Compare commits

..

1 Commits

Author SHA1 Message Date
Renovate Bot
3b93c84b68 Update renovate/renovate Docker tag to v41.97.10 2025-09-08 10:48:59 +00:00
99 changed files with 3966 additions and 1836 deletions

View File

@@ -1,25 +1,22 @@
name: renovate name: Renovate
on: on:
schedule: schedule:
- cron: "@daily" - cron: '@daily'
workflow_dispatch: workflow_dispatch:
jobs: jobs:
renovate: renovate:
runs-on: ubuntu-latest runs-on: ubuntu-latest
container:
image: renovate/renovate:41.97.7
options: |-
--network=bridge
steps: steps:
- name: Checkout repository - name: Checkout repository
uses: actions/checkout@v4 uses: actions/checkout@v4
- name: Run Renovate - name: Run Renovate
uses: docker://renovate/renovate:41.97.10
env: env:
LOG_LEVEL: info
RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }} RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}
GITHUB_COM_TOKEN: ${{ secrets.PAT_TOKEN }} GITHUB_COM_TOKEN: ${{ secrets.PAT_TOKEN }}
run: | with:
renovate args: ''

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: bazarr-longhorn name: bazarr-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 5Gi storage: 5Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -5,7 +5,7 @@ metadata:
name: bazarr name: bazarr
namespace: default namespace: default
spec: spec:
strategy: stratergy:
type: Recreate type: Recreate
replicas: 1 replicas: 1
selector: selector:
@@ -18,7 +18,7 @@ spec:
spec: spec:
containers: containers:
- name: bazarr - name: bazarr
image: linuxserver/bazarr:1.5.3 image: linuxserver/bazarr:1.5.2
ports: ports:
- containerPort: 6767 - containerPort: 6767
env: env:
@@ -38,7 +38,7 @@ spec:
volumes: volumes:
- name: config - name: config
persistentVolumeClaim: persistentVolumeClaim:
claimName: bazarr-longhorn claimName: bazarr-ceph
- name: tv - name: tv
nfs: nfs:
server: 10.0.0.123 server: 10.0.0.123

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: code-server-longhorn name: code-server-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -18,7 +18,7 @@ spec:
spec: spec:
containers: containers:
- name: code-server - name: code-server
image: lscr.io/linuxserver/code-server:4.104.3 image: lscr.io/linuxserver/code-server:4.103.2
ports: ports:
- containerPort: 8443 - containerPort: 8443
env: env:
@@ -46,4 +46,4 @@ spec:
volumes: volumes:
- name: code-server - name: code-server
persistentVolumeClaim: persistentVolumeClaim:
claimName: code-server-longhorn claimName: code-server-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: drone-longhorn name: drone-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -56,12 +56,12 @@ spec:
- name: DRONE_SERVER_PROTO - name: DRONE_SERVER_PROTO
value: "https" value: "https"
- name: DRONE_USER_CREATE - name: DRONE_USER_CREATE
value: "username:aggarwalakshun,admin:true" value: "username:akshun,admin:true"
volumeMounts: volumeMounts:
- name: drone-data - name: drone-data
mountPath: /data mountPath: /data
- name: drone-runner - name: drone-runner
image: drone/drone-runner-kube@sha256:a515ca817bb61be2801e5c70245ca7c2be0fce7b28b91bd7a6d0dd2f1d22eb23 image: drone/drone-runner-kube@sha256:282790766b911cae625500212948fe5928d7ed14c38ccb0cbfd765447daf70ba
env: env:
- name: DRONE_RPC_PROTO - name: DRONE_RPC_PROTO
value: "http" value: "http"
@@ -80,4 +80,4 @@ spec:
volumes: volumes:
- name: drone-data - name: drone-data
persistentVolumeClaim: persistentVolumeClaim:
claimName: drone-longhorn claimName: drone-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: ersatztv-longhorn name: ersatztv-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -10,5 +10,5 @@ spec:
volumeMode: Filesystem volumeMode: Filesystem
resources: resources:
requests: requests:
storage: 5Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -18,7 +18,7 @@ spec:
spec: spec:
containers: containers:
- name: ersatztv - name: ersatztv
image: jasongdove/ersatztv:v25.7.1 image: jasongdove/ersatztv:v25.5.0
ports: ports:
- containerPort: 8409 - containerPort: 8409
volumeMounts: volumeMounts:
@@ -40,7 +40,7 @@ spec:
volumes: volumes:
- name: data - name: data
persistentVolumeClaim: persistentVolumeClaim:
claimName: ersatztv-longhorn claimName: ersatztv-ceph
- name: i915 - name: i915
hostPath: hostPath:
path: /dev/dri path: /dev/dri

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: ghostfolio-longhorn name: ghostfolio-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -78,7 +78,7 @@ spec:
key: postgres-password key: postgres-password
containers: containers:
- name: ghostfolio - name: ghostfolio
image: docker.io/ghostfolio/ghostfolio:2.208.0 image: docker.io/ghostfolio/ghostfolio:2.197.0
securityContext: securityContext:
capabilities: capabilities:
drop: drop:
@@ -123,4 +123,4 @@ spec:
volumes: volumes:
- name: ghostfolio-data - name: ghostfolio-data
persistentVolumeClaim: persistentVolumeClaim:
claimName: ghostfolio-longhorn claimName: ghostfolio-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: gitea-act-runner-longhorn name: gitea-act-runner-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 100Mi storage: 100Mi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -18,14 +18,14 @@ spec:
labels: labels:
app: gitea-act-runner app: gitea-act-runner
spec: spec:
restartPolicy: Always
hostNetwork: true hostNetwork: true
restartPolicy: Always
volumes: volumes:
- name: docker-certs - name: docker-certs
emptyDir: {} emptyDir: {}
- name: runner-data - name: runner-data
persistentVolumeClaim: persistentVolumeClaim:
claimName: gitea-act-runner-longhorn claimName: gitea-act-runner-ceph
initContainers: initContainers:
- name: wait-for-gitea - name: wait-for-gitea
image: busybox image: busybox
@@ -52,7 +52,7 @@ spec:
- name: GITEA_INSTANCE_URL - name: GITEA_INSTANCE_URL
value: "https://gitea.akshun-lab.cc" value: "https://gitea.akshun-lab.cc"
- name: GITEA_RUNNER_REGISTRATION_TOKEN - name: GITEA_RUNNER_REGISTRATION_TOKEN
value: "uxvKmGvtraocJMCcfJ101XC9kUoY8OlCEN18CvgZ" value: "NvAHP4f1in4Fpe6VFaiwiN98IR0poOQoDv4dDKcN"
- name: CONFIG_FILE - name: CONFIG_FILE
value: "/data/config.yaml" value: "/data/config.yaml"
volumeMounts: volumeMounts:
@@ -61,7 +61,7 @@ spec:
- name: runner-data - name: runner-data
mountPath: /data mountPath: /data
- name: daemon - name: daemon
image: docker:28.5.1-dind image: docker:28.4.0-dind
env: env:
- name: DOCKER_TLS_CERTDIR - name: DOCKER_TLS_CERTDIR
value: /certs value: /certs
@@ -70,3 +70,4 @@ spec:
volumeMounts: volumeMounts:
- name: docker-certs - name: docker-certs
mountPath: /certs mountPath: /certs

