Files
k8scd/apps/templates/nextcloud-helm.yaml
T
2025-02-04 14:03:59 +01:00

94 lines
3.1 KiB
YAML

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: nextcloud-helm
namespace: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
destination:
namespace: nextcloud
server: https://kubernetes.default.svc
project: default
source:
repoURL: https://nextcloud.github.io/helm/
targetRevision: 6.6.3
chart: nextcloud
helm:
values: |
persistence:
# Nextcloud Data (/var/www/html)
enabled: true
accessMode: ReadWriteOnce
size: 100Gi
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi
nextcloud:
host: drive.hensen.io
configs:
proxy.config.php: |
<?php
$CONFIG = array (
'trusted_proxies' => ['10.0.0.0/8'],
);
phpClientHttpsFix:
enabled: true
protocol: https
ingress:
enabled: true
# className: nginx
annotations:
nginx.ingress.kubernetes.io/proxy-body-size: 100G
# kubernetes.io/tls-acme: "true"
cert-manager.io/cluster-issuer: prod-cluster-issuer
# # Keep this in sync with the README.md:
nginx.ingress.kubernetes.io/server-snippet: |-
server_tokens off;
add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload;";
proxy_hide_header X-Powered-By;
rewrite ^/.well-known/webfinger /index.php/.well-known/webfinger last;
rewrite ^/.well-known/nodeinfo /index.php/.well-known/nodeinfo last;
rewrite ^/.well-known/host-meta /public.php?service=host-meta last;
rewrite ^/.well-known/host-meta.json /public.php?service=host-meta-json;
location = /.well-known/carddav {
return 301 $scheme://$host/remote.php/dav;
}
location = /.well-known/caldav {
return 301 $scheme://$host/remote.php/dav;
}
location = /robots.txt {
allow all;
log_not_found off;
access_log off;
}
location ~ ^/(?:build|tests|config|lib|3rdparty|templates|data)/ {
deny all;
}
location ~ ^/(?:autotest|occ|issue|indie|db_|console) {
deny all;
}
tls:
- secretName: nextcloud-tls
hosts:
- drive.hensen.io
labels: {}
path: /
pathType: Prefix
syncPolicy:
syncOptions:
- CreateNamespace=true
automated:
selfHeal: true