diff --git a/k8s/OPERATIONS.md b/k8s/OPERATIONS.md index 54cac9a6..a4b36d45 100644 --- a/k8s/OPERATIONS.md +++ b/k8s/OPERATIONS.md @@ -70,16 +70,16 @@ the three moved services. ## Service inventory -This table is maintained with the HelmRelease files. `local-path` means +This table is maintained with the Flux workload declarations. `local-path` means node-local or host-mounted data and must be recovered on its owning node. -| Release | Chart | Namespace | URL | Dependencies | Persistence | Backup / restore owner | Data-loss expectation | +| Release | Delivery | Namespace | URL | Dependencies | Persistence | Backup / restore owner | Data-loss expectation | | ---------------- | ------------ | ----------- | ---------------------------- | ---------------------------------- | ---------------------------------------------- | ------------------------------ | --------------------------------------- | -| aly-codes | aly-codes | websites | https://aly.codes | — | none | Git/site build | rebuildable | -| collabora | collabora | default | https://collabora.cute.haus | nextcloud | none | configuration only | rebuildable | -| error-pages | error-pages | default | internal | traefik | none | Git | rebuildable | +| aly-codes | Kustomize | websites | https://aly.codes | — | none | Git/site build | rebuildable | +| collabora | Kustomize | default | https://collabora.cute.haus | nextcloud | none | configuration only | rebuildable | +| error-pages | Kustomize | default | internal | traefik | none | Git | rebuildable | | forward-auth | forward-auth | identity | internal | Pocket ID | SOPS secret | SOPS / identity operator | reconfigure clients | -| gotenberg | gotenberg | platform | internal | — | none | Git | rebuildable | +| gotenberg | Kustomize | platform | internal | — | none | Git | rebuildable | | immich | immich | default | https://immich.cute.haus | valkey | local-path uploads/ML cache, Longhorn database | node owner / Immich export | photo loss possible without node data | | morsels | morsels | websites | https://morsels.blue | — | Longhorn | Longhorn backup owner | restore from volume backup | | navidrome | navidrome | default | https://navidrome.cute.haus | forward-auth | Longhorn config, host media | Longhorn / media host owner | media is external; config may be lost | @@ -88,17 +88,17 @@ node-local or host-mounted data and must be recovered on its owning node. | paperless | paperless | default | https://paperless.cute.haus | pg-shared, valkey, tika, gotenberg | local-path data | node owner / CNPG backup owner | documents may be lost without node data | | pg-shared | pg-shared | cnpg-system | internal | CNPG | Longhorn database volumes, B2 backups | CNPG backup owner | point-in-time limited to backups | | plex | plex | default | https://plex.cute.haus | media host | local-path config and media mounts | node/media owner | config or metadata loss possible | -| pocket-id | pocket-id | default | https://id.cute.haus | pg-shared | CNPG | CNPG backup owner | identity records depend on DB backup | +| pocket-id | Kustomize | default | https://id.cute.haus | pg-shared | CNPG | CNPG backup owner | identity records depend on DB backup | | seerr | seerr | default | https://seerr.cute.haus | pg-shared | Longhorn config, CNPG | Longhorn / CNPG backup owner | restore app config and DB | -| slingshot | slingshot | microcosm | https://slingshot.cute.haus | — | ephemeral cache | Git | rebuildable | -| switchyard | switchyard | websites | https://switchyard.aly.codes | — | none | Git/site build | rebuildable | -| tika | tika | platform | internal | — | none | Git | rebuildable | -| tranquil-pds | tranquil-pds | default | https://pds.cute.haus | pg-shared, valkey | CNPG, B2 repository data | CNPG/B2 owner | account data loss without backups | +| slingshot | Kustomize | microcosm | https://slingshot.cute.haus | — | ephemeral cache | Git | rebuildable | +| switchyard | Kustomize | websites | https://switchyard.aly.codes | — | none | Git/site build | rebuildable | +| tika | Kustomize | platform | internal | — | none | Git | rebuildable | +| tranquil-pds | Kustomize | default | https://pds.cute.haus | pg-shared, valkey | CNPG, B2 repository data | CNPG/B2 owner | account data loss without backups | | uptime-kuma | uptime-kuma | default | https://kuma.cute.haus | — | Longhorn | Longhorn backup owner | monitor history/config loss possible | | vaultwarden | vaultwarden | default | https://vault.cute.haus | — | Longhorn | Longhorn backup owner | vault loss is critical | | valkey | valkey | default | internal | — | Longhorn | Longhorn backup owner | cache/session loss tolerated | | valkey-nextcloud | valkey | nextcloud | internal | — | Longhorn | Longhorn backup owner | cache/session loss tolerated | -| watsup | watsup | websites | https://cute.haus | — | ConfigMap | Git | rebuildable | +| watsup | Kustomize | websites | https://cute.haus | — | ConfigMap | Git | rebuildable | ## Stateful recovery diff --git a/k8s/charts/README.md b/k8s/charts/README.md index ae1a6253..2013d21f 100644 --- a/k8s/charts/README.md +++ b/k8s/charts/README.md @@ -1,22 +1,21 @@ # Charts In-tree Helm charts deployed by Flux HelmReleases under [`../flux`](../flux). +Small hand-authored workloads live as raw Kustomize manifests in their Flux +layer instead of as charts. -Most app charts use explicit Kubernetes manifests. Helm is used for light -substitution, mostly `.Chart.Name` and shared non-secret values passed by Flux. -Avoid shared Deployment/Service/PVC helpers; app-specific behavior should stay -visible in the app chart. +Helm is reserved for upstream packages, reusable releases, and charts that +need data-driven rendering. Avoid shared Deployment/Service/PVC helpers; +app-specific behavior should stay visible in direct manifests. ## Layout ```text charts/ -├── aly-codes/ # Static site (aly.codes) -├── tranquil-pds/ # Reference atproto Personal Data Server ├── cert-manager-issuers/ # Let's Encrypt ClusterIssuer + wildcard Certificates ├── external-routes/ # Ingress + Service + EndpointSlice for off-cluster targets ├── forward-auth/ # Per-app traefik-forward-auth frontends -├── immich/ # Photo library + ML + app-specific Postgres +├── immich/ # Photo library + app-specific Postgres ├── longhorn-creds/ # B2 backup Secret + recurring backup job + UI ingress ├── paperless/ # Document management with rclone media mount ├── pg-shared/ # CloudNativePG cluster using local-path replicas @@ -26,6 +25,17 @@ charts/ Undeployed charts live in [`../drafts`](../drafts), outside the Flux chart inventory. See its README before promoting a draft to production. +## Workload Styles + +Use raw Kustomize manifests for fixed, hand-authored workloads. Their files +live beside the Flux layer that applies them, for example +`../flux/apps/aly-codes/` or `../flux/platform/tika/`. Each directory has a +small `kustomization.yaml` that sets its namespace and lists its resources. + +Use Helm only when release reuse or structured rendering is meaningful. The +remaining local Helm charts are data-driven or stateful; they are not generic +wrappers around otherwise static YAML. + ## Chart Style Prefer direct manifests: @@ -91,20 +101,16 @@ Avoid these: Charts fall into three readability tiers: -- **Explicit application charts** keep app-specific resources visible in - separate templates. Most of these only substitute names and the shared - failover toleration; that small amount of templating is intentional. - **Configurable application charts** such as Plex, Valkey, Paperless, Nextcloud, and Immich render meaningful values that affect the workload. - **Data-driven charts** render repeated resources from structured values: `forward-auth`, `external-routes`, `pg-shared`, and `cert-manager-issuers`. -Do not move charts into namespace- or tier-named directories. The HelmRelease -is the deployment boundary, and a chart can be reused by multiple releases -(for example, the two Valkey releases). Keep fixed resource names readable, -but retain templating when it expresses release namespace, shared policy, or -real repetition. +Do not move Helm charts into namespace-named directories. The HelmRelease is +the deployment boundary, and a chart can be reused by multiple releases (for +example, the two Valkey releases). Fixed hand-authored workloads belong in +their Flux layer as raw manifests instead. ## Data-Driven Exceptions diff --git a/k8s/charts/aly-codes/Chart.yaml b/k8s/charts/aly-codes/Chart.yaml deleted file mode 100644 index 330b2474..00000000 --- a/k8s/charts/aly-codes/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: aly-codes -description: Static site for aly.codes -type: application -version: 0.1.0 diff --git a/k8s/charts/collabora/Chart.yaml b/k8s/charts/collabora/Chart.yaml deleted file mode 100644 index 508068fb..00000000 --- a/k8s/charts/collabora/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: collabora -description: Collabora Online (CODE) document server for Nextcloud Office -type: application -version: 0.1.0 diff --git a/k8s/charts/error-pages/Chart.yaml b/k8s/charts/error-pages/Chart.yaml deleted file mode 100644 index 255bb32d..00000000 --- a/k8s/charts/error-pages/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: error-pages -description: Custom error pages served by Traefik on 5xx responses -type: application -version: 0.1.0 diff --git a/k8s/charts/gotenberg/Chart.yaml b/k8s/charts/gotenberg/Chart.yaml deleted file mode 100644 index b4566b14..00000000 --- a/k8s/charts/gotenberg/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: gotenberg -description: Gotenberg document-to-PDF conversion service -type: application -version: 0.1.0 diff --git a/k8s/charts/pocket-id/Chart.yaml b/k8s/charts/pocket-id/Chart.yaml deleted file mode 100644 index 5590f98a..00000000 --- a/k8s/charts/pocket-id/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: pocket-id -description: Pocket ID passkey-only OIDC provider -type: application -version: 0.1.0 diff --git a/k8s/charts/slingshot/Chart.yaml b/k8s/charts/slingshot/Chart.yaml deleted file mode 100644 index 250b7206..00000000 --- a/k8s/charts/slingshot/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: slingshot -description: Slingshot (atproto record edge cache, microcosm-rs) -type: application -version: 0.1.0 diff --git a/k8s/charts/switchyard/Chart.yaml b/k8s/charts/switchyard/Chart.yaml deleted file mode 100644 index 2fbdab99..00000000 --- a/k8s/charts/switchyard/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: switchyard -description: Switchyard marketing site (switchyard.aly.codes) -type: application -version: 0.1.0 diff --git a/k8s/charts/tika/Chart.yaml b/k8s/charts/tika/Chart.yaml deleted file mode 100644 index 9403fc55..00000000 --- a/k8s/charts/tika/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: tika -description: Apache Tika document parsing and OCR service -type: application -version: 0.1.0 diff --git a/k8s/charts/tranquil-pds/Chart.yaml b/k8s/charts/tranquil-pds/Chart.yaml deleted file mode 100644 index 1b6d3f64..00000000 --- a/k8s/charts/tranquil-pds/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: tranquil-pds -description: Tranquil PDS (atproto Personal Data Server, postgres-backed) -type: application -version: 0.1.0 diff --git a/k8s/charts/watsup/Chart.yaml b/k8s/charts/watsup/Chart.yaml deleted file mode 100644 index 0d7a0f97..00000000 --- a/k8s/charts/watsup/Chart.