Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 3fa12e4e5a |
@@ -64,12 +64,8 @@ spec:
|
||||
archive_mode: "on"
|
||||
archive_timeout: 5min
|
||||
dynamic_shared_memory_type: posix
|
||||
effective_cache_size: 1536MB
|
||||
effective_cache_size: 256MB
|
||||
full_page_writes: "on"
|
||||
# Replicas report their oldest xmin to the primary, so multi-second reads on
|
||||
# a hot standby stop exhausting max_standby_streaming_delay and being
|
||||
# cancelled. Retained-dead-tuple cost is negligible on a ~155MB database.
|
||||
hot_standby_feedback: "on"
|
||||
log_destination: csvlog
|
||||
log_directory: /controller/log
|
||||
log_filename: postgres
|
||||
@@ -81,12 +77,7 @@ spec:
|
||||
max_parallel_workers: "16"
|
||||
max_replication_slots: "16"
|
||||
max_worker_processes: "16"
|
||||
# A pg_stat_statements.* parameter is what makes CNPG treat the extension as
|
||||
# managed and run CREATE EXTENSION in every database; preloading alone does
|
||||
# not create it.
|
||||
pg_stat_statements.max: "10000"
|
||||
pg_stat_statements.track: top
|
||||
shared_buffers: 512MB
|
||||
shared_buffers: 128MB
|
||||
shared_memory_type: mmap
|
||||
ssl_max_protocol_version: TLSv1.3
|
||||
ssl_min_protocol_version: TLSv1.3
|
||||
@@ -95,9 +86,6 @@ spec:
|
||||
wal_log_hints: "on"
|
||||
wal_receiver_timeout: 5s
|
||||
wal_sender_timeout: 5s
|
||||
# CNPG merges this with the libraries it manages itself.
|
||||
shared_preload_libraries:
|
||||
- pg_stat_statements
|
||||
syncReplicaElectionConstraint:
|
||||
enabled: false
|
||||
primaryUpdateMethod: restart
|
||||
@@ -117,16 +105,13 @@ spec:
|
||||
updateInterval: 30
|
||||
resources:
|
||||
limits:
|
||||
# 500m is a 50ms CFS quota per 100ms period, exhausted by bursts even at
|
||||
# ~0.01 cores average, so every query pays throttle latency.
|
||||
cpu: "2"
|
||||
cpu: 500m
|
||||
# 512Mi OOMKilled replicas under load (shared_buffers 128MB +
|
||||
# max_connections 200 leave no headroom) — see incident 2026-07-28.
|
||||
# shared_buffers 512MB needs the same headroom multiple, hence 2Gi.
|
||||
memory: 2Gi
|
||||
requests:
|
||||
cpu: 500m
|
||||
memory: 1Gi
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 512Mi
|
||||
smartShutdownTimeout: 180
|
||||
startDelay: 3600
|
||||
stopDelay: 1800
|
||||
|
||||
@@ -37,22 +37,6 @@ spec:
|
||||
name: authentik
|
||||
sectionName: https
|
||||
rules:
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: authentik-server
|
||||
port: 80
|
||||
weight: 1
|
||||
filters:
|
||||
- type: URLRewrite
|
||||
urlRewrite:
|
||||
path:
|
||||
type: ReplaceFullPath
|
||||
replaceFullPath: /application/o/token/
|
||||
matches:
|
||||
- path:
|
||||
type: Exact
|
||||
value: /application/o/token
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
@@ -102,22 +86,6 @@ spec:
|
||||
name: authentik-internal
|
||||
sectionName: https
|
||||
rules:
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: authentik-server
|
||||
port: 80
|
||||
weight: 1
|
||||
filters:
|
||||
- type: URLRewrite
|
||||
urlRewrite:
|
||||
path:
|
||||
type: ReplaceFullPath
|
||||
replaceFullPath: /application/o/token/
|
||||
matches:
|
||||
- path:
|
||||
type: Exact
|
||||
value: /application/o/token
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
|
||||
@@ -19,7 +19,6 @@ resources:
|
||||
- redis-deployment.yaml
|
||||
- redis-pvc.yaml
|
||||
- redis-service.yaml
|
||||
- server-vmpodscrape.yaml
|
||||
- vaultauth.yaml
|
||||
- vaultstaticsecret.yaml
|
||||
- vmpodscrape.yaml
|
||||
|
||||
@@ -1,16 +0,0 @@
|
||||
---
|
||||
# Scrape the authentik server's django_prometheus endpoint (:9300). Picked up
|
||||
# by the observability VMAgent (selectAllByDefault).
|
||||
apiVersion: operator.victoriametrics.com/v1beta1
|
||||
kind: VMPodScrape
|
||||
metadata:
|
||||
name: authentik-server
|
||||
namespace: authentik
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: authentik
|
||||
app.kubernetes.io/component: server
|
||||
podMetricsEndpoints:
|
||||
- port: metrics
|
||||
path: /metrics
|
||||
@@ -21,7 +21,7 @@ spec:
|
||||
runAsNonRoot: true
|
||||
containers:
|
||||
- name: operator
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.2.7
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.2.6
|
||||
args:
|
||||
- --metrics-bind-address=:8080
|
||||
- --health-probe-bind-address=:8081
|
||||
|
||||
@@ -6,7 +6,7 @@ resources:
|
||||
- namespace.yaml
|
||||
# CRDs are pulled from the bind-operator repo at the matching tag rather than
|
||||
# vendored here, so they never drift from the operator.
|
||||
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.7/config/crd/install.yaml
|
||||
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.6/config/crd/install.yaml
|
||||
- rbac.yaml
|
||||
- agent-dns-rbac.yaml
|
||||
- deployment.yaml
|
||||
|
||||
@@ -1,25 +0,0 @@
|
||||
---
|
||||
# Let's Encrypt *.ceph.unkin.net wildcard for the haproxy edge (ceph dashboard).
|
||||
# DNS-01 needs the delegated _acme-challenge.ceph.unkin.net CNAME in the public
|
||||
# unkin.net zone.
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: wildcard-ceph-unkin-net
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
secretName: wildcard-ceph-unkin-net-tls
|
||||
secretTemplate:
|
||||
annotations:
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "haproxy"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "haproxy"
|
||||
privateKey:
|
||||
size: 4096
|
||||
dnsNames:
|
||||
- "*.ceph.unkin.net"
|
||||
issuerRef:
|
||||
name: letsencrypt
|
||||
kind: ClusterIssuer
|
||||
group: cert-manager.io
|
||||
@@ -1,25 +0,0 @@
|
||||
---
|
||||
# Let's Encrypt *.main.unkin.net wildcard for the haproxy edge (pve, arr stack,
|
||||
# jellyfin, stalwart webadmin/autoconfig). DNS-01 needs the delegated
|
||||
# _acme-challenge.main.unkin.net CNAME in the public unkin.net zone.
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: wildcard-main-unkin-net
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
secretName: wildcard-main-unkin-net-tls
|
||||
secretTemplate:
|
||||
annotations:
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "haproxy"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "haproxy"
|
||||
privateKey:
|
||||
size: 4096
|
||||
dnsNames:
|
||||
- "*.main.unkin.net"
|
||||
issuerRef:
|
||||
name: letsencrypt
|
||||
kind: ClusterIssuer
|
||||
group: cert-manager.io
|
||||
@@ -14,9 +14,9 @@ spec:
|
||||
secretTemplate:
|
||||
annotations:
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy"
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner,haproxy"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner"
|
||||
privateKey:
|
||||
size: 4096
|
||||
dnsNames:
|
||||
|
||||
@@ -12,5 +12,3 @@ resources:
|
||||
- clusterissuer_letsencrypt.yaml
|
||||
- clusterissuer_letsencrypt-staging.yaml
|
||||
- certificate_wildcard-unkin-net.yaml
|
||||
- certificate_wildcard-main-unkin-net.yaml
|
||||
- certificate_wildcard-ceph-unkin-net.yaml
|
||||
|
||||
@@ -26,7 +26,7 @@ data:
|
||||
</key>
|
||||
<value>
|
||||
<PluginConfiguration>
|
||||
<OidEndpoint>https://identity.unkin.net/application/o/jellyfin/</OidEndpoint>
|
||||
<OidEndpoint>https://identity.k8s.syd1.au.unkin.net/application/o/jellyfin/</OidEndpoint>
|
||||
<OidClientId>jellyfin</OidClientId>
|
||||
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
|
||||
<Enabled>true</Enabled>
|
||||
|
||||
@@ -13,4 +13,6 @@ spec:
|
||||
targetPort: http
|
||||
selector:
|
||||
app: cheeztv
|
||||
# Pin each client to one replica to reduce transcode-session churn/takeover.
|
||||
sessionAffinity: ClientIP
|
||||
type: ClusterIP
|
||||
|
||||
@@ -4,8 +4,6 @@ kind: StatefulSet
|
||||
metadata:
|
||||
name: cheeztv
|
||||
namespace: cheeztv
|
||||
annotations:
|
||||
configmap.reloader.stakater.com/auto: "true"
|
||||
spec:
|
||||
# HA: two replicas coordinate transcode session ownership through Valkey and
|
||||
# resume each other's HLS segments off the shared RWX transcode PVC. Stable
|
||||
@@ -164,7 +162,7 @@ spec:
|
||||
readOnly: true
|
||||
containers:
|
||||
- name: cheeztv
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.2.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- name: http
|
||||
|
||||
@@ -26,7 +26,7 @@ data:
|
||||
</key>
|
||||
<value>
|
||||
<PluginConfiguration>
|
||||
<OidEndpoint>https://identity.unkin.net/application/o/jellyfin/</OidEndpoint>
|
||||
<OidEndpoint>https://identity.k8s.syd1.au.unkin.net/application/o/jellyfin/</OidEndpoint>
|
||||
<OidClientId>jellyfin</OidClientId>
|
||||
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
|
||||
<Enabled>true</Enabled>
|
||||
|
||||
@@ -13,4 +13,6 @@ spec:
|
||||
targetPort: http
|
||||
selector:
|
||||
app: fafflix
|
||||
# Pin each client to one replica to reduce transcode-session churn/takeover.
|
||||
sessionAffinity: ClientIP
|
||||
type: ClusterIP
|
||||
|
||||
@@ -4,8 +4,6 @@ kind: StatefulSet
|
||||
metadata:
|
||||
name: fafflix
|
||||
namespace: fafflix
|
||||
annotations:
|
||||
configmap.reloader.stakater.com/auto: "true"
|
||||
spec:
|
||||
# HA: two replicas coordinate transcode session ownership through Valkey and
|
||||
# resume each other's HLS segments off the shared RWX transcode PVC. Stable
|
||||
@@ -164,7 +162,7 @@ spec:
|
||||
readOnly: true
|
||||
containers:
|
||||
- name: fafflix
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.2.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- name: http
|
||||
|
||||
@@ -1,485 +0,0 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: haproxy-config
|
||||
namespace: haproxy
|
||||
data:
|
||||
certificate.list: |
|
||||
# First entry is the default cert for non-matching SNI.
|
||||
/etc/haproxy/certs/unkin-net/tls.crt
|
||||
/etc/haproxy/certs/main-unkin-net/tls.crt
|
||||
/etc/haproxy/certs/ceph-unkin-net/tls.crt
|
||||
|
||||
fe_http.map: |
|
||||
au-syd1-pve.main.unkin.net be_ausyd1pve_web
|
||||
au-syd1-pve-api.main.unkin.net be_ausyd1pve_api
|
||||
sonarr.main.unkin.net be_sonarr
|
||||
radarr.main.unkin.net be_radarr
|
||||
lidarr.main.unkin.net be_lidarr
|
||||
readarr.main.unkin.net be_readarr
|
||||
prowlarr.main.unkin.net be_prowlarr
|
||||
nzbget.main.unkin.net be_nzbget
|
||||
jellyfin.main.unkin.net be_jellyfin
|
||||
fafflix.unkin.net be_jellyfin
|
||||
git.unkin.net be_gitea
|
||||
grafana.unkin.net be_grafana
|
||||
dashboard.ceph.unkin.net be_ceph_dashboard
|
||||
mail-webadmin.main.unkin.net be_stalwart_webadmin
|
||||
autoconfig.main.unkin.net be_stalwart_webadmin
|
||||
autodiscovery.main.unkin.net be_stalwart_webadmin
|
||||
auth.unkin.net be_k8s_kanidm
|
||||
|
||||
fe_https.map: |
|
||||
au-syd1-pve.main.unkin.net be_ausyd1pve_web
|
||||
au-syd1-pve-api.main.unkin.net be_ausyd1pve_api
|
||||
sonarr.main.unkin.net be_sonarr
|
||||
radarr.main.unkin.net be_radarr
|
||||
lidarr.main.unkin.net be_lidarr
|
||||
readarr.main.unkin.net be_readarr
|
||||
prowlarr.main.unkin.net be_prowlarr
|
||||
nzbget.main.unkin.net be_nzbget
|
||||
jellyfin.main.unkin.net be_jellyfin
|
||||
fafflix.unkin.net be_jellyfin
|
||||
git.unkin.net be_gitea
|
||||
grafana.unkin.net be_grafana
|
||||
dashboard.ceph.unkin.net be_ceph_dashboard
|
||||
