Commit Graph

2613 Commits

Author SHA1 Message Date
JJGadgets
5ba9c8ae7b feat!: Flux localhost bootstrap from 1P, add Sinon cluster
- installs Flux in hostNetwork mode binded to localhost to new clusters

- rework Taskfiles for new bootstrap flow, including loading secrets direct from 1Password with no SOPS for secret zero

- use 1Password for both talsecret and talenv for talhelper genconfig

- remove SOPS secrets

- add Sinon cluster, used as NAS

- cleanup ExternalSecret and 1P Connect's Flux ks for smoother bootstrap

- try out 1Password Connect as extraContainer in external-secrets deployment to avoid secrets going over network

- general cleanup
2024-05-21 13:49:50 +08:00
tinfoild[bot]
54f4117a42 fix(container): update image ghcr.io/tchapi/davis to v4.4.3 (#898)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-20 02:28:20 +00:00
tinfoild[bot]
e62d8b03dd chore(container): update image docker.io/inspircd/inspircd-docker to 6885500 (#905)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-20 02:11:07 +00:00
JJGadgets
941c1151f5 fix(onepassword-connect): don't double base64
ESO docs are wrong?
2024-05-20 09:27:32 +08:00
JJGadgets
67203c8f0a fix(onepassword-connect): netpol for documents, ES for credentials 2024-05-20 09:17:05 +08:00
tinfoild[bot]
624b82d571 fix(container): update image ghcr.io/fluxcd/source-controller to v1.2.5 (#903)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-20 00:50:52 +00:00
JJGadgets
71759eef2e feat(bootstrap/flux)!: build Flux v2.2.3 localhost install manifests (#902)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-20 07:46:22 +08:00
JJGadgets
e2d0ab22b7 fix(actions/flux-localhost-build): use file reference for commit content
argument list too long
2024-05-20 07:42:48 +08:00
JJGadgets
a1a473b420 fix(actions/flux-localhost-build): update or create 2024-05-20 07:26:51 +08:00
JJGadgets
a3359f271a fix(actions/flux-localhost-build): update or create 2024-05-20 07:15:55 +08:00
JJGadgets
184ce4cd78 fix(actions/flux-localhost-build): update or create 2024-05-20 07:08:50 +08:00
JJGadgets
6d7c981147 fix(actions/flux-localhost-build): signed commits 2024-05-20 07:03:56 +08:00
JJGadgets
1e7facf3a2 fix(actions/flux-localhost-build): fix email 2024-05-20 06:44:55 +08:00
JJGadgets
59294bcc64 fix(actions/flux-localhost-build): force push 2024-05-20 06:42:09 +08:00
JJGadgets
3910c7c24b fix(actions/flux-localhost-build): git pull strategy 2024-05-20 06:40:02 +08:00
JJGadgets
f4aa686e12 fix(actions/flux-localhost-build): GH_TOKEN 2024-05-20 06:10:23 +08:00
JJGadgets
7e73f74c6e fix(actions/flux-localhost-build): git user info 2024-05-20 06:03:24 +08:00
JJGadgets
84fde6c10d fix(actions/flux-localhost-build): triggers 2024-05-20 05:57:15 +08:00
JJGadgets
cb5b89cb7a feat(actions): add flux-localhost-build 2024-05-20 05:55:18 +08:00
JJGadgets
7fb7e1f6b5 fix(piped): db secret username 2024-05-19 18:03:25 +08:00
JJGadgets
b596cbfd37 fix(alertmanager): avoid flooding Cilium dnsproxy 2024-05-19 17:48:30 +08:00
JJGadgets
9d8cc307d4 fix(authentik): pod-security label 2024-05-19 04:08:25 +08:00
JJGadgets
7837e64ef9 fix(rook-ceph): RGW HTTPS in-cluster 2024-05-19 03:18:37 +08:00
tinfoild[bot]
819ee4b77b feat(helm): update chart tailscale-operator to 1.66.3 (#663)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-19 01:38:25 +08:00
tinfoild[bot]
79bb0fd83b feat(container): update image ghcr.io/tailscale/tailscale to v1.66.3 (#664)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-19 01:37:53 +08:00
JJGadgets
01b81c8099 fix(authentik): external-proxy-x 2024-05-19 01:28:00 +08:00
JJGadgets
5882897f55 fix(authentik): wrong cloudflared ingress rule 2024-05-19 00:41:15 +08:00
JJGadgets
60f4ca99be fix(authentik): rm pgbouncer 2024-05-18 06:07:14 +08:00
JJGadgets
27c5903c22 fix(authentik): pg-ca use pgbouncer CA 2024-05-18 05:56:00 +08:00
JJGadgets
6d9f6fed4b fix(authentik): app-template netpol name bug? 2024-05-18 05:45:39 +08:00
JJGadgets
16de557a96 Revert "fix(helm): update chart cilium to 1.15.5 (#831)" (#895)
This reverts commit 390ae5249d.
2024-05-18 05:18:20 +08:00
JJGadgets
c4a6b264c2 fix(authentik): disable probes for now as TODO, fix pg-ca name 2024-05-18 05:15:34 +08:00
JJGadgets
0475eb3bb2 feat(authentik): app-template (#894)
* feat(authentik): app-template

