Story Crater Bot
5dd38d37d4
fix(vault): correct MinIO S3 backend endpoint/timeout/api_addr — converges to minio-cluster-hl:9000
2026-08-18 15:08:02 -07:00
Story Crater Bot
1ee24e947b
feat(temporal): drop Cassandra/ES, migrate persistence to CNPG PostgreSQL
2026-08-18 15:08:02 -07:00
Story Crater Bot
24dda9d8f8
fix(minio): disable standalone console (use tenant built-in console instead)
2026-08-18 15:08:02 -07:00
Story Crater Bot
92891d0f9c
feat(temporal): Cassandra/ES persistence bring-up attempt (RBAC + config iterate)
2026-08-18 15:08:02 -07:00
Story Crater Bot
3610fb9e5e
fix(prometheus): pin to az-a longhorn-wffc SC, drop conflicting ServerSideApply
2026-08-18 15:08:02 -07:00
Story Crater Bot
2845ded626
fix(ingress): switch riotpiao-com-tls to letsencrypt-prod issuer
...
Wildcard cert was left on letsencrypt-staging; staging root is not
browser-trusted so HTTPS to *.riotpiao.com fails cert validation.
Switch issuerRef to letsencrypt-prod to issue a trusted wildcard.
2026-08-18 15:08:02 -07:00
Story Crater Bot
96b4064ec7
fix(prometheus): scrapeTimeout must be <= scrapeInterval — authentik/nginx SMs (60s>30s) + global (60s>30s) blocked operator config gen, no Prometheus STS created
2026-08-18 15:08:02 -07:00
Story Crater Bot
dc1ab77b54
fix: set logging/monitoring namespaces privileged PSS for promtail/node-exporter hostPath access
2026-08-18 15:08:02 -07:00
Story Crater Bot
cd861a75e6
fix(argocd): raise repo-server memory 512Mi->1Gi — OOMKilled under CMP+Helm rendering caused chronic restarts, not-ready endpoint, and cluster-wide sync 'no route to host' failures
2026-08-18 15:08:02 -07:00
Story Crater Bot
a77e2b6579
fix(kmsvc-redis): use bitnamilegacy/redis mirror + allowInsecureImages — docker.io/bitnami pulled version-pinned tags, ImagePullBackOff blocked redis + queue-operator
2026-08-18 15:08:02 -07:00
Story Crater Bot
6cbd887b89
fix(forgejo-runner): add fsGroup 1000 so runner user can write /data/.runner — register hit permission denied on root-owned Longhorn PVC
2026-08-18 15:08:02 -07:00
Story Crater Bot
7e345625fa
chore(ci): refresh forgejo runner registration token — prior token invalid/expired
2026-08-18 15:08:02 -07:00
Story Crater Bot
b1be1d0d2c
fix(forgejo-runner): point at in-cluster forgejo Service :3000 not public :443 — runner i/o timeout, forgejo serves 3000 not 443
2026-08-18 15:08:02 -07:00
Story Crater Bot
0a6568491b
fix(minio,loki): declare loki-chunks/ruler/admin buckets in minio Tenant — loki failed with NoSuchBucket
2026-08-18 15:08:02 -07:00
Story Crater Bot
63fc502359
fix(loki,vault,iam): loki minio endpoint :80 not :9000, emit vault-minio-creds via CMP, drop redundant broken authentik-migrations job
2026-08-18 15:08:02 -07:00
Story Crater Bot
7ab39280c2
fix(ingress): add homelab-ingress ArgoCD app to apply orphaned ingress.yaml — services had no Ingress object, unreachable via LAN ingress .160
2026-08-18 15:08:02 -07:00
Story Crater Bot
97330d780c
feat(terraform): add per-node Cloudflare Tunnel cert SANs to controlplane certSANs — remote talosctl/kubectl over tunnel pass TLS verification
...
Adds optional cloudflare_talos_sans (machine.certSANs, talos API :50000) and
cloudflare_apiserver_sans (cluster.apiServer.certSANs, kube-apiserver :6443) per
control-plane node. cp-1 gets cp1.homelab + cp1-talos.homelab; cp-2/cp-3 get
their cpN-talos.homelab. Values set in gitignored tfvars.