View File

@@ -43,4 +43,4 @@ spec:
volumes: volumes:
- name: db - name: db
persistentVolumeClaim: persistentVolumeClaim:
claimName: gitea-db-longhorn claimName: gitea-db-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: gitea-app-longhorn name: gitea-app-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,13 +11,13 @@ spec:
resources: resources:
requests: requests:
storage: 5Gi storage: 5Gi
storageClassName: longhorn storageClassName: csi-rbd-sc
--- ---
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: gitea-db-longhorn name: gitea-db-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -26,4 +26,4 @@ spec:
resources: resources:
requests: requests:
storage: 5Gi storage: 5Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -29,7 +29,7 @@ spec:
done done
containers: containers:
- name: gitea - name: gitea
image: gitea/gitea:1.24.6 image: gitea/gitea:1.24.5
ports: ports:
- containerPort: 22 - containerPort: 22
- containerPort: 3000 - containerPort: 3000
@@ -69,4 +69,4 @@ spec:
type: File type: File
- name: gitea-data - name: gitea-data
persistentVolumeClaim: persistentVolumeClaim:
claimName: gitea-app-longhorn claimName: gitea-app-ceph

View File

@@ -1,12 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: gotenberg-service
namespace: default
spec:
selector:
app: gotenberg
type: ClusterIP
ports:
- port: 3000
targetPort: 3000

View File

@@ -1,30 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: gotenberg
namespace: default
spec:
selector:
matchLabels:
app: gotenberg
template:
metadata:
labels:
app: gotenberg
spec:
securityContext:
runAsUser: 1001
containers:
- name: gotenberg
image: gotenberg/gotenberg:8.24
command:
- sh
- -c
- |
gotenberg --chromium-disable-javascript=true --chromium-allow-list=file:///tmp/.*
ports:
- containerPort: 3000
securityContext:
readOnlyRootFilesystem: false
allowPrivilegeEscalation: false
privileged: false

View File

@@ -52,7 +52,7 @@ data:
useEqualHeights: true useEqualHeights: true
hideErrors: true hideErrors: true
statusStyle: "dot" statusStyle: "dot"
background: /images/sur.png background: /images/background.png
services.yaml: | services.yaml: |
- Apps: - Apps:
- Sonarr: - Sonarr:
@@ -259,6 +259,13 @@ data:
namespace: default namespace: default
podSelector: app=paperless-ngx podSelector: app=paperless-ngx
app: paperless-ngx app: paperless-ngx
- Open-WebUI:
icon: ollama.png
description: ollama Frontend
href: https://ollama.akshun-lab.cc
namespace: default
podSelector: app=open-webui
app: open-webui
- Ghostfolio: - Ghostfolio:
icon: ghostfolio.png icon: ghostfolio.png
description: portfolio analyzer description: portfolio analyzer
@@ -266,6 +273,12 @@ data:
namespace: default namespace: default
podSelector: app=ghostfolio podSelector: app=ghostfolio
app: ghostfolio app: ghostfolio
- Drone:
icon: drone.png
description: CI/CD
namespace: default
app: drone
href: https://drone.akshun-lab.cc
- Searxng: - Searxng:
icon: searxng.png icon: searxng.png
description: search engine description: search engine

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: homepage-longhorn name: homepage-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 100Mi storage: 100Mi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -42,7 +42,7 @@ spec:
subPath: services.yaml subPath: services.yaml
containers: containers:
- name: homepage - name: homepage
image: "ghcr.io/gethomepage/homepage:v1.5.0" image: "ghcr.io/gethomepage/homepage:v1.4.6"
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
env: env:
- name: HOMEPAGE_ALLOWED_HOSTS - name: HOMEPAGE_ALLOWED_HOSTS
@@ -86,7 +86,7 @@ spec:
name: homepage name: homepage
- name: images - name: images
persistentVolumeClaim: persistentVolumeClaim:
claimName: homepage-longhorn claimName: homepage-ceph
- name: logs - name: logs
emptyDir: {} emptyDir: {}
- name: tmp - name: tmp

View File

@@ -16,9 +16,10 @@ spec:
labels: labels:
app: immich-ml app: immich-ml
spec: spec:
runtimeClassName: nvidia
containers: containers:
- name: immich-machine-learning - name: immich-machine-learning
image: ghcr.io/immich-app/immich-machine-learning:v2.0.1-openvino image: ghcr.io/immich-app/immich-machine-learning:v1.140.1-cuda
ports: ports:
- containerPort: 3003 - containerPort: 3003
env: env:
@@ -33,10 +34,10 @@ spec:
mountPath: /cache mountPath: /cache
resources: resources:
requests: requests:
gpu.intel.com/i915: "1" nvidia.com/gpu: "1"
limits: limits:
gpu.intel.com/i915: "1" nvidia.com/gpu: "1"
volumes: volumes:
- name: model-cache - name: model-cache
persistentVolumeClaim: persistentVolumeClaim:
claimName: immich-cache-longhorn claimName: immich-cache-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: immich-cache-longhorn name: immich-cache-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,7 +11,7 @@ spec:
resources: resources:
requests: requests:
storage: 10Gi storage: 10Gi
storageClassName: longhorn storageClassName: csi-rbd-sc
--- ---
apiVersion: v1 apiVersion: v1

View File

@@ -39,7 +39,7 @@ spec:
done done
containers: containers:
- name: immich-server - name: immich-server
image: ghcr.io/immich-app/immich-server:v2.0.1 image: ghcr.io/immich-app/immich-server:v1.140.1
ports: ports:
- containerPort: 2283 - containerPort: 2283
env: env:

View File

@@ -13,7 +13,8 @@ data:
host: localhost host: localhost
port: 5432 port: 5432
check_tables: true check_tables: true
invidious_companion: signature_server: localhost:12999
- private_url: "http://localhost:8282/companion" visitor_data: ${VISITOR_DATA}
invidious_companion_key: ${INVIDIOUS_COMPANION_KEY} po_token: ${PO_TOKEN}
port: 3000
hmac_key: ${INVIDIOUS_HMAC_KEY} hmac_key: ${INVIDIOUS_HMAC_KEY}

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: invidious-longhorn name: invidious-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -65,22 +65,21 @@ spec:
volumeMounts: volumeMounts:
- name: postgres-data - name: postgres-data
mountPath: /var/lib/postgresql/data mountPath: /var/lib/postgresql/data
- name: inv-companion - name: inv-sig-helper
image: quay.io/invidious/invidious-companion@sha256:a96f7a1eb88bf0d5882d519c9410f8c7b2d391cafc378b72f3bfd37dd5f0e587 image: quay.io/invidious/inv-sig-helper@sha256:39fee87693ef3d71c212d9511f2adb3230783753342321489deab17caa87c42f
restartPolicy: Always restartPolicy: Always
args: ["--tcp", "0.0.0.0:12999"]
env: env:
- name: SERVER_SECRET_KEY - name: RUST_LOG
valueFrom: value: "info"
secretKeyRef:
name: invidious-secrets
key: INVIDIOUS_COMPANION_KEY
securityContext: securityContext:
readOnlyRootFilesystem: true
capabilities: capabilities:
drop: drop:
- ALL - ALL
containers: containers:
- name: invidious - name: invidious
image: quay.io/invidious/invidious@sha256:2836b5b8226a53a9cc2afdbd5f5fe6bccdd200f2e17cd92a828b4dc8d8b5cc06 image: quay.io/invidious/invidious@sha256:9ffa4f1ea5cf01abe3102777102bd7a13153c79f6ff6ac072b6a29dda6909a8b
command: command:
- sh - sh
- -c - -c
@@ -108,4 +107,4 @@ spec:
name: invidious-config name: invidious-config
- name: postgres-data - name: postgres-data
persistentVolumeClaim: persistentVolumeClaim:
claimName: invidious-longhorn claimName: invidious-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: jellyfin-longhorn name: jellyfin-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 20Gi storage: 20Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -24,6 +24,8 @@ spec:
volumeMounts: volumeMounts:
- name: media - name: media
mountPath: /media mountPath: /media
readOnly: true
recursiveReadOnly: Enabled
- name: config - name: config
mountPath: /config mountPath: /config
- name: cache - name: cache
@@ -40,7 +42,7 @@ spec:
volumes: volumes:
- name: config - name: config
persistentVolumeClaim: persistentVolumeClaim:
claimName: jellyfin-longhorn claimName: jellyfin-ceph
- name: cache - name: cache
hostPath: hostPath:
path: /tmp/ path: /tmp/

