Vegard Hagen
004c3cf1e2
fix(authelia): obfuscate smtp relay username to avoid getting "leaked" credentials emails
...
Also rotate both username and password
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-31 20:05:45 +02:00
Vegard Hagen
0ff3a46685
fix(email): change provider to mailersend
...
Mail from Brevo includes a tracking pixel that you can't get rid of. To quote Lemongrab: "Unacceptable!"
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-29 23:40:36 +02:00
Vegard Hagen
08c01b3fbc
fix(email): change provider to brevo
...
SendGrid started charging money for basic functionality, so changing to free tier in Brevo
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-29 22:36:32 +02:00
Vegard Hagen
285d9b075e
feat(monitoring): enable nodeExporter
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-28 18:21:58 +02:00
Vegard Hagen
5c3395210a
feat(argocd): add metrics and grafana dashboard
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-26 15:38:49 +02:00
Vegard Hagen
9fc5f0f0c4
feat(grafana): oauth/oidc integration
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-26 14:34:36 +02:00
Vegard Hagen
559b4c3d24
feat(cilium): add grafana dashboards
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-25 22:29:24 +02:00
Vegard Hagen
e864098520
fix(monitoring): try server-side apply of kube-prometheus-stack again
...
Try without an extra Application resource again
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-25 17:18:08 +02:00
Vegard Hagen
09966b457c
fix(qbit): change port
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-24 20:34:25 +02:00
Vegard Hagen
c1b1719e8c
fix(cilium): disable alpn
...
I have a hunch that this somehow interferes with Argo CD.
The Argo CD login page shows up in Safari 18.5, Brave 1.80.120 and
Firefox 140.0.4.
After logging in using Authelia (OIDC), Argo CD starts to display 404
error in Brave and Firefox, but it works in Safari.
Clearing site data makes the login page show up in Brave and Firefox
again.
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-21 10:27:13 +02:00
Vegard Hagen
cb66358a0e
fix(argocd): remove grpcroute
...
the tlsroute should be able to handle grpc-connections, having both seem to create some trouble
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-20 13:30:16 +02:00
Vegard Hagen
3d2de963b5
fix(netbird): clean up configuration
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-20 13:18:31 +02:00
Vegard Hagen
eea1d4a58b
fix(adguard): update config schema version
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-20 13:18:31 +02:00
Vegard Hagen
907c9876fe
fix(dns): remove special entries for proxmox and truenas
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-20 13:18:31 +02:00
Vegard Hagen
a2d0e263f0
fix(gateway): remove separate tls-passthrough gateway
...
It appears to work without a separate Gateway now. Should investigate if https://github.com/cilium/cilium/issues/32371 can be closed
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-20 13:18:31 +02:00
Vegard Hagen
a788e2e12c
feat(argocd): enable argocd cli
...
Also change Argo CD to use a proper certificate
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-20 13:18:31 +02:00
Vegard Hagen
f13ee5e73f
feat(lldap): clean up config
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-20 13:18:19 +02:00
Vegard Hagen
6c37523f6f
feat(ci): run tofu format inside devimage
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-19 19:02:39 +02:00
Karteek and Vegard Hagen
f457ce825f
feat: create GCS bucket to store remote state
...
feat: Add gcloud tofu code to automatically create gcs buckets to use as remote backend. Also setup workload identity federation, and store it to infisical, to use it in github actions.
Signed-off-by: Karteek <[email protected] >
feat(tofu): modularise gcs-state
Create a Google Cloud Storage (GCS) bucket and store the state for doing it in the bucket itself
Signed-off-by: Vegard Hagen <[email protected] >
feat(wif): enable workload identify federation
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-19 18:54:05 +02:00
7e388f55d7
chore(renovate): renovate 2025-07-18
...