2026-08-18 15:08:02 -07:00
Story Crater Bot
2b89981c28
chore(ci): add SOPS-encrypted runner-token secret record for forgejo-runner registration
2026-08-18 15:08:02 -07:00
Story Crater Bot
384548b424
fix(storage): add longhorn-wffc SC + pin portainer/forgejo-runner to az-a — fixes PVC attach
2026-08-18 15:08:02 -07:00
Story Crater Bot
cda75eeb7b
fix(authentik): drop redundant authentik-migrate init container — server entrypoint migrates; old-image manage migrate tripped version-history precheck on empty DB
2026-08-18 15:08:02 -07:00
Story Crater Bot
79118de8d3
feat(data): add CNPG managed roles + Database CRs for authentik/temporal — replaces missing helmfile post-sync user creation
...
authentik/temporal DB users+databases were never provisioned (old helmfile hook
gone; db-init-job only made schemas in shared app DB). Adds managed.roles
(authentik/temporal login roles, passwords from basic-auth secrets) + Database CRs
(dedicated DBs owned by each role). Role secrets applied out-of-band (SOPS), not in
kustomize resources so data-schemas app doesn't choke on ciphertext.
2026-08-18 15:08:02 -07:00
Story Crater Bot
48f3dd1db9
feat(argocd): wire SOPS CMP sidecar + fix loki/grafana/authentik secret resolution
2026-08-18 15:08:02 -07:00
Story Crater Bot
d9ae0a6c44
feat(substrate): deploy cert-manager/ingress-nginx/reloader + privileged PodSecurity for ingress-nginx
2026-08-18 15:08:02 -07:00
Story Crater Bot
a6465f7158
fix(minio): correct operator chart source + rewrite Tenant to v5 schema + config.env creds — tenant now boots
2026-08-18 15:08:02 -07:00
Story Crater Bot
2623eecfca
feat(argocd): SOPS CMP plugin decryption for Stage 0 secrets (simplify to directory source)
2026-08-18 15:08:02 -07:00
Story Crater Bot
dca0e7cb9a
feat(cloudflared): wire tunnel token secret and document bootstrap
...
- Create SOPS-encrypted cloudflared-secrets.enc.yaml with tunnel token
- Add Cloudflare vars to .env.example (CLOUDFLARE_CONNECTOR_TOKEN, ACCOUNT_ID, TUNNEL_ID, API_TOKEN)
- Document Phase 0 cloudflared-token Secret creation in BOOTSTRAP.md (manual step until CMP plugin wires it)
- Note: Cloudflare-side TCP routing (cp1.homelab -> 192.168.1.213:6443, etc.) must be configured manually in Zero Trust dashboard
Tunnel already deployed as ArgoCD Application in k8s/argocd/apps/60-applications.yaml (wave 8); this closes the missing Secret gap and documents the bootstrap path.
2026-08-18 15:08:02 -07:00
Story Crater Bot
1168dc8417
fix(k8s,docs): scale ddb-cluster to single instance, pin minio to storage namespace, document 3-CP topology in USAGE
2026-08-18 15:08:02 -07:00
Story Crater Bot
8f86a03828
refactor(argocd): replace wave/layer/phase schemes with two-phase bootstrap + app-of-apps and document both CD scopes — fixes self-hosted-git chicken-egg and stale paths
2026-08-18 15:08:02 -07:00
Story Crater Bot
5b34e71111
feat(terraform): restructure control planes into a 3-node map with LAN etcd advertise and live machine CA — enables talos-cp-1/2/3 HA and drops worker configs
2026-08-18 15:08:02 -07:00
Story Crater Bot
9956379f5f
chore: remove scratch planning docs — not meant for the repo
2026-08-18 15:08:02 -07:00
Story Crater Bot
54bfb5ade6
feat(gitops): migrate domain to riotpiao.com, add CNPG + Forgejo HA on Redis/Postgres, wire ArgoCD apps — enables cluster rebuild after etcd wipe and unblocks the git-source chicken-egg via standalone Helm-source Applications
2026-08-18 15:08:02 -07:00
Story Crater Bot
491e88e493
feat(ci,iac): Consolidate Forgejo CI workflows and add Talos Terraform IaC
...
Consolidate three separate Forgejo Actions (argocd-sync, security-scan, validate-k8s) into single cluster-ci workflow for cleaner CI/CD pipeline with proper job sequencing and reduced auth overhead.
