Added more subcharts and removed unused apps

This commit is contained in:
GeorgeRaven
2025-07-23 23:17:46 +01:00
parent ff63239013
commit 75fa524e5f
22 changed files with 0 additions and 636 deletions

Binary file not shown.

Binary file not shown.

View File

@@ -1,23 +0,0 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@@ -1,6 +0,0 @@
dependencies:
- name: dex
repository: https://charts.dexidp.io
version: 0.23.0
digest: sha256:1ea89746228c51235fc4fb406040d1e5838d2c1b6edc404ab034bd84150c6457
generated: "2025-05-25T09:21:37.005915814+01:00"

View File

@@ -1,29 +0,0 @@
apiVersion: v2
name: dex
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"
dependencies:
- name: dex
version: 0.23.0
repository: "https://charts.dexidp.io"

View File

@@ -1,38 +0,0 @@
# dex
![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square)
A Helm chart for Kubernetes
## Requirements
| Repository | Name | Version |
|------------|------|---------|
| https://charts.dexidp.io | dex | 0.23.0 |
## Values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| dex.config.connectors[0].claimMapping | string | `nil` | |
| dex.config.connectors[0].clientID | string | `"$AUTH_CLIENT_ID"` | |
| dex.config.connectors[0].clientSecret | string | `"$AUTH_CLIENT_SECRET"` | |
| dex.config.connectors[0].config.issuer | string | `"https://auth.deepcypher.me"` | |
| dex.config.connectors[0].id | string | `"authentik"` | |
| dex.config.connectors[0].name | string | `"authentik"` | |
| dex.config.connectors[0].redirectURI | string | `"https://dex.deepcypher.me/callback"` | |
| dex.config.connectors[0].type | string | `"oidc"` | |
| dex.config.enablePasswordDB | bool | `true` | |
| dex.config.issuer | string | `"http://dex.deepcypher.me"` | |
| dex.config.storage.type | string | `"memory"` | |
| dex.enabled | bool | `true` | |
| dex.fullnameOverride | string | `"dex"` | |
| dex.ingress.annotations."cert-manager.io/cluster-issuer" | string | `"aux-issuer"` | |
| dex.ingress.className | string | `"traefik"` | |
| dex.ingress.enabled | bool | `true` | |
| dex.ingress.hosts[0].host | string | `"dex.deepcypher.me"` | |
| dex.ingress.hosts[0].paths[0].path | string | `"/"` | |
| dex.ingress.hosts[0].paths[0].pathType | string | `"Prefix"` | |
| dex.ingress.tls[0].hosts[0] | string | `"dex.deepcypher.me"` | |
| dex.ingress.tls[0].secretName | string | `"dex-cert"` | |

View File

@@ -1,37 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-local-egress
spec:
podSelector: {}
policyTypes:
- Egress
egress:
- to:
# allow to go to WAN internet
- ipBlock:
cidr: 0.0.0.0/0
except:
- 10.0.0.0/8
- 192.168.0.0/16
- 172.16.0.0/20
# or allowed to go to local namespace
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: {{ .Release.Namespace }}
# Also
- to:
# allow DNS lookups
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: kube-system
# on specific ports
ports:
- protocol: UDP
port: 53
# Also
- to:
# allow to kubernetes api default in default namespace
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: default

