Enabled auto sync openbanking
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Successful in 15s
Check with kubeconform / lint (push) Successful in 10s
Auto-update README / Generate README and Create MR (push) Successful in 8s

This commit is contained in:
Aleksandr Bogomiakov
2026-08-01 13:24:23 +01:00
parent 80b792ce8c
commit 2583236f6d
4 changed files with 120 additions and 0 deletions
@@ -0,0 +1,96 @@
apiVersion: batch/v1
kind: CronJob
metadata:
name: firefly-data-importer-sync
labels:
app.kubernetes.io/name: firefly-data-importer-sync
spec:
schedule: "17 */6 * * *"
timeZone: Europe/London
concurrencyPolicy: Forbid
startingDeadlineSeconds: 1800
successfulJobsHistoryLimit: 2
failedJobsHistoryLimit: 5
jobTemplate:
spec:
backoffLimit: 1
activeDeadlineSeconds: 1200
template:
metadata:
labels:
app.kubernetes.io/name: firefly-data-importer-sync
spec:
automountServiceAccountToken: false
restartPolicy: Never
nodeSelector:
kubernetes.io/hostname: ai.tail2fe2d.ts.net
tolerations:
- key: workload
operator: Equal
value: ai
effect: NoSchedule
containers:
- name: data-importer-sync
image: fireflyiii/data-importer:version-2.3.4
imagePullPolicy: IfNotPresent
command:
- php
- artisan
- importer:import
- /import/import.json
env:
- name: FIREFLY_III_URL
value: http://firefly-iii
- name: VANITY_URL
value: http://ff.lan
- name: FIREFLY_III_ACCESS_TOKEN
valueFrom:
secretKeyRef:
name: firefly-data-importer-secrets
key: FIREFLY_III_ACCESS_TOKEN
- name: ENABLE_BANKING_APP_ID
valueFrom:
secretKeyRef:
name: firefly-data-importer-secrets
key: ENABLE_BANKING_APP_ID
- name: ENABLE_BANKING_PRIVATE_KEY
valueFrom:
secretKeyRef:
name: firefly-data-importer-secrets
key: ENABLE_BANKING_PRIVATE_KEY
- name: IMPORT_DIR_ALLOWLIST
value: /import
- name: TZ
value: Europe/London
- name: APP_ENV
value: production
- name: APP_DEBUG
value: "false"
- name: LOG_LEVEL
value: notice
volumeMounts:
- name: import-config
mountPath: /import
readOnly: true
resources:
requests:
cpu: 50m
memory: 128Mi
limits:
cpu: "1"
memory: 512Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
volumes:
- name: import-config
secret:
secretName: firefly-data-importer-secrets
items:
- key: import.json
path: import.json
securityContext:
seccompProfile:
type: RuntimeDefault
@@ -66,6 +66,10 @@ spec:
-----BEGIN PRIVATE KEY-----
{{ .private_key | replace "-----BEGIN PRIVATE KEY-----" "" | replace "-----END PRIVATE KEY-----" "" | replace " " "" | trim }}
-----END PRIVATE KEY-----
FIREFLY_III_ACCESS_TOKEN: |-
{{ .firefly_access_token }}
import.json: |-
{{ .import_config }}
data:
- secretKey: app_id
sourceRef:
@@ -83,3 +87,19 @@ spec:
remoteRef:
key: a1867c81-715c-47cd-978d-14ea5bcedea9
property: fields[4].value
- secretKey: firefly_access_token
sourceRef:
storeRef:
name: vaultwarden-login
kind: ClusterSecretStore
remoteRef:
key: a1867c81-715c-47cd-978d-14ea5bcedea9
property: fields[5].value
- secretKey: import_config
sourceRef:
storeRef:
name: vaultwarden-login
kind: ClusterSecretStore
remoteRef:
key: a1867c81-715c-47cd-978d-14ea5bcedea9
property: fields[6].value
+1
View File
@@ -4,6 +4,7 @@ kind: Kustomization
resources:
- app.yaml
- data-importer.yaml
- data-importer-sync.yaml
- data-importer-ingress.yaml
- external-secrets.yaml
- postgres.yaml
+3
View File
@@ -22,6 +22,9 @@ spec:
- podSelector:
matchLabels:
app.kubernetes.io/name: firefly-data-importer
- podSelector:
matchLabels:
app.kubernetes.io/name: firefly-data-importer-sync
# hostNetwork traffic is seen as node traffic rather than Pod traffic.
- ipBlock:
cidr: 192.168.1.117/32