Compare commits

...

13 commits

Author SHA1 Message Date
1baf92ddaf chore(deps): update registry-1.docker.io/bitnamicharts/elasticsearch docker tag to v21.3.24
Some checks failed
checks / pre-commit (push) Failing after 1m31s
checks / k8s (push) Failing after 1m32s
checks / tflint (push) Failing after 1m40s
Kaniko deployments / nextcloud (push) Failing after 1m34s
OpenTofu deployments / authentik (push) Failing after 1m39s
OpenTofu deployments / adguard (push) Failing after 1m28s
2024-11-13 01:26:37 +00:00
6672a721d1 chore(deps): update helm release renovate to 39.10.*
Some checks failed
checks / pre-commit (push) Successful in 1m16s
checks / k8s (push) Successful in 24s
checks / tflint (push) Failing after 23s
Kaniko deployments / nextcloud (push) Successful in 16m27s
OpenTofu deployments / authentik (push) Successful in 1m2s
OpenTofu deployments / adguard (push) Successful in 35s
2024-11-12 01:32:58 +00:00
1d4288caf5
feat: add invalidation_flow to the tofu authentik providers
Some checks failed
checks / k8s (push) Failing after 1m33s
checks / pre-commit (push) Failing after 1m36s
OpenTofu deployments / authentik (push) Failing after 41s
OpenTofu deployments / adguard (push) Failing after 1m46s
checks / tflint (push) Failing after 1m27s
Kaniko deployments / nextcloud (push) Failing after 1m37s
2024-11-11 16:46:56 +01:00
343b1d27af
chore: update netbird to v1.31.1
Some checks failed
checks / k8s (push) Failing after 1m26s
checks / pre-commit (push) Failing after 1m36s
checks / tflint (push) Failing after 1m42s
Kaniko deployments / nextcloud (push) Failing after 1m33s
OpenTofu deployments / authentik (push) Failing after 1m34s
OpenTofu deployments / adguard (push) Failing after 1m38s
2024-11-11 16:37:40 +01:00
a635c718cd
feat: add supervisor volumes to nextcloud
Some checks failed
checks / k8s (push) Failing after 1m32s
checks / pre-commit (push) Failing after 1m41s
checks / tflint (push) Failing after 1m36s
Kaniko deployments / nextcloud (push) Failing after 1m28s
OpenTofu deployments / authentik (push) Failing after 1m57s
OpenTofu deployments / adguard (push) Failing after 1m57s
2024-11-11 11:03:47 +01:00
2f5561f4cb
feat: update nextcloud to v30.0.2
Some checks failed
checks / tflint (push) Failing after 1m24s
checks / pre-commit (push) Failing after 1m39s
checks / k8s (push) Failing after 1m27s
Kaniko deployments / nextcloud (push) Failing after 1m39s
OpenTofu deployments / authentik (push) Failing after 1m28s
OpenTofu deployments / adguard (push) Successful in 1m36s
2024-11-11 09:56:04 +01:00
63dcbff693 chore(deps): update helm release renovate to 39.9.*
Some checks failed
Kaniko deployments / nextcloud (push) Failing after 1m38s
OpenTofu deployments / authentik (push) Failing after 1m30s
checks / k8s (push) Failing after 1m39s
checks / pre-commit (push) Failing after 1m39s
checks / tflint (push) Failing after 1m27s
OpenTofu deployments / adguard (push) Failing after 1m33s
2024-11-11 08:29:46 +00:00
2deb70474e chore(deps): update miniflux/miniflux docker tag to v2.2.3
Some checks failed
checks / pre-commit (push) Failing after 2m27s
checks / k8s (push) Failing after 2m11s
checks / tflint (push) Failing after 1m37s
Kaniko deployments / nextcloud (push) Failing after 1m38s
OpenTofu deployments / authentik (push) Failing after 1m27s
OpenTofu deployments / adguard (push) Failing after 1m29s
2024-11-11 08:11:30 +00:00
53fc602e13 chore(deps): update ghcr.io/paperless-ngx/paperless-ngx docker tag to v2.13.5
Some checks failed
OpenTofu deployments / adguard (push) Waiting to run
checks / pre-commit (push) Successful in 1m43s
checks / k8s (push) Successful in 23s
checks / tflint (push) Successful in 20s
Kaniko deployments / nextcloud (push) Has been cancelled
OpenTofu deployments / authentik (push) Has been cancelled
2024-11-11 08:05:16 +00:00
73b05c330a chore(deps): update code.forgejo.org/forgejo-helm/forgejo docker tag to v10.1.0
Some checks failed
checks / pre-commit (push) Failing after 2m7s
checks / k8s (push) Failing after 2m6s
checks / tflint (push) Failing after 1m33s
Kaniko deployments / nextcloud (push) Failing after 1m39s
OpenTofu deployments / authentik (push) Failing after 1m37s
OpenTofu deployments / adguard (push) Failing after 1m37s
2024-11-11 01:32:57 +00:00
55865cb406
chore: update vaultwarden to v1.32.4
Some checks failed
checks / k8s (push) Failing after 1m42s
checks / pre-commit (push) Failing after 1m54s
checks / tflint (push) Failing after 1m42s
Kaniko deployments / nextcloud (push) Failing after 1m41s
OpenTofu deployments / adguard (push) Failing after 1m32s
OpenTofu deployments / authentik (push) Failing after 1m44s
2024-11-11 00:59:48 +01:00
6e6542cc9b chore(deps): update registry-1.docker.io/bitnamicharts/elasticsearch docker tag to v21.3.23
Some checks failed
checks / k8s (push) Failing after 2m14s
checks / pre-commit (push) Failing after 2m15s
checks / tflint (push) Successful in 50s
Kaniko deployments / nextcloud (push) Failing after 7m54s
OpenTofu deployments / authentik (push) Failing after 1m39s
OpenTofu deployments / adguard (push) Failing after 1m27s
2024-11-10 02:47:50 +00:00
40353041e4 chore(deps): update helm release factorio-server-charts to 2.5.*
Some checks failed
checks / pre-commit (push) Failing after 2m58s
checks / k8s (push) Failing after 2m45s
checks / tflint (push) Failing after 2m33s
Kaniko deployments / nextcloud (push) Failing after 2m20s
OpenTofu deployments / authentik (push) Failing after 2m36s
OpenTofu deployments / adguard (push) Failing after 2m27s
2024-11-10 02:17:09 +00:00
14 changed files with 46 additions and 41 deletions

