Compare commits

...

485 Commits

Author SHA1 Message Date
renovate-bot 7abe503050 Update ghcr.io/juanfont/headscale Docker tag to v0.28.0
renovate/stability-days Updates have not met minimum release age requirement
2026-03-17 14:57:21 +00:00
mrtz b39b3aefc8 fix(cilium): Disable clustermesh again 2026-03-17 13:00:55 +01:00
mrtz a9c658466f feat(cilium): Enable clustermesh 2026-03-17 10:56:43 +01:00
mrtz 730dc2b865 Add kueuectl via nix 2026-03-17 10:14:18 +01:00
mrtz 5eea620225 fix(kueue): Cohort is deprecated 2026-03-16 15:24:21 +01:00
mrtz 863c242a50 fix(kueue): Remove alpha and beta features 2026-03-16 15:22:40 +01:00
mrtz 1cf2303c62 fix(kueue): Use cert-manager 2026-03-16 15:21:46 +01:00
mrtz 81e6823f3d fix(kueue): Disable internal cert 2026-03-16 15:17:52 +01:00
mrtz 2f2d6c1b70 fix(kueue): Bump CRDs 2026-03-16 15:12:11 +01:00
mrtz c99ed29e62 fix(kueue): Wrong crd 2026-03-16 15:09:12 +01:00
mrtz 7eda27cdd6 fix(kueue): Add sync-wave hooks 2026-03-16 15:05:10 +01:00
mrtz bf6542398c fix(kueue): Correct repo 2026-03-16 14:59:17 +01:00
mrtz be7954d499 feat: Add Kueue and JobSet to ekman 2026-03-16 14:52:43 +01:00
mrtz cc8a121bf6 chore: Bump velero to bitnami free version 2026-03-16 10:32:54 +01:00
Gitea Actions 88d21ba674 ci(staging): deploy docs 0d279bb9-debug 2026-03-15 19:45:40 +00:00
Gitea Actions 1eb5249f64 ci(staging): deploy docs 8d2cafc0-debug 2026-03-15 17:35:07 +00:00
Gitea Actions 3ee37fc0f7 ci(staging): deploy docs 1a0619f9-debug 2026-03-15 15:48:21 +00:00
renovate-bot ea4d9f3003 Update Helm release kube-prometheus-stack to v82.10.3 2026-03-15 08:49:11 +00:00
renovate-bot 4566ac7c28 Update Helm release openfga to v0.2.56 2026-03-15 08:47:57 +00:00
renovate-bot c13d4519bd Update Helm release umami to v7.7.3 2026-03-15 00:03:38 +00:00
renovate-bot 077153c344 Update docker.gitea.com/gitea Docker tag to v1.25.5 2026-03-14 19:35:04 +00:00
mrtz e44e83da5e fix(keycloak): Undo last commit 2026-03-14 20:15:36 +01:00
mrtz a541829037 fix(keycloak): Add back RollingUpdate 2026-03-14 20:12:28 +01:00
mrtz b818bead29 fix(keycloak): Disable resource presets 2026-03-14 20:08:02 +01:00
mrtz 7edb275cbe fix(keycloak): Add proxyHeaders 2026-03-14 20:03:54 +01:00
mrtz e7773d7fa5 fix(keycloak): Bump to latest bitnami 2026-03-14 19:58:29 +01:00
mrtz 3ba1ba12aa fix(keycloak): Use theme from gitea 2026-03-14 18:56:50 +01:00
mrtz bfc2bfdf9d fix(keycloak): Migrate theme to gitea 2026-03-14 18:20:51 +01:00
mrtz 14fa2447ec fix(dex): Kill it 2026-03-14 17:55:43 +01:00
mrtz ffc3ca2a24 fix(dex): Disable dex in values only nginx 2026-03-14 17:42:29 +01:00
mrtz c0cc05f0dd fix(dex): CORS for *.oceanbox.io 2026-03-14 17:39:15 +01:00
mrtz 98dde62710 fix(dex): Extend scopes 2026-03-14 17:38:53 +01:00
mrtz b0a986807b fix(dex): Fix for options 2026-03-14 17:34:06 +01:00
mrtz 81d69fb8cd fix(dex): Allow * 2026-03-14 17:33:30 +01:00
mrtz cd2280b5ed fix(dex): Allow cors 2026-03-14 17:26:40 +01:00
mrtz 0b2119b769 fix(dex): Cors allow all 2026-03-14 17:12:12 +01:00
mrtz 352acc54b0 fix(cnp): Allow graph.microsoft.com 2026-03-14 17:03:01 +01:00
mrtz 365c47f621 fix(dex): Set default scopes 2026-03-14 16:49:05 +01:00
mrtz 8ecd09734e fix(dex): Add theme 2026-03-14 16:40:09 +01:00
mrtz ff8f3387ea fix(dex): Only dev for now 2026-03-14 16:26:24 +01:00
mrtz 0728ac0d8b fix(dex): Only 1 replica for now 2026-03-14 16:16:01 +01:00
mrtz 9e76021c37 fix(argo): Allow dex 2026-03-14 16:13:03 +01:00
mrtz d08937816d fix(dex): Move to tos1 2026-03-14 16:10:57 +01:00
mrtz 9f34fc8222 refactor: Replace pocket-id with dex 2026-03-14 14:58:22 +01:00
mrtz 0805e0c988 fix(pocket-id): One Instance 2026-03-13 18:04:05 +01:00
mrtz 1520d72b59 fix(argo): Allow pocket-id in sys 2026-03-13 18:01:08 +01:00
mrtz 67cb247556 fix(pocket-id): Everything into sys 2026-03-13 17:59:02 +01:00
mrtz 16f9976abb fix(nix): Not a function 2026-03-13 17:57:24 +01:00
mrtz cfdb9f1fdd feat(pocket-id): Add Pocket ID 2026-03-13 17:53:18 +01:00
renovate-bot 6dc57af5ae Update Helm release argo-cd to v9.4.10 2026-03-12 15:47:37 +00:00
renovate-bot 7d6cf3b86e Update Helm release argo-workflows to v0.47.5 2026-03-12 15:25:10 +00:00
renovate-bot 31b62ef939 Update Helm release keycloak to v24.9.0 2026-03-12 12:37:39 +00:00
mrtz d2aa9e7588 fix(prom): Whitespace is important 2026-03-12 12:26:07 +00:00
mrtz b5486042f7 chore(prom): Bump to latest 2026-03-12 12:21:07 +00:00
mrtz 50f3bef3f1 chore(prom): Update CRDs 2026-03-12 12:16:34 +00:00
mrtz ac7fbf93b7 chore(prometheus): Bump to latest on ekman 2026-03-12 12:12:54 +00:00
simkir 4223f912e2 Revert "atlantis: Change beta over to beta umami site"
This reverts commit e049ec06b7.
2026-03-12 10:18:39 +01:00
simkir e049ec06b7 atlantis: Change beta over to beta umami site 2026-03-12 10:11:54 +01:00
Gitea Actions 7260a4af69 ci(staging): deploy makai d5e61949-debug 2026-03-12 08:51:05 +00:00
Gitea Actions 55571c6573 ci(staging): deploy docs e9fd3fc6-debug 2026-03-12 08:29:07 +00:00
simkir 204e7149c3 Allow Eli Anne and Hans Kristian to see themselves 2026-03-12 09:01:53 +01:00
Gitea Actions 8741e59de6 ci(staging): deploy docs 214d775b-debug 2026-03-11 12:51:53 +00:00
Gitea Actions eca8c357cd ci(staging): deploy docs 4a073026-debug 2026-03-11 12:46:47 +00:00
mrtz fe590bb37d fix(docs): Add healthchecks 2026-03-11 12:43:36 +00:00
Gitea Actions 56525c9c42 ci(staging): deploy docs 7fb356d1-debug 2026-03-11 12:40:39 +00:00
Gitea Actions 77fb7b505a ci(staging): deploy docs 65bd9569-debug 2026-03-11 12:36:01 +00:00
Gitea Actions aa10e94d11 ci(staging): deploy docs 9d16ceb8-debug 2026-03-11 12:29:24 +00:00
Gitea Actions a2de56a83a ci(staging): deploy docs b465e9ff-debug 2026-03-11 08:13:07 +00:00
Gitea Actions 0900c376ec ci(staging): deploy docs 9f27748c-debug 2026-03-11 06:17:20 +00:00
Gitea Actions e2a947f38a ci(staging): deploy docs 799accff-debug 2026-03-11 05:45:47 +00:00
Gitea Actions 999d7f3355 ci(staging): deploy makai 368cae58-debug 2026-03-10 19:48:54 +00:00
mrtz 207d6d996a fix(atlantis): Remove limits for prod redis 2026-03-10 14:04:20 +00:00
mrtz 85a9fb1d70 fix(prometheus): Remove duplicate field) 2026-03-10 13:43:36 +00:00
mrtz 5ccfb4aa89 fix(prometheus): Add cluster to env 2026-03-10 13:29:51 +00:00
Gitea Actions 5ffddfb205 ci(prod): deploy codex v1.46.5 2026-03-10 13:22:08 +00:00
Gitea Actions d175998762 ci(prod): deploy atlantis v1.46.5 2026-03-10 13:22:04 +00:00
Gitea Actions 78792bab72 ci(staging): deploy atlantis 23006866-debug 2026-03-10 13:21:09 +00:00
Gitea Actions ac157dd12d ci(prod): deploy sorcerer v1.46.5 2026-03-10 13:20:42 +00:00
mrtz ab4e7b89fa fix(prometheus): Don't ctrl+v 2026-03-10 13:18:47 +00:00
mrtz bb254e30f3 fix(prometheus): Bump CRDs 2026-03-10 13:15:29 +00:00
mrtz e3daeccdb4 fix(prometheus): Missing bracket 2026-03-10 12:56:53 +00:00
mrtz d72df1fd0d chore(prometheus): Bump to latest on hel1 2026-03-10 12:51:23 +00:00
Gitea Actions b77cb601fe ci(prod): deploy codex v1.42.17 2026-03-10 12:09:23 +00:00
Gitea Actions 063f6f8b89 ci(prod): deploy atlantis v1.42.17 2026-03-10 12:09:19 +00:00
Gitea Actions 4b2eac93ef ci(staging): deploy docs 0aa4082d-debug 2026-03-10 07:40:17 +00:00
Gitea Actions 8c296de10a ci(staging): deploy docs 819e56a5-debug 2026-03-09 20:28:51 +00:00
Gitea Actions f491cb7df7 ci(staging): deploy docs d0c093d7-debug 2026-03-09 20:24:12 +00:00
Gitea Actions d92cb46c94 ci(staging): deploy docs 2c2a839c-debug 2026-03-09 15:23:00 +00:00
Gitea Actions 6a25649cb8 ci(staging): deploy docs a3ed6af2-debug 2026-03-09 14:24:25 +00:00
Gitea Actions 521335b270 ci(staging): deploy docs 17b898d7-debug 2026-03-09 14:12:39 +00:00
Gitea Actions 442c7b663d ci(prod): deploy codex v1.42.16 2026-03-09 13:42:40 +00:00
Gitea Actions ee854ee384 ci(prod): deploy atlantis v1.42.16 2026-03-09 13:42:31 +00:00
Gitea Actions 1881027981 ci(prod): deploy codex v1.46.4 2026-03-09 13:40:27 +00:00
Gitea Actions d23e7fd4f6 ci(prod): deploy atlantis v1.46.4 2026-03-09 13:40:21 +00:00
Gitea Actions 08eaef297f ci(staging): deploy atlantis d4e612cb-debug 2026-03-09 13:39:03 +00:00
Gitea Actions 826badf7dc ci(prod): deploy sorcerer v1.46.4 2026-03-09 13:38:57 +00:00
Gitea Actions 0a29b5edf4 ci(staging): deploy docs 1f8dc1f4-debug 2026-03-09 13:28:20 +00:00
Gitea Actions ff8e632a2e ci(staging): deploy docs d6468b0d-debug 2026-03-09 13:25:26 +00:00
Gitea Actions f8f97754a4 ci(staging): deploy docs a0c4f2f7-debug 2026-03-09 13:22:10 +00:00
Gitea Actions 79ea3f74b7 ci(staging): deploy docs 3f4cd2f0-debug 2026-03-09 13:17:46 +00:00
Gitea Actions 78f17e17f7 ci(staging): deploy docs 28994314-debug 2026-03-09 13:04:50 +00:00
Gitea Actions 9dff187e33 ci(staging): deploy docs ae0a776c-debug 2026-03-09 12:41:12 +00:00
Gitea Actions cfc80f6f09 ci(staging): deploy docs ae53ae78-debug 2026-03-09 10:59:34 +00:00
Gitea Actions 25922f2cf0 ci(staging): deploy docs 20ba437f-debug 2026-03-09 10:56:49 +00:00
Gitea Actions cae367951d ci(staging): deploy docs b1df963d-debug 2026-03-09 09:48:26 +00:00
Gitea Actions a9a2743fab ci(staging): deploy docs 8a7a7e4f-debug 2026-03-09 09:43:55 +00:00
mrtz ed452a8ded fix(atlantis): Remove limits from deployment and redis 2026-03-09 10:33:15 +01:00
Gitea Actions 3957f89c95 ci(staging): deploy docs d1742a68-debug 2026-03-09 09:27:17 +00:00
Gitea Actions 3674896345 ci(staging): deploy docs e74f593f-debug 2026-03-09 09:25:23 +00:00
Gitea Actions 9d7af56981 ci(staging): deploy docs 6248a4a6-debug 2026-03-09 08:58:37 +00:00
Gitea Actions faa6acaedc ci(staging): deploy docs 31cf00b2-debug 2026-03-09 08:34:40 +00:00
renovate-bot 90b4d498f0 Update git.oceanbox.io/oceanbox/poseidon/atlantis Docker tag to v1.46.3 2026-03-08 07:34:14 +00:00
renovate-bot 60901fe1fc Update git.oceanbox.io/oceanbox/poseidon/codex Docker tag to v1.46.3 2026-03-08 07:34:07 +00:00
renovate-bot 4026bef580 Update git.oceanbox.io/oceanbox/poseidon/sorcerer Docker tag to v1.46.3 2026-03-08 00:02:44 +00:00
renovate-bot 37cc044120 Update Helm release umami to v7.7.2 2026-03-07 13:43:39 +00:00
Gitea Actions 4094bdf44d ci(staging): deploy docs b29798ef-debug 2026-03-06 14:57:17 +00:00
Gitea Actions 63441f83e0 ci(prod): deploy codex v1.42.15 2026-03-06 09:48:19 +00:00
Gitea Actions b1596c105f ci(prod): deploy atlantis v1.42.15 2026-03-06 09:47:39 +00:00
Gitea Actions db44f5fa23 ci(prod): deploy sorcerer v1.42.15 2026-03-06 09:46:59 +00:00
