feat: decommission legacy gluetun-proxy in favor of browser-vpn-proxy
Some checks failed
validate / lint (push) Failing after 0s

manifests/media/gluetun-proxy.yaml (the standalone Gluetun/OpenVPN
HTTP proxy, NodePort 30888) is now fully replaced by
manifests/multus/30-browser-vpn-proxy.yaml, live and validated
end-to-end (connectivity, DNS-through-proxy, PIA egress, fail-closed
kill switch). Removing the file from git - the live Deployment/Service
still need a separate kubectl delete, since media has prune: false.

Note gluetun.home.arpa (the dashy VPN-IP-banner hostname, and the
Certificate/IngressRoute in qbittorrent.yaml routing it to that pod's
ip-reporter sidecar) is unrelated and unaffected - it never pointed at
this standalone proxy.

Update the root README's VLAN 50 status table with browser-vpn-proxy
and this removal, including the exact commit to restore the old file
from if ever needed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Nik Afiq 2026-08-24 23:48:31 +09:00
parent 462a9d9c79
commit 6f6c3cf0eb
3 changed files with 9 additions and 106 deletions

View File

@ -253,6 +253,7 @@ piece's own README for exact commands and rollback:
| Multus, VLAN 50 NAD, canary | `manifests/multus/` (manual-sync Argo CD Application) | that directory's README | | Multus, VLAN 50 NAD, canary | `manifests/multus/` (manual-sync Argo CD Application) | that directory's README |
| qBittorrent VLAN 50 attachment | `manifests/media/qbittorrent.yaml` | no file-based copy kept — `git show 28d0628:manifests/media/qbittorrent.yaml \| kubectl apply -f -` restores the last pre-migration (Gluetun-based) version | | qBittorrent VLAN 50 attachment | `manifests/media/qbittorrent.yaml` | no file-based copy kept — `git show 28d0628:manifests/media/qbittorrent.yaml \| kubectl apply -f -` restores the last pre-migration (Gluetun-based) version |
| JDownloader VLAN 50 attachment | `manifests/media/jdownloader.yaml` | same approach — `git show 2f7ec5f:manifests/media/jdownloader.yaml \| kubectl apply -f -` | | JDownloader VLAN 50 attachment | `manifests/media/jdownloader.yaml` | same approach — `git show 2f7ec5f:manifests/media/jdownloader.yaml \| kubectl apply -f -` |
| browser-vpn-proxy (SOCKS5, no auth — see its own header for why) | `manifests/multus/30-browser-vpn-proxy.yaml` (manual-sync Argo CD Application) | that directory's README — replaces the standalone `manifests/media/gluetun-proxy.yaml` (removed 2026-08-24; `git show 462a9d9:manifests/media/gluetun-proxy.yaml \| kubectl apply -f -` restores it, NodePort `30888`, if ever needed) |
**Boot ordering** (minisforum): `pia-killswitch.service` seeds the closed **Boot ordering** (minisforum): `pia-killswitch.service` seeds the closed
routing/firewall state and is ordered `Before=` `wg-quick@pia-wg.service`; routing/firewall state and is ordered `Before=` `wg-quick@pia-wg.service`;
@ -291,11 +292,12 @@ collector for that host and adding a `PrometheusRule` — not done, flagged
here as the natural next step rather than guessed at. here as the natural next step rather than guessed at.
**Rollback (full)**: work through the table above bottom-to-top — restore **Rollback (full)**: work through the table above bottom-to-top — restore
qBittorrent/JDownloader from git history first (fastest to undo, keeps browser-vpn-proxy/qBittorrent/JDownloader from git history first (fastest
service running — see the table's Rollback column), then remove the to undo, keeps service running — see the table's Rollback column), then
Multus/NAD resources, then `ansible/roles/vlan50-parent`'s rollback, then remove the Multus/NAD resources, then `ansible/roles/vlan50-parent`'s
`ansible/roles/pia-gateway`'s rollback. None of these steps touch rollback, then `ansible/roles/pia-gateway`'s rollback. None of these
`pia-credentials`, PVCs, or the normal k3s/Argo CD control plane. steps touch `pia-credentials`, PVCs, or the normal k3s/Argo CD control
plane.
## Gotchas ## Gotchas