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: jellyseerr-longhorn name: jellyseerr-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -54,4 +54,4 @@ spec:
volumes: volumes:
- name: config - name: config
persistentVolumeClaim: persistentVolumeClaim:
claimName: jellyseerr-longhorn claimName: jellyseerr-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: jellystat-longhorn name: jellystat-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,19 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: jellystat-backups-longhorn
namespace: default
spec:
accessModes:
- ReadWriteOnce
volumeMode: Filesystem
resources:
requests:
storage: 1Gi
storageClassName: longhorn

View File

@@ -32,11 +32,10 @@ spec:
secretKeyRef: secretKeyRef:
name: jellystat-secret name: jellystat-secret
key: password key: password
- name: PGDATA
value: /mnt/postgres/data
volumeMounts: volumeMounts:
- name: postgres-data - name: backup
mountPath: /mnt/postgres mountPath: /var/lib/postgresql/data
subPath: db
containers: containers:
- name: jellystat - name: jellystat
image: cyfershepard/jellystat:1.1.6 image: cyfershepard/jellystat:1.1.6
@@ -60,12 +59,10 @@ spec:
name: jellystat-secret name: jellystat-secret
key: jwt key: jwt
volumeMounts: volumeMounts:
- name: backups - name: backup
mountPath: /app/backend/backup-data mountPath: /app/backend/backup-data
subPath: backup
volumes: volumes:
- name: postgres-data - name: backup
persistentVolumeClaim: persistentVolumeClaim:
claimName: jellystat-longhorn claimName: jellystat-ceph
- name: backups
persistentVolumeClaim:
claimName: jellystat-backups-longhorn

View File

@@ -17,7 +17,7 @@ spec:
spec: spec:
containers: containers:
- name: collabora - name: collabora
image: collabora/code:25.04.6.1.1 image: collabora/code:25.04.5.1.1
ports: ports:
- containerPort: 9980 - containerPort: 9980
env: env:

View File

@@ -28,7 +28,7 @@ spec:
done done
containers: containers:
- name: nextcloud - name: nextcloud
image: lscr.io/linuxserver/nextcloud:32.0.0 image: lscr.io/linuxserver/nextcloud:31.0.8
ports: ports:
- containerPort: 443 - containerPort: 443
env: env:

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: open-webui-longhorn name: open-webui-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -10,5 +10,5 @@ spec:
volumeMode: Filesystem volumeMode: Filesystem
resources: resources:
requests: requests:
storage: 2Gi storage: 5Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -17,7 +17,7 @@ spec:
spec: spec:
containers: containers:
- name: open-webui - name: open-webui
image: ghcr.io/open-webui/open-webui:0.6.33 image: ghcr.io/open-webui/open-webui:v0.6.26
ports: ports:
- containerPort: 8080 - containerPort: 8080
env: env:
@@ -29,4 +29,4 @@ spec:
volumes: volumes:
- name: config - name: config
persistentVolumeClaim: persistentVolumeClaim:
claimName: open-webui-longhorn claimName: open-webui-ceph

View File

@@ -41,12 +41,6 @@ spec:
value: "https://ngx.akshun-lab.cc" value: "https://ngx.akshun-lab.cc"
- name: PAPERLESS_TIME_ZONE - name: PAPERLESS_TIME_ZONE
value: "Asia/Kolkata" value: "Asia/Kolkata"
- name: PAPERLESS_TIKA_ENABLED
value: "1"
- name: PAPERLESS_TIKA_ENDPOINT
value: "http://tika-service:9998"
- name: PAPERLESS_TIKA_GOTENBERG_ENDPOINT
value: "http://gotenberg-service:3000"
volumeMounts: volumeMounts:
- name: data - name: data
mountPath: /usr/src/paperless/data mountPath: /usr/src/paperless/data
@@ -63,4 +57,4 @@ spec:
volumes: volumes:
- name: data - name: data
persistentVolumeClaim: persistentVolumeClaim:
claimName: paperless-longhorn claimName: paperless-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: paperless-longhorn name: paperless-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: pihole-longhorn name: pihole-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -16,18 +16,6 @@ spec:
app: pihole app: pihole
spec: spec:
hostNetwork: true hostNetwork: true
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: kubernetes.io/hostname
operator: In
values:
- kube-02
- kube-03
- kube-04
- kube-05
containers: containers:
- name: pihole - name: pihole
image: pihole/pihole@sha256:90a1412b3d3037d1c22131402bde19180d898255b584d685c84d943cf9c14821 image: pihole/pihole@sha256:90a1412b3d3037d1c22131402bde19180d898255b584d685c84d943cf9c14821
@@ -51,4 +39,4 @@ spec:
volumes: volumes:
- name: pihole-data - name: pihole-data
persistentVolumeClaim: persistentVolumeClaim:
claimName: pihole-longhorn claimName: pihole-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: prowlarr-longhorn name: prowlarr-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -56,4 +56,4 @@ spec:
volumes: volumes:
- name: config - name: config
persistentVolumeClaim: persistentVolumeClaim:
claimName: prowlarr-longhorn claimName: prowlarr-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: pulse-longhorn name: pulse-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 100Mi storage: 100Mi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -17,7 +17,7 @@ spec:
spec: spec:
containers: containers:
- name: pulse - name: pulse
image: rcourtman/pulse:4.23.0 image: rcourtman/pulse:4.14.0
volumeMounts: volumeMounts:
- name: pulse-data - name: pulse-data
mountPath: /data mountPath: /data
@@ -27,4 +27,4 @@ spec:
volumes: volumes:
- name: pulse-data - name: pulse-data
persistentVolumeClaim: persistentVolumeClaim:
claimName: pulse-longhorn claimName: pulse-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: qbittorrent-longhorn name: qbittorrent-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -58,7 +58,7 @@ spec:
volumes: volumes:
- name: config - name: config
persistentVolumeClaim: persistentVolumeClaim:
claimName: qbittorrent-longhorn claimName: qbittorrent-ceph
- name: downloads - name: downloads
nfs: nfs:
server: 10.0.0.123 server: 10.0.0.123