renovate-bot bc13d5989b Update Helm release umami to v7.7.1 2026-03-05 21:09:20 +00:00
renovate-bot c243ade6d6 Update jobset Docker tag to v0.11.1 2026-03-05 18:16:37 +00:00
Gitea Actions 76e951bd49 ci(prod): deploy codex v1.46.3 2026-03-05 10:12:58 +00:00
Gitea Actions 3003bf16f3 ci(prod): deploy atlantis v1.46.3 2026-03-05 10:12:54 +00:00
Gitea Actions bb39438196 ci(prod): deploy sorcerer v1.46.3 2026-03-05 10:11:40 +00:00
Gitea Actions 1542aa23e7 ci(staging): deploy atlantis 35d4e6b1-debug 2026-03-05 10:11:33 +00:00
renovate-bot 86920e937d Update Helm release argo-cd to v9.4.7 2026-03-05 08:52:38 +00:00
mrtz aaf8f07a3a chore(cilium): Bump hel1 to 1.19.1 2026-03-04 15:34:05 +01:00
simkir 69e80fb6e6 Bump beta v1.46.1 -> v1.46.2 2026-03-04 14:45:53 +01:00
Gitea Actions 15b11e6a6c ci(prod): deploy atlantis v1.46.2 2026-03-04 13:39:41 +00:00
Gitea Actions f7e4dba746 ci(prod): deploy codex v1.46.2 2026-03-04 13:39:37 +00:00
Gitea Actions b269a15b3d ci(staging): deploy codex 38eeb4cc-debug 2026-03-04 13:39:01 +00:00
Gitea Actions 26d878c05c ci(staging): deploy atlantis 38eeb4cc-debug 2026-03-04 13:38:56 +00:00
Gitea Actions fa62279633 ci(prod): deploy sorcerer v1.46.2 2026-03-04 13:38:04 +00:00
Gitea Actions 27de3ab9a2 ci(staging): deploy sorcerer 38eeb4cc-debug 2026-03-04 13:37:09 +00:00
simkir 0662886f31 Bump beta v1.44.1 -> v1.46.1 2026-03-04 14:28:18 +01:00
renovate-bot d3779429dc Update Helm release opentelemetry-collector to v0.146.1 2026-03-04 12:58:14 +00:00
Gitea Actions a651708569 ci(prod): deploy sorcerer v1.46.0 2026-03-04 11:55:08 +00:00
mrtz af6c401dab fix: Working plume tag 2026-03-04 12:30:39 +01:00
Gitea Actions ee7fbf166f ci(prod): deploy atlantis v1.42.14 2026-03-03 16:02:50 +00:00
Gitea Actions af47ffe174 ci(prod): deploy codex v1.42.14 2026-03-03 16:02:46 +00:00
Gitea Actions fb3227b206 ci(prod): deploy codex v1.45.5 2026-03-03 16:00:52 +00:00
Gitea Actions 519710226d ci(prod): deploy atlantis v1.45.5 2026-03-03 16:00:46 +00:00
Gitea Actions e5ee05adc0 ci(staging): deploy codex b6f8430d-debug 2026-03-03 15:59:58 +00:00
Gitea Actions 8d5302a374 ci(prod): deploy codex v1.45.4 2026-03-03 15:59:51 +00:00
Gitea Actions 4a6e5bf349 ci(prod): deploy atlantis v1.45.4 2026-03-03 15:59:40 +00:00
Gitea Actions ace26cca1c ci(prod): deploy sorcerer v1.45.5 2026-03-03 15:59:20 +00:00
Gitea Actions 493d1f53ba ci(prod): deploy sorcerer v1.45.4 2026-03-03 15:57:31 +00:00
mrtz fb42e27f96 fix(cilium): Disable encryption 2026-03-03 15:24:35 +01:00
mrtz 33714ec032 fix(cilium): Enable auditmode 2026-03-03 14:53:23 +01:00
mrtz e3b27f7a4b fix(cilium): Keep envoy on hel1 2026-03-03 14:27:01 +01:00
mrtz 2fccd6e206 feat(cilium): Deploy on Ekman 2026-03-03 14:25:29 +01:00
renovate-bot 592733ad80 Update Helm release umami to v7.7.0 2026-03-03 12:28:32 +00:00
Gitea Actions 04a972df7c ci(prod): deploy codex v1.42.13 2026-03-03 11:38:32 +00:00
Gitea Actions e25ce17369 ci(prod): deploy atlantis v1.42.13 2026-03-03 11:37:50 +00:00
Gitea Actions fa60c5a9bc ci(prod): deploy atlantis v1.45.3 2026-03-03 10:54:33 +00:00
Gitea Actions b11ab3e709 ci(prod): deploy codex v1.45.3 2026-03-03 10:54:29 +00:00
Gitea Actions 4efddc31ba ci(prod): deploy sorcerer v1.45.3 2026-03-03 10:53:16 +00:00
Gitea Actions 1942a10110 ci(staging): deploy atlantis 4873e564-debug 2026-03-03 10:52:49 +00:00
Gitea Actions 7d62696fa1 ci(prod): deploy codex v1.45.2 2026-03-03 09:58:44 +00:00
Gitea Actions 9ea063f8d4 ci(prod): deploy atlantis v1.45.2 2026-03-03 09:58:39 +00:00
Gitea Actions 680147a59a ci(prod): deploy sorcerer v1.45.2 2026-03-03 09:57:21 +00:00
Gitea Actions caef32f86f ci(staging): deploy docs 5de1aec7-debug 2026-03-03 07:28:12 +00:00
Gitea Actions 889efc450a ci(staging): deploy docs 8166dee4-debug 2026-03-02 20:07:17 +00:00
mrtz e3f4cce683 fix: Downgrade prod 2026-03-02 17:52:32 +01:00
renovate-bot 3d49aff36d Update Helm release openfga to v0.2.55 2026-03-02 16:48:40 +00:00
renovate-bot 456884fc3d Update Helm release argo-cd to v9.4.6 2026-03-02 16:45:09 +00:00
mrtz 9241901a1c chore(dapr): Bump to latest on 1.16 2026-03-02 17:20:19 +01:00
Gitea Actions eccb80c3ec ci(prod): deploy atlantis v1.45.1 2026-03-02 14:42:33 +00:00
Gitea Actions 678d53d4fd ci(prod): deploy codex v1.45.1 2026-03-02 14:42:24 +00:00
Gitea Actions 8946a6bd77 ci(prod): deploy sorcerer v1.45.1 2026-03-02 14:41:15 +00:00
renovate-bot e8d6625085 Update Helm release velero to v11.4.0 2026-03-02 14:01:31 +00:00
simkir 5945146f3c grafana: Fix umami weekly users query sorting 2026-03-02 14:16:21 +01:00
Gitea Actions ff4def0d81 ci(staging): deploy docs 58d6c665-debug 2026-02-28 11:34:28 +00:00
Gitea Actions 14d883cb4c ci(prod): deploy atlantis v1.45.0 2026-02-27 15:50:36 +00:00
Gitea Actions 2d880e7971 ci(prod): deploy codex v1.45.0 2026-02-27 15:50:31 +00:00
Gitea Actions e604dd8540 ci(prod): deploy sorcerer v1.45.0 2026-02-27 15:49:19 +00:00
renovate-bot c564aade25 Update Helm release opentelemetry-collector to v0.146.0 2026-02-27 14:15:48 +00:00
Gitea Actions 31134652b6 ci(staging): deploy docs c290d83d-debug 2026-02-27 13:03:51 +00:00
mrtz 9cf39763a0 fix(diadash): Don't hardcore stuff 2026-02-25 17:36:31 +01:00
mrtz fd0274b698 fix: Add diadash to plume 2026-02-25 16:35:48 +01:00
renovate-bot c6141093a3 Update slurm-operator Docker tag to v1 2026-02-24 21:02:06 +00:00
renovate-bot a0d58b1d1e Update slurm Docker tag to v1 2026-02-24 21:01:49 +00:00
renovate-bot d2b334dccf Update cert-manager Docker tag to v1.19.4 2026-02-24 20:54:17 +00:00
Gitea Actions 99a1bdd7e5 ci(staging): deploy makai ce32dbe6-debug 2026-02-24 18:15:41 +00:00
Gitea Actions 2de96339fb ci(staging): deploy makai dd38e702-debug 2026-02-24 16:54:33 +00:00
Gitea Actions 502d59791d ci(staging): deploy makai f570c90c-debug 2026-02-24 16:52:09 +00:00
simkir 3a73ad6cc2 atlantis: Add codex dev to staging cors 2026-02-24 13:50:16 +01:00
simkir 62102698b0 Bump staging codex 2026-02-24 13:45:26 +01:00
Gitea Actions 8ff5239bdc ci(prod): deploy atlantis v1.42.12 2026-02-24 10:34:24 +00:00
Gitea Actions b9c6cc7519 ci(prod): deploy codex v1.42.12 2026-02-24 10:34:20 +00:00
simkir fd8be6d2c7 Bump beta v1.44.1 2026-02-24 11:23:06 +01:00
Gitea Actions 1aa2f66c54 ci(prod): deploy atlantis v1.42.11 2026-02-24 09:19:30 +00:00
mrtz 9f9c5ff2c3 fix: Deploy staging plume 2026-02-24 10:03:18 +01:00
Gitea Actions ec96465d17 ci(prod): deploy atlantis v1.44.1 2026-02-24 08:07:48 +00:00
Gitea Actions 91295a9ad8 ci(prod): deploy sorcerer v1.44.1 2026-02-24 08:06:41 +00:00
mrtz 0064e0c1da fix(jobset): Ignore secret 2026-02-23 19:56:28 +01:00
mrtz ea8c280154 fix(argo): Allow jobsets 2026-02-23 19:52:50 +01:00
mrtz 655fd3827f feat: Add Jobsets 2026-02-23 19:51:18 +01:00
renovate-bot bd85f43980 Update Helm release argo-workflows to v0.47.4 2026-02-23 16:21:39 +00:00
mrtz 170813bf35 fix(kyverno): Ignore annotations and lables 2026-02-23 17:16:18 +01:00
renovate-bot 4fff9667a2 Update Helm release kyverno to v3.7.1 2026-02-23 16:11:31 +00:00
mrtz 46d62fc789 chore(helmfile-cmp): Bump helmfile image 2026-02-23 16:55:43 +01:00
renovate-bot 780c756b79 Update Helm release kube-prometheus-stack to v72.9.1 2026-02-23 15:44:19 +00:00
renovate-bot 6536ca8cae Update Helm release loki to v6.53.0 2026-02-23 15:39:22 +00:00
mrtz cab5108ff1 chore(gatus): Bump to 5.35.0 2026-02-23 16:35:04 +01:00
mrtz 0d26156c2c chore(argocd): Bump all clusters to latest 2026-02-23 16:12:31 +01:00
mrtz 8461f6fa79 fix(argocd): This is not cilium 2026-02-23 16:06:38 +01:00
mrtz d354da0f49 chore: Bump argocd hel1 2026-02-23 16:04:02 +01:00
Gitea Actions 0cdf358d69 ci(prod): deploy codex v1.44.0 2026-02-23 13:02:04 +00:00
Gitea Actions 2a395f603f ci(prod): deploy atlantis v1.44.0 2026-02-23 13:01:58 +00:00
Gitea Actions a464f33106 ci(staging): deploy atlantis 09ef6fb1-debug 2026-02-23 13:00:54 +00:00
Gitea Actions 95b27f5e41 ci(prod): deploy sorcerer v1.44.0 2026-02-23 13:00:47 +00:00
mrtz 459231db7d fix: Remove duplicate helmfile-cmp 2026-02-23 11:25:43 +01:00
mrtz 70f1d7da01 fix: Remove old helper 2026-02-23 11:17:59 +01:00
mrtz 6a859f8c81 fix: Bump to 1.43.3 2026-02-23 11:17:28 +01:00
mrtz f2475a2882 fix: Undeploy 1.43.3 2026-02-23 11:15:57 +01:00
Gitea Actions b904899ad8 ci(prod): deploy atlantis v1.43.3 2026-02-23 10:11:10 +00:00
Gitea Actions f3d11cb9cd ci(prod): deploy codex v1.43.3 2026-02-23 10:11:06 +00:00
Gitea Actions afb367efbc ci(staging): deploy atlantis 43bf7264-debug 2026-02-23 10:10:01 +00:00
Gitea Actions ca5d6db326 ci(prod): deploy sorcerer v1.43.3 2026-02-23 10:09:47 +00:00
mrtz 62713f27dd chore: Bump beta to 1.42.10 2026-02-23 11:01:29 +01:00
Gitea Actions c6094b1968 ci(prod): deploy codex v1.42.10 2026-02-23 09:58:35 +00:00
Gitea Actions 6519b210b2 ci(prod): deploy atlantis v1.42.10 2026-02-23 09:58:10 +00:00
Gitea Actions a2685c721e ci(prod): deploy sorcerer v1.42.10 2026-02-23 09:56:32 +00:00
Gitea Actions 3fbe57b3bc ci(staging): deploy makai 64665f31-debug 2026-02-23 09:00:51 +00:00
Gitea Actions 74e6e6a69c ci(staging): deploy makai ff18286c-debug 2026-02-23 08:07:48 +00:00
Gitea Actions 4ef32f2def ci(staging): deploy docs d07fea42-debug 2026-02-22 09:59:49 +00:00
mrtz 67f73b5cb2 fix(codex): Drop gitlab url 2026-02-17 17:23:04 +01:00
mrtz 1bb1dd09a3 fix(atlantis): Remove hardcoded gitlab link 2026-02-17 17:18:48 +01:00
mrtz e36d36951c fix: Add to default whitelist 2026-02-17 17:13:36 +01:00
mrtz 6488e9b5c3 fix: Add hel1 to argocd whitelsit 2026-02-17 17:09:59 +01:00
mrtz 0ba1a9e5bb fix: Remove acl 2026-02-17 16:33:06 +01:00
mrtz ad1bae4e8e fix: Remove git hooks 2026-02-17 15:39:40 +01:00
simkir f14f604579 Bump atlantis beta 1.42.9 -> 1.43.2 2026-02-17 10:48:36 +01:00
Gitea Actions 8bfa0e67c9 ci(prod): deploy atlantis v1.43.2 2026-02-17 09:46:39 +00:00
Gitea Actions 9234e68bf5 ci(prod): deploy codex v1.43.2 2026-02-17 09:46:35 +00:00
Gitea Actions 7366b7ffa7 ci(staging): deploy codex 7e5c70ea-debug 2026-02-17 09:45:41 +00:00
Gitea Actions e3565f8ef0 ci(staging): deploy atlantis 7e5c70ea-debug 2026-02-17 09:45:36 +00:00
Gitea Actions d0fbbb410b ci(prod): deploy sorcerer v1.43.2 2026-02-17 09:44:50 +00:00
Gitea Actions 1260f8a71e ci(staging): deploy makai 6c39e7f5-debug 2026-02-17 09:31:17 +00:00
simkir b3db48161c atlantis: Add codex prod to allowed origin 2026-02-17 10:26:46 +01:00
simkir 7b6534b20c codex: Enable dapr in prod 2026-02-17 10:17:56 +01:00
simkir eb64e50ae6 codex: Fix signout redirect uri's 2026-02-17 10:06:28 +01:00
simkir e99debc111 codex: Enable dapr 2026-02-17 09:58:20 +01:00
simkir edd3459453 codex: Mount dapr api token secret 2026-02-17 09:52:13 +01:00
simkir db222bbd08 Bump atlantis beta 1.42.7 -> 1.42.9 2026-02-17 09:45:50 +01:00
Gitea Actions dc98abcf8a ci(prod): deploy codex v1.42.9 2026-02-17 08:39:56 +00:00
Gitea Actions a7b46b7076 ci(prod): deploy atlantis v1.42.9 2026-02-17 08:39:51 +00:00
simkir 51e9a85714 codex: Add ArchiveSvc to appsettings 2026-02-16 14:26:04 +01:00
Gitea Actions 9a2d1b29c4 ci(prod): deploy atlantis v1.42.8 2026-02-16 12:25:28 +00:00
Gitea Actions 1bebc7ed70 ci(prod): deploy codex v1.43.1 2026-02-16 12:21:59 +00:00
Gitea Actions f6f42ff6e0 ci(prod): deploy atlantis v1.43.1 2026-02-16 12:21:55 +00:00
Gitea Actions 33ae1ca753 ci(staging): deploy atlantis 3cb281f7-debug 2026-02-16 12:20:53 +00:00
Gitea Actions 8cd381a69e ci(prod): deploy sorcerer v1.43.1 2026-02-16 12:20:34 +00:00
mrtz 1d43829e62 fix: Deprecate atlantis.beta and atlas 2026-02-16 12:44:14 +01:00
mrtz ddcb24f9c9 fix: Remove atlantis beta 2026-02-16 12:42:00 +01:00
mrtz cd20a60538 fix(grafana): Lower requests 2026-02-16 12:41:06 +01:00
Gitea Actions 63e19b8e7e ci(staging): deploy makai 0e2db4f2-debug 2026-02-16 11:30:24 +00:00
simkir 97b765d0fd Bump atlantis beta 1.42.2 -> 1.42.7 2026-02-16 12:28:51 +01:00
Gitea Actions 45c764c505 ci(prod): deploy atlantis v1.42.7 2026-02-16 10:52:55 +00:00
Gitea Actions 8ef93878ab ci(prod): deploy codex v1.43.0 2026-02-16 10:27:51 +00:00
Gitea Actions b5039f8955 ci(prod): deploy atlantis v1.43.0 2026-02-16 10:27:45 +00:00
Gitea Actions 435ed38a20 ci(staging): deploy atlantis a1a2d7b9-debug 2026-02-16 10:26:48 +00:00
Gitea Actions 7c33a65c08 ci(prod): deploy sorcerer v1.43.0 2026-02-16 10:26:40 +00:00
Gitea Actions c714f7568f ci(staging): deploy docs b4196643-debug 2026-02-15 09:42:16 +00:00
renovate-bot bb1e0ce546 Update Helm release argo-rollouts to v2.40.6 2026-02-15 07:55:15 +00:00
renovate-bot 05e9235369 Update Helm release umami to v7 2026-02-15 00:09:37 +00:00
mrtz 8f4d9d4639 fix(gatus): Add beta and dev labels 2026-02-14 16:24:05 +01:00
renovate-bot 9dd5722ea0 Update Helm release argo-workflows to v0.47.3 2026-02-14 11:45:06 +00:00
renovate-bot c3f84d8ea3 Update Helm release gatus to v1.5.0 2026-02-14 11:44:49 +00:00
Gitea Actions 5fd82cd19d ci(prod): deploy codex v1.42.4 2026-02-13 17:52:43 +00:00
Gitea Actions 321dd9e939 ci(prod): deploy atlantis v1.42.4 2026-02-13 17:52:39 +00:00
Gitea Actions 21a6cfdfad ci(staging): deploy atlantis 18e06783-debug 2026-02-13 17:51:37 +00:00
Gitea Actions f1427d82c9 ci(prod): deploy sorcerer v1.42.4 2026-02-13 17:51:21 +00:00
mrtz cc6551752c feat: Release on Friday 13th version 42 2026-02-13 18:30:08 +01:00
Gitea Actions 55cf4cbbcc ci(prod): deploy codex v1.42.3 2026-02-13 17:18:04 +00:00
Gitea Actions 53c1b07cac ci(prod): deploy atlantis v1.42.3 2026-02-13 17:18:00 +00:00
mrtz 62542caa55 fix: Install redis datasource 2026-02-13 18:17:42 +01:00
Gitea Actions d1d5b51879 ci(staging): deploy atlantis bfed892e-debug 2026-02-13 17:16:54 +00:00
Gitea Actions cde0671238 ci(prod): deploy sorcerer v1.42.3 2026-02-13 17:16:43 +00:00
renovate-bot 91a6795bfc Update dragonfly-operator Docker tag to v1.4.0 2026-02-13 17:00:13 +00:00
renovate-bot 46d0dcb545 Update Helm release plugin-barman-cloud to v0.5.0 2026-02-13 16:57:12 +00:00
renovate-bot a5da0f745a Update Helm release opentelemetry-collector to v0.145.0 2026-02-13 16:50:03 +00:00
renovate-bot 27f407d685 Update Helm release openfga to v0.2.54 2026-02-13 16:47:05 +00:00
mrtz e3d70b6c7f feat: Bump beta to 1.42.2 2026-02-13 17:41:43 +01:00
Gitea Actions e88544abdb ci(prod): deploy codex v1.42.2 2026-02-13 16:39:03 +00:00
Gitea Actions 7961dc30db ci(prod): deploy atlantis v1.42.2 2026-02-13 16:38:59 +00:00
Gitea Actions fce0f71832 ci(staging): deploy atlantis bc9dccaa-debug 2026-02-13 16:37:47 +00:00
Gitea Actions 4207c28e45 ci(prod): deploy sorcerer v1.42.2 2026-02-13 16:37:31 +00:00
Gitea Actions abaeae3603 ci(prod): deploy plume v1.6.13 2026-02-13 16:11:27 +00:00
Gitea Actions 6ee7490954 ci(staging): deploy plume 9d99f7cf-debug 2026-02-13 16:11:07 +00:00
Gitea Actions 3cab8a1edf ci(staging): deploy plume 982a30de-debug 2026-02-13 16:06:07 +00:00
mrtz 461f2a8f7d fix: Switch plume to gitea 2026-02-13 17:01:28 +01:00
mrtz debd8fe561 fix: Release 2026-02-13 16:59:36 +01:00
Gitea Actions 7352efcaa5 ci(prod): deploy atlantis v1.42.1 2026-02-13 15:58:08 +00:00
Gitea Actions c4a6539913 ci(prod): deploy codex v1.42.1 2026-02-13 15:58:05 +00:00
Gitea Actions 14ed79c528 ci(prod): deploy sorcerer v1.42.1 2026-02-13 15:56:56 +00:00
Gitea Actions e3dcf6b0a8 ci(prod): deploy atlantis v1.42.0 2026-02-13 15:47:35 +00:00
Gitea Actions add314bbf1 ci(prod): deploy codex v1.42.0 2026-02-13 15:45:14 +00:00
Gitea Actions aab18c0a72 ci(staging): deploy codex d34652dd-debug 2026-02-13 15:44:23 +00:00
Gitea Actions d311fcc17c ci(staging): deploy atlantis d34652dd-debug 2026-02-13 15:44:14 +00:00
Gitea Actions 3f1ca12a8a ci(prod): deploy sorcerer v1.42.0 2026-02-13 15:43:42 +00:00
Gitea Actions bde7b6068a ci(staging): deploy plume d9375078-debug 2026-02-13 15:16:18 +00:00
Gitea Actions d317537799 ci(staging): deploy plume bfbc0be1-debug 2026-02-13 14:50:51 +00:00
Gitea Actions 8e5016284e ci(staging): deploy plume ff7983ec-debug 2026-02-13 14:44:28 +00:00
Gitea Actions 9ecf89c8d0 ci(staging): deploy plume c10e4b29-debug 2026-02-13 14:31:00 +00:00
mrtz 9416ea5512 feat(poseidon): Release beta 1.41.7 2026-02-12 17:26:41 +01:00
mrtz b12deba899 fix(poseidon): Wrong way 2026-02-12 17:21:33 +01:00
Gitea Actions 83e446568f ci(prod): deploy codex v1.41.7 2026-02-12 16:21:32 +00:00
Gitea Actions c222b4dd12 ci(prod): deploy atlantis v1.41.7 2026-02-12 16:21:27 +00:00
Gitea Actions c8ca2e7fca ci(prod): deploy sorcerer v1.41.7 2026-02-12 16:20:18 +00:00
Gitea Actions 93484df20d ci(prod): deploy atlantis v1.41.6 2026-02-12 16:13:51 +00:00
Gitea Actions a15c24ed00 ci(prod): deploy sorcerer v1.41.6 2026-02-12 16:12:42 +00:00
Gitea Actions db0918c40a ci(prod): deploy sorcerer v1.41.5 2026-02-12 16:03:53 +00:00
Gitea Actions 64e37101be ci(staging): deploy sorcerer 06e2e5b9-debug 2026-02-12 16:02:07 +00:00
mrtz 9de9a27845 fix(atlantis): Remove secret remover 2026-02-12 16:56:32 +01:00
mrtz 5e1d6109db fix(atlantis): Try again to remove secret 2026-02-12 16:54:18 +01:00
mrtz a86dec26ae fix(atlantis): Remove old 2026-02-12 16:52:52 +01:00
mrtz 5ce6701aff fix(atlantis): Remove secret 2026-02-12 16:52:33 +01:00
mrtz 0fc78f9f01 fix(poseidon): No Autosync 2026-02-12 16:51:06 +01:00
mrtz 53950f1397 fix(sorcerer): Remvoe unused 2026-02-12 16:49:36 +01:00
mrtz e9db733f06 fix(sorcerer): No autosync 2026-02-12 16:48:25 +01:00
mrtz 966c1bb92c fix(atlantis): Remove db secret and autosync 2026-02-12 16:47:22 +01:00
mrtz b72fd6270d feat(poseidon): Push to beta 2026-02-12 16:36:04 +01:00
mrtz 4e30fbd542 fix(hs): Move makai 2026-02-12 16:22:20 +01:00
mrtz 6da4d37558 fix(makai/docs): Move to hel1 2026-02-12 16:19:28 +01:00
mrtz 4391a3d7cf fix(hs): Correct ip 2026-02-12 15:58:10 +01:00
mrtz e397903a6f fix(hs): Persist hel1 in dc net 2026-02-12 15:46:27 +01:00
mrtz a935926cf8 fix(hs): Change docs IP 2026-02-12 15:44:03 +01:00
mrtz 0f595fc2dd fix(atlantis): No super user secret please 2026-02-12 15:41:37 +01:00
mrtz fadb7ca5a6 fix(docs): No more envs 2026-02-12 15:34:20 +01:00
mrtz f47fa7d20d fix(docs): Move to hel1 2026-02-12 15:31:00 +01:00
mrtz 82c56c04ba fix(atlantis): Remove secrets 2026-02-12 14:14:53 +01:00
mrtz 4fc5b4f7e7 fix(sorcere/atlantis): Naming beta sorcerer *.ekman 2026-02-12 14:11:13 +01:00
mrtz 1904f02d65 fix(sorcerer): Correct store 2026-02-12 13:39:27 +01:00
mrtz 72fd6c638f fix(sorcerer): Bump redis specs 2026-02-12 13:37:14 +01:00
mrtz 9433bd431e fix(atlantius): No masters and wrong rabbit 2026-02-12 13:32:40 +01:00
mrtz 2bdaab1bd7 fix(sorcerer): Undo 2026-02-12 13:31:02 +01:00
mrtz 7239c6118b fix(sorcerer): Naming 2026-02-12 13:29:54 +01:00
mrtz 0229238c0c fix(sorcerer): Add missing kustomize dirs 2026-02-12 13:28:34 +01:00
mrtz 74ea8d1d05 fix(sorcerer): Switch to rbd 2026-02-12 13:25:59 +01:00
mrtz 01cbc0f588 fix(sorcerer): Beta only 2026-02-12 13:23:21 +01:00
mrtz 0b1d686b4a feat(sorcerer): Add beta 2026-02-12 13:19:50 +01:00
mrtz 7b0fef382d fix(atlatnis): Use beta bindings 2026-02-12 12:52:00 +01:00
mrtz 6d2e053a0b fix(atlantis): Use beta redis 2026-02-12 12:11:46 +01:00
mrtz e0682e740c fix(atlantis): Use dragonfly in beta 2026-02-12 11:11:37 +01:00
mrtz a34a63089d fix(atlantis): Beta 2026-02-12 11:00:44 +01:00
mrtz cf94f5b9b7 fix(cilium+hs): Back to lb for ssh 2026-02-10 12:05:38 +01:00
mrtz f1eb50fcd5 fix(headscale): Move internal git to cilium 2026-02-10 10:42:20 +01:00
mrtz 0fea3410a2 fix(cilium): Disable hostnetwork
https://github.com/cilium/cilium/issues/38559
2026-02-10 10:28:07 +01:00
mrtz 8d63ca97c3 fix(cilium): STRING 2026-02-10 10:19:15 +01:00
mrtz 89c291dcd9 fix(cilium): Force gatewayclass creation 2026-02-10 10:18:09 +01:00
mrtz deb3769f25 fix(namecheap): Set correct apikey 2026-02-10 09:45:12 +01:00
mrtz ba5f392e92 fix(cilium): Make argo happy 2026-02-10 09:39:31 +01:00
mrtz 382f8a6de1 fix(cilium): Use DNS cert 2026-02-10 09:38:40 +01:00
mrtz d4adb6eb7c fix(cilium): Combine Gateways 2026-02-10 09:33:43 +01:00
mrtz e527d32697 fix(cilium): Typo 2026-02-10 09:30:15 +01:00
mrtz 124fafcaf7 fix(cilium): Correct hostname 2026-02-10 09:27:54 +01:00
mrtz 8efdf8d4c8 feat(cilium): Enable gateway 2026-02-10 09:24:43 +01:00
mrtz c39c188020 fix(certmgr): Enable gatewayApi 2026-02-09 16:45:33 +01:00
mrtz 7e5836383c fix(cilium): Bump patch and set upgradeComp 2026-02-09 16:23:16 +01:00
mrtz 09d5ff9ab0 fix(cilium): Bump version 2026-02-09 16:09:31 +01:00
mrtz 36ed342f53 fix(cilium): Without v? 2026-02-09 16:08:36 +01:00
mrtz 3e811e03aa fix: Back to without cilium 2026-02-09 16:05:06 +01:00
mrtz 9233a5307e fix(cilium): Add cilium 2026-02-09 16:03:44 +01:00
mrtz 655679794a fix(cilium): Oci requires v 2026-02-09 16:02:32 +01:00
mrtz d802941faa fix(cilium): Switch to oci chart
Why OCI Registries?

