Compare commits

..

6 Commits

Author SHA1 Message Date
gitea-admin 777e1c98f3 feat: deploy Wings instance for ARK SA
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-19 00:16:00 +00:00
gitea-admin aa2906c3c0 feat: deploy Wings instance for ARK SA 2026-05-19 00:15:59 +00:00
gitea-admin c82086eed8 feat: deploy Wings instance for ARK SA 2026-05-19 00:15:59 +00:00
gitea-admin 5e4efe948d feat: deploy Wings instance for ARK SA 2026-05-19 00:15:59 +00:00
gitea-admin 71ba268be5 feat: deploy Wings instance for ARK SA 2026-05-19 00:15:58 +00:00
gitea-admin 7be21685d6 feat: deploy Wings instance for ARK SA 2026-05-19 00:15:58 +00:00
21 changed files with 86 additions and 547 deletions
@@ -1,59 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: bitwarden
namespace: security
labels:
app: bitwarden
spec:
replicas: 1
selector:
matchLabels:
app: bitwarden
template:
metadata:
labels:
app: bitwarden
spec:
containers:
- name: bitwarden
image: bitwarden/server:latest
ports:
- containerPort: 80
env:
- name: SIGNUPS_ALLOWED
value: "true"
- name: WEBVAULT_ENABLED
value: "true"
- name: IDENTITY_URL
value: "https://bitwarden.khalisio.com"
- name: API_URL
value: "https://bitwarden.khalisio.com"
- name: DATABASE_URL
value: "/bitwarden/data/bitwarden.db"
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi
volumeMounts:
- name: bitwarden-data
mountPath: /bitwarden
readinessProbe:
httpGet:
path: /healthz
port: 80
initialDelaySeconds: 15
periodSeconds: 10
livenessProbe:
httpGet:
path: /healthz
port: 80
initialDelaySeconds: 30
periodSeconds: 30
volumes:
- name: bitwarden-data
persistentVolumeClaim:
claimName: bitwarden-data
@@ -1,26 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: bitwarden
namespace: security
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
traefik.ingress.kubernetes.io/router.entrypoints: websecure
traefik.ingress.kubernetes.io/router.tls: "true"
spec:
ingressClassName: traefik
tls:
- hosts:
- bitwarden.khalisio.com
secretName: bitwarden-tls
rules:
- host: bitwarden.khalisio.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: bitwarden
port:
number: 80
-12
View File
@@ -1,12 +0,0 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: bitwarden-data
namespace: security
spec:
accessModes:
- ReadWriteOnce
storageClassName: longhorn
resources:
requests:
storage: 5Gi
@@ -1,13 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: bitwarden
namespace: security
spec:
selector:
app: bitwarden
ports:
- name: http
port: 80
targetPort: 80
type: ClusterIP
-50
View File
@@ -1,50 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: bitwarden
namespace: security
labels:
app: bitwarden
spec:
replicas: 1
selector:
matchLabels:
app: bitwarden
template:
metadata:
labels:
app: bitwarden
spec:
containers:
- name: bitwarden
image: bitwarden/server:1.30.1
ports:
- containerPort: 80
env:
- name: WEBSOCKET_ENABLED
value: "true"
- name: SIGNUPS_ALLOWED
value: "true"
- name: ADMIN_TOKEN
valueFrom:
secretKeyRef:
name: bitwarden-secret
key: admin-token
- name: DB_CERT_FORMAT
value: "pem"
- name: SIGNUP_ORIGINS
value: "https://bitwarden.khalisio.com"
volumeMounts:
- name: bitwarden-data
mountPath: /data
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
volumes:
- name: bitwarden-data
persistentVolumeClaim:
claimName: bitwarden-data
-21
View File
@@ -1,21 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: bitwarden
namespace: security
annotations:
kubernetes.io/ingress.class: traefik
spec:
entryPoints:
- websecure
routes:
- match: Host(`bitwarden.khalisio.com`)
kind: Rule
services:
- name: bitwarden
port: 80
tls:
secretName: bitwarden-tls
options:
name: default
kind: ClusterEntrypoint
-7
View File
@@ -1,7 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: security
labels:
app.kubernetes.io/name: bitwarden
app.kubernetes.io/managed-by: orion
-12
View File
@@ -1,12 +0,0 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: bitwarden-data
namespace: security
spec:
accessModes:
- ReadWriteOnce
storageClassName: longhorn
resources:
requests:
storage: 5Gi
-15
View File
@@ -1,15 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: bitwarden
namespace: security
labels:
app: bitwarden
spec:
type: ClusterIP
ports:
- port: 80
targetPort: 80
protocol: TCP
selector:
app: bitwarden
@@ -1,17 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-7d2d