chore(deps): update helm release cert-manager to v1.18.2 (#293 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update proxmox-csi-plugin docker tag to v0.3.11 (#311 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update cloudflare/cloudflared docker tag to v2025.7.0 (#314 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update dependency siderolabs/talos to v1.10.5 (#331 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update media containers (#328 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update ghcr.io/prometheus-community/charts/kube-prometheus-stack docker tag to v73.2.3 (#332 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update cilium (#333 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update actions/checkout action to v4.2.2 (#336 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update docker.io/adguard/adguardhome docker tag to v0.107.63 (#338 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update dependency kubernetes/kubernetes to v1.33.3 (#335 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update ghcr.io/authelia/authelia docker tag to v4.39.5 (#339 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update ghcr.io/home-operations/qbittorrent docker tag to v5.1.2 (#340 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update helm release authelia to v0.10.39 (#341 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update registry.k8s.io/git-sync/git-sync docker tag to v4.4.2 (#342 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update sealed-secrets docker tag to v2.5.16 (#343 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update ghcr.io/advplyr/audiobookshelf docker tag to v2.26.1 (#344 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update netbird (#345 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update terraform proxmox to v0.80.0 (#346 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update ghcr.io/home-operations/prowlarr docker tag to v2 (#347 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update ghcr.io/prometheus-community/charts/kube-prometheus-stack docker tag to v75 (#348 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: Vegard Hagen <[email protected] >
chore(deps): update helm release authelia to v0.10.41 (#349 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-07-19 18:51:55 +02:00
Vegard Hagen
88c39b2b50
feat(devcontainer): add kubeconform
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-18 19:56:18 +02:00
Vegard Hagen
b1214dc993
feat(devcontainer): add Node
...
Many GitHub actions rely on Node. If we want to run the actions inside this image we need it
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-18 19:09:49 +02:00
Vegard Stenhjem Hagen
eaf7c15a8f
feat(ci): only run tofu fmt when necessary
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-16 23:54:47 +02:00
Vegard Hagen
53ef70cc44
feat(devcontainer): absorb common-utils feature into Containerfile
...
This will hopefully cut down on build-time and was an interesting exercise
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-16 23:54:42 +02:00
Vegard Hagen
a3c5313f74
feat(devcontainer): do more in Containerfile for thinner image
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-14 23:26:34 +02:00
Vegard Hagen
cdea7e1719
fix(ci): use devcontainer image directly for tofu checks
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-14 18:52:39 +02:00
Vegard Hagen
66dad81d84
feat(devcontainer): split into build and run configfiles
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-14 13:38:30 +02:00
Vegard Hagen
da7d2d4a54
fix(devcontainer): add timeout for build job
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-14 08:24:10 +02:00
Vegard Stenhjem Hagen and GitHub
1deb5aced1
feat(devcontainer): build a Devcontainer with useful tools for this project
...
Also use said devcontainer i GitHub workflows to validate config.
* feat(devcontainer): build devcontainer
Signed-off-by: Vegard Hagen <[email protected] >
* feat(ci): validate tofu files on push
Signed-off-by: Vegard Hagen <[email protected] >
* feat(devcontainer): simplify devcontainer
Signed-off-by: Vegard Hagen <[email protected] >
* fix(devcontainer): don't cache package index
This will reduce the final image size.
Signed-off-by: Vegard Hagen <[email protected] >
* feat(devcontainer): switch to ubuntu and use devcontainer features as much as possible
Signed-off-by: Vegard Hagen <[email protected] >
---------
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-13 23:18:26 +02:00
Vegard Hagen
f5841b4a3b
fix(authelia): explicit custom attribute configuration
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-13 15:46:41 +02:00
Vegard Hagen
838a335ecc
feat(authelia): description of custom claims
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-12 17:17:42 +02:00
Vegard Hagen
5de4066796
feat(authelia): custom argocd claim
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-12 15:45:23 +02:00
Vegard Hagen
aa884cd9d2
fix(authelia): clean up configuration
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-11 20:51:00 +02:00
Vegard Hagen
9fa04832e4
fix(unbound): use default config
...
Experiencing some issues with using Unbound as a recursive solver, so reverting to default config
Signed-off-by: Vegard Hagen <[email protected] >
2025-07-11 19:47:37 +02:00
Vegard Hagen
992c6a52a0
chore(lldap): edit config
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-06-25 20:56:34 +02:00
karteekiitg and GitHub
b46838873a
feat: Github actions to check for formatting of tofu files. ( #296 )
...
Tofu format check for changed files in pr and all files scheduled
Signed-off-by: Karteek <[email protected] >
2025-06-09 21:27:42 +02:00
0e448bc5f9
fix: Added missing subnet mask ( #298 )
...
Signed-off-by: Karteek <[email protected] >
Co-authored-by: Vegard Stenhjem Hagen <[email protected] >
2025-06-09 21:26:44 +02:00
Vegard Hagen
3d68e49d4d
fix(tofu): allow multiple nodes on the same host again
...
