cheeztv is a second, kids-only Jellyfin instance in the media project. Kids
titles need a separate, safe library front (cheeztv.unkin.net) while staying
resumable in the existing adult instance (fafflix).
- apps/base/cheeztv: mirror the jellyfin (fafflix) HA stack 1:1 - same
jellyfin-ha:v0.1.3 fork image, 2-replica StatefulSet, RWX transcode PVC,
Intel iGPU transcode, CNPG Postgres + PgBouncer, Valkey transcode store,
k8up config backup, VMPodScrape. Media mounts subPath kids on the shared
movies/tv CephFS subvolumes so cheeztv sees only the kids trees.
- Separate state: own namespace, config PVC, cheeztv-postgres cluster,
cheeztv-valkey, and cnpg-cheeztv / cheeztv-config-backup buckets - nothing
shared with fafflix.
- Ingress/DNS: cheeztv.unkin.net (internal Traefik + external-dns at
198.18.200.4, cert-manager cheeztv-tls) plus the cluster hostname variant
cheeztv.k8s.syd1.au.unkin.net, matching how fafflix and logviewer.unkin.net
are wired.
- fafflix: add movies/kids and tvshows/kids subPath mounts alongside its
existing media mounts so kids libraries are browsable/resumable there; its
existing mounts, hostname and ingress are untouched.
- Register cheeztv in the media ApplicationSet generator and AppProject
destinations.