feat: add home-assistant

This commit is contained in:
JJGadgets
2024-01-28 15:32:58 +08:00
parent 1320d0f6e3
commit 3c8780941c
6 changed files with 169 additions and 2 deletions

View File

@@ -188,6 +188,8 @@ APP_IP_TAILSCALE=ENC[AES256_GCM,data:Qe3K9HQqMlIQEBc=,iv:TKU933gQCfVxGQrcn3ck8NF
APP_IP_EXT_TAILSCALE=ENC[AES256_GCM,data:7sOT0wBRCWBO,iv:1Xgybjm+fyf6YwW5S2SePyzof4jAU81j4Jibc4cScQk=,tag:GjLlsgzeAgaoPQXd39KZaA==,type:str]
APP_UID_TAILSCALE=ENC[AES256_GCM,data:HpYp/hQ=,iv:3WmuUMZoq9bGSdEG087iO1WQhZ9GIaMqrQHLGjIebsU=,tag:1h1I+dCNZACauDW7LSB/Jw==,type:str]
APP_UID_READECK=ENC[AES256_GCM,data:SOgCzqI=,iv:/Jz2dJZgScRxN2ESXgqmR99r1IXDr7FIxsa1ITbFA48=,tag:M3QTlOypDe4U1x8uYUXvvg==,type:str]
APP_DNS_HOME_ASSISTANT=ENC[AES256_GCM,data:eM/UKO8GZufDSE4=,iv:gEhilhDd//WpPrspYYy7INH0vwGjWGXyYEAlqtaX0Y4=,tag:5ANZb98etuKpiOW8VNxBLQ==,type:str]
APP_UID_HOME_ASSISTANT=ENC[AES256_GCM,data:siSvWIQ=,iv:yKE4QR0OZ2Ebjr9Itrl2ArE8K4GwfWWm3A6f1H71Qbs=,tag:LlbhDrhOqkoR/0YMoxFFNQ==,type:str]
APP_DNS_K8S_SCHEMAS=ENC[AES256_GCM,data:dHuRdq+6XS8e5jDASQ==,iv:ldh4b30ZFgeKSjks/O+Uosv+6teiR/nttqm5CVVwfpM=,tag:2OVl+Pv3kXbc7L6g9VA69w==,type:str]
CONFIG_TAILSCALE_NODE_PORT=ENC[AES256_GCM,data:5fOGZnU=,iv:ACISp8g5R65r4wfL9GPCenCqqszwalLiAa99BDVWS7w=,tag:ECJ5gRru2kd8ccGXEbj7yQ==,type:str]
CONFIG_MINECRAFT_OPS=ENC[AES256_GCM,data:al3glJDrtuqtTM2z4W7n+tPNf6XVfK64Jdb9s5RAE5NUwxyK,iv:kYqlsOabsa2iBZKgqjOpFYJo0DMFuoo3ZWCqb/Xzi5c=,tag:nIqPXvBvxdi8crMj1CYsEw==,type:str]
@@ -217,8 +219,8 @@ VM_UUID_AD_DC1=ENC[AES256_GCM,data:IS+IhA/KhbFuv0XxIEzOyV9yLwaw2RpHoguMBKsfD4urY
VM_UUID_AD_DC2=ENC[AES256_GCM,data:wdGQCok1cHLNfubTXA636+0FpKJex1MY9IRYvGX05Rrl+8E/,iv:DdGleAp8cT9xhsMmgFMnoJgb5Ctem9tVm6qI6xXgUBo=,tag:BmMdCbhCYOmOgi+NudfAgQ==,type:str]
sops_age__list_0__map_enc=-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBFSXFvLzFQaFJ0OVJKUFV5\nTWh2OUltUlpJWFlVVytFYU9VajBHSnQ4SGdjCnRVbEVXdDVyUHJrR05Ba0xvUm1l\nTkt2YmNUZy90ZFA2b3QrODFKZ01EVG8KLS0tIEw2dkd1cnFCbnI5eWxKL2o1aDVB\nN0hveXZ2dWdxQ2k2L0pGR0ROMStVTmsK4dV/hNyDjsYnVUiFQ7kqdmcVHfYyVckz\nh/rwLjcZgsup72WDVP3v6Eul8B3LKFrSb8CDFA54tyQmSdFDCQC+Zg==\n-----END AGE ENCRYPTED FILE-----\n
sops_age__list_0__map_recipient=age1u57l4s400gqstc0p485j4646cemntufr0pcyp32yudklsp90xpmszxvnkj
sops_lastmodified=2024-01-23T02:35:50Z
sops_mac=ENC[AES256_GCM,data:jJOVE77bKVVWetdQwtWXK+1ri2yyvb6W0LIc2QlRcE6ZkCP40nbvn9Kjv2ArBvJ4H3TSa4XDeJeMV/2lt8OsC56dau1dXJZ7reG4Yz/xqCtB18dPwysKe7LYzoLtvtFXwE4kk1DO6Rv1nZ7JdAy9ss92HUJyFJlBjXOPek2JcVg=,iv:XZ7KFTZuCZJUk0x/7rfoKEcIvlxnxJp1Y847XjkkZ5s=,tag:AOfFXV4eo97xUTpa1q2nZQ==,type:str]
sops_lastmodified=2024-01-28T07:22:30Z
sops_mac=ENC[AES256_GCM,data:a7zcUeaBJYypeXcxtikHxNB+oo7AdyhVStcsTpP5QvjFWE//sv+znasuQ1eqlSJ7PlKr2XUUjLPvRBy8p7HBjCrPwVLs9te/uTxtzKgb5W+nhG8akauiQdQ7FW5J/RuwH3Dst8+eqjzYlvvYw1gAlbXqtfXPWH5cCDkgeFI/cV4=,iv:XsaHqzeS+km4puhMIovkTyj7ilhQZP20t2tYqcqja70=,tag:RU2kM2YPN5uHq43siUiCSA==,type:str]
sops_pgp__list_0__map_created_at=2023-06-01T18:01:04Z
sops_pgp__list_0__map_enc=-----BEGIN PGP MESSAGE-----\n\nhF4DAAAAAAAAAAASAQdAbA35718t0WVKrjQFYUPviCb0lVuh8NpfSdJCHjHcWWww\n8ak4q4VL69tZLSjQHx+VsMmKooknxWz6pw0lGxyDYlZMQ81bodInjaZGFZSz8Uuh\n0l4BhDCNDBBALTrnTliz6/DAHvmavI4UxMHost5alFio9JPkTDNmXZyvcy1/R6aw\n/uhQXLUBRvm0TSOhBZb7d0SLkLfe02Um40w1TibpKXsZz1GOMbPRNBMHHra0QIuQ\n=0jA+\n-----END PGP MESSAGE-----\n
sops_pgp__list_0__map_fp=31E70E5BC80C58AFF5DD649921AC5A1AC6E5B7F2

