737fca6481
feat: Authentik | upgrade to 2024.10.5
2024-12-11 13:51:00 +05:00
30243d86db
fix: Authentik | update version + add rihla auth domain
2024-11-30 15:18:22 +05:00
b1de30cb87
chore: enable proxied dns routes
2024-11-20 15:04:28 +05:00
c8257741e1
feat: add nix flake for development
2024-11-20 15:03:20 +05:00
e503427098
fix: 1Password | add cloudflare token secret
2024-11-18 13:49:20 +05:00
6dd312ea13
feat: Longhorn | set up automatic backups to R2
2024-10-24 20:11:41 +05:00
33f03970f8
chore: Minio | remove minio
2024-10-24 17:20:42 +05:00
df97a4ca38
feat: Minio | create operator and tenant helm deployments
2024-10-24 17:15:24 +05:00
653ff659f6
fix: ExternalDNS | use pihole secure domain through ingress
2024-10-24 14:13:51 +05:00
d4dd6bac73
fix: CoreDNS | configure sequential nameserver usage
...
This is required for core dns to pick the correct nameservers as
configured by the host's resolv.conf file, according to
https://github.com/k3s-io/k3s/discussions/7822
2024-10-24 13:49:41 +05:00
4f3b705305
fix: PiHole | remove dnsmasq hosts and use Cloudflare backup DNS
2024-10-24 13:49:41 +05:00
0d4f700b89
feat: NixOS | use LUKS and proper hostname for k3s domain
...
feat: NixOS | move cluster config to /master
fix: update all stuff for office network
feat: PiHole | set up DHCP server
chore: Cloudflare | delete api token secret
chore: remove external-dns annotations from ingressed services
fix: PiHole | turn off liveness checks due to host ip
fix: GiteaActions | use encrypted storage for runner
fix: ElasticSearch | use encrypted volumes for storage
fix: Pihole | static mac addresses all caps
feat: NixOS | manual network configuration
fix: NixOS | k3s cluster init point to static ip with tls-san
chore: Postgres | move certificate resources into own file + reduce volume size
fix: Pihole | add ingress class name
sec: NixOS | remove token from git
2024-10-24 13:49:41 +05:00
38e5e53fd9
fix: ElasticSearch | using clusterIP was a mistake
2024-10-13 17:35:32 +05:00
5f0cd94f34
chore: use RSA certificates and clusterIP on elasticsearch
2024-10-12 22:31:52 +05:00
f8d7470ee6
fix: ElasticSearch | use single node cluster
2024-10-12 21:55:57 +05:00
f54e6f11de
chore: Network | use nginx as much as possible
2024-10-12 21:11:06 +05:00
058666330a
feat: Gitea | enable smtp mail
2024-10-12 18:58:26 +05:00
db935d355c
fix: Gitea | use redis for queue
2024-10-12 18:26:54 +05:00
70736f440e
fix: Gitea | use https endpoint in action runners
2024-10-12 16:05:22 +05:00
6d8afdefb6
feat: ElasticSearch | set up https for service
2024-10-12 13:35:14 +05:00
b313b746df
feat: Authentik | set up for HA
2024-10-12 13:34:58 +05:00
80a6b9c49c
feat: Authentik | set up authentik + dependencies
...
Includes redis and changes to pihole, nginx, prometheus and gitea
2024-10-12 09:31:50 +05:00
5a7fccdfa1
feat: Cloudflare | set up DDNS container
2024-10-12 09:31:16 +05:00
dea64bc039
feat: ElasticSearch | add elasticsearch cluster
2024-10-12 09:30:49 +05:00
c6933157c0
feat: Postgers | use client managed certificates
2024-10-11 15:04:41 +05:00
77a9668446
fix: Pihole | use sticky connections for http
2024-10-08 15:07:09 +05:00
60a54c48ff
fix: Pihole | use router as dns2
2024-10-08 14:56:16 +05:00
887afaca1e
fix: Pihole | use ReadWriteMany access mode on PVC
2024-10-08 13:44:51 +05:00
18ac01be63
feat: Pihole | enable externalDNS metrics and use dogar.dev domain
2024-10-08 13:40:53 +05:00
258877e127
fix: Pihole | remove 192.168.0.1 dns address
2024-10-08 13:34:17 +05:00
7b2de50e02
feat: Gitea | use ED25519 for cloudflare cert
2024-10-08 13:23:25 +05:00
7343e744bf
expose grafana to public internet
2024-10-01 19:19:39 +05:00
34fa878e17
feat: Postgres | expose cluster to public internet
2024-10-01 19:11:32 +05:00
85e8981a11
chore: Memcached | make the pod a single replica
2024-10-01 18:53:43 +05:00
9a655b80af
feat: Memcached| expose memcached on dogar.dev
2024-10-01 17:43:59 +05:00
601a15cca5
feat: Cloudflare | add DDNS container
2024-10-01 17:19:02 +05:00
9a0bd728ac
chore: Nginx | formatting
2024-10-01 17:06:09 +05:00
6b6b9231a6
fix: Gitea | fix ssh clone url
2024-10-01 17:06:00 +05:00
ca7a9fd616
fix: Gitea | use local ip address for home network
2024-10-01 16:06:45 +05:00
e40b3bc110
chore: Cloudflared | remove cloudflare tunnels
2024-10-01 16:06:17 +05:00
4a5c9fda34
feat: Gitea | expose service to public internet without cloudflared
2024-10-01 16:04:52 +05:00
18605f98a1
fix: Postgres | use async replicas only and add dogar.dev to certificate sans
2024-10-01 09:10:50 +05:00
d4edcc0645
fix: only use git.dogar.dev domain for gitea
2024-10-01 09:08:38 +05:00
adee1b5941
fix: Memcached | expose service as type Loadbalancer
...
Also added some custom settings
2024-09-16 14:27:27 +05:00
9340c66e37
feat: adjust ROOT_URL in gitea and create action runner
2024-09-16 13:22:05 +05:00
b2c327e218
fix: Gitea | preserve gitea.home for use, git.dogar.dev readonly
2024-09-09 08:56:23 +05:00
0c956bda49
fix: Gitea | use git.dogar.dev as primary domain name
2024-09-09 07:17:46 +05:00
fd1133237f
feat: Cloudflared | expose gitea service over cloudflare tunnel
2024-09-09 06:46:57 +05:00
649d481ed0
sec: Gitea | disable user registration
2024-09-09 06:36:06 +05:00
f9504f556e
fix: Gitea | disable registration
2024-09-09 06:05:11 +05:00