View file

@ -20,5 +20,5 @@ jobs:
password: ${{ secrets.REGISTRY_PASSWORD }}
cache: true
registry: git.roboces.dev
tag: nextcloud-30.0.1
tag: nextcloud-30.0.2
path: docker/nextcloud

View file

@ -23,7 +23,7 @@ services:
max-size: "500m"
max-file: "2"
signal:
image: netbirdio/signal:0.31.0
image: netbirdio/signal:0.31.1
restart: unless-stopped
volumes:
- netbird-signal:/var/lib/netbird
@ -35,7 +35,7 @@ services:
max-size: "500m"
max-file: "2"
relay:
image: netbirdio/relay:0.31.0
image: netbirdio/relay:0.31.1
restart: unless-stopped
environment:
NB_LOG_LEVEL: ${NB_LOG_LEVEL:-info}
@ -50,7 +50,7 @@ services:
max-size: "500m"
max-file: "2"
management:
image: netbirdio/management:0.31.0
image: netbirdio/management:0.31.1
restart: unless-stopped
depends_on:
- dashboard
@ -91,7 +91,7 @@ services:
max-file: "2"
peer-1:
image: netbirdio/netbird:0.30.3
image: netbirdio/netbird:0.31.1
restart: unless-stopped
volumes:
- ${NETBIRD_PEER_VOLUME:-/mnt/nas1/shared/netbird/peer-1}/data:/etc/netbird

View file

@ -14,7 +14,7 @@ services:
- nextcloud
nextcloud:
image: git.roboces.dev/catalin/fukuops:nextcloud-30.0.1
image: git.roboces.dev/catalin/fukuops:nextcloud-30.0.2
volumes:
- /mnt/nas1/legacy-storage/cloud/cloud/data:/var/www/html/data
- /mnt/nas1/legacy-storage/cloud/cloud/config:/var/www/html/config
@ -22,6 +22,8 @@ services:
- /mnt/nas1/legacy-storage/cloud/cloud/apps:/var/www/html/apps
- type: tmpfs
target: /tmp:exec
- supervisorlog:/var/log/supervisor:z
- supervisorpid:/var/run/supervisord/:z
environment:
PHP_MEMORY_LIMIT: ${PHP_MEMORY_LIMIT:-2048M}
NEXTCLOUD_INIT_HTACCESS: ${NEXTCLOUD_INIT_HTACCESS:-1}
@ -33,3 +35,6 @@ services:
networks:
nextcloud: {}
volumes:
supervisorlog: {}
supervisorpid: {}

View file

@ -14,7 +14,7 @@ services:
webserver:
image: ghcr.io/paperless-ngx/paperless-ngx:2.13.4
image: ghcr.io/paperless-ngx/paperless-ngx:2.13.5
restart: unless-stopped
ports:
- 8002:8000

View file

@ -1,7 +1,7 @@
---
services:
vaultwarden:
image: vaultwarden/server:1.32.3-alpine
image: vaultwarden/server:1.32.4-alpine
restart: unless-stopped
environment:
DATABASE_URL: ${DATABASE_URL}

