1280 Commits

Author SHA1 Message Date
f44eef36c2 health: allow portal wger sync 2026-01-15 00:41:28 -03:00
ec7e0ef6e1 comms: move synapse secrets to vault 2026-01-15 00:35:41 -03:00
fedeb3bab7 bstein-dev-home: bump portal images 2026-01-15 00:28:15 -03:00
6183b1f57a jellyfin: prefer gpu nodes by hostname 2026-01-14 23:56:02 -03:00
d60ae9d02d health: add nginx main config 2026-01-14 23:55:50 -03:00
1ca3ee018f health: run nginx directly 2026-01-14 23:47:23 -03:00
64b9351b1b jellyfin: schedule on nvidia accelerators 2026-01-14 23:37:06 -03:00
ee455ec4f0 health: fix nginx pid path 2026-01-14 23:35:07 -03:00
8e1f03f99d jellyfin: trim vault ldap template 2026-01-14 23:34:39 -03:00
b5eb29af2f health: stabilize wger startup 2026-01-14 23:26:07 -03:00
662e724c95 vault: sync oidc and wger env 2026-01-14 23:21:39 -03:00
d957e7e7f7 vault: read oidc config from vault 2026-01-14 23:20:04 -03:00
cb15d9cf66 jellyfin: read LDAP config from vault 2026-01-14 23:15:19 -03:00
b23377119e comms: mount synapse signing key 2026-01-14 22:59:11 -03:00
355088058e comms: mount vault signing key volume 2026-01-14 22:56:30 -03:00
3b6f9ad650 comms: keep redis env while injecting vault 2026-01-14 22:43:50 -03:00
5fc530b6de vault: fix hyphenated key templates 2026-01-14 22:37:18 -03:00
c26b8bb44a comms: fix synapse vault patch 2026-01-14 22:34:02 -03:00
dd0b4e28e7 vault: inject comms and grafana secrets 2026-01-14 22:29:27 -03:00
49d4d13a64 health: fix wger env template newlines 2026-01-14 22:23:48 -03:00
790e41300f health: avoid surge rollout for wger 2026-01-14 22:16:36 -03:00
a99f680711 health: load wger secrets without shell expansion 2026-01-14 22:11:55 -03:00
bc3bfb9348 harbor: fix vault env templates 2026-01-14 22:07:51 -03:00
79d4cac000 health: escape wger env vars and fix nginx temp paths 2026-01-14 22:03:40 -03:00
efbfca1677 harbor: preserve required volume mounts 2026-01-14 21:29:40 -03:00
665612b781 vault: keep copy loop from clobbering args 2026-01-14 21:24:16 -03:00
f484083653 harbor: fix vault secretKey file path 2026-01-14 21:17:05 -03:00
6c91e0313f harbor: mount vault entrypoint script 2026-01-14 21:02:50 -03:00
a2646d92f0 harbor: move secrets to vault sidecars 2026-01-14 20:46:46 -03:00
d716edb6ef jenkins: load vault env via env 2026-01-14 17:57:10 -03:00
dbfc541ccb jenkins: escape vault env values 2026-01-14 17:53:09 -03:00
fb05c442f5 longhorn: read oauth2-proxy secrets from vault 2026-01-14 17:48:12 -03:00
4f99000aab vault: inject remaining services with wrappers 2026-01-14 17:29:09 -03:00
df7369f8d3 vault: inject monitoring exporter and health jobs 2026-01-14 14:49:41 -03:00
fa389be9b8 vault: bump job names for injector 2026-01-14 14:33:57 -03:00
223ff4936f vault: prepopulate injector for jobs 2026-01-14 14:29:29 -03:00
c6914b4488 comms: add vault-secrets emptyDir for mas 2026-01-14 14:24:55 -03:00
be9d4bf32e comms: shorten vault inject file names 2026-01-14 14:21:58 -03:00
f11fb2e2e1 vault: move comms and mailu workloads to injector 2026-01-14 14:17:26 -03:00
f126dc5412 keycloak: schedule on arm64 workers 2026-01-14 13:49:37 -03:00
558c1a0b32 gitea: tolerate oidc init failures 2026-01-14 13:46:34 -03:00
6d46ca1e3b gitea: trim vault secret newlines 2026-01-14 13:43:56 -03:00
65d87f0b2e keycloak: bump job names 2026-01-14 13:42:08 -03:00
4279db1619 vault: stabilize injector templates and add health apps 2026-01-14 13:40:29 -03:00
1c3cb83b0a keycloak: switch jobs to vault injector 2026-01-14 13:20:57 -03:00
50b446aec3 nextcloud: fix vault template keys 2026-01-14 13:00:21 -03:00
3c5032f12f gitea: run vault init first 2026-01-14 12:44:49 -03:00
0928c62d91 bstein-dev-home: bump onboarding job 2026-01-14 12:34:02 -03:00
9c99e68ad8 vault: move core apps to injector 2026-01-14 12:28:10 -03:00
ac0d7a40ab infra: add vault injector 2026-01-14 11:46:13 -03:00