Compare commits
22
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
44d5207622 | ||
|
|
7a239b2469 | ||
|
|
795cef5a85 | ||
|
|
c1a2dbf52a | ||
|
|
0f854f2bfa | ||
|
|
283d30b422 | ||
|
|
2b2ceab2d1 | ||
|
|
6243ac40b7 | ||
|
|
d6fca68f33 | ||
|
|
e12327f963 | ||
|
|
b03098aa1c | ||
|
|
f61e8f1f68 | ||
|
|
7016f764e6 | ||
|
|
d826510a98 | ||
|
|
467b3441c9 | ||
|
|
7e91262257 | ||
|
|
0edd6bc73a | ||
|
|
4ad0102260 | ||
|
|
e0c08a90b3 | ||
|
|
dfbe2cc920 | ||
|
|
ae93c7ca0d | ||
|
|
91ce48ffae |
@@ -6,11 +6,9 @@ metadata:
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/proxy-read-timeout: "600"
|
||||
nginx.ingress.kubernetes.io/proxy-send-timeout: "600"
|
||||
# WebSocket support for Gotify client connections
|
||||
# WebSocket support for Gotify client connections (/stream endpoint)
|
||||
# nginx-ingress handles Upgrade/Connection headers natively with http/1.1
|
||||
nginx.ingress.kubernetes.io/proxy-http-version: "1.1"
|
||||
nginx.ingress.kubernetes.io/configuration-snippet: |
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
spec:
|
||||
ingressClassName: nginx
|
||||
rules:
|
||||
|
||||
@@ -20,3 +20,7 @@ data:
|
||||
# wire up allauth's confirm-email view, so signup 500s with NoReverseMatch
|
||||
# on 'account_confirm_email' without this.
|
||||
PAPERLESS_ACCOUNT_EMAIL_VERIFICATION: "none"
|
||||
# Auto-connect social accounts to existing users with matching email
|
||||
PAPERLESS_SOCIAL_AUTO_SIGNUP: "true"
|
||||
# Allow automatic linking of social accounts to existing users
|
||||
PAPERLESS_ACCOUNT_ALLOW_SIGNUPS: "true"
|
||||
|
||||
@@ -4,6 +4,7 @@ namespace: paperless
|
||||
resources:
|
||||
- pvc.yaml
|
||||
- configmap.yaml
|
||||
- paperless-ai-config.yaml
|
||||
- redis.yaml
|
||||
- deployment.yaml
|
||||
- service.yaml
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: paperless-ai-env
|
||||
namespace: paperless
|
||||
data:
|
||||
paperless-ai-config.env: |
|
||||
# Paperless-NGX API configuration
|
||||
PAPERLESS_URL=http://paperless.paperless.svc.cluster.local:8000
|
||||
PAPERLESS_API_TOKEN=7b89463e04c141f4172fbcddf78d623547d327ec
|
||||
|
||||
# AI Processing settings
|
||||
ENABLE_AI_PROCESSING=yes
|
||||
AI_MODEL=reasoning
|
||||
LLM_API_URL=https://api.riotpiao.com/v1
|
||||
LLM_API_TOKEN_FILE=/app/data/llm_token.txt
|
