1183 Commits

Author SHA1 Message Date
05cdf75dc6 finance: add actual budget and firefly 2026-01-16 23:52:56 -03:00
dc9b6e1213 planka: allow project creation for all users 2026-01-16 17:58:20 -03:00
fd88e8e04f keycloak: rerun realm and user overrides 2026-01-16 17:47:34 -03:00
574353d884 keycloak: enforce bstein group membership 2026-01-16 17:36:07 -03:00
5ba9501db9 longhorn: use harbor mirrors and vault pull secret 2026-01-16 17:31:29 -03:00
90a25ac73e platform: add cert-manager and align postgres vault path 2026-01-16 11:14:48 -03:00
f552119323 jellyfin: move cache to emptyDir 2026-01-16 09:43:01 -03:00
85e5584b20 maintenance: avoid blocking on k3s traefik cleanup 2026-01-16 09:38:14 -03:00
fe7bfd590d maintenance: allow traefik cleanup watch 2026-01-16 09:33:11 -03:00
37571ef738 maintenance: cleanup k3s traefik and wger attrs 2026-01-16 09:27:22 -03:00
b72561e5ec maintenance: disable k3s traefik; keycloak portal admin roles 2026-01-16 07:53:04 -03:00
913dd7208a jellyfin: set traefik tls annotations 2026-01-16 04:01:27 -03:00
a603b88eea vault/keycloak: restore kv access and wger sync rbac 2026-01-16 03:46:07 -03:00
b308ee8d55 vault: allow admin kv browse 2026-01-16 03:20:32 -03:00
05b0242e26 vault: allow UI mount listing for admins 2026-01-16 02:06:31 -03:00
af86a610d9 fix ingress tls routing 2026-01-16 01:40:50 -03:00
109bd3026f fix logging pipeline secret and scheduling 2026-01-16 00:15:58 -03:00
621550cba1 comms: fix mas vault file paths 2026-01-15 23:56:32 -03:00
4de2e96f4d gitea: expose ssh via metallb shared IP 2026-01-15 16:39:04 -03:00
04a58b43d6 core: add bstein.dev coredns overrides 2026-01-15 16:29:32 -03:00
ae688d0db6 logging: disable wait for data-prepper helmrelease 2026-01-15 04:47:07 -03:00
6d249466ee keycloak: align smtp probe user 2026-01-15 04:44:35 -03:00
9bddcd1e76 keycloak: rerun execute-actions email e2e 2026-01-15 04:37:12 -03:00
78a547d6b8 bstein-dev-home: rerun onboarding e2e job 2026-01-15 04:35:06 -03:00
b1ddb110cc logging: fix data-prepper post-render patch 2026-01-15 04:27:25 -03:00
397eefdaf6 keycloak: rerun realm smtp config 2026-01-15 04:24:16 -03:00
d4f110534f vault: allow admin policy to update shared secrets 2026-01-15 04:17:14 -03:00
98ca8f6b1a smtp: use mail.bstein.dev for app relays 2026-01-15 04:04:50 -03:00
e6ce9b0d88 smtp: point services at mailu relay 2026-01-15 03:58:03 -03:00
ebca451243 vault: allow sso role to read portal admin secret 2026-01-15 03:46:58 -03:00
ad0b6d597d fix: bump keycloak and portal e2e job names 2026-01-15 03:44:27 -03:00
30588fd739 vault: fix data-prepper pipeline and portal admin secret job 2026-01-15 03:42:57 -03:00
5e4cc4a416 logging: patch data-prepper volume via json 2026-01-15 03:30:16 -03:00
54bc294d34 logging: drop namespace from data-prepper patch 2026-01-15 03:27:36 -03:00
b63660c4c5 logging: simplify data-prepper patch 2026-01-15 03:25:33 -03:00
2127a0098c logging: use strategic patch for pipeline volume 2026-01-15 03:23:42 -03:00
6ebeee384c logging: switch data-prepper volume to configmap 2026-01-15 03:17:07 -03:00
8e5190a20f logging: replace pipeline volume with configmap 2026-01-15 03:14:07 -03:00
e9318db2fc logging: patch data-prepper volume to configmap 2026-01-15 03:12:13 -03:00
05a88bae9e bstein-dev-home: restore image automation setters 2026-01-15 03:11:57 -03:00
55383a654e nextcloud: fix cronjob shell flags 2026-01-15 03:08:01 -03:00
11dbb10b50 logging: move data-prepper pipeline to configmap 2026-01-15 02:59:21 -03:00
5b8dd6f322 keycloak: stop writing oauth2-proxy secret 2026-01-15 02:37:04 -03:00
5ac24c85b0 crypto: drop wallet rpc bootstrap job 2026-01-15 02:31:31 -03:00
0f80e905ec crypto: fix wallet rpc image 2026-01-15 02:26:54 -03:00
f35f0e27b5 vault: prepopulate oidc job 2026-01-15 02:22:52 -03:00
ee1fd7f458 vault: default oidc claims type 2026-01-15 02:20:53 -03:00
d82146cfd6 vault: harden oidc claims type 2026-01-15 02:18:50 -03:00
a4d20efe7d vault: allow oidc tuning 2026-01-15 02:16:55 -03:00
2b934d4263 vault: use static token reviewer 2026-01-15 02:14:08 -03:00