A bug reported in #299 resulted in it not being possible to schedule two Talos nodes on the same host machine with the same schematic ID and image version
This commit fixes #299
Signed-off-by: Vegard Hagen <[email protected] >
2025-06-09 21:21:41 +02:00
renovate[bot] and Vegard Hagen
e3e8de2137
chore(deps): update dependency kubernetes-sigs/gateway-api to v1.3.0
...
Reference GH issue #94 for updating article
2025-06-08 22:23:47 +02:00
Vegard Hagen
9aae3a5aa6
chore(talos): update talos to 1.10.3
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-06-08 22:23:47 +02:00
renovate[bot] and Vegard Hagen
71dc835717
chore(deps): update dependency siderolabs/talos to v1.10.3
2025-06-08 22:23:47 +02:00
renovate[bot] and Vegard Hagen
1e137986d8
chore(deps): update dependency kubernetes/kubernetes to v1.33.1
2025-06-08 22:23:47 +02:00
Vegard Hagen
2a2606d178
fix(netbird): use renvsubst container to create configuration
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-06-08 22:23:47 +02:00
Vegard Hagen
e1cabbf2bb
fix(gateway): use the addresses field instead of infrastructure annotation
...
See GH issue #94
This was fixed in https://github.com/cilium/cilium/issues/32865
Signed-off-by: Vegard Hagen <[email protected] >
2025-06-08 22:23:47 +02:00
Vegard Hagen
b3752260e7
fix(cilium): use cilium-cli image instead of cilium-cli-ci image to install cilium
...
Following Talos docs: https://www.talos.dev/v1.10/kubernetes-guides/network/deploying-cilium/#method-5-using-a-job
Signed-off-by: Vegard Hagen <[email protected] >
2025-06-08 22:23:46 +02:00
be9b1ac24e
chore(deps): renovate 2025-06-08
...
chore(deps): update media containers
chore(deps): update netbird
chore(deps): update netbird
chore(deps): update dependency cert-manager/cert-manager to v1.17.2
chore(deps): update helm release authelia to v0.10.11
chore(deps): update docker.io/adguard/adguardhome docker tag to v0.107.62
chore(deps): update helm release node-feature-discovery to v0.17.3
chore(deps): update helm release argo-cd to v7.9.1
chore(deps): update cilium to v1.17.4
chore(deps): update ghcr.io/authelia/authelia docker tag to v4.39.4
chore(deps): update helm release argo-cd to v8
chore(deps): update helm release cloudnative-pg to v0.24.0
chore(deps): update ghcr.io/prometheus-community/charts/kube-prometheus-stack docker tag to v73
chore(deps): update ghcr.io/home-operations/qbittorrent docker tag to v5.1.0
chore(deps): update ghcr.io/advplyr/audiobookshelf docker tag to v2.24.0
chore(deps): update cloudflare/cloudflared docker tag to v2025.5.0
chore(deps): update registry.k8s.io/git-sync/git-sync docker tag to v4.4.1
chore(deps): update proxmox-csi-plugin docker tag to v0.3.7
chore(deps): update sealed-secrets docker tag to v2.5.13
chore(deps): update intel device plugins to v0.32.1
chore(deps): update terraform talos to v0.8.1 (#324 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update terraform kubernetes to v2.37.1 (#322 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
chore(deps): update terraform proxmox to v0.78.1 (#323 )
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-06-08 22:23:30 +02:00
Vegard Hagen
7adf4cb1ff
fix(renovate): add .tofu extension for terraform providers
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-06-08 22:23:24 +02:00
2b400a3d4a
chore(config): migrate renovate config ( #307 )
...
chore(config): migrate config renovate.json
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-06-08 16:59:56 +02:00
Vegard Hagen
1fbe9fb6bd
feat(auth): add custom user properties for audiobookshelf
...
Add custom user schema in LLDAP which maps to a custom attribute in
Authelia which we then again map to a custom claim which we include in a
custom scope which audiobookshelf requests
Signed-off-by: Vegard Hagen <[email protected] >
2025-05-03 19:15:27 +02:00
Vegard Hagen
e0fdbafa35
feat(authelia): add audiobookshelf OIDC client
...
Signed-off-by: Vegard Hagen <[email protected] >
2025-05-03 11:47:25 +02:00