8s_role: puppet_certmanager
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
mount_point: pki_int
role_name: servers_default
output_path: /tmp/certmanager
tls_skip_verify: false
timeout: 30s
@@ -0,0 +1,11 @@
---
vault:
addr: https://vault.service.consul:8200
auth_method: kubernetes
k8s_mount: k8s/au/syd1
k8s_role: puppet_sshsigner
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
mount_point: sshca
role_name: signhost
tls_skip_verify: false
timeout: 30s
+1
View File
@@ -15,6 +15,7 @@ resources:
- serviceaccount_mediamark_ci.yaml - serviceaccount_mediamark_ci.yaml
- serviceaccount_plugin_docker_buildx.yaml - serviceaccount_plugin_docker_buildx.yaml
- serviceaccount_jellyfin_ha_src.yaml - serviceaccount_jellyfin_ha_src.yaml
- serviceaccount_jellyfin_plugin_sso.yaml
- serviceaccount_repospawner_ci.yaml - serviceaccount_repospawner_ci.yaml
- serviceaccount_terraform_artifactapi.yaml - serviceaccount_terraform_artifactapi.yaml
- serviceaccount_terraform_authentik.yaml - serviceaccount_terraform_authentik.yaml
@@ -0,0 +1,6 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: jellyfin-plugin-sso
namespace: woodpecker
@@ -26,6 +26,10 @@ data:
issuer: https://identity.unkin.net/application/o/argocd/ issuer: https://identity.unkin.net/application/o/argocd/
clientID: argocd clientID: argocd
clientSecret: $argocd-oidc:client_secret clientSecret: $argocd-oidc:client_secret
# The Authentik client is public (the iOS app can't hold a secret), so
# Authentik no longer enforces clientSecret; PKCE replaces it as the
# protection against authorization-code interception.
enablePKCEAuthentication: true
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the # identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
# stock image trust store validates it; no rootCA pin. # stock image trust store validates it; no rootCA pin.
requestedScopes: requestedScopes: