Compare commits

..

63 Commits

Author SHA1 Message Date
gitea-admin 8f93998837 fix: correct API versions for ExternalSecrets and Traefik
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-19 22:49:41 +00:00
gitea-admin 744838d202 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:41 +00:00
gitea-admin a32cf601f8 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:41 +00:00
gitea-admin ca0b1f3843 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:40 +00:00
gitea-admin 0ebff3739f fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:40 +00:00
gitea-admin ad86dd3d60 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:40 +00:00
gitea-admin 4d7cb1f774 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:39 +00:00
gitea-admin d52bdb9ff3 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:39 +00:00
gitea-admin e8da11f29b fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:39 +00:00
gitea-admin 78522eac19 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:38 +00:00
gitea-admin 6ca194fdeb fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:38 +00:00
gitea-admin 0642a88018 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:38 +00:00
gitea-admin 39f657b5a1 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:37 +00:00
gitea-admin 35e031e84f fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:37 +00:00
gitea-admin ee17547fc4 fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:37 +00:00
gitea-admin ee647a5dff fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:36 +00:00
gitea-admin df6f6241bb fix: correct API versions for ExternalSecrets and Traefik 2026-05-19 22:49:36 +00:00
gitea-admin d822cbe546 Update deployments/media/pvc.yaml 2026-05-19 22:25:57 +00:00
gitea-admin 9386134fc7 Update deployments/media/lidarr/pvc.yaml 2026-05-19 22:22:55 +00:00
gitea-admin 1286ebae4a Update deployments/media/emby/pvc.yaml 2026-05-19 22:22:43 +00:00
gitea-admin 6b434e5230 Update deployments/media/bazarr/pvc.yaml 2026-05-19 22:22:22 +00:00
gitea-admin 3676a5de46 Update deployments/media/pvc.yaml 2026-05-19 22:22:05 +00:00
gitea-admin f4a9de8b82 Delete deployments/media/media-pvc.yaml 2026-05-19 22:21:53 +00:00
gitea-admin 37cb3bbeb6 Update deployments/media/sonarr/pvc.yaml 2026-05-19 22:21:37 +00:00
gitea-admin 56320aa920 Update deployments/media/sonarrpvc.yaml 2026-05-19 22:21:30 +00:00
gitea-admin 86e817e3c3 Update deployments/media/radarr/pvc.yaml 2026-05-19 22:21:20 +00:00
gitea-admin 91f0184941 Update deployments/media/prowlarr/pvc.yaml 2026-05-19 22:21:13 +00:00
gitea-admin 644f777b7c Update deployments/media/lidarr/lidarr-pvc.yaml 2026-05-19 22:21:00 +00:00
gitea-admin f2b20d549a Update deployments/media/emby/emby-pvc.yaml 2026-05-19 22:20:37 +00:00
gitea-admin 70a9f23b7f Update deployments/media/bazarr/bazarr-pvc.yaml 2026-05-19 22:20:26 +00:00
gitea-admin 36d3a45e02 Delete directory 'deployments/bitwarden' 2026-05-19 22:19:40 +00:00
gitea-admin 71348a5a65 Merge pull request 'fix: move Bitwarden to security/bitwarden/ (correct namespace structure)' (#101) from orion/auto/fix-move-bitwarden-to-security-bitwarden-1779229047173 into main
Reviewed-on: #101
2026-05-19 22:19:00 +00:00
gitea-admin 2d1b6cf487 fix: move Bitwarden to security/bitwarden/ (correct namespace structure)
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-19 22:17:30 +00:00
gitea-admin 1436def461 fix: move Bitwarden to security/bitwarden/ (correct namespace structure) 2026-05-19 22:17:30 +00:00
gitea-admin 309c291917 fix: move Bitwarden to security/bitwarden/ (correct namespace structure) 2026-05-19 22:17:29 +00:00
gitea-admin 0b35e7500a fix: move Bitwarden to security/bitwarden/ (correct namespace structure) 2026-05-19 22:17:29 +00:00
gitea-admin 96e4179de5 fix: move Bitwarden to security/bitwarden/ (correct namespace structure) 2026-05-19 22:17:29 +00:00
gitea-admin 18c7a798d4 fix: move Bitwarden to security/bitwarden/ (correct namespace structure) 2026-05-19 22:17:28 +00:00
gitea-admin 4a170e2a7b fix: move Bitwarden to security/bitwarden/ (correct namespace structure) 2026-05-19 22:17:28 +00:00
gitea-admin 61faadcea3 fix: move Bitwarden to security/bitwarden/ (correct namespace structure) 2026-05-19 22:17:28 +00:00
gitea-admin 6619978c47 fix: move Bitwarden to security/bitwarden/ (correct namespace structure) 2026-05-19 22:17:27 +00:00
gitea-admin ce7384d92e fix: move Bitwarden to security/bitwarden/ (correct namespace structure) 2026-05-19 22:17:27 +00:00
gitea-admin 082a79b613 Merge pull request 'feat: deploy Bitwarden vault to security namespace' (#99) from orion/auto/feat-deploy-bitwarden-vault-to-security--1779180493216 into main
Reviewed-on: #99
2026-05-19 08:48:38 +00:00
gitea-admin e44858053c feat: deploy Bitwarden vault to security namespace
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-19 08:48:14 +00:00
gitea-admin 56141866cb feat: deploy Bitwarden vault to security namespace 2026-05-19 08:48:14 +00:00
gitea-admin 808f2aff06 feat: deploy Bitwarden vault to security namespace 2026-05-19 08:48:13 +00:00
gitea-admin b03242120e feat: deploy Bitwarden vault to security namespace 2026-05-19 08:48:13 +00:00
gitea-admin 96cf67dfa0 Merge pull request 'feat: deploy Bitwarden self-hosted in security namespace' (#97) from orion/auto/feat-deploy-bitwarden-self-hosted-in-sec-1779180155812 into main
Reviewed-on: #97
2026-05-19 08:43:33 +00:00
gitea-admin f882fbff41 feat: deploy Bitwarden self-hosted in security namespace
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-19 08:42:37 +00:00
gitea-admin 3259058743 feat: deploy Bitwarden self-hosted in security namespace 2026-05-19 08:42:37 +00:00
gitea-admin a25bd791ee feat: deploy Bitwarden self-hosted in security namespace 2026-05-19 08:42:36 +00:00
gitea-admin 0db41645f1 feat: deploy Bitwarden self-hosted in security namespace 2026-05-19 08:42:36 +00:00
gitea-admin 8b2476f98e feat: deploy Bitwarden self-hosted in security namespace 2026-05-19 08:42:36 +00:00
gitea-admin e412ed2f37 Merge pull request 'fix: correct Valheim UUID and ingress API version for all Wings instances' (#96) from orion/auto/fix-correct-valheim-uuid-and-ingress-api-1779150243957 into main
Reviewed-on: #96
2026-05-19 00:24:22 +00:00
gitea-admin 54afdb38c6 fix: correct Valheim UUID and ingress API version for all Wings instances
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-19 00:24:06 +00:00
gitea-admin b2ec5765b2 fix: correct Valheim UUID and ingress API version for all Wings instances 2026-05-19 00:24:06 +00:00
gitea-admin c2d7fcd637 fix: correct Valheim UUID and ingress API version for all Wings instances 2026-05-19 00:24:06 +00:00
gitea-admin c6b30bb4b5 fix: correct Valheim UUID and ingress API version for all Wings instances 2026-05-19 00:24:05 +00:00
gitea-admin f68f033c1d fix: correct Valheim UUID and ingress API version for all Wings instances 2026-05-19 00:24:05 +00:00
gitea-admin b1cb35b14f fix: correct Valheim UUID and ingress API version for all Wings instances 2026-05-19 00:24:05 +00:00
gitea-admin bc05720128 fix: correct Valheim UUID and ingress API version for all Wings instances 2026-05-19 00:24:04 +00:00
gitea-admin c13886552a fix: correct Valheim UUID and ingress API version for all Wings instances 2026-05-19 00:24:04 +00:00
gitea-admin bd464ac1c9 fix: correct Valheim UUID and ingress API version for all Wings instances 2026-05-19 00:24:04 +00:00
30 changed files with 500 additions and 35 deletions
@@ -0,0 +1,22 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: wings-7d2d-config
namespace: game-servers
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-secret-store
kind: ClusterSecretStore
target:
name: wings-7d2d-config
creationPolicy: Owner
data:
- secretKey: config
remoteRef:
key: Talos Cluster/wings/7d2d
property: config
- secretKey: api_key
remoteRef:
key: Talos Cluster/wings/7d2d
property: api_key
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-7d2d-api
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-7d2d-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-7d2d.khalisio.com`)
kind: Rule
services:
- name: wings-7d2d-api
port: 8081
@@ -1,4 +1,4 @@
apiVersion: external-secrets.io/v1beta1
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: wings-ark-sa-config
@@ -6,21 +6,17 @@ metadata:
spec:
refreshInterval: 1h
secretStoreRef:
name: vault
name: vault-secret-store
kind: ClusterSecretStore
target:
name: wings-ark-sa-config
creationPolicy: Owner
data:
- secretKey: WINGS_UUID
- secretKey: config
remoteRef:
key: wings/ark-sa
property: uuid
- secretKey: WINGS_TOKEN
key: Talos Cluster/wings/ark-sa
property: config
- secretKey: api_key
remoteRef:
key: wings/ark-sa
property: token
- secretKey: LOCALE
remoteRef:
key: wings/ark-sa
property: locale
key: Talos Cluster/wings/ark-sa
property: api_key
@@ -1,4 +1,4 @@
apiVersion: traefik.containo.us/v1alpha1
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-ark-sa-api
@@ -8,20 +8,10 @@ spec:
- websecure
tls:
secretName: wings-ark-sa-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-ark-sa.khalisio.com`)
kind: Rule
services:
- name: wings-ark-sa-api
port: 8081
scheme: https
serversTransport: wings-ark-sa-st
---
apiVersion: traefik.io/v1alpha1
kind: ServersTransport
metadata:
name: wings-ark-sa-st
namespace: game-servers
spec:
serverTransport:
insecureSkipVerify: true
port: 8081
@@ -0,0 +1,22 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: wings-enshrouded-config
namespace: game-servers
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-secret-store
kind: ClusterSecretStore
target:
name: wings-enshrouded-config
creationPolicy: Owner
data:
- secretKey: config
remoteRef:
key: Talos Cluster/wings/enshrouded
property: config
- secretKey: api_key
remoteRef:
key: Talos Cluster/wings/enshrouded
property: api_key
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-enshrouded-api
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-enshrouded-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-enshrouded.khalisio.com`)
kind: Rule
services:
- name: wings-enshrouded-api
port: 8081
@@ -0,0 +1,22 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: wings-moria-config
namespace: game-servers
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-secret-store
kind: ClusterSecretStore
target:
name: wings-moria-config
creationPolicy: Owner
data:
- secretKey: config
remoteRef:
key: Talos Cluster/wings/moria
property: config
- secretKey: api_key
remoteRef:
key: Talos Cluster/wings/moria
property: api_key
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-moria-api
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-moria-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-moria.khalisio.com`)
kind: Rule
services:
- name: wings-moria-api
port: 8081
@@ -0,0 +1,22 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: wings-palworld-config
namespace: game-servers
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-secret-store
kind: ClusterSecretStore
target:
name: wings-palworld-config
creationPolicy: Owner
data:
- secretKey: config
remoteRef:
key: Talos Cluster/wings/palworld
property: config
- secretKey: api_key
remoteRef:
key: Talos Cluster/wings/palworld
property: api_key
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-palworld-api
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-palworld-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-palworld.khalisio.com`)
kind: Rule
services:
- name: wings-palworld-api
port: 8081
@@ -0,0 +1,22 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: wings-satisfactory-config
namespace: game-servers
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-secret-store
kind: ClusterSecretStore
target:
name: wings-satisfactory-config
creationPolicy: Owner
data:
- secretKey: config
remoteRef:
key: Talos Cluster/wings/satisfactory
property: config
- secretKey: api_key
remoteRef:
key: Talos Cluster/wings/satisfactory
property: api_key
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-satisfactory-api
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-satisfactory-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-satisfactory.khalisio.com`)
kind: Rule
services:
- name: wings-satisfactory-api
port: 8081
@@ -0,0 +1,22 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: wings-sotf-config
namespace: game-servers
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-secret-store
kind: ClusterSecretStore
target:
name: wings-sotf-config
creationPolicy: Owner
data:
- secretKey: config
remoteRef:
key: Talos Cluster/wings/sotf
property: config
- secretKey: api_key
remoteRef:
key: Talos Cluster/wings/sotf
property: api_key
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-sotf-api
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-sotf-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-sotf.khalisio.com`)
kind: Rule
services:
- name: wings-sotf-api
port: 8081
@@ -0,0 +1,118 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: wings-valheim
namespace: game-servers
labels:
app.kubernetes.io/name: wings
app.kubernetes.io/component: game-server
app.kubernetes.io/part-of: pelican
game: valheim
spec:
strategy:
type: Recreate
selector:
matchLabels:
app: wings-valheim
template:
metadata:
labels:
app: wings-valheim
game: valheim
spec:
nodeSelector:
kubernetes.io/arch: amd64
containers:
- name: wings
image: ghcr.io/pelican-dev/wings:latest
env:
- name: DOCKER_HOST
value: tcp://localhost:2375
- name: WINGS_UID
value: "1000"
- name: WINGS_GID
value: "1000"
- name: WINGS_PORT
value: "8081"
- name: WINGS_API_SFTP_PORT
value: "2023"
- name: WINGS_SERVER_UUID
value: "9d09e83d-00c3-4404-07c0522a6c25"
envFrom:
- secretRef:
name: wings-valheim-config
volumeMounts:
- name: docker-socket
mountPath: /var/run/docker.sock
- name: wings-data
mountPath: /var/lib/wings
- name: server-data
mountPath: /mnt/server
readinessProbe:
httpGet:
path: /ready
port: 8081
initialDelaySeconds: 10
periodSeconds: 10
livenessProbe:
httpGet:
path: /health
port: 8081
initialDelaySeconds: 15
periodSeconds: 30
- name: dind
image: docker:24-dind
securityContext:
privileged: true
env:
- name: DOCKER_TLS_CERTDIR
value: ""
volumeMounts:
- name: docker-socket
mountPath: /var/run
- name: dind-storage
mountPath: /var/lib/docker
readinessProbe:
exec:
command:
- sh
- -c
- '[ -S /var/run/docker.sock ]'
initialDelaySeconds: 5
periodSeconds: 5
- name: game-autostart
image: curlimages/curl:latest
env:
- name: PELICAN_API_KEY
valueFrom:
secretKeyRef:
name: pelican-autostart-key
key: api_key
- name: SERVER_UUID
value: "9d09e83d-00c3-4404-07c0522a6c25"
command:
- /bin/sh
- -c
- |
echo "Waiting for Wings API to be ready..."