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-7d2d-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-7d2d.khalisio.com`)
kind: Rule
services:
- name: wings-7d2d-api
port: 8081
@@ -21,101 +21,95 @@ spec:
spec:
nodeSelector:
kubernetes.io/arch: amd64
affinity:
podAntiAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- labelSelector:
matchExpressions:
- key: game
operator: In
values: [ark-sa]
topologyKey: "kubernetes.io/hostname"
volumes:
- name: wings-config
secret:
secretName: wings-ark-sa-config
- name: game-data
persistentVolumeClaim:
claimName: wings-ark-sa-data
- name: docker-socket
emptyDir: {}
- name: autostart-token
secret:
secretName: pelican-autostart-key
containers:
- name: dind
image: docker:dind
args:
- "--storage-driver=vfs"
- "--iptables=false"
image: docker:24-dind
securityContext:
privileged: true
volumeMounts:
- name: docker-socket
mountPath: /var/run/docker.sock
env:
- name: DOCKER_TLS_CERTDIR
value: ""
resources:
requests:
cpu: "500m"
memory: "512Mi"
memory: "1Gi"
limits:
cpu: "1"
memory: "1Gi"
memory: "2Gi"
- name: wings
image: ghcr.io/pelican-dev/wings:latest
command:
- /bin/sh
- -c
- |
export DOCKER_HOST=tcp://localhost:2375
exec wings
envFrom:
- secretRef:
name: wings-ark-sa-config
env:
- name: DOCKER_HOST
value: tcp://localhost:2375
- name: WATCHDOG_ENABLED
value: "true"
volumeMounts:
- name: wings-config
mountPath: /etc/pterodactyl
readOnly: true
- name: game-data
mountPath: /mnt/server
- name: docker-socket
mountPath: /var/run/docker.sock
- name: WINGS_Umask
value: "0002"
- name: GRPC_PORT
value: "50051"
- name: WINGS_API_LISTEN
value: "0.0.0.0:8081"
- name: WINGS_SFTP_LISTEN
value: "0.0.0.0:2023"
- name: WINGS_SERVER_UUID
valueFrom:
secretKeyRef:
name: wings-ark-sa-config
key: server_uuid
- name: WINGS_API_KEY
valueFrom:
secretKeyRef:
name: wings-ark-sa-config
key: api_key
envFrom:
- secretRef:
name: wings-ark-sa-config
ports:
- containerPort: 8081
- containerPort: 2023
resources:
requests:
cpu: "2"
memory: "4Gi"
memory: "8Gi"
limits:
cpu: "4"
memory: "8Gi"
memory: "16Gi"
volumeMounts:
- name: data
mountPath: /home/container
- name: game-autostart
image: curlimages/curl:latest
command:
- /bin/sh
- -c
command: ["/bin/sh", "-c"]
args:
- |
while true; do
WINGS_READY=false
while [ "$WINGS_READY" = "false" ]; do
if curl -sf http://localhost:8081/health > /dev/null 2>&1; then
WINGS_READY=true
echo "Wings is ready, sending start signal..."
sleep 30
curl -sf -X POST \
-H "Authorization: Bearer $PELICAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{"signal":"start"}' \
https://pelican.khalisio.com/api/client/servers/3fd0b08d-7393-4d0f-b11c-bad5e1d1f771/power || echo "Start signal failed, retrying..."
break
fi
echo "Waiting for Wings to be ready..."
sleep 5
done
sleep 60
curl -sf -X POST "https://pelican.khalisio.com/api/client/servers/3fd0b08d-7393-4d0f-b11c-bad5e1d1f771/power" \
-H "Authorization: Bearer $(cat /etc/secrets/autostart/api_key)" \
-H "Content-Type: application/json" \
-d '{"signal":"start"}' > /dev/null 2>&1 || true
done
volumeMounts:
- name: autostart-token
mountPath: /etc/secrets/autostart
readOnly: true
envFrom:
- secretRef:
name: pelican-autostart-key
resources:
requests:
cpu: "50m"
memory: "64Mi"
limits:
cpu: "100m"
memory: "128Mi"
restartPolicy: Always
memory: "256Mi"
limits:
cpu: "500m"
memory: "512Mi"
volumes:
- name: data
persistentVolumeClaim:
claimName: wings-ark-sa-data
@@ -6,21 +6,18 @@ metadata:
spec:
refreshInterval: 1h
secretStoreRef:
name: vault
name: vault-secret-store
kind: ClusterSecretStore
target:
name: wings-ark-sa-config
creationPolicy: Owner
template:
engineVersion: v2
data:
- secretKey: WINGS_UUID
- secretKey: config
remoteRef:
key: wings/ark-sa
property: uuid
- secretKey: WINGS_TOKEN
key: secret/data/Talos Cluster/wings/ark-sa
property: config
- secretKey: api_key
remoteRef:
key: wings/ark-sa
property: token
- secretKey: LOCALE
remoteRef:
key: wings/ark-sa
property: locale
key: secret/data/Talos Cluster/wings/ark-sa
property: api_key
@@ -5,6 +5,8 @@ metadata:
namespace: game-servers
spec:
type: ClusterIP
selector:
app: wings-ark-sa
ports:
- name: api
port: 8081
@@ -14,5 +16,3 @@ spec:
port: 2023
targetPort: 2023
protocol: TCP
selector:
app: wings-ark-sa
@@ -4,22 +4,22 @@ metadata:
name: wings-ark-sa-game
namespace: game-servers
