Compare commits

..

2 Commits

Author SHA1 Message Date
bf91e72429 Revert "fix: remove Ingress and TLS configurations for Watch Party and Portfolio services"
Some checks failed
validate / lint (push) Failing after 8s
This reverts commit 3657519b17c16888fbde0946ba5c65c855330d2b.
2026-08-19 00:38:49 +09:00
e15911305f Revert "feat: move Gitea traffic from gitea.nik4nao.com to gitea.home.arpa"
This reverts commit fd13b8a. The registry-host migration broke image
pulls for home-services/portfolio (internal CA not trusted by
containerd) and has left them Degraded for 11 days; reverting back to
gitea.nik4nao.com pending a decision on how to proceed. Not pushed yet.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-19 00:22:27 +09:00
41 changed files with 154 additions and 81 deletions

View File

@ -29,7 +29,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/<area>
directory:

View File

@ -52,7 +52,7 @@ Public services under `nik4nao.com` use Let's Encrypt.
| `https://auth.nik4nao.com` | Authentik public | Let's Encrypt |
| `https://traefik.home.arpa` | Traefik dashboard | Internal CA |
| `https://grafana.nik4nao.com` | Grafana | Let's Encrypt |
| `https://gitea.home.arpa` | Gitea | Internal CA |
| `https://gitea.nik4nao.com` | Gitea | Let's Encrypt |
| `https://pihole.home.arpa` | Pi-hole | Internal CA |
| `https://dashy.home.arpa` | Dashy | Internal CA |
| `https://jellyfin.home.arpa` | Jellyfin | Internal CA |
@ -235,10 +235,9 @@ mobileconfig profile. The `ca-sync` CronJob updates those files from the
- Argo CD Applications mostly set `prune: false`; removing resources from Git may
require manual cleanup.
- Gitea is routed at `gitea.home.arpa` via `manifests/gitea/gitea-ingress.yaml`
(Certificate + IngressRoute); `values/gitea.yaml` has no `ingress:` key at
all, so the chart's own ingress is off by chart default, not an explicit
setting.
- Gitea uses a manual public `IngressRoute`; `values/gitea.yaml` has no
`ingress:` key at all, so the chart's own ingress is off by chart default,
not an explicit setting.
- Grafana and Loki's static hostPath PVs (`grafana-pv`, `loki-pv` in
`manifests/monitoring/monitoring-pvs.yaml`) are currently unbound — their
Helm-managed PVCs got dynamically provisioned via the `local-path`

View File

@ -61,7 +61,7 @@
After=network.target
[Service]
Environment=GITEA_INSTANCE_URL=https://gitea.home.arpa
Environment=GITEA_INSTANCE_URL=https://gitea.nik4nao.com
Environment=GITEA_RUNNER_REGISTRATION_TOKEN={{ gitea_runner_token }}
Environment=GITEA_RUNNER_NAME=minisforum
Environment=SSL_CERT_FILE=/etc/ssl/certs/homelab-ca.pem

View File

@ -3,5 +3,5 @@
# Called by: ansible/playbooks/deploy-watch-party.yaml
# Description: Default variables for the watch-party role including repo URL and local directory.
watch_party_repo: https://gitea.home.arpa/nik/watch-party.git
watch_party_repo: https://gitea.nik4nao.com/nik/watch-party.git
watch_party_dir: /Users/nik/repo/watch-party

View File

@ -6,7 +6,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/argocd
destination:

View File

@ -6,7 +6,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/authentik
directory:

View File

@ -20,7 +20,7 @@ spec:
helm:
valueFiles:
- $values/values/authentik.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -8,7 +8,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/cert-manager
directory:

View File

@ -14,7 +14,7 @@ spec:
helm:
valueFiles:
- $values/values/cert-manager.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -6,7 +6,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/core
directory:

View File

@ -8,7 +8,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/gitea
destination:

View File

@ -34,7 +34,7 @@ spec:
helm:
valueFiles:
- $values/values/gitea.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -8,7 +8,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/home-services
destination:

View File

@ -6,7 +6,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/homeassistant
destination:

View File

@ -16,7 +16,7 @@ spec:
releaseName: loki-stack
valueFiles:
- $values/values/loki-stack.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -6,7 +6,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/media
destination:

View File

@ -8,7 +8,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/monitoring
destination:

View File

@ -15,7 +15,7 @@ spec:
releaseName: kube-prometheus-stack
valueFiles:
- $values/values/kube-prometheus-stack.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -8,7 +8,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/network
directory:

View File

@ -6,7 +6,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/network
directory:

View File

@ -13,7 +13,7 @@ spec:
releaseName: otel-collector
valueFiles:
- $values/values/otel-collector.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -12,7 +12,7 @@ spec:
helm:
valueFiles:
- $values/values/pihole-debian.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -12,7 +12,7 @@ spec:
helm:
valueFiles:
- $values/values/pihole.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -6,7 +6,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: manifests/portfolio
directory:

View File

@ -14,7 +14,7 @@ spec:
helm:
valueFiles:
- $values/values/sealed-secrets.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -13,7 +13,7 @@ spec:
releaseName: tempo
valueFiles:
- $values/values/tempo.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -12,7 +12,7 @@ spec:
helm:
valueFiles:
- $values/values/traefik.yaml
- repoURL: https://gitea.home.arpa/nik/homelab.git
- repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
ref: values
destination:

View File

@ -106,7 +106,7 @@ sections:
id: 3_services_grafana
- title: Gitea
icon: si-gitea
url: https://gitea.home.arpa
url: https://gitea.nik4nao.com
target: newtab
id: 4_services_gitea
- title: Pi-hole

View File

@ -8,7 +8,7 @@ metadata:
spec:
project: default
source:
repoURL: https://gitea.home.arpa/nik/homelab.git
repoURL: https://gitea.nik4nao.com/nik/homelab.git
targetRevision: main
path: argocd/apps
destination:

View File

@ -1,29 +0,0 @@
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: gitea-tls
namespace: gitea
spec:
secretName: gitea-tls
issuerRef:
name: internal-ca-issuer
kind: ClusterIssuer
dnsNames:
- gitea.home.arpa
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: gitea
namespace: gitea
spec:
entryPoints:
- websecure
routes:
- match: Host(`gitea.home.arpa`)
kind: Rule
services:
- name: gitea-http
port: 3000
tls:
secretName: gitea-tls

View File

@ -0,0 +1,32 @@
# Apply: kubectl apply -f manifests/gitea/gitea-public-ingress.yaml
# Delete: kubectl delete -f manifests/gitea/gitea-public-ingress.yaml
# Description: Let's Encrypt TLS certificate and public IngressRoute for Gitea at gitea.nik4nao.com.
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: gitea-nik4nao-tls
namespace: gitea
spec:
secretName: gitea-nik4nao-tls
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
dnsNames:
- gitea.nik4nao.com
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: gitea-public
namespace: gitea
spec:
entryPoints:
- websecure
routes:
- match: Host(`gitea.nik4nao.com`)
kind: Rule
services:
- name: gitea-http
port: 3000
tls:
secretName: gitea-nik4nao-tls

View File

@ -19,7 +19,7 @@ spec:
- name: gitea-registry-secret
containers:
- name: ai-gateway
image: gitea.home.arpa/nik/ai-gateway:latest
image: gitea.nik4nao.com/nik/ai-gateway:latest
ports:
- containerPort: 50052
name: grpc

View File

@ -19,7 +19,7 @@ spec:
- name: gitea-registry-secret
containers:
- name: alert-bridge
image: gitea.home.arpa/nik/alert-bridge:latest
image: gitea.nik4nao.com/nik/alert-bridge:latest
ports:
- containerPort: 8080
name: http

View File

@ -19,7 +19,7 @@ spec:
- name: gitea-registry-secret
containers:
- name: alexa-bridge
image: gitea.home.arpa/nik/alexa-bridge:latest
image: gitea.nik4nao.com/nik/alexa-bridge:latest
ports:
- containerPort: 8080
name: http

View File

@ -19,7 +19,7 @@ spec:
- name: gitea-registry-secret
containers:
- name: discord-bot
image: gitea.home.arpa/nik/discord-bot:latest
image: gitea.nik4nao.com/nik/discord-bot:latest
env:
- name: DISCORD_TOKEN
valueFrom:

View File

@ -19,7 +19,7 @@ spec:
- name: gitea-registry-secret
containers:
- name: ha-gateway
image: gitea.home.arpa/nik/ha-gateway:latest
image: gitea.nik4nao.com/nik/ha-gateway:latest
ports:
- containerPort: 50051
name: grpc

View File

@ -6,7 +6,7 @@ set -euo pipefail
source "$(dirname "$0")/../../.env"
kubectl create secret docker-registry gitea-registry-secret \
--namespace=home-services \
--docker-server=gitea.home.arpa \
--docker-server=gitea.nik4nao.com \
--docker-username=nik \
--docker-password="${REGISTRY_PASSWORD}" \
--dry-run=client -o yaml | kubectl apply -f -