View File

@@ -1,110 +0,0 @@
dex:
enabled: true
fullnameOverride: dex
ingress:
enabled: true
className: traefik
annotations:
cert-manager.io/cluster-issuer: aux-issuer
hosts:
- host: dex.deepcypher.me
paths:
- path: /
pathType: Prefix
tls:
- hosts:
- dex.deepcypher.me
secretName: dex-cert
config:
# Set it to a valid URL
issuer: http://dex.deepcypher.me
# See https://dexidp.io/docs/storage/ for more options
storage:
type: memory
# Enable at least one connector
# See https://dexidp.io/docs/connectors/ for more options
enablePasswordDB: true
connectors:
- type: oidc
id: authentik
name: authentik
config:
# MUST match what is in /.well-known/openid-configuration/
issuer: "https://auth.deepcypher.me"
# connector config values starting with $ will be env substituted
clientID: $AUTH_CLIENT_ID
clientSecret: $AUTH_CLIENT_SECRET
# Dex's issuer URL + "/callback"
redirectURI: "https://dex.deepcypher.me/callback"
# Some providers require passing client_secret via POST parameters instead
# of basic auth, despite the OAuth2 RFC discouraging it. Many of these
# cases are caught internally, but some may need to uncomment the
# following field.
#
# basicAuthUnsupported: true
# List of additional scopes to request in token response
# Default is profile and email
# Full list at https://dexidp.io/docs/custom-scopes-claims-clients/
# scopes:
# - profile
# - email
# - groups
# Some providers return claims without "email_verified", when they had no usage of emails verification in enrollment process
# or if they are acting as a proxy for another IDP etc AWS Cognito with an upstream SAML IDP
# This can be overridden with the below option
# insecureSkipEmailVerified: true
# Groups claims (like the rest of oidc claims through dex) only refresh when the id token is refreshed
# meaning the regular refresh flow doesn't update the groups claim. As such by default the oidc connector
# doesn't allow groups claims. If you are okay with having potentially stale group claims you can use
# this option to enable groups claims through the oidc connector on a per-connector basis.
# This can be overridden with the below option
# insecureEnableGroups: true
# When enabled, the OpenID Connector will query the UserInfo endpoint for additional claims. UserInfo claims
# take priority over claims returned by the IDToken. This option should be used when the IDToken doesn't contain
# all the claims requested.
# https://openid.net/specs/openid-connect-core-1_0.html#UserInfo
# getUserInfo: true
# The set claim is used as user id.
# Claims list at https://openid.net/specs/openid-connect-core-1_0.html#Claims
# Default: sub
# userIDKey: nickname
# The set claim is used as user name.
# Default: name
# userNameKey: nickname
# The acr_values variable specifies the Authentication Context Class Values within
# the Authentication Request that the Authorization Server is being requested to process
# from this Client.
# acrValues:
# - <value>
# - <value>
# For offline_access, the prompt parameter is set by default to "prompt=consent".
# However this is not supported by all OIDC providers, some of them support different
# value for prompt, like "prompt=login" or "prompt=none"
# promptType: consent
# Some providers return non-standard claims (eg. mail).
# Use claimMapping to map those claims to standard claims:
# https://openid.net/specs/openid-connect-core-1_0.html#Claims
# claimMapping can only map a non-standard claim to a standard one if it's not returned in the id_token.
claimMapping:
# The set claim is used as preferred username.
# Default: preferred_username
# preferred_username: other_user_name
# The set claim is used as email.
# Default: email
# email: mail
# The set claim is used as groups.
# Default: groups
# groups: "cognito:groups"

View File

@@ -1,23 +0,0 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@@ -1,24 +0,0 @@
apiVersion: v2
name: dc-template
description: DeepCypher AoA template cluster decleration
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "0.1.0"

View File

@@ -1,13 +0,0 @@
# dc-template
![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 0.1.0](https://img.shields.io/badge/AppVersion-0.1.0-informational?style=flat-square)
DeepCypher AoA template cluster decleration
## Values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| exmongo.persistence.size | string | `"9Gi"` | |
| exmongo.version | string | `"10.30.12"` | |

View File

@@ -1,38 +0,0 @@
# @Author: GeorgeRaven <archer>
# @Date: 2021-05-14T14:38:52+01:00
# @Last modified by: archer
# @Last modified time: 2021-05-20T19:57:00+01:00
# @License: please see LICENSE file in project root
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-local-egress
namespace: mongodb-experimental
spec:
podSelector: {}
policyTypes:
- Egress
egress:
- to:
# allow to go to WAN internet
- ipBlock:
cidr: 0.0.0.0/0
except:
- 10.0.0.0/8
- 192.168.0.0/16
- 172.16.0.0/20
# or allowed to go to local namespace
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: mongodb-experimental
# Also
- to:
# allow DNS lookups
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: kube-system
# on specific ports
ports:
- protocol: UDP
port: 53

View File

@@ -1,47 +0,0 @@
# @Author: archer
# @Date: 2021-12-08T15:41:37+00:00
# @Last modified by: archer
# @Last modified time: 2021-12-10T13:08:37+00:00
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: exp-mongodb-helm
namespace: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
destination:
name: ''
namespace: mongodb-experimental
server: 'https://kubernetes.default.svc'
source:
path: ''
repoURL: 'https://charts.bitnami.com/bitnami'
targetRevision: {{ .Values.exmongo.version }}
chart: mongodb
# helm:
# parameters:
# - name: key
# value: 'value'
helm:
values: |-
image:
tag: "5.0.5-debian-10-r5"
architecture: "standalone"
tls:
enabled: true
mode: preferTLS
directoryPerDB: true
persistence:
size: {{ .Values.exmongo.persistence.size }}
storageClass : exp-mongodb
project: default
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true

View File

@@ -1,4 +0,0 @@
exmongo:
version: 10.30.12
persistence:
size: 9Gi

View File

@@ -1,23 +0,0 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@@ -1,12 +0,0 @@
dependencies:
- name: external-dns
repository: https://kubernetes-sigs.github.io/external-dns
version: 1.18.0
- name: etcd
repository: oci://registry-1.docker.io/bitnamicharts
version: 12.0.12
- name: coredns
repository: https://coredns.github.io/helm
version: 1.43.0
digest: sha256:69902725f52798b49a8d5ea7b6bc58c0617aa0f236768ead5b411926e8e7bb51
generated: "2025-07-23T22:05:26.928600788Z"

View File

@@ -1,38 +0,0 @@
apiVersion: v2
name: external-dns
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"
dependencies:
- name: external-dns
version: 1.18.0
repository: "https://kubernetes-sigs.github.io/external-dns"
condition: external-dns.enabled
- name: etcd
version: 12.0.12
repository: "oci://registry-1.docker.io/bitnamicharts"
condition: etcd.enabled
- name: coredns
version: 1.43.0
repository: "https://coredns.github.io/helm"
condition: coredns.enabled

View File

@@ -1,30 +0,0 @@
# external-dns
![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square)
A Helm chart for Kubernetes
## Requirements
| Repository | Name | Version |
|------------|------|---------|
| https://coredns.github.io/helm | coredns | 1.43.0 |
| https://kubernetes-sigs.github.io/external-dns | external-dns | 1.17.0 |
| oci://registry-1.docker.io/bitnamicharts | etcd | 11.3.6 |
## Values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| coredns.enabled | bool | `true` | |
| coredns.isClusterService | bool | `false` | |
| coredns.rbac.create | bool | `true` | |
| coredns.servers[0].plugins | list | `[{"name":"errors"},{"configBlock":"lameduck 5s","name":"health"},{"name":"ready"},{"configBlock":"pods insecure\nfallthrough in-addr.arpa ip6.arpa\nttl 30","name":"kubernetes","parameters":"cluster.local in-addr.arpa ip6.arpa"},{"name":"prometheus","parameters":"0.0.0.0:9153"},{"name":"forward","parameters":". /etc/resolv.conf"},{"configBlock":"stubzones\npath /skydns\nendpoint http://etcd:2379","name":"etcd","parameters":"deepcypher.me"},{"name":"cache","parameters":30},{"name":"loop"},{"name":"reload"},{"name":"loadbalance"}]` | expose the service on a different port servicePort: 5353 If serviceType is nodePort you can specify nodePort here nodePort: 30053 hostPort: 53 |
| coredns.servers[0].port | int | `53` | |
| coredns.servers[0].zones[0].zone | string | `"."` | |
| etcd.enabled | bool | `true` | |
| etcd.fullnameOverride | string | `"etcd"` | |
| etcd.replicaCount | int | `3` | |
| external-dns.enabled | bool | `false` | |
| external-dns.provider.name | string | `"coredns"` | |

