256bfbd80d45ee396d5b5ea3e5eb8051409a6a8b
Activate the arr forks' #14 Redis features (SignalR backplane, cross-replica cache-invalidation bus, distributed rate limiter), which ship deployed but inert because no Valkey exists and nothing is wired. - Add a single shared ValkeyCluster (arrstack-valkey) under apps/base/arrstack/valkey, modeled on jellyfin-valkey: shards:1/replicas:2 HA, image via artifactapi, passwordless default user, node spread + cluster PDB, ephemeral storage. - Register the valkey component in the arrstack base kustomization. - Wire <App>__Redis__Host/Port into the sonarr/radarr/prowlarr env ConfigMaps, all pointing at the shared service valkey-arrstack-valkey:6379. Host is the activation switch (RedisOptions.IsConfigured gates on Host; no Enabled flag). Passwordless (jellyfin parity) so no Password/Ssl. Per-app key/channel prefixes keep the three apps isolated on one cluster.
argocd-apps docs
Operational notes for the manifests in this repo.
| Doc | What it covers |
|---|---|
| cnpg-backups.md | How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured. |
| cnpg-restore.md | Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas. |
| authentik-rancher-sso.md | Manual runtime step to point Rancher's OIDC auth at the canonical identity.unkin.net issuer and trust the internal CA. |
| gitea-migration.md | Staged cutover of the git.unkin.net forge from the Puppet VM to the gitea namespace. |
| ca-rotation.md | Rolling the internal unkin.net PKI CA (vault-ca-cert): what Reloader restarts automatically vs. manual/CNPG restarts. |
Description
Languages
Shell
88.8%
Makefile
11.2%