View File

@@ -95,6 +95,7 @@ resources:
- ../../../deploy/apps/readeck/
- ../../../deploy/apps/k8s-schemas/
- ../../../deploy/apps/restic-rest-nfs/
- ../../../deploy/apps/home-assistant/
- ../../../deploy/vm/_kubevirt/
#- ../../../deploy/vm/_base/
- ../../../deploy/vm/ad/

View File

@@ -0,0 +1,105 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2beta1
kind: HelmRelease
metadata:
name: &app home-assistant
namespace: *app
spec:
interval: 5m
chart:
spec:
chart: app-template
version: "2.5.0"
sourceRef:
name: bjw-s
kind: HelmRepository
namespace: flux-system
values:
controllers:
main:
type: deployment
replicas: 1
pod:
labels:
ingress.home.arpa/nginx-internal: "allow"
containers:
main:
image:
repository: "ghcr.io/onedr0p/home-assistant"
tag: "2024.1.5@sha256:64bb3ffa532c3c52563f0e4a4de8d50c889f42a1b0826b35ee1ac728652fb107"
env:
TZ: "${CONFIG_TZ}"
#envFrom:
# - secretRef:
# name: "home-assistant-secrets"
securityContext:
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
resources:
requests:
cpu: "10m"
limits:
cpu: "3000m"
memory: "1Gi"
service:
main:
ports:
http:
port: 8123
ingress:
main:
enabled: true
primary: true
className: "nginx-internal"
hosts:
- host: &host "${APP_DNS_HOME_ASSISTANT}"
paths: &paths
- path: /
pathType: Prefix
service:
name: main
port: http
tls:
- hosts: [*host]
persistence:
config:
enabled: true
existingClaim: "home-assistant-data"
advancedMounts:
main:
main:
- subPath: "config"
path: "/config"
tmp:
enabled: true
type: emptyDir
medium: Memory
globalMounts:
- path: "/tmp"
readOnly: false
defaultPodOptions:
automountServiceAccountToken: false
enableServiceLinks: false
securityContext:
runAsNonRoot: true
runAsUser: &uid ${APP_UID_HOME_ASSISTANT}
runAsGroup: *uid
fsGroup: *uid
fsGroupChangePolicy: "Always"
seccompProfile: { type: "RuntimeDefault" }
topologySpreadConstraints:
- maxSkew: 1
topologyKey: "kubernetes.io/hostname"
whenUnsatisfiable: "DoNotSchedule"
labelSelector:
matchLabels:
app.kubernetes.io/name: *app
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: "fuckoff.home.arpa/home-assistant"
operator: "DoesNotExist"

View File

@@ -0,0 +1,43 @@
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: home-assistant-app
namespace: flux-system
labels: &l
app.kubernetes.io/name: "home-assistant"
spec:
commonMetadata:
labels: *l
path: ./kube/deploy/apps/home-assistant/app
targetNamespace: "home-assistant"
dependsOn:
- name: home-assistant-pvc
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: home-assistant-pvc
namespace: flux-system
labels: &l
app.kubernetes.io/name: "home-assistant"
spec:
commonMetadata:
labels: *l
path: ./kube/deploy/core/storage/volsync/template
targetNamespace: "home-assistant"
dependsOn:
- name: 1-core-storage-volsync-app
- name: 1-core-storage-rook-ceph-cluster
postBuild:
substitute:
PVC: "home-assistant-data"
SIZE: "10Gi"
SC: "file"
ACCESSMODE: "ReadWriteMany"
RUID: !!str &uid |
${APP_UID_HOME_ASSISTANT}
RGID: !!str |
${APP_UID_HOME_ASSISTANT}
RFSG: !!str |
${APP_UID_HOME_ASSISTANT}

View File

@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ns.yaml
- ks.yaml

View File

@@ -0,0 +1,10 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: home-assistant
labels:
kustomize.toolkit.fluxcd.io/prune: disabled
pod-security.kubernetes.io/enforce: &ps restricted
pod-security.kubernetes.io/audit: *ps
pod-security.kubernetes.io/warn: *ps