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v2 -name: watsup -description: Watsup dashboard -type: application -version: 0.1.0 diff --git a/k8s/charts/watsup/config.toml b/k8s/charts/watsup/config.toml deleted file mode 100644 index 469b8ae6..00000000 --- a/k8s/charts/watsup/config.toml +++ /dev/null @@ -1,124 +0,0 @@ -title = "watsup" - -[[sections]] -type = "widgets" -columns = 4 - -[[sections.widgets]] -type = "weather" - -[[sections.widgets]] -type = "search" -span = 3 - -[[sections]] -type = "widgets" -columns = 2 - -[[sections.widgets]] -type = "lobsters" -title = "Lobsters" - -[[sections.widgets]] -type = "hacker-news" -title = "Hacker News" - -[[sections]] -type = "services" -title = "Atmosphere Apps+Infra" -columns = 3 - -[[sections.services]] -name = "atbbs" -url = "https://atbbs.xyz/" - -[[sections.services]] -name = "morsels.blue" -url = "https://morsels.blue/" - -[[sections.services]] -name = "haunt.at" -url = "https://haunt.at/" - -[[sections.services]] -name = "snarled.at" -url = "https://snarled.at/" - -[[sections.services]] -name = "aly.social" -url = "https://pds.cute.haus" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/bluesky.png" - -[[sections.services]] -name = "slingshot" -url = "https://slingshot.cute.haus" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/bluesky.png" - -[[sections]] -type = "services" -title = "Webpages" -columns = 3 - -[[sections.services]] -name = "Aly Raffauf" -url = "https://aly.codes/" - -[[sections.services]] -name = "Switchyard" -url = "https://switchyard.aly.codes/" - -[[sections.services]] -name = "Morgan Tamayo" -url = "https://morgantamayo.com/" - -[[sections]] -type = "services" -title = "Apps" -columns = 4 - -[[sections.services]] -name = "Pocket ID" -url = "https://id.cute.haus/" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/pocket-id.png" - -[[sections.services]] -name = "Plex" -url = "https://plex.cute.haus/" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/plex.png" - -[[sections.services]] -name = "Ombi" -url = "https://ombi.cute.haus/" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/ombi.png" - -[[sections.services]] -name = "Immich" -url = "https://immich.cute.haus/" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/immich.png" - -[[sections.services]] -name = "Navidrome" -url = "https://navidrome.cute.haus" -healthUrl = "http://navidrome.default.svc.cluster.local/" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/navidrome.png" - -[[sections.services]] -name = "Paperless" -url = "https://paperless.cute.haus" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/paperless-ngx.png" - -[[sections.services]] -name = "Vaultwarden" -url = "https://vault.cute.haus/" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/vaultwarden.png" - -[[sections.services]] -name = "Uptime Kuma" -url = "https://kuma.cute.haus/" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/uptime-kuma.png" - -[[sections.services]] -name = "Grafana" -url = "https://grafana.narwhal-snapper.ts.net/" -healthUrl = "http://10.254.0.4:3010/api/health" -icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/grafana.png" diff --git a/k8s/charts/watsup/templates/configmap.yaml b/k8s/charts/watsup/templates/configmap.yaml deleted file mode 100644 index 718fc492..00000000 --- a/k8s/charts/watsup/templates/configmap.yaml +++ /dev/null @@ -1,11 +0,0 @@ -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ .Chart.Name }}-config - annotations: - helm.sh/resource-policy: keep - labels: - app: {{ .Chart.Name }} -data: - watsup.toml: | -{{ .Files.Get "config.toml" | indent 4 }} diff --git a/k8s/flux/apps/aly-codes.yaml b/k8s/flux/apps/aly-codes.yaml deleted file mode 100644 index fc4e0635..00000000 --- a/k8s/flux/apps/aly-codes.yaml +++ /dev/null @@ -1,28 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: aly-codes - namespace: flux-system -spec: - interval: 15m - releaseName: aly-codes - targetNamespace: websites - install: - remediation: - retries: 3 - upgrade: - remediation: - retries: 3 - chart: - spec: - chart: ./k8s/charts/aly-codes - interval: 15m - reconcileStrategy: Revision - sourceRef: - kind: GitRepository - name: flux-system - namespace: flux-system - valuesFrom: - - kind: ConfigMap - name: cute-haus-global - valuesKey: values.yaml diff --git a/k8s/charts/aly-codes/templates/deployment.yaml b/k8s/flux/apps/aly-codes/deployment.yaml similarity index 91% rename from k8s/charts/aly-codes/templates/deployment.yaml rename to k8s/flux/apps/aly-codes/deployment.yaml index c6f81faf..b8b4ce71 100644 --- a/k8s/charts/aly-codes/templates/deployment.yaml +++ b/k8s/flux/apps/aly-codes/deployment.yaml @@ -25,11 +25,11 @@ spec: - key: node.kubernetes.io/not-ready operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 - key: node.kubernetes.io/unreachable operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 topologySpreadConstraints: - maxSkew: 1 topologyKey: topology.kubernetes.io/zone diff --git a/k8s/charts/aly-codes/templates/ingress.yaml b/k8s/flux/apps/aly-codes/ingress.yaml similarity index 100% rename from k8s/charts/aly-codes/templates/ingress.yaml rename to k8s/flux/apps/aly-codes/ingress.yaml diff --git a/k8s/flux/apps/aly-codes/kustomization.yaml b/k8s/flux/apps/aly-codes/kustomization.yaml new file mode 100644 index 00000000..943868e2 --- /dev/null +++ b/k8s/flux/apps/aly-codes/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: websites +resources: + - deployment.yaml + - ingress.yaml + - pdb.yaml + - service.yaml diff --git a/k8s/charts/aly-codes/templates/pdb.yaml b/k8s/flux/apps/aly-codes/pdb.yaml similarity index 100% rename from k8s/charts/aly-codes/templates/pdb.yaml rename to k8s/flux/apps/aly-codes/pdb.yaml diff --git a/k8s/charts/aly-codes/templates/service.yaml b/k8s/flux/apps/aly-codes/service.yaml similarity index 100% rename from k8s/charts/aly-codes/templates/service.yaml rename to k8s/flux/apps/aly-codes/service.yaml diff --git a/k8s/flux/apps/collabora.yaml b/k8s/flux/apps/collabora.yaml deleted file mode 100644 index be80650c..00000000 --- a/k8s/flux/apps/collabora.yaml +++ /dev/null @@ -1,22 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: collabora - namespace: flux-system -spec: - interval: 15m - releaseName: collabora - targetNamespace: default - install: - remediation: { retries: 3 } - upgrade: - remediation: { retries: 3 } - chart: - spec: - chart: ./k8s/charts/collabora - interval: 15m - reconcileStrategy: Revision - sourceRef: - { kind: GitRepository, name: flux-system, namespace: flux-system } - valuesFrom: - - { kind: ConfigMap, name: cute-haus-global, valuesKey: values.yaml } diff --git