Storing Helm charts in OCI registries alongside container images offers several advantages:

- Signed charts — All charts are signed with cosign for verification
- Simpler setup — No repository configuration needed
- Digest pinning — Reference exact chart versions by SHA for reproducibility
- Unified tooling — Use the same registry infrastructure for images and charts
2026-02-09 16:00:26 +01:00
mrtz c61617f276 fix(argo): Add cilium and certmgr oci charts 2026-02-09 15:59:04 +01:00
mrtz e1c78c3703 fix(cilium): Audit mode for now 2026-02-09 15:27:03 +01:00
mrtz c483dfc18b fix(cilium): Enable proxy protocol on hel1 2026-02-09 15:22:31 +01:00
mrtz cb8b035fe0 fix(cilium): Version based on cluster 2026-02-09 15:19:11 +01:00
renovate-bot 03d458be7e Update twinproduction/gatus Docker tag to v5.34.0 2026-02-09 13:40:04 +00:00
mrtz 305ca06352 fix(cilium): Enable gateway api on hel1 2026-02-09 14:35:21 +01:00
renovate-bot 9d1e04abf4 Update Helm release mariadb-operator to v25.10.4 2026-02-09 13:20:58 +00:00
mrtz 6f60b8c110 fix: Only works in root 2026-02-09 13:34:42 +01:00
mrtz e71f983a0b fix: Move archmeister to attic 2026-02-09 13:10:15 +01:00
mrtz 01b154ba8b fix(plume): Use new git repo 2026-02-09 13:05:36 +01:00
mrtz 7639eee45b ci: Remove gitlab-ci 2026-02-09 13:03:36 +01:00
renovate-bot bb33b5ec60 Update cert-manager Docker tag to v1.19.3 2026-02-09 11:59:35 +00:00
Gitea Actions 67675d0146 ci(staging): deploy docs 5c4cda2e-debug 2026-02-06 18:15:53 +00:00
Gitea Actions 1f1639aeaf ci(staging): deploy plume f8f5e004-debug 2026-02-06 18:04:29 +00:00
Gitea Actions 80f5cba2e9 ci(staging): deploy plume cdc4dda5-debug 2026-02-06 17:59:12 +00:00
mrtz 2f7218bc99 fix(hs): Readd so whitelist in gitea works 2026-02-06 18:56:30 +01:00
mrtz ffbdde94f7 fix(hs): Persist values 2026-02-06 18:47:04 +01:00
mrtz d8883a4ec8 fix(hs): Remove Magic DNS for gitea 2026-02-06 18:46:21 +01:00
Gitea Actions 562b21e4b2 ci(staging): deploy plume ff19f1a6-debug 2026-02-06 17:39:18 +00:00
Gitea Actions 7250ad80b2 ci(staging): deploy plume 2a7a94fe-debug 2026-02-06 17:32:47 +00:00
mrtz 30b3103cd3 Release staging atlantis/sorcerer 2026-02-05 17:58:26 +01:00
mrtz 05f067e691 chore(docs): Bump again 2026-02-05 10:28:50 +01:00
mrtz dc93f45e32 chore: Bump docs 2026-02-05 10:28:21 +01:00
mrtz feefc87ea7 fix(attic): Remove 2026-02-03 17:13:14 +01:00
mrtz 513361728e fix(headscale): Remove spacing 2026-02-03 13:24:07 +01:00
mrtz 166ba8ae58 fix(argo): Switch to gitea for oceanbox cluster 2026-02-03 13:10:01 +01:00
mrtz faabcea369 fix(gatus): Disable vtn sorcerer 2026-02-03 12:37:16 +01:00
mrtz 8fc175b209 fix: Switch hel1 to gitea 2026-02-03 12:10:49 +01:00
mrtz 9bd7adb057 fix(argo): Add new url to sys 2026-02-03 11:03:10 +01:00
mrtz b41171d8d1 feat(ekman): Move to git.oceanbox.io 2026-02-03 11:00:39 +01:00
mrtz 8c14fb7034 chore(nginx): Bump to fix CVE 2026-02-03 10:15:11 +01:00
juselius fceba8ccea fix: add eli and hansi to ocenographers acl 2026-02-02 15:37:19 +01:00
juselius bfb16288b9 Merge branch 'main' of gitlab.com:oceanbox/manifests 2026-02-02 12:31:00 +01:00
juselius d90f43411f fix: migrate rossby manifests to gitea 2026-02-02 12:28:36 +01:00
mrtz a30a5f28fb fix: Use working env 2026-02-01 22:46:56 +01:00
mrtz e4cb8b36df fix(gitea/pf): Add mail 2026-02-01 22:40:08 +01:00
juselius ff956948bf fix: add hel1 lb to whitelist 2026-02-01 15:18:36 +01:00
juselius 18e3815e03 fix: change attic source to git.oceanbox.io 2026-02-01 15:12:28 +01:00
juselius 2dfca9bcbc fix: add port 22 to hel1 for oceanographers 2026-02-01 14:56:52 +01:00
mrtz 5a013b42ba fix: Add gitea to sys-proj and whitelist 2026-02-01 11:56:37 +01:00
mrtz 5cb695e096 fix(gitea): Don't use azure scopes 2026-02-01 11:19:12 +01:00
mrtz 3b7582edd0 fix(gitea): TRy new claim 2026-02-01 11:04:04 +01:00
mrtz 49321a0fa0 fix(gitea): Set admins 2026-02-01 10:52:15 +01:00
mrtz 9b55685967 fix(gitea): Add ekman/oceanbox to whitelist 2026-02-01 10:34:41 +01:00
mrtz d257651195 fix(gitea): Only link on login 2026-02-01 10:33:35 +01:00
mrtz 63b6d99955 chore: Bump makai 2026-01-29 19:06:09 +01:00
mrtz a48077f9b3 fifix(gitea): Enable registrations for nickname and email 2026-01-29 17:40:34 +01:00
Radovan Bast 9c60baeff9 ci: docs 2026-01-29 09:57:25 +00:00
mrtz d30515ab76 ci: docs 2026-01-29 09:41:42 +00:00
mrtz 85117976c3 ci: docs 2026-01-29 09:32:30 +00:00
mrtz 2ec369f428 ci: docs 2026-01-29 09:29:39 +00:00
mrtz aadf8995e6 ci: docs 2026-01-29 09:27:09 +00:00
mrtz 53776f68dd ci: docs 2026-01-29 09:18:51 +00:00
mrtz d4a56867e5 fix: Add docs to headscale 2026-01-29 10:00:56 +01:00
mrtz 8ae4f2c854 fix: Set registry path 2026-01-29 09:43:47 +01:00
mrtz ee21078412 fix: docs 2026-01-29 09:40:34 +01:00
mrtz a0e69a053d ci: docs 2026-01-29 08:38:15 +00:00
mrtz 3bae9f5065 fix: makai -> docs 2026-01-29 09:29:01 +01:00
mrtz cf816e621b feat: Add docs 2026-01-29 09:26:53 +01:00
Radovan Bast b71da56da7 ci: makai 2026-01-28 12:35:09 +00:00
simkir 3b6ed8e544 ci: makai 2026-01-28 11:48:46 +00:00
mrtz 9cbb16ae08 fix(gitea): Increase session lifetime 2026-01-27 21:04:23 +01:00
mrtz 708a44fa9b fix(gitea): Typo 2026-01-26 17:39:33 +01:00
mrtz f4a53934c2 fix(gitea): remove unused 2026-01-26 17:30:44 +01:00
mrtz 79ad206db3 fix(gitea): Reset 2026-01-26 17:28:56 +01:00
mrtz 6c850b312c fix(gitae):... 2026-01-26 17:27:36 +01:00
mrtz d1c4b25499 fix(gitea): More secrets 2026-01-26 17:25:11 +01:00
mrtz 265c370787 fix(gitea): Also for attachements 2026-01-26 17:23:27 +01:00
mrtz ed017894b5 fix(gitea): Dup 2026-01-26 17:21:33 +01:00
mrtz 9f0503bbf3 fix(gitea): Use env 2026-01-26 17:18:29 +01:00
mrtz 5aa937acb3 fix(gitea): All in buckets 2026-01-26 17:16:08 +01:00
mrtz 548c942b42 fix(hs): Add new gitea 2026-01-26 09:42:38 +01:00
mrtz b49f8dc005 fix(gitea): Change to public DNS with private IP 2026-01-26 08:55:16 +01:00
mrtz 955424cc70 Merge branch 'renovate/gatus-1.x' into 'main'
Update Helm release gatus to v1.4.5

See merge request oceanbox/manifests!71
2026-01-25 21:08:35 +01:00
mrtz 6e7fa3a642 fix(gitea): Cleanup 2026-01-25 20:38:43 +01:00
mrtz f6d6282aea chore(gitea): Bump 2026-01-25 11:45:13 +01:00
Renovate Bot f20375c7ca Update Helm release gatus to v1.4.5 2026-01-25 08:58:18 +00:00
mrtz 127722c4b4 fix(argo): Add postfix 2026-01-24 16:51:12 +01:00
mrtz d345172d8a fix(postfix): Move into manifests 2026-01-24 16:49:33 +01:00
mrtz e55212a859 fix(postfix): Plain 2026-01-24 16:47:38 +01:00
mrtz 8a39fb8afc Intiall Postfix setup :/ 2026-01-24 15:52:10 +01:00
mrtz 212739ae94 Merge branch 'automated/npins-update-20260123' into 'main'
chore: update npins dependencies

See merge request oceanbox/manifests!70
2026-01-24 08:29:11 +01:00
mrtz a940a2fedf fix(gitea): More metrics and NodePort 2026-01-23 20:03:56 +01:00
mrtz 38264b4879 fix(gitea): LB 2026-01-23 19:43:51 +01:00
mrtz 941e98abb8 fix(gitea): Add push to create and lb 2026-01-23 19:42:51 +01:00
mrtz 09b8030d03 chore: update npins dependencies
Automated update of Nix dependencies via npins.

    Updated packages:
    +      "revision": "a1ef738813b15cf8ec759bdff5761b027e3e1d23",
+      "hash": "sha256-Efs3VUPelRduf3PpfPP2ovEB4CXT7vHf8W+xc49RL/U="
+      "hash": "sha256-XH6awru9NnBc/m+2YhRNT8r1PAKEiPGF3gs//F3ods0="
2026-01-23 15:01:05 +00:00
mrtz e7ba9bf363 fix(gitea): Via proxy protocol 2026-01-22 17:36:52 +01:00
mrtz 3a188746de fix(gitea): Secure cookie 2026-01-22 17:32:46 +01:00
mrtz f315c5019b fix(gitea): Rootless-Rootless 2026-01-22 16:31:00 +01:00
mrtz 6213f4ce2e fix(gitea): Rootless 2026-01-22 16:28:01 +01:00
mrtz 6d61ba9243 chore(gitea): Bump 2026-01-22 16:23:26 +01:00
mrtz ead05c101d fix(gitea|hs): Cool git domain 2026-01-22 16:16:38 +01:00
mrtz 44a93f15a6 fix(hs): New LB for git 2026-01-22 16:15:51 +01:00
mrtz 97d21660b1 fix(gitea): Back to svc for now 2026-01-22 15:46:31 +01:00
mrtz 9ff1f8aafc fix(gitea): Nodeport 2026-01-22 15:41:49 +01:00
mrtz f9cf9ad9b1 fix(gitea): Don't overwrite http LB 2026-01-22 15:28:16 +01:00
mrtz 807d9bca35 fix(gitea): Enabled by default 2026-01-22 15:26:28 +01:00
mrtz bf15426393 fix(gitea): LB take two 2026-01-22 15:25:14 +01:00
mrtz 21c57dac36 fix(gitea): Add LB 2026-01-22 15:24:05 +01:00
mrtz 1fd177b73a fix(gitea): Type again 2026-01-22 15:01:45 +01:00
mrtz 9d5b144d2d fix(gitea): Set nodePort 2026-01-22 14:59:01 +01:00
mrtz 24dfb63714 fix(gitea): Bump nodeport 2026-01-22 14:52:47 +01:00
mrtz e467799bd6 fix(gitea): Add admin secret and nodeport 2026-01-22 14:50:07 +01:00
mrtz ad258bf3fe feat: Add Gitea 2026-01-22 12:31:52 +01:00
mrtz 0801c0c6c7 fix: Remove attic reference 2026-01-22 09:57:37 +01:00
mrtz 924c7c74a4 fix(rabbitmq): Bump memroy 2026-01-22 08:42:42 +01:00
mrtz 1b766341cb ci: atlantis 2026-01-21 12:53:15 +00:00
mrtz b8c199718a fix(forgejo): Increase caching and don't send confirmation emails 2026-01-21 13:48:38 +01:00
mrtz b77b968420 fix(forgejo): Add metrics 2026-01-21 13:39:03 +01:00
mrtz 449a0f0e60 ci: atlantis 2026-01-21 09:42:26 +00:00
mrtz b1584703d1 fix: Remove nexus helmfile 2026-01-21 09:37:24 +01:00
mrtz d3ecef770f fix: Remove unused values 2026-01-21 09:36:29 +01:00
mrtz f43588cb93 fix(cilium): Autosync of by default 2026-01-21 09:03:41 +01:00
mrtz be985a1ac4 Merge branch 'renovate/forgejo-16.x' into 'main'
Update forgejo Docker tag to v16.0.1

See merge request oceanbox/manifests!68
2026-01-20 19:09:10 +01:00
mrtz 6a3e3855df Merge branch 'renovate/argocd-apps-2.x' into 'main'
Update Helm release argocd-apps to v2.0.4

See merge request oceanbox/manifests!69
2026-01-20 19:08:50 +01:00
Renovate Bot da5a2ea142 Update Helm release argocd-apps to v2.0.4 2026-01-20 18:04:14 +00:00
Renovate Bot d3db1db7c5 Update forgejo Docker tag to v16.0.1 2026-01-20 18:04:09 +00:00
mrtz 411550cc23 devel: Remove vCluster
Now available on the `vcluster` branch
2026-01-20 18:53:17 +01:00
225 changed files with 2734 additions and 1374 deletions
+9 -6
View File
@@ -1,13 +1,16 @@
#!/usr/bin/env bash
# the shebang is ignored, but nice for editors
watch_file nix/sources.json
watch_file nix/checks.nix
watch_file npins/sources.json
# Load .env file if it exists
dotenv_if_exists
# Set npins dir
export NPINS_DIRECTORY="nix"
# Activate development shell
use nix
if type lorri &>/dev/null; then
echo "direnv: using lorri from PATH ($(type -p lorri))"
eval "$(lorri direnv)"
