1 Commits

Author SHA1 Message Date
renovate[bot] 5cc2bbc818 Update helm chart cert-manager to v1.20.2 2026-05-14 18:35:07 +00:00
19 changed files with 63 additions and 439 deletions
+2 -2
View File
@@ -12,14 +12,14 @@ spec:
project: default
source:
repoURL: https://community-charts.github.io/helm-charts
targetRevision: 1.8.9
targetRevision: 1.8.7
chart: actualbudget
helm:
values: |
# Actual Budget configuration
image:
tag: "26.6.0"
tag: "26.3.0"
# Authentication configuration
login:
-21
View File
@@ -1,21 +0,0 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: bolletjestrui
namespace: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
project: default
source:
repoURL: https://github.com/rubenhensen/k8scd.git
targetRevision: HEAD
path: bolletjestrui
destination:
server: https://kubernetes.default.svc
namespace: bolletjestrui
syncPolicy:
syncOptions:
- CreateNamespace=true
automated:
selfHeal: true
+1 -1
View File
@@ -12,7 +12,7 @@ spec:
project: default
source:
repoURL: https://charts.jetstack.io
targetRevision: v1.15.5
targetRevision: v1.20.2
chart: cert-manager
helm:
parameters:
-21
View File
@@ -1,21 +0,0 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: gitea
namespace: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
project: default
source:
repoURL: https://github.com/rubenhensen/k8scd.git
targetRevision: HEAD
path: gitea
destination:
server: https://kubernetes.default.svc
namespace: gitea
syncPolicy:
syncOptions:
- CreateNamespace=true
automated:
selfHeal: true
-5
View File
@@ -41,11 +41,6 @@ spec:
secretKeyRef:
name: mbgwp-mariadb-credentials
key: password
- name: WF_ENCRYPTION_KEY
valueFrom:
secretKeyRef:
name: wordpress-credentials
key: wf-encryption-key
# WordPress specific settings
settings:
@@ -1,80 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
labels:
app: bolletjestrui
name: bolletjestrui
spec:
replicas: 1
selector:
matchLabels:
app: bolletjestrui
strategy:
type: Recreate
template:
metadata:
labels:
app: bolletjestrui
spec:
containers:
- image: ghcr.io/rubenhensen/bolletjestrui:main-bb54c6a
name: bolletjestrui
ports:
- containerPort: 3000
protocol: TCP
env:
- name: DATABASE_URL
value: /app/data/bolletjestrui.db
- name: ORIGIN
value: https://vic.rubenhensen.nl
- name: PROTOCOL_HEADER
value: x-forwarded-proto
- name: HOST_HEADER
value: x-forwarded-host
# route GPX uploads can be a few MB; raise adapter-node's 512K default
- name: BODY_SIZE_LIMIT
value: "10M"
- name: TZ
value: Europe/Amsterdam
- name: SITE_PASSWORD
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: site_password
- name: ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: admin_password
- name: KEY_SECRET
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: key_secret
resources:
requests:
memory: "128Mi"
cpu: "50m"
limits:
memory: "512Mi"
cpu: "500m"
readinessProbe:
httpGet:
path: /login
port: 3000
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
httpGet:
path: /login
port: 3000
initialDelaySeconds: 15
periodSeconds: 20
volumeMounts:
- mountPath: /app/data
name: data
restartPolicy: Always
volumes:
- name: data
persistentVolumeClaim:
claimName: bolletjestrui-data
-13
View File
@@ -1,13 +0,0 @@
apiVersion: v1
kind: Service
metadata:
labels:
app: bolletjestrui
name: bolletjestrui
spec:
ports:
- name: "3000"
port: 3000
targetPort: 3000
selector:
app: bolletjestrui
@@ -1,12 +0,0 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
labels:
app: bolletjestrui
name: bolletjestrui-data
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 2Gi
-25
View File
@@ -1,25 +0,0 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: bolletjestrui-secrets
spec:
secretStoreRef:
name: vault-backend
kind: ClusterSecretStore
refreshInterval: 15m
target:
name: bolletjestrui-secrets
creationPolicy: Owner
data:
- secretKey: site_password
remoteRef:
key: kv/bolletjestrui
property: site_password
- secretKey: admin_password
remoteRef:
key: kv/bolletjestrui
property: admin_password
- secretKey: key_secret
remoteRef:
key: kv/bolletjestrui
property: key_secret
-26
View File
@@ -1,26 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: bolletjestrui-ingress
annotations:
cert-manager.io/cluster-issuer: prod-cluster-issuer
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
nginx.ingress.kubernetes.io/ssl-passthrough: "false"
nginx.ingress.kubernetes.io/proxy-body-size: "10m"
spec:
