feat: add vikunja

This commit is contained in:
JJGadgets
2024-02-14 17:17:46 +08:00
parent c9d24c073f
commit dcfc5f315c
8 changed files with 301 additions and 0 deletions

View File

@@ -105,6 +105,7 @@ resources:
- ../../../deploy/apps/redbot/
- ../../../deploy/apps/code-server/
- ../../../deploy/apps/homebox/
- ../../../deploy/apps/vikunja/
- ../../../deploy/vm/_kubevirt/
#- ../../../deploy/vm/_base/
- ../../../deploy/vm/ad/

View File

@@ -0,0 +1,34 @@
---
# yaml-language-server: $schema=https://crds.jank.ing/external-secrets.io/externalsecret_v1beta1.json
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: &name vikunja-secrets
namespace: vikunja
spec:
secretStoreRef:
kind: ClusterSecretStore
name: 1p
dataFrom:
- extract:
key: "Vikunja - ${CLUSTER_NAME}"
target:
creationPolicy: Owner
deletionPolicy: Retain
name: *name
template:
engineVersion: v2
mergePolicy: Merge
data:
VIKUNJA_SERVICE_JWTSECRET: "{{ .VIKUNJA_SERVICE_JWTSECRET }}"
config.yml: |
auth:
local:
enabled: false
openid:
enabled: true
providers:
- name: "JJGadgets Auth"
authurl: {{ .OIDC_URL }}
clientid: {{ .OIDC_ID }}
clientsecret: {{ .OIDC_SECRET }}

View File

@@ -0,0 +1,158 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2beta2
kind: HelmRelease
metadata:
name: &app vikunja
namespace: *app
spec:
interval: 5m
chart:
spec:
chart: app-template
version: "2.5.0"
sourceRef:
name: bjw-s
kind: HelmRepository
namespace: flux-system
values:
controllers:
main:
type: deployment
replicas: 1
pod:
labels:
ingress.home.arpa/nginx-internal: "allow"
db.home.arpa/pg: "pg-home"
containers:
main:
image: &img
repository: "docker.io/vikunja/vikunja"
tag: "0.23.0@sha256:f852e65b62e975a38d8db26c67417903cf7e0d9b533cb2d0a177d37b95375555"
env:
VIKUNJA_SERVICE_TIMEZONE: "${CONFIG_TZ}"
VIKUNJA_SERVICE_JWTSECRET:
valueFrom:
secretKeyRef:
name: "vikunja-secrets"
key: "VIKUNJA_SERVICE_JWTSECRET"
VIKUNJA_SERVICE_JWTTTL: "86400" # 1 day
VIKUNJA_SERVICE_JWTTTLLONG: "1209600" # 2 weeks
VIKUNJA_SERVICE_INTERFACE: ":8080"
VIKUNJA_SERVICE_PUBLICURL: "${APP_DNS_VIKUNJA}"
VIKUNJA_SERVICE_MAXITEMSPERPAGE: "200"
VIKUNJA_SERVICE_ENABLEREGISTRATION: "${CONFIG_VIKUNJA_REGISTRATION:=false}"
VIKUNJA_SERVICE_CUSTOMLOGOURL: "https://raw.githubusercontent.com/JJGadgets/images/main/icon.png"
VIKUNJA_SENTRY_ENABLED: "false"
VIKUNJA_DATABASE_TYPE: "postgres"
VIKUNJA_DATABASE_HOST:
valueFrom:
secretKeyRef:
name: &pgsec "pg-home-pguser-vikunja"
key: "pgbouncer-host"
VIKUNJA_DATABASE_DATABASE:
valueFrom:
secretKeyRef:
name: *pgsec
key: "dbname"
VIKUNJA_DATABASE_USER:
valueFrom:
secretKeyRef:
name: *pgsec
key: "user"
VIKUNJA_DATABASE_PASSWORD:
valueFrom:
secretKeyRef:
name: *pgsec
key: "password"
VIKUNJA_DATABASE_SSLMODE: "require"
VIKUNJA_DATABASE_SSLROOTCERT: "/tls/pg-ca.crt"
VIKUNJA_METRICS_ENABLED: "true"
VIKUNJA_LOG_PATH: "/dev/stdout"
VIKUNJA_DEFAULTSETTINGS_AVATAR_PROVIDER: "initials"
securityContext: &sc
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
resources:
requests:
cpu: "10m"
memory: "128Mi"
limits:
cpu: "3000m"
memory: "6000Mi"
service:
main:
ports:
http:
port: 8080
ingress:
main:
enabled: true
primary: true
className: "nginx-internal"
hosts:
- host: &host "${APP_DNS_VIKUNJA}"
paths: &paths
- path: /
pathType: Prefix
service:
name: main
port: http
tls:
- hosts: [*host]
persistence:
config:
enabled: true
type: secret
name: "vikunja-secrets"
advancedMounts:
main:
main:
- subPath: "config.yml"
path: "/etc/vikunja/config.yml"
readOnly: true
pg:
enabled: true
type: secret
name: "pg-home-ca"
defaultMode: 0400
advancedMounts:
main:
main:
- subPath: "ca.crt"
path: "/tls/pg-ca.crt"
readOnly: true
defaultPodOptions:
automountServiceAccountToken: false
enableServiceLinks: false
securityContext:
runAsNonRoot: true
runAsUser: &uid ${APP_UID_VIKUNJA}
runAsGroup: *uid
fsGroup: *uid
fsGroupChangePolicy: "Always"
seccompProfile: { type: "RuntimeDefault" }
topologySpreadConstraints:
- maxSkew: 1
topologyKey: "kubernetes.io/hostname"
whenUnsatisfiable: "DoNotSchedule"
labelSelector:
matchLabels:
app.kubernetes.io/name: *app
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: "fuckoff.home.arpa/vikunja"
operator: "DoesNotExist"
serviceMonitor:
main:
enabled: true
endpoints:
- port: http
scheme: http
path: "/api/v1/metrics"
interval: 1m
scrapeTimeout: 30s

View File

@@ -0,0 +1,68 @@
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: vikunja-app
namespace: flux-system
labels: &l
app.kubernetes.io/name: "vikunja"
spec:
commonMetadata:
labels: *l
path: ./kube/deploy/apps/vikunja/app
targetNamespace: "vikunja"
dependsOn:
- name: vikunja-db
# - name: vikunja-pvc
# ---
# apiVersion: kustomize.toolkit.fluxcd.io/v1
# kind: Kustomization
# metadata:
# name: vikunja-pvc
# namespace: flux-system
# labels: &l
# app.kubernetes.io/name: "vikunja"
# spec:
# commonMetadata:
# labels: *l
# path: ./kube/deploy/core/storage/volsync/template
# targetNamespace: "vikunja"
# dependsOn:
# - name: 1-core-storage-volsync-app
# - name: 1-core-storage-rook-ceph-cluster
# postBuild:
# substitute:
# PVC: "vikunja-data"
# SIZE: "10Gi"
# SC: &sc "file"
# SNAP: *sc
# ACCESSMODE: "ReadWriteMany"
# RUID: !!str &uid |
# ${APP_UID_VIKUNJA}
# RGID: !!str |
# ${APP_UID_VIKUNJA}
# RFSG: !!str |
# ${APP_UID_VIKUNJA}
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: vikunja-db
namespace: flux-system
labels: &l
prune.flux.home.arpa/enabled: "true"
db.home.arpa/pg: "pg-home"
app.kubernetes.io/name: "vikunja"
spec:
commonMetadata:
labels: *l
path: ./kube/deploy/core/db/pg/clusters/template/pguser
targetNamespace: "pg"
dependsOn:
- name: 1-core-db-pg-clusters-home
- name: 1-core-secrets-es-k8s
postBuild:
substitute:
PG_NAME: "home"
PG_DB_USER: &app "vikunja"
PG_APP_NS: *app

View File

@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ns.yaml
- ks.yaml

View File

@@ -0,0 +1,10 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: vikunja
labels:
kustomize.toolkit.fluxcd.io/prune: disabled
pod-security.kubernetes.io/enforce: &ps restricted
pod-security.kubernetes.io/audit: *ps
pod-security.kubernetes.io/warn: *ps

View File

@@ -39,6 +39,10 @@ spec:
databases: ["paperless-ngx"]
- name: "joplin"
databases: ["joplin"]
- name: "vikunja"
databases: ["vikunja"]
- name: "kanboard"
databases: ["kanboard"]
target:
group: postgres-operator.crunchydata.com
kind: PostgresCluster

View File

@@ -91,3 +91,23 @@ spec:
remoteRef:
remoteKey: *name
property: *key
---
# yaml-language-server: $schema=https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/external-secrets.io/pushsecret_v1alpha1.json
apiVersion: external-secrets.io/v1alpha1
kind: PushSecret
metadata:
name: &name "pg-${PG_NAME}-ca"
spec:
refreshInterval: "1m"
secretStoreRefs:
- kind: "SecretStore"
name: "pg-${PG_NAME}-${PG_APP_NS}-${PG_DB_USER}"
selector:
secret:
name: "pg-${PG_NAME}-cluster-cert" # source secret name
data:
- match:
secretKey: &key "ca.crt" # source secret key
remoteRef:
remoteKey: *name # destination secret name
property: *key # destination secret key