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: radarr-longhorn name: radarr-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 2Gi storage: 2Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -46,4 +46,4 @@ spec:
path: /merge/downloads path: /merge/downloads
- name: config - name: config
persistentVolumeClaim: persistentVolumeClaim:
claimName: radarr-longhorn claimName: radarr-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: searxng-longhorn name: searxng-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 100Mi storage: 100Mi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -18,7 +18,7 @@ spec:
spec: spec:
containers: containers:
- name: searxng - name: searxng
image: searxng/searxng@sha256:0e0493d1bff9ed55f774709c9113185aa3da0db3aea84bf86b356e97a21d54c6 image: searxng/searxng@sha256:511fa3f34c1d119c47f88c9a1e7eda1340f346543e980c17e5f14b27dac6a1ed
ports: ports:
- containerPort: 8080 - containerPort: 8080
env: env:
@@ -32,4 +32,4 @@ spec:
volumes: volumes:
- name: searxng - name: searxng
persistentVolumeClaim: persistentVolumeClaim:
claimName: searxng-longhorn claimName: searxng-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: semaphore-longhorn name: semaphore-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 2Gi storage: 2Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -40,7 +40,7 @@ spec:
subPath: db subPath: db
containers: containers:
- name: semaphore - name: semaphore
image: public.ecr.aws/semaphore/pro/server:v2.16.34 image: public.ecr.aws/semaphore/pro/server:v2.16.29
ports: ports:
- containerPort: 3000 - containerPort: 3000
envFrom: envFrom:
@@ -65,4 +65,4 @@ spec:
volumes: volumes:
- name: db - name: db
persistentVolumeClaim: persistentVolumeClaim:
claimName: semaphore-longhorn claimName: semaphore-ceph

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: sonarr-longhorn name: sonarr-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 5Gi storage: 5Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -38,7 +38,7 @@ spec:
volumes: volumes:
- name: config - name: config
persistentVolumeClaim: persistentVolumeClaim:
claimName: sonarr-longhorn claimName: sonarr-ceph
- name: downloads - name: downloads
nfs: nfs:
server: 10.0.0.123 server: 10.0.0.123

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: speedtest-longhorn name: speedtest-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 100Mi storage: 100Mi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -18,7 +18,7 @@ spec:
spec: spec:
containers: containers:
- name: speedtest - name: speedtest
image: lscr.io/linuxserver/speedtest-tracker:1.6.8 image: lscr.io/linuxserver/speedtest-tracker:1.6.6
ports: ports:
- containerPort: 80 - containerPort: 80
env: env:
@@ -49,4 +49,4 @@ spec:
volumes: volumes:
- name: config - name: config
persistentVolumeClaim: persistentVolumeClaim:
claimName: speedtest-longhorn claimName: speedtest-ceph

View File

@@ -1,12 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: tika-service
namespace: default
spec:
type: ClusterIP
selector:
app: tika
ports:
- port: 9998
targetPort: 9998

View File

@@ -1,19 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tika
namespace: default
spec:
selector:
matchLabels:
app: tika
template:
metadata:
labels:
app: tika
spec:
containers:
- name: tika
image: apache/tika:3.2.3.0
ports:
- containerPort: 9998

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: vaultwarden-longhorn name: vaultwarden-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -11,4 +11,4 @@ spec:
resources: resources:
requests: requests:
storage: 1Gi storage: 1Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -30,4 +30,4 @@ spec:
volumes: volumes:
- name: data - name: data
persistentVolumeClaim: persistentVolumeClaim:
claimName: vaultwarden-longhorn claimName: vaultwarden-ceph

View File

@@ -48,7 +48,7 @@ spec:
containers: containers:
- name: csi-rbdplugin - name: csi-rbdplugin
# for stable functionality replace canary with latest release version # for stable functionality replace canary with latest release version
image: quay.io/cephcsi/cephcsi:v3.15.0-amd64 image: quay.io/cephcsi/cephcsi:canary
args: args:
- "--nodeid=$(NODE_ID)" - "--nodeid=$(NODE_ID)"
- "--type=rbd" - "--type=rbd"
@@ -159,7 +159,7 @@ spec:
- name: socket-dir - name: socket-dir
mountPath: /csi mountPath: /csi
- name: csi-attacher - name: csi-attacher
image: registry.k8s.io/sig-storage/csi-attacher:v4.10.0 image: registry.k8s.io/sig-storage/csi-attacher:v4.9.0
args: args:
- "--v=1" - "--v=1"
- "--csi-address=$(ADDRESS)" - "--csi-address=$(ADDRESS)"
@@ -210,7 +210,7 @@ spec:
mountPath: /csi mountPath: /csi
- name: csi-rbdplugin-controller - name: csi-rbdplugin-controller
# for stable functionality replace canary with latest release version # for stable functionality replace canary with latest release version
image: quay.io/cephcsi/cephcsi:v3.15.0-amd64 image: quay.io/cephcsi/cephcsi:canary
args: args:
- "--type=controller" - "--type=controller"
- "--v=5" - "--v=5"
@@ -231,7 +231,7 @@ spec:
- name: ceph-config - name: ceph-config
mountPath: /etc/ceph/ mountPath: /etc/ceph/
- name: liveness-prometheus - name: liveness-prometheus
image: quay.io/cephcsi/cephcsi:v3.15-canary-amd64 image: quay.io/cephcsi/cephcsi:canary
args: args:
- "--type=liveness" - "--type=liveness"
- "--endpoint=$(CSI_ENDPOINT)" - "--endpoint=$(CSI_ENDPOINT)"

View File

@@ -29,7 +29,7 @@ spec:
add: ["SYS_ADMIN"] add: ["SYS_ADMIN"]
allowPrivilegeEscalation: true allowPrivilegeEscalation: true
# for stable functionality replace canary with latest release version # for stable functionality replace canary with latest release version
image: quay.io/cephcsi/cephcsi:v3.15-canary-amd64 image: quay.io/cephcsi/cephcsi:canary
args: args:
- "--nodeid=$(NODE_ID)" - "--nodeid=$(NODE_ID)"
- "--pluginpath=/var/lib/kubelet/plugins" - "--pluginpath=/var/lib/kubelet/plugins"
@@ -116,7 +116,7 @@ spec:
securityContext: securityContext:
privileged: true privileged: true
allowPrivilegeEscalation: true allowPrivilegeEscalation: true
image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.0 image: registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.0
args: args:
- "--v=1" - "--v=1"
- "--csi-address=/csi/csi.sock" - "--csi-address=/csi/csi.sock"
@@ -135,7 +135,7 @@ spec:
securityContext: securityContext:
privileged: true privileged: true
allowPrivilegeEscalation: true allowPrivilegeEscalation: true
image: quay.io/cephcsi/cephcsi:v3.15-canary-amd64 image: quay.io/cephcsi/cephcsi:canary
args: args:
- "--type=liveness" - "--type=liveness"
- "--endpoint=$(CSI_ENDPOINT)" - "--endpoint=$(CSI_ENDPOINT)"