View file

@ -12,7 +12,7 @@ spec:
sources:
- chart: elasticsearch
repoURL: registry-1.docker.io/bitnamicharts
targetRevision: 21.3.22
targetRevision: 21.3.24
helm:
valuesObject:
service:

View file

@ -12,7 +12,7 @@ spec:
sources:
- chart: factorio-server-charts
repoURL: https://sqljames.github.io/factorio-server-charts/
targetRevision: 2.2.*
targetRevision: 2.5.*
helm:
valuesObject:
rcon:

View file

@ -12,7 +12,7 @@ spec:
sources:
- chart: forgejo
repoURL: code.forgejo.org/forgejo-helm
targetRevision: 10.0.2
targetRevision: 10.1.0
helm:
valuesObject:
replicaCount: 2

View file

@ -13,7 +13,7 @@ spec:
sources:
- chart: renovate
repoURL: https://docs.renovatebot.com/helm-charts
targetRevision: 39.8.*
targetRevision: 39.10.*
helm:
valuesObject:
renovate:

View file

@ -28,7 +28,7 @@ spec:
spec:
containers:
- name: miniflux
image: miniflux/miniflux:2.2.2
image: miniflux/miniflux:2.2.3
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false

View file

@ -33,21 +33,6 @@ resource "authentik_group" "vpn" {
}
module "firezone" {
source = "../modules/authentik-oidc"
app_name = "Firezone"
app_slug = "firezone"
client_id = var.firezone_client_id
client_secret = var.firezone_client_secret
app_access_group_id = authentik_group.admins.id
redirect_uris = ["https://fz.fukurokuju.dev/auth/oidc/authentik/callback/"]
app_icon = "https://www.firezone.dev/icon.svg"
app_description = "VPN"
app_publisher = "Firezone"
app_url = "https://fz.fukurokuju.dev"
sub_mode = "hashed_user_id"
}
module "gitea" {
source = "../modules/authentik-oidc"
app_name = "Gitea"
@ -159,5 +144,6 @@ module "netbird" {
extra_property_mappings = [
"goauthentik.io/providers/oauth2/scope-authentik_api"
]
app_icon = "https://vpn.fukurokuju.dev/apple-icon.png"
app_icon = "https://vpn.fukurokuju.dev/apple-icon.png"
access_token_validity = "days=10"
}

View file

@ -26,20 +26,25 @@ data "authentik_property_mapping_provider_scope" "default-scopes" {
], var.extra_property_mappings)
}
data "authentik_flow" "default-provider-invalidation-flow" {
slug = "default-provider-invalidation-flow "
}
resource "authentik_provider_oauth2" "provider_oidc" {
name = var.app_name
client_id = var.client_id
client_secret = var.client_secret
client_type = var.client_type
authorization_flow = data.authentik_flow.default-authorization-flow.id
authentication_flow = data.authentik_flow.default-authentication-flow.id
redirect_uris = var.redirect_uris
property_mappings = data.authentik_property_mapping_provider_scope.default-scopes.ids
sub_mode = var.sub_mode
signing_key = var.oidc_signing_key
access_code_validity = var.access_code_validity
access_token_validity = var.access_token_validity
name = var.app_name
client_id = var.client_id
client_secret = var.client_secret
client_type = var.client_type
authorization_flow = data.authentik_flow.default-authorization-flow.id
authentication_flow = data.authentik_flow.default-authentication-flow.id
redirect_uris = var.redirect_uris
property_mappings = data.authentik_property_mapping_provider_scope.default-scopes.ids
sub_mode = var.sub_mode
signing_key = var.oidc_signing_key
access_code_validity = var.access_code_validity
access_token_validity = var.access_token_validity
refresh_token_validity = var.refresh_token_validity
invalidation_flow = data.authentik_flow.default-provider-invalidation-flow.id
}

View file

@ -90,6 +90,11 @@ variable "access_token_validity" {
default = "minutes=10"
}
variable "refresh_token_validity" {
type = string
default = "days=30"
}
variable "extra_property_mappings" {
type = list(string)
default = []

View file

@ -16,6 +16,9 @@ data "authentik_flow" "default-authentication-flow" {
slug = "default-authentication-flow"
}
data "authentik_flow" "default-provider-invalidation-flow" {
slug = "default-provider-invalidation-flow "
}
resource "authentik_provider_proxy" "provider_proxy" {
authorization_flow = data.authentik_flow.default-authorization-flow.id
@ -24,6 +27,7 @@ resource "authentik_provider_proxy" "provider_proxy" {
internal_host = var.internal_host
name = var.app_name
internal_host_ssl_validation = var.internal_host_ssl_validation
invalidation_flow = data.authentik_flow.default-provider-invalidation-flow.id
}