while ! curl -sf http://localhost:8081/ready; do
sleep 2
done
echo "Wings ready. Starting game server..."
while true; do
sleep 60
echo "Checking game server status..."
done
volumeMounts:
- name: server-data
mountPath: /mnt/server
volumes:
- name: docker-socket
emptyDir: {}
- name: dind-storage
emptyDir: {}
- name: wings-data
emptyDir: {}
- name: server-data
persistentVolumeClaim:
claimName: wings-valheim-data
@@ -0,0 +1,22 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: wings-valheim-config
namespace: game-servers
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-secret-store
kind: ClusterSecretStore
target:
name: wings-valheim-config
creationPolicy: Owner
data:
- secretKey: config
remoteRef:
key: Talos Cluster/wings/valheim
property: config
- secretKey: api_key
remoteRef:
key: Talos Cluster/wings/valheim
property: api_key
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-valheim-api
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-valheim-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-valheim.khalisio.com`)
kind: Rule
services:
- name: wings-valheim-api
port: 8081
@@ -9,4 +9,4 @@ spec:
storageClassName: longhorn
resources:
requests:
storage: 500Gi
storage: 3Ti
+4 -6
View File
@@ -1,19 +1,17 @@
apiVersion: traefik.containo.us/v1alpha1
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: pelican-panel
namespace: pelican
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
spec:
entryPoints:
- websecure
tls:
secretName: pelican-panel-tls
secretName: pelican-tls
certResolver: letsencrypt
routes:
- match: Host(`pelican.khalisio.com`)
kind: Rule
services:
- name: pelican-panel
port: 80
scheme: http
port: 8080
@@ -0,0 +1,45 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: bitwarden
namespace: security
labels:
app: bitwarden
spec:
replicas: 1
selector:
matchLabels:
app: bitwarden
template:
metadata:
labels:
app: bitwarden
spec:
containers:
- name: bitwarden
image: bitwarden/server:latest
ports:
- containerPort: 80
env:
- name: BW_ADMIN_DOMAIN
value: bitwarden.khalisio.com
- name: WEBSOCKETS_ENABLED
value: "true"
- name: SIGNUPS_ALLOWED
value: "true"
- name: DOMAIN
value: https://bitwarden.khalisio.com
volumeMounts:
- name: bitwarden-data
mountPath: /data
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
volumes:
- name: bitwarden-data
persistentVolumeClaim:
claimName: bitwarden-data
@@ -0,0 +1,25 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: bitwarden
namespace: security
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
traefik.ingress.kubernetes.io/router.entrypoints: websecure
spec:
ingressClassName: traefik
tls:
- hosts:
- bitwarden.khalisio.com
secretName: bitwarden-tls
rules:
- host: bitwarden.khalisio.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: bitwarden
port:
number: 80
@@ -1,12 +1,12 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: media-data
namespace: media
name: bitwarden-data
namespace: security
spec:
accessModes:
- ReadWriteOnce
storageClassName: longhorn
resources:
requests:
storage: 500Gi
storage: 5Gi
@@ -0,0 +1,13 @@
apiVersion: v1
kind: Service
metadata:
name: bitwarden
namespace: security
spec:
selector:
app: bitwarden
ports:
- name: http
port: 80
targetPort: 80
type: ClusterIP
+7
View File
@@ -0,0 +1,7 @@
apiVersion: v1
kind: Namespace
metadata:
name: security
labels:
app.kubernetes.io/name: security
app.kubernetes.io/managed-by: orion