Add Terraform configuration for Talos cluster machine configs:
- Provider setup for Talos
- Centralized variables for CP and worker configs
- Template-based config generation for controlplane.yaml and worker-*.yaml
- Sensitive data separated in terraform.tfvars (gitignored)
- Local state tracking for infrastructure
2026-08-18 15:08:01 -07:00
Story Crater Bot
e48580adb9
fix(ci): Forgejo Actions auth + kustomize cleanup in validate-k8s workflow
2026-08-18 15:08:01 -07:00
Story Crater Bot
517d823f77
feat(minio): Expand CRDs to include Policies and Users — full YAML-driven resource creation
...
Add MinIO Policies and Users via CRD alongside Buckets.
Resources now declarative:
- Bucket: riotpiao-models (versioning enabled)
- Policy: policy-ollama (scoped bucket access)
- User: user-ollama (service account for Ollama/LLM)
Access keys can be overridden via SOPS or kustomize overlays.
All MinIO resource creation now git-tracked and version controlled.
2026-08-18 15:08:01 -07:00
Story Crater Bot
5c259237d7
feat(data): Add CNPG cluster + database schema initialization
...
Create production PostgreSQL cluster via CNPG (3-node HA, Longhorn storage).
Schema initialization Job creates schemas for:
- Authentik (identity provider)
- Temporal (workflow engine)
- Vault (secrets management)
- App (generic application databases)
Database layer now captures complete IaC for stateful infrastructure.
Services find ready schemas when deployed.
2026-08-18 15:08:01 -07:00
Story Crater Bot
c12fbcf45e
feat(minio): Add MinIO Bucket CRD for riotpiao-models — replaces shell script setup
2026-08-18 15:08:01 -07:00
Story Crater Bot
0f30d77288
refactor(k8s): Reorganize into 5-layer structure with production kustomizations
2026-08-18 15:08:01 -07:00
Story Crater Bot
563f720d09
refactor: retire Terraform, migrate to pure ArgoCD GitOps + CI validation
2026-08-18 15:08:01 -07:00
Story Crater Bot
adbad3d97e
fix(ci): use direct in-cluster Kubernetes auth for CI runner — drop kubeconfig file dependency
2026-08-18 15:08:01 -07:00
Story Crater Bot
3833c0d119
fix: terraform fmt — normalize formatting across all files
2026-08-18 15:08:01 -07:00
Story Crater Bot
df9d9845c0
fix(ci): correct core-cli auth + S3 backend config for CI runner (iterate)
2026-08-18 15:08:01 -07:00
Story Crater Bot
f16f439feb
feat: Terraform CI via Forgejo Actions + MinIO S3 state backend
...
- ArgoCD manages MinIO (phase 0), Terraform manages infrastructure
- Runner workflow: pulls state from S3, validates, plans, applies
- 34 resources imported to state, S3 backend operational
- Fixed AppProject repos, S3 endpoint deprecation, runner package manager
2026-08-18 15:08:01 -07:00
Story Crater Bot
292146bce4
feat(phase4): ArgoCD-driven Terraform apply via PVC imports (Pod Job approach tried and reverted)
2026-08-18 15:08:01 -07:00
Story Crater Bot
74729f1c59
docs(terraform): add state management script and best practices guide
2026-08-18 15:08:01 -07:00
Story Crater Bot
31a266ee58
chore(phase4): stub helmfile — all releases managed by Terraform + ArgoCD
2026-08-18 15:08:01 -07:00
Story Crater Bot
5e887b4da3
feat(argocd): migrate phase3 (authentik) to ArgoCD, keep temporal on helmfile
2026-08-18 15:08:01 -07:00
Story Crater Bot
0b4a79b5ca
fix(argocd): use homelab-ca wildcard TLS instead of --insecure mode
2026-08-18 15:08:01 -07:00
Story Crater Bot
2060d4c493
feat(argocd): migrate phase2 releases (CNPG/Loki/Grafana/Forgejo/Forgejo-Runner) to ArgoCD
2026-08-18 15:08:01 -07:00
Story Crater Bot
3e0a1c86ba
feat(argocd): migrate phase1 hookless releases to ArgoCD
2026-08-18 15:08:01 -07:00
Story Crater Bot
8eab299b30
docs(phase1): create migration guide for 9 hookless releases
...
Detailed Phase 1 workflow:
- Template Application spec (Helm source, values, sync policy)
- Per-release migration pattern (create → test → remove → commit)
- Helmfile ↔ ArgoCD mapping table
- Local chart handling (source.path vs source.chart)
- Verification checklist
- Rollback instructions
Reference: execute one release at a time, verify before next.
2026-08-18 15:08:01 -07:00