Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a44c143153 | ||
|
|
5768a4ff3b | ||
|
|
7ce98c4982 | ||
|
|
18f2654ff1 | ||
|
|
2fb63dded8 | ||
|
|
46bf1dc41b | ||
|
|
eda408aaea | ||
|
|
7b9da9236f | ||
|
|
f2a607fda1 | ||
|
|
d57bb01608 | ||
|
|
76f77fbc56 | ||
|
|
e90efbd016 | ||
|
|
b0378ffb40 | ||
|
|
5c2e7d0e33 | ||
|
|
b9052a99f1 |
@@ -8,3 +8,4 @@ resources:
|
||||
- ingress.yaml
|
||||
- deployment.yaml
|
||||
- servicemonitor.yaml
|
||||
- socks-proxy.yaml
|
||||
|
||||
@@ -0,0 +1,106 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: furumi-socks-proxy
|
||||
labels:
|
||||
app: furumi-socks-proxy
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: furumi-socks-proxy
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: furumi-socks-proxy
|
||||
spec:
|
||||
nodeSelector:
|
||||
kubernetes.io/hostname: ai.tail2fe2d.ts.net
|
||||
tolerations:
|
||||
- key: workload
|
||||
operator: Equal
|
||||
value: ai
|
||||
effect: NoSchedule
|
||||
containers:
|
||||
- name: socks-proxy
|
||||
image: serjs/go-socks5-proxy:v0.0.4
|
||||
imagePullPolicy: IfNotPresent
|
||||
env:
|
||||
- name: REQUIRE_AUTH
|
||||
value: "true"
|
||||
- name: PROXY_USER
|
||||
value: furumi
|
||||
- name: PROXY_PASSWORD
|
||||
value: furumi
|
||||
- name: PROXY_PORT
|
||||
value: "1080"
|
||||
ports:
|
||||
- name: socks5
|
||||
containerPort: 1080
|
||||
protocol: TCP
|
||||
readinessProbe:
|
||||
tcpSocket:
|
||||
port: socks5
|
||||
initialDelaySeconds: 2
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 2
|
||||
failureThreshold: 3
|
||||
livenessProbe:
|
||||
tcpSocket:
|
||||
port: socks5
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 2
|
||||
failureThreshold: 3
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 16Mi
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 64Mi
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
readOnlyRootFilesystem: true
|
||||
runAsNonRoot: true
|
||||
securityContext:
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: furumi-socks-proxy
|
||||
labels:
|
||||
app: furumi-socks-proxy
|
||||
spec:
|
||||
type: ClusterIP
|
||||
selector:
|
||||
app: furumi-socks-proxy
|
||||
ports:
|
||||
- name: socks5
|
||||
protocol: TCP
|
||||
port: 1080
|
||||
targetPort: socks5
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: furumi-socks-proxy-ingress
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels:
|
||||
app: furumi-socks-proxy
|
||||
policyTypes:
|
||||
- Ingress
|
||||
ingress:
|
||||
- from:
|
||||
- podSelector:
|
||||
matchLabels:
|
||||
app: furumi-player
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 1080
|
||||
@@ -48,7 +48,7 @@ spec:
|
||||
value: "true"
|
||||
- name: GITEA__service__CAPTCHA_TYPE
|
||||
value: "cfturnstile"
|
||||
- name: GITEA__webhook__ALLOWED_HOST_LIST
|
||||
- name: GITEA__security__ALLOWED_HOST_LIST
|
||||
value: "*"
|
||||
envFrom:
|
||||
- secretRef:
|
||||
|
||||
@@ -70,6 +70,7 @@ spec:
|
||||
action: suggest
|
||||
template: "{{ `{{ user.email }}` }}"
|
||||
set_email_verification: always
|
||||
on_conflict: replace
|
||||
data:
|
||||
- secretKey: oauth_client_id
|
||||
sourceRef:
|
||||
@@ -93,4 +94,3 @@ spec:
|
||||
metadataPolicy: None
|
||||
key: ca76867f-49f3-4a30-9ef3-b05af35ee49a
|
||||
property: fields[1].value
|
||||
on_conflict: replace
|
||||
|
||||
@@ -18,7 +18,7 @@ spec:
|
||||
spec:
|
||||
nodeSelector:
|
||||
kubernetes.io/os: linux
|
||||
kubernetes.io/hostname: master.tail2fe2d.ts.net