View File

@ -39,7 +39,7 @@ spec:
# very files this container needs to copy from.
initContainers:
- name: model-init
image: gitea.home.arpa/nik/tts-model:latest
image: gitea.nik4nao.com/nik/tts-model:latest
command: ["cp", "-a", "/models/.", "/dest/"]
volumeMounts:
- name: models
@ -53,7 +53,7 @@ spec:
memory: 64Mi
containers:
- name: tts-gateway
image: gitea.home.arpa/nik/tts-gateway:latest
image: gitea.nik4nao.com/nik/tts-gateway:latest
ports:
- containerPort: 50053
name: grpc
@ -98,7 +98,7 @@ spec:
# reach it over localhost, mirroring the --network host setup used
# for local docker testing (see tts-gateway/README.md).
- name: tts-sidecar
image: gitea.home.arpa/nik/tts-sidecar:latest
image: gitea.nik4nao.com/nik/tts-sidecar:latest
ports:
- containerPort: 50054
name: http
@ -139,7 +139,7 @@ spec:
secret:
secretName: tts-gateway-tls
# Populated at pod start by the model-init init container above, copying from the
# versioned gitea.home.arpa/nik/tts-model image - not a hostPath into nik-gpu's raw
# versioned gitea.nik4nao.com/nik/tts-model image - not a hostPath into nik-gpu's raw
# disk, so this survives node reprovisioning and isn't tied to manual file placement.
- name: models
emptyDir:

View File

@ -1,7 +1,6 @@
# Apply: kubectl apply -f manifests/network/watch-party-ingress.yaml
# Delete: kubectl delete -f manifests/network/watch-party-ingress.yaml
# Description: External Endpoints and Service for Watch Party on Mac Mini. No public
# route — taken off the internet (was Ingress + Let's Encrypt cert at watch-party.nik4nao.com).
# Description: External Endpoints, Service, and Ingress for Watch Party on Mac Mini at watch-party.nik4nao.com.
apiVersion: v1
kind: Endpoints
metadata:
@ -22,3 +21,30 @@ spec:
ports:
- port: 3000
targetPort: 3000
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: watch-party
namespace: default
annotations:
traefik.ingress.kubernetes.io/router.entrypoints: websecure
traefik.ingress.kubernetes.io/router.tls: "true"
cert-manager.io/cluster-issuer: letsencrypt-prod
spec:
ingressClassName: traefik
tls:
- secretName: watch-party-tls
hosts:
- watch-party.nik4nao.com
rules:
- host: watch-party.nik4nao.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: watch-party-mac-mini
port:
number: 3000

View File

@ -1,7 +1,6 @@
# Apply: kubectl apply -f manifests/portfolio/portfolio.yaml
# Delete: kubectl delete -f manifests/portfolio/portfolio.yaml
# Description: Portfolio website deployment and service. No public route — taken off
# the internet (was IngressRoute + Let's Encrypt cert at nik4nao.com).
# Description: Portfolio website deployment, service, TLS certificate, and public IngressRoute at nik4nao.com.
---
apiVersion: v1
kind: Namespace
@ -27,7 +26,7 @@ spec:
- name: gitea-registry
containers:
- name: portfolio
image: gitea.home.arpa/nik/portfolio:latest
image: gitea.nik4nao.com/nik/portfolio:latest
imagePullPolicy: Always
ports:
- containerPort: 80
@ -49,4 +48,50 @@ spec:
app: portfolio
ports:
- port: 80
targetPort: 80
targetPort: 80
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: portfolio-tls
namespace: portfolio
spec:
secretName: portfolio-tls
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
dnsNames:
- nik4nao.com
---
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: portfolio
namespace: portfolio
spec:
entryPoints:
- websecure
routes:
- match: Host(`nik4nao.com`)
kind: Rule
middlewares:
- name: portfolio-ratelimit
services:
- name: portfolio
port: 80
tls:
secretName: portfolio-tls
---
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: portfolio-ratelimit
namespace: portfolio
spec:
rateLimit:
average: 50
burst: 100
period: 1m
sourceCriterion:
ipStrategy:
depth: 1

View File

@ -13,9 +13,9 @@ gitea:
config:
server:
DOMAIN: gitea.home.arpa
ROOT_URL: https://gitea.home.arpa
SSH_DOMAIN: gitea.home.arpa
DOMAIN: gitea.nik4nao.com
ROOT_URL: https://gitea.nik4nao.com
SSH_DOMAIN: gitea.nik4nao.com
SSH_PORT: 2222
repository:
DEFAULT_PRIVATE: true