Compare commits

...

7 Commits

Author SHA1 Message Date
Gitea Actions Bot 429a073faf Auto-update README with current k8s applications
Keycloak Terraform / Terraform (pull_request) Successful in 20s
Generated by CI/CD workflow on 2026-06-20 14:12:55

This PR updates the README.md file with the current list of applications found in the k8s/ directory structure.
2026-06-20 14:12:55 +00:00
ab 78c1519398 Adde prom auth ingress
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Successful in 6s
Check with kubeconform / lint (push) Successful in 7s
Auto-update README / Generate README and Create MR (push) Successful in 7s
2026-06-20 17:12:03 +03:00
ab d8a5a916e1 Added prom.hexor.cy rsauth-proxy app
Keycloak Terraform / Terraform (push) Successful in 22s
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Successful in 2m35s
2026-06-20 16:55:39 +03:00
ab a840dd674a Update k8s/core/prom-stack/prom-values.yaml
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Successful in 8s
Check with kubeconform / lint (push) Successful in 8s
Auto-update README / Generate README and Create MR (push) Successful in 11s
2026-06-19 17:45:35 +00:00
ab a094d3b925 Added Gitea captcha
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Successful in 5s
Check with kubeconform / lint (push) Successful in 5s
Auto-update README / Generate README and Create MR (push) Successful in 5s
2026-06-18 02:32:33 +01:00
ab 9508a8483c Added Gitea captcha
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Successful in 6s
Check with kubeconform / lint (push) Successful in 5s
Auto-update README / Generate README and Create MR (push) Successful in 5s
2026-06-18 02:30:49 +01:00
ab c5919259f6 Added Gitea captcha
Check with kubeconform / lint (push) Successful in 14s
Auto-update README / Generate README and Create MR (push) Failing after 2m57s
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Failing after 16m35s
2026-06-18 02:27:24 +01:00
7 changed files with 68 additions and 32 deletions
+2
View File
@@ -42,6 +42,7 @@ ArgoCD homelab project
| Application | Status |
| :--- | :---: |
| **amnezia** | [![amnezia](https://ag.hexor.cy/api/badge?name=amnezia&revision=true)](https://ag.hexor.cy/applications/argocd/amnezia) |
| **comfyui** | [![comfyui](https://ag.hexor.cy/api/badge?name=comfyui&revision=true)](https://ag.hexor.cy/applications/argocd/comfyui) |
| **furumi** | [![furumi](https://ag.hexor.cy/api/badge?name=furumi&revision=true)](https://ag.hexor.cy/applications/argocd/furumi) |
| **gitea** | [![gitea](https://ag.hexor.cy/api/badge?name=gitea&revision=true)](https://ag.hexor.cy/applications/argocd/gitea) |
@@ -53,6 +54,7 @@ ArgoCD homelab project
| **k8s-secrets** | [![k8s-secrets](https://ag.hexor.cy/api/badge?name=k8s-secrets&revision=true)](https://ag.hexor.cy/applications/argocd/k8s-secrets) |
| **khm** | [![khm](https://ag.hexor.cy/api/badge?name=khm&revision=true)](https://ag.hexor.cy/applications/argocd/khm) |
| **lidarr** | [![lidarr](https://ag.hexor.cy/api/badge?name=lidarr&revision=true)](https://ag.hexor.cy/applications/argocd/lidarr) |
| **llamacpp** | [![llamacpp](https://ag.hexor.cy/api/badge?name=llamacpp&revision=true)](https://ag.hexor.cy/applications/argocd/llamacpp) |
| **matrix** | [![matrix](https://ag.hexor.cy/api/badge?name=matrix&revision=true)](https://ag.hexor.cy/applications/argocd/matrix) |
| **mtproxy** | [![mtproxy](https://ag.hexor.cy/api/badge?name=mtproxy&revision=true)](https://ag.hexor.cy/applications/argocd/mtproxy) |
