apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - app.yaml - external-secrets.yaml - postgres.yaml - storage.yaml - storage-prep.yaml - traefik-ai.yaml - network-policy.yaml helmCharts: - name: firefly-iii repo: https://harish2k01.github.io/helm-charts version: 0.1.2 releaseName: firefly-iii namespace: firefly-iii valuesFile: values.yaml includeCRDs: true patches: # Chart 0.1.2 requires postgres.enabled=true. Remove its StatefulSet and # make the generated database Service select the CloudNativePG instance. - target: group: apps version: v1 kind: StatefulSet name: firefly-iii-postgres patch: |- $patch: delete apiVersion: apps/v1 kind: StatefulSet metadata: name: firefly-iii-postgres - target: version: v1 kind: Service name: firefly-iii-postgres patch: |- - op: replace path: /spec/selector value: cnpg.io/cluster: firefly-postgres # The upstream chart does not expose scheduling settings for its CronJob. - target: group: batch version: v1 kind: CronJob name: firefly-iii-cron patch: |- - op: add path: /spec/jobTemplate/spec/template/spec/nodeSelector value: kubernetes.io/hostname: ai.tail2fe2d.ts.net - op: add path: /spec/jobTemplate/spec/template/spec/tolerations value: - key: workload operator: Equal value: ai effect: NoSchedule # A second independent filter in addition to ingressClassName. - target: group: networking.k8s.io version: v1 kind: Ingress name: firefly-iii patch: |- - op: add path: /metadata/labels/firefly.hexor.cy~1private-ai value: "true" # The shared Traefik has the same controller identifier and can discover # IngressClass objects. The explicit annotation partitions this Ingress # so only the instance configured with ingressclass=traefik-ai accepts it. - op: add path: /metadata/annotations/kubernetes.io~1ingress.class value: traefik-ai - op: remove path: /spec/ingressClassName