mail-webadmin.main.unkin.net be_stalwart_webadmin
|
||||
autoconfig.main.unkin.net be_stalwart_webadmin
|
||||
autodiscovery.main.unkin.net be_stalwart_webadmin
|
||||
auth.unkin.net be_k8s_kanidm
|
||||
|
||||
haproxy.cfg: |
|
||||
global
|
||||
log stdout format raw local0
|
||||
log stdout format raw local1 notice
|
||||
maxconn 4000
|
||||
hard-stop-after 2m
|
||||
ssl-default-bind-ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH
|
||||
ssl-default-bind-options ssl-min-ver TLSv1.2 ssl-max-ver TLSv1.3
|
||||
ssl-default-server-ciphers kEECDH+aRSA+AES:kRSA+AES:+AES256:RC4-SHA:!kEDH:!LOW:!EXP:!MD5:!aNULL:!eNULL
|
||||
ssl-default-server-options no-sslv3
|
||||
stats timeout 30s
|
||||
stats socket /var/lib/haproxy/stats
|
||||
stats socket /var/lib/haproxy/admin.sock mode 660 level admin
|
||||
tune.ssl.default-dh-param 2048
|
||||
|
||||
defaults
|
||||
log global
|
||||
maxconn 5000
|
||||
mode http
|
||||
option httplog
|
||||
option dontlognull
|
||||
option http-server-close
|
||||
option forwardfor except 127.0.0.0/8
|
||||
option redispatch
|
||||
retries 3
|
||||
stats enable
|
||||
timeout http-request 10s
|
||||
timeout queue 1m
|
||||
timeout connect 10s
|
||||
timeout client 5m
|
||||
timeout server 5m
|
||||
timeout http-keep-alive 10s
|
||||
timeout check 10s
|
||||
|
||||
frontend fe_http
|
||||
bind 0.0.0.0:80
|
||||
mode http
|
||||
description Global HTTP Frontend
|
||||
acl acl-letsencrypt path_beg /.well-known/acme-challenge/
|
||||
http-request set-header X-Forwarded-Proto https
|
||||
http-request set-header X-Real-IP %[src]
|
||||
use_backend be_letsencrypt if acl-letsencrypt
|
||||
use_backend %[req.hdr(host),lower,map(/usr/local/etc/haproxy/fe_http.map,be_default)]
|
||||
|
||||
frontend fe_https
|
||||
bind 0.0.0.0:443 ssl crt-list /usr/local/etc/haproxy/certificate.list ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH force-tlsv12
|
||||
mode http
|
||||
description Global HTTPS Frontend
|
||||
acl acl-letsencrypt path_beg /.well-known/acme-challenge/
|
||||
acl acl_ausyd1pve req.hdr(host) -i au-syd1-pve.main.unkin.net
|
||||
acl acl_sonarr req.hdr(host) -i sonarr.main.unkin.net
|
||||
acl acl_radarr req.hdr(host) -i radarr.main.unkin.net
|
||||
acl acl_lidarr req.hdr(host) -i lidarr.main.unkin.net
|
||||
acl acl_readarr req.hdr(host) -i readarr.main.unkin.net
|
||||
acl acl_prowlarr req.hdr(host) -i prowlarr.main.unkin.net
|
||||
acl acl_nzbget req.hdr(host) -i nzbget.main.unkin.net
|
||||
acl acl_jellyfin req.hdr(host) -i jellyfin.main.unkin.net
|
||||
acl acl_fafflix req.hdr(host) -i fafflix.unkin.net
|
||||
acl acl_gitea req.hdr(host) -i git.unkin.net
|
||||
acl acl_grafana req.hdr(host) -i grafana.unkin.net
|
||||
acl acl_ceph_dashboard req.hdr(host) -i dashboard.ceph.unkin.net
|
||||
acl acl_stalwart_webadmin req.hdr(host) -i mail-webadmin.main.unkin.net
|
||||
acl acl_stalwart_webadmin req.hdr(host) -i autoconfig.main.unkin.net
|
||||
acl acl_stalwart_webadmin req.hdr(host) -i autodiscovery.main.unkin.net
|
||||
acl acl_kanidm req.hdr(host) -i auth.unkin.net
|
||||
acl acl_internalsubnets src 198.18.0.0/16 10.10.12.0/24
|
||||
http-request set-header X-Forwarded-Proto https
|
||||
http-request set-header X-Real-IP %[src]
|
||||
http-request deny if { hdr_dom(host) -i au-syd1-pve.main.unkin.net } !acl_internalsubnets
|
||||
http-response set-header X-Frame-Options DENY if acl_ausyd1pve
|
||||
http-response set-header X-Frame-Options DENY if acl_sonarr
|
||||
http-response set-header X-Frame-Options DENY if acl_radarr
|
||||
http-response set-header X-Frame-Options DENY if acl_lidarr
|
||||
http-response set-header X-Frame-Options DENY if acl_readarr
|
||||
http-response set-header X-Frame-Options DENY if acl_prowlarr
|
||||
http-response set-header X-Frame-Options DENY if acl_nzbget
|
||||
http-response set-header X-Frame-Options DENY if acl_jellyfin
|
||||
http-response set-header X-Frame-Options DENY if acl_fafflix
|
||||
http-response set-header X-Frame-Options DENY if acl_gitea
|
||||
http-response set-header X-Frame-Options DENY if acl_grafana
|
||||
http-response set-header X-Frame-Options DENY if acl_ceph_dashboard
|
||||
http-response set-header X-Frame-Options DENY if acl_stalwart_webadmin
|
||||
http-response set-header X-Frame-Options DENY if acl_kanidm
|
||||
http-response set-header X-Content-Type-Options nosniff
|
||||
http-response set-header X-XSS-Protection 1;mode=block
|
||||
use_backend be_letsencrypt if acl-letsencrypt
|
||||
use_backend %[req.hdr(host),lower,map(/usr/local/etc/haproxy/fe_https.map,be_default)]
|
||||
|
||||
frontend fe_imap
|
||||
bind 0.0.0.0:143
|
||||
mode tcp
|
||||
description Frontend for Stalwart IMAP (STARTTLS)
|
||||
default_backend be_stalwart_imap
|
||||
log global
|
||||
option tcplog
|
||||
tcp-request inspect-delay 5s
|
||||
tcp-request content accept if { req_len 0 }
|
||||
|
||||
frontend fe_imaps
|
||||
bind 0.0.0.0:993
|
||||
mode tcp
|
||||
description Frontend for Stalwart IMAPS (implicit TLS)
|
||||
default_backend be_stalwart_imaps
|
||||
log global
|
||||
option tcplog
|
||||
tcp-request inspect-delay 5s
|
||||
tcp-request content accept if { req_len 0 }
|
||||
|
||||
frontend fe_metrics
|
||||
bind 0.0.0.0:8405
|
||||
mode http
|
||||
description Metrics Frontend
|
||||
http-request set-header X-Forwarded-Proto https
|
||||
http-request set-header X-Real-IP %[src]
|
||||
http-request use-service prometheus-exporter if { path /metrics }
|
||||
|
||||
frontend fe_smtp
|
||||
bind 0.0.0.0:25
|
||||
mode tcp
|
||||
description Frontend for Stalwart SMTP
|
||||
default_backend be_stalwart_smtp
|
||||
log global
|
||||
option tcplog
|
||||
tcp-request inspect-delay 5s
|
||||