View File

@@ -5,6 +5,7 @@ metadata:
name: server-plan name: server-plan
namespace: system-upgrade namespace: system-upgrade
spec: spec:
channel: https://update.k3s.io/v1-release/channels/stable
concurrency: 1 concurrency: 1
cordon: true cordon: true
nodeSelector: nodeSelector:
@@ -16,7 +17,6 @@ spec:
serviceAccountName: system-upgrade serviceAccountName: system-upgrade
upgrade: upgrade:
image: rancher/k3s-upgrade image: rancher/k3s-upgrade
channel: https://update.k3s.io/v1-release/channels/stable
--- ---
# Agent plan # Agent plan
apiVersion: upgrade.cattle.io/v1 apiVersion: upgrade.cattle.io/v1
@@ -25,6 +25,7 @@ metadata:
name: agent-plan name: agent-plan
namespace: system-upgrade namespace: system-upgrade
spec: spec:
channel: https://update.k3s.io/v1-release/channels/stable
concurrency: 1 concurrency: 1
cordon: true cordon: true
nodeSelector: nodeSelector:
@@ -39,4 +40,3 @@ spec:
serviceAccountName: system-upgrade serviceAccountName: system-upgrade
upgrade: upgrade:
image: rancher/k3s-upgrade image: rancher/k3s-upgrade
channel: https://update.k3s.io/v1-release/channels/stable

File diff suppressed because it is too large Load Diff

View File

@@ -264,7 +264,7 @@ spec:
envFrom: envFrom:
- configMapRef: - configMapRef:
name: default-controller-env name: default-controller-env
image: rancher/system-upgrade-controller:v0.16.3 image: rancher/system-upgrade-controller:v0.15.2
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
name: system-upgrade-controller name: system-upgrade-controller
securityContext: securityContext:

View File

@@ -22,6 +22,14 @@ metadata:
labels: labels:
name: monitoring name: monitoring
---
kind: Namespace
apiVersion: v1
metadata:
name: ceph
labels:
name: ceph
--- ---
kind: Namespace kind: Namespace
apiVersion: v1 apiVersion: v1
@@ -29,19 +37,3 @@ metadata:
name: goldilocks name: goldilocks
labels: labels:
name: goldilocks name: goldilocks
---
kind: Namespace
apiVersion: v1
metadata:
name: newt-ns
labels:
name: newt-ns
---
kind: Namespace
apiVersion: v1
metadata:
name: longhorn-system
labels:
name: longhorn-system

View File

@@ -0,0 +1,17 @@
---
apiVersion: bitnami.com/v1alpha1
kind: SealedSecret
metadata:
creationTimestamp: null
name: invidious-app-secrets
namespace: default
spec:
encryptedData:
companion-key: AgAaS5Ktylm7uoZfPI6kUn/XrrmSL69EgT2SdJzMJ20Gh0ChbOrMQhyn10XhLpTCCLYdCtASwiZi5MoUnhbF5qFbJDM7/RQsfnzIZh52ej37ATckgRIe7/WoriAr7ZzFAQrKr80mcHp93DWdV20eBWkBLzZBSzYzl897NOxHsSrReAEPzkO/mfidjxhuov06J8cahPswzPrdeEJOUJDYrliZiduxpWIQH3cCFX9AU2u8rpS3Gl4Qf48VAaxWtDkgAibilnzOp+KFfW7h0Nmva6EkFGGcHK6FrLrtGPDwKAidg9G9szuOJwu1NgowSRq8gHhah6KC5lHJ3xPpmA5txfked2T2IWHVStssZw9Gx5utH4wkX0PZW58oaJp1lwsC42M3UpPPanB0gvDD1l8iC8Szzh5FY+GyshfcVstdxa4rJW5RZ2/kaDDotGWL021ogAzJmVDvLm8HisMwTrOsA1M9EpesW5sKGmiJc9Ce/wGrU+8kutkbyt8j6pFNl1RGRLUPEsoXaVTfKLdv1o/IWdmaZ/8HeBMkL7iDBqTJHLVOkhUYN+zgDmh2iAkINkYtEPRPTV64DsCLBdCRLZp2obtU2vxxw4J6sQF3FQOZYAhg4YywT+ENwWtorplHU0798RqJpId5b6ktp/bQ5H2innFkjrt7wihgYT4ZS8sSr+8EFQi9kY/A88i2cZ5PdBN6zj+28qHKuxb6CYr9DTm3Q5ZJ
hmac-key: AgAv23AhCeIkVAaPuih0yzUM7LY5GRpTrIccZDKgvKW36XLPLAkYnr7SV+S1ADyShyurVvJYl+nOg7hlRpsPldz4PPTas9ahQIrfJHf7JaPauIM1iqG/8UX4Ud2grWSuYz5XBheOIAxlCSFMzK1XgKdMK5Lm/er8ymb9K2KWN35BcnF8lyC/y02uHWhZFJm5CqB2pcJTct1VmNkRt20PHhKKOC/Ruw51CDOYKsrr9HzSNxCO0/d4zhO8F+Q+f3bKHXcQjZbkgkIEE5F0dYfUxpzga/0CqQT1XibYlgBA72GBe06PeIsD9HJIhe03ROsQEAVfLuqMF3vQRNbXdnW9kPVxEbQuXLiitymUPpLE4dRuv7SA3A6Q+bKRlA4+1cTUKquLKNJAerezZkN0e1NJhXQUAAIQbXMFi0c3nMWAr15YtzLmjhEBMmGZoGcMpHOuk/O8uS7opFVHHNrPNxgIsFzfrayTKRcoZJ1LNK8Qkp/5pqlXWNb263da5YS2gv9L90/mB3y1mazxvbFa+b4FjL9b+4dBB2ueiuM8ZbAiCU5o7as0wMJrhoVNq2n66irkIB7Atmv2fCuXiKk6tOrVfH2yNaLI3sOK397up19XJmmX+XHExHlIrEUqZYIx1YSesbNNCrSxfI9WkuRwTORp3JGHeclfbQNpckGGsOn8D/egcrphiqqHB4Rv/sFoscfgjGubv2mLFkVECZwXnhX4dV461bF9lK2nORxflvyRL5/X9nxTI5RLObCu/Vsid7zWXjiSdsxscWyl5rI8/V+7OFDYAJWs4s4yrHIwLgdVnGRWF81j5Z434EOHi8MiGdYOdLNrnQ6KhvsEhVnSAvwMEvdRgfcCmiNp4MyLrLTLkF8MPA==
template:
metadata:
creationTimestamp: null
name: invidious-app-secrets
namespace: default
type: Opaque

