feat: NixOS | move cluster config to /master fix: update all stuff for office network feat: PiHole | set up DHCP server chore: Cloudflare | delete api token secret chore: remove external-dns annotations from ingressed services fix: PiHole | turn off liveness checks due to host ip fix: GiteaActions | use encrypted storage for runner fix: ElasticSearch | use encrypted volumes for storage fix: Pihole | static mac addresses all caps feat: NixOS | manual network configuration fix: NixOS | k3s cluster init point to static ip with tls-san chore: Postgres | move certificate resources into own file + reduce volume size fix: Pihole | add ingress class name sec: NixOS | remove token from git
141 lines
3.1 KiB
YAML
141 lines
3.1 KiB
YAML
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: gitea-admin
|
|
namespace: gitea-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/gitea-admin"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: gitea-postgres
|
|
namespace: gitea-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/gitea-postgres"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: pihole-admin
|
|
namespace: pihole-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/pihole"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: postgres-password
|
|
namespace: postgres-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/Postgres"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: runner-secret
|
|
namespace: gitea-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/Gitea"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: cloudflare-token
|
|
namespace: cert-manager
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/Cloudflare"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: authentik-postgres
|
|
namespace: authentik-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/authentik-postgres"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: redis
|
|
namespace: redis-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/redis"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: authentik-redis
|
|
namespace: authentik-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/redis"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: gitea-oauth
|
|
namespace: gitea-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/gitea-oauth"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: gitea-elasticsearch
|
|
namespace: gitea-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/gitea-elasticsearch"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: gitea-redis
|
|
namespace: gitea-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/gitea-redis"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: smtp-token
|
|
namespace: gitea-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/smtp-token"
|
|
---
|
|
apiVersion: onepassword.com/v1
|
|
kind: OnePasswordItem
|
|
metadata:
|
|
name: longhorn-encryption
|
|
namespace: longhorn-system
|
|
annotations:
|
|
operator.1password.io/auto-restart: "true"
|
|
spec:
|
|
itemPath: "vaults/Lab/items/longhorn-encryption"
|