Compare commits

...
Author SHA1 Message Date
Gitea Actions Bot 71e30c1115 Auto-update README with current k8s applications
Keycloak Terraform / Terraform (pull_request) Successful in 21s
Generated by CI/CD workflow on 2026-08-05 12:45:16

This PR updates the README.md file with the current list of applications found in the k8s/ directory structure.
2026-08-05 12:45:16 +00:00
Ultradesu d41171955b Moved traefik-ai to kube-system-custom, fixed lan-play ingress
Check with kubeconform / lint (push) Successful in 7s
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Successful in 7s
Auto-update README / Generate README and Create MR (push) Successful in 9s
2026-08-05 13:44:30 +01:00
Ultradesu f038016d46 Added UK lan-play instance
Keycloak Terraform / Terraform (push) Successful in 26s
Update Kubernetes Services Wiki / Generate and Update K8s Wiki (push) Successful in 15s
Check with kubeconform / lint (push) Successful in 11s
Auto-update README / Generate README and Create MR (push) Successful in 18s
2026-08-05 12:56:42 +01:00
10 changed files with 242 additions and 6 deletions
+5
View File
@@ -42,7 +42,10 @@ ArgoCD homelab project
| Application | Status |
| :--- | :---: |
| **amnezia** | [![amnezia](https://ag.hexor.cy/api/badge?name=amnezia&revision=true)](https://ag.hexor.cy/applications/argocd/amnezia) |
| **comfyui** | [![comfyui](https://ag.hexor.cy/api/badge?name=comfyui&revision=true)](https://ag.hexor.cy/applications/argocd/comfyui) |
| **doka2-lobby-list** | [![doka2-lobby-list](https://ag.hexor.cy/api/badge?name=doka2-lobby-list&revision=true)](https://ag.hexor.cy/applications/argocd/doka2-lobby-list) |
| **firefly-iii** | [![firefly-iii](https://ag.hexor.cy/api/badge?name=firefly-iii&revision=true)](https://ag.hexor.cy/applications/argocd/firefly-iii) |
| **furumi** | [![furumi](https://ag.hexor.cy/api/badge?name=furumi&revision=true)](https://ag.hexor.cy/applications/argocd/furumi) |
| **gitea** | [![gitea](https://ag.hexor.cy/api/badge?name=gitea&revision=true)](https://ag.hexor.cy/applications/argocd/gitea) |
| **greece-notifier** | [![greece-notifier](https://ag.hexor.cy/api/badge?name=greece-notifier&revision=true)](https://ag.hexor.cy/applications/argocd/greece-notifier) |
@@ -52,7 +55,9 @@ ArgoCD homelab project
| **jellyfin** | [![jellyfin](https://ag.hexor.cy/api/badge?name=jellyfin&revision=true)](https://ag.hexor.cy/applications/argocd/jellyfin) |
| **k8s-secrets** | [![k8s-secrets](https://ag.hexor.cy/api/badge?name=k8s-secrets&revision=true)](https://ag.hexor.cy/applications/argocd/k8s-secrets) |
| **khm** | [![khm](https://ag.hexor.cy/api/badge?name=khm&revision=true)](https://ag.hexor.cy/applications/argocd/khm) |
| **lan-play** | [![lan-play](https://ag.hexor.cy/api/badge?name=lan-play&revision=true)](https://ag.hexor.cy/applications/argocd/lan-play) |
| **lidarr** | [![lidarr](https://ag.hexor.cy/api/badge?name=lidarr&revision=true)](https://ag.hexor.cy/applications/argocd/lidarr) |
| **llamacpp** | [![llamacpp](https://ag.hexor.cy/api/badge?name=llamacpp&revision=true)](https://ag.hexor.cy/applications/argocd/llamacpp) |
| **matrix** | [![matrix](https://ag.hexor.cy/api/badge?name=matrix&revision=true)](https://ag.hexor.cy/applications/argocd/matrix) |
| **mtproxy** | [![mtproxy](https://ag.hexor.cy/api/badge?name=mtproxy&revision=true)](https://ag.hexor.cy/applications/argocd/mtproxy) |
| **n8n** | [![n8n](https://ag.hexor.cy/api/badge?name=n8n&revision=true)](https://ag.hexor.cy/applications/argocd/n8n) |
-1
View File
@@ -10,7 +10,6 @@ resources:
- postgres.yaml
- storage.yaml
- storage-prep.yaml
- traefik-ai.yaml
- network-policy.yaml
helmCharts:
+20
View File
@@ -0,0 +1,20 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: lan-play
namespace: argocd
spec:
project: apps
destination:
namespace: lan-play
server: https://kubernetes.default.svc
source:
repoURL: ssh://git@gt.hexor.cy:30022/ab/homelab.git
targetRevision: HEAD
path: k8s/apps/lan-play
syncPolicy:
automated:
selfHeal: true
prune: true
syncOptions:
- CreateNamespace=true
+63
View File
@@ -0,0 +1,63 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: lan-play
labels:
app.kubernetes.io/name: lan-play
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/name: lan-play
template:
metadata:
labels:
app.kubernetes.io/name: lan-play
spec:
nodeSelector:
kubernetes.io/hostname: ai.tail2fe2d.ts.net
tolerations:
- key: workload
