Files
argocd-apps/apps/base/fafflix/cnpg_backup.yaml
T
unkin-agent 0cd5446d6b
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
Replace legacy jellyfin app with fafflix (adult, cheeztv pattern)
Rebuild the adult media instance as 'fafflix' following the same HA pattern
as the kids instance (cheeztv): Postgres-backed jellyfin-ha fork, Valkey
transcode-lease store, shared-RWX transcode, CNPG + k8up/restic backups,
static CephFS media PVs.

- Add apps/base/fafflix (namespace/labels/secrets/buckets/Vault path fafflix-*)
- fafflix mounts the shared movies/tv subvolumes' adult subtree at
  /media/{movies,tv} plus the kids subtree at /media/{movies,tv}-kids so it can
  resume kids content started on cheeztv; new unique static PV volumeHandles
- Keep serving the legacy hostname jellyfin.k8s.syd1.au.unkin.net (fafflix-tls);
  dedicated fafflix domain deferred, no new public host
- config PVC on cephfs-raid5-delete
- Remove apps/base/jellyfin + overlay; swap jellyfin->fafflix in the media
  ApplicationSet glob and AppProject namespace destination
- No data currently on the adult instance, so the wipe/replace is sanctioned
2026-08-24 22:50:15 +10:00

46 lines
1.2 KiB
YAML

---
# Ceph RGW (S3) backup target for the fafflix CNPG cluster, provisioned by the
# in-estate cephrgw-operator: one dedicated bucket + owner user. CNPG reads the
# S3 credential Secret from its own namespace.
apiVersion: ceph.unkin.net/v1alpha1
kind: ObjectStoreUser
metadata:
name: cnpg-fafflix-backup
namespace: fafflix
spec:
displayName: "CNPG backup owner (fafflix)"
uid: cnpg-fafflix-backup
maxBuckets: 5
secretName: cnpg-fafflix-backup-s3
retainOnDelete: true
---
apiVersion: ceph.unkin.net/v1alpha1
kind: Bucket
metadata:
name: cnpg-fafflix
namespace: fafflix
spec:
placementTarget: ec
bucketName: cnpg-fafflix
ownerRef: cnpg-fafflix-backup
versioning: false
tags:
app: fafflix
purpose: cnpg-backup
retainOnDelete: true
---
# Nightly base backup on top of always-on WAL archiving. Scheduled off-peak and
# staggered from the other CNPG clusters (6-field cron, seconds first).
apiVersion: postgresql.cnpg.io/v1
kind: ScheduledBackup
metadata:
name: cnpg-fafflix-nightly
namespace: fafflix
spec:
schedule: "0 35 3 * * *"
immediate: false
backupOwnerReference: self
method: barmanObjectStore
cluster:
name: fafflix-postgres