* feat(authentik): app-template

* feat(authentik): app-template

* feat(authentik): app-template

* feat(authentik): app-template

* feat(authentik): app-template

* feat(authentik): app-template

* feat(authentik): app-template
2024-05-18 04:50:51 +08:00
tinfoild[bot]
e9a0cf3a81 chore(container): update image docker.io/searxng/searxng to 75f2824 (#893)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-17 15:29:30 +00:00
tinfoild[bot]
86e9e27ee2 chore(container): update image docker.io/searxng/searxng to b07ef2d (#892)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-17 14:50:42 +00:00
tinfoild[bot]
bd85542ae7 chore(container): update image ghcr.io/thelounge/thelounge to 8becb60 (#891)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-17 09:35:16 +00:00
tinfoild[bot]
7b7c93eaf7 chore(container): update image docker.io/searxng/searxng to 2fa3ede (#890)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-17 07:39:31 +00:00
JJGadgets
6c1125c9f7 fix(flux): podAffinity, cleanup 2024-05-17 10:49:58 +08:00
JJGadgets
5fcbf5515d feat(flux): use localhost version 2024-05-17 10:43:09 +08:00
JJGadgets
ad4d1c0220 feat(flux): localhost hostNetwork 2024-05-17 10:35:11 +08:00
tinfoild[bot]
724a1deb2c fix(container): update image docker.io/mpepping/cyberchef to v10.18.6 (#889)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-17 01:24:12 +00:00
tinfoild[bot]
a27694a9bd feat(container): update image ghcr.io/nicolaka/netshoot to v0.13 (#882)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-16 19:31:30 +00:00
tinfoild[bot]
88cf551cb4 fix(github-action): update actions/checkout action to v4.1.6 (#887)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-16 18:24:18 +00:00
tinfoild[bot]
7e227770e3 fix(container): update image ghcr.io/paperless-ngx/paperless-ngx to v2.8.6 (#866)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-16 17:21:19 +00:00
tinfoild[bot]
890e38ee2c fix(container): update image docker.io/owncloud/ocis to v5.0.4 (#871)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-16 17:16:55 +00:00
tinfoild[bot]
d72ec14a29 chore(container): update image public.ecr.aws/docker/library/redis to 5a93f6b (#870)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-16 16:15:02 +00:00
JJGadgets
7004140fc1 fix(cilium): hubble eventQueueSize 2024-05-16 23:21:08 +08:00
tinfoild[bot]
dd6d939944 chore(container): update image docker.io/searxng/searxng to 6e41850 (#879)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-16 15:16:30 +00:00
tinfoild[bot]
4b1aea328a fix(container): update image ghcr.io/coder/code-server to v4.89.1 (#874)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-16 15:16:07 +00:00
tinfoild[bot]
390ae5249d fix(helm): update chart cilium to 1.15.5 (#831)
Co-authored-by: tinfoild[bot] <140665299+tinfoild[bot]@users.noreply.github.com>
2024-05-16 23:05:57 +08:00