||||
|
||||
# Auto-tagging configuration
|
||||
ENABLE_AUTO_TAGGING=yes
|
||||
ENABLE_CORRESPONDENT_EXTRACTION=yes
|
||||
ENABLE_DOCUMENT_TYPE_EXTRACTION=yes
|
||||
ENABLE_TITLE_GENERATION=yes
|
||||
|
||||
# Advanced tagging with AI
|
||||
ENABLE_INTELLIGENT_TAGGING=yes
|
||||
ENABLE_DATE_EXTRACTION=yes
|
||||
ENABLE_TIMELINE_TAGGING=yes
|
||||
AUTO_CREATE_TAGS=yes
|
||||
|
||||
# Tagging prompts for custom extraction
|
||||
CUSTOM_EXTRACTION_PROMPT=Extract document date, time period, financial year, and temporal context. Create tags like YYYY, Q1-YYYY, Last-Month, Current-Year, Historic
|
||||
TAG_EXTRACTION_MODEL=reasoning
|
||||
|
||||
# Scanning behavior
|
||||
SCAN_INTERVAL_SECONDS=60
|
||||
PROCESS_EXISTING_DOCUMENTS=no
|
||||
ADD_AI_TAG=yes
|
||||
AI_TAG_NAME=ai-processed
|
||||
|
||||
# Date/Timeline tagging configuration
|
||||
DATE_EXTRACTION_FORMAT=iso8601
|
||||
TIMELINE_TAG_GRANULARITY=year,quarter,month
|
||||
AUTO_TAG_HISTORICAL=yes
|
||||
AUTO_TAG_RECENT=yes
|
||||
|
||||
# Performance
|
||||
MAX_CONCURRENT_REQUESTS=2
|
||||
REQUEST_TIMEOUT=60
|
||||
DATE_EXTRACTION_TIMEOUT=30
|
||||
@@ -25,9 +25,15 @@ spec:
|
||||
- name: paperless-ai-data
|
||||
persistentVolumeClaim:
|
||||
claimName: paperless-ai-data
|
||||
- name: paperless-ai-env-config
|
||||
configMap:
|
||||
name: paperless-ai-env
|
||||
initContainers:
|
||||
- name: fetch-llm-token
|
||||
image: curlimages/curl:8.12.0
|
||||
securityContext:
|
||||
runAsUser: 0
|
||||
fsGroup: 0
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
@@ -43,8 +49,8 @@ spec:
|
||||
-d "client_secret=${LLM_AUTH_CLIENT_SECRET}" \
|
||||
-d "scope=openid llm:inference" 2>/dev/null)
|
||||
|
||||
# Extract token
|
||||
TOKEN=$(echo "$TOKEN_RESPONSE" | grep -o '"access_token":"[^"]*' | cut -d'"' -f4)
|
||||
# Extract token from JSON response using sed (handles spaces after colons)
|
||||
TOKEN=$(echo "$TOKEN_RESPONSE" | sed -n 's/.*"access_token"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p')
|
||||
|
||||
if [ -z "$TOKEN" ]; then
|
||||
echo "[error] Failed to get token. Response: $TOKEN_RESPONSE"
|
||||
@@ -52,9 +58,13 @@ spec:
|
||||
fi
|
||||
|
||||
# Store token in file for main container to read
|
||||
mkdir -p /data
|
||||
echo "$TOKEN" > /data/llm_token.txt
|
||||
echo "[init] Token fetched and stored successfully"