View File

@@ -7,9 +7,10 @@ metadata:
namespace: default namespace: default
spec: spec:
encryptedData: encryptedData:
INVIDIOUS_COMPANION_KEY: AgCnfbrG/ji25f6RV/avt613WpOpZNlPsuTP/DU9HULXC1aMM3HzEJR3lIEfeqt9y7iHI7Z4WdD4EqYjdWeDkmLnBLkQB3V7RfPm8tNcfRmMad+Q7bm0viSSq2WhxPtVvtI1G5zoIWs4RGw7F+ee7JqDz8rCKWSHJ0XyuBJUsk3bBLXWNhWtxbaWJz/uxNQoO8ZHV+fa00kqijGcebj9IM6wq4Q7CI5n1NcQqJhJPg1ggOavAiOgcrV5z82PUXDx2tdVbXbynNJfzrTYrU4s0f08rYAT5qF3nXZFtRs4sWEEYCTXZ/E7OdOmWFTsA7af2S1DLE8pkNjzKlVQo/wBV6mvCJcQZtgtLiAKDwnYdoExp8gP9SgL89lyZEa56KtEBAbnU/YBpEQndaFDoLb3mKd1YHn5j4wJXvxinuMEHz9HCANEgDB1NvNGTy443nzzlUzbOiFmMudhBV5wzN9wQ7KNRwVSlU5OlmKO3gBw/gvCAZEKmsHMcDKvUpkKrcDvIMkEA6cCg3Wms8+Le/4EyvRr2VOu+rTXX01/rJ97bcsLGXddJuxc2xvKW6QZEWGtRiK90zkUCaY+PJH1djmjCEb8JIrdGhYy3CMrS3SEVxgPQl0rduAg+z3FtWR4GMttWA7lU1/bPtCIhM+OzgFd/Dy79DuNw4+tbjzEINJUgPpmpYL+1GbsjZ+R48B9pppM+rzKrdfxsOdSvEjTQewn0L14 INVIDIOUS_DB_PASSWORD: AgDZXhcsP5wC5PKnJ0ICfQSx75WYeU+ai2VVAwXL9PSLBkb5b5BQGxFKmXSvuOyJC+VrzoqkTEAhbI8/maHsn3zrE1QFC/7+Yn7ZcvYDO8INzSS9uL6+0NZj0SsOOufgaBtXaniklvL3C/PZ57VYcPNv6lIX9K+WG+8qUnVdKRr0bputl9WHEwMoZXs+l/xYe3jBao62RZ/fVWoMT4dnjNCHCkFsRClsXTxQevfgzfa4xNCDpIWoSewDkX3VaV3AafDDY52t4A2kbsrSL6pVqbeC/VWCKnR0C0x1XuZkQP2fYIsBI//drbHNxTfFSN7mJVZvBJUGNpQsTXGkKLGNFrz/QNjo8kimJfkQPXHbAmAlSB88Z9uFalDIwm/Emh++PEdMA3RuBE6uK/Cmo4M4/UGI6JjLA2DBk1zC9rtVzH6MN6qHDElhlyoMZ6SbGRHtzDrvvmNXDVfJ0KKqhcshBrXyZOIVlCJCs1s91+XOYLG2S0msEk0DIiY6ZhYiPobTPhHSNP8SrFnlMz1nBG+m2+IS+vpquL2l7cOLYAl01q88i3cCobwKtFWmpNiucxLHIbM699Kw8SZ63/jIWpRuNIy6F91GIa0VQzdmAg/AOML4/85bLNXiBlHwO7LlOdDU0kceBLOC1u81CK8mcT8npKjDsHTpuQYpRMHEMFdd53t+qh9JHs/Jo2SU0ZDBwgtSeJYkh50IGzElAErjTA==
INVIDIOUS_DB_PASSWORD: AgA3xb3XXIxHQVbjaZGb6xkWwrr5HSN8B/iF4Kl0EaQyivs7fYqoE3daylu/2x6D0btH/JYWK9+NeyFVNXPCy3holiteD5/9mJFqBCbtkAFxF0lKyLRjtw5BB6Wp5b/HuVJuLQG4sd+TB9XMGDeRyRkXjTRH0NbXYMlcVILAugb3vBNVCcLQqzlHbOngEMOUZxuUcMPL8crOGOmKosTKrWyt2weAFawlXkiz/cwlvdOmgMb8KWI1opEVAKv4OeUQeGRqa9+7fn0CcuM0PLzBvYPa2eoUb4dTFBzZfKpL5/mmZ9NUXEvV1dXN1oBHLHkIS8wBLhHAt8/Mh1rjhd5IGiIWIwlDT2iBuqKLRjwYbVbT7Co8OuTqs7OvxuYVYlmfOZna2o+kF39oeTH/RtYy3atHBsnW6j7GaUJ7nCZfDUZw4xYcHya5v+h2GI76SVnxKhjNpMGjHZMdDUD/cl3rBp+6gHICOYGCi+Wy4EYXCRJkZs0K84AFlLxoDkxARw6eBpFT+QEVnuMDXRrdNqC/Te9p5jzGWvPvXlfCCkQ9hi4hoNmZxw5P/nXdXg1rALiCVZbnM3O/Ud7KwgtYqNSCThPOj/BoExsQE4xSUJzAm35R0/AidOhOTVxztMba5co9Stavj772lRyV5PNbIieXDu6WNdOJNjjiRhuPzQTqbLzRbSa1I+KBDcbkmbOEBuyhXe1EoBp7anoHrKLYyw== INVIDIOUS_HMAC_KEY: AgAI30IJiYq2a+idkc5YIf7VWAdb2cJ3IxkFP5f9vCxy1xzyxyj7fKY6LbaDOg8+NPO0hB2klFixh7KMGS+hFONDKzig82BWG+zqO7n0qnxvLtBNOI7c/zMTKuDtr7pT5tji8yDpazlmJbgrV03Gm2yvpsSNmKYixlHhN976W0OuavfPmQ8iomRnE999G/HOYpTELmPlsakf6rYVv9OVi9uCK8vd7oPrY6ep1aofuuB4olDxPr/rBuZdNMFXMcZzvG05KRAQZ3fwKi4EQBAG15TFHPTEtWIAVtfkzpBBOarDFHFFu+W//CI/1aHWHfUSaOp2IfBZ1csYwDkxtkX5lueh26jSAL54BqqvvfkcpRx/GHKQrM797XvN+uuYCq39kjnk0rAKeeEq1Lbm88Zyrcx9W9qBFGkMdKN1uKAvl3bcMQLF8E6ejub4AsMOwR5kfEmADJs10l2gYT7GPNneyIHkqx1bHAz0tlTPzTd2JPFhvaERc7BU2UhDFT57AxuG2qdwAxkhu1YWcNharcz6+LpUnH5adceJlToWqvIfZkgcYgSqxiHYTyhL/x6FDH4OBpiy1rTPUST+xGZCwyjTlYqM3yqkcUgdDePcFYv3tqORV8oH8riC0RD94FUkujLlWiVtCN7FXoba1ApdyCNmfIRHOO4Os9g8H7oxUeTDlUWERsWVgCXtv0H65Tb+EMjaRtIROFCCnrC3qFzybyW1OX06
INVIDIOUS_HMAC_KEY: AgBqsFM5UcFmJQwCPG/xl6ZZus6u/uIlJtxsQGR1p+kWcI1DOfCqLCURxku7yuEi82HizZYDSrQ1X8rLtuBVJmCvCsgWclC+3N1zpUCBhbzzPSSa/U66D7LdDpYAgfMDpkiRMXFOZBGCZtYL7I5Wgp2vxYpjsWVXdk5GXFWbR8Dw5ndUROd2+LmrtJxaWeLiEY7OKHPZ8csEwGibIvQlyBsqPON0jKG70nes1oMFmy1TgmdYpRuW5ZwBCFu1ChpL+Ital1IR8TbSW6K2nXdpku+J+WE9CT4nFQLH/NhWsRw8MWPBp2IGnAr+/iIJJYqbfUGIzMnMpvKZW6Xna/mEBJ826WoCbs1CsUAtemmsIyDzO3tANvNEOr8UWpKm7a62HN8Y3HOiduOoonrRVCS9c8jjt1M20z8JQD06fY6ymsOXEYaYkWesO2WieJtT/6qbJlkwx9RJrdMz7mlWcN5edilkF8X3TSw4YpHP7LhofliGjBYx/w2cWWCkWN1QJhbXt2CmYKxhHnAJS/S5Lmmxs3nNpF1mVOCjTIDFXmR86wG5gJEYS7PHw1ZlMUaOeU/uG0E4caGWwJfn3/Z3upZkuuu5oFy/nDodHD+V6YKHQTQ3dWdjTXJ1kW8vLRb3Roii7dxhXW0dFhdBjyX3P6+58PAkdiZzF89naVLW8x7niFrqW5fQ5M06W/PTQQKIO37bM7L/oy/9a3XQmM8dQeTt9d9g PO_TOKEN: AgAbSZdJpITThH2TxcsvrbrGls8mWuADdRmoR3XP46nr4DWyujaOMsdWr1gV+YM8HgzRx/voZeNZqouh7rnY4dHoFLIJ4vxR7r7hIXyVY+GinUd8R73/NUNgnoI99zd4HqGD+y2HYmoKjKpriOvnYI+arOtcSuQyQB3R/vY9bcoM54oXIc3dQaXKku2+t/cEoZcyZRoeGgk+M73CIhoP9lBLgEq3VIKAcgfnKwgTxTJC4hLYukHa33TriVvVh/8QrNGXpMtclBgYkj5XVpbbh8YeTjS56VqDUO1LWS41UzPc1GjsHINjWMw29GDjLKnlWmpHwWXzXWzy07vgr73aHxE2tLEvQI06GW71HodG0MVG9jS7la4fISzB4r1+eRwYf7aBtw1x+GiB4oMW/3wp5U04iFUiySc+4M7dnfe02yy98MzNLtrbSYUjmKKcBkYWsPtqtQg8CR0RRHa8dGWFSwtFWeMycag18DEDbgwxD6ozFwTuYjCQGflilQahfHxCb3WuQeWeftUk/1N4Pg4aYoL6MMkls+DZyO3/0BtVqldHc2RUHtqnrNZ4mA4ymKbcvBPHe/njjIapfmV6Se/BHC6uYwflRXhXU08ovhiOVJBQM7azku5CCodTENd4cCZYpcQ2F4sJ0blwbt40b/2p1oX3b2lRW47TEWUCIu9RdGRLhyCjKigPGLcZ+Jx+66zp+/vas72pWG0iXYy4ppDP/R1FYz4kTC80VNlBHLcAcP9kd2nwBnowDPNUZLAQgC28mJRGvFFF5qgGCnRWn2oj7iOrBt5Bcv+/WgbIYWk9qzVetiElXS61Xu0lOfduid5fWVltn0Ys02j46Ewh71ojYIAbsVAatkbQwV45ikHIwkXOWq+t7M/nHQaFb25t7KWYVjT/FDZTql7BtRKYJX9OD/TQ
VISITOR_DATA: AgA+ERW9tbeo2/6DgV9RG3rOzqME6vz3UXS23TNwjra0dOr8W3gP6Atl7KR1vblwAFXozl6tCtqugBbq1hCdwKx79lwWIaI5DtpwEaGJQe32i+bGM/cDcI/PmqJK9FYDp9gX+G1ldKgAUi9F6MRQ73ze7gG0jFD3q3rwads+kjI0+UI+JwBsOD72YIkgm2a3j4ZRhJOPrd5XZPSNMgbRU5ZZ0I0VjztxpM4iRyeW+Caxo1ltOZijZbLy10fQAf2P/pM2kfXrfuPqlVgCOTuiU9FcuBuL5hSPZqw6QB+ZrQukM7I5KlzhMH7Zfw5DEj4tb+eT9f9/nr3CR3tDTzVJkXo9FVZ1qKvDu6tIZrWD7g5wYcZZWe2Ll/1DFpteDuKE1ry8wgTDdK52mNCVzC5/jYIhR54bfllzY9deZ33Ux75I/l9OHFvEzLrWuhCf9+iL8EW7/a7bTGSiYZXkyiXd+sSsyjmqK3xzqb9MkTE0VmNNKrG8PbdjlfrJQAs8PmX8S1yEcqexBjp7UWND50TwX5zANAqeQMnInaVlB6dXzQSCTeOGnGZOi0oKJ/eH3YbmbKErbqISm18wMbFzU/I3nDR0PFMt5ryRFhgMcIPnBv9kIc6TLY7DLcHHGEEYNjQYRLR3uWCTJeI0fSVnZqxvc+5iCqmPfgWA2TDKTck5FSCwSj3rxIPbEVTlujf+JEapiwAE/OVr08mZ725kvHoTkj43/JStqtZ3nLg5ZxO05Qv7cp96ToK7bS4wUP9ZdWh+pb4=
template: template:
metadata: metadata:
creationTimestamp: null creationTimestamp: null