a/k8s/charts/collabora/templates/deployment.yaml b/k8s/flux/apps/collabora/deployment.yaml similarity index 92% rename from k8s/charts/collabora/templates/deployment.yaml rename to k8s/flux/apps/collabora/deployment.yaml index b51330a4..9aa8ee53 100644 --- a/k8s/charts/collabora/templates/deployment.yaml +++ b/k8s/flux/apps/collabora/deployment.yaml @@ -28,11 +28,11 @@ spec: - key: node.kubernetes.io/not-ready operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 - key: node.kubernetes.io/unreachable operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 containers: - name: collabora image: docker.io/collabora/code:latest@sha256:1f864ce3f0c49e867787b6dd303bd6ba989542d3023f6809df558eafd04c1b97 diff --git a/k8s/charts/collabora/templates/ingress.yaml b/k8s/flux/apps/collabora/ingress.yaml similarity index 100% rename from k8s/charts/collabora/templates/ingress.yaml rename to k8s/flux/apps/collabora/ingress.yaml diff --git a/k8s/flux/apps/collabora/kustomization.yaml b/k8s/flux/apps/collabora/kustomization.yaml new file mode 100644 index 00000000..90c3c573 --- /dev/null +++ b/k8s/flux/apps/collabora/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: default +resources: + - deployment.yaml + - ingress.yaml + - service.yaml diff --git a/k8s/charts/collabora/templates/service.yaml b/k8s/flux/apps/collabora/service.yaml similarity index 100% rename from k8s/charts/collabora/templates/service.yaml rename to k8s/flux/apps/collabora/service.yaml diff --git a/k8s/flux/apps/error-pages.yaml b/k8s/flux/apps/error-pages.yaml deleted file mode 100644 index 390152cf..00000000 --- a/k8s/flux/apps/error-pages.yaml +++ /dev/null @@ -1,20 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: error-pages - namespace: flux-system -spec: - interval: 15m - releaseName: error-pages - targetNamespace: default - install: { remediation: { retries: 3 } } - upgrade: { remediation: { retries: 3 } } - chart: - spec: - chart: ./k8s/charts/error-pages - interval: 15m - reconcileStrategy: Revision - sourceRef: - { kind: GitRepository, name: flux-system, namespace: flux-system } - valuesFrom: - - { kind: ConfigMap, name: cute-haus-global, valuesKey: values.yaml } diff --git a/k8s/charts/error-pages/templates/deployment.yaml b/k8s/flux/apps/error-pages/deployment.yaml similarity index 89% rename from k8s/charts/error-pages/templates/deployment.yaml rename to k8s/flux/apps/error-pages/deployment.yaml index aa9b43b4..68da76cc 100644 --- a/k8s/charts/error-pages/templates/deployment.yaml +++ b/k8s/flux/apps/error-pages/deployment.yaml @@ -25,11 +25,11 @@ spec: - key: node.kubernetes.io/not-ready operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 - key: node.kubernetes.io/unreachable operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 containers: - name: error-pages image: ghcr.io/tarampampam/error-pages:4@sha256:f23f8042a2804669315fd232281d0ccecf1959332314a46e02ca2482064064a6 diff --git a/k8s/flux/apps/error-pages/kustomization.yaml b/k8s/flux/apps/error-pages/kustomization.yaml new file mode 100644 index 00000000..d4001524 --- /dev/null +++ b/k8s/flux/apps/error-pages/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: default +resources: + - deployment.yaml + - middleware.yaml + - service.yaml diff --git a/k8s/charts/error-pages/templates/middleware.yaml b/k8s/flux/apps/error-pages/middleware.yaml similarity index 100% rename from k8s/charts/error-pages/templates/middleware.yaml rename to k8s/flux/apps/error-pages/middleware.yaml diff --git a/k8s/charts/error-pages/templates/service.yaml b/k8s/flux/apps/error-pages/service.yaml similarity index 100% rename from k8s/charts/error-pages/templates/service.yaml rename to k8s/flux/apps/error-pages/service.yaml diff --git a/k8s/flux/apps/kustomization.yaml b/k8s/flux/apps/kustomization.yaml index e70a9d94..ea9bfb71 100644 --- a/k8s/flux/apps/kustomization.yaml +++ b/k8s/flux/apps/kustomization.yaml @@ -1,9 +1,9 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - aly-codes.yaml - - collabora.yaml - - error-pages.yaml + - aly-codes + - collabora + - error-pages - forward-auth.yaml - immich.yaml - morsels.yaml @@ -12,11 +12,11 @@ resources: - ombi.yaml - paperless.yaml - plex.yaml - - pocket-id.yaml + - pocket-id - seerr.yaml - - slingshot.yaml - - switchyard.yaml - - tranquil-pds.yaml + - slingshot + - switchyard + - tranquil-pds - uptime-kuma.yaml - vaultwarden.yaml - - watsup.yaml + - watsup diff --git a/k8s/flux/apps/pocket-id.yaml b/k8s/flux/apps/pocket-id.yaml deleted file mode 100644 index 7517a712..00000000 --- a/k8s/flux/apps/pocket-id.yaml +++ /dev/null @@ -1,22 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: pocket-id - namespace: flux-system -spec: - dependsOn: - - name: pg-shared - interval: 15m - releaseName: pocket-id - targetNamespace: default - install: { remediation: { retries: 3 } } - upgrade: { remediation: { retries: 3 } } - chart: - spec: - chart: ./k8s/charts/pocket-id - interval: 15m - reconcileStrategy: Revision - sourceRef: - { kind: GitRepository, name: flux-system, namespace: flux-system } - valuesFrom: - - { kind: ConfigMap, name: cute-haus-global, valuesKey: values.yaml } diff --git a/k8s/charts/pocket-id/templates/deployment.yaml b/k8s/flux/apps/pocket-id/deployment.yaml similarity index 92% rename from k8s/charts/pocket-id/templates/deployment.yaml rename to k8s/flux/apps/pocket-id/deployment.yaml index 2ded4956..6cfdeea4 100644 --- a/k8s/charts/pocket-id/templates/deployment.yaml +++ b/k8s/flux/apps/pocket-id/deployment.yaml @@ -29,11 +29,11 @@ spec: - key: node.kubernetes.io/not-ready operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 - key: node.kubernetes.io/unreachable operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 affinity: nodeAffinity: preferredDuringSchedulingIgnoredDuringExecution: diff --git a/k8s/charts/pocket-id/templates/ingress.yaml b/k8s/flux/apps/pocket-id/ingress.yaml similarity index 100% rename from k8s/charts/pocket-id/templates/ingress.yaml rename to k8s/flux/apps/pocket-id/ingress.yaml diff --git a/k8s/flux/apps/pocket-id/kustomization.yaml b/k8s/flux/apps/pocket-id/kustomization.yaml new file mode 100644 index 00000000..90c3c573 --- /dev/null +++ b/k8s/flux/apps/pocket-id/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: default +resources: + - deployment.yaml + - ingress.yaml + - service.yaml diff --git a/k8s/charts/pocket-id/templates/service.yaml b/k8s/flux/apps/pocket-id/service.yaml similarity index 100% rename from k8s/charts/pocket-id/templates/service.yaml rename to k8s/flux/apps/pocket-id/service.yaml diff --git a/k8s/flux/apps/slingshot.yaml b/k8s/flux/apps/slingshot.yaml deleted file mode 100644 index 555173d8..00000000 --- a/k8s/flux/apps/slingshot.yaml +++ /dev/null @@ -1,20 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: slingshot - namespace: flux-system -spec: - interval: 15m - releaseName: slingshot - targetNamespace: microcosm - install: { remediation: { retries: 3 } } - upgrade: { remediation: { retries: 3 } } - chart: - spec: - chart: ./k8s/charts/slingshot - interval: 15m - reconcileStrategy: Revision - sourceRef: - { kind: GitRepository, name: flux-system, namespace: flux-system } - valuesFrom: - - { kind: ConfigMap, name: cute-haus-global, valuesKey: values.yaml } diff --git a/k8s/charts/slingshot/templates/deployment.yaml b/k8s/flux/apps/slingshot/deployment.yaml similarity index 93% rename from k8s/charts/slingshot/templates/deployment.yaml rename to k8s/flux/apps/slingshot/deployment.yaml index b1f8c747..efe1d18f 100644 --- a/k8s/charts/slingshot/templates/deployment.yaml +++ b/k8s/flux/apps/slingshot/deployment.yaml @@ -33,11 +33,11 @@ spec: - key: node.kubernetes.io/not-ready operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 - key: node.kubernetes.io/unreachable operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 containers: - name: slingshot image: ghcr.io/alyraffauf/slingshot:latest@sha256:24d0777f1beedb946c4b2a06410a55cea75ff883430cc7629a18336207f212f7 diff --git a/k8s/charts/slingshot/templates/ingress.yaml b/k8s/flux/apps/slingshot/ingress.yaml similarity index 100% rename from k8s/charts/slingshot/templates/ingress.yaml rename to k8s/flux/apps/slingshot/ingress.yaml diff --git a/k8s/flux/apps/slingshot/kustomization.yaml b/k8s/flux/apps/slingshot/kustomization.yaml new file mode 100644 index 00000000..8ffd40de --- /dev/null +++ b/k8s/flux/apps/slingshot/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: microcosm +resources: + - deployment.yaml + - ingress.yaml + - pdb.yaml + - service.yaml diff --git a/k8s/charts/slingshot/templates/pdb.yaml b/k8s/flux/apps/slingshot/pdb.yaml similarity index 100% rename from k8s/charts/slingshot/templates/pdb.yaml rename to k8s/flux/apps/slingshot/pdb.yaml diff --git a/k8s/charts/slingshot/templates/service.yaml b/k8s/flux/apps/slingshot/service.yaml similarity index 100% rename from k8s/charts/slingshot/templates/service.yaml rename to k8s/flux/apps/slingshot/service.yaml diff --git a/k8s/flux/apps/switchyard.yaml b/k8s/flux/apps/switchyard.yaml deleted file mode 100644 index 0c389a4b..00000000 --- a/k8s/flux/apps/switchyard.yaml +++ /dev/null @@ -1,20 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: switchyard - namespace: flux-system -spec: - interval: 15m - releaseName: switchyard - targetNamespace: websites - install: { remediation: { retries: 3 } } - upgrade: { remediation: { retries: 3 } } - chart: - spec: - chart: ./k8s/charts/switchyard - interval: 15m - reconcileStrategy: Revision - sourceRef: - { kind: GitRepository, name: flux-system, namespace: flux-system } - valuesFrom: - - { kind: ConfigMap, name: cute-haus-global, valuesKey: values.yaml } diff --git a/k8s/charts/switchyard/templates/deployment.yaml b/k8s/flux/apps/switchyard/deployment.yaml similarity index 91% rename from k8s/charts/switchyard/templates/deployment.yaml rename to k8s/flux/apps/switchyard/deployment.yaml index dcc60c58..f1bbcf0f 100644 --- a/k8s/charts/switchyard/templates/deployment.yaml +++ b/k8s/flux/apps/switchyard/deployment.yaml @@ -25,11 +25,11 @@ spec: - key: node.kubernetes.io/not-ready operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 - key: node.kubernetes.io/unreachable operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 topologySpreadConstraints: - maxSkew: 1 topologyKey: topology.kubernetes.io/zone diff --git a/k8s/charts/switchyard/templates/ingress.yaml b/k8s/flux/apps/switchyard/ingress.yaml similarity index 100% rename from k8s/charts/switchyard/templates/ingress.yaml rename to k8s/flux/apps/switchyard/ingress.yaml diff --git a/k8s/flux/apps/switchyard/kustomization.yaml b/k8s/flux/apps/switchyard/kustomization.yaml new file mode 100644 index 00000000..943868e2 --- /dev/null +++ b/k8s/flux/apps/switchyard/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: websites +resources: + - deployment.yaml + - ingress.yaml + - pdb.yaml + - service.yaml diff --git a/k8s/charts/switchyard/templates/pdb.yaml b/k8s/flux/apps/switchyard/pdb.yaml similarity index 100% rename from k8s/charts/switchyard/templates/pdb.yaml rename to k8s/flux/apps/switchyard/pdb.yaml diff --git a/k8s/charts/switchyard/templates/service.yaml b/k8s/flux/apps/switchyard/service.yaml similarity index 100% rename from k8s/charts/switchyard/templates/service.yaml rename to k8s/flux/apps/switchyard/service.yaml diff --git a/k8s/flux/apps/tranquil-pds.yaml b/k8s/flux/apps/tranquil-pds.yaml deleted file mode 100644 index 49949da9..00000000 --- a/k8s/flux/apps/tranquil-pds.yaml +++ /dev/null @@ -1,23 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: tranquil-pds - namespace: flux-system -spec: - dependsOn: - - name: pg-shared - - name: valkey - interval: 15m - releaseName: tranquil-pds - targetNamespace: default - install: { remediation: { retries: 3 } } - upgrade: { remediation: { retries: 3 } } - chart: - spec: - chart: ./k8s/charts/tranquil-pds - interval: 15m - reconcileStrategy: Revision - sourceRef: - { kind: GitRepository, name: flux-system, namespace: flux-system } - valuesFrom: - - { kind: ConfigMap, name: cute-haus-global, valuesKey: values.yaml } diff --git a/k8s/charts/tranquil-pds/templates/deployment.yaml b/k8s/flux/apps/tranquil-pds/deployment.yaml similarity index 95% rename from k8s/charts/tranquil-pds/templates/deployment.yaml rename to k8s/flux/apps/tranquil-pds/deployment.yaml index f5034e70..c6f15bc4 100644 --- a/k8s/charts/tranquil-pds/templates/deployment.yaml +++ b/k8s/flux/apps/tranquil-pds/deployment.yaml @@ -29,11 +29,11 @@ spec: - key: node.kubernetes.io/not-ready operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 - key: node.kubernetes.io/unreachable operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 imagePullSecrets: - name: atcr-pull topologySpreadConstraints: diff --git a/k8s/charts/tranquil-pds/templates/ingress.yaml b/k8s/flux/apps/tranquil-pds/ingress.yaml similarity index 100% rename from k8s/charts/tranquil-pds/templates/ingress.yaml rename to k8s/flux/apps/tranquil-pds/ingress.yaml diff --git a/k8s/flux/apps/tranquil-pds/kustomization.yaml b/k8s/flux/apps/tranquil-pds/kustomization.yaml new file mode 100644 index 00000000..a6aa18c4 --- /dev/null +++ b/k8s/flux/apps/tranquil-pds/kustomization.yaml @@ -0,0 +1,8 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: default +resources: + - deployment.yaml + - ingress.yaml + - pdb.yaml + - service.yaml diff --git a/k8s/charts/tranquil-pds/templates/pdb.yaml b/k8s/flux/apps/tranquil-pds/pdb.yaml similarity index 100% rename from k8s/charts/tranquil-pds/templates/pdb.yaml rename to k8s/flux/apps/tranquil-pds/pdb.yaml diff --git a/k8s/charts/tranquil-pds/templates/service.yaml b/k8s/flux/apps/tranquil-pds/service.yaml similarity index 100% rename from k8s/charts/tranquil-pds/templates/service.yaml rename to k8s/flux/apps/tranquil-pds/service.yaml diff --git a/k8s/flux/apps/watsup.yaml b/k8s/flux/apps/watsup.yaml deleted file mode 100644 index a0cf1c99..00000000 --- a/k8s/flux/apps/watsup.yaml +++ /dev/null @@ -1,20 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: watsup - namespace: flux-system -spec: - interval: 15m - releaseName: watsup - targetNamespace: websites - install: { remediation: { retries: 3 } } - upgrade: { remediation: { retries: 3 } } - chart: - spec: - chart: ./k8s/charts/watsup - interval: 15m - reconcileStrategy: Revision - sourceRef: - { kind: GitRepository, name: flux-system, namespace: flux-system } - valuesFrom: - - { kind: ConfigMap, name: cute-haus-global, valuesKey: values.yaml } diff --git a/k8s/flux/apps/watsup/configmap.yaml b/k8s/flux/apps/watsup/configmap.yaml new file mode 100644 index 00000000..882178a1 --- /dev/null +++ b/k8s/flux/apps/watsup/configmap.yaml @@ -0,0 +1,134 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: watsup-config + annotations: + helm.sh/resource-policy: keep + labels: + app: watsup +data: + watsup.toml: | + title = "watsup" + + [[sections]] + type = "widgets" + columns = 4 + + [[sections.widgets]] + type = "weather" + + [[sections.widgets]] + type = "search" + span = 3 + + [[sections]] + type = "widgets" + columns = 2 + + [[sections.widgets]] + type = "lobsters" + title = "Lobsters" + + [[sections.widgets]] + type = "hacker-news" + title = "Hacker News" + + [[sections]] + type = "services" + title = "Atmosphere Apps+Infra" + columns = 3 + + [[sections.services]] + name = "atbbs" + url = "https://atbbs.xyz/" + + [[sections.services]] + name = "morsels.blue" + url = "https://morsels.blue/" + + [[sections.services]] + name = "haunt.at" + url = "https://haunt.at/" + + [[sections.services]] + name = "snarled.at" + url = "https://snarled.at/" + + [[sections.services]] + name = "aly.social" + url = "https://pds.cute.haus" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/bluesky.png" + + [[sections.services]] + name = "slingshot" + url = "https://slingshot.cute.haus" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/bluesky.png" + + [[sections]] + type = "services" + title = "Webpages" + columns = 3 + + [[sections.services]] + name = "Aly Raffauf" + url = "https://aly.codes/" + + [[sections.services]] + name = "Switchyard" + url = "https://switchyard.aly.codes/" + + [[sections.services]] + name = "Morgan Tamayo" + url = "https://morgantamayo.com/" + + [[sections]] + type = "services" + title = "Apps" + columns = 4 + + [[sections.services]] + name = "Pocket ID" + url = "https://id.cute.haus/" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/pocket-id.png" + + [[sections.services]] + name = "Plex" + url = "https://plex.cute.haus/" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/plex.png" + + [[sections.services]] + name = "Ombi" + url = "https://ombi.cute.haus/" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/ombi.png" + + [[sections.services]] + name = "Immich" + url = "https://immich.cute.haus/" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/immich.png" + + [[sections.services]] + name = "Navidrome" + url = "https://navidrome.cute.haus" + healthUrl = "http://navidrome.default.svc.cluster.local/" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/navidrome.png" + + [[sections.services]] + name = "Paperless" + url = "https://paperless.cute.haus" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/paperless-ngx.png" + + [[sections.services]] + name = "Vaultwarden" + url = "https://vault.cute.haus/" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/vaultwarden.png" + + [[sections.services]] + name = "Uptime Kuma" + url = "https://kuma.cute.haus/" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/uptime-kuma.png" + + [[sections.services]] + name = "Grafana" + url = "https://grafana.narwhal-snapper.ts.net/" + healthUrl = "http://10.254.0.4:3010/api/health" + icon = "https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons/png/grafana.png" diff --git a/k8s/charts/watsup/templates/deployment.yaml b/k8s/flux/apps/watsup/deployment.yaml similarity index 87% rename from k8s/charts/watsup/templates/deployment.yaml rename to k8s/flux/apps/watsup/deployment.yaml index 213d3bad..23270a1e 100644 --- a/k8s/charts/watsup/templates/deployment.yaml +++ b/k8s/flux/apps/watsup/deployment.yaml @@ -1,20 +1,20 @@ apiVersion: apps/v1 kind: Deployment metadata: - name: {{ .Chart.Name }} + name: watsup annotations: helm.sh/resource-policy: keep labels: - app: {{ .Chart.Name }} + app: watsup spec: replicas: 2 selector: matchLabels: - app: {{ .Chart.Name }} + app: watsup template: metadata: labels: - app: {{ .Chart.Name }} + app: watsup spec: automountServiceAccountToken: false enableServiceLinks: false @@ -28,15 +28,15 @@ spec: whenUnsatisfiable: DoNotSchedule labelSelector: matchLabels: - app: {{ .Chart.Name }} + app: watsup - maxSkew: 1 topologyKey: kubernetes.io/hostname whenUnsatisfiable: DoNotSchedule labelSelector: matchLabels: - app: {{ .Chart.Name }} + app: watsup containers: - - name: {{ .Chart.Name }} + - name: watsup image: ghcr.io/alyraffauf/watsup:latest@sha256:f28824be43af70f7a163dfa8056b77fadd0fa59f95cad1d713e8cad35c529b18 imagePullPolicy: IfNotPresent env: @@ -72,4 +72,4 @@ spec: volumes: - name: config configMap: - name: {{ .Chart.Name }}-config + name: watsup-config diff --git a/k8s/charts/watsup/templates/ingress.yaml b/k8s/flux/apps/watsup/ingress.yaml similarity index 83% rename from k8s/charts/watsup/templates/ingress.yaml rename to k8s/flux/apps/watsup/ingress.yaml index 18384c03..859e1229 100644 --- a/k8s/charts/watsup/templates/ingress.yaml +++ b/k8s/flux/apps/watsup/ingress.yaml @@ -1,11 +1,11 @@ apiVersion: networking.k8s.io/v1 kind: Ingress metadata: - name: {{ .Chart.Name }} + name: watsup annotations: helm.sh/resource-policy: keep labels: - app: {{ .Chart.Name }} + app: watsup spec: ingressClassName: traefik tls: @@ -21,7 +21,7 @@ spec: pathType: Prefix backend: service: - name: {{ .Chart.Name }} + name: watsup port: number: 80 - host: "www.cute.haus" @@ -31,6 +31,6 @@ spec: pathType: Prefix backend: service: - name: {{ .Chart.Name }} + name: watsup port: number: 80 diff --git a/k8s/flux/apps/watsup/kustomization.yaml b/k8s/flux/apps/watsup/kustomization.yaml new file mode 100644 index 00000000..dbf6ceb9 --- /dev/null +++ b/k8s/flux/apps/watsup/kustomization.yaml @@ -0,0 +1,9 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: websites +resources: + - configmap.yaml + - deployment.yaml + - ingress.yaml + - pdb.yaml + - service.yaml diff --git a/k8s/charts/watsup/templates/pdb.yaml b/k8s/flux/apps/watsup/pdb.yaml similarity index 67% rename from k8s/charts/watsup/templates/pdb.yaml rename to k8s/flux/apps/watsup/pdb.yaml index d03f25bc..9edfad90 100644 --- a/k8s/charts/watsup/templates/pdb.yaml +++ b/k8s/flux/apps/watsup/pdb.yaml @@ -1,13 +1,13 @@ apiVersion: policy/v1 kind: PodDisruptionBudget metadata: - name: {{ .Chart.Name }} + name: watsup annotations: helm.sh/resource-policy: keep labels: - app: {{ .Chart.Name }} + app: watsup spec: minAvailable: 1 selector: matchLabels: - app: {{ .Chart.Name }} + app: watsup diff --git a/k8s/charts/watsup/templates/service.yaml b/k8s/flux/apps/watsup/service.yaml similarity index 71% rename from k8s/charts/watsup/templates/service.yaml rename to k8s/flux/apps/watsup/service.yaml index ae470ed5..4b9336dc 100644 --- a/k8s/charts/watsup/templates/service.yaml +++ b/k8s/flux/apps/watsup/service.yaml @@ -1,15 +1,15 @@ apiVersion: v1 kind: Service metadata: - name: {{ .Chart.Name }} + name: watsup annotations: helm.sh/resource-policy: keep labels: - app: {{ .Chart.Name }} + app: watsup spec: type: ClusterIP selector: - app: {{ .Chart.Name }} + app: watsup ports: - name: http port: 80 diff --git a/k8s/flux/platform/gotenberg.yaml b/k8s/flux/platform/gotenberg.yaml deleted file mode 100644 index 18f220cc..00000000 --- a/k8s/flux/platform/gotenberg.yaml +++ /dev/null @@ -1,28 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: gotenberg - namespace: flux-system -spec: - interval: 15m - releaseName: gotenberg - targetNamespace: platform - install: - remediation: - retries: 3 - upgrade: - remediation: - retries: 3 - chart: - spec: - chart: ./k8s/charts/gotenberg - interval: 15m - reconcileStrategy: Revision - sourceRef: - kind: GitRepository - name: flux-system - namespace: flux-system - valuesFrom: - - kind: ConfigMap - name: cute-haus-global - valuesKey: values.yaml diff --git a/k8s/charts/gotenberg/templates/deployment.yaml b/k8s/flux/platform/gotenberg/deployment.yaml similarity index 89% rename from k8s/charts/gotenberg/templates/deployment.yaml rename to k8s/flux/platform/gotenberg/deployment.yaml index bb4d4dfe..dd5218ce 100644 --- a/k8s/charts/gotenberg/templates/deployment.yaml +++ b/k8s/flux/platform/gotenberg/deployment.yaml @@ -27,11 +27,11 @@ spec: - key: node.kubernetes.io/not-ready operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 - key: node.kubernetes.io/unreachable operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 containers: - name: gotenberg image: gotenberg/gotenberg:8@sha256:67097317623a503ba2a6a7e9ae8db6929a1f7e1bbd88077bacf2d325fbdab923 diff --git a/k8s/flux/platform/gotenberg/kustomization.yaml b/k8s/flux/platform/gotenberg/kustomization.yaml new file mode 100644 index 00000000..953fa8ad --- /dev/null +++ b/k8s/flux/platform/gotenberg/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: platform +resources: + - deployment.yaml + - service.yaml diff --git a/k8s/charts/gotenberg/templates/service.yaml b/k8s/flux/platform/gotenberg/service.yaml similarity index 100% rename from k8s/charts/gotenberg/templates/service.yaml rename to k8s/flux/platform/gotenberg/service.yaml diff --git a/k8s/flux/platform/kustomization.yaml b/k8s/flux/platform/kustomization.yaml index 97d26115..45a02e08 100644 --- a/k8s/flux/platform/kustomization.yaml +++ b/k8s/flux/platform/kustomization.yaml @@ -1,10 +1,10 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - - gotenberg.yaml + - gotenberg - kubernetes-alloy.yaml - kubernetes-prometheus.yaml - pg-shared.yaml - - tika.yaml + - tika - valkey.yaml - valkey-nextcloud.yaml diff --git a/k8s/flux/platform/tika.yaml b/k8s/flux/platform/tika.yaml deleted file mode 100644 index fc5ce5ff..00000000 --- a/k8s/flux/platform/tika.yaml +++ /dev/null @@ -1,28 +0,0 @@ -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: tika - namespace: flux-system -spec: - interval: 15m - releaseName: tika - targetNamespace: platform - install: - remediation: - retries: 3 - upgrade: - remediation: - retries: 3 - chart: - spec: - chart: ./k8s/charts/tika - interval: 15m - reconcileStrategy: Revision - sourceRef: - kind: GitRepository - name: flux-system - namespace: flux-system - valuesFrom: - - kind: ConfigMap - name: cute-haus-global - valuesKey: values.yaml diff --git a/k8s/charts/tika/templates/deployment.yaml b/k8s/flux/platform/tika/deployment.yaml similarity index 88% rename from k8s/charts/tika/templates/deployment.yaml rename to k8s/flux/platform/tika/deployment.yaml index adccbddf..fdd4b3cb 100644 --- a/k8s/charts/tika/templates/deployment.yaml +++ b/k8s/flux/platform/tika/deployment.yaml @@ -27,11 +27,11 @@ spec: - key: node.kubernetes.io/not-ready operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 - key: node.kubernetes.io/unreachable operator: Exists effect: NoExecute - tolerationSeconds: {{ $.Values.global.failover.fastTolerationSeconds | default 60 }} + tolerationSeconds: 60 containers: - name: tika image: apache/tika:3.3.1.0-full@sha256:d8e6ed96260ad89307a93195a1b856102987a818ac648502f8efbaf313d32470 diff --git a/k8s/flux/platform/tika/kustomization.yaml b/k8s/flux/platform/tika/kustomization.yaml new file mode 100644 index 00000000..953fa8ad --- /dev/null +++ b/k8s/flux/platform/tika/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: platform +resources: + - deployment.yaml + - service.yaml diff --git a/k8s/charts/tika/templates/service.yaml b/k8s/flux/platform/tika/service.yaml similarity index 100% rename from k8s/charts/tika/templates/service.yaml rename to k8s/flux/platform/tika/service.yaml diff --git a/scripts/check-chart-inventory.ts b/scripts/check-chart-inventory.ts index 69a387f7..30e6eb43 100644 --- a/scripts/check-chart-inventory.ts +++ b/scripts/check-chart-inventory.ts @@ -55,11 +55,23 @@ async function chartDirectories(root: string): Promise> { return charts; } +async function rawApplicationNames(): Promise> { + const names = new Set(); + for (const layer of ["apps", "platform"]) { + const files = new Bun.Glob(`k8s/flux/${layer}/*/kustomization.yaml`); + for await (const path of files.scan(".")) { + names.add(path.split("/")[3]); + } + } + return names; +} + export async function checkChartInventory(): Promise { - const [declared, production, drafts] = await Promise.all([ + const [declared, production, drafts, rawApplications] = await Promise.all([ declaredChartCounts(), chartDirectories("k8s/charts"), chartDirectories("k8s/drafts"), + rawApplicationNames(), ]); const errors: string[] = []; @@ -88,5 +100,16 @@ export async function checkChartInventory(): Promise { ); } + for (const application of rawApplications) { + if (declared.has(application)) + errors.push( + `application '${application}' is declared as both a Helm chart and raw Kustomize workload`, + ); + if (production.has(application)) + errors.push( + `raw Kustomize application '${application}' still has a production Helm chart`, + ); + } + return errors; } diff --git a/scripts/check-pinned-images.ts b/scripts/check-pinned-images.ts index ef9469ac..6d256173 100644 --- a/scripts/check-pinned-images.ts +++ b/scripts/check-pinned-images.ts @@ -4,6 +4,10 @@ // push-and-redeploy loop. const GLOB = "k8s/charts/*/**/*.yaml"; +const RAW_GLOBS = [ + "k8s/flux/apps/*/**/*.yaml", + "k8s/flux/platform/*/**/*.yaml", +]; const FLUX_DIRS = [ "k8s/flux/infra-crds", "k8s/flux/infra-core", @@ -77,5 +81,30 @@ export async function checkPinnedImages(): Promise { } } + for (const rawGlob of RAW_GLOBS) { + const rawFiles = new Bun.Glob(rawGlob); + for await (const manifestPath of rawFiles.scan(".")) { + const application = manifestPath.split("/")[3]; + if (ALLOW_FLOATING.has(application)) continue; + + const text = await Bun.file(manifestPath).text(); + const imageLines = [ + ...text.matchAll( + /^\s*(?:image|imageName):\s+["']?([^"'\s{}]+:[^"'\s{}]+)["']?\s*$/gm, + ), + ]; + for (const match of imageLines) { + const fullRef = match[1]; + if (fullRef.includes("@sha256:")) continue; + + const [repo, tag] = fullRef.split(":"); + const shortRepo = repo.split("/").slice(-1)[0]; + errors.push( + `${application}: ${shortRepo} '${tag}' is not pinned to a sha256 digest`, + ); + } + } + } + return errors; } diff --git a/scripts/render-releases.ts b/scripts/render-releases.ts index 8e15751f..9313ffd1 100644 --- a/scripts/render-releases.ts +++ b/scripts/render-releases.ts @@ -108,6 +108,16 @@ async function run(command: string[], input?: string): Promise { if ((await process.exited) !== 0) throw new Error(command.join(" ")); } +async function commandOutput(command: string[]): Promise { + const process = Bun.spawn(command, { + stdout: "pipe", + stderr: "inherit", + }); + const output = await new Response(process.stdout).text(); + if ((await process.exited) !== 0) throw new Error(command.join(" ")); + return output; +} + async function renderRelease( release: HelmRelease, globalValues: Record, @@ -172,6 +182,21 @@ async function renderRelease( } } +async function renderRawKustomizations(): Promise { + for (const layer of ["apps", "platform"]) { + const files = new Bun.Glob(`k8s/flux/${layer}/*/kustomization.yaml`); + for await (const path of files.scan(".")) { + const directory = path.replace(/\/kustomization\.yaml$/, ""); + console.log(`${directory}: render and validate`); + const manifest = await commandOutput(["kubectl", "kustomize", directory]); + await run( + ["kubeconform", "-ignore-missing-schemas", "-summary"], + manifest, + ); + } + } +} + const globalValues = Bun.YAML.parse( await Bun.file("k8s/flux/sources/global.values.yaml").text(), ) as Record; @@ -179,3 +204,5 @@ const globalValues = Bun.YAML.parse( for (const release of await localReleases()) { await renderRelease(release, globalValues); } + +await renderRawKustomizations();