mirror of
https://github.com/dredx/prole.git
synced 2026-09-27 21:54:30 +00:00
knoe-auth (prole.org k3s): - Fix CNPG manifest drift: remove spec.backup.pluginConfiguration (CNPG 1.28 only), switch spec.certificates from serverTLSSecret to serverAltDNSNames - Apply knoe-auth Round 1 schema + GRANTs manually (postInitSQL had never run on live cluster) - Fix OIDC signing key generator: base64(DER) not base64(PEM) — OidcTokenService does Base64.decode() → PKCS8EncodedKeySpec which requires raw DER bytes - Add OIDC controllers: authorize, token, userinfo, jwks, discovery - Add prole Spring profile: cookieDomain, emailDomain, Kerberos config - Add secret example templates: knoe-db-user, knoe-auth-oidc-signing, knoe-auth-google-prole - Kong configmap: scope knoe-auth route to /auth prefix only Tenant onboarding: - Add etc/onboard_tenant.sh: provision/apply/rotate/status workflow backed by 1Password vaults; types: 'enterprise' (own Kerberos + domain) and 'tenant' (hosted, initContainer KDC) - Provision 'Knoe Tenant - prole.org' vault; apply all 7 k8s secrets to knoe-system - init_knoe_auth.sh: add explicit GRANT + ALTER DEFAULT PRIVILEGES for knoe role Cluster stabilisation: - gitea: roll back 14-day stuck rollout (RWO PVC + maxSurge=100% deadlock); patch deployment strategy to Recreate - supabase: create supabase_admin role, _supabase db, _analytics schema, _realtime schema in CNPG — analytics and realtime had never connected since Helm install day 1 - knoe-db barman ObjectStore: add GCS-backed objectstore manifest + scheduled backup Infrastructure: - gandalf host_vars: k3s registry config - pi host_vars: clean up stale entries - knoe-db schemas: ekosystem.sql, ekosystem_objects.sql - init_prole_app.sql: prole app DB initialisation Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
36 lines
1.0 KiB
YAML
36 lines
1.0 KiB
YAML
iscsi_portal: 10.0.0.203
|
|
|
|
# pi.prole.org is a dedicated pihole node — k3s disabled, insufficient RAM.
|
|
# PROLE-DATA-3 (d003) moved to gandalf.prole.org 2026-05-24.
|
|
k3s_required_mounts: []
|
|
|
|
iscsi_targets:
|
|
# PROLE-PI-2 — pihole log storage
|
|
- iqn: "iqn.2000-01.com.synology:synology.Target-19.292d45194a1"
|
|
chap_user: "prole"
|
|
chap_password: "{{ vault_iscsi_prole_password }}"
|
|
mounts:
|
|
- path: /var/log/pihole
|
|
fstype: ext4
|
|
opts: "_netdev,noatime"
|
|
src: "UUID=56b21ec3-2826-4171-b909-a6715223f9a4"
|
|
|
|
# k3s intentionally disabled — pi.prole.org is a dedicated pihole node;
|
|
# insufficient RAM for k3s workloads; agent manually stopped 2026-04-01.
|
|
k3s_enabled: false
|
|
k3s_state: absent
|
|
k3s_rancher_mount_required: false
|
|
|
|
k3s_role: agent
|
|
k3s_cluster_init: false
|
|
k3s_server_url: "https://myrddin.prole.org:6443"
|
|
k3s_service_node_labels:
|
|
- "prole.org/node-role=general"
|
|
- "prole.org/role=observer"
|
|
k3s_node_taints: []
|
|
|
|
k3s_write_kubeconfig_mode: "0640"
|
|
k3s_kubeconfig_group: kubeadm
|
|
k3s_kubeconfig_users:
|
|
- pi
|