File diff suppressed because it is too large Load Diff

View File

@@ -9,7 +9,7 @@ spec:
chart: chart:
spec: spec:
chart: cert-manager chart: cert-manager
version: "v1.19.0" version: "v1.18.2"
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: jetstack name: jetstack

View File

@@ -9,7 +9,7 @@ spec:
chart: chart:
spec: spec:
chart: csi-driver-smb chart: csi-driver-smb
version: "1.19.1" version: "1.18.0"
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: csi-driver-smb name: csi-driver-smb

View File

@@ -9,7 +9,7 @@ spec:
chart: chart:
spec: spec:
chart: gpu-operator chart: gpu-operator
version: "v25.3.4" version: "v25.3.2"
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: nvidia name: nvidia

View File

@@ -1,23 +0,0 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: device-plugin-operator
namespace: gpu-operator
spec:
interval: 24h
chart:
spec:
chart: intel-device-plugins-operator
version: "0.34.0"
sourceRef:
kind: HelmRepository
name: intel
namespace: flux-system
interval: 24h
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3

View File

@@ -1,27 +0,0 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: gpu-device-plugin
namespace: gpu-operator
spec:
interval: 24h
chart:
spec:
chart: intel-device-plugins-gpu
version: "0.34.0"
sourceRef:
kind: HelmRepository
name: intel
namespace: flux-system
interval: 24h
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
sharedDevNum: 4
nodeSelector:
intel.feature.node.kubernetes.io/gpu: 'true'

View File

@@ -1,9 +0,0 @@
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: intel
namespace: flux-system
spec:
interval: 24h
url: https://intel.github.io/helm-charts