else
# fall back to using direnv's builtin nix support
# to prevent bootstrapping problems.
use nix
fi
-54
View File
@@ -1,54 +0,0 @@
# yaml-language-server: $schema=https://gitlab.com/gitlab-org/gitlab/-/raw/master/app/assets/javascripts/editor/schema/ci.json
default:
tags:
- nix
include:
- project: oceanbox/gitlab-ci
ref: v4.5
file: template/Base.gitlab-ci.yml
# stages:
# - release
# image:
# name: alpine/helm:latest
# entrypoint: ["/bin/bash", "-c"]
# release:
# stage: release
# rules:
# - if: "$CI_COMMIT_BRANCH =~ /^main/"
# when: always
# - when: never
# script:
# - |
# cd $CI_PROJECT_DIR
# for i in $(git show --pretty="" --name-only | grep '^charts/.*/Chart.yaml' | cut -d/ -f2); do
# pack=$(helm package ./charts/$i | sed 's/Success.*: \(.*\)/\1/')
# if [ ! -z $pack ]; then
# chart=$(basename $pack)
# curl --request POST \
# --user gitlab-ci-token:$CI_JOB_TOKEN \
# --form "chart=@${chart}" \
# "${CI_API_V4_URL}/projects/${CI_PROJECT_ID}/packages/helm/api/stable/charts"
# fi
# done
# rebuild:
# stage: release
# rules:
# - when: manual
# allow_failure: true
# script:
# - |
# cd $CI_PROJECT_DIR
# for i in $(find ./charts -maxdepth 2 -name Chart.yaml | cut -d/ -f3); do
# pack=$(helm package ./charts/$i | sed 's/Success.*: \(.*\)/\1/')
# if [ ! -z $pack ]; then
# chart=$(basename $pack)
# curl --request POST \
# --user gitlab-ci-token:$CI_JOB_TOKEN \
# --form "chart=@${chart}" \
# "${CI_API_V4_URL}/projects/${CI_PROJECT_ID}/packages/helm/api/stable/charts"
# fi
# done
+1 -1
View File
@@ -1,4 +1,4 @@
FROM ghcr.io/helmfile/helmfile:v1.1.9
FROM ghcr.io/helmfile/helmfile:v1.3.1
RUN mkdir -p /home/argocd/cmp-server/config/
COPY plugin.yaml /home/argocd/cmp-server/config/
+1 -1
View File
@@ -1,6 +1,6 @@
#!/bin/sh
img=registry.gitlab.com/oceanbox/manifests/helmfile-cmp
img=git.oceanbox.io/platform/manifests/helmfile-cmp
tag=${1:-latest}
docker build -t "${img}":"${tag}" .
+3
View File
@@ -0,0 +1,3 @@
FROM busybox
COPY keycloak-themes/oceanbox /theme
@@ -0,0 +1,109 @@
/* Oceanbox Keycloak Login Theme
*
* Branding aligned with oceanbox.io:
* Primary teal: #0bb4aa
* Dark teal: #37746F
* Deep blue: #031275
* Background: #f9fafd
* Text: #101010
*/
:root {
--pf-v5-global--primary-color--100: #0bb4aa;
--pf-v5-global--primary-color--200: #099e95;
--pf-v5-global--link--Color: #0bb4aa;
--pf-v5-global--link--Color--hover: #031275;
}
.login-pf body {
background: #f9fafd url("../img/oceanbox-bg.png") no-repeat center bottom fixed;
background-size: cover;
height: 100%;
}
/* Login container layout */
.pf-v5-c-login__container {
grid-template-columns: 34rem;
grid-template-areas: "header"
"main";
}
/* Logo */
div.kc-logo-text {
background-image: url('../img/oceanbox-logo-text.png');
height: 80px;
width: 360px;
background-repeat: no-repeat;
background-size: contain;
background-position: center;
margin: 0 auto;
}
div.kc-logo-text span {
display: none;
}
/* Header */
#kc-header-wrapper {
font-size: 29px;
text-transform: uppercase;
letter-spacing: 3px;
line-height: 1.2em;
white-space: normal;
color: #37746F !important;
text-align: center;
}
/* Login card */
.pf-v5-c-login__main {
border-radius: 8px;
box-shadow: 0 4px 24px rgba(0, 0, 0, 0.08);
}
/* Primary button */
.pf-v5-c-button.pf-m-primary {
--pf-v5-c-button--m-primary--BackgroundColor: #0bb4aa;
--pf-v5-c-button--m-primary--hover--BackgroundColor: #099e95;
--pf-v5-c-button--m-primary--active--BackgroundColor: #37746F;
--pf-v5-c-button--m-primary--focus--BackgroundColor: #099e95;
border-radius: 4px;
}
/* Links */
.pf-v5-c-button.pf-m-link {
--pf-v5-c-button--m-link--Color: #0bb4aa;
--pf-v5-c-button--m-link--hover--Color: #031275;
}
a {
color: #0bb4aa;
}
a:hover {
color: #031275;
}
/* Form inputs */
.pf-v5-c-form-control > input,
.pf-v5-c-form-control > textarea {
border-radius: 4px;
}
#kc-recovery-codes-list {
columns: 2;
}
#certificate_subjectDN {
overflow-wrap: break-word;
}
hr {
margin-top: var(--pf-v5-global--spacer--sm);
margin-bottom: var(--pf-v5-global--spacer--md);
}
@media (min-width: 768px) {
div.pf-v5-c-login__main-header {
grid-template-columns: 70% 30%;
}
}
Binary file not shown.

After

Width:  |  Height:  |  Size: 2.4 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 57 KiB

@@ -0,0 +1,5 @@
parent=keycloak.v2
import=common/keycloak
stylesCommon=vendor/patternfly-v5/patternfly.min.css vendor/patternfly-v5/patternfly-addons.css
styles=css/styles.css css/oceanbox.css
+2 -2
View File
@@ -4,10 +4,10 @@ description: Atlantis map and simulation service
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
version: v1.35.2
version: v1.46.5
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application.
appVersion: v1.35.2
appVersion: v1.46.5
dependencies:
- name: diagrid-dashboard
version: "0.1.0"
+2 -3
View File
@@ -3,8 +3,8 @@
# Declare variables to be passed into your templates.
replicaCount: 1
image:
repository: registry.gitlab.com/oceanbox/poseidon/atlantis
tag: v1.35.2
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
tag: v1.46.5
pullPolicy: IfNotPresent
init:
enabled: false
@@ -116,6 +116,5 @@ serviceMonitor:
nodeSelector: {}
tolerations: []
affinity: {}
diagrid-dashboard:
enabled: false
+2 -2
View File
@@ -13,9 +13,9 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: v1.35.2
version: v1.46.5
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "v1.35.2"
appVersion: "v1.46.5"
+2 -2
View File
@@ -6,11 +6,11 @@
replicaCount: 1
# This sets the container image more information can be found here: https://kubernetes.io/docs/concepts/containers/images/
image:
repository: registry.gitlab.com/oceanbox/poseidon/codex
repository: git.oceanbox.io/oceanbox/poseidon/codex
# This sets the pull policy for images.
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
tag: v1.35.2
tag: v1.46.5
# This is for the secrets for pulling an image from a private repository more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
imagePullSecrets:
- name: gitlab-pull-secret
@@ -8,6 +8,7 @@ data:
kind: Component
metadata:
name: statestore
namespace: {{ .Values.statestore.namespace | default "default" }}
scopes:
- {{ .Values.statestore.scope }}
spec:
@@ -17,10 +18,10 @@ data:
- name: redisUsername
value: default
- name: redisPassword
value: secret
value: {{ .Values.statestore.password | default "secret" }}
- name: actorStateStore
value: "true"
- name: redisDB
value: "1"
value: "{{ .Values.statestore.redisDB | default "0" }}"
type: state.redis
version: v1
+3
View File
@@ -5,6 +5,9 @@
statestore:
scope: my-scope
redis: my-redis
namespace: default
password: secret
redisDB: "0"
# This will set the replicaset count more information can be found here: https://kubernetes.io/docs/concepts/workloads/controllers/replicaset/
replicaCount: 1
+26
View File
@@ -0,0 +1,26 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
base/
prod/
staging/
review/
+18
View File
@@ -0,0 +1,18 @@
apiVersion: v2
name: docs
description: Oceanbox Documentation
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
version: v0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application.
appVersion: v0.1.0
+22
View File
@@ -0,0 +1,22 @@
1. Get the application URL by running these commands:
{{- if .Values.ingress.enabled }}
{{- range $host := .Values.ingress.hosts }}
{{- range .paths }}
http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }}
{{- end }}
{{- end }}
{{- else if contains "NodePort" .Values.service.type }}
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "docs.fullname" . }})
export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}")
echo http://$NODE_IP:$NODE_PORT
{{- else if contains "LoadBalancer" .Values.service.type }}
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "docs.fullname" . }}'
export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "docs.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}")
echo http://$SERVICE_IP:{{ .Values.service.port }}
{{- else if contains "ClusterIP" .Values.service.type }}
export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "docs.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}")
export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}")
echo "Visit http://127.0.0.1:8080 to use your application"
kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT
{{- end }}
+63
View File
@@ -0,0 +1,63 @@
{{/* vim: set filetype=mustache: */}}
{{/*
Expand the name of the chart.
*/}}
{{- define "docs.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "docs.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- $name := default .Chart.Name .Values.nameOverride }}
{{- if contains $name .Release.Name }}
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{- end }}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "docs.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Common labels
*/}}
{{- define "docs.labels" -}}
helm.sh/chart: {{ include "docs.chart" . }}
{{ include "docs.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/*
Selector labels
*/}}
{{- define "docs.selectorLabels" -}}
app.kubernetes.io/name: {{ include "docs.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}
{{/*
Create the name of the service account to use
*/}}
{{- define "docs.serviceAccountName" -}}
{{- if .Values.serviceAccount.create -}}
{{ default (include "docs.fullname" .) .Values.serviceAccount.name }}
{{- else -}}
{{ default "default" .Values.serviceAccount.name }}
{{- end -}}
{{- end -}}
+24
View File
@@ -0,0 +1,24 @@
{{- if .Values.cluster.enabled -}}
apiVersion: postgresql.cnpg.io/v1
kind: Cluster
metadata:
name: {{ include "docs.fullname" . }}
annotations:
linkerd.io/inject: disabled
labels:
{{- include "docs.labels" . | nindent 4 }}
spec:
instances: {{ .Values.cluster.instances | default "2" }}
# Example of rolling update strategy:
# - unsupervised: automated update of the primary once all
# replicas have been upgraded (default)
# - supervised: requires manual supervision to perform
# the switchover of the primary
primaryUpdateStrategy: unsupervised
backup:
retentionPolicy: {{ .Values.cluster.backupRetention | default "60d" }}
storage:
size: {{ .Values.cluster.size | default "5Gi" }}
{{- end }}
+84
View File
@@ -0,0 +1,84 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "docs.fullname" . }}
labels:
{{- include "docs.labels" . | nindent 4 }}
spec:
{{- if not .Values.autoscaling.enabled }}
replicas: {{ .Values.replicaCount }}
{{- end }}
selector:
matchLabels:
{{- include "docs.selectorLabels" . | nindent 6 }}
template:
metadata:
{{- with .Values.podAnnotations }}
annotations:
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "docs.selectorLabels" . | nindent 8 }}
spec:
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
serviceAccountName: {{ include "docs.serviceAccountName" . }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
containers:
- name: {{ .Chart.Name }}
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- name: http
containerPort: {{ .Values.service.port }}
protocol: TCP
env:
- name: LOG_LEVEL
value: "3"
livenessProbe:
httpGet:
path: /healthz
port: http
readinessProbe:
httpGet:
path: /healthz
port: http
resources:
{{- toYaml .Values.resources | nindent 12 }}
volumeMounts:
- name: data
mountPath: /data
{{- if .Values.init.enabled }}
initContainers:
- name: init
image: {{ .Values.init.image }}
command: {{- toYaml .Values.init.command | nindent 10 }}
volumeMounts:
- name: data
mountPath: /data
{{- end }}
volumes:
- name: data
{{- if .Values.persistence.enabled }}
persistentVolumeClaim:
claimName: {{ .Values.persistence.existingClaim | default (include "docs.fullname" .) }}
{{- else }}
emptyDir: {}
{{- end }}
{{- with .Values.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.tolerations }}
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}
+28
View File
@@ -0,0 +1,28 @@
{{- if .Values.autoscaling.enabled }}
apiVersion: autoscaling/v2beta1
kind: HorizontalPodAutoscaler
metadata:
name: {{ include "docs.fullname" . }}
labels:
{{- include "docs.labels" . | nindent 4 }}
spec:
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: {{ include "docs.fullname" . }}
minReplicas: {{ .Values.autoscaling.minReplicas }}
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
metrics:
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
- type: Resource
resource:
name: cpu
targetAverageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
{{- end }}
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
- type: Resource
resource:
name: memory
targetAverageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
{{- end }}
{{- end }}
+61
View File
@@ -0,0 +1,61 @@
{{- if .Values.ingress.enabled -}}
{{- $fullName := include "docs.fullname" . -}}
{{- $svcPort := .Values.service.port -}}
{{- if and .Values.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }}
{{- if not (hasKey .Values.ingress.annotations "kubernetes.io/ingress.class") }}
{{- $_ := set .Values.ingress.annotations "kubernetes.io/ingress.class" .Values.ingress.className}}
{{- end }}
{{- end }}
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.GitVersion -}}
apiVersion: networking.k8s.io/v1
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}}
apiVersion: networking.k8s.io/v1beta1
{{- else -}}
apiVersion: extensions/v1beta1
{{- end }}
kind: Ingress
metadata:
name: {{ $fullName }}
labels:
{{- include "docs.labels" . | nindent 4 }}
{{- with .Values.ingress.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
{{- if and .Values.ingress.className (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion) }}
ingressClassName: {{ .Values.ingress.className }}
{{- end }}
{{- if .Values.ingress.tls }}
tls:
{{- range .Values.ingress.tls }}
- hosts:
{{- range .hosts }}
- {{ . | quote }}
{{- end }}
secretName: {{ .secretName }}
{{- end }}
{{- end }}
rules:
{{- range .Values.ingress.hosts }}
- host: {{ .host | quote }}
http:
paths:
{{- range .paths }}
- path: {{ .path }}
{{- if and .pathType (semverCompare ">=1.18-0" $.Capabilities.KubeVersion.GitVersion) }}
pathType: {{ .pathType }}
{{- end }}
backend:
{{- if semverCompare ">=1.19-0" $.Capabilities.KubeVersion.GitVersion }}
service:
name: {{ $fullName }}
port:
number: {{ $svcPort }}
{{- else }}
serviceName: {{ $fullName }}
servicePort: {{ $svcPort }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
+25
View File
@@ -0,0 +1,25 @@
{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) }}
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: {{ template "docs.fullname" . }}
{{- with .Values.persistence.annotations }}
annotations:
{{ toYaml . | indent 4 }}
{{- end }}
labels:
{{ include "docs.labels" . | indent 4 }}
spec:
accessModes:
- {{ .Values.persistence.accessMode | quote }}
resources:
requests:
storage: {{ .Values.persistence.size | quote }}
{{- if .Values.persistence.storageClass }}
{{- if (eq "-" .Values.persistence.storageClass) }}
storageClassName: ""
{{- else }}
storageClassName: "{{ .Values.persistence.storageClass }}"
{{- end }}
{{- end }}
{{- end }}
+15
View File
@@ -0,0 +1,15 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "docs.fullname" . }}
labels:
{{- include "docs.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
- port: {{ .Values.service.port }}
targetPort: http
protocol: TCP
name: http
selector:
{{- include "docs.selectorLabels" . | nindent 4 }}
+12
View File
@@ -0,0 +1,12 @@
{{- if .Values.serviceAccount.create -}}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "docs.serviceAccountName" . }}
labels:
{{- include "docs.labels" . | nindent 4 }}
{{- with .Values.serviceAccount.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
+82
View File
@@ -0,0 +1,82 @@
# Default values for docs.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
replicaCount: 1
image:
repository: git.oceanbox.io/oceanbox/documentation/docs
tag: v0.1.0
pullPolicy: IfNotPresent
init:
enabled: false
image: ubuntu:rolling
command: ["/bin/sh", "-c", "true"]
env:
- name: LOG_LEVEL
value: "2"
- name: APP_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: APP_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
# imagePullSecrets:
# - name: gitea-pull-secret
nameOverride: ""
fullnameOverride: ""
serviceAccount:
create: true
# Annotations to add to the service account
annotations: {}
# The name of the service account to use.
# If not set and create is true, a name is generated using the fullname template
name: ""
podAnnotations: {}
podSecurityContext:
fsGroup: 2000
securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: false
runAsNonRoot: false
runAsUser: 0
service:
type: ClusterIP
port: 8080
ingress:
enabled: true
className: nginx
persistence:
enabled: false
size: 1G
storageClass: ""
accessMode: ReadWriteOnce
cluster:
enabled: false
instances: 2
backupEnabled: true
backupRetention: 60d
size: 5Gi
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi
autoscaling:
enabled: false
minReplicas: 1
maxReplicas: 100
targetCPUUtilizationPercentage: 80
# targetMemoryUtilizationPercentage: 80
nodeSelector: {}
tolerations: []
affinity: {}
+1 -1
View File
@@ -3,7 +3,7 @@
# Declare variables to be passed into your templates.
replicaCount: 1
image:
repository: registry.gitlab.com/oceanbox/makai
repository: git.oceanbox.io/oceanbox/makai/makai
tag: v0.1.0
pullPolicy: IfNotPresent
init:
+7 -2
View File
@@ -4,7 +4,12 @@ description: A Helm chart for Kubernetes
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
version: v1.6.7
version: v1.6.13
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application.
appVersion: v1.6.7
appVersion: v1.6.13
dependencies:
- name: diagrid-dashboard
version: "0.1.0"
repository: "file://../diagrid-dashboard"
condition: diagrid-dashboard.enabled
+5 -2
View File
@@ -3,8 +3,8 @@
# Declare variables to be passed into your templates.
replicaCount: 1
image:
repository: registry.gitlab.com/oceanbox/plume
tag: v1.6.7
repository: git.oceanbox.io/oceanbox/plume/plume
tag: v1.6.13
pullPolicy: IfNotPresent
init:
enabled: false
@@ -90,3 +90,6 @@ serviceMonitor:
nodeSelector: {}
tolerations: []
affinity: {}
diagrid-dashboard:
enabled: false
+2 -2
View File
@@ -4,10 +4,10 @@ description: A Helm chart for Kubernetes
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
version: v1.35.2
version: v1.46.5
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application.
appVersion: v1.35.2
appVersion: v1.46.5
dependencies:
- name: diagrid-dashboard
version: "0.1.0"
+2 -3
View File
@@ -4,8 +4,8 @@
replicaCount: 1
image:
repository: registry.gitlab.com/oceanbox/poseidon/sorcerer
tag: v1.35.2
repository: git.oceanbox.io/oceanbox/poseidon/sorcerer
tag: v1.46.5
pullPolicy: IfNotPresent
init:
enabled: false
@@ -108,7 +108,6 @@ serviceMonitor:
nodeSelector: {}
tolerations: []
affinity: {}
diagrid-dashboard:
enabled: false
statestore:
+7
View File
@@ -20,4 +20,11 @@ environments:
- ../values/*/env.yaml.gotmpl
- ../values/*/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
missingFileHandler: Info
beta:
values:
- ../values/env.yaml
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
- ../values/*/env.yaml.gotmpl
- ../values/*/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
missingFileHandler: Info
+4 -5
View File
@@ -15,7 +15,7 @@ releases:
- name: argocd
namespace: argocd
chart: argo/argo-cd
version: 7.9.1
version: 9.4.10
condition: argo.enabled
values:
- ../values/argo/values/argocd.yaml.gotmpl
@@ -27,7 +27,7 @@ releases:
- name: argocd-apps
namespace: argocd
chart: argo/argocd-apps
version: 2.0.3
version: 2.0.4
condition: argo.apps.enabled
values:
- ../values/argo/values/apps.yaml.gotmpl
@@ -35,7 +35,7 @@ releases:
- name: argo-rollouts
namespace: argocd
chart: argo/argo-rollouts
version: 2.40.5
version: 2.40.6
condition: argo.rollouts.enabled
values:
- ../values/argo/values/rollouts.yaml.gotmpl
@@ -43,7 +43,7 @@ releases:
- name: argo-workflows
namespace: argocd
chart: argo/argo-workflows
version: 0.45.27
version: 0.47.5
condition: argo.workflows.enabled
missingFileHandler: Info
- name: manifests
@@ -66,4 +66,3 @@ releases:
- '{{`{{ .Environment.Name }}`}}'
- ../values/argo/manifests
- _argo
+1 -1
View File
@@ -13,7 +13,7 @@ releases:
- name: cert-manager
namespace: cert-manager
chart: cert-manager/cert-manager
version: v1.19.2
version: v1.19.4
condition: cert_manager.enabled
values:
- ../values/cert-manager/values/cert-manager.yaml.gotmpl
+4 -4
View File
@@ -3,7 +3,8 @@ bases:
repositories:
- name: cilium
url: 'https://helm.cilium.io'
oci: true
url: 'quay.io/cilium/charts'
commonLabels:
tier: system
@@ -15,11 +16,11 @@ releases:
- name: cilium
namespace: kube-system
chart: cilium/cilium
version: 1.16.2
version: {{ if eq (requiredEnv "ARGOCD_ENV_CLUSTER_NAME") "hel1" }}1.19.1{{ else if eq (requiredEnv "ARGOCD_ENV_CLUSTER_NAME") "ekman" }}1.19.1{{ else }}1.16.19{{ end }}
condition: cilium.enabled
values:
- ../values/cilium/values/cilium.yaml.gotmpl
- ../values/cilium/values/cilium-{{ .Environment.Name }}.yaml.gotmpl
- ../values/cilium/values/cilium-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
missingFileHandler: Info
- name: manifests
namespace: cilium
@@ -55,4 +56,3 @@ releases:
- '{{`{{ .Environment.Name }}`}}'
- ../values/cilium/cilium-manifests
- manifests
+38
View File
@@ -0,0 +1,38 @@
bases:
- ../envs/environments.yaml.gotmpl
commonLabels:
tier: oceanbox
releases:
- name: docs
namespace: docs
chart: ../charts/docs
condition: docs.enabled
values:
- ../values/docs/values/values.yaml
- ../values/docs/values/values-{{ .Environment.Name }}.yaml
postRenderer: ../bin/kustomizer
postRendererArgs:
- ../values/docs/kustomize/{{ .Environment.Name }}
missingFileHandler: Info
- name: manifests
namespace: docs
chart: manifests
condition: docs.enabled
missingFileHandler: Info
values:
- ../values/env.yaml
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
- ../values/docs/env.yaml.gotmpl
- ../values/docs/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
hooks:
- events: [ prepare, cleanup ]
showlogs: true
command: ../bin/helmify
args:
- '{{`{{ if eq .Event.Name "prepare" }}build{{ else }}clean{{ end }}`}}'
- '{{`{{ .Release.Chart }}`}}'
- '{{`{{ .Environment.Name }}`}}'
- ../values/docs/manifests
- manifests
+1 -1
View File
@@ -13,7 +13,7 @@ releases:
- name: dragonfly
namespace: dragonfly
chart: dragonfly/dragonfly-operator
version: v1.3.1
version: v1.4.0
condition: dragonfly.enabled
values:
- ../values/dragonfly/values/dragonfly.yaml.gotmpl
+43
View File
@@ -0,0 +1,43 @@
bases:
- ../envs/environments.yaml.gotmpl
#repositories:
#- name: drupal
# url: "https://drupalwxt.github.io/helm-drupal/index.yaml"
commonLabels:
tier: system
releases:
- name: drupal
namespace: drupal
#chart: drupal/drupal
#version: v1.3.0
condition: drupal.enabled
values:
- ../values/drupal/values/drupal.yaml.gotmpl
- ../values/drupal/values/drupal-{{ .Environment.Name }}.yaml.gotmpl
postRenderer: ../bin/kustomizer
postRendererArgs:
- ../values/drupal/kustomize/{{ .Environment.Name }}
missingFileHandler: Info
- name: manifests
namespace: drupal
chart: manifests
condition: drupal.enabled
missingFileHandler: Info
values:
- ../values/env.yaml
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
- ../values/drupal/env.yaml.gotmpl
- ../values/drupal/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
hooks:
- events: [ prepare, cleanup ]
showlogs: true
command: ../bin/helmify
args:
- '{{`{{ if eq .Event.Name "prepare" }}build{{ else }}clean{{ end }}`}}'
- '{{`{{ .Release.Chart }}`}}'
- '{{`{{ .Environment.Name }}`}}'
- ../values/drupal/manifests
- manifests
+1 -1
View File
@@ -12,7 +12,7 @@ releases:
- name: gatus
namespace: uptime
chart: gatus/gatus
version: 1.4.4
version: 1.5.0
condition: gatus.enabled
values:
- ../values/gatus/values/values.yaml
@@ -2,35 +2,36 @@ bases:
- ../envs/environments.yaml.gotmpl
repositories:
- name: stevehipwell
url: 'https://stevehipwell.github.io/helm-charts/'
- name: gitea
oci: true
url: docker.gitea.com/charts
commonLabels:
tier: system
releases:
- name: nexus3
namespace: nexus
chart: stevehipwell/nexus3
version: 5.9.0
condition: nexus.enabled
- name: gitea
namespace: gitea
chart: gitea/gitea
version: 12.5.0
condition: gitea.enabled
values:
- ../values/nexus/values/nexus.yaml.gotmpl
- ../values/nexus/values/nexus-{{ .Environment.Name }}.yaml.gotmpl
- ../values/gitea/values/values.yaml
- ../values/gitea/values/values-{{ .Environment.Name }}.yaml
postRenderer: ../bin/kustomizer
postRendererArgs:
- ../values/nexus/kustomize/{{ .Environment.Name }}
- ../values/gitea/kustomize/{{ .Environment.Name }}
missingFileHandler: Info
- name: manifests
namespace: nexus
namespace: gitea
chart: manifests
condition: nexus.enabled
condition: gitea.enabled
missingFileHandler: Info
values:
- ../values/env.yaml
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
- ../values/nexus/env.yaml.gotmpl
- ../values/nexus/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
- ../values/gitea/env.yaml.gotmpl
- ../values/gitea/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
hooks:
- events: [ prepare, cleanup ]
showlogs: true
@@ -39,5 +40,5 @@ releases:
- '{{`{{ if eq .Event.Name "prepare" }}build{{ else }}clean{{ end }}`}}'
- '{{`{{ .Release.Chart }}`}}'
- '{{`{{ .Environment.Name }}`}}'
- ../values/nexus/manifests
- ../values/gitea/manifests
- manifests
+1 -1
View File
@@ -12,7 +12,7 @@ releases:
- name: ingress-nginx
namespace: ingress-nginx
chart: ingress-nginx/ingress-nginx
version: 4.14.1
version: 4.14.3
condition: nginx.enabled
values:
- ../values/ingress-nginx/values/ingress-nginx.yaml.gotmpl
+41
View File
@@ -0,0 +1,41 @@
bases:
- ../envs/environments.yaml.gotmpl
repositories:
- name: jobset
oci: true
url: registry.k8s.io/jobset/charts
releases:
- name: jobset
namespace: jobset-system
chart: jobset/jobset
version: 0.11.1
condition: jobset.enabled
values:
- ../values/jobset/values/jobset.yaml.gotmpl
- ../values/jobset/values/jobset-{{ .Environment.Name }}.yaml.gotmpl
postRenderer: ../bin/kustomizer
postRendererArgs:
- ../values/jobset/kustomize/{{ .Environment.Name }}
missingFileHandler: Info
- name: manifests
namespace: jobset-system
chart: manifests
condition: jobset.enabled
missingFileHandler: Info
values:
- ../values/env.yaml
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
- ../values/jobset/env.yaml.gotmpl
- ../values/jobset/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
hooks:
- events: [ prepare, cleanup ]
showlogs: true
command: ../bin/helmify
args:
- '{{`{{ if eq .Event.Name "prepare" }}build{{ else }}clean{{ end }}`}}'
- '{{`{{ .Release.Chart }}`}}'
- '{{`{{ .Environment.Name }}`}}'
- ../values/jobset/manifests
- manifests
+1 -1
View File
@@ -12,7 +12,7 @@ releases:
- name: {{ .Environment.Name }}-keycloak
namespace: keycloak
chart: bitnami/keycloak
version: 24.0.2
version: 25.2.0
condition: keycloak.enabled
values:
- ../values/keycloak/values/values.yaml
+1 -1
View File
@@ -8,7 +8,7 @@ releases:
- name: kueue
namespace: kueue-system
chart: oci://registry.k8s.io/kueue/charts/kueue
version: 0.15.0
version: 0.16.2
condition: kueue.enabled
values:
- ../values/kueue/values/values.yaml
+1 -1
View File
@@ -15,7 +15,7 @@ releases:
- name: kyverno
namespace: kyverno
chart: kyverno/kyverno
version: 3.6.1
version: 3.7.1
condition: kyverno.enabled
values:
- ../values/kyverno/values/kyverno.yaml.gotmpl
+1 -1
View File
@@ -12,7 +12,7 @@ releases:
- name: loki
namespace: loki
chart: loki/loki
version: 6.42.0
version: 6.53.0
condition: loki.enabled
values:
- ../values/loki/values/loki.yaml.gotmpl
+2 -2
View File
@@ -6,7 +6,7 @@ commonLabels:
releases:
- name: makai
namespace: {{ .Environment.Name }}-makai
namespace: makai
chart: ../charts/makai
condition: makai.enabled
values:
@@ -17,7 +17,7 @@ releases:
- ../values/makai/kustomize/{{ .Environment.Name }}
missingFileHandler: Info
- name: manifests
namespace: {{ .Environment.Name }}-makai
namespace: makai
chart: manifests
condition: makai.enabled
missingFileHandler: Info
+1 -1
View File
@@ -12,7 +12,7 @@ releases:
- name: mariadb-operator
namespace: mariadb-operator
chart: mariadb-operator/mariadb-operator
version: 25.10.3
version: 25.10.4
condition: mariadb_operator.enabled
values:
- ../values/mariadb-operator/values/mariadb-operator.yaml.gotmpl
+1 -1
View File
@@ -16,7 +16,7 @@ releases:
namespace: {{ .Environment.Name }}-openfga
{{- end }}
chart: openfga/openfga
version: 0.2.50
version: 0.2.56
condition: openfga.enabled
values:
- ../values/openfga/values/values.yaml
@@ -12,7 +12,7 @@ releases:
- name: opentelemetry-collector
namespace: otel
chart: open-telemetry/opentelemetry-collector
version: 0.142.1
version: 0.146.1
condition: otel.enabled
values:
- ../values/opentelemetry-collector/values/values.yaml
@@ -2,36 +2,35 @@ bases:
- ../envs/environments.yaml.gotmpl
repositories:
- name: forgejo
oci: true
url: code.forgejo.org/forgejo-helm
- name: postfix
url: https://bokysan.github.io/docker-postfix
commonLabels:
tier: system
releases:
- name: forgejo
namespace: forgejo
chart: forgejo/forgejo
version: 16.0.0
condition: forgejo.enabled
- name: postfix
namespace: postfix
chart: postfix/mail
version: 5.1.0
condition: postfix.enabled
values:
- ../values/forgejo/values/values.yaml
- ../values/forgejo/values/values-{{ .Environment.Name }}.yaml
- ../values/postfix/values/values.yaml
- ../values/postfix/values/values-{{ .Environment.Name }}.yaml
postRenderer: ../bin/kustomizer
postRendererArgs:
- ../values/forgejo/kustomize/{{ .Environment.Name }}
- ../values/postfix/kustomize/{{ .Environment.Name }}
missingFileHandler: Info
- name: manifests
namespace: forgejo
namespace: postfix
chart: manifests
condition: forgejo.enabled
condition: postfix.enabled
missingFileHandler: Info
values:
- ../values/env.yaml
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
- ../values/forgejo/env.yaml.gotmpl
- ../values/forgejo/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
- ../values/postfix/env.yaml.gotmpl
- ../values/postfix/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
hooks:
- events: [ prepare, cleanup ]
showlogs: true
@@ -40,5 +39,5 @@ releases:
- '{{`{{ if eq .Event.Name "prepare" }}build{{ else }}clean{{ end }}`}}'
- '{{`{{ .Release.Chart }}`}}'
- '{{`{{ .Environment.Name }}`}}'
- ../values/forgejo/manifests
- ../values/postfix/manifests
- manifests
+1 -1
View File
@@ -27,7 +27,7 @@ releases:
- name: plugin-barman-cloud
namespace: cnpg
chart: cloudnative-pg/plugin-barman-cloud
version: 0.3.1
version: 0.5.0
condition: postgres_operator.enabled
values:
- ../values/postgres-operator/values/plugin-barman-cloud.yaml.gotmpl
+1 -1
View File
@@ -15,7 +15,7 @@ releases:
- name: prometheus
namespace: prometheus
chart: prometheus/kube-prometheus-stack
version: 72.7.0
version: 82.10.3
condition: prometheus.enabled
values:
- ../values/prometheus/values/prometheus.yaml.gotmpl
+1 -1
View File
@@ -13,7 +13,7 @@ releases:
- name: slurm-operator
namespace: slinky
chart: slurm-operator/slurm-operator
version: 0.4.1
version: 1.0.2
condition: slurm_operator.enabled
values:
- ../values/slurm-operator/values/slurm-operator.yaml.gotmpl
+1 -1
View File
@@ -13,7 +13,7 @@ releases:
- name: slurm
namespace: slurm
chart: slurm/slurm
version: 0.4.1
version: 1.0.2
condition: slurm.enabled
values:
- ../values/slurm/values/slurm.yaml.gotmpl
+1 -1
View File
@@ -14,7 +14,7 @@ releases:
- name: umami
namespace: analytics
chart: umami/umami
version: 6.0.1
version: 7.7.3
condition: umami.enabled
values:
- ../values/umami/values/values.yaml
+1 -1
View File
@@ -15,7 +15,7 @@ releases:
- name: velero
namespace: velero
chart: velero/velero
version: 11.3.2
version: 12.0.0
condition: velero.enabled
values:
- ../values/velero/values/velero.yaml.gotmpl
+19
View File
@@ -0,0 +1,19 @@
{
buildGoModule,
fetchFromGitHub,
}:
buildGoModule rec {
pname = "kueuectl";
version = "0.16.3";
src = fetchFromGitHub {
owner = "kubernetes-sigs";
repo = "kueue";
rev = "v${version}";
hash = "sha256-JbU+ZoQ+YriaiIbbVCe45OTYycxYRanLhmQAdpE+xQ4=";
};
vendorHash = null;
subPackages = [ "cmd/kueuectl" ];
}
-24
View File
@@ -1,24 +0,0 @@
{
"pins": {
"git-hooks": {
"type": "Git",
"repository": {
"type": "GitHub",
"owner": "cachix",
"repo": "git-hooks.nix"
},
"branch": "master",
"submodules": false,
"revision": "f0927703b7b1c8d97511c4116eb9b4ec6645a0fa",
"url": "https://github.com/cachix/git-hooks.nix/archive/f0927703b7b1c8d97511c4116eb9b4ec6645a0fa.tar.gz",
"hash": "sha256-6MkqajPICgugsuZ92OMoQcgSHnD6sJHwk8AxvMcIgTE="
},
"nixpkgs": {
"type": "Channel",
"name": "nixpkgs-unstable",
"url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.05pre927565.13868c071cc7/nixexprs.tar.xz",
"hash": "sha256-wufp5c0nWh/87f9eK7xy1eZXms5zd4yl6S4SR+LfA08="
}
},
"version": 7
}
+71
View File
@@ -0,0 +1,71 @@
{
sources ? import ../npins,
pkgs ? import sources.nixpkgs { },
treefmt ? import sources.treefmt-nix,
}:
let
globalExcludes = [
"npins/default.nix"
"attic"
"vcluster"
".*vendor"
".*chart/.*"
".*schema.json"
];
in
treefmt.evalModule pkgs {
projectRootFile = ".git/config";
settings = {
excludes = globalExcludes;
};
programs = {
# --- Nix formatting ---
nixfmt = {
enable = true;
package = pkgs.nixfmt-rfc-style;
};
statix.enable = true;
deadnix.enable = true;
# --- Shell ---
shellcheck = {
enable = true;
excludes = [
"vcluster/"
"attic/"
];
};
shfmt.enable = true;
# --- YAML ---
yamllint = {
enable = true;
excludes = [
"attic/"
"charts/templates/"
"charts/"
"values/"
"vcluster/"
];
settings = {
extends = "default";
rules = {
document-start = "disable";
line-length = {
max = 300;
};
};
};
};
# --- JSON ---
jsonfmt.enable = true;
# Optional: keep JSON sorted
# prettier.enable = true;
};
}
View File
+24
View File
@@ -0,0 +1,24 @@
{
"pins": {
"nixpkgs": {
"type": "Channel",
"name": "nixpkgs-unstable",
"url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.05pre961788.75690239f08f/nixexprs.tar.xz",
"hash": "sha256-p0h/nSeqzIkbn/2uFC4keoIPwmqXGHsX0gkCXM7km00="
},
"treefmt-nix": {
"type": "Git",
"repository": {
"type": "GitHub",
"owner": "numtide",
"repo": "treefmt-nix"
},
"branch": "main",
"submodules": false,
"revision": "71b125cd05fbfd78cab3e070b73544abe24c5016",
"url": "https://github.com/numtide/treefmt-nix/archive/71b125cd05fbfd78cab3e070b73544abe24c5016.tar.gz",
"hash": "sha256-6E/yhXP7Oy/NbXtf1ktzmU8SdVqJQ09HC/48ebEGBpk="
}
},
"version": 7
}
-1
View File
@@ -6,7 +6,6 @@
"dependencyDashboard": true,
"semanticCommits": "disabled",
"ignorePaths": [
"**/attic/**",
"**/bootstrap/**"
],
"helmfile": {
+33 -42
View File
@@ -1,57 +1,51 @@
let
sources = import ./nix;
sources = import ./npins;
system = builtins.currentSystem;
pkgs = import sources.nixpkgs {
inherit system;
config = { };
overlays = [ ];
};
checks = import ./nix/checks.nix;
treefmt = import ./nix/treefmt.nix { };
kueuectl = pkgs.callPackage ./nix/kueuectl.nix { };
in
pkgs.mkShellNoCC {
name = "clstr";
packages = [
# dev tools
pkgs.just
pkgs.npins
treefmt.config.build.wrapper
packages =
with pkgs;
[
# dev tools
just
npins
# helm
pkgs.helmfile
pkgs.kubernetes-helm
# helm
helmfile
kubernetes-helm
# kubectl tools
pkgs.kubectl-cnpg
pkgs.kubectl-neat
pkgs.kubectl-graph
pkgs.kubectl-klock
pkgs.kubectl-rook-ceph
# kubectl tools
kubectl-cnpg
kubectl-neat
kubelogin
kubelogin-oidc
kubectl-rook-ceph
kubectl-graph
kubectl-klock
graphviz
# other tools activate when needed
# step-cli
# linkerd
# cmctl
# rclone
# velero
# renovate
# dapr
dapr-cli
]
++ checks.enabledPackages;
# other tools activate when needed
kueuectl
# pkgs.step-cli
# pkgs.linkerd
# pkgs.cmctl
# pkgs.rclone
# pkgs.velero
# pkgs.renovate
# pkgs.graphviz
# pkgs.hubble
pkgs.cilium-cli
pkgs.dapr-cli
];
# Environment variables
ARGOCD_ENV_CLUSTER_NAME = "hel1";
ARGOCD_ENV_CLUSTER_NAME = "ekman";
HELM_GIT_ACCESS_TOKEN = "glpat-xxx";
shellHook = builtins.concatStringsSep "\n" [
checks.shellHook
];
API_SERVER_IP = "localhost";
API_SERVER_PORT = "7445";
# Alternative shells
passthru = pkgs.lib.mapAttrs (name: value: pkgs.mkShellNoCC (value // { inherit name; })) {
@@ -59,9 +53,6 @@ pkgs.mkShellNoCC {
packages = [
pkgs.npins
];
shellHook = ''
export NPINS_DIRECTORY="nix"
'';
};
};
}
+1 -5
View File
@@ -24,11 +24,7 @@ argocd:
cpu: 250m
repoServers:
- name: "helmfile-cmp"
image: "registry.gitlab.com/oceanbox/manifests/helmfile-cmp:latest"
imagePullSecrets:
- gitlab-pull-secret
- name: "kustomize-helm-with-rewrite"
image: "registry.gitlab.com/oceanbox/manifests/kustomize-helm-with-rewrite:latest"
image: "git.oceanbox.io/platform/manifests/helmfile-cmp:latest"
imagePullSecrets:
- gitlab-pull-secret
additional_rbac_settings:
+15 -2
View File
@@ -88,11 +88,19 @@ spec:
server: https://kubernetes.default.svc
- namespace: uptime
server: https://kubernetes.default.svc
- namespace: forgejo
- namespace: gitea
server: https://kubernetes.default.svc
- namespace: postfix
server: https://kubernetes.default.svc
- namespace: jobset-system
server: https://kubernetes.default.svc
- namespace: dex
server: https://kubernetes.default.svc
sourceRepos:
- https://argoproj.github.io/argo-helm
- https://kubernetes-sigs.github.io/metrics-server/
- https://git.oceanbox.io/platform/manifests.git
- https://git.oceanbox.io/platform/manifests
- https://gitlab.com/oceanbox/manifests.git
- https://kubernetes.github.io/ingress-nginx
- https://cloudnative-pg.github.io/charts
@@ -120,13 +128,18 @@ spec:
- https://open-telemetry.github.io/opentelemetry-helm-charts
- https://ghcr.io/slinkyproject/charts/slurm-operator
- https://ghcr.io/slinkyproject/charts/slurm-operator-crds
- https://bokysan.github.io/docker-postfix/
- ghcr.io/slinkyproject/charts
- ghcr.io/slinkyproject/charts/slurm-operator
- ghcr.io/slinkyproject/charts/slurm-operator-crds
- ghcr.io/spegel-org/helm-charts
- quay.io/cilium/charts
- quay.io/jetstack/charts
- registry.k8s.io/jobset/charts/jobset
- ghcr.io/dragonflydb/dragonfly-operator/helm/dragonfly-operator
- code.forgejo.org/forgejo-helm
- docker.gitea.com
- https://operator.mariadb.com/mariadb-enterprise-operator
- https://operator.mariadb.com
- https://ot-container-kit.github.io/helm-charts
- https://twin.github.io/helm-charts
- https://charts.dexidp.io
+5 -25
View File
@@ -15,7 +15,7 @@ configs:
application.resourceTrackingMethod: annotation+label
application.instanceLabelKey: app.kubernetes.io/instance
create: true
# NOTE(kai): callback URL for dex
# NOTE: callback URL for dex
url: "https://argocd.{{ .Values.clusterConfig.domain }}"
resource.compareoptions: |
ignoreAggregatedRoles: true
@@ -81,6 +81,7 @@ configs:
p, role:org-admin, applications, *, */*, allow
p, role:org-admin, projects, *, *, allow
p, role:org-admin, logs, get, *, allow
p, role:org-admin, logs, get, */*, allow
p, role:org-admin, clusters, get, *, allow
p, role:org-admin, clusters, update, *, allow
p, role:org-admin, repositories, get, *, allow