View File

@ -1,100 +0,0 @@
# Apply: kubectl apply -f manifests/network/gluetun-proxy.yaml
# Delete: kubectl delete -f manifests/network/gluetun-proxy.yaml
# Description: Standalone Gluetun HTTP proxy for browser traffic via PIA.
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: gluetun-proxy
namespace: downloads
spec:
replicas: 1
selector:
matchLabels:
app: gluetun-proxy
template:
metadata:
labels:
app: gluetun-proxy
spec:
containers:
- name: gluetun
image: qmcgaw/gluetun:v3.41
securityContext:
capabilities:
add:
- NET_ADMIN
env:
- name: VPN_SERVICE_PROVIDER
value: private internet access
- name: VPN_TYPE
value: openvpn
- name: SERVER_REGIONS
## AU Adelaide, AU Brisbane, AU Melbourne, AU Perth, AU Sydney, Albania, Algeria, Andorra, Argentina, Armenia, Australia Streaming Optimized, Austria, Bahamas, Bangladesh, Belgium, Bolivia, Bosnia and Herzegovina, Brazil, Bulgaria, CA Montreal, CA Ontario, CA Ontario Streaming Optimized, CA Toronto, CA Vancouver, Cambodia, Chile, China, Colombia, Costa Rica, Croatia, Cyprus, Czech Republic, DE Berlin, DE Frankfurt, DE Germany Streaming Optimized, DK Copenhagen, DK Streaming Optimized, ES Madrid, ES Valencia, Ecuador, Egypt, Estonia, FI Helsinki, FI Streaming Optimized, France, Georgia, Greece, Greenland, Guatemala, Hong Kong, Hungary, IT Milano, IT Streaming Optimized, Iceland, India, Indonesia, Ireland, Isle of Man, Israel, JP Streaming Optimized, JP Tokyo, Kazakhstan, Latvia, Liechtenstein, Lithuania, Luxembourg, Macao, Malaysia, Malta, Mexico, Moldova, Monaco, Mongolia, Montenegro, Morocco, NL Netherlands Streaming Optimized, Nepal, Netherlands, New Zealand, Nigeria, North Macedonia, Norway, Panama, Peru, Philippines, Poland, Portugal, Qatar, Romania, SE Stockholm, SE Streaming Optimized, Saudi Arabia, Serbia, Singapore, Slovakia, Slovenia, South Africa, South Korea, Sri Lanka, Switzerland, Taiwan, Turkey, UK London, UK Manchester, UK Southampton, UK Streaming Optimized, US Alabama, US Alaska, US Arkansas, US Atlanta, US Baltimore, US California, US Chicago, US Connecticut, US Denver, US East, US East Streaming Optimized, US Florida, US Honolulu, US Houston, US Idaho, US Indiana, US Iowa, US Kansas, US Kentucky, US Las Vegas, US Louisiana, US Maine, US Massachusetts, US Michigan, US Minnesota, US Mississippi, US Missouri, US Montana, US Nebraska, US New Hampshire, US New Mexico, US New York, US North Carolina, US North Dakota, US Ohio, US Oklahoma, US Oregon, US Pennsylvania, US Rhode Island, US Salt Lake City, US Seattle, US Silicon Valley, US South Carolina, US South Dakota, US Tennessee, US Texas, US Vermont, US Virginia, US Washington DC, US West, US West Streaming Optimized, US West Virginia, US Wilmington, US Wisconsin, US Wyoming, Ukraine, United Arab Emirates, Uruguay, Venezuela, Vietnam
value: JP Tokyo,Taiwan,Hong Kong
- name: OPENVPN_USER
valueFrom:
secretKeyRef:
name: pia-credentials
key: OPENVPN_USER
- name: OPENVPN_PASSWORD
valueFrom:
secretKeyRef:
name: pia-credentials
key: OPENVPN_PASSWORD
- name: HTTPPROXY
value: "on"
- name: HTTPPROXY_LISTENING_ADDRESS
value: ":8888"
- name: HTTPPROXY_LOG
value: "off"
- name: FIREWALL_OUTBOUND_SUBNETS
value: "10.42.0.0/16,10.43.0.0/16,10.10.40.0/24"
- name: BLOCK_IPV6
value: "on"
ports:
- containerPort: 8888
startupProbe:
exec:
command:
- /gluetun-entrypoint
- healthcheck
periodSeconds: 10
failureThreshold: 60
livenessProbe:
exec:
command:
- /gluetun-entrypoint
- healthcheck
periodSeconds: 30
failureThreshold: 3
readinessProbe:
exec:
command:
- /gluetun-entrypoint
- healthcheck
periodSeconds: 10
failureThreshold: 3
volumeMounts:
- name: tun
mountPath: /dev/net/tun
volumes:
- name: tun
hostPath:
path: /dev/net/tun
type: CharDevice
---
apiVersion: v1
kind: Service
metadata:
name: gluetun-proxy
namespace: downloads
spec:
selector:
app: gluetun-proxy
type: NodePort
ports:
- name: httpproxy
port: 8888
targetPort: 8888
nodePort: 30888

View File

@ -76,7 +76,8 @@
# does not) rather than assuming it does. # does not) rather than assuming it does.
# - Service is NodePort, not LoadBalancer/Ingress — reachable from the # - Service is NodePort, not LoadBalancer/Ingress — reachable from the
# LAN at <any node IP>:30889, never exposed publicly (no port-forward # LAN at <any node IP>:30889, never exposed publicly (no port-forward
# on Flint/the router for it, same as the existing gluetun-proxy). # on Flint/the router for it, same as the now-decommissioned
# gluetun-proxy was).
# #
# Browser configuration — this is the part that actually matters for # Browser configuration — this is the part that actually matters for
# "DNS must be resolved through the proxy": configuring a SOCKS5 proxy # "DNS must be resolved through the proxy": configuring a SOCKS5 proxy