|
||||
# kubernetes.io/hostname: master.tail2fe2d.ts.net
|
||||
volumes:
|
||||
- name: data
|
||||
persistentVolumeClaim:
|
||||
|
||||
@@ -10,7 +10,7 @@ resources:
|
||||
helmCharts:
|
||||
- name: argo-cd
|
||||
repo: https://argoproj.github.io/argo-helm
|
||||
version: 10.2.1
|
||||
version: 10.6.0
|
||||
releaseName: argocd
|
||||
namespace: argocd
|
||||
valuesFile: values.yaml
|
||||
|
||||
@@ -10,7 +10,7 @@ resources:
|
||||
helmCharts:
|
||||
- name: cert-manager
|
||||
repo: https://charts.jetstack.io
|
||||
version: 1.20.0
|
||||
version: 1.21.1
|
||||
releaseName: cert-manager
|
||||
namespace: cert-manager
|
||||
valuesFile: values.yaml
|
||||
|
||||
@@ -7,7 +7,7 @@ resources:
|
||||
helmCharts:
|
||||
- name: external-secrets
|
||||
repo: https://charts.external-secrets.io
|
||||
version: 1.1.0
|
||||
version: 2.10.0
|
||||
releaseName: external-secrets
|
||||
namespace: external-secrets
|
||||
valuesFile: values.yaml
|
||||
|
||||
@@ -9,7 +9,7 @@ resources:
|
||||
helmCharts:
|
||||
- name: keycloakx
|
||||
repo: https://codecentric.github.io/helm-charts
|
||||
version: 7.1.11
|
||||
version: 7.3.1
|
||||
releaseName: keycloak
|
||||
namespace: keycloak
|
||||
valuesFile: values.yaml
|
||||
|
||||
@@ -7,7 +7,7 @@ kind: Kustomization
|
||||
helmCharts:
|
||||
- name: longhorn
|
||||
repo: https://charts.longhorn.io
|
||||
version: 1.12.0
|
||||
version: 1.12.1
|
||||
releaseName: longhorn
|
||||
namespace: longhorn-system
|
||||
valuesFile: values.yaml
|
||||
|
||||
@@ -14,15 +14,15 @@ resources:
|
||||
helmCharts:
|
||||
- name: kube-prometheus-stack
|
||||
repo: https://prometheus-community.github.io/helm-charts
|
||||
version: 84.3.0
|
||||
version: 88.6.2
|
||||
releaseName: prometheus
|
||||
namespace: prometheus
|
||||
valuesFile: prom-values.yaml
|
||||
includeCRDs: true
|
||||
|
||||
- name: loki
|
||||
repo: https://grafana.github.io/helm-charts
|
||||
version: 6.29.0
|
||||
repo: https://grafana-community.github.io/helm-charts
|
||||
version: 18.11.7
|
||||
releaseName: loki
|
||||
namespace: prometheus
|
||||
valuesFile: loki-values.yaml
|
||||
@@ -30,7 +30,7 @@ helmCharts:
|
||||
|
||||
- name: promtail
|
||||
repo: https://grafana.github.io/helm-charts
|
||||
version: 6.16.6
|
||||
version: 6.17.1
|
||||
releaseName: promtail
|
||||
namespace: prometheus
|
||||
valuesFile: promtail-values.yaml
|
||||
|
||||
@@ -75,6 +75,10 @@ prometheus:
|
||||
static_configs:
|
||||
- targets: ['prom-a2s-exporter.counter-strike.svc:9841']
|
||||
labels: {instance: master}
|
||||
- job_name: macos_prom_exporter
|
||||
static_configs:
|
||||
- targets: ['macbook-pro.tail2fe2d.ts.net:9100']
|
||||
labels: {instance: ultrabook-pro}
|
||||
|
||||
retention: "380d"
|
||||
retentionSize: "0"
|
||||
@@ -91,6 +95,11 @@ prometheus:
|
||||
|
||||
grafana:
|
||||
enabled: true
|
||||
|
||||
sidecar:
|
||||
datasources:
|
||||
alertmanager:
|
||||
uid: ff9iga3xqregwc
|
||||
|
||||
serviceAccount:
|
||||
create: true
|
||||
|
||||
@@ -18,7 +18,7 @@ spec:
|
||||
serviceAccountName: system-upgrade
|
||||
upgrade:
|
||||
image: rancher/k3s-upgrade
|
||||
version: v1.36.1+k3s1
|
||||
version: v1.36.4+k3s1
|
||||
---
|
||||
# Agent plan
|
||||
apiVersion: upgrade.cattle.io/v1
|
||||
@@ -43,4 +43,4 @@ spec:
|
||||
serviceAccountName: system-upgrade
|
||||
upgrade:
|
||||
image: rancher/k3s-upgrade
|
||||
version: v1.36.1+k3s1
|
||||
version: v1.36.4+k3s1
|
||||
|
||||
Reference in New Issue
Block a user