@@ -167,7 +168,7 @@ repoServer:
extraContainers:
- command:
- /var/run/argocd/argocd-cmp-server
image: registry.gitlab.com/oceanbox/manifests/helmfile-cmp:latest
image: {{ .image }}
env:
- name: HELM_GIT_ACCESS_TOKEN
valueFrom:
@@ -176,25 +177,6 @@ repoServer:
name: oceanbox-gitops-repo
optional: false
imagePullPolicy: Always
name: helmfile-cmp
securityContext:
runAsNonRoot: true
runAsUser: 999
terminationMessagePath: /dev/termination-log
terminationMessagePolicy: File
volumeMounts:
- mountPath: /var/run/argocd
name: var-files
- mountPath: /home/argocd/cmp-server/plugins
name: plugins
- mountPath: /tmp
name: cmp-tmp
- mountPath: /helm-working-dir
name: helm-working-dir
- command:
- /var/run/argocd/argocd-cmp-server
image: {{ .image }}
imagePullPolicy: Always
name: {{ .name }}
securityContext:
runAsNonRoot: true
@@ -208,6 +190,8 @@ repoServer:
name: plugins
- mountPath: /tmp
name: cmp-tmp
- mountPath: /helm-working-dir
name: helm-working-dir
volumes:
- name: cmp-tmp
emptyDir: {}
@@ -283,10 +267,6 @@ applicationSet:
ingressClassName: nginx
annotations:
cert-manager.io/cluster-issuer: {{ .Values.clusterConfig.ingress_clusterissuer }}
# {{- with .Values.clusterConfig.ingress_whitelist}}
# NOTE(kai): include gitlab and github webhook ranges
# nginx.ingress.kubernetes.io/whitelist-source-range: {{ join "," . }},192.30.252.0/22,140.82.112.0/20,34.74.226.27/28,34.74.226.0/24
# {{- end }}
hostname: "argocd-applicationset.{{ .Values.clusterConfig.domain }}"
tls:
- secretName: argocd-applicationset-tls
-1
View File
@@ -1,3 +1,2 @@
atlantis:
enabled: true
+1 -2
View File
@@ -1,5 +1,4 @@
atlantis:
enabled: false
autosync: {{ if eq .Environment.Name "prod" }} false {{ else }} true {{ end }}
autosync: {{ if or (eq .Environment.Name "prod") (eq .Environment.Name "beta") }}false{{ else }}true{{ end }}
env: {{ .Environment.Name }}
@@ -0,0 +1,96 @@
{
"oidc": {
"issuer": "https://auth.oceanbox.io/realms/oceanbox",
"authorization_endpoint": "https://auth.oceanbox.io/realms/oceanbox/protocol/openid-connect/auth",
"token_endpoint": "https://auth.oceanbox.io/realms/oceanbox/protocol/openid-connect/token",
"jwks_uri": "https://auth.oceanbox.io/realms/oceanbox/protocol/openid-connect/certs",
"userinfo_endpoint": "https://auth.oceanbox.io/realms/oceanbox/protocol/openid-connect/userinfo",
"end_session_endpoint": "https://auth.oceanbox.io/realms/oceanbox/protocol/openid-connect/logout",
"device_authorization_endpoint": "https://auth.oceanbox.io/realms/oceanbox/protocol/openid-connect/auth/device",
"clientId": "atlantis",
"clientSecret": "",
"scopes": [
"openid",
"email",
"offline_access",
"profile"
],
"audiences": [
"atlantis",
"atlantis_dev",
"sorcerer",
"sorcerer_dev"
]
},
"sso": {
"cookieDomain": ".oceanbox.io",
"cookieName": ".obx.beta",
"ttl": 12.0,
"signedOutRedirectUri": "https://maps.beta.oceanbox.io",
"realm": "atlantis",
"environment": "prod",
"keyStore": {
"kind": "azure",
"uri": "https://atlantis.blob.core.windows.net",
"key": "dataprotection-keys"
},
"keyVault": {
"kind": "azure",
"uri": "https://atlantisvault.vault.azure.net",
"key": "dataencryption-keys"
}
},
"fga": {
"apiUrl": "http://prod-openfga.openfga.svc.cluster.local:8080",
"apiKey": "",
"storeId": "01JKTZXMP7ANN4GG2P5W8Y56M6",
"modelId": "01JKTZYMCZZBVSBG66W27XMW0A"
},
"sentryUrl": "https://b6e03cfc8e247297b89217b09341b4cb@o4509530141622272.ingest.de.sentry.io/4509530195492944",
"plainAuthUsers": [
{
"username": "admin",
"password": "en-to-tre-fire",
"groups": [ "/oceanbox" ],
"roles": [ "admin" ]
},
{
"username": "sorcerer",
"password": "fire tre to en",
"groups": [ "/oceanbox" ],
"roles": [ "admin" ]
},
{
"username": "archivist",
"password": "en-to-tre-fire",
"groups": [ "/oceanbox" ],
"roles": [ "admin" ]
}
],
"plume": "plume.data.oceanbox.io",
"redis": "beta-atlantis-redis:6379",
"objectStore": "https://atlantis.blob.core.windows.net",
"connString": "Username=postgres;Password=secret;Host=localhost;Port=5432;Database=app;Pooling=true;",
"sorcerer" : "https://sorcerer.beta.ekman.oceanbox.io",
"allowedOrigins": [
"https://maps.beta.oceanbox.io"
],
"appName": "atlantis",
"appEnv": "prod",
"appNamespace": "atlantis",
"appVersion": "2.95.1",
"otelCollector": "http://opentelemetry-collector.otel.svc:4317",
"pubsubName": "pubsub",
"pubsubTopic": "hipster-atlantis",
"slurm": {
"baseUrl": "https://slurmrestd.ekman.oceanbox.io/",
"slurmApi": "slurm/v0.0.42/",
"dbdApi": "slurmdbd/v0.0.42/",
"accessToken": ""
},
"amqp": {
"auth": "user:hunny-bunny",
"host": "10.255.241.201:30673"
},
"fenceRadius": 1250.0
}
@@ -0,0 +1,22 @@
apiVersion: dapr.io/v1alpha1
kind: Component
metadata:
name: slurm-events
spec:
type: bindings.rabbitmq
version: v1
metadata:
- name: host
secretKeyRef:
name: prod-atlantis-rabbitmq
key: connString
- name: queueName
value: beta-slurm-job-events
- name: durable
value: true
- name: contentType
value: "application/json"
- name: route
value: /events/slurm
scopes:
- beta-atlantis
@@ -0,0 +1,20 @@
apiVersion: dapr.io/v1alpha1
kind: Component
metadata:
name: configstore
spec:
type: configuration.redis
version: v1
metadata:
- name: redisHost
value: beta-atlantis-redis:6379
- name: redisUsername
value: default
- name: redisPassword
secretKeyRef:
name: beta-atlantis-redis
key: redis-password
- name: redisDB
value: "1"
scopes:
- beta-atlantis
@@ -0,0 +1 @@
OIDC_CLIENT_SECRET=KOJ6bDHzE5vdyfSrzgwLjtM5PzA809Zm
@@ -0,0 +1,10 @@
- op: add
path: /spec/template/spec/containers/0/envFrom/-
value:
secretRef:
name: azure-keyvault
- op: add
path: /spec/template/spec/containers/0/envFrom/-
value:
secretRef:
name: prod-atlantis-env
@@ -0,0 +1,22 @@
apiVersion: dapr.io/v1alpha1
kind: Component
metadata:
name: azure-keyvault
spec:
type: secretstores.azure.keyvault
version: v1
metadata:
- name: vaultName
value: atlantisvault
- name: azureTenantId
secretKeyRef:
name: azure-keyvault
key: AZURE_TENANT_ID
- name: azureClientId
secretKeyRef:
name: azure-keyvault
key: AZURE_CLIENT_ID
- name: azureClientSecret
secretKeyRef:
name: azure-keyvault
key: AZURE_CLIENT_SECRET
@@ -0,0 +1,24 @@
generatorOptions:
disableNameSuffixHash: true
configMapGenerator:
- name: beta-atlantis-appsettings
files:
- appsettings.json
patches:
- target:
group: apps
version: v1
kind: Deployment
path: deployment_patch.yaml
resources:
- ../base
- rbac.yaml
- tracing.yaml
- bindings.yaml
- pubsub.yaml
- statestore.yaml
- subscriptions.yaml
- configurations.yaml
- secretstore.yaml
- keyvault.yaml
@@ -0,0 +1,52 @@
apiVersion: dapr.io/v1alpha1
kind: Component
metadata:
name: pubsub
spec:
version: v1
type: pubsub.rabbitmq
metadata:
- name: hostname
value: prod-rabbitmq.rabbitmq
- name: username
value: user
- name: password
secretKeyRef:
name: prod-atlantis-rabbitmq
key: rabbitmq-password
- name: protocol
value: amqp
- name: durable
value: true
- name: deletedWhenUnused
value: false
- name: autoAck
value: false
- name: deliveryMode
value: 1
- name: requeueInFailure
value: false
- name: prefetchCount
value: 0
- name: reconnectWait
value: 0
- name: concurrencyMode
value: parallel
- name: publisherConfirm
value: false
- name: backOffPolicy
value: exponential
- name: backOffInitialInterval
value: 100
- name: backOffMaxRetries
value: 16
- name: enableDeadLetter # Optional enable dead Letter or not
value: true
- name: maxLen # Optional max message count in a queue
value: 3000
- name: maxLenBytes # Optional maximum length in bytes of a queue.
value: 10485760
- name: exchangeKind
value: fanout
- name: clientName
value: "{appID}"
+40
View File
@@ -0,0 +1,40 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: beta-atlantis
namespace: beta-atlantis
rules:
- apiGroups:
- ""
resourceNames:
- beta-atlantis-appsettings
resources:
- configmaps
verbs:
- get
- watch
- apiGroups:
- ""
resourceNames:
- azure-keyvault
- beta-atlantis-redis
- slurm-access-token
resources:
- secrets
verbs:
- get
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: beta-atlantis
namespace: beta-atlantis
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: beta-atlantis
subjects:
- kind: ServiceAccount
name: beta-atlantis
namespace: beta-atlantis
@@ -0,0 +1,10 @@
apiVersion: dapr.io/v1alpha1
kind: Component
metadata:
name: secretstore
spec:
type: secretstores.kubernetes
version: v1
metadata:
- name: defaultNamespace
value: beta-atlantis
@@ -0,0 +1,22 @@
apiVersion: dapr.io/v1alpha1
kind: Component
metadata:
name: statestore
spec:
type: state.redis
version: v1
metadata:
- name: redisHost
value: beta-atlantis-redis:6379
- name: redisUsername
value: default
- name: redisPassword
secretKeyRef:
name: beta-atlantis-redis
key: redis-password
- name: actorStateStore
value: "true"
- name: redisDB
value: "0"
scopes:
- beta-atlantis
@@ -0,0 +1,27 @@
apiVersion: dapr.io/v2alpha1
kind: Subscription
metadata:
name: hipster-events
spec:
topic: hipster
routes:
default: /events/hipster
pubsubname: pubsub
metadata:
queueType: quorum
scopes:
- beta-atlantis
---
apiVersion: dapr.io/v2alpha1
kind: Subscription
metadata:
name: inbox-events
spec:
topic: inbox
routes:
default: /events/inbox
pubsubname: pubsub
metadata:
queueType: quorum
scopes:
- beta-atlantis
@@ -0,0 +1,11 @@
apiVersion: dapr.io/v1alpha1
kind: Configuration
metadata:
name: tracing
spec:
tracing:
samplingRate: "1"
otel:
endpointAddress: "opentelemetry-collector.otel.svc.cluster.local:4317"
protocol: grpc
isSecure: false
@@ -73,7 +73,8 @@
"connString": "Username=postgres;Password=secret;Host=localhost;Port=5432;Database=app;Pooling=true;",
"sorcerer" : "https://sorcerer.data.oceanbox.io",
"allowedOrigins": [
"https://maps.oceanbox.io"
"https://maps.oceanbox.io",
"https://codex.adm.oceanbox.io"
],
"appName": "atlantis",
"appEnv": "prod",
@@ -26,7 +26,7 @@
"cookieDomain": ".oceanbox.io",
"cookieName": ".obx.staging",
"ttl": 12.0,
"signedOutRedirectUri": "https://atlantis.beta.oceanbox.io",
"signedOutRedirectUri": "https://maps.dev.oceanbox.io",
"realm": "atlantis",
"environment": "staging",
"keyStore": {
@@ -76,7 +76,8 @@
"https://atlantis.beta.oceanbox.io",
"https://atlantis.dev.oceanbox.io",
"https://atlantis.local.oceanbox.io:8080",
"https://maps.dev.oceanbox.io"
"https://maps.dev.oceanbox.io",
"https://codex.dev.oceanbox.io"
],
"appName": "atlantis",
"appEnv": "staging",
+15 -1
View File
@@ -27,16 +27,24 @@ spec:
value: {{ .Values.atlantis.env }}
- name: HELMFILE_FILE_PATH
value: atlantis.yaml.gotmpl
{{- if ne .Values.atlantis.env "beta" }}
- repoURL: https://charts.bitnami.com/bitnami
targetRevision: 20.1.7
chart: redis
helm:
valueFiles:
- $values/values/atlantis/values/redis-{{ .Values.atlantis.env }}.yaml
- repoURL: https://gitlab.com/oceanbox/manifests.git
{{- end }}
- repoURL: https://git.oceanbox.io/platform/manifests.git
targetRevision: main
ref: values
ignoreDifferences:
- kind: Secret
name: beta-atlantis-db-superuser
jqPathExpressions:
- '.data'
- '.metadata.labels'
- '.metadata.annotations'
- kind: Secret
name: azure-keyvault
jqPathExpressions:
@@ -67,6 +75,12 @@ spec:
- '.data'
- '.metadata.labels'
- '.metadata.annotations'
- kind: Secret
name: slurm-access-token
jqPathExpressions:
- '.data'
- '.metadata.labels'
- '.metadata.annotations'
syncPolicy:
syncOptions:
- CreateNamespace=true

Some files were not shown because too many files have changed in this diff Show More