|
||||
# Write to both locations for compatibility
|
||||
mkdir -p /tmp/llm-token /app/data 2>/dev/null || true
|
||||
echo "$TOKEN" | tee /tmp/llm-token/llm_token.txt > /dev/null 2>&1
|
||||
echo "$TOKEN" > /app/data/llm_token.txt 2>/dev/null || true
|
||||
echo "[init] Token fetched and stored"
|
||||
[ -f /tmp/llm-token/llm_token.txt ] && echo " -> /tmp/llm-token/llm_token.txt"
|
||||
[ -f /app/data/llm_token.txt ] && echo " -> /app/data/llm_token.txt"
|
||||
env:
|
||||
- name: LLM_AUTH_CLIENT_SECRET
|
||||
valueFrom:
|
||||
@@ -63,7 +73,7 @@ spec:
|
||||
key: LLM_AUTH_CLIENT_SECRET
|
||||
volumeMounts:
|
||||
- name: paperless-ai-data
|
||||
mountPath: /data
|
||||
mountPath: /app/data
|
||||
containers:
|
||||
- name: paperless-ai
|
||||
image: clusterzx/paperless-ai:latest
|
||||
@@ -105,6 +115,9 @@ spec:
|
||||
volumeMounts:
|
||||
- name: paperless-ai-data
|
||||
mountPath: /app/data
|
||||
- name: paperless-ai-env-config
|
||||
mountPath: /app/data/.env
|
||||
subPath: paperless-ai-config.env
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
|
||||
@@ -1,23 +1,24 @@
|
||||
apiVersion: ENC[AES256_GCM,data:l7I=,iv:NZY7r3JVW3zVwxeiScvWKpAQUDa9+nckHd0qWVrGU88=,tag:qpowp5OILdYKtTux/nlWpg==,type:str]
|
||||
kind: ENC[AES256_GCM,data:6oeEbuIk,iv:5flI9TtcYQ961wOYPBPhvQpitHFYAf8yMdNBXqytbJs=,tag:WNhlbKmSeZEqZ9ZgiB/BYg==,type:str]
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: ENC[AES256_GCM,data:fvJMsgy+wPZqMCdxm9hoV3n/+Q==,iv:I3rVtHIJBOME+bxhPws58Zjhj5i+KT5UtB9o7Vus5EU=,tag:6h4FnUu7PGxlQPIQxPYCRg==,type:str]
|
||||
namespace: ENC[AES256_GCM,data:CDriLoLovROW,iv:rHXcN1xm5+t2D/Tq/2sx9lQFF8anD5jH24ZntPuBA8U=,tag:XstJAz6S8IM1c/pp9Cg0Ww==,type:str]
|
||||
type: ENC[AES256_GCM,data:JdTwBbag,iv:9Ys15Ketl0ghNK0u0N8IOpUt7+KoloutiG5M9zHPXxw=,tag:teau/udf41Ty34A5wLAm6Q==,type:str]
|
||||
name: paperless-ai-config
|
||||
namespace: paperless
|
||||
type: Opaque
|
||||
stringData:
|
||||
PAPERLESS_API_TOKEN: ENC[AES256_GCM,data:TuQeDx8po3h4loTRABlItVYQJ7gFjnmIn3zQQGtUcoNFMKpkqLK/GQ==,iv:TDg0stpca5pDtatqu8DFU7R0Bm/S/BI9ZoiG4K8mCT4=,tag:BfjX25V5gL7AeIsscClRAg==,type:str]
|
||||
PAPERLESS_API_TOKEN: ENC[AES256_GCM,data:wlBC85ep6zioWLhfhNczkKfTMR8tmciN+4r3of8GpQoJmKyE2r7pOg==,iv:Rem/UJl5wUNi8G+uEV7f2eCLabaY26sZ7+AsKYiOZ4I=,tag:bGS1fu13Mwsrr+5NUEzzLw==,type:str]