ingressClassName: nginx
rules:
- host: vic.rubenhensen.nl
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: bolletjestrui
port:
number: 3000
tls:
- secretName: letsencrypt-prod
hosts:
- vic.rubenhensen.nl
+12 -20
View File
@@ -10,59 +10,51 @@ records:
- name: "phocaslustrum"
expire: 300
type: A
content: "62.41.86.27"
content: "62.41.87.114"
- name: "ynab"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "authentik"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "ldap"
expire: 300
type: A
content: "62.41.86.27"
content: "62.41.87.114"
- name: "argocd"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "vault"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "rss"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "ha"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "longhorn"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "lingo"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "blog"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "serpbear"
expire: 300
type: A
content: "46.224.26.65"
- name: "git"
expire: 300
type: A
content: "46.224.26.65"
- name: "vic"
expire: 300
type: A
content: "46.224.26.65"
content: "62.41.87.114"
- name: "@"
expire: 300
type: MX
@@ -1,10 +0,0 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: gitea-data
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 10Gi
-60
View File
@@ -1,60 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: gitea
labels:
app: gitea
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app: gitea
template:
metadata:
labels:
app: gitea
spec:
securityContext:
fsGroup: 1000
containers:
- name: gitea
image: gitea/gitea:1
env:
- name: USER_UID
value: "1000"
- name: USER_GID
value: "1000"
- name: TZ
value: Europe/Amsterdam
- name: GITEA__server__ROOT_URL
value: https://git.rubenhensen.nl/
- name: GITEA__server__DOMAIN
value: git.rubenhensen.nl
- name: GITEA__server__PROTOCOL
value: http
- name: GITEA__server__HTTP_PORT
value: "3000"
- name: GITEA__server__DISABLE_SSH
value: "true"
- name: GITEA__database__DB_TYPE
value: sqlite3
- name: GITEA__database__PATH
value: /data/gitea/gitea.db
- name: GITEA__security__INSTALL_LOCK
value: "true"
- name: GITEA__log__MODE
value: console
ports:
- containerPort: 3000
name: http
protocol: TCP
volumeMounts:
- mountPath: /data
name: data
restartPolicy: Always
volumes:
- name: data
persistentVolumeClaim:
claimName: gitea-data
-13
View File
@@ -1,13 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: gitea
labels:
app: gitea
spec:
selector:
app: gitea
ports:
- name: http
port: 3000
targetPort: 3000
-24
View File
@@ -1,24 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: gitea-ingress
annotations:
cert-manager.io/cluster-issuer: prod-cluster-issuer
nginx.ingress.kubernetes.io/proxy-body-size: "1g"
spec:
ingressClassName: nginx
rules:
- host: git.rubenhensen.nl
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: gitea
port:
number: 3000
tls:
- secretName: letsencrypt-prod
hosts:
- git.rubenhensen.nl
+1 -5
View File
@@ -19,8 +19,4 @@ spec:
- secretKey: smtp-password
remoteRef:
key: kv/mbgwp
property: smtp-password
- secretKey: wf-encryption-key
remoteRef:
key: kv/mbgwp
property: wf-encryption-key
property: smtp-password
+45 -98
View File
@@ -1,43 +1,4 @@
{ config, pkgs, lib, ... }:
let
# Public IP of the home network where the k8s cluster ingress lives.
# Keep in sync with dns/domains/rubenhensen.nl.yaml.
homeIP = "62.41.86.27";
# Hosts tunneled to the home k8s cluster. Each entry gets:
# * an SNI map entry for TCP passthrough on :443
# * an HTTP vhost on :80 that reverse-proxies to the cluster
# The cluster's nginx-ingress terminates TLS with cert-manager.
tunneledHosts = [
"rss.rubenhensen.nl"
"authentik.rubenhensen.nl"
"vault.rubenhensen.nl"
"ynab.rubenhensen.nl"
"argocd.rubenhensen.nl"
"ha.rubenhensen.nl"
"longhorn.rubenhensen.nl"
"lingo.rubenhensen.nl"
"blog.rubenhensen.nl"
"serpbear.rubenhensen.nl"
"git.rubenhensen.nl"
];
sniMapEntries =
lib.concatMapStringsSep "\n"
(h: " ${h} ${homeIP}:443;")
tunneledHosts;
tunneledVhosts = lib.listToAttrs (map (h: {
name = h;
value = {
listen = [
{ addr = "0.0.0.0"; port = 80; }
{ addr = "[::]"; port = 80; }
];
locations."/".proxyPass = "http://${homeIP}";
};
}) tunneledHosts);
in
{
# ──────────────────────────────────────────────
# Firewall
@@ -74,67 +35,55 @@ in
"d /var/lib/acme/acme-challenge 0755 acme acme -"
];