tcp-request content accept if { req_len 0 }
|
||||
|
||||
frontend fe_submission
|
||||
bind 0.0.0.0:587
|
||||
mode tcp
|
||||
description Frontend for Stalwart SMTP Submission
|
||||
default_backend be_stalwart_submission
|
||||
log global
|
||||
option tcplog
|
||||
tcp-request inspect-delay 5s
|
||||
tcp-request content accept if { req_len 0 }
|
||||
|
||||
backend be_ausyd1pve_api
|
||||
description Backend for au-syd1 pve cluster (API only)
|
||||
balance roundrobin
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
|
||||
backend be_ausyd1pve_web
|
||||
description Backend for au-syd1 pve cluster (Web)
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
|
||||
backend be_ceph_dashboard
|
||||
description Backend for Ceph Dashboard from Mgr instances
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-check expect status 200
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 9443 }
|
||||
http-reuse always
|
||||
option httpchk GET /
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
stick-table type ip size 200k expire 30m
|
||||
server prodnxsr0009 198.18.23.9:9443 check cookie prodnxsr0009 fall 2 inter 2s rise 3 ssl verify none
|
||||
server prodnxsr0010 198.18.23.10:9443 check cookie prodnxsr0010 fall 2 inter 2s rise 3 ssl verify none
|
||||
server prodnxsr0011 198.18.23.11:9443 check cookie prodnxsr0011 fall 2 inter 2s rise 3 ssl verify none
|
||||
server prodnxsr0012 198.18.23.12:9443 check cookie prodnxsr0012 fall 2 inter 2s rise 3 ssl verify none
|
||||
server prodnxsr0013 198.18.23.13:9443 check cookie prodnxsr0013 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_default
|
||||
description Backend for unmatched HTTP traffic
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
option httpchk GET /
|
||||
option forwardfor
|
||||
|
||||
backend be_gitea
|
||||
description Backend for gitea cluster
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
stick on src
|
||||
stick-table type ip size 200k expire 30m
|
||||
server ausyd1nxvm2080 198.18.26.18:443 check cookie ausyd1nxvm2080 fall 2 inter 2s rise 3 ssl verify none
|
||||
server ausyd1nxvm2081 198.18.27.117:443 check cookie ausyd1nxvm2081 fall 2 inter 2s rise 3 ssl verify none
|
||||
server ausyd1nxvm2082 198.18.28.71:443 check cookie ausyd1nxvm2082 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_grafana
|
||||
description Backend for grafana nodes
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
stick on src
|
||||
stick-table type ip size 200k expire 30m
|
||||
server ausyd1nxvm2015 198.18.27.2:443 check cookie ausyd1nxvm2015 fall 2 inter 2s rise 3 ssl verify none
|
||||
server ausyd1nxvm2016 198.18.28.189:443 check cookie ausyd1nxvm2016 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_jellyfin
|
||||
description Backend for au-syd1 jellyfin
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
server ausyd1nxvm2051 198.18.25.164:443 check cookie ausyd1nxvm2051 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_k8s_kanidm
|
||||
description Backend for Kanidm (auth.unkin.net via Kubernetes internal Traefik)
|
||||
balance roundrobin
|
||||
http-reuse always
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
option httpchk
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
http-check connect ssl sni auth.unkin.net
|
||||
http-check send meth GET uri /status ver HTTP/1.1 hdr Host auth.unkin.net
|
||||
http-check expect status 200
|
||||
server k8s-traefik-internal 198.18.200.4:443 ssl verify none check inter 2s rise 3 fall 2 sni str(auth.unkin.net)
|
||||
|
||||
backend be_letsencrypt
|
||||
description Backend for LetsEncrypt Verifications
|
||||
balance roundrobin
|
||||
server ausyd1nxvm2057 198.18.25.3:8888
|
||||
|
||||
backend be_lidarr
|
||||
description Backend for au-syd1 lidarr
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /consul/health
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
server ausyd1nxvm2048 198.18.28.165:443 check cookie ausyd1nxvm2048 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_nzbget
|
||||
description Backend for au-syd1 nzbget
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /consul/health
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
server ausyd1nxvm2045 198.18.25.44:443 check cookie ausyd1nxvm2045 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_prowlarr
|
||||
description Backend for au-syd1 prowlarr
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /consul/health
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
server ausyd1nxvm2050 198.18.25.66:443 check cookie ausyd1nxvm2050 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_radarr
|
||||
description Backend for au-syd1 radarr
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /consul/health
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
server ausyd1nxvm2047 198.18.27.131:443 check cookie ausyd1nxvm2047 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_readarr
|
||||
description Backend for au-syd1 readarr
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /consul/health
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
server ausyd1nxvm2049 198.18.29.32:443 check cookie ausyd1nxvm2049 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_sonarr
|
||||
description Backend for au-syd1 sonarr
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 443 }
|
||||
http-reuse always
|
||||
option httpchk GET /consul/health
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
server ausyd1nxvm2046 198.18.26.161:443 check cookie ausyd1nxvm2046 fall 2 inter 2s rise 3 ssl verify none
|
||||
|
||||
backend be_stalwart_imap
|
||||
description Backend for Stalwart IMAP (STARTTLS)
|
||||
balance roundrobin
|
||||
mode tcp
|
||||
option tcp-check