|
||||
LLM_AUTH_CLIENT_SECRET: ENC[AES256_GCM,data:co7FfmRXKgrz9fNgR10KtlHL/iG4F5WKJgjcKem1H5hF5FviVi4+CQNekA==,iv:ADtBHiI6BtrkuH1iIfKV3I5odNLMQe5y/9GGTJrPNN0=,tag:j6wX6zO5VhKoLzdr7BQZCw==,type:str]
|
||||
sops:
|
||||
age:
|
||||
- enc: |
|
||||
-----BEGIN AGE ENCRYPTED FILE-----
|
||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBKVDN3aFVqVmFXY1VQVXZP
|
||||
OUsrNHdNdlRvRFgvTDQrNE5uL2xaazVENTBjCkNPbGR5Vk16RXNDOW15OGNTRmFR
|
||||
U0JOeTllaWU1dzNVY3lBbEVyVG5tOEkKLS0tIEZvajlvcUtJdFNNUkkzV3FKOFRj
|
||||
UUE2TDBzT0xVc2E1NlUvQXAyZytMZEUKBv+ChaoQCstA742L3Bq5mBJlW/UC4Pyw
|
||||
ZvFAyYbs1NaEqhjtHq+4T62jTWcH/St/vKgUuFQ9LCUQhYd8DUzAow==
|
||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBJWDZwTE1haUY5ZkgybnBx
|
||||
WEFVSzQvNjlGaDlvaHhuSTVCY2dYb0s1NW4wCmhkM0N6YlNIRTYrVkdxaHJaVHVG
|
||||
bUEzTVV3WFQ0OWwrdEZnanJJa09Nb3MKLS0tIGduNEFtT2hCUDlkZWpWZmliZy83
|
||||
cUoxcXp1NFF3SFpBVVdSZE5GY1VIWmsKH+cMqasOVxgCnGedaM2IAsgwOzEsOMct
|
||||
0XjmInpppWNe+t7leEb6MqEY2cPQHL+l2L5jkZzAOfImwaIwMQnghw==
|
||||
-----END AGE ENCRYPTED FILE-----
|
||||
recipient: age1e5fq3hwxy78psus2nfvmtmua36g0u3suk78ephw6246l974d2utsvn0hla
|
||||
lastmodified: "2026-09-12T21:04:26Z"
|
||||
mac: ENC[AES256_GCM,data:0ks96xQzOa8ygNDDYfKV8EJ8dWLBaC0PCnLG73NinMByF/KoWkCdwMDPC34W9xxVoTD2NiF1i/3pgCG4QFezTE7tPHPPKdYcQfwda9fkooiXW4Nh2M/sgbq/xgsy9N3qpHD/O5iILgpehb9y0DuErOyxcn2AIYizynU7m8e63pc=,iv:fvPWBsfE6YHskKzdlxJidp14dUgRR0XdMkEu6IxMMSo=,tag:5FiuIrFOg/GXvlQVy7drJQ==,type:str]
|
||||
unencrypted_suffix: _unencrypted
|
||||
encrypted_regex: ^(data|stringData)$
|
||||
lastmodified: "2026-09-14T14:19:39Z"
|
||||
mac: ENC[AES256_GCM,data:jDdmiFg6uB1za7sAjO1CnGHdRPyUnmWCMJxqHrE3BO82pNbtm8yLOf+W6CfFKAjfZYqEE2mdKhABm7zeJgJlub3eXJbAirAFrp5jrbfHw0qsFo85Gj/BsrSDB401Aky6PxvRomz66FyX5zDDXIGAMEMlyNEadMplTfrZQQ9hQWM=,iv:UTSF72ofUyWs1LXGKQwBP60hK64UxhqTFM8QTVozGoo=,tag:OKivMDAqwWgrX+kNjvQrPg==,type:str]
|
||||
version: 3.13.2
|
||||
|
||||
@@ -73,7 +73,7 @@ grafana.ini:
|
||||
auth.generic_oauth:
|
||||
enabled: true
|
||||
name: Authentik
|
||||
allow_sign_up: true
|
||||
allow_sign_up: true # Allow sync to create/update users from OAuth claims
|
||||
client_id: grafana
|
||||
scopes: openid email profile groups
|
||||
auth_url: https://authentik.riotpiao.com/application/o/authorize/
|
||||
@@ -84,13 +84,13 @@ grafana.ini:
|
||||
# Authentik doesn't serve — request 404s with "Error getting email address"
|
||||
# and the whole OAuth login fails.
|
||||
email_attribute_path: email
|
||||
login_attribute_path: preferred_username
|
||||
login_attribute_path: preferred_username # Use preferred_username — OpenID standard claim, always present
|
||||
name_attribute_path: name
|
||||
role_attribute_path: "preferred_username == 'akadmin' && 'GrafanaAdmin' || contains(groups[*], 'homelab-admins') && 'Admin' || 'Viewer'"
|
||||
allow_assign_grafana_admin: true
|
||||
use_pkce: false
|
||||
use_refresh_token: false
|
||||
skip_org_role_sync: false
|
||||
skip_org_role_sync: false # Sync org roles from OAuth groups
|
||||
tls_skip_verify_insecure: true # Authentik uses self-signed cert; verify in prod
|
||||
|
||||
# GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET is injected from the grafana-oidc K8s
|
||||
|
||||
@@ -112,10 +112,16 @@ spec:
|
||||
name: minio-oidc
|
||||
key: MINIO_IDENTITY_OPENID_CLIENT_SECRET
|
||||
- name: MINIO_IDENTITY_OPENID_CLAIM_NAME
|
||||
value: "policy"
|
||||
value: "groups"
|
||||
- name: MINIO_IDENTITY_OPENID_CLAIM_PREFIX
|
||||
value: ""
|
||||
- name: MINIO_IDENTITY_OPENID_REDIRECT_URI
|
||||
value: "https://minio.riotpiao.com/oauth_callback"
|
||||
- name: MINIO_IDENTITY_OPENID_DISPLAY_NAME
|
||||
value: "Authentik"
|
||||
- name: MINIO_IDENTITY_OPENID_SCOPES
|
||||
value: "openid,profile,email,minio"
|
||||
value: "openid,profile,email,groups"
|
||||
- name: MINIO_BROWSER_LOGIN_ANIMATION
|
||||
value: "off"
|
||||
- name: MINIO_BROWSER_REDIRECT_URL
|
||||
value: "https://minio.riotpiao.com"
|
||||
|
||||
@@ -54,8 +54,8 @@ alertmanager:
|
||||
# ── Prometheus ────────────────────────────────────────────────────────────────
|
||||
prometheus:
|
||||
prometheusSpec:
|
||||
retention: 15d
|
||||
retentionSize: "18GB"
|
||||
retention: 30d
|
||||
retentionSize: "95GB"
|
||||
|
||||
# scrapeTimeout MUST be <= scrapeInterval or the operator refuses to generate
|
||||
# the Prometheus config ("scrapeTimeout greater than scrapeInterval") and no
|
||||
@@ -64,10 +64,9 @@ prometheus:
|
||||
scrapeTimeout: 60s
|
||||
evaluationInterval: 30s
|
||||
|
||||
# Pin to az-a (talos-cp-1) — sole Longhorn node; else the RWO PVC can't
|
||||
# attach on cp-2/cp-3 (CSINode lacks driver.longhorn.io).
|
||||
# Pin to worker-1 for more storage capacity
|
||||
nodeSelector:
|
||||
topology.kubernetes.io/zone: az-a
|
||||
kubernetes.io/hostname: worker-1
|
||||
|
||||
# Persistent storage — metrics survive node reboots and pod restarts.
|
||||
# Uses the default `longhorn` StorageClass; nodeSelector above already pins
|
||||
@@ -79,7 +78,7 @@ prometheus:
|
||||
accessModes: ["ReadWriteOnce"]
|
||||
resources:
|
||||
requests:
|
||||
storage: 20Gi
|
||||
storage: 100Gi
|
||||
|
||||
resources:
|
||||
requests:
|
||||
|
||||
@@ -38,6 +38,7 @@
|
||||
rewrite name api.riotpiao.com ingress-nginx-controller.ingress-nginx.svc.cluster.local
|
||||
rewrite name comfy.riotpiao.com ingress-nginx-controller.ingress-nginx.svc.cluster.local
|
||||
rewrite name comfyui.riotpiao.com ingress-nginx-controller.ingress-nginx.svc.cluster.local
|
||||
rewrite name gotify.riotpiao.com ingress-nginx-controller.ingress-nginx.svc.cluster.local
|
||||
rewrite name riotpiao.com ingress-nginx-controller.ingress-nginx.svc.cluster.local
|
||||
|
||||
kubernetes cluster.local in-addr.arpa ip6.arpa {
|
||||
|
||||
Reference in New Issue
Block a user