View File

@@ -1,85 +0,0 @@
#apiVersion: v1
#kind: Service
#metadata:
# name: etcd-client
#spec:
# type: ClusterIP
# ports:
# - name: etcd-client
# port: 2379
# protocol: TCP
# targetPort: 2379
# selector:
# app.kubernetes.io/name: etcd
#---
#apiVersion: v1
#kind: Service
#metadata:
# name: etcd
#spec:
# clusterIP: None
# ports:
# - port: 2379
# name: client
# - port: 2380
# name: peer
# selector:
# app.kubernetes.io/name: etcd
#---
#apiVersion: apps/v1
#kind: StatefulSet
#metadata:
# name: etcd
# labels:
# app.kubernetes.io/name: etcd
#spec:
# serviceName: etcd
# replicas: 3
# selector:
# matchLabels:
# app.kubernetes.io/name: etcd
# template:
# metadata:
# name: etcd
# labels:
# app.kubernetes.io/name: etcd
# spec:
# containers:
# - name: etcd
# image: quay.io/coreos/etcd:v3.5.9
# env:
# - name: PEERS
# value: "etcd-0=http://etcd-0.{{ .Release.Namespace }}:2380,etcd-1=http://etcd-1.{{ .Release.Namespace }}:2380,etcd-2=http://etcd-2.{{ .Release.Namespace }}:2380"
# - name: HOSTNAME
# valueFrom:
# fieldRef:
# fieldPath: metadata.name
# ports:
# - containerPort: 2379
# name: client
# - containerPort: 2380
# name: peer
# volumeMounts:
# - name: data
# mountPath: /var/run/etcd
# command:
# - /usr/local/bin/etcd
# args:
# - --name ${HOSTNAME}
# - --listen-peer-urls http://0.0.0.0:2380
# - --listen-client-urls http://0.0.0.0:2379
# - --advertise-client-urls http://${HOSTNAME}.{{ .Release.Namespace }}:2379
# - --initial-advertise-peer-urls http://${HOSTNAME}:2380
# - --initial-cluster-token etcd-cluster-1
# - --initial-cluster ${PEERS}
# - --initial-cluster-state new
# - --data-dir /var/run/etcd/default.etcd
# volumeClaimTemplates:
# - metadata:
# name: data
# spec:
# storageClassName: ceph-filesystem
# accessModes: [ "ReadWriteOnce" ]
# resources:
# requests:
# storage: 2Gi

View File

@@ -1,56 +0,0 @@
external-dns:
enabled: false
provider:
name: "coredns"
coredns:
enabled: true
rbac:
create: true
isClusterService: false # default true but would integrat to k8s cluster itself
servers:
- zones:
- zone: .
port: 53
# -- expose the service on a different port
# servicePort: 5353
# If serviceType is nodePort you can specify nodePort here
# nodePort: 30053
# hostPort: 53
plugins:
- name: errors
# Serves a /health endpoint on :8080, required for livenessProbe
- name: health
configBlock: |-
lameduck 5s
# Serves a /ready endpoint on :8181, required for readinessProbe
- name: ready
# Required to query kubernetes API for data
- name: kubernetes
parameters: cluster.local in-addr.arpa ip6.arpa
configBlock: |-
pods insecure
fallthrough in-addr.arpa ip6.arpa
ttl 30
# Serves a /metrics endpoint on :9153, required for serviceMonitor
- name: prometheus
parameters: 0.0.0.0:9153
- name: forward
parameters: . /etc/resolv.conf
- name: etcd
parameters: deepcypher.me
configBlock: |-
stubzones
path /skydns
endpoint http://etcd:2379
- name: cache
parameters: 30
- name: loop
- name: reload
- name: loadbalance
etcd:
enabled: true
fullnameOverride: etcd # to ensure consistent naming
replicaCount: 3