|
||||
option prefer-last-server
|
||||
stick on src
|
||||
stick-table type ip size 200k expire 30m
|
||||
tcp-check connect port 143 send-proxy
|
||||
tcp-check expect string "* OK"
|
||||
tcp-check send "A001 STARTTLS\r\n"
|
||||
tcp-check expect rstring "A001 (OK|2.0.0)"
|
||||
server ausyd1nxvm2124 198.18.28.76:143 check fall 3 inter 3s rise 2 send-proxy-v2
|
||||
server ausyd1nxvm2125 198.18.29.44:143 check fall 3 inter 3s rise 2 send-proxy-v2
|
||||
server ausyd1nxvm2126 198.18.25.160:143 check fall 3 inter 3s rise 2 send-proxy-v2
|
||||
|
||||
backend be_stalwart_imaps
|
||||
description Backend for Stalwart IMAPS (implicit TLS)
|
||||
balance roundrobin
|
||||
mode tcp
|
||||
option tcp-check
|
||||
option prefer-last-server
|
||||
stick on src
|
||||
stick-table type ip size 200k expire 30m
|
||||
tcp-check connect ssl send-proxy
|
||||
tcp-check expect string "* OK"
|
||||
server ausyd1nxvm2124 198.18.28.76:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none
|
||||
server ausyd1nxvm2125 198.18.29.44:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none
|
||||
server ausyd1nxvm2126 198.18.25.160:993 check fall 3 inter 3s rise 2 send-proxy-v2 ssl verify none
|
||||
|
||||
backend be_stalwart_smtp
|
||||
description Backend for Stalwart SMTP
|
||||
balance roundrobin
|
||||
mode tcp
|
||||
option tcp-check
|
||||
option prefer-last-server
|
||||
stick on src
|
||||
stick-table type ip size 200k expire 30m
|
||||
tcp-check connect port 25 send-proxy
|
||||
tcp-check expect string "220 "
|
||||
server ausyd1nxvm2124 198.18.28.76:25 check fall 3 inter 3s rise 2 send-proxy-v2
|
||||
server ausyd1nxvm2125 198.18.29.44:25 check fall 3 inter 3s rise 2 send-proxy-v2
|
||||
server ausyd1nxvm2126 198.18.25.160:25 check fall 3 inter 3s rise 2 send-proxy-v2
|
||||
|
||||
backend be_stalwart_submission
|
||||
description Backend for Stalwart SMTP Submission
|
||||
balance roundrobin
|
||||
mode tcp
|
||||
option tcp-check
|
||||
option prefer-last-server
|
||||
stick on src
|
||||
stick-table type ip size 200k expire 30m
|
||||
tcp-check connect port 587 send-proxy
|
||||
tcp-check expect string "220 "
|
||||
server ausyd1nxvm2124 198.18.28.76:587 check fall 3 inter 3s rise 2 send-proxy-v2
|
||||
server ausyd1nxvm2125 198.18.29.44:587 check fall 3 inter 3s rise 2 send-proxy-v2
|
||||
server ausyd1nxvm2126 198.18.25.160:587 check fall 3 inter 3s rise 2 send-proxy-v2
|
||||
|
||||
backend be_stalwart_webadmin
|
||||
description Backend for Stalwart Webadmin
|
||||
balance roundrobin
|
||||
cookie SRVNAME insert indirect nocache
|
||||
http-check expect status 200
|
||||
http-request set-header X-Forwarded-Port %[dst_port]
|
||||
http-request add-header X-Forwarded-Proto https if { dst_port 9443 }
|
||||
http-reuse always
|
||||
option httpchk GET /
|
||||
option forwardfor
|
||||
option http-keep-alive
|
||||
option prefer-last-server
|
||||
redirect scheme https if !{ ssl_fc }
|
||||
stick-table type ip size 200k expire 30m
|
||||
server ausyd1nxvm2124 198.18.28.76:443 check cookie ausyd1nxvm2124 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none
|
||||
server ausyd1nxvm2125 198.18.29.44:443 check cookie ausyd1nxvm2125 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none
|
||||
server ausyd1nxvm2126 198.18.25.160:443 check cookie ausyd1nxvm2126 fall 2 inter 2s rise 3 send-proxy-v2 ssl verify none
|
||||
|
||||
# The `peers au-syd1-prod` section is dropped: peer names must be static and a
|
||||
# Deployment cannot provide them. Service sessionAffinity: ClientIP pins a
|
||||
# client to one replica so the per-replica stick-tables behave as before.
|
||||
|
||||
listen health
|
||||
bind 0.0.0.0:8404
|
||||
mode http
|
||||
monitor-uri /healthz
|
||||
|
||||
listen stats
|
||||
bind 127.0.0.1:9090
|
||||
mode http
|
||||
stats uri /
|
||||
stats auth admin:admin
|
||||
@@ -1,162 +0,0 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: haproxy
|
||||
namespace: haproxy
|
||||
annotations:
|
||||
reloader.stakater.com/auto: "true"
|
||||
spec:
|
||||
replicas: 3
|
||||
selector:
|
||||
matchLabels:
|
||||
app: haproxy
|
||||
strategy:
|
||||
type: RollingUpdate
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: haproxy
|
||||
spec:
|
||||
automountServiceAccountToken: false
|
||||
terminationGracePeriodSeconds: 150
|
||||
affinity:
|
||||
podAntiAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
- labelSelector:
|
||||
matchLabels:
|
||||
app: haproxy
|
||||
topologyKey: kubernetes.io/hostname
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 99
|
||||
runAsGroup: 99
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: haproxy
|
||||
image: haproxy:3.2.24-alpine
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- haproxy
|
||||
- -W
|
||||
- -db
|
||||
- -f
|
||||
- /usr/local/etc/haproxy/haproxy.cfg
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop: [ALL]
|
||||
# Frontends bind 25/80/143/443/587; the dst_port ACLs need the real ports.
|
||||
add: [NET_BIND_SERVICE]
|
||||
ports:
|
||||
- name: http
|
||||
containerPort: 80
|
||||
protocol: TCP
|
||||
- name: https
|
||||
containerPort: 443
|
||||
protocol: TCP
|
||||
- name: smtp
|
||||
containerPort: 25
|
||||
protocol: TCP
|
||||
- name: imap
|
||||
containerPort: 143
|
||||
protocol: TCP
|
||||
- name: submission
|
||||
containerPort: 587
|
||||
protocol: TCP
|
||||
- name: imaps
|
||||
containerPort: 993
|
||||
protocol: TCP
|
||||
- name: health
|
||||
containerPort: 8404
|
||||
protocol: TCP
|
||||
- name: metrics
|
||||
containerPort: 8405
|
||||
protocol: TCP
|
||||
- name: stats
|
||||
containerPort: 9090
|
||||
protocol: TCP
|
||||
lifecycle:
|
||||
preStop:
|
||||
exec:
|
||||
# SIGUSR1 to the master soft-stops the workers; hard-stop-after
|
||||
# caps the drain. Wait so kubelet holds SIGTERM until it is done.
|
||||
command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- kill -s USR1 1; while kill -0 1 2>/dev/null; do sleep 1; done
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: health
|
||||
initialDelaySeconds: 15
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: health
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 5
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
resources:
|
||||
requests:
|
||||
cpu: 200m
|
||||
memory: 256Mi
|
||||
limits:
|
||||
cpu: 2
|
||||
memory: 1Gi
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: /usr/local/etc/haproxy
|
||||
readOnly: true
|
||||
- name: cert-unkin-net
|
||||
mountPath: /etc/haproxy/certs/unkin-net
|
||||
readOnly: true
|
||||
- name: cert-main-unkin-net
|
||||
mountPath: /etc/haproxy/certs/main-unkin-net
|
||||
readOnly: true
|
||||
- name: cert-ceph-unkin-net
|
||||
mountPath: /etc/haproxy/certs/ceph-unkin-net
|
||||
readOnly: true
|
||||
- name: run
|
||||
mountPath: /var/lib/haproxy
|
||||
volumes:
|
||||
- name: config
|
||||
configMap:
|
||||
name: haproxy-config
|
||||
# ssl-load-extra-files loads <crtfile>.key by default, so the key is
|
||||
# projected next to the cert as tls.crt.key.
|
||||
- name: cert-unkin-net
|
||||
secret:
|
||||
secretName: wildcard-unkin-net-tls
|
||||
items:
|
||||
- key: tls.crt
|
||||
path: tls.crt
|
||||
- key: tls.key
|
||||
path: tls.crt.key
|
||||
- name: cert-main-unkin-net
|
||||
secret:
|
||||
secretName: wildcard-main-unkin-net-tls
|
||||
items:
|
||||
- key: tls.crt
|
||||
path: tls.crt
|
||||
- key: tls.key
|
||||
path: tls.crt.key
|
||||
- name: cert-ceph-unkin-net
|
||||
secret:
|
||||
secretName: wildcard-ceph-unkin-net-tls
|
||||
items:
|
||||
- key: tls.crt
|
||||
path: tls.crt
|
||||
- key: tls.key
|
||||
path: tls.crt.key
|
||||
- name: run
|
||||
emptyDir: {}
|
||||
restartPolicy: Always
|
||||
@@ -1,12 +0,0 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- configmap.yaml
|
||||
- deployment.yaml
|
||||
- service.yaml
|
||||
- pdb.yaml
|
||||
- vpa.yaml
|
||||
- vmpodscrape.yaml
|
||||
@@ -1,5 +0,0 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: haproxy
|
||||
@@ -1,11 +0,0 @@
|
||||
---
|
||||
apiVersion: policy/v1
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
name: haproxy
|
||||
namespace: haproxy
|
||||
spec:
|
||||
maxUnavailable: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: haproxy
|
||||
@@ -1,43 +0,0 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: haproxy
|
||||
namespace: haproxy
|
||||
annotations:
|
||||
purelb.io/service-group: dmz
|
||||
purelb.io/addresses: 198.18.199.1
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
loadBalancerIP: "198.18.199.1"
|
||||
# Source IP must survive for acl_internalsubnets, X-Real-IP and SMTP.
|
||||
externalTrafficPolicy: Local
|
||||
# Pins a client to one replica, standing in for the dropped stick-table peers.
|
||||
sessionAffinity: ClientIP
|
||||
selector:
|
||||
app: haproxy
|
||||
ports:
|
||||
- name: http
|
||||
port: 80
|
||||
protocol: TCP
|
||||
targetPort: http
|
||||
- name: https
|
||||
port: 443
|
||||
protocol: TCP
|
||||
targetPort: https
|
||||
- name: smtp
|
||||
port: 25
|
||||
protocol: TCP
|
||||
targetPort: smtp
|
||||
- name: imap
|
||||
port: 143
|
||||
protocol: TCP
|
||||
targetPort: imap
|
||||
- name: submission
|
||||
port: 587
|
||||
protocol: TCP
|
||||
targetPort: submission
|
||||
- name: imaps
|
||||
port: 993
|
||||
protocol: TCP
|
||||
targetPort: imaps
|
||||
@@ -1,13 +0,0 @@
|
||||
---
|
||||
apiVersion: operator.victoriametrics.com/v1beta1
|
||||
kind: VMPodScrape
|
||||
metadata:
|
||||
name: haproxy
|
||||
namespace: haproxy
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: haproxy
|
||||
podMetricsEndpoints:
|
||||
- port: metrics
|
||||
path: /metrics
|
||||
@@ -1,13 +0,0 @@
|
||||
---
|
||||
apiVersion: autoscaling.k8s.io/v1
|
||||
kind: VerticalPodAutoscaler
|
||||
metadata:
|
||||
name: haproxy-vpa
|
||||
namespace: haproxy
|
||||
spec:
|
||||
targetRef:
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
name: haproxy
|
||||
updatePolicy:
|
||||
updateMode: "Off"
|
||||
@@ -99,23 +99,24 @@ spec:
|
||||
- mountPath: /docker-custom-entrypoint.d/post-startup/additional-ruby-gems.sh
|
||||
name: additional-ruby-gems
|
||||
subPath: additional-ruby-gems.sh
|
||||
- mountPath: /usr/local/bin/certmanager
|
||||
name: cert-helpers
|
||||
subPath: vault-helper
|
||||
- mountPath: /usr/local/bin/sshsignhost
|
||||
name: cert-helpers
|
||||
subPath: vault-helper
|
||||
- mountPath: /opt/certmanager/config.yaml
|
||||
name: cert-helpers
|
||||
subPath: certmanager-config.yaml
|
||||
- mountPath: /opt/sshsignhost/config.yaml
|
||||
name: cert-helpers
|
||||
subPath: sshsignhost-config.yaml
|
||||
- mountPath: /configmaps/auth.conf
|
||||
name: compiler-auth-conf
|
||||
subPath: auth.conf
|
||||
- mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh
|
||||
name: compiler-auth-conf-seed
|
||||
subPath: 10-auth-conf.sh
|
||||
- mountPath: /docker-custom-entrypoint.d/pre-default/20-vault-helpers.sh
|
||||
name: compiler-vault-helpers-seed
|
||||
subPath: 20-vault-helpers.sh
|
||||
- mountPath: /opt/certmanager/config.yaml
|
||||
name: certmanager-config
|
||||
subPath: certmanager.yaml
|
||||
readOnly: true
|
||||
- mountPath: /opt/sshsignhost/config.yaml
|
||||
name: sshsignhost-config
|
||||
subPath: sshsignhost.yaml
|
||||
readOnly: true
|
||||
initContainers:
|
||||
- name: copy-configmaps
|
||||
image: busybox:1.35
|
||||
@@ -213,41 +214,67 @@ spec:
|
||||
echo "$EXPECTED encapic" | sha256sum -c -
|
||||
install -m 0755 encapic /opt/bin/encapic
|
||||
|
||||
# Puppet shells out to these two from generate() during catalog
|
||||
# compilation: profiles::pki::vault runs certmanager and
|
||||
# profiles::ssh::sign runs sshsignhost.
|
||||
install_release() {
|
||||
name=$1
|
||||
version=$2
|
||||
asset="$name-linux-amd64"
|
||||
base="https://git.unkin.net/unkin/$name/releases/download/$version"
|
||||
curl -fsSL -o "$name" "$base/$asset"
|
||||
curl -fsSL -o "$name.checksums" "$base/checksums.txt"
|
||||
# checksums.txt covers every release asset; pick the line for the
|
||||
# one we downloaded and verify it under our local filename.
|
||||
expected=$(awk -v a="$asset" '$NF == a || $NF == "*"a {print $1}' "$name.checksums")
|
||||
if [ -z "$expected" ]; then
|
||||
echo "no checksum for $asset in $version checksums.txt" >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "$expected $name" | sha256sum -c -
|
||||
install -m 0755 "$name" "/opt/bin/$name"
|
||||
}
|
||||
|
||||
install_release certmanager v0.2.0
|
||||
install_release sshsignhost v0.1.0
|
||||
|
||||
echo "Shared binaries setup completed"
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 256Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 64Mi
|
||||
volumeMounts:
|
||||
- mountPath: /opt/bin/
|
||||
name: puppet-shared-bins
|
||||
|
||||
- name: setup-cert-helpers
|
||||
image: git.unkin.net/unkin/almalinux9-base:20260606
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
args:
|
||||
- |
|
||||
set -e
|
||||
CH=/opt/bin/certhelpers
|
||||
PYROOT=$CH/py-el9-1
|
||||
TPL=/etc/puppetlabs/code/environments/develop/site/profiles/templates/helpers
|
||||
mkdir -p "$CH"
|
||||
|
||||
# The helpers are python3 (requests, pyyaml) and openvoxserver ships
|
||||
# no python, so stage a self-contained EL9 tree once per volume.
|
||||
if [ ! -f "$PYROOT/.ready" ]; then
|
||||
echo "Staging python runtime for the cert helpers..."
|
||||
TMP=$CH/.py-el9-1.$$
|
||||
rm -rf "$TMP"
|
||||
dnf -y --installroot="$TMP" --releasever=9 --nodocs \
|
||||
--setopt=install_weak_deps=0 --disablerepo=unkin install \
|
||||
python3 python3-requests python3-pyyaml python3-six
|
||||
rm -rf "$TMP/var/cache" "$TMP/var/lib/dnf" "$TMP/var/lib/rpm" \
|
||||
"$TMP/usr/share/locale"
|
||||
# Both hardcode EL absolute paths that only exist inside the tree.
|
||||
SP=$TMP/usr/lib/python3.9/site-packages
|
||||
ln -sfn ../../six.py "$SP/urllib3/packages/six.py"
|
||||
sed -i "s|'/etc/pki/tls/certs/ca-bundle.crt'|'$PYROOT/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem'|" \
|
||||
"$SP/requests/certs.py"
|
||||
touch "$TMP/.ready"
|
||||
mv -T "$TMP" "$PYROOT" || rm -rf "$TMP"
|
||||
fi
|
||||
|
||||
# Render from the puppet-prod ERB templates on the code volume so this
|
||||
# repo never carries a second copy of the scripts.
|
||||
for n in certmanager sshsignhost; do
|
||||
sed -e "s|<%= @venv_path %>|$PYROOT/usr|g" \
|
||||
-e "s|<%= @config_path %>|/opt/$n/config.yaml|g" \
|
||||
"$TPL/$n.erb" > "$CH/.$n.$$"
|
||||
chmod 0755 "$CH/.$n.$$"
|
||||
mv "$CH/.$n.$$" "$CH/$n"
|
||||
done
|
||||
echo "Cert helpers setup completed"
|
||||
resources:
|
||||
limits:
|
||||
cpu: 1
|
||||
memory: 1Gi
|
||||
requests:
|
||||
cpu: 200m
|
||||
memory: 256Mi
|
||||
volumeMounts:
|
||||
- mountPath: /opt/bin/
|
||||
name: puppet-shared-bins
|
||||
- mountPath: /etc/puppetlabs/code/
|
||||
name: puppet-code-volume
|
||||
readOnly: true
|
||||
securityContext:
|
||||
fsGroup: 999
|
||||
seccompProfile:
|
||||
@@ -282,6 +309,19 @@ spec:
|
||||
configMap:
|
||||
name: additional-ruby-gems
|
||||
defaultMode: 0755
|
||||
- name: cert-helpers
|
||||
configMap:
|
||||
name: cert-helpers
|
||||
items:
|
||||
- key: vault-helper
|
||||
path: vault-helper
|
||||
mode: 0755
|
||||
- key: certmanager-config.yaml
|
||||
path: certmanager-config.yaml
|
||||
mode: 0444
|
||||
- key: sshsignhost-config.yaml
|
||||
path: sshsignhost-config.yaml
|
||||
mode: 0444
|
||||
- name: compiler-auth-conf
|
||||
configMap:
|
||||
name: compiler-auth.conf
|
||||
@@ -289,15 +329,5 @@ spec:
|
||||
configMap:
|
||||
name: compiler-auth-conf-seed
|
||||
defaultMode: 0755
|
||||
- name: compiler-vault-helpers-seed
|
||||
configMap:
|
||||
name: compiler-vault-helpers-seed
|
||||
defaultMode: 0755
|
||||
- name: certmanager-config
|
||||
configMap:
|
||||
name: certmanager-config
|
||||
- name: sshsignhost-config
|
||||
configMap:
|
||||
name: sshsignhost-config
|
||||
strategy:
|
||||
type: RollingUpdate
|
||||
|
||||
@@ -64,23 +64,15 @@ configMapGenerator:
|
||||
- resources/compiler/10-auth-conf.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: compiler-vault-helpers-seed
|
||||
files:
|
||||
- resources/compiler/20-vault-helpers.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: certmanager-config
|
||||
files:
|
||||
- resources/compiler/certmanager.yaml
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: sshsignhost-config
|
||||
files:
|
||||
- resources/compiler/sshsignhost.yaml
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: additional-ruby-gems
|
||||
files:
|
||||
- resources/additional-ruby-gems.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: cert-helpers
|
||||
files:
|
||||
- resources/cert-helpers/vault-helper
|
||||
- resources/cert-helpers/certmanager-config.yaml
|
||||
- resources/cert-helpers/sshsignhost-config.yaml
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
|
||||
@@ -6,6 +6,4 @@ echo "Installing additional Ruby gems..."