# Serve ACME challenges via nginx on port 80.
# Also reverse-proxy tunneled hosts to the home k8s cluster, and do
# SNI-based TCP passthrough on 443 so the cluster's cert-manager keeps
# owning the TLS certificate for those hosts.
# Serve ACME challenges via nginx on port 80
services.nginx = {
enable = true;
recommendedProxySettings = true;
# SNI passthrough on 443:
# - mail.rubenhensen.nl (and anything else) → local stalwart on 8443
# - tunneled hosts → home cluster ingress on 443
streamConfig = ''
map $ssl_preread_server_name $tunnel_upstream {
${sniMapEntries}
default 127.0.0.1:8443;
}
server {
listen 443;
listen [::]:443;
proxy_pass $tunnel_upstream;
ssl_preread on;
}
'';
# Port 80: tunneled hosts reverse-proxy to the home cluster so its
# nginx-ingress handles HTTP→HTTPS redirects and cert-manager
# HTTP-01 ACME challenges. Mail-related hosts serve ACME challenges
# locally for stalwart's cert and redirect everything else to HTTPS.
virtualHosts = tunneledVhosts // {
"mail.rubenhensen.nl" = {
listen = [
{ addr = "0.0.0.0"; port = 80; }
{ addr = "[::]"; port = 80; }
];
locations."/.well-known/acme-challenge/".root = "/var/lib/acme/acme-challenge";
locations."/".return = "301 https://$host$request_uri";
virtualHosts."mail.rubenhensen.nl" = {
listen = [
{ addr = "0.0.0.0"; port = 80; }
{ addr = "[::]"; port = 80; }
];
locations."/.well-known/acme-challenge/" = {
root = "/var/lib/acme/acme-challenge";
};
"autoconfig.rubenhensen.nl" = {
listen = [
{ addr = "0.0.0.0"; port = 80; }
{ addr = "[::]"; port = 80; }
];
locations."/.well-known/acme-challenge/".root = "/var/lib/acme/acme-challenge";
locations."/".return = "301 https://$host$request_uri";
locations."/" = {
return = "301 https://$host$request_uri";
};
"autodiscover.rubenhensen.nl" = {
listen = [
{ addr = "0.0.0.0"; port = 80; }
{ addr = "[::]"; port = 80; }
];
locations."/.well-known/acme-challenge/".root = "/var/lib/acme/acme-challenge";
locations."/".return = "301 https://$host$request_uri";
};
virtualHosts."autoconfig.rubenhensen.nl" = {
listen = [
{ addr = "0.0.0.0"; port = 80; }
{ addr = "[::]"; port = 80; }
];
locations."/.well-known/acme-challenge/" = {
root = "/var/lib/acme/acme-challenge";
};
"rubenhensen.nl" = {
listen = [
{ addr = "0.0.0.0"; port = 80; }
{ addr = "[::]"; port = 80; }
];
locations."/.well-known/acme-challenge/".root = "/var/lib/acme/acme-challenge";
locations."/".return = "301 https://$host$request_uri";
locations."/" = {
return = "301 https://$host$request_uri";
};
};
virtualHosts."autodiscover.rubenhensen.nl" = {
listen = [
{ addr = "0.0.0.0"; port = 80; }
{ addr = "[::]"; port = 80; }
];
locations."/.well-known/acme-challenge/" = {
root = "/var/lib/acme/acme-challenge";
};
locations."/" = {
return = "301 https://$host$request_uri";
};
};
virtualHosts."rubenhensen.nl" = {
listen = [
{ addr = "0.0.0.0"; port = 80; }
{ addr = "[::]"; port = 80; }
];
locations."/.well-known/acme-challenge/" = {
root = "/var/lib/acme/acme-challenge";
};
locations."/" = {
return = "301 https://$host$request_uri";
};
};
};
@@ -171,9 +120,7 @@ ${sniMapEntries}
protocol = "managesieve";
};
https = {
# nginx owns the public :443 and does SNI passthrough to here
# for the mail.rubenhensen.nl SNI. Stalwart still terminates TLS.
bind = "127.0.0.1:8443";
bind = "[::]:443";
protocol = "http";
tls.implicit = true;
};
+1 -2
View File
@@ -16,8 +16,7 @@
"kubernetes": {
"managerFilePatterns": [
"/apps/templates/.+\\.yaml$/",
"/serpbear/.+\\.yaml$/",
"/bolletjestrui/.+\\.yaml$/"
"/serpbear/.+\\.yaml$/"
]
},
"customManagers": [
+1 -1
View File
@@ -1,4 +1,4 @@
apiVersion: external-secrets.io/v1
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: serpbear-secrets