annotations:
metallb.universe.tf/address-pool: default-lb-pool
metallb.io/address-pool: "default"
spec:
type: LoadBalancer
loadBalancerIP: 10.4.4.200
ports:
- name: ark-game
port: 7777
protocol: UDP
targetPort: 7777
- name: ark-query
port: 27015
protocol: UDP
targetPort: 27015
- name: ark-tcp
port: 27016
protocol: TCP
targetPort: 27016
selector:
app: wings-ark-sa
ports:
- name: udp
port: 7777
targetPort: 7777
protocol: UDP
- name: tcp
port: 7777
targetPort: 7777
protocol: TCP
- name: query
port: 27015
targetPort: 27015
protocol: UDP
@@ -1,17 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-enshrouded
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-enshrouded-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-enshrouded.khalisio.com`)
kind: Rule
services:
- name: wings-enshrouded-api
port: 8081
@@ -1,17 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-moria
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-moria-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-moria.khalisio.com`)
kind: Rule
services:
- name: wings-moria-api
port: 8081
@@ -1,17 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-palworld
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-palworld-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-palworld.khalisio.com`)
kind: Rule
services:
- name: wings-palworld-api
port: 8081
@@ -1,17 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-satisfactory
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-satisfactory-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-satisfactory.khalisio.com`)
kind: Rule
services:
- name: wings-satisfactory-api
port: 8081
@@ -1,17 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-sotf
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-sotf-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-sotf.khalisio.com`)
kind: Rule
services:
- name: wings-sotf-api
port: 8081
@@ -1,118 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: wings-valheim
namespace: game-servers
labels:
app.kubernetes.io/name: wings
app.kubernetes.io/component: game-server
app.kubernetes.io/part-of: pelican
game: valheim
spec:
strategy:
type: Recreate
selector:
matchLabels:
app: wings-valheim
template:
metadata:
labels:
app: wings-valheim
game: valheim
spec:
nodeSelector:
kubernetes.io/arch: amd64
containers:
- name: wings
image: ghcr.io/pelican-dev/wings:latest
env:
- name: DOCKER_HOST
value: tcp://localhost:2375
- name: WINGS_UID
value: "1000"
- name: WINGS_GID
value: "1000"
- name: WINGS_PORT
value: "8081"
- name: WINGS_API_SFTP_PORT
value: "2023"
- name: WINGS_SERVER_UUID
value: "9d09e83d-00c3-4404-07c0522a6c25"
envFrom:
- secretRef:
name: wings-valheim-config
volumeMounts:
- name: docker-socket
mountPath: /var/run/docker.sock
- name: wings-data
mountPath: /var/lib/wings
- name: server-data
mountPath: /mnt/server
readinessProbe:
httpGet:
path: /ready
port: 8081
initialDelaySeconds: 10
periodSeconds: 10
livenessProbe:
httpGet:
path: /health
port: 8081
initialDelaySeconds: 15
periodSeconds: 30
- name: dind
image: docker:24-dind
securityContext:
privileged: true
env:
- name: DOCKER_TLS_CERTDIR
value: ""
volumeMounts:
- name: docker-socket
mountPath: /var/run
- name: dind-storage
mountPath: /var/lib/docker
readinessProbe:
exec:
command:
- sh
- -c
- '[ -S /var/run/docker.sock ]'
initialDelaySeconds: 5
periodSeconds: 5
- name: game-autostart
image: curlimages/curl:latest
env:
- name: PELICAN_API_KEY
valueFrom:
secretKeyRef:
name: pelican-autostart-key
key: api_key
- name: SERVER_UUID
value: "9d09e83d-00c3-4404-07c0522a6c25"
command:
- /bin/sh
- -c
- |
echo "Waiting for Wings API to be ready..."
while ! curl -sf http://localhost:8081/ready; do
sleep 2
done
echo "Wings ready. Starting game server..."
while true; do
sleep 60
echo "Checking game server status..."
done
volumeMounts:
- name: server-data
mountPath: /mnt/server
volumes:
- name: docker-socket
emptyDir: {}
- name: dind-storage
emptyDir: {}
- name: wings-data
emptyDir: {}
- name: server-data
persistentVolumeClaim:
claimName: wings-valheim-data
@@ -1,17 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-valheim
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-valheim-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-valheim.khalisio.com`)
kind: Rule
services:
- name: wings-valheim-api
port: 8081