|
||||
/opt/puppetlabs/puppet/bin/gem install ipaddr
|
||||
/opt/puppetlabs/puppet/bin/gem install hiera-eyaml
|
||||
/opt/puppetlabs/puppet/bin/gem install toml
|
||||
# Under set -e a failed install kills the entrypoint post-startup hooks, taking down an already-serving compiler.
|
||||
/opt/puppetlabs/bin/puppetserver gem install toml
|
||||
echo "Additional Ruby gems installed successfully"
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
---
|
||||
# profiles::helpers::certmanager::vault_config, with kubernetes auth: the
|
||||
# certmanager approle is CIDR-bound to the legacy VM masters.
|
||||
vault:
|
||||
addr: 'https://vault.service.consul:8200'
|
||||
auth_method: 'kubernetes'
|
||||
k8s_mount: 'k8s/au/syd1'
|
||||
k8s_role: 'puppet_certmanager'
|
||||
jwt_path: '/var/run/secrets/kubernetes.io/serviceaccount/token'
|
||||
mount_point: 'pki_int'
|
||||
role_name: 'servers_default'
|
||||
output_path: '/tmp/certmanager'
|
||||
@@ -0,0 +1,11 @@
|
||||
---
|
||||
# profiles::helpers::sshsignhost::vault_config, with kubernetes auth.
|
||||
vault:
|
||||
addr: 'https://vault.service.consul:8200'
|
||||
auth_method: 'kubernetes'
|
||||
k8s_mount: 'k8s/au/syd1'
|
||||
k8s_role: 'puppet_sshsigner'
|
||||
jwt_path: '/var/run/secrets/kubernetes.io/serviceaccount/token'
|
||||
mount_point: 'ssh-host-signer'
|
||||
role_name: 'hostrole'
|
||||
output_path: '/tmp/sshsignhost'
|
||||
+11
@@ -0,0 +1,11 @@
|
||||
#!/bin/sh
|
||||
# Runs the certmanager/sshsignhost helper matching the name it is invoked as.
|
||||
# The openvoxserver image has no python, so the EL9 tree staged on the shared
|
||||
# bins volume is started through its own dynamic loader.
|
||||
set -eu
|
||||
|
||||
PYROOT=/opt/bin/certhelpers/py-el9-1
|
||||
|
||||
exec "${PYROOT}/lib64/ld-linux-x86-64.so.2" \
|
||||
--library-path "${PYROOT}/lib64:${PYROOT}/usr/lib64" \
|
||||
"${PYROOT}/usr/bin/python3.9" "/opt/bin/certhelpers/${0##*/}" "$@"
|
||||
@@ -1,29 +0,0 @@
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
|
||||
BIN_DIR=/opt/bin
|
||||
CA=/opt/vault-ca-cert.crt
|
||||
|
||||
if [ ! -s "$CA" ]; then
|
||||
echo "FATAL: $CA missing or empty; certmanager and sshsignhost cannot verify Vault" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# profiles::pki::vault and profiles::ssh::sign shell out to fixed /usr/local/bin
|
||||
# paths from generate(); the binaries ship on the shared PVC, and /usr/local/bin
|
||||
# lives in the image. Wrappers rather than symlinks because neither binary reads
|
||||
# a CA path from its config: SSL_CERT_FILE scopes the internal CA to these two
|
||||
# processes instead of the puppetserver JVM's own trust store.
|
||||
for bin in certmanager sshsignhost; do
|
||||
if [ ! -x "$BIN_DIR/$bin" ]; then
|
||||
echo "FATAL: $BIN_DIR/$bin missing; generate() would abort every catalog compile" >&2
|
||||
exit 1
|
||||
fi
|
||||
cat > "/usr/local/bin/$bin" <<WRAPPER
|
||||
#!/bin/sh
|
||||
SSL_CERT_FILE=$CA
|
||||
export SSL_CERT_FILE
|
||||
exec $BIN_DIR/$bin "\$@"
|
||||
WRAPPER
|
||||
chmod 0755 "/usr/local/bin/$bin"
|
||||
done
|
||||
@@ -1,12 +0,0 @@
|
||||
---
|
||||
vault:
|
||||
addr: https://vault.service.consul:8200
|
||||
auth_method: kubernetes
|
||||
k8s_mount: k8s/au/syd1
|
||||
k8s_role: puppet_certmanager
|
||||
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||
mount_point: pki_int
|
||||
role_name: servers_default
|
||||
output_path: /tmp/certmanager
|
||||
tls_skip_verify: false
|
||||
timeout: 30s
|
||||
@@ -1,11 +0,0 @@
|
||||
---
|
||||
vault:
|
||||
addr: https://vault.service.consul:8200
|
||||
auth_method: kubernetes
|
||||
k8s_mount: k8s/au/syd1
|
||||
k8s_role: puppet_sshsigner
|
||||
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||
mount_point: sshca
|
||||
role_name: signhost
|
||||
tls_skip_verify: false
|
||||
timeout: 30s
|
||||
@@ -15,7 +15,6 @@ resources:
|
||||
- serviceaccount_mediamark_ci.yaml
|
||||
- serviceaccount_plugin_docker_buildx.yaml
|
||||
- serviceaccount_jellyfin_ha_src.yaml
|
||||
- serviceaccount_jellyfin_plugin_sso.yaml
|
||||
- serviceaccount_repospawner_ci.yaml
|
||||
- serviceaccount_terraform_artifactapi.yaml
|
||||
- serviceaccount_terraform_authentik.yaml
|
||||
|
||||
@@ -1,6 +0,0 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: jellyfin-plugin-sso
|
||||
namespace: woodpecker
|
||||
@@ -1,6 +0,0 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- ../../../base/haproxy
|
||||
@@ -29,7 +29,6 @@ spec:
|
||||
- path: apps/overlays/*/ghp
|
||||
- path: apps/overlays/*/gitea
|
||||
- path: apps/overlays/*/grafana-system
|
||||
- path: apps/overlays/*/haproxy
|
||||
- path: apps/overlays/*/inteldeviceplugins-system
|
||||
- path: apps/overlays/*/jfrog
|
||||
- path: apps/overlays/*/k8up-system
|
||||
|
||||
@@ -43,8 +43,6 @@ spec:
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: 'gitea'
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: 'haproxy'
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: 'jfrog'
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: 'kanidm'
|
||||
|
||||
@@ -26,10 +26,6 @@ data:
|
||||
issuer: https://identity.unkin.net/application/o/argocd/
|
||||
clientID: argocd
|
||||
clientSecret: $argocd-oidc:client_secret
|
||||
# The Authentik client is public (the iOS app can't hold a secret), so
|
||||
# Authentik no longer enforces clientSecret; PKCE replaces it as the
|
||||
# protection against authorization-code interception.
|
||||
enablePKCEAuthentication: true
|
||||
# identity.unkin.net now serves the LetsEncrypt *.unkin.net wildcard, so the
|
||||
# stock image trust store validates it; no rootCA pin.
|
||||
requestedScopes:
|
||||
|
||||
Reference in New Issue
Block a user