operator: Equal
value: ai
effect: NoSchedule
containers:
- name: lan-play
image: ultradesu/lan-play:latest
imagePullPolicy: Always
ports:
- name: http
containerPort: 8080
protocol: TCP
volumeMounts:
- name: media
mountPath: /media
readinessProbe:
tcpSocket:
port: http
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
tcpSocket:
port: http
initialDelaySeconds: 20
periodSeconds: 30
resources:
requests:
cpu: "2"
memory: 2Gi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
volumes:
- name: media
hostPath:
path: /k8s/lan-play
type: DirectoryOrCreate
securityContext:
seccompProfile:
type: RuntimeDefault
+63
View File
@@ -0,0 +1,63 @@
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: lan-play-auth
spec:
forwardAuth:
address: http://auth-proxy.auth-proxy.svc:80/auth
trustForwardHeader: true
authResponseHeaders:
- X-Auth-Request-User
- X-Auth-Request-Email
- X-Auth-Request-Groups
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: lan-play-public
spec:
entryPoints:
- websecure
routes:
- match: Host(`lp.hexor.cy`)
kind: Rule
middlewares:
- name: lan-play-auth
services:
- name: lan-play
port: 80
tls:
secretName: lan-play-tls
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: lan-play-tls
spec:
secretName: lan-play-tls
issuerRef:
name: letsencrypt
kind: ClusterIssuer
dnsNames:
- lp.hexor.cy
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: lan-play-local
labels:
firefly.hexor.cy/private-ai: "true"
annotations:
kubernetes.io/ingress.class: traefik-ai
spec:
rules:
- host: video.lan
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: lan-play
port:
number: 80
+8
View File
@@ -0,0 +1,8 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- app.yaml
- deployment.yaml
- service.yaml
- ingress.yaml
+15
View File
@@ -0,0 +1,15 @@
apiVersion: v1
kind: Service
metadata:
name: lan-play
labels:
app.kubernetes.io/name: lan-play
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: lan-play
ports:
- name: http
port: 80
targetPort: http
protocol: TCP
@@ -7,6 +7,7 @@ resources:
- coredns-internal-resolve.yaml
- https-middleware.yaml
- node-external-ip-labeler.yaml
- traefik-ai.yaml
helmCharts:
- name: csi-driver-nfs
@@ -9,11 +9,13 @@ apiVersion: v1
kind: ServiceAccount
metadata:
name: traefik-ai
namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: traefik-ai
namespace: firefly-iii
rules:
- apiGroups:
- ""
@@ -52,6 +54,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: traefik-ai
namespace: firefly-iii
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
@@ -59,11 +62,65 @@ roleRef:
subjects:
- kind: ServiceAccount
name: traefik-ai
namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: traefik-ai
namespace: lan-play
rules:
- apiGroups:
- ""
resources:
- services
- secrets
- endpoints
verbs:
- get
- list
- watch
- apiGroups:
- discovery.k8s.io
resources:
- endpointslices
verbs:
- get
- list
- watch
- apiGroups:
- networking.k8s.io
resources:
- ingresses
verbs:
- get
- list
- watch
- apiGroups:
- networking.k8s.io
resources:
- ingresses/status
verbs:
- update
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: traefik-ai
namespace: lan-play
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: traefik-ai
subjects:
- kind: ServiceAccount
name: traefik-ai
namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: firefly-traefik-ai
name: traefik-ai
rules:
- apiGroups:
- ""
@@ -85,20 +142,21 @@ rules:
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: firefly-traefik-ai
name: traefik-ai
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: firefly-traefik-ai
name: traefik-ai
subjects:
- kind: ServiceAccount
name: traefik-ai
namespace: firefly-iii
namespace: kube-system
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: traefik-ai
namespace: kube-system
labels:
app.kubernetes.io/name: traefik-ai
spec:
@@ -130,7 +188,7 @@ spec:
args:
- --entrypoints.web.address=192.168.1.117:80
- --providers.kubernetesingress=true
- --providers.kubernetesingress.namespaces=firefly-iii
- --providers.kubernetesingress.namespaces=firefly-iii,lan-play
- --providers.kubernetesingress.ingressclass=traefik-ai
- --providers.kubernetesingress.labelselector=firefly.hexor.cy/private-ai=true
- --providers.kubernetescrd=false
+4
View File
@@ -24,6 +24,10 @@ proxy_applications = {
domain = "import.hexor.cy"
allowed_groups = ["hexor-admin"]
}
LanPlay = {
domain = "lp.hexor.cy"
allowed_groups = ["hexor-admin"]
}
}
oauth2_applications = {