| **n8n** | [![n8n](https://ag.hexor.cy/api/badge?name=n8n&revision=true)](https://ag.hexor.cy/applications/argocd/n8n) |
+4 -4
View File
@@ -41,18 +41,18 @@ spec:
- name: GITEA__service__REGISTER_MANUAL_CONFIRM
value: "true"
- name: GITEA__service__ENABLE_CAPTCHA
value: "false"
- name: GITEA__service__REQUIRE_CAPTCHA_FOR_LOGIN
value: "true"
- name: GITEA__service__REQUIRE_CAPTCHA_FOR_LOGIN
value: "false"
- name: GITEA__service__REQUIRE_EXTERNAL_REGISTRATION_CAPTCHA
value: "true"
- name: GITEA__service__CAPTCHA_TYPE
value: "hcaptcha"
value: "cfturnstile"
- name: GITEA__webhook__ALLOWED_HOST_LIST
value: "*"
envFrom:
- secretRef:
name: gitea-recapcha-creds
name: gitea-runner-act-runner-secrets
ports:
- name: http
containerPort: 3000
+10 -25
View File
@@ -13,6 +13,10 @@ spec:
data:
token: |-
{{ .password }}
GITEA__service__CF_TURNSTILE_SITEKEY: |-
{{ .CF_TURNSTILE_SITEKEY }}
GITEA__service__CF_TURNSTILE_SECRET: |-
{{ .CF_TURNSTILE_SECRET }}
data:
- secretKey: password
sourceRef:
@@ -22,38 +26,19 @@ spec:
remoteRef:
key: e475b5ab-ea3c-48a5-bb4c-a6bc552fc064
property: login.password
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: gitea-recapcha-creds
spec:
refreshInterval: 1m
target:
name: gitea-recapcha-creds
deletionPolicy: Delete
template:
type: Opaque
data:
GITEA__service__HCAPTCHA_SITEKEY: |-
{{ .HCAPTCHA_SITEKEY }}
GITEA__service__HCAPTCHA_SECRET: |-
{{ .HCAPTCHA_SECRET }}
data:
- secretKey: HCAPTCHA_SITEKEY
- secretKey: CF_TURNSTILE_SITEKEY
sourceRef:
storeRef:
name: vaultwarden-login
kind: ClusterSecretStore
remoteRef:
key: 89c8d8d2-6b53-42c5-805f-38a341ef163e
property: login.username
- secretKey: HCAPTCHA_SECRET
key: e475b5ab-ea3c-48a5-bb4c-a6bc552fc064
property: fields[0].value
- secretKey: CF_TURNSTILE_SECRET
sourceRef:
storeRef:
name: vaultwarden-login
kind: ClusterSecretStore
remoteRef:
key: 89c8d8d2-6b53-42c5-805f-38a341ef163e
property: login.password
key: e475b5ab-ea3c-48a5-bb4c-a6bc552fc064
property: fields[1].value
+45
View File
@@ -0,0 +1,45 @@
---
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: auth-proxy
spec:
forwardAuth:
address: http://auth-proxy.auth-proxy.svc:80/auth
trustForwardHeader: true
authResponseHeaders:
- X-Auth-Request-User
- X-Auth-Request-Email
- X-Auth-Request-Groups
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: prometheus
annotations:
cert-manager.io/cluster-issuer: letsencrypt
spec:
entryPoints:
- websecure
routes:
- match: Host(`prom.hexor.cy`)
kind: Rule
middlewares:
- name: auth-proxy
services:
- name: prometheus-kube-prometheus-prometheus
port: 9090
tls:
secretName: prometheus-tls
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: prometheus-tls
spec:
secretName: prometheus-tls
issuerRef:
name: letsencrypt
kind: ClusterIssuer
dnsNames:
- prom.hexor.cy
+1
View File
@@ -4,6 +4,7 @@ kind: Kustomization
resources:
- persistentVolume.yaml
- external-secrets.yaml
- ingress.yaml
- grafana-alerting-configmap.yaml
- alertmanager-config.yaml
- dashboards/telemt-dashboard-cm.yaml
+2 -3
View File
@@ -1,4 +1,3 @@
alertmanager:
config:
global:
@@ -25,7 +24,7 @@ alertmanager:
{{ end }}
ingress:
enabled: true
enabled: false
ingressClassName: traefik
annotations:
cert-manager.io/cluster-issuer: letsencrypt
@@ -46,7 +45,7 @@ alertmanager:
prometheus:
ingress:
enabled: true
enabled: false
ingressClassName: traefik
annotations:
cert-manager.io/cluster-issuer: letsencrypt
+4
View File
@@ -16,6 +16,10 @@ proxy_applications = {
domain = "pass.hexor.cy"
allowed_groups = ["hexor-admin", "app-pass"]
}
Prometheus = {
domain = "prom.hexor.cy"
allowed_groups = ["hexor-admin"]
}
}
oauth2_applications = {