diff --git a/actual/deployment.yaml b/actual/deployment.yaml new file mode 100644 index 0000000..1c63fe6 --- /dev/null +++ b/actual/deployment.yaml @@ -0,0 +1,30 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: actual + namespace: actual +spec: + selector: + matchLabels: + app: actual + template: + metadata: + labels: + app: actual + spec: + containers: + - name: actual + image: docker.io/actualbudget/actual-server:latest + ports: + - containerPort: 5006 + name: http + protocol: TCP + volumeMounts: + - mountPath: /data + name: data + volumes: + - name: data + persistentVolumeClaim: + claimName: actual-data + + diff --git a/actual/dns-endpoint.yaml b/actual/dns-endpoint.yaml new file mode 100644 index 0000000..0898738 --- /dev/null +++ b/actual/dns-endpoint.yaml @@ -0,0 +1,12 @@ +apiVersion: externaldns.k8s.io/v1alpha1 +kind: DNSEndpoint +metadata: + name: actual.michaelthomson.dev + namespace: actual +spec: + endpoints: + - dnsName: actual.michaelthomson.dev + recordTTL: 180 + recordType: CNAME + targets: + - server.michaelthomson.dev diff --git a/actual/ingress.yaml b/actual/ingress.yaml new file mode 100644 index 0000000..eb905b5 --- /dev/null +++ b/actual/ingress.yaml @@ -0,0 +1,25 @@ +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: actual + namespace: actual + annotations: + traefik.ingress.kubernetes.io/router.entrypoints: websecure + traefik.ingress.kubernetes.io/router.middlewares: traefik-authentik@kubernetescrd + traefik.ingress.kubernetes.io/router.tls: "true" +spec: + rules: + - host: actual.michaelthomson.dev + http: + paths: + - pathType: ImplementationSpecific + path: / + backend: + service: + name: actual + port: + name: http + tls: + - hosts: + - actual.michaelthomson.dev + secretName: letsencrypt-wildcard-cert-michaelthomson.dev diff --git a/actual/pvc-data.yaml b/actual/pvc-data.yaml new file mode 100644 index 0000000..76c5f77 --- /dev/null +++ b/actual/pvc-data.yaml @@ -0,0 +1,12 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: actual-data + namespace: actual +spec: + resources: + requests: + storage: 2Gi + storageClassName: longhorn + accessModes: + - ReadWriteOnce diff --git a/actual/service.yaml b/actual/service.yaml new file mode 100644 index 0000000..cffb3f2 --- /dev/null +++ b/actual/service.yaml @@ -0,0 +1,12 @@ +apiVersion: v1 +kind: Service +metadata: + name: actual + namespace: actual +spec: + selector: + app: actual + ports: + - port: 80 + targetPort: http + name: http diff --git a/bootstrap/kustomizations/kustomization-actual.yaml b/bootstrap/kustomizations/kustomization-actual.yaml new file mode 100644 index 0000000..1434d78 --- /dev/null +++ b/bootstrap/kustomizations/kustomization-actual.yaml @@ -0,0 +1,18 @@ +apiVersion: kustomize.toolkit.fluxcd.io/v1 +kind: Kustomization +metadata: + name: actual + namespace: flux-system +spec: + interval: 30m + path: ./actual + prune: true # remove any elements later removed from the above path + timeout: 2m # if not set, this defaults to interval duration, which is 1h + sourceRef: + kind: GitRepository + name: flux-system + healthChecks: + - apiVersion: apps/v1 + kind: Deployment + name: actual + namespace: actual diff --git a/bootstrap/namespaces/namespace-actual.yaml b/bootstrap/namespaces/namespace-actual.yaml new file mode 100644 index 0000000..11b4358 --- /dev/null +++ b/bootstrap/namespaces/namespace-actual.yaml @@ -0,0 +1,4 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: actual