View File

@@ -1,16 +0,0 @@
---
apiVersion: bitnami.com/v1alpha1
kind: SealedSecret
metadata:
name: newt-cred
namespace: newt-ns
spec:
encryptedData:
NEWT_ID: AgANlHH+ezjEX2Vlu5VgJF0XVqQopfthSt1J1lRSIrB6gHooRKa/Nx55ZZwwJiOzgLz5Rm1XLL2AO9lP+r9gxkPp0QO6gBOciIT5JjF7KPYGd8Mz7JM3YvQmrmQVe5gwltoLcpNgNkOcqf2i4BvLKrsEfLzfYci6nH3paWaopi5pWdzSKmyfJfSL1LtftBBbWMZ4GYq54KiQM8+vrxH8QqnhKrASnd+zQ1Yb1NA0RiraSom8OZiStyvNo4F82bRyZWIBgp7O23gUXH4+Zf5ZbiH1hMiZZOwQfc+sRp3E9b3x5AZAMeWv6RSuRbfX/yODY2mwptAM5sAAaKAwnf53pUA9pqYN0/taAUrEQLd6TNw1nRAuxdZwsKCt/FnWkEo0WtVkiUeciNQMVrlCvQ6YvKU3+1fYYYSMuwpP4gBbjgLmeY+gQVcBwKi8eRHAxaRuhqBP22wdVozlKcA9UysRNu0VcnB5sAsxxpHwWMQgwJ7DvayMgX10tdnXDtBCYGNOeKuDnJWbkAEHAOLguYW8VsZSXB1a+1SQe/MVnTAPKTgqKwbD8Tf2pDOg11z/WwpRXLgRyahmxJt+li2vEE7PVjyVFF1ZN81TYlnlOiGkMSYB5bHT2zcQZ2hxa4J1QBzl3J1kAydyrCQZNvkzQ0vrtKSt6k8cAlsr61b4zPhX7IrSGjQw3zRjnAMAJc2zvDu2FB53641hZknoO2HsAZbqDXw=
NEWT_SECRET: AgAffzmD9CZCn4P3GNC0sT3h86iPpzvMvmELZpqUOfWsMgPq6cY/HSfd927ShxPEDZXrd1FLDu+tH9Ealk2duhkq0YEanaMu5j5x8/GiSctRdhtD6H8t4uONRXQjKWG2HaySz7oR+GcO8/EM6rEcki17HhI7px+dzLm7HowcBMvw2ne+RqthmdOlVvxeIzLejnWIrzY2wcuieK7r3zq+d3unZi9T7GbevmzCA5V3wQrWqvsNezHHj0BIJlIYn3Vzx5ZZN6pgUT8x0y8TteC+FtHDKgODHgtT2ZYkK+LR3wtCXgO1Y6NILr2Ijg96aeL8/TYY3e5T8q4cKr1HabYjfenCjigzuqS27m9u2wCI8Zv6ffWjEYUED4GQ8oXqMyE44pYrzzb+Do3V3Ezj6PMDEvtQaWJ78JvQaOdHnszXMXpAsIsKhgeo7WdiIJWBnFW9lYhC3OdxuW2yNi5lv9z/oJEB+13pmVHkTzYHqhollz1AAY5nna5+JHNNFbRfbj8pj7I07qjOj291e2jZ+p9LBkip5xNfVOeSoX8YOwn8aZTaZPKvPgSZFvFS54JlcO8KWIeqGOc2CKO0r+6GaysO+6LxHH8WGdxxh9JLlNZdcnunQ9Cxlh1vPTuxG7zhEu4KiWwL/5KAQf9Ksyd33WdgR4qNQGnfXccomGRD4fxral6K8jDJjDJlCUQcbYAl2n+eMu377YWkhW0ecMLgYiLzkyNdZO5HnuoNqHr+HsUD+4g7UNtb8cwFhj6uaX+6RXlBS/U=
PANGOLIN_ENDPOINT: AgCkSy8lFTJZJT0luEKhfSOMO9aeSsUvmxaLXc9+nDHmlDoWBv15q7uEsutXDr8OPuM9sl7g6KLfYFTlaPO502Wrw/FV6ncX6es/KfguEydAebdl3uZ096FcwaTGtcpd/mdo4W8z2348EnttoxeJ23tZWabZcYfyVu/UA4Sor05hpnYdTxK3mYra89dhb/u4Pz5BdQUKlseCIWiLqk7HON0nI775ANq8OJ6MZeMSZoAdjOdy24hw3SSwwpX1Y1p6Ior5UV9tiCXpbL5UVj6Wo4LIGkqBRomPQ3V6Furim5bhfLDNDYTFVqWo0UEa6eYwP6NgPZ+oxfI1pFdio1g39+iY9AHlJoYRDkYF0wJLjfGdnju4L+KXsdWiyQVXS7lX+GAohna3p3xSaOrFzYt3SxEQ9lGvUFrXIXB5UrBrN1iODpbRyJb6KdXNZM9SklKKycZ9WCfLzhWV1ppwReQrICR4JljngSMWuBGxjr90BlkvMSQVOFGrHSs9AeY/ymf6P1TQ8WwecivTZ3oK8x+NIqdJSXRr2HEZkNOfJH4hDcD9NLO/7Wt/bkp4sX8Bvs2MrZ466hHovm2ENC9Cz/LHZLpHHtidmBn4hgrT39Cjgbq6bPR2SBSQnoXB/FVA9zuqJ6E+Z69O3pdXtxTEIZAvtJ4BaEiOkzQzonScowNwklnkEaru/TSx50rNjfW2k2CNx/Tz7XZf4vEudRbxc1nzXxzkMnQyldheczPjnWvcTgI=
template:
metadata:
name: newt-cred
namespace: newt-ns
type: Opaque

View File

@@ -1,29 +0,0 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: newt
namespace: newt-ns
spec:
interval: 24h
chart:
spec:
chart: newt
version: "1.1.0"
sourceRef:
kind: HelmRepository
name: newt
namespace: flux-system
interval: 24h
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
newtInstances:
- name: main
enabled: true
auth:
existingSecretName: newt-cred

View File

@@ -1,9 +0,0 @@
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: newt
namespace: flux-system
spec:
interval: 24h
url: https://charts.fossorial.io

View File

@@ -2,7 +2,7 @@
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: metadata:
name: ollama-longhorn name: ollama-ceph
namespace: default namespace: default
spec: spec:
accessModes: accessModes:
@@ -10,5 +10,5 @@ spec:
volumeMode: Filesystem volumeMode: Filesystem
resources: resources:
requests: requests:
storage: 6Gi storage: 20Gi
storageClassName: longhorn storageClassName: csi-rbd-sc

View File

@@ -9,7 +9,7 @@ spec:
chart: chart:
spec: spec:
chart: ollama chart: ollama
version: "1.31.0" version: "1.28.0"
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: ollama name: ollama
@@ -37,4 +37,4 @@ spec:
runtimeClassName: nvidia runtimeClassName: nvidia
persistentVolume: persistentVolume:
enabled: true enabled: true
existingClaim: ollama-longhorn existingClaim: ollama-ceph

View File

@@ -9,7 +9,7 @@ spec:
chart: chart:
spec: spec:
chart: longhorn chart: longhorn
version: "1.10.0" version: "1.9.1"
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: longhorn name: longhorn
@@ -22,10 +22,11 @@ spec:
remediateLastFailure: true remediateLastFailure: true
values: values:
persistence: persistence:
defaultClass: false defaultClass: true
reclaimPolicy: Retain reclaimPolicy: Retain
ingress: ingress:
enabled: false enabled: false
service: service:
ui: ui:
type: ClusterIP type: LoadBalancer
nodePort: 85

View File

@@ -9,7 +9,7 @@ spec:
chart: chart:
spec: spec:
chart: prometheus chart: prometheus
version: "27.40.1" version: "27.35.0"
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: prometheus-community name: prometheus-community

26
drone.yml Normal file
View File

@@ -0,0 +1,26 @@
---
kind: pipeline
type: kubernetes
name: renovate
trigger:
event:
- cron
- custom
environment:
LOG_LEVEL: info
steps:
- name: renovate
privileged: true
image: renovate/renovate:41.97.7
commands:
- unset GIT_COMMITTER_NAME GIT_COMMITTER_EMAIL GIT_AUTHOR_NAME GIT_AUTHOR_EMAIL
- renovate
environment:
RENOVATE_TOKEN:
from_secret: RENOVATE_TOKEN
GITHUB_COM_TOKEN:
from_secret: GITHUB_COM_TOKEN