feat(homarr): complete wiring for landing page deployment
Adds Homarr landing page with Authentik SSO: - k8s/argocd/apps/60-applications.yaml: multi-source Application (homarr chart from homarr-labs + in-repo values), ns dashboard, wave 8 - k8s/bootstrap/ingress/ingress.yaml: homarr.riotpiao.com → dashboard/homarr:3000 - k8s/bootstrap/coredns/coredns-configmap.yaml: rewrite homarr.riotpiao.com to ingress controller - k8s/security/iam/scripts/authentik-provision.py: added 'homarr' to SERVICES (generates OAuth provider/app + homarr-oidc secret with client-id/secret) - k8s/security/iam/rbac-dashboard-rolebinding.yaml: grants authentik-provisioner SA access to dashboard ns for secret management - k8s/security/iam/kustomization.yaml: includes new RoleBinding Homarr now fully wired: - Ingress: https://homarr.riotpiao.com - SSO: redirects to Authentik, login as rock - Persistence: 5Gi RWO on longhorn-wffc (3-replica HA) - Tile config: UI-managed (saved to PVC)
This commit is contained in:
@@ -132,3 +132,32 @@ spec:
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
---
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: homarr
|
||||
namespace: argocd
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "8"
|
||||
spec:
|
||||
project: homelab
|
||||
sources:
|
||||
- repoURL: https://homarr-labs.github.io/charts
|
||||
chart: homarr
|
||||
targetRevision: "*"
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/k8s/applications/homarr/homarr-values.yaml
|
||||
- repoURL: https://forgejo.riotpiao.com/riotpiao.com/homelab.git
|
||||
targetRevision: main
|
||||
ref: values
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: dashboard
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
syncOptions:
|
||||
- CreateNamespace=true
|
||||
|
||||
Reference in New Issue
Block a user