8847e20e0e352f35f88904534e0fc872730f863f
Servarr MediaCover (posters/fanart) and backups currently live on each replica's local /config, which is an emptyDir - so covers a leader downloads are invisible to the other replicas behind the Service. Provision a shared S3 bucket to hold these assets instead. - Add an arrstack-media ObjectStoreUser + Bucket (cephrgw-operator), mirroring the CNPG backup pattern; the operator mints the arrstack-media-s3 credential Secret in-namespace, so no Vault KV seeding is required. - Wire the radarr Deployment to the bucket via Radarr__MediaCover__S3__* env (creds from the operator Secret, estate CA mounted for RGW TLS). Unknown to the current image and activated by the -unkin3+ MediaCover-S3 build; sonarr and prowlarr wiring follow.
argocd-apps docs
Operational notes for the manifests in this repo.
| Doc | What it covers |
|---|---|
| cnpg-backups.md | How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured. |
| cnpg-restore.md | Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas. |
| authentik-rancher-sso.md | Manual runtime step to point Rancher's OIDC auth at the canonical identity.unkin.net issuer and trust the internal CA. |
| gitea-migration.md | Staged cutover of the git.unkin.net forge from the Puppet VM to the gitea namespace. |
| ca-rotation.md | Rolling the internal unkin.net PKI CA (vault-ca-cert): what Reloader restarts automatically vs. manual/CNPG restarts. |
Description
Languages
Shell
88.8%
Makefile
11.2%